Skip to content

Troubleshooting

Errors you may meet while building and running the backend pipeline, what causes them and how to fix them.

About 15 min · Verified 8 October 2026

The pipeline has five moving parts, so the first job is to work out which stage failed. Open CodePipelineshortlink-api-prod and look for the red box.

Your computerWhich stage and action failed, and why?
aws codepipeline get-pipeline-state --region ap-south-1 --name shortlink-api-prod \
  --query 'stageStates[].{stage:stageName,actions:actionStates[].{action:actionName,status:latestExecution.status,error:latestExecution.errorDetails.message}}' \
  --output json

Connection and source#

SymptomCauseFix
Source cannot read the repoThe connection is Pending, or in another RegionOpen it and finish Update pending connection. It must be Available in ap-south-1
Your fork is missing from the repository listThe GitHub App is not installed on itGitHub → SettingsApplicationsAWS Connector for GitHubConfigure, add the fork
The pipeline does not start on pushThe push was not to main, did not touch a filtered path, or you used a pull request triggerCheck the trigger filters, or use Release change
The pipeline ran the instructor's codeThe Source action points at Amaan-Khan14/shortlink instead of your forkEdit the Source action's repository to <GITHUB_USER>/shortlink
GitHub says you cannot install the appYou are installing on a repo you do not ownFork the repository and install on the fork

Build#

SymptomCauseFix
codebuild:StartBuild AccessDenied and no CodeBuild logThe pipeline role cannot start the project, so the failure happened in CodePipelineAdd codebuild:StartBuild and BatchGetBuilds for shortlink-api-build to the pipeline role
YAML_FILE_ERROR or stat deploy/buildspec-api.yml: no such fileThe buildspec path in the project is wrong, or the file is not on mainSet the buildspec to deploy/buildspec-api.yml and push the file
npm ci fails: lockfile out of syncpackage.json and package-lock.json disagreeRun npm install in shortlink-api, commit the lockfile
A test failsA real regressionRead the failing test, fix the code, push
The Node version is wrongAn image that does not support nodejs: 20Use the amazonlinux-x86_64-standard image (version 5.0 or newer)
Source/artifact type error when changing the projectCodeBuild validates both types togetherSet both to CODEPIPELINE (see the pipeline chapter)

Deploy: before the scripts run#

SymptomCauseFix
No instances found for deployment groupTag mismatch, instance stopped, or agent not runningInstance tag Name=shortlink-api exactly; instance running; systemctl is-active codedeploy-agent is active
The agent never picks up the deploymentThe agent cannot reach CodeDeployThe private subnet needs the NAT route; check the agent log
DownloadBundle fails with Access Deniedshortlink-ec2-role cannot read the artifact bucketAdd the inline policy, and check the bucket name has no typo
The overall deployment failed because too many individual instances failed deploymentGeneric wrapper messageOpen View events on the instance. The real error is in the failed event
InvalidRoleException / role cannot assumeThe deployment group's service role is wrongUse shortlink-codedeploy-service-role with AWSCodeDeployRole
Stuck at BlockTrafficThe target is drainingWait for the deregistration delay to pass

Deploy: the hook scripts#

Failed eventCauseFix
ApplicationStopA script from the previous revision ran and failedMake that behaviour harmless; the current appspec has no stop script
BeforeInstall: Unit shortlink-api.service not loadedThe service was never created by handCreate the systemd unit (guide 1, chapter 10)
BeforeInstall: test -s /etc/shortlink/shortlink.envThe env file is missing or emptyRecreate it (guide 1, chapter 10)
BeforeInstall: Permission denied / script not foundA hook is not executable, or appspec.yml is nestedgit ls-files -s deploy/hooks must show 100755, and appspec.yml must be at the ZIP root
AfterInstall fails in npm ciNo outbound path to npmNAT route, security group egress
AfterInstall fails in init-db.jsThe database is unreachable or the password is wrongSame checks as guide 1: current RDS endpoint, shortlink-db-sg rule
ValidateService failsNew version started but /health never says database: upsudo journalctl -u shortlink-api -n 80 --no-pager, then curl http://127.0.0.1:3000/health
AllowTraffic failsTarget group health check does not passCheck the health check path /health and the shortlink-api-sg rule from the load balancer

After the deploy#

SymptomCauseFix
503 for a minute, then fineIn-place deployment on one serverExpected. Add a second server for zero-downtime
Old code still servingThe service still runs from /opt/shortlink/reposystemctl cat shortlink-api must show WorkingDirectory=/opt/shortlink/app. If it does not, the ApplicationStart hook did not run; read its event
Environment changes ignoredThe API reads the file only at startsudo systemctl restart shortlink-api
Everything worked, then stoppedAn old deployment rolled back, or the instance was replacedCompare the deployed commit with main; re-run Release change

Found a mistake? Edit this page on GitHub.