Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
235 changes: 160 additions & 75 deletions docs/admin/code_hosts/aws_codecommit.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -34,86 +34,171 @@ AWS CodeCommit connections support the following configuration options, which ar

{/* SCHEMA_SYNC_START: admin/code_hosts/aws_codecommit.schema.json */}
{/* WARNING: This section is auto-generated during releases. Do not edit manually. */}
{/* Last updated: Manual setup - will be automated via sourcegraph/sourcegraph releases */}
{/* Last updated: 2025-07-01T19:22:27Z via sourcegraph/sourcegraph@v6.5.1211 */}
```json
{
// The AWS access key ID to use when listing and updating repositories from AWS CodeCommit. Must have the AWSCodeCommitReadOnly IAM policy.
"accessKeyID": null,

// A list of repositories to never mirror from AWS CodeCommit.
//
// Supports excluding by name ({"name": "git-codecommit.us-west-1.amazonaws.com/repo-name"}) or by ARN ({"id": "arn:aws:codecommit:us-west-1:999999999999:name"}).
"exclude": null,
// Other example values:
// - [
// {
// "name": "go-monorepo"
// },
// {
// "id": "f001337a-3450-46fd-b7d2-650c0EXAMPLE"
// }
// ]
// - [
// {
// "name": "go-monorepo"
// },
// {
// "name": "go-client"
// }
// ]

// The Git credentials used for authentication when cloning an AWS CodeCommit repository over HTTPS.
//
// See the AWS CodeCommit documentation on Git credentials for CodeCommit: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_ssh-keys.html#git-credentials-code-commit.
// For detailed instructions on how to create the credentials in IAM, see this page: https://docs.aws.amazon.com/codecommit/latest/userguide/setting-up-gc.html
"gitCredentials": null,

// Deprecated and ignored field which will be removed entirely in the next release. AWS CodeCommit repositories can no longer be enabled or disabled explicitly. Configure which repositories should not be mirrored via "exclude" instead.
"initialRepositoryEnablement": false,

// The AWS region in which to access AWS CodeCommit. See the list of supported regions at https://docs.aws.amazon.com/codecommit/latest/userguide/regions.html#regions-git.
"region": "us-east-1",

// The pattern used to generate a the corresponding Sourcegraph repository name for an AWS CodeCommit repository. In the pattern, the variable "{name}" is replaced with the repository's name.
//
// For example, if your Sourcegraph instance is at https://src.example.com, then a repositoryPathPattern of "awsrepos/{name}" would mean that a AWS CodeCommit repository named "myrepo" is available on Sourcegraph at https://src.example.com/awsrepos/myrepo.
//
// It is important that the Sourcegraph repository name generated with this pattern be unique to this code host. If different code hosts generate repository names that collide, Sourcegraph's behavior is undefined.
"repositoryPathPattern": "{name}",
// Other example values:
// - "git-codecommit.us-west-1.amazonaws.com/{name}"
// - "git-codecommit.eu-central-1.amazonaws.com/{name}"

// The AWS secret access key (that corresponds to the AWS access key ID set in `accessKeyID`).
"secretAccessKey": null
}
```

## Setup steps for SSH connections to AWS CodeCommit repositories

To add CodeCommit repositories in Docker Container:

1. Generate a public/private rsa key pair that does not require passphrase as listed in the [Step 3.1 of the AWS SSH setup guide](https://docs.aws.amazon.com/codecommit/latest/userguide/setting-up-ssh-unixes.html#setting-up-ssh-unixes-keys). Sourcegraph does not work with the key pair that requires passphrase.
1. Follow the rest of the steps detailed in the [AWS SSH setup guide](https://docs.aws.amazon.com/codecommit/latest/userguide/setting-up-ssh-unixes.html) to make sure you can connect to the code host locally.
1. Confirm you have the connection by running the following ssh command locally: `ssh git-codecommit.us-west-1.amazonaws.com` (Update link with your server region)
1. Confirm you can clone the repository locally.

