QuestionQ13

Security and Compliance

A company uses AWS CodeCommit for source-code control. Developers make changes in various feature branches and create pull requests to move those changes to the main branch when the changes are ready for production.

Developers must not be able to push changes directly to the main branch. The company applied the AWSCodeCommitPowerUser managed policy to the developers’ IAM role, and the developers can now push changes directly to the main branch in every repository in the AWS account.

What should the company do to restrict the developers’ ability to push changes directly to the main branch?

Explanation

An IAM explicit Deny overrides the Allows granted by AWSCodeCommitPowerUser. A separate customer-managed policy can deny codecommit:GitPush and codecommit:PutFile for the specified repositories when the reference is the main branch, while leaving feature-branch work permitted. AWS-managed policies cannot be edited. AWS CodeCommit’s branch-restriction guidance uses a conditional Deny to prevent updates to a branch, including pushes and pull-request merges.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!