CodeBuild artifact encryption key needs review

Check whether the encryption key for CodeBuild output artifacts meets your key-management requirements.

Description

CodeBuild uses EncryptionKey to select a KMS key for output artifacts. If it is omitted, CodeBuild uses the AWS managed KMS key for Amazon S3. Omission alone does not mean artifacts are stored in plaintext.

Where a customer managed key is required, select one whose policy and lifecycle you control. This setting does not configure encryption for all caches and logs.

Potential impact

  • The default key may not meet requirements for customer managed keys or separation of permissions.
  • An unavailable key or insufficient permissions can prevent artifacts from being stored or read.

Remediation

  • When a customer managed key is required, set EncryptionKey to an approved key ARN or alias.
  • Grant the service role and artifact consumers the necessary KMS and S3 permissions, then verify a build and artifact read.
  • Check artifact encryption-disable settings and encryption for cache and log destinations separately.

Examples

These are excerpts from a project with S3 output artifacts. Supply the bucket and key inputs, CodeBuildRole, build environment and source settings separately.

Before

yaml
Resources:
  BuildProject:
    Type: AWS::CodeBuild::Project
    Properties:
      Name: my-build
      ServiceRole: !GetAtt CodeBuildRole.Arn
      Artifacts:
        Type: S3
        Location: !Ref ArtifactBucketName

The output-artifact key is omitted, so the default AWS managed key is used. This does not mean encryption is absent, but it may not meet a customer-managed-key requirement.

After

yaml
Resources:
  BuildProject:
    Type: AWS::CodeBuild::Project
    Properties:
      Name: my-build
      EncryptionKey: !Ref ArtifactKeyArn
      ServiceRole: !GetAtt CodeBuildRole.Arn
      Artifacts:
        Type: S3
        Location: !Ref ArtifactBucketName

The artifact key is explicit. Selecting a key and granting permission to use it are separate steps.

References