How to create an AWS CodeBuild project without sharing source credentials

Viewed 623

Unless I am misunderstanding things there is an astounding security flaw in CodeBuild in that every credential added is available to any codebuild project on an account? I need to provide GitHub personal access tokens for multiple project without cross sharing sensitive info across projects. Is that not possible?

ImportSourceCredentials docs CreateProject docs

The only auth field on there is deprecated (OAUTH) and OAuth is of no use to me in my situation.

My current workaround is to pass the GitHub personal access token in the URL which seems to work for GH.

2 Answers

From docs: "The credentials are global to a given account in a given region - they are not defined per CodeBuild project. CodeBuild only allows storing a single credential of a given type"

Essentially CodeBuild w GH is pretty much limited to internal projects. I was able to resolve my issue by creating am internal module (so I hooked up GitHub OAuth from AWS CodeBuild panel) and used this (nodejs) module as the foundation of my build project. In my buildspec I run a yarn command with the repository I do actually wish to use (using inline personal access token) to add this to my project. I then import the module in my main entry filed that I defined in my first "internal" project.

I use AWS Secrets Manager to solve this exact issue. Here is a snippet:

- echo Getting GitHub token
- SSH_KEY_BASE64=$(aws secretsmanager get-secret-value --secret-id ${GITHUB_SSH_KEY} | jq --raw-output '.SecretString' | jq .key | xargs)
- echo $SSH_KEY_BASE64 > /tmp/ssh_key_base_64
- base64 -d /tmp/ssh_key_base_64 > ~/.ssh/id_rsa
- chmod 400 ~/.ssh/id_rsa
- eval $(ssh-agent)
- ssh-add ~/.ssh/id_rsa
- echo "  StrictHostKeyChecking no" >> ~/.ssh/config
- chmod 644 ~/.ssh/config

Related