

# `AWSConfigRemediation-DeleteAccessKeysFromCodeBuildProject`


 **Description** 

 The `AWSConfigRemediation-DeleteAccessKeysFromCodeBuildProject` runbook deletes the `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY` environment variables from the Amazon CodeBuild (CodeBuild) project you specify. Amazon Config must be enabled in the Amazon Web Services Region where you run this automation. 

 [Run this Automation (console)](https://console.amazonaws.cn/systems-manager/automation/execute/AWSConfigRemediation-DeleteAccessKeysFromCodeBuildProject) 

**Document type**

Automation

**Owner**

Amazon

**Platforms**

Linux, macOS, Windows

**Parameters**
+ AutomationAssumeRole

  Type: String

  Description: (Required) The Amazon Resource Name (ARN) of the Amazon Identity and Access Management (IAM) role that allows Systems Manager Automation to perform the actions on your behalf.
+ ResourceId

  Type: String

  Description: (Required) The ID of the CodeBuild project whose access key environment variables you want to delete.

**Required IAM permissions**

The `AutomationAssumeRole` parameter requires the following actions to use the runbook successfully.
+  `ssm:StartAutomationExecution` 
+  `ssm:GetAutomationExecution` 
+  `config:GetResourceConfigHistory` 
+  `codebuild:BatchGetProjects` 
+  `codebuild:UpdateProject` 

 **Document Steps** 
+  `aws:executeScript` - Deletes the access key environment variables for the CodeBuild project specified in the `ResourceId` parameter. 