Review the CodeBuild artifact encryption key

Choose artifact encryption settings that meet the CodeBuild project’s key-management requirements.

Description

CodeBuild encryption_key selects the key for build output artifacts. Omitting it uses the default AWS managed key, so the absence of an explicit key does not establish that artifacts are plaintext.

Potential impact

Relying on the default key may not meet requirements to control the key policy or lifecycle directly.

Remediation

Check effective artifact encryption and select a customer managed key accessible to the service role when direct key management is required. For CodePipeline artifacts, also check the pipeline artifact store. The project key does not protect all logs and environment variables.

Examples

These excerpts compare an implicit default key with an explicit alias/aws/s3 key. The latter is still AWS managed. Build environment and pipeline settings are omitted.

Before

yaml
- name: My project
  community.aws.codebuild_project:
    name: my_project
    description: My nice little project v2
    service_role: arn:aws:iam::123456789012:role/service-role/code-build-service-role
    source:
      type: CODEPIPELINE
      buildspec: ''
    artifacts:
      type: CODEPIPELINE
      name: my_project
    region: us-east-1
    state: present

After

yaml
- name: My project
  community.aws.codebuild_project:
    name: my_project
    description: My nice little project
    service_role: arn:aws:iam::123456789012:role/service-role/code-build-service-role
    source:
      type: CODEPIPELINE
      buildspec: ''
    artifacts:
      type: CODEPIPELINE
      name: my_project
    encryption_key: arn:aws:kms:us-east-1:123456789012:alias/aws/s3
    region: us-east-1
    state: present

References