Skip to content

Releases: aws/aws-codedeploy-agent

v2.1.0

Choose a tag to compare

@gmiliaras gmiliaras released this 09 Sep 15:01
0764f30

Release Notes:

  • New feature: 2.1.0 adds support for the RESTART deployment mode, which restarts the application on the target instances using the revision from the deployment group's last successful deployment, without downloading a new revision. The agent installs from the copy of the revision already on the instance. If that copy is missing or incomplete, the agent downloads the revision, so the deployment still completes. For the deployment mode itself, see deploymentMode in the AWS CodeDeploy API Reference.
  • Security improvement: The agent now rejects a deployment whose AppSpec file path resolves outside the application revision directory. Paths nested inside the revision, such as configs/appspec.yml, are still supported.

What's Changed (Commit log)

Full Changelog: v2.0.1...v2.1.0

v2.0.1

Choose a tag to compare

@gmiliaras gmiliaras released this 09 Sep 08:43
090fbc9

Release notes:

Fixed: Windows AppSpec paths with leading separators failed deployments. A files.source or hooks.location beginning with \ (including the bare \ "entire revision" form) or / was resolved against the drive root instead of the deployment archive, failing Install events with access-denied errors. Leading separators are now stripped so these paths always resolve inside the deployment archive.

v2.0.0

Choose a tag to compare

@gmiliaras gmiliaras released this 29 Jul 16:10
5a96830

Overview

Version 2.0.0 replaces the Ruby runtime with a single native binary in Rust while preserving v1.8.x deployment behavior by default.

Highlights

  • Removes the Ruby runtime dependency entirely. One binary, no interpreter needed.
  • Expanded platform support, including Windows Server 2025, RHEL 10, Ubuntu 26.04, CentOS Stream 10.
  • Native systemd service management on Linux (no more SysV init.d compatibility layer).
  • Native Windows Service Control Manager integration (no more win32-daemon gem).
  • Built-in throttle handling with coordinated backoff across worker threads.
  • deploy-local is now a subcommand of the agent binary, with added support for GitHub sources (including private repos) and S3.
  • Optional loopback-only command port for local diagnostics without restarting the agent.
  • A set of opt-in security hardening flags for bundle validation, hook environments, and filesystem permissions.

Supported platforms

The agent has been tested on the following operating systems:

OS Versions Architectures
Amazon Linux 2023 latest x86_64, aarch64
Amazon Linux 2 latest x86_64, aarch64
RHEL 8, 9, 10 x86_64, aarch64
Oracle Linux 8, 9, 10 x86_64, aarch64
Rocky Linux 9, 10 x86_64, aarch64
CentOS Stream 9, 10 x86_64, aarch64
SLES 15 x86_64, aarch64
Debian 11, 12, 13 x86_64, aarch64
Ubuntu Server 16.04, 18.04, 20.04, 22.04, 24.04, 25.04, 26.04 x86_64, aarch64
Windows Server 2016, 2019, 2022, 2025 x86_64

New in 2.0.0: Windows Server 2025, RHEL 10, Oracle Linux 8/9/10, Rocky Linux 9/10, CentOS Stream 9/10, SLES 15, Debian 11/12/13, and Ubuntu 24.04/25.04/26.04.

Upgrade notes

Existing deployments continue to work without configuration changes. Review the following before upgrading:

  • Local deployment IDs changed. Local deploys now use the format local-<pid> instead of d-XXXXXXXXX-local. Scripts that key on this folder name need updating.
  • Core dumps disabled by default. The agent suppresses core dumps because it holds credentials in memory. Set disable_core_dumps: false if you need them for crash investigation.
  • Retired configuration keys are ignored. Keys like children, shared_dir, user, instance_service_*, and codedeploy_test_profile no longer have any effect. Each is logged once on startup.
  • Credential refresh. Rotated credentials are picked up in place without restarting the agent or failing long-running deployments.

Security improvements

The new agent introduces opt-in hardening controls. All default to v1-compatible behavior unless you enable them:

  • reject_symlinks_in_bundle — reject bundles containing symlinks or hardlinks.
  • reject_path_traversal_in_bundle — reject path-traversal attempts in archive entries and AppSpec fields.
  • reject_unsafe_permissions_in_bundle — reject SUID/SGID files and modes.
  • reject_unconfined_selinux_in_bundle — reject SELinux types that disable MAC.
  • reject_symlink_permission_targets — reject symlinked destinations in AppSpec permissions: blocks.
  • ignore_ownership_in_bundle — ignore uid/gid from tar headers; own extracted files as the agent process.
  • restrict_agent_dir_permissions — tighten agent directory and state file permissions.
  • restrict_log_dir_permissions — tighten log directory permissions.
  • restrict_hook_env_to_allowlist — limit hook environment to documented deployment variables only.
  • strip_loader_env_in_hooks — strip LD_PRELOAD/LD_LIBRARY_PATH/LD_AUDIT from hook environments.
  • disable_powershell_profile_in_hooks — run PowerShell hooks with -NoProfile -NonInteractive.
  • archive_max_extraction_size — cap uncompressed bundle size.

Always-on improvements (no flag needed):

  • Hook timeout enforcement uses SIGTERM then SIGKILL, preventing indefinite hangs.
  • scripts.log is size-rotated (64 MiB x 8 files).
  • ANSI escape sequences are stripped from logs shipped to CodeDeploy.

