You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AWS CodeCommit中禁止部分用户推送至master分支?

How to Restrict Specific Users from Pushing to the master Branch in AWS CodeCommit

Hey there! Great question—you absolutely can lock down push access to your master branch for specific users in AWS CodeCommit. Here are the most reliable methods to get this done:

Option 1: Use IAM Policies to Explicitly Deny Push Access

IAM's deny rules take precedence over allow rules, making this a solid way to block push access for targeted users/groups:

  • Create or modify an IAM policy with a deny statement for the codecommit:GitPush action on your master branch. Here's a ready-to-use example:
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Deny",
            "Action": "codecommit:GitPush",
            "Resource": "arn:aws:codecommit:REGION:ACCOUNT_ID:YOUR_REPO_NAME",
            "Condition": {
                "StringEquals": {
                    "codecommit:BranchName": "master"
                }
            }
        }
    ]
}
  • Replace REGION, ACCOUNT_ID, and YOUR_REPO_NAME with your actual AWS details.
  • Attach this policy to the IAM users or groups you want to restrict. Double-check that no conflicting allow policies override this deny rule (IAM always prioritizes Deny over Allow).

Option 2: Use CodeCommit's Built-In Branch Permissions (Console)

If you prefer a visual approach, the CodeCommit console makes this super simple:

  • Navigate to your repository in the AWS CodeCommit console.
  • Go to Settings > Branch permissions.
  • Select the master branch from the dropdown menu.
  • Click Edit permissions under the Actions column.
  • For each user/group you want to restrict, set the Push permission to Deny (you can leave Pull access set to Allow if they still need to fetch code).
  • Save your changes—restrictions take effect right away.

Option 3: Use AWS CLI for Branch Permission Management

For command-line enthusiasts, you can set these permissions via the AWS CLI:

  • To deny push access for a single user, run:
aws codecommit put-branch-permissions \
    --repository-name YOUR_REPO_NAME \
    --branch-name master \
    --user-arn arn:aws:iam::ACCOUNT_ID:user/RESTRICTED_USER_NAME \
    --permission DENY \
    --actions GitPush
  • To apply this to an IAM group, replace --user-arn with --group-arn and use the group's ARN instead.

Quick Pro Tips

  • Always test these permissions with a test user first to ensure they work as intended.
  • If you want to restrict most users but allow a select few to push to master, you can combine these methods: deny push access for everyone, then explicitly allow your trusted users via either IAM policies or branch permissions.

内容的提问来源于stack exchange,提问作者Fellipe Medeiros

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 07:50:54