forked from aws/aws-cdk
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat(codepipeline-actions): introduce the CodeStarConnectionsSourceAc…
…tion (aws#13781) At the same time, deprecate the unfortunately-named `BitBucketSourceAction`. Fixes aws#10632 ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
- Loading branch information
Showing
7 changed files
with
367 additions
and
125 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
139 changes: 139 additions & 0 deletions
139
packages/@aws-cdk/aws-codepipeline-actions/lib/codestar-connections/source-action.ts
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,139 @@ | ||
import * as codepipeline from '@aws-cdk/aws-codepipeline'; | ||
import * as iam from '@aws-cdk/aws-iam'; | ||
|
||
import { Action } from '../action'; | ||
import { sourceArtifactBounds } from '../common'; | ||
|
||
// keep this import separate from other imports to reduce chance for merge conflicts with v2-main | ||
// eslint-disable-next-line no-duplicate-imports, import/order | ||
import { Construct } from '@aws-cdk/core'; | ||
|
||
/** | ||
* Construction properties for {@link CodeStarConnectionsSourceAction}. | ||
*/ | ||
export interface CodeStarConnectionsSourceActionProps extends codepipeline.CommonAwsActionProps { | ||
/** | ||
* The output artifact that this action produces. | ||
* Can be used as input for further pipeline actions. | ||
*/ | ||
readonly output: codepipeline.Artifact; | ||
|
||
/** | ||
* The ARN of the CodeStar Connection created in the AWS console | ||
* that has permissions to access this BitBucket repository. | ||
* | ||
* @example 'arn:aws:codestar-connections:us-east-1:123456789012:connection/12345678-abcd-12ab-34cdef5678gh' | ||
* @see https://docs.aws.amazon.com/codepipeline/latest/userguide/connections-create.html | ||
*/ | ||
readonly connectionArn: string; | ||
|
||
/** | ||
* The owning user or organization of the repository. | ||
* | ||
* @example 'aws' | ||
*/ | ||
readonly owner: string; | ||
|
||
/** | ||
* The name of the repository. | ||
* | ||
* @example 'aws-cdk' | ||
*/ | ||
readonly repo: string; | ||
|
||
/** | ||
* The branch to build. | ||
* | ||
* @default 'master' | ||
*/ | ||
readonly branch?: string; | ||
|
||
// long URL in @see | ||
/** | ||
* Whether the output should be the contents of the repository | ||
* (which is the default), | ||
* or a link that allows CodeBuild to clone the repository before building. | ||
* | ||
* **Note**: if this option is true, | ||
* then only CodeBuild actions can use the resulting {@link output}. | ||
* | ||
* @default false | ||
* @see https://docs.aws.amazon.com/codepipeline/latest/userguide/action-reference-CodestarConnectionSource.html#action-reference-CodestarConnectionSource-config | ||
*/ | ||
readonly codeBuildCloneOutput?: boolean; | ||
|
||
/** | ||
* Controls automatically starting your pipeline when a new commit | ||
* is made on the configured repository and branch. If unspecified, | ||
* the default value is true, and the field does not display by default. | ||
* | ||
* @default true | ||
* @see https://docs.aws.amazon.com/codepipeline/latest/userguide/action-reference-CodestarConnectionSource.html | ||
*/ | ||
readonly triggerOnPush?: boolean; | ||
} | ||
|
||
/** | ||
* A CodePipeline source action for the CodeStar Connections source, | ||
* which allows connecting to GitHub and BitBucket. | ||
*/ | ||
export class CodeStarConnectionsSourceAction extends Action { | ||
/** | ||
* The name of the property that holds the ARN of the CodeStar Connection | ||
* inside of the CodePipeline Artifact's metadata. | ||
* | ||
* @internal | ||
*/ | ||
public static readonly _CONNECTION_ARN_PROPERTY = 'CodeStarConnectionArnProperty'; | ||
|
||
private readonly props: CodeStarConnectionsSourceActionProps; | ||
|
||
constructor(props: CodeStarConnectionsSourceActionProps) { | ||
super({ | ||
...props, | ||
category: codepipeline.ActionCategory.SOURCE, | ||
owner: 'AWS', // because props also has a (different!) owner property! | ||
provider: 'CodeStarSourceConnection', | ||
artifactBounds: sourceArtifactBounds(), | ||
outputs: [props.output], | ||
}); | ||
|
||
this.props = props; | ||
} | ||
|
||
protected bound(_scope: Construct, _stage: codepipeline.IStage, options: codepipeline.ActionBindOptions): codepipeline.ActionConfig { | ||
// https://docs.aws.amazon.com/codepipeline/latest/userguide/security-iam.html#how-to-update-role-new-services | ||
options.role.addToPolicy(new iam.PolicyStatement({ | ||
actions: [ | ||
'codestar-connections:UseConnection', | ||
], | ||
resources: [ | ||
this.props.connectionArn, | ||
], | ||
})); | ||
|
||
// the action needs to write the output to the pipeline bucket | ||
options.bucket.grantReadWrite(options.role); | ||
options.bucket.grantPutAcl(options.role); | ||
|
||
// if codeBuildCloneOutput is true, | ||
// save the connectionArn in the Artifact instance | ||
// to be read by the CodeBuildAction later | ||
if (this.props.codeBuildCloneOutput === true) { | ||
this.props.output.setMetadata(CodeStarConnectionsSourceAction._CONNECTION_ARN_PROPERTY, | ||
this.props.connectionArn); | ||
} | ||
|
||
return { | ||
configuration: { | ||
ConnectionArn: this.props.connectionArn, | ||
FullRepositoryId: `${this.props.owner}/${this.props.repo}`, | ||
BranchName: this.props.branch ?? 'master', | ||
OutputArtifactFormat: this.props.codeBuildCloneOutput === true | ||
? 'CODEBUILD_CLONE_REF' | ||
: undefined, | ||
DetectChanges: this.props.triggerOnPush, | ||
}, | ||
}; | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.