AWS cross account access for code commit in build AWS code job source

Viewed 572

I have two AWS accounts A, B.

All my code commit repositories are present in account A.

Now I want to create the AWS code Build job in account B for repositories in account A.

I am trying to figure out to get the list of AWS repositories in account B from account A while selecting the source for creating a code build job.

enter image description here

I am not sure how to get the list of repositories from account A to account B in the source Repository field.

I have followed the below tutorial only till the second topic. https://docs.aws.amazon.com/codecommit/latest/userguide/cross-account.html

Any help will be appreciated.

1 Answers

You can configure access to CodeCommit repositories for IAM users and groups in another AWS account. This is often referred to as cross-account access.

Mainly you be need to do the following:

  1. Will need to create a policy and role for the repository with the needed permissions.

  2. Create a policy and attach to your CodeBuild Role allowing the access on the Resource for the created Role

eg.

"Resource": "arn:aws:iam::REPO_ACCOUNT:role/MyCrossAccountRepositoryContributorRole"

This will enable the CodeBuild to access the needed CodeCommit repository.

This page explain this very well: Configure cross-account access to an AWS CodeCommit repository using roles.

Also, check this blog post that explain a little more detailed what you want: AWS CodePipeline with a Cross-Account CodeCommit Repository.

Related