Following https://support.atlassian.com/bitbucket-cloud/docs/deploy-on-aws-using-bitbucket-pipelines-openid-connect I've been able to setup a pipeline with a `bitbucket-pipelines.yml` statement:
pipelines:
default:
- parallel:
- step:
name: Build and Test
deployment: Test
image:
name: 242011367797.dkr.ecr.ap-southeast-2.amazonaws.com/datallama/bitbucket_pipeline:0.3
aws:
oidc-role: arn:aws:iam::242011367797:role/dl_ecr_admin
oidc: true
script:
- export AWS_REGION=ap-southeast-2
- ./containers.sh --pipeline --container-engine docker --version $BITBUCKET_BUILD_NUMBER
#- pipe: atlassian/aws-ecr-push-image:2.3.0
# variables:
# IMAGE_NAME: 242011367797.dkr.ecr.ap-southeast-2.amazonaws.com/datallama/test/dlmvp_658/mytest2:${BITBUCKET_BUILD_NUMBER}
The setup has permitted me to pull the image from the ecr private repository, however I have failed to use the `aws ecr describe-repositories` or `docker login` with this credential witin the script file `containers.sh` - the former hits the following error:
<span>aws ecr describe-repositories --region ap-southeast-2 --repository-names <a href="http://242011367797.dkr.ecr.ap-southeast-2.amazonaws.com/datallama/test/dlmvp_658/mytest2" rel="noopener nofollow noreferrer" target="_blank">242011367797.dkr.ecr.ap-southeast-2.amazonaws.com/datallama/test/dlmvp_658/mytest2</a></span>
<span>An error occurred (UnrecognizedClientException) when calling <br>the DescribeRepositories operation: <br>The security token included in the request is invalid.'</span>
I'm baffled because the role is visible as I've proven credentials are pushed into the session with is visible with
<span>+ aws configure list</span>
<span>Name Value Type Location</span>
<span>---- ----- ---- --------</span>
<span>profile <not set> None None</span>
<span>access_key ****************TUMK env </span>
<span>secret_key ****************dQo= env </span>
<span>ap-southeast-2 env ['AWS_REGION', 'AWS_DEFAULT_REGION']</span>
and the role includes the following permissions:
AmazonEC2ContainerRegistryFullAccess
AmazonElasticContainerRegistryPublicFullAccess
*note* hopefully irrelevant, but I am using custom containers so that I had the most recent awscli and git binaries
# aws --version && git --version
aws-cli/2.15.15 Python/3.11.6 Linux/6.6.13-200.fc39prompt/off
git version 2.29.0
built with the following docker file:
FROM atlassian/default-image
RUN apt remove --yes git
RUN add-apt-repository --yes ppa:git-core/ppa
RUN apt update --yes
RUN apt install --yes git
RUN curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "/tmp/awscliv2.zip" \
&& unzip -d /tmp/ /tmp/awscliv2.zip \
&& /tmp/aws/install \
&& rm -rf /tmp/{aws,awscliv2.zip}
Ideas?