Description
CodeBuild uses EncryptionKey to select a KMS key for output artifacts. If it is omitted, CodeBuild uses the AWS managed KMS key for Amazon S3. Omission alone does not mean artifacts are stored in plaintext.
Where a customer managed key is required, select one whose policy and lifecycle you control. This setting does not configure encryption for all caches and logs.
Potential impact
- The default key may not meet requirements for customer managed keys or separation of permissions.
- An unavailable key or insufficient permissions can prevent artifacts from being stored or read.
Remediation
- When a customer managed key is required, set
EncryptionKeyto an approved key ARN or alias. - Grant the service role and artifact consumers the necessary KMS and S3 permissions, then verify a build and artifact read.
- Check artifact encryption-disable settings and encryption for cache and log destinations separately.
Examples
These are excerpts from a project with S3 output artifacts. Supply the bucket and key inputs, CodeBuildRole, build environment and source settings separately.
Before
Resources:
BuildProject:
Type: AWS::CodeBuild::Project
Properties:
Name: my-build
ServiceRole: !GetAtt CodeBuildRole.Arn
Artifacts:
Type: S3
Location: !Ref ArtifactBucketName
The output-artifact key is omitted, so the default AWS managed key is used. This does not mean encryption is absent, but it may not meet a customer-managed-key requirement.
After
Resources:
BuildProject:
Type: AWS::CodeBuild::Project
Properties:
Name: my-build
EncryptionKey: !Ref ArtifactKeyArn
ServiceRole: !GetAtt CodeBuildRole.Arn
Artifacts:
Type: S3
Location: !Ref ArtifactBucketName
The artifact key is explicit. Selecting a key and granting permission to use it are separate steps.