AWS Certified Developer – Associate (DVA-C02)DeploymentEasy

A developer is configuring an AWS CodeBuild project to build a Docker image and push it to Amazon ECR. The CodeBuild project needs to assume an IAM role that has permissions to push images to ECR. Which CodeBuild environment variable should be set to automatically retrieve and use temporary credentials for the build process?

  1. ACODEBUILD_INITIATOR
  2. BAWS_CONTAINER_CREDENTIALS_RELATIVE_URI
  3. CAWS_DEFAULT_REGION
  4. DCODEBUILD_BUILD_ID
Show answer & explanation

Correct answer: B. AWS_CONTAINER_CREDENTIALS_RELATIVE_URI

When CodeBuild runs, it automatically sets the AWS_CONTAINER_CREDENTIALS_RELATIVE_URI environment variable. Docker can use this variable to retrieve temporary credentials from the CodeBuild agent, allowing it to authenticate with ECR without explicitly managing static AWS credentials.

Why the other options are wrong

  • A. This variable indicates who initiated the build (e.g., CodePipeline, console) and is not for credential management.
  • C. This variable specifies the AWS region and is not used for credential management.
  • D. This variable holds the unique ID of the CodeBuild build and is not related to credentials.

CodeBuild ECR Credentials

CodeBuild automatically provides temporary AWS credentials to its build environment, which can be used by tools like Docker to interact with AWS services such as ECR.

  • AWS_CONTAINER_CREDENTIALS_RELATIVE_URI environment variable is automatically set.
  • Docker can leverage this variable to authenticate with ECR.
  • Eliminates the need to embed static credentials in build scripts.

Memory trick: Credentials for containers, CodeBuild handles the keys.

More Deployment questions