Lesson 367 · AWS Learning Path

AWS 367: Lambda aliases with linear and canary deployment

· Published · 4 min read

Labelled process diagram for AWS 367: Versioned intent to Automated validation to Controlled AWS change to Observed result and retained evidence, with decision, proof and rejection evidence.

Why this lesson matters

Publishing Lambda code does not safely release it. A production design needs an immutable version, an alias that callers use, measured traffic shifting, validation hooks, version-specific telemetry, and a recovery plan for side effects. Lambda aliases with linear and canary deployment make those controls explicit.

Versions, aliases, and qualifiers

$LATEST is mutable working state. Publishing creates an immutable numbered version containing code and most configuration. An alias such as prod is a named pointer to a numbered version. A qualified ARN ends in a version or alias; an unqualified ARN does not select one.

An alias can route a percentage to one additional version. Both versions must use the same IAM execution role and dead-letter queue configuration, and neither can be $LATEST. Traffic allocation is probabilistic per invocation, so ten requests do not guarantee exactly one canary request. Low-volume services need synthetic traffic or a longer observation window.

ControlPurposeFailure to detect
Published versionImmutable release unitMutable code changes
AliasStable caller endpointCallers pinned to old version
Routing weightCanary sampleToo little traffic for evidence
CodeDeploy configurationTimed canary, linear, or all-at-once shiftUnsafe manual weight changes
HookPre/post-traffic functional validationA healthy runtime with wrong behavior
Alarm and rollbackStop on measured harmSilent errors, latency, throttles
Release identifier in logsAttribute outcome by versionAggregates hiding the canary

CodeDeploy traffic shifting

For Lambda, CodeDeploy changes an alias from the current version to the target version. Canary shifts an initial percentage, waits, then shifts the remainder. Linear shifts equal increments at fixed intervals. All-at-once changes immediately. Predefined configurations are convenient, but the chosen percentage and interval must fit traffic volume and time-to-detect.

The deployment AppSpec identifies the function, current alias version, target version, and optional BeforeAllowTraffic and AfterAllowTraffic validation functions. A hook must report success or failure to CodeDeploy and must be idempotent, time bounded, least privileged, and independently observable. A hook invocation succeeding technically is not proof that its assertion was useful.

Automatic rollback redirects the alias to the prior version after a configured alarm or deployment failure. It does not undo records written, messages published, emails sent, payments requested, or incompatible schema changes. Design idempotency keys, compensating action, backward-compatible schemas, and replay handling before deployment.

Metrics, alarms, and concurrency

Dimension alarms by the alias and executed version where possible. Track errors, duration percentiles, throttles, concurrency, iterator age for streams, asynchronous delivery failures, destinations or dead-letter outcomes, and business success. An account-wide average can hide a bad ten-percent canary.

Provisioned concurrency is attached to a version or alias. During weighted routing, allocate enough provisioned capacity for both versions and expected bursts; otherwise spillover may create cold starts and distort the comparison. Reserved concurrency limits the function as a whole and can cause the deployment or its validation function to throttle.

Synchronous callers see the selected version for that request. Asynchronous events can retry, so both versions and destinations must tolerate duplicates. Poll-based event source mappings have their own batching, retry, ordering, and partial-failure behavior. Confirm that the mapping invokes the intended alias or version and that old and new consumers can process the same record contract.

Read-only inspection

aws lambda list-versions-by-function --function-name FUNCTION --region ap-south-1
aws lambda get-alias --function-name FUNCTION --name prod --region ap-south-1
aws lambda get-provisioned-concurrency-config --function-name FUNCTION --qualifier prod --region ap-south-1
aws deploy get-deployment-group --application-name APP --deployment-group-name GROUP --region ap-south-1
aws deploy list-deployments --application-name APP --deployment-group-name GROUP --region ap-south-1

Interpret FunctionVersion, RoutingConfig.AdditionalVersionWeights, provisioned allocation/status, deployment configuration, alarms, auto-rollback events, hook functions, and service role. Redact account IDs, ARNs, environment values, tags, and business metrics.

Design exercise and failure game day

Design a release from version 41 to 42 through alias prod. Given 6,000 requests per hour and a 5 percent defect, estimate how many failures a 10 percent ten-minute canary should expose. State why the observed count can differ. Select error-rate and latency alarms with evaluation periods shorter than the canary interval but long enough for meaningful samples.

Test: wrong alias qualifier, no canary traffic, hook permission failure, hook false positive, new version timeout, provisioned-concurrency spillover, throttle, alarm with missing data, asynchronous duplicate, stream poison record, incompatible payload, and rollback after an irreversible write. For every case record version, alias weights, request ID, executed-version log field, alarm history, deployment event, customer effect, and recovery decision.

Cost, security, and cleanup

Price requests, duration by architecture and memory, provisioned concurrency, logs, tracing, CodeDeploy-connected resources, and data transfer. Canary overlap can temporarily increase provisioned capacity and telemetry volume. Separate deployment role, hook role, and function execution role. Encrypt secrets outside code and never log event secrets.

This lesson creates nothing. For a later approved lab, remove unused versions only after confirming no alias or event source uses them; delete test deployment resources, alarms, logs, and provisioned concurrency according to retention policy.

Acceptance

Submit a version-to-alias diagram, traffic math, AppSpec/hook contract, concurrency plan, version-scoped dashboard, alarm and missing-data policy, event-source compatibility matrix, twelve failure results, rollback limits, cost model, and cleanup proof. Pass requires immutable versions, qualified callers, enough observations, outcome-based alarms, safe side effects, and proof that rollback restored user health.

Official sources

Advertisement