You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Bitbucket作为CodePipeline源时出现权限错误如何解决

Bitbucket对接AWS CodePipeline权限报错修复方案

问题背景

需要将Bitbucket配置为AWS CodePipeline的源仓库,部署过程中出现权限不足报错,初步判断需要为AWS CloudFormation执行角色授予对应权限但不清楚操作方法。

具体报错信息

User: arn:aws:sts::678100228133:assumed-role/cdk-hnb659fds-cfn-exec-role-678100228133-us-west-2/AWSCloudFormation is not authorized to perform: codestar-connections:PassConnection on resource: ari:cloud:bitbucket::app/{67a68345-bf8e-49c5-8eca-833727e2d892}/aws-codestar (Service: AWSCodePipeline; Status Code: 400; Error Code: AccessDeniedException; Request ID: 0d152b96-e756-4821-9ad1-7551cb9e8bf7; Proxy: null)

现有部署代码

已手动完成Bitbucket侧AWS CodeStar应用安装,使用CDK定义流水线源动作的代码如下:

const bitbucketSourceOutput = new cdk.aws_codepipeline.Artifact();
const bitbucketSourceAction = new cdk.aws_codepipeline_actions.CodeStarConnectionsSourceAction({
  actionName: `ss-${targetEnv}-ecs-bitbucket-build`,
  owner: 'aws',
  repo: 'myname/testrepo',
  output: bitbucketSourceOutput,
  connectionArn: 'ari:cloud:bitbucket::app/{67a68345-bf8e-49c5-8eca-833727e2d892}/aws-codestar',
});

修复步骤

  • 修正connectionArn配置错误
    代码中填写的ari:cloud:bitbucket::app/{67a68345-bf8e-49c5-8eca-833727e2d892}/aws-codestar是Bitbucket侧安装CodeStar应用的标识,不是AWS侧CodeStar连接的合法ARN。需要打开AWS控制台CodeStar Connections页面,找到绑定Bitbucket、状态为Available的连接,复制其ARN,格式为arn:aws:codestar-connections:us-west-2:678100228133:connection/<连接唯一ID>,替换代码中原有connectionArn的值。
  • 修正仓库owner配置
    代码中owner: 'aws'配置错误,需要替换为你的Bitbucket工作区ID,也就是仓库路径myname/testrepo中/前的myname,否则后续会出现拉取代码404错误。
  • 为CloudFormation执行角色补充缺失权限
    打开IAM控制台,找到报错中提到的角色cdk-hnb659fds-cfn-exec-role-678100228133-us-west-2,为其添加如下内联权限策略:
    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Action": "codestar-connections:PassConnection",
                "Resource": "上一步复制的CodeStar连接ARN",
                "Condition": {
                    "StringEquals": {
                        "codestar-connections:PassedToService": "codepipeline.amazonaws.com"
                    }
                }
            }
        ]
    }
    
    测试环境如果需要快速验证,也可以将Resource设置为*,生产环境建议绑定具体连接ARN做权限最小化收敛。

完成以上配置后重新执行CDK部署即可解决报错。

内容的提问来源于stack exchange,提问作者whitebear

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.27 17:54:26