Tags: aws/aws-codedeploy-agent
Tags
Strip leading backslashes from AppSpec paths on Windows (#425) On Windows the "\" separator in an AppSpec files.source or hooks.location was treated as a filesystem root, so PathBuf::join discarded the archive directory and resolved the path to the drive root. Strip every leading separator via paths::APPSPEC_PATH_SEPARATORS (['/', '\\'] on Windows, ['/'] on Unix) so such paths always resolve inside the deployment archive. Bump agent version to 2.0.1 Co-authored-by: Giorgos Miliaras <gmiliara@amazon.com>
Complete the v2 agent implementation Brings the Rust agent to functional equivalence with agent v1.8.x and adds the v2-only capabilities. - Deployment lifecycle: bundle download and unpacking from S3, GitHub, and local directories, with native Rust extractors when the host lacks tar/unzip; lifecycle event execution with per-hook audit logging and bounded hook timeout escalation - Concurrent deployments: dispatch up to worker capacity and re-poll immediately rather than waiting a full interval, with in-flight command de-duplication so a re-delivered command is not run twice - Credentials from IAM session, on-premises file, and IMDS providers, with in-place refresh on rotation - Local command port: a loopback-only management interface, disabled by default and token-protected - Windows service integration via the Service Control Manager, plus a native systemd unit on Linux - Packaging for Debian, RPM, and Windows MSI; a codedeploy-local symlink preserves the documented standalone invocation - Live configuration ships at conf/codedeployagent.yml and still parses the legacy `:key: value` symbol form; unknown and retired keys are ignored and logged rather than fatal - Opt-in hardening flags covering bundle intake, file modes, permission sinks, and the hook environment - Expanded security test coverage Deployment outcomes, AppSpec handling, hook semantics, polling cadence, on-disk layout, and configuration keys are unchanged from v1 unless noted in CHANGELOG.md. Every hardening flag defaults to the v1-compatible behavior, so an upgrade changes nothing until a flag is set.
PreviousNext