Compatibility

The following remain unchanged from v1.8.x:

  • AppSpec semantics (versions, file handling, permissions, ACLs, SELinux contexts)
  • Deployment lifecycle event ordering
  • Hook execution and rollback mapping
  • Deployment archive structure and ETag verification
  • PKCS7 signature verification
  • On-disk layout and tracking files
  • Existing configuration file syntax (including symbol-style :key: value format)
  • Error codes

Full changelog

For the complete technical list of changes, see CHANGELOG.md.

v1.8.1

Choose a tag to compare

@splokhikh splokhikh released this 20 Feb 15:25
800eb28
  • S3 endpoint bugfix
  • Added Sectigo CA certificate to Windows CA list

1.8.0

Choose a tag to compare

@NsTremblay NsTremblay released this 07 Aug 23:45
d48f3bd

Changed: Upgraded the bundled Ruby to 3.2 in the CodeDeploy agent for Windows.

1.7.1

Choose a tag to compare

@NsTremblay NsTremblay released this 02 Nov 00:22

changed: Updated dependencies for security patches.

1.7.0

Choose a tag to compare

@danwangkm danwangkm released this 17 Jan 23:05

Release Notes:

Added: A :disable_imds_v1: configuration setting to the CodeDeploy agent configuration file. Use this setting to disable the fallback to IMDSv1 when IMDSv2 errors occur. Defaults to false (enable the fallback).

Added: Support for the Red Hat Enterprise Linux 9 (RHEL 9) operating system.

Added: Support for Ruby versions 3.1 and 3.2 on Ubuntu.

Fixed: The CodeDeploy agent now generates a user-friendly error if the CodeDeploy agent configuration file fails to load.

Changed: Upgraded Ruby to 2.7.8-1 in the CodeDeploy agent for Windows.

1.6.0

Choose a tag to compare

@t0shiii t0shiii released this 22 May 23:46
3ba4279

Release Notes:

Added: Support for Ruby 3.1, 3.2.

Added: Support for Amazon Linux 2023.

Added: Support for Windows Server 2022.

Changed: The default setting of verbose is now false for Windows Server instances. To continue to print debug messages in log files on Windows, you must set verbose to true.

Removed: Support for Windows Server 2016 and Windows Server 2012 R2.

Removed: Support for Amazon Linux 2018.03.x.

S3 Keys and ETags

MSI

   latest/codedeploy-agent.msi
   releases/codedeploy-agent-1.6.0.49.msi
   ETag: "0464a4779af65e2ac6fd0351b6151a9c"

DEB

    latest/codedeploy-agent_all.deb
    releases/codedeploy-agent_1.6.0-49_all.deb
    ETag: "456d67c61d906b21e851b5f8b3a0c729"

RPM

    latest/codedeploy-agent.noarch.rpm
    releases/codedeploy-agent-1.6.0-49.noarch.rpm
    ETag: "04f0d0c3afdacd457593f343d76bdcb8"

Special thanks to: @aj-aws @mwjones-aws @t0shiii @puneethnr @philstrong @amznchrs

1.5.0

Choose a tag to compare

@t0shiii t0shiii released this 03 Apr 19:12
e227cbf

Release Notes:

Added: Support for Ruby 3.

Added: Support for Ubuntu 22.04.

Fixed: An issue where restarting the CodeDeploy agent soon after startup would lead to the agent hanging.

Changed: The CodeDeploy agent now fails a host deployment on agent startup if the agent service restarts unexpectedly while running a hook script. This fix lets you avoid waiting the 70 minute timeout period before retrying a deployment.

Deprecation notice: CodeDeploy agent 1.5.0 is the last release to support Windows Server 2016, and Windows Server 2012 R2.

Removed: Support for the CodeDeploy agent on Ubuntu 14.04 LTS, Windows Server 2008 R2, Windows Server 2008 R2 32-bit.

S3 keys and ETags

MSI

latest/codedeploy-agent.msi
releases/codedeploy-agent-1.5.0.57.msi
ETag: "46e324841ab9a6fae5f4af1c956473fd"

DEB

latest/codedeploy-agent_all.deb
releases/codedeploy-agent_1.5.0-57_all.deb
ETag: "a5a0a7a6568b357fdad1f2806ba12308"

RPM

latest/codedeploy-agent.noarch.rpm
releases/codedeploy-agent-1.5.0-57.noarch.rpm
ETag: "edc76825fe23aa51c692b6e74f635f6a"

Special thanks to: @aj-aws @mwjones-aws @t0shiii @puneethnr @philstrong @amznchrs

1.4.0

Choose a tag to compare

@mwjones-aws mwjones-aws released this 16 Sep 17:47
1a53e8f

Added: Support for Red Hat Enterprise Linux 8.

Fixed: An issue with the unzip operation when the disk was full. The CodeDeploy agent now detects the unzip's exit code 50 indicating a full disk, removes partially extracted files, and raises an exception to post a failure to the CodeDeploy server. The error message is visible as a lifecycle event error message, and the host-level deployment will stop without being stuck or timing-out.

Fixed: An issue that would cause the agent to fail.

Fixed: An issue where hooks would time out during an edge-case race condition. Hooks with no scripts will now continue and no longer cause failures or timeouts.

Changed: The update script from the CodeDeploy agent's bin directory was removed because it is no longer used.

Changed: The CodeDeploy agent for Windows Server now bundles Ruby 2.7.

Changed: New environment variables were added, to be used by hook scripts depending on the source of the deployment bundle (Amazon S3 or GitHub).

For further details and deprecation notices see release notes

Special thanks to: @keithcyu @mwjones-aws @t0shiii @dljvette @kaiwensun @puneethnr @jcbhl @amznchrs