### Configuring SSH credentials in the Web UI

```json
{
"gitURLType": "ssh",
"gitSSHKeyID": "<SSH key ID>",
"gitSSHCredential": {
// make sure the key is base64 encoded
// $ cat ~/.ssh/id_rsa | base64
"privateKey": "<base64 encoded of the SSH private key>",
"passphrase": "<passphrase if applicable, omit if none is needed>"
}
"$id": "aws_codecommit.schema.json#",
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"allowComments": true,
"description": "Configuration for a connection to AWS CodeCommit.",
"properties": {
"accessKeyID": {
"description": "The AWS access key ID to use when listing and updating repositories from AWS CodeCommit. Must have the AWSCodeCommitReadOnly IAM policy.",
"type": "string"
},
"exclude": {
"description": "A list of repositories to never mirror from AWS CodeCommit. \n\nSupports excluding by name ({\"name\": \"git-codecommit.us-west-1.amazonaws.com/repo-name\"}) or by ARN ({\"id\": \"arn:aws:codecommit:us-west-1:999999999999:name\"}).",
"examples": [
[
{
"name": "go-monorepo"
},
{
"id": "f001337a-3450-46fd-b7d2-650c0EXAMPLE"
}
],
[
{
"name": "go-monorepo"
},
{
"name": "go-client"
}
]
],
"items": {
"additionalProperties": false,
"anyOf": [
{
"required": [
"name"
]
},
{
"required": [
"id"
]
}
],
"properties": {
"id": {
"description": "The ID of an AWS Code Commit repository (as returned by the AWS API) to exclude from mirroring. Use this to exclude the repository, even if renamed, or to differentiate between repositories with the same name in multiple regions.",
"pattern": "^[\\w-]+$",
"type": "string"
},
"name": {
"description": "The name of an AWS CodeCommit repository (\"repo-name\") to exclude from mirroring.",
"pattern": "^[\\w.-]+$",
"type": "string"
}
},
"title": "ExcludedAWSCodeCommitRepo",
"type": "object"
},
"minItems": 1,
"type": "array"
},
"gitCredentials": {
"description": "The Git credentials used for authentication when cloning an AWS CodeCommit repository over HTTPS.\n\nSee the AWS CodeCommit documentation on Git credentials for CodeCommit: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_ssh-keys.html#git-credentials-code-commit.\nFor detailed instructions on how to create the credentials in IAM, see this page: https://docs.aws.amazon.com/codecommit/latest/userguide/setting-up-gc.html",
"properties": {
"password": {
"description": "The Git password",
"minLength": 1,
"type": "string"
},
"username": {
"description": "The Git username",
"minLength": 1,
"type": "string"
}
},
"required": [
"username",
"password"
],
"title": "AWSCodeCommitGitCredentials",
"type": "object"
},
"gitSSHCipher": {
"$ref": "git.schema.json#/definitions/gitSSHCipher",
"description": "SSH cipher to use when cloning via SSH. Must be a valid choice from `ssh -Q cipher`."
},
"gitSSHCredential": {
"$ref": "git.schema.json#/definitions/gitSSHCredential",
"description": "SSH keys to use when cloning Git repo."
},
"gitSSHKeyID": {
"description": "The ID of the SSH key created for your IAM users. It is required when using SSH to clone repositories.",
"type": "string"
},
"gitURLType": {
"default": "http",
"description": "The type of Git URLs to use for cloning and fetching Git repositories.",
"enum": [
"http",
"ssh"
],
"type": "string"
},
"initialRepositoryEnablement": {
"default": false,
"description": "Deprecated and ignored field which will be removed entirely in the next release. AWS CodeCommit repositories can no longer be enabled or disabled explicitly. Configure which repositories should not be mirrored via \"exclude\" instead.",
"type": "boolean"
},
"maxDeletions": {
"default": 0,
"description": "The maximum number of repos that will be deleted per sync. A value of 0 or less indicates no maximum.",
"type": "integer"
},
"region": {
"default": "us-east-1",
"description": "The AWS region in which to access AWS CodeCommit. See the list of supported regions at https://docs.aws.amazon.com/codecommit/latest/userguide/regions.html#regions-git.",
"enum": [
"ap-northeast-1",
"ap-northeast-2",
"ap-south-1",
"ap-southeast-1",
"ap-southeast-2",
"ca-central-1",
"eu-central-1",
"eu-west-1",
"eu-west-2",
"eu-west-3",
"sa-east-1",
"us-east-1",
"us-east-2",
"us-west-1",
"us-west-2"
],
"pattern": "^[a-z\\d-]+$",
"type": "string"
},
"repositoryPathPattern": {
"default": "{name}",
"description": "The pattern used to generate a the corresponding Sourcegraph repository name for an AWS CodeCommit repository. In the pattern, the variable \"{name}\" is replaced with the repository's name.\n\nFor example, if your Sourcegraph instance is at https://src.example.com, then a repositoryPathPattern of \"awsrepos/{name}\" would mean that a AWS CodeCommit repository named \"myrepo\" is available on Sourcegraph at https://src.example.com/awsrepos/myrepo.\n\nIt is important that the Sourcegraph repository name generated with this pattern be unique to this code host. If different code hosts generate repository names that collide, Sourcegraph's behavior is undefined.",
"examples": [
"git-codecommit.us-west-1.amazonaws.com/{name}",
"git-codecommit.eu-central-1.amazonaws.com/{name}"
],
"type": "string"
},
"secretAccessKey": {
"description": "The AWS secret access key (that corresponds to the AWS access key ID set in `accessKeyID`).",
"type": "string"
}
},
"required": [
"region",
"accessKeyID",
"secretAccessKey",
"gitCredentials"
],
"title": "AWSCodeCommitConnection",
"type": "object"
}
```
{/* SCHEMA_SYNC_END: admin/code_hosts/aws_codecommit.schema.json */}

## Configuration Notes

### Git Credentials Requirement
Expand Down
Loading