MCPcopy Create free account
hub / github.com/anomalyco/console / createIamRoleInUserAccount

Function createIamRoleInUserAccount

packages/core/src/run/codebuild-runner.ts:80–181  ·  view source on GitHub ↗
()

Source from the content-addressed store, hash-verified

78 };
79
80 async function createIamRoleInUserAccount() {
81 using iam = disposable(
82 () => new IAMClient(sdkConfig),
83 (client) => client.destroy(),
84 );
85 const roleName = `sst-runner-${region}-${suffix}`;
86 try {
87 const ret = await iam.send(
88 new CreateRoleCommand({
89 RoleName: roleName,
90 AssumeRolePolicyDocument: JSON.stringify({
91 Version: "2012-10-17",
92 Statement: [
93 {
94 Effect: "Allow",
95 Principal: {
96 Service: "codebuild.amazonaws.com",
97 },
98 Action: "sts:AssumeRole",
99 },
100 ],
101 }),
102 }),
103 );
104 await iam.send(
105 new PutRolePolicyCommand({
106 RoleName: roleName,
107 PolicyName: "default",
108 PolicyDocument: JSON.stringify({
109 Version: "2012-10-17",
110 Statement: [
111 {
112 Sid: "Events",
113 Effect: "Allow",
114 Action: "events:PutEvents",
115 Resource: "*",
116 },
117 {
118 Sid: "Logs",
119 Effect: "Allow",
120 Action: [
121 "logs:CreateLogStream",
122 "logs:CreateLogGroup",
123 "logs:PutLogEvents",
124 ],
125 Resource: [
126 `arn:aws:logs:${region}:${awsAccountExternalID}:log-group:/aws/codebuild/${projectName}`,
127 `arn:aws:logs:${region}:${awsAccountExternalID}:log-group:/aws/codebuild/${projectName}:*`,
128 ],
129 },
130 {
131 Sid: "CodeBuild",
132 Action: [
133 "codebuild:CreateReportGroup",
134 "codebuild:CreateReport",
135 "codebuild:UpdateReport",
136 "codebuild:BatchPutTestCases",
137 "codebuild:BatchPutCodeCoverages",

Callers 1

Calls 1

disposableFunction · 0.90

Tested by

no test coverage detected