Deploy Lambda with a canary configuration and automatic rollback triggered by API Gateway 5XX alarms
A DevOps team uses AWS CodePipeline, AWS CodeBuild, and AWS CodeDeploy to deploy an application. The application is a REST API that uses AWS Lambda functions and Amazon API Gateway. Recent deployments have introduced errors that have affected many customers. The DevOps team needs a solution that reverts to the most recent stable version of the application when an error is detected. The solution must affect the fewest customers possible. Which solution will meet these requirements with the MOST operational efficiency?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The two decisive requirements are minimizing affected customers and operational efficiency, which means automated rollback. A canary configuration shifts only 10 percent of traffic for 10 minutes before proceeding, so a bad release touches far fewer customers than an all-at-once deployment, and automatic rollback on a CloudWatch alarm reacts without a human (B). Using LambdaAllAtOnce (A, C) maximizes blast radius, and manual rollback or a metric filter invoking Lambda (C, D) adds custom code and human latency.
Because the API and Lambda tiers must be rolled back to the last stable version as soon as errors appear, and customer impact must be minimized, the deployment should shift a small percentage of traffic first and roll back automatically on failure. Using the LambdaCanary10Percent10Minutes deployment configuration with automatic rollback enabled, and configuring the deployment group to roll back when CloudWatch alarms detecting HTTP 502 errors on API Gateway breach their threshold, achieves both goals with no manual intervention.
Choosing LambdaAllAtOnce (A and C)—it replaces all traffic at the same time, so if the release is faulty the error affects every customer immediately, violating the requirement to affect as few customers as possible. Relying on manual rollback or a metric filter that triggers a new Lambda (C and D)—CloudWatch metric filters cannot invoke Lambda directly, and manual rollback is neither automated nor operationally efficient.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The canary deployment configuration LambdaCanary10Percent10Minutes routes only 10 percent of traffic to the new version for a 10-minute evaluation window before shifting the remainder, which limits the number of customers exposed if the release is defective. Enabling automatic rollback on the deployment group and configuring it to roll back when the CloudWatch alarm watching for HTTP 502 errors on API Gateway reaches its threshold means the previous stable version is restored programmatically the moment errors appear, with no operator action and no custom code.Why the Other Options Are Wrong
A and C use LambdaAllAtOnce, which deploys the new version to all traffic simultaneously; a defective release then affects every customer at once, directly contradicting the requirement to affect as few customers as possible. C also depends on a new Lambda function invoked from SNS to stop and restart deployments, adding custom code and manual orchestration. D attempts to invoke Lambda from a CloudWatch metric filter, which metric filters cannot do, and combines it with manual rollback. B is the only option satisfying both the canary blast-radius limit and automated rollback.Community Comment Notes
Community voted B (94). Commenters identified that LambdaAllAtOnce removes the rollback safety net and exposes all customers, and that metric filters cannot trigger Lambda, making D unworkable. One commenter argued for C on blast-radius grounds, but the canary plus automatic rollback combination in B best satisfies both stated requirements with the least manual effort.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →