Find and fixAccess to your assetsAWS CodeCommit

AWS CodeCommit

Last updated: Sep 30, 2026


To give Fluid Attacks access to your CodeCommit repositories, make an IAM role with cross-account access.

The role creation has these steps:

  1. Get the external ID that Fluid Attacks makes for your organization. To do this, open the platform. Go to Credentials > Add credentials > Add manually. Select AWS Role as the credentials type.
  2. Make the IAM role with that external ID as a shared secret. The secret confirms that the role assumption requests come from Fluid Attacks.
  3. Add the Amazon Resource Name (ARN) of the role in the Fluid Attacks platform.

You can make the role with one of these methods:

Manual configuration from AWS Management Console

Follow these steps to make the role in the AWS user interface:

  1. Sign in to the AWS Management Console. Use an account with permissions to make IAM roles and attach policies.

  2. In the search bar, find the IAM service. Open it.

    Select IAM for integration with Fluid Attacks platform
  3. In the IAM Dashboard, click Roles in the left sidebar menu.

    Go to Roles for integration with Fluid Attacks platform
  4. Click Create role.

    Create IAM role for integration with Fluid Attacks platform
  5. In the Trusted entity type section, select Custom trust policy.

    Set IAM Role policy for Fluid Attacks integration
  6. In the code editor below, paste this JSON policy:

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "FluidAttacksAccess",
          "Effect": "Allow",
          "Principal": {
            "AWS": "*"
          },
          "Action": "sts:AssumeRole",
          "Condition": {
            "ArnEquals": {
              "aws:PrincipalArn": "arn:aws:iam::205810638802:role/prod_integrates"
            },
            "StringEquals": {
              "sts:ExternalId": "<YOUR-EXTERNAL-ID>"
            }
          }
        }
      ]
    }

Replace <YOUR-EXTERNAL-ID> with the external ID that Fluid Attacks made for your organization.

Elements of the trust policy: The trust policy has four primary elements:

  • Principal ("AWS": "*"): This field lets all AWS accounts assume the role. The conditions below limit the actual access.
  • Action (sts:AssumeRole): This field lets external entities assume the role.
  • Condition (aws:PrincipalArn): This condition limits the role assumption to the production role of Fluid Attacks only (arn:aws:iam::205810638802:role/prod_integrates).
  • Shared secret (sts:ExternalId): Fluid Attacks and your organization share this secret. It confirms that the assumption requests come from Fluid Attacks. This prevents unauthorized access.
  1. Give permissions to the role: Click Next to open the permissions configuration. You can select the ReadOnlyAccess permission. But step 8 shows a recommended user-managed policy to clone CodeCommit repositories.

    Select ReadOnlyAccess for Fluid Attacks integration
  2. Make or attach a policy that gives access to your CodeCommit repositories. Fluid Attacks recommends this policy, which follows the principle of least privilege:

    {
      "Version": "2012-10-17",
      "Statement": [
        {
          "Sid": "CodeCommitAccess",
          "Effect": "Allow",
          "Action": ["codecommit:Get*", "codecommit:GitPull"],
          "Resource": ["<REPO-ARN>"]
        }
      ]
    }

    Replace <REPO-ARN> with the ARN of your repository. To give access to some repositories, add their ARNs to the Resource array.

  3. Click Next to examine the role configuration.

  4. Type a name for the role, for example "FluidAttacksCodeCommit". Add a description.

    Enter Role name for Fluid Attacks integration
  5. Click Create role.

  6. Find your new role in the IAM roles list. Click it to see its details.

  7. Copy the ARN (Amazon Resource Name) at the top of the role summary. This value is necessary to complete the configuration in the Fluid Attacks platform.

    Get IAM Role ARN for Fluid Attacks integration

Use AWS CloudFormation templates

You can automate the role creation with AWS CloudFormation. This method fits infrastructure-as-code workflows and multi-account deployments.

