为本地服务器创建AWS CodeDeploy扮演角色:控制台服务选择咨询
Great question! Setting up CodeDeploy with a local server requires a slightly different IAM setup than AWS-hosted instances—let's break this down for you:
1. Choosing the IAM Role's Trusted Entity (Service/Principal)
Since you're working with a local server (not an AWS-managed service like EC2), you won't select a pre-defined AWS service as the trusted entity in the IAM console. Instead, you need to manually configure the trust policy to allow your local environment to assume this role.
Here's the step-by-step approach:
- When creating the IAM role, start by selecting "Another AWS account" (use your own AWS account ID here) as the initial trusted entity type.
- After creating the role, edit its trust policy to explicitly allow your IAM user (or the entity you'll use to generate temporary credentials) to perform
sts:AssumeRole. Example policy:
This lets your local CodeDeploy agent (via the{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::YOUR_ACCOUNT_ID:user/YOUR_IAM_USER_NAME" }, "Action": "sts:AssumeRole" } ] }aws-codedeploy-session-helper) assume the role to fetch temporary credentials.
2. Configuring the Required Permissions Policy
You specified needing s3:Get* and s3:List* access to all resources. To set this up:
- Create a custom IAM policy with the following JSON (you can also add optional CodeDeploy service permissions if your agent needs to communicate with AWS CodeDeploy directly):
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:Get*", "s3:List*" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "codedeploy:RegisterApplicationRevision", "codedeploy:GetDeploymentConfig", "codedeploy:GetApplicationRevision" ], "Resource": "*" } ] } - Attach this policy to the IAM role you created earlier.
3. Using aws-codedeploy-session-helper for Credential Refresh
Once your role is configured, the aws-codedeploy-session-helper will handle fetching and refreshing temporary credentials for your local CodeDeploy agent. Just make sure:
- Your local AWS CLI is set up with the IAM user credentials that have permission to assume the role.
- The helper is configured to target the IAM role you created, so it can automatically renew credentials before they expire.
If you run into any issues with policy editing or role assumption, feel free to follow up with specific details!
内容的提问来源于stack exchange,提问作者Otto45

