Skip to main content
Connect your AWS CodeCommit repositories to let CloudThinker agents list and read them, and to run Review on their pull requests. AWS CodeCommit authenticates with an IAM role (recommended) or IAM user access keys, scoped to one AWS Region.

Prerequisites

  • An AWS account that holds the CodeCommit repositories you want CloudThinker to reach.
  • Permission to create an IAM role or IAM user in that account, and to open AWS CloudShell. AWS grants CloudShell access through the AWSCloudShellFullAccess managed policy.
  • The AWS Region where your repositories live. A CodeCommit repository exists in one Region.
A workspace holds one AWS CodeCommit connection, and one connection covers one Region. Repositories in other Regions are not reachable through it.

Setup

Navigate to Connections → AWS CodeCommit in your CloudThinker workspace, click Connect, and choose the AWS Region where your repositories live. Then pick an authentication method.
AWS does not show a secret access key again after you create it. Copy it from the script output before you close CloudShell.
Review also needs pull request events from AWS. Finish the webhook step after you connect.

Connection details

Required permissions

The setup script attaches an inline policy with these CodeCommit actions: The policy also lets CloudThinker manage Amazon EventBridge rules whose names start with CloudThinker-CodeCommit-, so pull request events can reach Review.
Follow least privilege: keep the policy the script attaches and add nothing broader. Use the IAM role method so no long-lived key is stored.

Agent capabilities

Once connected, agents can:

Verify the connection

Example prompts

CodeCommit supports fewer mention commands than GitHub or GitLab: questions in top-level comments only, with no review or autofix.

Troubleshooting

CloudThinker could not use the credentials. For the IAM role method, the role’s trust policy must include the external ID the wizard shows for this connection, so re-run the script if you changed it. For access keys, check the key pair and that the user is allowed to list repositories. Also check that the AWS Region is valid, and that the workspace does not already have an AWS CodeCommit connection.
An unexpected error stopped the check. Try again; if it repeats, contact support.
The credentials work, but the chosen Region holds no repositories the role or user can list. Confirm the AWS Region and that the permissions above are attached.
Repositories in another Region do not appear. Check the AWS Region on the connection.
AWS sends no pull request events until the webhook step is done. Run the webhook script from the wizard, then mark it configured. See provider authentication.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • External ID — the role’s trust policy requires it, which protects against the confused deputy problem. AWS does not treat an external ID as a secret.
  • Dedicated identity — use the IAM user or role the script creates only for CloudThinker, so you can revoke it without touching anything else.

Review Setup

Turn on automated AI code reviews for your CodeCommit repositories

Provider Authentication

Authentication and webhook details for every Review provider