> For the complete documentation index, see [llms.txt](https://oklencodes.gitbook.io/untitled/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://oklencodes.gitbook.io/untitled/devops/creating-a-codebuild-project-and-getting-the-output-with-cloudwatch-logs/iam.md).

# IAM

Click on Policies, then Create policy. Following that, the next screen click on the JSON button then copy and paste the code below then click Next.

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Resource": [
                "*"
            ],
            "Action": [
                "logs:CreateLogGroup",
                "logs:CreateLogStream",
                "logs:PutLogEvents",
                "logs:List*",
                "logs:Get*",
                "logs:Describe*"
            ]
        },
        {
            "Effect": "Allow",
            "Resource": [
                "*"
            ],
            "Action": [
                "s3:PutObject",
                "s3:Get*",
                "s3:List*"
            ]
        },
        {
            "Effect": "Allow",
            "Action": [
                "codebuild:CreateReportGroup",
                "codebuild:CreateReport",
                "codebuild:UpdateReport",
                "codebuild:BatchPutTestCases",
                "codebuild:Get*",
                "codebuild:Describe*",
                "codebuild:Batch*",
                "codebuild:List*",
                "codebuild:BatchPutCodeCoverages"
            ],
            "Resource": [
                "*"
            ]
        }
    ]
}    
```

<figure><img src="https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2F37TZqBnXLnDDuU8DCUlE%2Fimage.png?alt=media&amp;token=d296b2c5-1161-4561-8158-cffa6e83fd42" alt=""><figcaption></figcaption></figure>

Once the whole JSON has been copied and reviewed. The policy can be reviewed and created

<figure><img src="https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FAWORVs6JSfn8yXKtzOM9%2Fimage.png?alt=media&amp;token=a98aa7d4-3189-4086-81da-a2dc93b97946" alt=""><figcaption></figcaption></figure>

Permissions defined in the policy because of the Json output should be:

<figure><img src="https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FW3z7pDhFtmoXXwOzNMno%2Fimage.png?alt=media&amp;token=9e6ac14a-92b9-44c3-8b04-87f905e7ff3d" alt=""><figcaption></figcaption></figure>

Next in IAM roles, select create role then for trust entity select AWS Service

<figure><img src="https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FSlwhL1UMDal38Horz1Je%2Fimage.png?alt=media&amp;token=ff85485d-6d5f-430d-b272-99e8dfc194f7" alt=""><figcaption></figcaption></figure>

and use case is CodeBuild.

For permissions should only need Codebuild-policy before selecting next

<figure><img src="https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FtGLJBjI9oXqww6okxrOV%2Fimage.png?alt=media&amp;token=c0f436ac-f3d6-483b-96b3-a74994b9fa43" alt=""><figcaption></figcaption></figure>

For simplicity i’ve named it CodeBuild-Role

<figure><img src="https://2022164620-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtzurpgroDJSMn9AFVmQP%2Fuploads%2FtNiJBYj1dO1CxacjGnMu%2Fimage.png?alt=media&amp;token=3986b9c4-08fe-4b95-a3d6-629c49862d92" alt=""><figcaption></figcaption></figure>

<br>

<br>
