如何在AWS CodeCommit中禁止部分用户推送至master分支?
How to Restrict Specific Users from Pushing to the
master Branch in AWS CodeCommit Hey there! Great question—you absolutely can lock down push access to your master branch for specific users in AWS CodeCommit. Here are the most reliable methods to get this done:
Option 1: Use IAM Policies to Explicitly Deny Push Access
IAM's deny rules take precedence over allow rules, making this a solid way to block push access for targeted users/groups:
- Create or modify an IAM policy with a deny statement for the
codecommit:GitPushaction on yourmasterbranch. Here's a ready-to-use example:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Deny", "Action": "codecommit:GitPush", "Resource": "arn:aws:codecommit:REGION:ACCOUNT_ID:YOUR_REPO_NAME", "Condition": { "StringEquals": { "codecommit:BranchName": "master" } } } ] }
- Replace
REGION,ACCOUNT_ID, andYOUR_REPO_NAMEwith your actual AWS details. - Attach this policy to the IAM users or groups you want to restrict. Double-check that no conflicting allow policies override this deny rule (IAM always prioritizes Deny over Allow).
Option 2: Use CodeCommit's Built-In Branch Permissions (Console)
If you prefer a visual approach, the CodeCommit console makes this super simple:
- Navigate to your repository in the AWS CodeCommit console.
- Go to Settings > Branch permissions.
- Select the
masterbranch from the dropdown menu. - Click Edit permissions under the Actions column.
- For each user/group you want to restrict, set the Push permission to Deny (you can leave Pull access set to Allow if they still need to fetch code).
- Save your changes—restrictions take effect right away.
Option 3: Use AWS CLI for Branch Permission Management
For command-line enthusiasts, you can set these permissions via the AWS CLI:
- To deny push access for a single user, run:
aws codecommit put-branch-permissions \ --repository-name YOUR_REPO_NAME \ --branch-name master \ --user-arn arn:aws:iam::ACCOUNT_ID:user/RESTRICTED_USER_NAME \ --permission DENY \ --actions GitPush
- To apply this to an IAM group, replace
--user-arnwith--group-arnand use the group's ARN instead.
Quick Pro Tips
- Always test these permissions with a test user first to ensure they work as intended.
- If you want to restrict most users but allow a select few to push to
master, you can combine these methods: deny push access for everyone, then explicitly allow your trusted users via either IAM policies or branch permissions.
内容的提问来源于stack exchange,提问作者Fellipe Medeiros
相关产品推荐
相关产品推荐

