You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何定制AWS Codestar/CloudFormation模板配置CodeBuild项目及管道环境?

How to Modify CodeStar Pipeline's CodeBuild Environment (Python 3.7) via SAM Template

When you use the default SAM+Python AWS CodeStar template, the CI/CD pipeline (including the CodeBuild project) is automatically provisioned by the AWS::CodeStar transform. Defining a standalone AWS::CodeBuild::Project in your template won't modify the existing pipeline's CodeBuild configuration—it just creates a separate resource. Here's how to properly update the pipeline's CodeBuild environment to use Python 3.7:

Key Background

The AWS::CodeStar transform manages the default pipeline resources behind the scenes. To customize the pipeline (including its CodeBuild stage), you need to explicitly define an AWS::CodeStar::Pipeline resource in your template, which overrides the default pipeline setup and lets you link your custom CodeBuild project to the pipeline.

Step-by-Step Solution

1. Update Your template.yml to Include the Custom Pipeline and CodeBuild Project

Replace or extend your existing template with the following configuration. This explicitly defines the CodeStar pipeline and ties it to a CodeBuild project using the Python 3.7 image:

AWSTemplateFormatVersion: 2010-09-09
Transform:
  - AWS::Serverless-2016-10-31
  - AWS::CodeStar
Parameters:
  ProjectId:
    Type: String
    Description: CodeStar projectId used to associate new resources to team members
Resources:
  HelloWorld:
    Type: AWS::Serverless::Function
    Properties:
      Handler: index.lambda_handler
      Runtime: python3.7
      Layers:
        - arn:aws:lambda:us-east-1:xxxxxxxxxxxx:layer:your-layer:1
      Role: !GetAtt LambdaExecutionRole.Arn

  # Explicitly define the CodeStar pipeline to override default settings
  CodeStarPipeline:
    Type: AWS::CodeStar::Pipeline
    Properties:
      ProjectId: !Ref ProjectId
      Pipeline:
        Name: !Sub "${ProjectId}-pipeline"
        Stages:
          - Name: Source
            Actions:
              - Name: Source
                ActionTypeId:
                  Category: Source
                  Owner: AWS
                  Provider: CodeCommit
                  Version: "1"
                Configuration:
                  RepositoryName: !Ref ProjectId
                  BranchName: main
                OutputArtifacts:
                  - Name: SourceArtifact
          - Name: Build
            Actions:
              - Name: Build
                ActionTypeId:
                  Category: Build
                  Owner: AWS
                  Provider: CodeBuild
                  Version: "1"
                Configuration:
                  ProjectName: !Ref CodeBuildProject
                InputArtifacts:
                  - Name: SourceArtifact
                OutputArtifacts:
                  - Name: BuildArtifact
          - Name: Deploy
            Actions:
              - Name: Deploy
                ActionTypeId:
                  Category: Deploy
                  Owner: AWS
                  Provider: CloudFormation
                  Version: "1"
                Configuration:
                  ActionMode: CREATE_UPDATE
                  StackName: !Sub "${ProjectId}-stack"
                  TemplatePath: BuildArtifact::template.yml
                  RoleArn: !GetAtt CloudFormationExecutionRole.Arn
                InputArtifacts:
                  - Name: BuildArtifact

  # Custom CodeBuild project with Python 3.7 image
  CodeBuildProject:
    Type: AWS::CodeBuild::Project
    Properties:
      Description: CodeBuild project for CodeStar pipeline (Python 3.7)
      Artifacts:
        Type: CODEPIPELINE
      Environment:
        Type: LINUX_CONTAINER
        ComputeType: BUILD_GENERAL1_SMALL
        Image: aws/codebuild/python:3.7.1
        EnvironmentVariables:
          - Name: PYTHON_VERSION
            Value: "3.7"
      Source:
        Type: CODEPIPELINE
      TimeoutInMinutes: 10
      ServiceRole: !GetAtt CodeBuildServiceRole.Arn

  # IAM Roles (adjust permissions as needed, or use existing CodeStar roles)
  LambdaExecutionRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Principal:
              Service: lambda.amazonaws.com
            Action: sts:AssumeRole
      ManagedPolicyArns:
        - arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole

  CodeBuildServiceRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Principal:
              Service: codebuild.amazonaws.com
            Action: sts:AssumeRole
      ManagedPolicyArns:
        - arn:aws:iam::aws:policy/AWSCodeBuildAdminAccess

  CloudFormationExecutionRole:
    Type: AWS::IAM::Role
    Properties:
      AssumeRolePolicyDocument:
        Version: "2012-10-17"
        Statement:
          - Effect: Allow
            Principal:
              Service: cloudformation.amazonaws.com
            Action: sts:AssumeRole
      ManagedPolicyArns:
        - arn:aws:iam::aws:policy/AdministratorAccess

2. Adjust Your buildspec.yml for Python 3.7

Make sure your build commands are compatible with Python 3.7. Here's an example buildspec:

version: 0.2
phases:
  install:
    runtime-versions:
      python: 3.7
    commands:
      - pip3 install -r requirements.txt -t .
  build:
    commands:
      - sam build
      - sam package --output-template-file packaged.yml --s3-bucket your-codebuild-artifact-bucket
artifacts:
  files:
    - packaged.yml

3. Deploy the Template via CloudFormation Change Set

  1. Go to the AWS CloudFormation console and select your CodeStar stack.
  2. Choose Create change set and upload your updated template.yml.
  3. Review the change set to confirm it will update the existing pipeline and CodeBuild resources (instead of creating new ones).
  4. Execute the change set to apply the updates.

Important Notes

  • If you already have existing IAM roles created by CodeStar (like the CodeBuild service role), you can reference them instead of creating new ones using !Ref or !ImportValue (check the CloudFormation stack resources for their names).
  • Ensure the S3 bucket used in sam package exists and is accessible by the CodeBuild service role. You can use the default bucket created by CodeStar for your project.

内容的提问来源于stack exchange,提问作者Vladyslav Didenko

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 09:27:27