Description
CodeBuild's encryption_key selects the key used to encrypt build output artifacts. By default, CodeBuild uses the AWS managed KMS key for Amazon S3. An AWS managed key does not itself mean artifacts are plaintext or encryption is weak.
You cannot edit the AWS managed key's policy. Choose a customer-managed key if the organization must directly control artifact key policies and lifecycle. This setting does not provide unified protection for all build data, such as caches, logs and environment variables.
Potential impact
The configuration may not meet artifact-protection requirements for customer-managed keys. Excessive artifact-read permissions require separate restrictions, while incorrect key permissions can prevent artifact uploads or reads.
Remediation
- When required, set
encryption_keyto an actual customer-managed KMS key ARN or alias. - Grant the CodeBuild service role the necessary key permissions, and minimize S3 and KMS access for artifact readers.
- Check artifact configuration, actual encryption and build/download operation. Manage cache and log storage protection and secret delivery separately.
Examples
These excerpts show only key selection and the service role. Referenced keys and roles must exist; source, build-environment and artifact settings are also required separately.
AWS managed key
data "aws_kms_key" "by_alias" {
key_id = "alias/aws/s3"
}
resource "aws_codebuild_project" "example" {
name = "project-cloudrail-test"
service_role = aws_iam_role.codebuild.arn
encryption_key = data.aws_kms_key.by_alias.arn
}
This looks up the AWS managed key for Amazon S3 and uses it for artifact encryption.
Customer-managed key
data "aws_kms_key" "by_alias" {
key_id = "alias/myAlias"
}
resource "aws_codebuild_project" "example" {
name = "project-cloudrail-test"
service_role = aws_iam_role.codebuild2.arn
encryption_key = data.aws_kms_key.by_alias.arn
}
Use an actual customer-managed key alias and a service role with the required permissions. This example specifies a different role, so verify its key-use and artifact-access permissions too.