A company uses AWS CodeCommit for source-code control. Developers make changes in various feature branches and create pull requests to move those changes to the main branch when the changes are ready for production.
Developers must not be able to push changes directly to the main branch. The company applied the AWSCodeCommitPowerUser managed policy to the developers’ IAM role, and the developers can now push changes directly to the main branch in every repository in the AWS account.
What should the company do to restrict the developers’ ability to push changes directly to the main branch?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion