bitbucket pipeline for CodeArtifact

Viewed 621

I am using the bitbucket pipeline to publish the artifacts to AWS code artifact, everything is running perfectly but 12 hours validity of the token needs me to update the password every time. Could anyone guide me on how I can automate this process?

EDIT: finally was able to solve it myself.

pipelines:
  default:
    - step:
        name: test
        image: atlassian/pipelines-awscli
        script:
           - export AWS_ACCESS_KEY_ID=$AWS_ACCESS_KEY_ID
           - export AWS_SECRET_ACCESS_KEY=$AWS_SECRET_ACCESS_KEY
           - export AWS_DEFAULT_REGION=$AWS_DEFAULT_REGION
           - aws codeartifact get-authorization-token --domain XXXXX --domain-owner XXXXXx --query authorizationToken --output text > pass.txt
           - value=$(<pass.txt)
           - echo $value
           - echo "export value=$value" set_env.sh

           - printenv > set_env.sh 

        artifacts:
           - set_env.sh
     
              
    - step:
        name: maven
        image: maven:3.8.1
        caches:
          - maven
        script: # Modify the commands below to build your repository.
         
          - source set_env.sh
          - echo $value
          - sed -i 's/passwd12/'"$value"'/g' ./settings.xml
          - cat settings.xml
          - mvn clean deploy -s settings.xml -P snapshot
      
1 Answers

I didn't realize BitBucket had global account-wide Workspace Variables. Some were already defined for our other repos. I added some to hold the values for AccessKeyId and SecretAccessKey for our npm registry at CodeArtifact.

Prior to npm install, I create a named AWS profile in the pipelines.yml file:

- aws configure --profile codeartifactuser set aws_access_key_id $AWS_ACCESS_KEY_ID_NPM
- aws configure --profile codeartifactuser set aws_secret_access_key $AWS_SECRET_ACCESS_KEY_NPM

Then use that to make the call to authenticate and get a new token:

aws codeartifact login --tool npm --repository <repository> --domain <domain> --namespace @<namespace> --profile codeartifactuser

Now our npm install, etc... works as expected.

I used a named profile in case other parts of the build script expect different credentials. Just seems cleaner.

Related