Releases: aws/aws-codedeploy-agent
Release list
v2.1.0
Release Notes:
- New feature:
2.1.0adds support for theRESTARTdeployment mode, which restarts the application on the target instances using the revision from the deployment group's last successful deployment, without downloading a new revision. The agent installs from the copy of the revision already on the instance. If that copy is missing or incomplete, the agent downloads the revision, so the deployment still completes. For the deployment mode itself, see deploymentMode in the AWS CodeDeploy API Reference. - Security improvement: The agent now rejects a deployment whose AppSpec file path resolves outside the application revision directory. Paths nested inside the revision, such as
configs/appspec.yml, are still supported.
What's Changed (Commit log)
- Remove stale annotations and a dangling comment fragment by @gmiliaras in #426
- 2.1.x Agent Release by @filipdanic in #427
Full Changelog: v2.0.1...v2.1.0
v2.0.1
Release notes:
Fixed: Windows AppSpec paths with leading separators failed deployments. A files.source or hooks.location beginning with \ (including the bare \ "entire revision" form) or / was resolved against the drive root instead of the deployment archive, failing Install events with access-denied errors. Leading separators are now stripped so these paths always resolve inside the deployment archive.
v2.0.0
Overview
Version 2.0.0 replaces the Ruby runtime with a single native binary in Rust while preserving v1.8.x deployment behavior by default.
Highlights
- Removes the Ruby runtime dependency entirely. One binary, no interpreter needed.
- Expanded platform support, including Windows Server 2025, RHEL 10, Ubuntu 26.04, CentOS Stream 10.
- Native systemd service management on Linux (no more SysV init.d compatibility layer).
- Native Windows Service Control Manager integration (no more
win32-daemongem). - Built-in throttle handling with coordinated backoff across worker threads.
deploy-localis now a subcommand of the agent binary, with added support for GitHub sources (including private repos) and S3.- Optional loopback-only command port for local diagnostics without restarting the agent.
- A set of opt-in security hardening flags for bundle validation, hook environments, and filesystem permissions.
Supported platforms
The agent has been tested on the following operating systems:
| OS | Versions | Architectures |
|---|---|---|
| Amazon Linux 2023 | latest | x86_64, aarch64 |
| Amazon Linux 2 | latest | x86_64, aarch64 |
| RHEL | 8, 9, 10 | x86_64, aarch64 |
| Oracle Linux | 8, 9, 10 | x86_64, aarch64 |
| Rocky Linux | 9, 10 | x86_64, aarch64 |
| CentOS Stream | 9, 10 | x86_64, aarch64 |
| SLES | 15 | x86_64, aarch64 |
| Debian | 11, 12, 13 | x86_64, aarch64 |
| Ubuntu Server | 16.04, 18.04, 20.04, 22.04, 24.04, 25.04, 26.04 | x86_64, aarch64 |
| Windows Server | 2016, 2019, 2022, 2025 | x86_64 |
New in 2.0.0: Windows Server 2025, RHEL 10, Oracle Linux 8/9/10, Rocky Linux 9/10, CentOS Stream 9/10, SLES 15, Debian 11/12/13, and Ubuntu 24.04/25.04/26.04.
Upgrade notes
Existing deployments continue to work without configuration changes. Review the following before upgrading:
- Local deployment IDs changed. Local deploys now use the format
local-<pid>instead ofd-XXXXXXXXX-local. Scripts that key on this folder name need updating. - Core dumps disabled by default. The agent suppresses core dumps because it holds credentials in memory. Set
disable_core_dumps: falseif you need them for crash investigation. - Retired configuration keys are ignored. Keys like
children,shared_dir,user,instance_service_*, andcodedeploy_test_profileno longer have any effect. Each is logged once on startup. - Credential refresh. Rotated credentials are picked up in place without restarting the agent or failing long-running deployments.
Security improvements
The new agent introduces opt-in hardening controls. All default to v1-compatible behavior unless you enable them:
reject_symlinks_in_bundle— reject bundles containing symlinks or hardlinks.reject_path_traversal_in_bundle— reject path-traversal attempts in archive entries and AppSpec fields.reject_unsafe_permissions_in_bundle— reject SUID/SGID files and modes.reject_unconfined_selinux_in_bundle— reject SELinux types that disable MAC.reject_symlink_permission_targets— reject symlinked destinations in AppSpecpermissions:blocks.ignore_ownership_in_bundle— ignore uid/gid from tar headers; own extracted files as the agent process.restrict_agent_dir_permissions— tighten agent directory and state file permissions.restrict_log_dir_permissions— tighten log directory permissions.restrict_hook_env_to_allowlist— limit hook environment to documented deployment variables only.strip_loader_env_in_hooks— stripLD_PRELOAD/LD_LIBRARY_PATH/LD_AUDITfrom hook environments.disable_powershell_profile_in_hooks— run PowerShell hooks with-NoProfile -NonInteractive.archive_max_extraction_size— cap uncompressed bundle size.
