()
| 78 | }; |
| 79 | |
| 80 | async function createIamRoleInUserAccount() { |
| 81 | using iam = disposable( |
| 82 | () => new IAMClient(sdkConfig), |
| 83 | (client) => client.destroy(), |
| 84 | ); |
| 85 | const roleName = `sst-runner-${region}-${suffix}`; |
| 86 | try { |
| 87 | const ret = await iam.send( |
| 88 | new CreateRoleCommand({ |
| 89 | RoleName: roleName, |
| 90 | AssumeRolePolicyDocument: JSON.stringify({ |
| 91 | Version: "2012-10-17", |
| 92 | Statement: [ |
| 93 | { |
| 94 | Effect: "Allow", |
| 95 | Principal: { |
| 96 | Service: "codebuild.amazonaws.com", |
| 97 | }, |
| 98 | Action: "sts:AssumeRole", |
| 99 | }, |
| 100 | ], |
| 101 | }), |
| 102 | }), |
| 103 | ); |
| 104 | await iam.send( |
| 105 | new PutRolePolicyCommand({ |
| 106 | RoleName: roleName, |
| 107 | PolicyName: "default", |
| 108 | PolicyDocument: JSON.stringify({ |
| 109 | Version: "2012-10-17", |
| 110 | Statement: [ |
| 111 | { |
| 112 | Sid: "Events", |
| 113 | Effect: "Allow", |
| 114 | Action: "events:PutEvents", |
| 115 | Resource: "*", |
| 116 | }, |
| 117 | { |
| 118 | Sid: "Logs", |
| 119 | Effect: "Allow", |
| 120 | Action: [ |
| 121 | "logs:CreateLogStream", |
| 122 | "logs:CreateLogGroup", |
| 123 | "logs:PutLogEvents", |
| 124 | ], |
| 125 | Resource: [ |
| 126 | `arn:aws:logs:${region}:${awsAccountExternalID}:log-group:/aws/codebuild/${projectName}`, |
| 127 | `arn:aws:logs:${region}:${awsAccountExternalID}:log-group:/aws/codebuild/${projectName}:*`, |
| 128 | ], |
| 129 | }, |
| 130 | { |
| 131 | Sid: "CodeBuild", |
| 132 | Action: [ |
| 133 | "codebuild:CreateReportGroup", |
| 134 | "codebuild:CreateReport", |
| 135 | "codebuild:UpdateReport", |
| 136 | "codebuild:BatchPutTestCases", |
| 137 | "codebuild:BatchPutCodeCoverages", |
no test coverage detected