Skip to content

Permissions between the pieces

Why each IAM role needs its own policy, and the two policies you add so deployments can download and start.

About 20 min · Verified 8 October 2026

0 of 4 steps done0%

Every component in the pipeline acts as a different IAM role, and a permission only helps the role it is attached to. This is the number one source of confusing errors, so spend a moment on the map before you add anything.

Who needs what#

RoleWho uses itWhat it must be able to do
Pipeline service role (created by the wizard)CodePipelineRead the GitHub connection, read/write the artifact bucket, start CodeBuild, create CodeDeploy deployments
codebuild-shortlink-api-build-service-role (wizard)CodeBuildWrite logs, read/write the artifact bucket
shortlink-codedeploy-service-roleThe CodeDeploy serviceFind your instance, and control the target group (AWSCodeDeployRole)
shortlink-ec2-roleThe agent on the serverSystems Manager, and download revisions from the artifact bucket

The wizard handles the first two rows when you create the pipeline from it. The last row is the one people forget, and the pipeline row sometimes lacks CodeDeploy rights. You will fix both.

Find the names you need#

Get the artifact bucket and the pipeline role#

Your computerArtifact bucket and pipeline role
aws codepipeline get-pipeline --region ap-south-1 --name shortlink-api-prod \
  --query 'pipeline.{bucket:artifactStore.location,role:roleArn}' --output table

Copy the bucket (it starts with codepipeline-) into My values → Pipeline artifact bucket. Note the pipeline role name: it is the last part of the ARN.

Let the server download releases#

Open IAMRolesshortlink-ec2-rolePermissionsAdd permissionsCreate inline policy. Switch to the JSON tab, paste this, and name the policy shortlink-pipeline-artifacts-read.

Paste in the AWS consoleshortlink-pipeline-artifacts-read
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:GetObject", "s3:GetObjectVersion"],
      "Resource": "arn:aws:s3:::<ARTIFACT_BUCKET>/*"
    }
  ]
}

Replace <ARTIFACT_BUCKET> with your own value (or fill in the known ones once under My values at the top of the page).

The agent (running as this role) downloads the ZIP straight from S3. Your server reaches S3 through the gateway endpoint you created in the network chapter, so it does not use the NAT gateway for this.

Let the pipeline start CodeDeploy#

Add an inline policy to the pipeline service role#

Open IAMRoles(your pipeline role)PermissionsAdd permissionsCreate inline policyJSON. Name it shortlink-api-deploy.

Paste in the AWS consoleshortlink-api-deploy
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "codedeploy:CreateDeployment",
        "codedeploy:GetApplication",
        "codedeploy:GetApplicationRevision",
        "codedeploy:GetDeployment",
        "codedeploy:RegisterApplicationRevision",
        "codedeploy:ListDeployments",
        "codedeploy:ListDeploymentGroups",
        "codedeploy:GetDeploymentGroup"
      ],
      "Resource": [
        "arn:aws:codedeploy:ap-south-1:<AWS_ACCOUNT_ID>:application:shortlink-api",
        "arn:aws:codedeploy:ap-south-1:<AWS_ACCOUNT_ID>:deploymentgroup:shortlink-api/shortlink-api-prod"
      ]
    },
    {
      "Effect": "Allow",
      "Action": "codedeploy:GetDeploymentConfig",
      "Resource": "arn:aws:codedeploy:ap-south-1:<AWS_ACCOUNT_ID>:deploymentconfig:CodeDeployDefault.AllAtOnce"
    },
    {
      "Effect": "Allow",
      "Action": "codedeploy:ListDeploymentConfigs",
      "Resource": "*"
    }
  ]
}

Replace <AWS_ACCOUNT_ID> with your own value (or fill in the known ones once under My values at the top of the page).

If the wizard already granted these, this policy is harmless: IAM permissions only add up.

Check the other two roles by eye#

  • Pipeline role also has a managed or inline policy mentioning codeconnections:UseConnection for your connection <CONNECTION_ARN>, and codebuild:StartBuild / codebuild:BatchGetBuilds for shortlink-api-build. The wizard writes both.
  • codebuild-shortlink-api-build-service-role has CloudWatch Logs access and S3 access to the codepipeline-<region>-… bucket.
  • shortlink-codedeploy-service-role has AWSCodeDeployRole attached.
Your computerList what the CodeDeploy role has attached
aws iam list-attached-role-policies --role-name shortlink-codedeploy-service-role --output table
aws iam list-role-policies --role-name shortlink-ec2-role --output table
You should see
The first shows AWSCodeDeployRole. The second lists shortlink-pipeline-artifacts-read.

The errors these policies prevent#

Error textRole to fix
AccessDenied / not authorized to perform: codedeploy:… in the pipeline's Deploy actionPipeline role: shortlink-api-deploy
Access Denied in the CodeDeploy event DownloadBundleshortlink-ec2-role: artifact read
not authorized to perform: codebuild:StartBuild and no CodeBuild log existsPipeline role. The failure is in CodePipeline, before any build begins
Unable to access the artifact bucket in a CodeBuild logThe CodeBuild service role
Could not determine instances / InvalidTagFilterThe tag, or shortlink-codedeploy-service-role

Next: run the first release.

Found a mistake? Edit this page on GitHub.