CDK bootstrap
The generated deploy job runs AWS CDK. CDK manages your infrastructure through a bootstrap (a.k.a. toolkit) stack of type AWS CDK: Default Resources in the region it deploys into, plus per-deployment CloudFormation stacks. Before cdk deploy runs, the workflow confirms that bootstrap is present — if you have never deployed from this account and region through the generated pipeline, it is created for you on the first run.
The generated deploy job must never run a destructive or manual deploy. It never issues cdk destroy, never prompts, and never runs interactive cdk diff. The first cdk deploy in a region creates the bootstrap stack for you.
Common causes
Section titled “Common causes”- Bootstrap not created yet — first deploy in a brand-new account and region, and the bootstrap step is still in progress. The workflow polls briefly; give it a moment and re-run.
- Bootstrap creation denied — the OIDC deploy role is missing permission to create or update the default toolkit stack, or AWS Organization SCPs block it. This is the only case where you may need to create the bootstrap stack manually (an advanced path, not normal operation) — see “Manual bootstrap” below.
- Bootstrap drift — the toolkit stack’s bootstrap bucket, KMS, or ECR parameters were changed out from under the deploy, so
cdk deployno longer matches. Re-deploy the stack (or re-create bootstrap) to reconcile.
Identify which one you have from the deploy job log: the error names the specific step (Ensure CDK bootstrap, Deploy CDK stack) and usually includes the underlying CloudFormation reason. If it is a CloudFormation failure, continue to Stack rollback.
Manual bootstrap (advanced, only if needed)
Section titled “Manual bootstrap (advanced, only if needed)”Create the default CDK bootstrap toolkit stack in the target region with AWS CloudFormation, using the bootstrap template for the CDK version your deployment uses and any account-specific parameters (bootstrap bucket, SSM, ECR, KMS) you maintain:
- In the AWS Console: CloudFormation → Create stack → Upload a template file, and select the toolkit template for your CDK version.
- Fill in your parameters exactly as your environment defines them (bootstrap bucket, KMS keys, ECR) — do not guess values.
- Create the stack, then re-run the deploy workflow in ScaleBop.
You own the bootstrap. ScaleBop never creates a manual bootstrap on your behalf and never deletes it. If you are asked to, or if creation is blocked (for example, by an SCP), create it once for that account and region. The generated deploy job will still refuse to run a destructive cdk destroy even after a manual bootstrap exists.
Fix and retry
Section titled “Fix and retry”Once the bootstrap is present and reachable, re-run the deploy workflow from ScaleBop’s Pipeline page or from GitHub Actions. After the deploy step succeeds, the pipeline continues through health-check (after publish, for static sites).