A software development company uses AWS CodeCommit for source code management. They need to enforce a policy where only developers from a specific IAM group can push code to certain repositories, and only after their code has been reviewed and approved. Additionally, they want to ensure that all changes to these repositories are logged for auditing purposes. How can these requirements be met most effectively?
- AConfigure repository-level IAM policies for push access, and use AWS CodeBuild to enforce code review before merging.
- BUse IAM policies to restrict 'git push' access to the specific group and rely on CodeCommit's default logging.
- CImplement IAM policies to control 'git push' actions and configure AWS CloudTrail to log all CodeCommit API calls.
- DUse IAM policies to manage push access, and integrate CodeCommit with AWS CodePipeline to enforce pull requests and approvals before merging to protected branches.
Show answer & explanationAnswer & explanation
Correct answer: D. Use IAM policies to manage push access, and integrate CodeCommit with AWS CodePipeline to enforce pull requests and approvals before merging to protected branches.
IAM policies control who can perform 'git push' actions, ensuring only authorized groups can initiate pushes. Integrating CodeCommit with AWS CodePipeline allows for the enforcement of pull requests and approval workflows on protected branches, which addresses the 'reviewed and approved' requirement. All CodeCommit actions, including pushes and merges, are logged by default in CloudTrail for auditing.
Why the other options are wrong
- A. CodeBuild is for building and testing code, not for enforcing code review workflows before merging. Repository-level IAM policies are part of the solution but incomplete for the review process.
- B. While IAM policies restrict push access, CodeCommit's default logging might not be detailed enough for all audit requirements, and it doesn't enforce code review before pushing (only before merging if pull requests are used).
- C. IAM policies and CloudTrail are good for access control and auditing, but this option doesn't address the 'reviewed and approved' requirement for code changes before they are accepted.
CodeCommit Secure Workflow
A secure workflow in AWS CodeCommit combines IAM for access control, CodePipeline for enforcing code review and approval, and CloudTrail for auditing.
- IAM policies grant/deny repository access.
- CodePipeline enforces pull request and approval workflows.
- Protected branches prevent direct pushes without review.
- AWS CloudTrail logs all CodeCommit API calls for auditing.
Memory trick: IAM, Pipeline, and CloudTrail: The 'IPC' of secure code.