Skip to content

Create the pipeline

Source, Build and Deploy stages created with the CodePipeline wizard, triggered only by pushes that touch the API.

About 25 min · Verified 8 October 2026

0 of 8 steps done0%

The CodePipeline wizard creates the pipeline, a CodeBuild project and the service roles in one pass. You will answer six screens.

Run the wizard#

Choose how to create it#

Open CodePipelinePipelinesCreate pipeline. Choose Build custom pipeline and then Next.

Pipeline settings#

FieldValue
Pipeline nameshortlink-api-prod
Pipeline typeV2
Execution modeQueued
Service roleNew service role (accept the generated name)
Allow AWS CodePipeline to create a service roleticked

Under Advanced settings leave Artifact store on Default location and the encryption key on Default AWS managed key. The artifact store is a private bucket named codepipeline-<region>-…, not your website bucket.

Choose Next.

Source#

FieldValue
Source providerGitHub (via GitHub App)
Connectionshortlink-github
Repository name<GITHUB_USER>/shortlink (your fork)
Default branchmain
Output artifact formatCodePipeline default (a ZIP)

Under Trigger, keep Start the pipeline on source code change and add a filter so only backend changes start a release:

FieldValue
Event typePush
Branches → Includemain
File paths → Includeshortlink-api/**, appspec.yml, deploy/**

Choose Next. The output artifact for this stage is called SourceArtifact.

Build: create the CodeBuild project#

FieldValue
Build providerOther build providers → AWS CodeBuild
Regionap-south-1
Project namechoose Create project

A new window or panel opens for the CodeBuild project:

FieldValue
Project nameshortlink-api-build
Project typeDefault project (not Runner project)
Environment imageManaged image
ComputeEC2
Operating systemAmazon Linux
Runtime(s)Standard
Imageaws/codebuild/amazonlinux-x86_64-standard:5.0 (or the newest standard image offered)
Service roleNew service role (accept the name)
BuildspecUse a buildspec file → deploy/buildspec-api.yml
LogsCloudWatch logs ticked
VPCnone

Choose Continue to CodePipeline. Back in the wizard, confirm Input artifacts is SourceArtifact, Build type is Single build, and leave the output artifact as the default, BuildArtifact. Choose Next.

Test: skip#

Choose Skip test stage (and confirm). Tests already run inside the build.

Deploy#

FieldValue
Deploy providerAWS CodeDeploy
Regionap-south-1
Application nameshortlink-api
Deployment groupshortlink-api-prod
Input artifactsBuildArtifact

Choose Next.

Review and create#

Check the summary: Source (SourceArtifact) → Build (BuildArtifact) → Deploy. Choose Create pipeline.

The pipeline starts running. Let it. If Deploy fails with an access denied or cannot download message, that is the expected first failure.

Verify the structure#

Your computerShow stages and actions
aws codepipeline get-pipeline --region ap-south-1 --name shortlink-api-prod \
  --query 'pipeline.{type:pipelineType,mode:executionMode,stages:stages[].{stage:name,actions:actions[].{action:name,provider:actionTypeId.provider,in:inputArtifacts[].name,out:outputArtifacts[].name}}}' \
  --output json
You should see
Three stages, Source (provider CodeStarSourceConnection, output SourceArtifact), Build (CodeBuild, input SourceArtifact, output BuildArtifact) and Deploy (CodeDeploy, input BuildArtifact). type is V2 and mode is QUEUED.
The Build action has no output artifact

Open CodePipelineshortlink-api-prodEditBuildEdit stagethe actionEdit and set Output artifacts to BuildArtifact. Then check that the Deploy action's input is BuildArtifact. Save the pipeline.

CodeBuild says its source type is GitHub instead of CodePipeline

Projects created from the wizard use the CODEPIPELINE source and artifact types automatically. That mismatch only happens when a project was created separately in the CodeBuild console first. Fix it from the command line, then confirm:

Your computerSwitch a CodeBuild project to pipeline mode
aws codebuild update-project --region ap-south-1 --name shortlink-api-build \
  --source 'type=CODEPIPELINE,buildspec=deploy/buildspec-api.yml' --artifacts 'type=CODEPIPELINE'
aws codebuild batch-get-projects --region ap-south-1 --names shortlink-api-build \
  --query 'projects[].{name:name,source:source.type,artifacts:artifacts.type,buildspec:source.buildspec}'

Both source and artifacts must say CODEPIPELINE. CodeBuild validates them together, so setting only the source (or NO_ARTIFACTS) is rejected.

Next: fix the permissions.

Found a mistake? Edit this page on GitHub.