First, make the template. Then deploy it with one of these options:

Make the CloudFormation template

  1. Make a new file with the .yaml extension.

  2. Copy this CloudFormation template into the file:

    Resources:
      CodeCommitAccessRole:
        Type: AWS::IAM::Role
        Properties:
          AssumeRolePolicyDocument:
            Version: "2012-10-17"
            Statement:
              - Effect: Allow
                Action:
                  - "sts:AssumeRole"
                Principal:
                  AWS:
                    - "*"
                Condition:
                  ArnEquals:
                    aws:PrincipalArn: "arn:aws:iam::205810638802:role/prod_integrates"
                  StringEquals:
                    sts:ExternalId: "<YOUR-EXTERNAL-ID>"
          Description: Role to grant Fluid Attacks access to CodeCommit repositories
          ManagedPolicyArns:
            - arn:aws:iam::aws:policy/AWSCodeCommitReadOnly
          RoleName: FluidAttacksCodeCommit
  3. Replace <YOUR-EXTERNAL-ID> with the external ID that Fluid Attacks made for your organization.

  4. Save the file.

Deploy with the AWS CLI

  1. If you do not have the AWS CLI, install it.

  2. Configure your security credentials (AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY). Use a user with permissions to make CloudFormation stacks and IAM resources.

  3. Run this command to deploy the stack:

    aws cloudformation deploy --template-file <path/to/template.yaml> \
      --stack-name <stack-name> \
      --capabilities CAPABILITY_NAMED_IAM

Replace <path/to/template.yaml> with the path to your template file. Replace <stack-name> with a descriptive name, for example fluid-attacks-codecommit.

  1. After the deployment completes, get the role ARN with this command:

    aws iam get-role --role-name "FluidAttacksCodeCommit"

    The command returns a JSON response with the role details, with the ARN.

Deploy with the AWS Management Console

  1. Sign in to the AWS Management Console. Use an account with read and write permissions for CloudFormation and IAM resources.

  2. In the search bar, find the CloudFormation service. Open it.

    Find CloudFormation to setup Fluid Attacks integration
  3. In the CloudFormation Dashboard, click the Create stack dropdown. Select With new resources (standard).

    Create stack for Fluid Attacks integration
  4. In Prerequisite - Prepare template, select Template is ready. In Specify template, select Upload a template file. Click Choose file. Select the template that you made.

    Create stack from template for Fluid Attacks integration
  5. Click Next.

  6. Type a name for the stack. Click Next.

    Name the stack for Fluid Attacks integration
  7. On the Configure stack options page, keep the default settings. Click Next.

  8. On the review page, scroll to the Capabilities section at the bottom. Check the box to acknowledge that CloudFormation can make IAM resources with custom names.

    Set CloudFormation Capabilities for Fluid Attacks integration
  9. Click Submit to start the deployment. Wait until the stack status shows "CREATE_COMPLETE".

  10. Go to the Resources tab. Click the Physical ID link of the role resource. This opens the IAM Dashboard.

  11. Copy the ARN from the role summary. Use it in the Fluid Attacks platform.

Troubleshooting

If you have problems when you add your AWS environment to the Fluid Attacks platform, check these items:

  • Role permissions: Make sure that the role has the AWSCodeCommitReadOnly managed policy. Or make sure that your custom policy includes the codecommit:Get* and codecommit:GitPull actions for the target repositories.
  • External ID: Make sure that the external ID in the trust policy of your role matches the external ID that Fluid Attacks assigned to your organization. If the two IDs are not the same, the role assumption fails.
  • Custom KMS keys: Repositories with encryption from a custom Customer Managed Key (CMK) in AWS KMS can fail to clone with authentication errors (403). Custom KMS keys must have explicit decrypt permissions for the CodeCommit service and for each user that clones the repository. Solutions:
    • Change to AWS Managed Keys: Change the encryption settings of your repository to the default AWS managed key (aws/codecommit). This key handles all the necessary permissions.
    • If you keep a custom CMK: Make sure that your KMS key policy gives decrypt permissions to CodeCommit, and that the IAM users have kms:Decrypt on the key. See AWS KMS Key Policies.

On this page