如何定制AWS Codestar/CloudFormation模板配置CodeBuild项目及管道环境?
When you use the default SAM+Python AWS CodeStar template, the CI/CD pipeline (including the CodeBuild project) is automatically provisioned by the AWS::CodeStar transform. Defining a standalone AWS::CodeBuild::Project in your template won't modify the existing pipeline's CodeBuild configuration—it just creates a separate resource. Here's how to properly update the pipeline's CodeBuild environment to use Python 3.7:
Key Background
The AWS::CodeStar transform manages the default pipeline resources behind the scenes. To customize the pipeline (including its CodeBuild stage), you need to explicitly define an AWS::CodeStar::Pipeline resource in your template, which overrides the default pipeline setup and lets you link your custom CodeBuild project to the pipeline.
Step-by-Step Solution
1. Update Your template.yml to Include the Custom Pipeline and CodeBuild Project
Replace or extend your existing template with the following configuration. This explicitly defines the CodeStar pipeline and ties it to a CodeBuild project using the Python 3.7 image:
AWSTemplateFormatVersion: 2010-09-09 Transform: - AWS::Serverless-2016-10-31 - AWS::CodeStar Parameters: ProjectId: Type: String Description: CodeStar projectId used to associate new resources to team members Resources: HelloWorld: Type: AWS::Serverless::Function Properties: Handler: index.lambda_handler Runtime: python3.7 Layers: - arn:aws:lambda:us-east-1:xxxxxxxxxxxx:layer:your-layer:1 Role: !GetAtt LambdaExecutionRole.Arn # Explicitly define the CodeStar pipeline to override default settings CodeStarPipeline: Type: AWS::CodeStar::Pipeline Properties: ProjectId: !Ref ProjectId Pipeline: Name: !Sub "${ProjectId}-pipeline" Stages: - Name: Source Actions: - Name: Source ActionTypeId: Category: Source Owner: AWS Provider: CodeCommit Version: "1" Configuration: RepositoryName: !Ref ProjectId BranchName: main OutputArtifacts: - Name: SourceArtifact - Name: Build Actions: - Name: Build ActionTypeId: Category: Build Owner: AWS Provider: CodeBuild Version: "1" Configuration: ProjectName: !Ref CodeBuildProject InputArtifacts: - Name: SourceArtifact OutputArtifacts: - Name: BuildArtifact - Name: Deploy Actions: - Name: Deploy ActionTypeId: Category: Deploy Owner: AWS Provider: CloudFormation Version: "1" Configuration: ActionMode: CREATE_UPDATE StackName: !Sub "${ProjectId}-stack" TemplatePath: BuildArtifact::template.yml RoleArn: !GetAtt CloudFormationExecutionRole.Arn InputArtifacts: - Name: BuildArtifact # Custom CodeBuild project with Python 3.7 image CodeBuildProject: Type: AWS::CodeBuild::Project Properties: Description: CodeBuild project for CodeStar pipeline (Python 3.7) Artifacts: Type: CODEPIPELINE Environment: Type: LINUX_CONTAINER ComputeType: BUILD_GENERAL1_SMALL Image: aws/codebuild/python:3.7.1 EnvironmentVariables: - Name: PYTHON_VERSION Value: "3.7" Source: Type: CODEPIPELINE TimeoutInMinutes: 10 ServiceRole: !GetAtt CodeBuildServiceRole.Arn # IAM Roles (adjust permissions as needed, or use existing CodeStar roles) LambdaExecutionRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Service: lambda.amazonaws.com Action: sts:AssumeRole ManagedPolicyArns: - arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole CodeBuildServiceRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Service: codebuild.amazonaws.com Action: sts:AssumeRole ManagedPolicyArns: - arn:aws:iam::aws:policy/AWSCodeBuildAdminAccess CloudFormationExecutionRole: Type: AWS::IAM::Role Properties: AssumeRolePolicyDocument: Version: "2012-10-17" Statement: - Effect: Allow Principal: Service: cloudformation.amazonaws.com Action: sts:AssumeRole ManagedPolicyArns: - arn:aws:iam::aws:policy/AdministratorAccess
2. Adjust Your buildspec.yml for Python 3.7
Make sure your build commands are compatible with Python 3.7. Here's an example buildspec:
version: 0.2 phases: install: runtime-versions: python: 3.7 commands: - pip3 install -r requirements.txt -t . build: commands: - sam build - sam package --output-template-file packaged.yml --s3-bucket your-codebuild-artifact-bucket artifacts: files: - packaged.yml
3. Deploy the Template via CloudFormation Change Set
- Go to the AWS CloudFormation console and select your CodeStar stack.
- Choose Create change set and upload your updated
template.yml. - Review the change set to confirm it will update the existing pipeline and CodeBuild resources (instead of creating new ones).
- Execute the change set to apply the updates.
Important Notes
- If you already have existing IAM roles created by CodeStar (like the CodeBuild service role), you can reference them instead of creating new ones using
!Refor!ImportValue(check the CloudFormation stack resources for their names). - Ensure the S3 bucket used in
sam packageexists and is accessible by the CodeBuild service role. You can use the default bucket created by CodeStar for your project.
内容的提问来源于stack exchange,提问作者Vladyslav Didenko

