Permissions between the pieces
Why each IAM role needs its own policy, and the two policies you add so deployments can download and start.
About 20 min · Verified 8 October 2026
On this page
- Who needs what
- Find the names you need
- Get the artifact bucket and the pipeline role
- Let the server download releases
- Add an inline policy to shortlink-ec2-role
- Let the pipeline start CodeDeploy
- Add an inline policy to the pipeline service role
- Check the other two roles by eye
- The errors these policies prevent
Every component in the pipeline acts as a different IAM role, and a permission only helps the role it is attached to. This is the number one source of confusing errors, so spend a moment on the map before you add anything.
Who needs what#
| Role | Who uses it | What it must be able to do |
|---|---|---|
| Pipeline service role (created by the wizard) | CodePipeline | Read the GitHub connection, read/write the artifact bucket, start CodeBuild, create CodeDeploy deployments |
codebuild-shortlink-api-build-service-role (wizard) | CodeBuild | Write logs, read/write the artifact bucket |
shortlink-codedeploy-service-role | The CodeDeploy service | Find your instance, and control the target group (AWSCodeDeployRole) |
shortlink-ec2-role | The agent on the server | Systems Manager, and download revisions from the artifact bucket |
The wizard handles the first two rows when you create the pipeline from it. The last row is the one people forget, and the pipeline row sometimes lacks CodeDeploy rights. You will fix both.
Find the names you need#
Get the artifact bucket and the pipeline role#
aws codepipeline get-pipeline --region ap-south-1 --name shortlink-api-prod \
--query 'pipeline.{bucket:artifactStore.location,role:roleArn}' --output tableCopy the bucket (it starts with codepipeline-) into My values → Pipeline artifact bucket. Note the pipeline role name: it is the last part of the ARN.
Let the server download releases#
Add an inline policy to shortlink-ec2-role#
Open IAMRolesshortlink-ec2-rolePermissionsAdd permissionsCreate inline policy. Switch to the JSON tab, paste this, and name the policy shortlink-pipeline-artifacts-read.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:GetObject", "s3:GetObjectVersion"],
"Resource": "arn:aws:s3:::<ARTIFACT_BUCKET>/*"
}
]
}Replace <ARTIFACT_BUCKET> with your own value (or fill in the known ones once under My values at the top of the page).
The agent (running as this role) downloads the ZIP straight from S3. Your server reaches S3 through the gateway endpoint you created in the network chapter, so it does not use the NAT gateway for this.
Let the pipeline start CodeDeploy#
Add an inline policy to the pipeline service role#
Open IAMRoles(your pipeline role)PermissionsAdd permissionsCreate inline policyJSON. Name it shortlink-api-deploy.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"codedeploy:CreateDeployment",
"codedeploy:GetApplication",
"codedeploy:GetApplicationRevision",
"codedeploy:GetDeployment",
"codedeploy:RegisterApplicationRevision",
"codedeploy:ListDeployments",
"codedeploy:ListDeploymentGroups",
"codedeploy:GetDeploymentGroup"
],
"Resource": [
"arn:aws:codedeploy:ap-south-1:<AWS_ACCOUNT_ID>:application:shortlink-api",
"arn:aws:codedeploy:ap-south-1:<AWS_ACCOUNT_ID>:deploymentgroup:shortlink-api/shortlink-api-prod"
]
},
{
"Effect": "Allow",
"Action": "codedeploy:GetDeploymentConfig",
"Resource": "arn:aws:codedeploy:ap-south-1:<AWS_ACCOUNT_ID>:deploymentconfig:CodeDeployDefault.AllAtOnce"
},
{
"Effect": "Allow",
"Action": "codedeploy:ListDeploymentConfigs",
"Resource": "*"
}
]
}Replace <AWS_ACCOUNT_ID> with your own value (or fill in the known ones once under My values at the top of the page).
If the wizard already granted these, this policy is harmless: IAM permissions only add up.
Check the other two roles by eye#
- Pipeline role also has a managed or inline policy mentioning
codeconnections:UseConnectionfor your connection<CONNECTION_ARN>, andcodebuild:StartBuild/codebuild:BatchGetBuildsforshortlink-api-build. The wizard writes both. codebuild-shortlink-api-build-service-rolehas CloudWatch Logs access and S3 access to thecodepipeline-<region>-…bucket.shortlink-codedeploy-service-rolehasAWSCodeDeployRoleattached.
aws iam list-attached-role-policies --role-name shortlink-codedeploy-service-role --output table
aws iam list-role-policies --role-name shortlink-ec2-role --output tableAWSCodeDeployRole. The second lists shortlink-pipeline-artifacts-read.The errors these policies prevent#
| Error text | Role to fix |
|---|---|
AccessDenied / not authorized to perform: codedeploy:… in the pipeline's Deploy action | Pipeline role: shortlink-api-deploy |
Access Denied in the CodeDeploy event DownloadBundle | shortlink-ec2-role: artifact read |
not authorized to perform: codebuild:StartBuild and no CodeBuild log exists | Pipeline role. The failure is in CodePipeline, before any build begins |
Unable to access the artifact bucket in a CodeBuild log | The CodeBuild service role |
Could not determine instances / InvalidTagFilter | The tag, or shortlink-codedeploy-service-role |
Next: run the first release.
Found a mistake? Edit this page on GitHub.