I followed the following tutorial to create a Lambda deploy pipeline using CDK. When I try to keep everything in the same account it works well. https://docs.aws.amazon.com/cdk/latest/guide/codepipeline_example.html
But my scenario is slightly different from the example because it involves two AWS accounts instead one. I maintain application source code and pipeline in the OPS account and this pipeline will deploy the Lambda application to the UAT account.
OPS Account (12345678) - CodeCommit repo & CodePipeline UAT Account (87654321) - Lambda application
As per the aws following aws documentation (Cross-account actions section) I made the following changes to source code. https://docs.aws.amazon.com/cdk/api/latest/docs/aws-codepipeline-actions-readme.html
Lambda stack expose deploy action role as follows
export class LambdaStack extends cdk.Stack { public readonly deployActionRole: iam.Role; constructor(scope: cdk.Construct, id: string, props?: cdk.StackProps) { ... this.deployActionRole = new iam.Role(this, 'ActionRole', { assumedBy: new iam.AccountPrincipal('12345678'), //pipeline account // the role has to have a physical name set roleName: 'DeployActionRole', }); } }In the pipeline stack,
new codePipeline.Pipeline(this, 'MicroServicePipeline', { pipelineName: 'MicroServicePipeline', stages: [ { stageName: 'Deploy', actions: [ new codePipelineAction.CloudFormationCreateUpdateStackAction({ role: props.deployActionRole, .... }) ] } ] });Following is how I initiate stacks
const app = new cdk.App(); const opsEnv: cdk.Environment = {account: '12345678', region: 'ap-southeast-2'}; const uatEnv: cdk.Environment = {account: '87654321', region: 'ap-southeast-2'}; const lambdaStack = new LambdaStack(app, 'LambdaStack', {env: uatEnv}); const lambdaCode = lambdaStack.lambdaCode; const deployActionRole = lambdaStack.deployActionRole; new MicroServicePipelineStack(app, 'MicroServicePipelineStack', { env: opsEnv, stackName: 'MicroServicePipelineStack', lambdaCode, deployActionRole }); app.synth();AWS credentials profiles looks liks
[profile uatadmin] role_arn=arn:aws:iam::87654321:role/PigletUatAdminRole source_profile=opsadmin region=ap-southeast-2
when I run cdk diff or deploy I get an error saying,
➜ infra git:(master) ✗ cdk diff MicroServicePipelineStack --profile uatadmin
Including dependency stacks: LambdaStack
Stack LambdaStack
Need to perform AWS calls for account 87654321, but no credentials have been configured.
What have I done wrong here? Is it my CDK code or is it the way I have configured my AWS profile?
Thanks, Kasun