Hi, I'm trying to figure out why my build uses a different AWS_ACCESS_KEY_ID.
Here are the things I've tried so far
- I've created an AWS user for bitbucket pipeline and set AWS_ACCESS_KEY_ID(whenever I refer to this, it also includes the secret var) in the repo's Repository Variables
- at the beginning of the pipeline, I print what was the identity awscli was using by `aws sts get-caller-identity`. I got a completely different identity!
- So I removed AWS_ACCESS_KEY_ID from the Repository Variables. Same thing, still getting the wrong identity.
- I checked the workspace variables, AWS_ACCESS_KEY_ID is not set there.
- I checked my repo for all AWS related variables/script/configurations/passwords/etc but nothing. I don't commit keys in the repo.
So where else could variable AWS_ACCESS_KEY_ID be set? Am I missing something here?
Here is a snippet of my pipeline:
pipelines:
default:
- step:
name: Build & Deploy
image: node:14
caches:
- node
script:
- //do build
artifacts:
- dist/**
- step:
name: Deploy to S3
image: amazon/aws-cli
deployment: production
script:
- aws sts get-caller-identity
- ls -ltR dist/
- aws s3 sync ... --acl=public-read
- aws cloudfront create-invalidation ...