从BitBucket推送至CodeCommit失败,请求技术协助
Hey there, let's dig into why your BitBucket Pipeline is failing to push to AWS CodeCommit. I've worked through similar issues before, so here are the most likely culprits to check:
1. Verify your SSH key format (Puttygen gotcha!)
Puttygen generates .ppk keys by default, but AWS CodeCommit expects an OpenSSH-formatted private key. If you just exported the raw PPK content without converting it, that's probably breaking the authentication.
- Fix: Open your PPK file in Puttygen, go to
Conversions > Export OpenSSH key, and save it as a plain text file. Make sure you skip setting a passphrase (BitBucket Pipelines can't prompt for it). Then re-encode this OpenSSH key to base64 and update yourCodeCommitKeyPipeline variable.
2. Fix the truncated base64 decoding step
Looking at your bitbucket-pipelines.yml, the base64 command is cut off (base64 -d ~/.ssh/codec...). An incomplete command will leave you with a corrupted private key, which causes authentication failures.
- Fix: Make sure the full decoding command is present. It should look like this:
Double-check that your- base64 -d ~/.ssh/codecommit_rsa.tmp > ~/.ssh/codecommit_rsaCodeCommitKeyvariable holds the full, untruncated base64 string of your OpenSSH private key.
3. Enforce strict SSH key permissions
AWS CodeCommit requires private keys to have restrictive permissions (only the owner can read them). If your key file has too open permissions, SSH will reject it outright.
- Add this step right after decoding the key:
- chmod 600 ~/.ssh/codecommit_rsa
4. Set up the SSH config for CodeCommit
You need to tell SSH to use your specific key when connecting to CodeCommit's hostname. Without this config, SSH might try to use the wrong key (or none at all).
- Add this step to create the necessary config file:
Replace- echo -e "Host git-codecommit.*.amazonaws.com\n User YOUR_IAM_SSH_KEY_ID\n IdentityFile ~/.ssh/codecommit_rsa" > ~/.ssh/configYOUR_IAM_SSH_KEY_IDwith the SSH key ID linked to your IAM user (you can find this in the IAM console under the user's SSH keys section).
5. Confirm IAM permissions are set correctly
Your IAM user needs explicit permissions to push to the target CodeCommit repository. If the user lacks codecommit:GitPush access, the push will fail with a permission error (or silently, depending on the setup).
- Fix: Attach the
AWSCodeCommitPowerUsermanaged policy (or a custom policy that grantscodecommit:GitPushon your specific repo) to your IAM user.
6. Validate the remote repository setup
Make sure you're adding the CodeCommit remote correctly and pushing to the right branch in your pipeline.
- Add these steps to your script (adjust the repo URL to match your AWS region and repository name):
- git remote add codecommit ssh://git-codecommit.us-east-1.amazonaws.com/v1/repos/YourTargetRepoName - git push codecommit main # replace with your target branch name
内容的提问来源于stack exchange,提问作者Greg Sansom

