Description
CodeBuild encryption_key selects the key for build output artifacts. Omitting it uses the default AWS managed key, so the absence of an explicit key does not establish that artifacts are plaintext.
Potential impact
Relying on the default key may not meet requirements to control the key policy or lifecycle directly.
Remediation
Check effective artifact encryption and select a customer managed key accessible to the service role when direct key management is required. For CodePipeline artifacts, also check the pipeline artifact store. The project key does not protect all logs and environment variables.
Examples
These excerpts compare an implicit default key with an explicit alias/aws/s3 key. The latter is still AWS managed. Build environment and pipeline settings are omitted.
Before
- name: My project
community.aws.codebuild_project:
name: my_project
description: My nice little project v2
service_role: arn:aws:iam::123456789012:role/service-role/code-build-service-role
source:
type: CODEPIPELINE
buildspec: ''
artifacts:
type: CODEPIPELINE
name: my_project
region: us-east-1
state: present
After
- name: My project
community.aws.codebuild_project:
name: my_project
description: My nice little project
service_role: arn:aws:iam::123456789012:role/service-role/code-build-service-role
source:
type: CODEPIPELINE
buildspec: ''
artifacts:
type: CODEPIPELINE
name: my_project
encryption_key: arn:aws:kms:us-east-1:123456789012:alias/aws/s3
region: us-east-1
state: present