CodeBuild project using an AWS managed key

Choose an AWS managed or customer-managed key according to the key-policy requirements for CodeBuild artifacts.

Description

CodeBuild's encryption_key selects the key used to encrypt build output artifacts. By default, CodeBuild uses the AWS managed KMS key for Amazon S3. An AWS managed key does not itself mean artifacts are plaintext or encryption is weak.

You cannot edit the AWS managed key's policy. Choose a customer-managed key if the organization must directly control artifact key policies and lifecycle. This setting does not provide unified protection for all build data, such as caches, logs and environment variables.

Potential impact

The configuration may not meet artifact-protection requirements for customer-managed keys. Excessive artifact-read permissions require separate restrictions, while incorrect key permissions can prevent artifact uploads or reads.

Remediation

  • When required, set encryption_key to an actual customer-managed KMS key ARN or alias.
  • Grant the CodeBuild service role the necessary key permissions, and minimize S3 and KMS access for artifact readers.
  • Check artifact configuration, actual encryption and build/download operation. Manage cache and log storage protection and secret delivery separately.

Examples

These excerpts show only key selection and the service role. Referenced keys and roles must exist; source, build-environment and artifact settings are also required separately.

AWS managed key

hcl
data "aws_kms_key" "by_alias" {
  key_id = "alias/aws/s3"
}

resource "aws_codebuild_project" "example" {
  name           = "project-cloudrail-test"
  service_role   = aws_iam_role.codebuild.arn
  encryption_key = data.aws_kms_key.by_alias.arn
}

This looks up the AWS managed key for Amazon S3 and uses it for artifact encryption.

Customer-managed key

hcl
data "aws_kms_key" "by_alias" {
  key_id = "alias/myAlias"
}

resource "aws_codebuild_project" "example" {
  name           = "project-cloudrail-test"
  service_role   = aws_iam_role.codebuild2.arn
  encryption_key = data.aws_kms_key.by_alias.arn
}

Use an actual customer-managed key alias and a service role with the required permissions. This example specifies a different role, so verify its key-use and artifact-access permissions too.

References