Fix pipeline: add ECR permissions for Fargate image builds #16
1 changed files with 16 additions and 1 deletions
|
|
@ -69,6 +69,21 @@ Resources:
|
|||
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-file-publishing-role-${AWS::AccountId}-${AWS::Region}"
|
||||
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-lookup-role-${AWS::AccountId}-${AWS::Region}"
|
||||
- !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-cfn-exec-role-${AWS::AccountId}-${AWS::Region}"
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- ecr:GetAuthorizationToken
|
||||
Resource: "*"
|
||||
- Effect: Allow
|
||||
Action:
|
||||
- ecr:DescribeRepositories
|
||||
- ecr:BatchCheckLayerAvailability
|
||||
- ecr:GetDownloadUrlForLayer
|
||||
- ecr:BatchGetImage
|
||||
- ecr:PutImage
|
||||
- ecr:InitiateLayerUpload
|
||||
- ecr:UploadLayerPart
|
||||
- ecr:CompleteLayerUpload
|
||||
Resource: !Sub "arn:aws:ecr:${AWS::Region}:${AWS::AccountId}:repository/cdk-hnb659fds-container-assets-${AWS::AccountId}-${AWS::Region}"
|
||||
|
||||
CodeBuildProject:
|
||||
Type: AWS::CodeBuild::Project
|
||||
|
|
@ -83,7 +98,7 @@ Resources:
|
|||
ComputeType: BUILD_GENERAL1_SMALL
|
||||
Image: aws/codebuild/amazonlinux-aarch64-standard:3.0
|
||||
EnvironmentVariables: []
|
||||
PrivilegedMode: false
|
||||
PrivilegedMode: true
|
||||
Source:
|
||||
Type: CODEPIPELINE
|
||||
BuildSpec: buildspec.yml
|
||||
|
|
|
|||
Reference in a new issue