A company uses AWS CodePipeline for CI/CD. A recent pipeline execution failed at the 'Deploy' stage with the error 'Action execution failed: Access Denied'. The pipeline uses an IAM service role. Which THREE checks should the engineer perform to resolve this?
CodePipeline executes deploy actions by assuming a dedicated IAM service role, and that role must contain an identity-based policy granting the required API permissions (e.g., codedeploy:CreateDeployment, ecs:UpdateService, or cloudformation:CreateStack) on the target resource. If a required permission is missing or explicitly denied, the deploy stage fails with an AccessDenied error even though every other pipeline configuration is correct. You should review the pipeline execution details to identify the specific denied action, then attach an appropriate managed or inline policy to the service role.
Why this answer
The 'Access Denied' error at the Deploy stage indicates a permissions issue. The correct checks are: B) Verify that the IAM service role has sufficient permissions for the deploy action on the target resource, as the role must have the necessary IAM policies to perform deployments. C) Ensure the artifact store S3 bucket has a bucket policy that allows the pipeline role to access it, because the pipeline needs to read artifacts from the bucket.
E) Confirm that the service role's trust policy allows CodePipeline to assume the role, since the trust policy must grant the `sts:AssumeRole` permission to the CodePipeline service. Option A is incorrect because CloudWatch Events rules trigger pipeline execution but are not related to the deploy stage's access denied error. Option D is incorrect because S3 event notifications trigger the pipeline on code changes, not resolve deployment failures.