Skip to main content
ECS tried to start tasks from your new version, watched them fail, and triggered its deployment circuit breaker. It then tried to restore the previous version, and that failed too. Unlike ecs.circuit_breaker, the previous version was not left in place, so the service may be running neither version. The cause could not be attributed automatically.

Why this happens

The rollback starts tasks from the previous version, so it fails for the same reasons a deployment does, against the state the new version left behind. Common causes:
  • The new version’s migration changed the database schema, and the previous version cannot boot against it. Its schema gate refuses, or its code fails at startup.
  • The capacity the previous version needs is gone. A capacity provider is out of instances, or a quota is exhausted.
  • A secret, parameter or image the previous version reads was removed or replaced.
The deployment failure sits in the ecs_stabilise phase. The provider reason from ECS carries its own explanation of the failed rollback.

How to fix it

  1. Check what the service is running now. The service’s deployments tab in the ECS console shows the revision ECS ended on and how many of its tasks are running.
  2. Read the ECS service events and the stopped tasks of both versions. The previous version’s stopped tasks say why the rollback failed.
  3. If a migration moved the schema ahead of the previous version, roll forward rather than back: fix the new version and deploy it, since the database already holds its schema.
  4. If capacity or a missing secret blocked the rollback, restore it, then deploy again.
If CloudFormation is still updating the stack, the deploy cancels the update five minutes after ECS’s verdict, and CloudFormation then tries its own rollback. When that fails as well, the stack reaches UPDATE_ROLLBACK_FAILED. The deploy prints the steps to continue that rollback.

What Fjall shows you

The deployment’s detail page on fjall.io shows the failure title, this code, the per-deployment detail, the ECS reason verbatim under “ECS said”, the remediation steps, and a link back to this page. Non-interactive CLI runs print the same fields in an Error Detail block.

Next Steps

Deployment safety

How the circuit breaker and the ECS event tail protect your rollouts.

ecs.circuit_breaker

The same failure when the rollback succeeds.

fjall releases & rollback

The recorded releases, and rolling the services back to one of them.

Deploy an application

The full deployment flow, phase by phase.