Conversation
Contributor
Please make sure your PR references an existing issue using the format |
aws-cdk-automation
requested changes
Sep 20, 2026
aws-cdk-automation
left a comment
Collaborator
There was a problem hiding this comment.
The pull request linter fails with the following errors:
❌ Fixes must contain a change to an integration test file and the resulting snapshot.
If you believe this pull request should receive an exemption, please comment and provide a justification. A comment requesting an exemption should contain the text Exemption Request. Additionally, if clarification is needed, add Clarification Request to a comment.
1 task
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue # (if applicable)
Closes #21156
Reason for this change
A newly created pipeline can start an execution before CloudFormation finishes creating or updating an action role's IAM policy. A CodeBuild action can then fail its first
codebuild:StartBuildcall because the policy is not attached yet; retrying after deployment succeeds.Description of changes
Action binding now carries the IAM policy dependencies returned by role grants to the underlying
CfnPipeline. This covers CodeBuild actions and AWS-owned source actions backed by CodeCommit, CodeStar Connections, ECR, and S3. The pipeline waits on the specific policy resources changed during binding; it does not depend on entire role construct trees.The change supports generated roles, supplied mutable roles, and mutable imported roles. A mutable imported role in another stack now orders the pipeline stack after the stack that creates its policy. An immutable imported role does not gain a synthesized policy. Cross-account and cross-stack synthesis is covered, including dependency-cycle checks.
The IAM statements and resource scopes are unchanged, and no CloudFormation resource logical IDs change. CloudFormation ordering only waits for the IAM resource operation to finish; IAM propagation is eventually consistent, so this cannot guarantee that the permission is immediately available to the first pipeline execution.
Describe any new or updated permissions being added
None. Existing IAM permissions are unchanged.
Description of how you validated changes
git diff --checkpasses.@aws-cdk/asset-awscli-v12.2.292 declared but 2.2.282 installed, and package lint/typecheck report missing generated modules. The full action pipeline test file also has one unrelated CloudFormation validation failure for an existingAction3with no input artifact; the other 15 tests pass.Checklist
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license