Prerequisites
- An AWS account that holds the CodeCommit repositories you want CloudThinker to reach.
- Permission to create an IAM role or IAM user in that account, and to open AWS CloudShell. AWS grants CloudShell access through the
AWSCloudShellFullAccessmanaged policy. - The AWS Region where your repositories live. A CodeCommit repository exists in one Region.
A workspace holds one AWS CodeCommit connection, and one connection covers one Region. Repositories in other Regions are not reachable through it.
Setup
Navigate to Connections → AWS CodeCommit in your CloudThinker workspace, click Connect, and choose the AWS Region where your repositories live. Then pick an authentication method.- IAM role (recommended)
- Access keys
1
Open AWS CloudShell
On the IAM Role tab, click Open CloudShell. It runs in your browser, so there is nothing to install.
2
Run the setup script
Click Copy Script to Clipboard, paste the script into CloudShell, and run it. It creates the role
CloudThinkerCodeCommitAccessRole with a trust policy that includes a unique external ID, then prints the Role ARN. The wizard also lists the same steps as manual commands.3
Paste the Role ARN
Paste the ARN into Role ARN and click Connect. CloudThinker assumes the role, lists your repositories, and shows a Connected status with the number of repositories it can reach.
Connection details
Required permissions
The setup script attaches an inline policy with these CodeCommit actions:
The policy also lets CloudThinker manage Amazon EventBridge rules whose names start with
CloudThinker-CodeCommit-, so pull request events can reach Review.
Agent capabilities
Once connected, agents can:Verify the connection
Example prompts
review or autofix.
Troubleshooting
Failed to connect to AWS CodeCommit. Please verify your credentials.
Failed to connect to AWS CodeCommit. Please verify your credentials.
CloudThinker could not use the credentials. For the IAM role method, the role’s trust policy must include the external ID the wizard shows for this connection, so re-run the script if you changed it. For access keys, check the key pair and that the user is allowed to list repositories. Also check that the AWS Region is valid, and that the workspace does not already have an AWS CodeCommit connection.
Failed to connect to AWS CodeCommit. Please try again.
Failed to connect to AWS CodeCommit. Please try again.
An unexpected error stopped the check. Try again; if it repeats, contact support.
Connected — no repositories found yet
Connected — no repositories found yet
The credentials work, but the chosen Region holds no repositories the role or user can list. Confirm the AWS Region and that the permissions above are attached.
An expected repository is missing
An expected repository is missing
Repositories in another Region do not appear. Check the AWS Region on the connection.
Review does not start on new pull requests
Review does not start on new pull requests
AWS sends no pull request events until the webhook step is done. Run the webhook script from the wizard, then mark it configured. See provider authentication.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- External ID — the role’s trust policy requires it, which protects against the confused deputy problem. AWS does not treat an external ID as a secret.
- Dedicated identity — use the IAM user or role the script creates only for CloudThinker, so you can revoke it without touching anything else.
Related
Review Setup
Turn on automated AI code reviews for your CodeCommit repositories
Provider Authentication
Authentication and webhook details for every Review provider