如何实现CodeDeploy失败时终止Bitbucket流水线?
Absolutely! You can absolutely implement this by polling the AWS CodeDeploy API in a loop within your Bitbucket Pipeline. Here's a step-by-step breakdown of how to do it, including the specific API you'll need and example configurations for your files.
Polling the AWS CodeDeploy API is a reliable way to wait for your deployment to fully complete (including the ValidateService step) and fail the pipeline if the deployment doesn't succeed. The key API you'll use is get-deployment — this returns detailed status information for a specific CodeDeploy deployment.
First, when you trigger your CodeDeploy deployment from the pipeline, make sure to capture the deploymentId returned by the create-deployment command. You'll need this ID to poll the status later.
Example snippet for your deployment step in bitbucket-pipeline.yml:
- step: name: Deploy to CodeDeploy script: # Assume AWS credentials are configured via secured pipeline variables - DEPLOYMENT_ID=$(aws deploy create-deployment --application-name YOUR_APP_NAME --deployment-group-name YOUR_DEPLOYMENT_GROUP --github-location repository=YOUR_REPO,commitId=$BITBUCKET_COMMIT --output text --query deploymentId) - echo "Initiated deployment with ID: $DEPLOYMENT_ID" # Save the ID to a file to pass to the next step (Bitbucket allows sharing via artifacts) - echo $DEPLOYMENT_ID > deployment_id.txt artifacts: - deployment_id.txt
Next, add a new step that reads the deployment ID, then repeatedly calls aws deploy get-deployment to check the status until it reaches a terminal state (SUCCEEDED, FAILED, or STOPPED). If it fails, we'll exit with a non-zero code to terminate the pipeline.
This step uses jq (a JSON parsing tool) to extract the status from the API response — install it if your pipeline image doesn't include it by default.
Example polling step:
- step: name: Monitor CodeDeploy Deployment script: # Install jq (adjust command if using a non-Ubuntu image, e.g., yum install jq for Amazon Linux) - apt-get update && apt-get install -y jq # Retrieve the deployment ID from the artifact - DEPLOYMENT_ID=$(cat deployment_id.txt) # Configure polling parameters (adjust based on your deployment's typical duration) - POLL_INTERVAL=30 - MAX_ATTEMPTS=20 - ATTEMPT=0 echo "Starting monitoring for deployment $DEPLOYMENT_ID..." while [ $ATTEMPT -lt $MAX_ATTEMPTS ]; do # Fetch deployment status DEPLOYMENT_STATUS=$(aws deploy get-deployment --deployment-id $DEPLOYMENT_ID --output json | jq -r '.deploymentInfo.status') echo "Attempt $((ATTEMPT+1)): Current status → $DEPLOYMENT_STATUS" case $DEPLOYMENT_STATUS in "SUCCEEDED") echo "Deployment completed successfully!" exit 0 ;; "FAILED" | "STOPPED") echo "Deployment failed with status: $DEPLOYMENT_STATUS" # Optional: Fetch failure details for debugging aws deploy get-deployment --deployment-id $DEPLOYMENT_ID --output json | jq '.deploymentInfo.errorInformation' exit 1 ;; *) echo "Deployment still in progress. Waiting $POLL_INTERVAL seconds..." sleep $POLL_INTERVAL ATTEMPT=$((ATTEMPT+1)) ;; esac done # Fail pipeline if deployment times out echo "Deployment timed out after $MAX_ATTEMPTS attempts." exit 1
get-deployment API - The API returns a JSON object where
deploymentInfo.statuscan be:PENDING: Deployment is queued to startIN_PROGRESS: Deployment is running (including yourValidateServicehook)SUCCEEDED: All steps (including validation) completed successfullyFAILED: One or more deployment steps failedSTOPPED: Deployment was manually halted
- Ensure your AWS IAM user (used by the Bitbucket Pipeline) has the
codedeploy:GetDeploymentpermission added to its policy.
ValidateService Wait Issue Since you mentioned Bitbucket wasn't waiting for the ValidateService step to finish, this polling approach solves that problem — it waits for the entire deployment lifecycle to conclude. The SUCCEEDED status is only returned after all hooks defined in your appspec.yml (including ValidateService) have passed.
- Tune
POLL_INTERVALandMAX_ATTEMPTSto match your deployment's average runtime to avoid unnecessary waits or infinite loops. - Store AWS credentials as secured variables in Bitbucket to prevent exposure in logs.
- If using a custom pipeline image, pre-install
jqto speed up the step.
内容的提问来源于stack exchange,提问作者KarmicJohn

