Skip to content

Create the pipeline

Source and Build from the wizard, then add the deploy stage with its own CodeBuild project.

About 30 min · Verified 8 October 2026

0 of 7 steps done0%

You build this pipeline in two passes. The wizard creates Source and Build. Then you edit the pipeline to add a DeployWeb stage, because the wizard's Deploy step cannot run aws s3 sync --delete with your cache headers, but a CodeBuild project can.

Pass 1: the wizard#

Pipeline settings#

Open CodePipelinePipelinesCreate pipeline, choose Build custom pipeline, Next.

FieldValue
Pipeline nameshortlink-web-prod
Pipeline typeV2
Execution modeQueued
Service roleNew service role

Leave the artifact store on Default location. It is a private codepipeline-<region>-… bucket, not your website bucket. Choose Next.

Source#

FieldValue
Source providerGitHub (via GitHub App)
Connectionshortlink-github
Repository name<GITHUB_USER>/shortlink (your fork)
Default branchmain
Output artifact formatCodePipeline default

Under Trigger keep Start the pipeline on source code change and add:

FieldValue
Event typePush
Branches → Includemain
File paths → Includeshortlink-web/**, deploy/buildspec-web.yml, deploy/buildspec-web-deploy.yml

Only commits that change the website or its buildspecs publish a new site. Choose Next.

FieldValue
Build providerOther build providers → AWS CodeBuild
Regionap-south-1
Project nameCreate project

In the CodeBuild form:

FieldValue
Project nameshortlink-web-build
Project typeDefault project
Environment imageManaged image
ComputeEC2
Operating system / RuntimeAmazon Linux / Standard
Imageaws/codebuild/amazonlinux-x86_64-standard:5.0 (or the newest standard image)
Compute size3 GB memory, 2 vCPUs or larger (the reference setup used medium)
Service roleNew service role
BuildspecUse a buildspec file → deploy/buildspec-web.yml
LogsCloudWatch logs ticked

Open Additional configuration and add the environment variable that tells the site where the API is:

NameValueType
VITE_API_BASE_URL<API_URL>Plaintext

Choose Continue to CodePipeline. Check Input artifacts is SourceArtifact, Build type is Single build, and leave the output artifact as BuildArtifact. Choose Next.

Test and Deploy: skip both#

Choose Skip test stage, then Skip deploy stage (confirm each). Choose Create pipeline.

The pipeline runs Source → Build once. When Build is green, you have a working build. Nothing is published yet.

Pass 2: add the deploy stage#

Edit the pipeline and add a stage#

Open the pipeline and choose Edit. Under the Build stage choose + Add stage, name it DeployWeb, and Add stage. In the new stage choose + Add action group.

Configure the WebDeploy action#

FieldValue
Action nameWebDeploy
Action providerAWS CodeBuild (listed under Build)
Regionap-south-1
Input artifactsBuildArtifact
Project nameCreate project

In the CodeBuild form:

FieldValue
Project nameshortlink-web-deploy
Project typeDefault project
Environmentsame as the build project: managed image, EC2, Amazon Linux, Standard, 5.0
Compute sizethe smallest is fine
Service roleNew service role
BuildspecUse a buildspec file → deploy/buildspec-web-deploy.yml
Environment variablesnone

Choose Continue to CodePipeline, set Build type to Single build, leave Output artifacts empty, and choose Done. Then Done on the stage, and Save the pipeline (confirm).

Verify the structure#

Your computerShow stages and actions
aws codepipeline get-pipeline --region ap-south-1 --name shortlink-web-prod \
  --query 'pipeline.stages[].{stage:name,actions:actions[].{action:name,provider:actionTypeId.provider,project:configuration.ProjectName,in:inputArtifacts[].name,out:outputArtifacts[].name}}' \
  --output json
You should see
Three stages in order: Source → Build (shortlink-web-build, in SourceArtifact, out BuildArtifact) → DeployWeb (WebDeploy, shortlink-web-deploy, in BuildArtifact, no output).

Confirm both CodeBuild projects run in pipeline mode:

Your computerBoth projects must use the CODEPIPELINE types
aws codebuild batch-get-projects --region ap-south-1 --names shortlink-web-build shortlink-web-deploy \
  --query 'projects[].{name:name,source:source.type,artifacts:artifacts.type,buildspec:source.buildspec,webhook:webhook.url}' --output table

source and artifacts must both be CODEPIPELINE and webhook must be empty. Projects created from inside the pipeline editor are right already.

My CodeBuild projects show GitHub as the source, or a webhook is set

That happens when a project was created in the CodeBuild console on its own, before being added to the pipeline. A direct webhook would also start builds that bypass the pipeline. Remove it and switch the types:

Your computerFix a project created outside the pipeline
aws codebuild delete-webhook --region ap-south-1 --project-name shortlink-web-deploy
aws codebuild update-project --region ap-south-1 --name shortlink-web-build \
  --source 'type=CODEPIPELINE,buildspec=deploy/buildspec-web.yml' --artifacts 'type=CODEPIPELINE'
aws codebuild update-project --region ap-south-1 --name shortlink-web-deploy \
  --source 'type=CODEPIPELINE,buildspec=deploy/buildspec-web-deploy.yml' --artifacts 'type=CODEPIPELINE'

Skip delete-webhook if the project has no webhook. Note that the deploy project needs artifacts of type CODEPIPELINE too, even though it produces no output: CodeBuild checks source and artifact types together and rejects NO_ARTIFACTS when the source is CODEPIPELINE.

Next: give the deploy project permission to write to S3.

Found a mistake? Edit this page on GitHub.