Always-on improvements (no flag needed):
- Hook timeout enforcement uses SIGTERM then SIGKILL, preventing indefinite hangs.
scripts.logis size-rotated (64 MiB x 8 files).- ANSI escape sequences are stripped from logs shipped to CodeDeploy.
Compatibility
The following remain unchanged from v1.8.x:
- AppSpec semantics (versions, file handling, permissions, ACLs, SELinux contexts)
- Deployment lifecycle event ordering
- Hook execution and rollback mapping
- Deployment archive structure and ETag verification
- PKCS7 signature verification
- On-disk layout and tracking files
- Existing configuration file syntax (including symbol-style
:key: valueformat) - Error codes
Full changelog
For the complete technical list of changes, see CHANGELOG.md.
v1.8.1
1.8.0
Changed: Upgraded the bundled Ruby to 3.2 in the CodeDeploy agent for Windows.
1.7.1
changed: Updated dependencies for security patches.
1.7.0
Release Notes:
Added: A :disable_imds_v1: configuration setting to the CodeDeploy agent configuration file. Use this setting to disable the fallback to IMDSv1 when IMDSv2 errors occur. Defaults to false (enable the fallback).
Added: Support for the Red Hat Enterprise Linux 9 (RHEL 9) operating system.
Added: Support for Ruby versions 3.1 and 3.2 on Ubuntu.
Fixed: The CodeDeploy agent now generates a user-friendly error if the CodeDeploy agent configuration file fails to load.
Changed: Upgraded Ruby to 2.7.8-1 in the CodeDeploy agent for Windows.
1.6.0
Release Notes:
Added: Support for Ruby 3.1, 3.2.
Added: Support for Amazon Linux 2023.
Added: Support for Windows Server 2022.
Changed: The default setting of verbose is now false for Windows Server instances. To continue to print debug messages in log files on Windows, you must set verbose to true.
Removed: Support for Windows Server 2016 and Windows Server 2012 R2.
Removed: Support for Amazon Linux 2018.03.x.
S3 Keys and ETags
MSI
latest/codedeploy-agent.msi
releases/codedeploy-agent-1.6.0.49.msi
ETag: "0464a4779af65e2ac6fd0351b6151a9c"
DEB
latest/codedeploy-agent_all.deb
releases/codedeploy-agent_1.6.0-49_all.deb
ETag: "456d67c61d906b21e851b5f8b3a0c729"
RPM
latest/codedeploy-agent.noarch.rpm
releases/codedeploy-agent-1.6.0-49.noarch.rpm
ETag: "04f0d0c3afdacd457593f343d76bdcb8"
Special thanks to: @aj-aws @mwjones-aws @t0shiii @puneethnr @philstrong @amznchrs
1.5.0
Release Notes:
Added: Support for Ruby 3.
Added: Support for Ubuntu 22.04.
Fixed: An issue where restarting the CodeDeploy agent soon after startup would lead to the agent hanging.
Changed: The CodeDeploy agent now fails a host deployment on agent startup if the agent service restarts unexpectedly while running a hook script. This fix lets you avoid waiting the 70 minute timeout period before retrying a deployment.
Deprecation notice: CodeDeploy agent 1.5.0 is the last release to support Windows Server 2016, and Windows Server 2012 R2.
Removed: Support for the CodeDeploy agent on Ubuntu 14.04 LTS, Windows Server 2008 R2, Windows Server 2008 R2 32-bit.
S3 keys and ETags
MSI
latest/codedeploy-agent.msi
releases/codedeploy-agent-1.5.0.57.msi
ETag: "46e324841ab9a6fae5f4af1c956473fd"
DEB
latest/codedeploy-agent_all.deb
releases/codedeploy-agent_1.5.0-57_all.deb
ETag: "a5a0a7a6568b357fdad1f2806ba12308"
RPM
latest/codedeploy-agent.noarch.rpm
releases/codedeploy-agent-1.5.0-57.noarch.rpm
ETag: "edc76825fe23aa51c692b6e74f635f6a"
Special thanks to: @aj-aws @mwjones-aws @t0shiii @puneethnr @philstrong @amznchrs
1.4.0
Added: Support for Red Hat Enterprise Linux 8.
Fixed: An issue with the unzip operation when the disk was full. The CodeDeploy agent now detects the unzip's exit code 50 indicating a full disk, removes partially extracted files, and raises an exception to post a failure to the CodeDeploy server. The error message is visible as a lifecycle event error message, and the host-level deployment will stop without being stuck or timing-out.
Fixed: An issue that would cause the agent to fail.
Fixed: An issue where hooks would time out during an edge-case race condition. Hooks with no scripts will now continue and no longer cause failures or timeouts.
Changed: The update script from the CodeDeploy agent's bin directory was removed because it is no longer used.
Changed: The CodeDeploy agent for Windows Server now bundles Ruby 2.7.
Changed: New environment variables were added, to be used by hook scripts depending on the source of the deployment bundle (Amazon S3 or GitHub).
For further details and deprecation notices see release notes
Special thanks to: @keithcyu @mwjones-aws @t0shiii @dljvette @kaiwensun @puneethnr @jcbhl @amznchrs