AWSConfigRemediation-DeleteAccessKeysFromCodeBuildProject
Description
The
AWSConfigRemediation-DeleteAccessKeysFromCodeBuildProject
runbook
deletes the
AWS_ACCESS_KEY_ID
and
AWS_SECRET_ACCESS_KEY
environment variables from the Amazon CodeBuild (CodeBuild) project you specify. Amazon Config must be
enabled in the Amazon Web Services Region where you run this automation.
Document type
Automation
Owner
Amazon
Platforms
Linux, macOS, Windows
Parameters
-
AutomationAssumeRole
Type: String
Allowed values: ^arn:(?:aws|aws-us-gov|aws-cn):iam::\d{12}:role\/[\w+=,.@/-]+$
Description: (Required) The Amazon Resource Name (ARN) of the Amazon Identity and Access Management (IAM) role that allows Systems Manager Automation to perform the actions on your behalf.
-
ResourceId
Type: String
Description: (Required) The ID of the CodeBuild project whose access key environment variables you want to delete.
Required IAM permissions
The AutomationAssumeRole
parameter requires the following actions to
successfully use the runbook.
-
ssm:StartAutomationExecution
-
ssm:GetAutomationExecution
-
config:GetResourceConfigHistory
-
codebuild:BatchGetProjects
-
codebuild:UpdateProject
Document Steps
-
aws:executeScript
- Deletes the access key environment variables for the CodeBuild project specified in theResourceId
parameter.