Strategic advisors

Kent Graziano

Kent Graziano

The Data Warrior, Strategic Advisor, Data Vault Master, Author, Speaker, and Tae Kwon Do Grandmaster

Gordon Wong

Gordon Wong

Leading organizations through analytics transformations, preference for social missions, healthcare, energy, education, and civic engagement

SqlDBM + AWS CodeCommit

Schema changes reach your account as commits made by an IAM identity you control — not by a database login sitting in somebody’s password manager.

THE PROBLEM

Every other change in your account is governed by a policy

In AWS you decide who can read which bucket, who can start which job, who can touch production. It’s written down, reviewed, and revoked centrally. Then there’s the database schema, which gets altered by whoever holds a warehouse login — an account no policy describes, that nothing expires, and that leaves when the person does, if anyone remembers.

  • No policy describes it. Nothing written down says who may alter a table, because the permission lives in the database rather than in IAM.
  • It doesn’t expire. A warehouse login keeps working long after the project that needed it ended.
  • It leaves with the person. Or it doesn’t, which is the worse of the two.

THE DIFFERENCE

A credential your policy actually covers

SqlDBM connects to CodeCommit with an IAM user’s access key, not a database password. Generated DDL and dbt YAML arrive as commits — or pull requests — authored by that identity, scoped by the policy you attached to it, and limited to the repositories in its organization. What happens next is your pipeline’s business: CodeBuild, CodeDeploy, CodePipeline, whatever you already run.

A comparison of how a schema change reaches an AWS account. A personal database login is granted by whoever had admin that day, reaches everything that login can see, is revoked by someone remembering to, and is recorded nowhere in particular. An IAM identity is granted by a policy you wrote, reaches only the repository actions you allowed, is revoked by changing the policy, and is recorded with the rest of your AWS activity.

IN CODECOMMIT

The author column tells you who

Pull requests SqlDBM opens are authored by the IAM user you configured, and named for the project and revision they carry. Anyone with access to the repository can see which identity made the change — not a shared account, not an anonymous push, and not somebody’s personal warehouse credentials.

CodeCommit pull requests list,
showing the Author column

Connecting AWS CodeCommit

1

Create an IAM user with programmatic access

Under Access Management → Users, create a user with programmatic access selected, and attach a policy granting read and write on the repositories it needs.

2

Copy both keys

Take the Access Key ID and the Secret Access Key when they’re shown. AWS won’t display the secret again.

3

Add the connection in SqlDBM

On the User Connections page, choose AWS CodeCommit and enter both keys.

4

Point it at a repository

Initialise a repository with at least one file on main, copy its HTTPS URL and give it to SqlDBM. You can only link repositories in the organization the secret key belongs to. Choose whether pushes open a pull request or commit directly.

If you rotate the access key, update it in User Connections or the connection stops working.

THE PAYOFF

What your security team gets

A credential with a policy

Access is described by an IAM policy you wrote, reviewed and can change, rather than by a database grant nobody documented.

Revocation that works

Detach the policy or delete the key and the connection stops. There’s no second place to remember.

An author on every change

Commits carry the identity that made them, so the repository answers who as well as what.

One less standing credential

Nobody needs a personal warehouse login in order to get a schema change reviewed.

Related Integrations

Azure DevOps

The equivalent for teams building on Azure.

GitHub

The same push workflow, outside AWS.

dbt

Source and model YAML over the same connection.

IAM user setup, key handling and repository limits, in full.

Trusted by data teams globally

400,000+ users globally

Try modeling with SqlDBM for your Enterprise