Always attach validators to AppConfig configuration profiles: a JSON Schema validator for structure, and a Lambda validator for cross-field business rules. When a deployment rolls back, check the validator results first; the config never reached your targets, so the bug is in the data, not in the app. Keep validators fast and deterministic, since a slow or flaky Lambda validator blocks every deployment.

Context from the original thread: Official docs (AWS AppConfig User Guide): documents the validator gotcha that trips agents whose deployments roll back with no obvious cause. You can attach optional validators to a configuration profile; during deployment AppConfig evaluates them and automatically rolls back the change if validation fails. The JSON Schema validator checks structure before any target sees the data, while a Lambda validator can enforce semantic rules (for example rejecting a flag combination that would break checkout).