An extra 30% off every course until Sunday, October 11.Choose your certification →

Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.1.1.1. Code, Image, and Artifact Repositories (CodeCommit, ECR, S3)

2.1.1.1. Code, Image, and Artifact Repositories (CodeCommit, ECR, S3)

Every CI/CD pipeline starts with a source of truth. If your team can't answer "what exact version of code is running in production right now?" — your repository strategy has failed. AWS provides three purpose-built repository types:

AWS CodeCommit hosts private Git repositories with IAM-based access control (no SSH key management), encryption at rest via KMS, and native integration with CodePipeline triggers. It supports standard Git operations including branching, pull requests, and approval rules.

⚠️ CodeCommit Status: In July 2024 AWS stopped onboarding new CodeCommit customers, then reversed that decision and returned CodeCommit to general availability on November 24, 2025, with new customers accepted again. Third-party Git providers (GitHub, GitLab, Bitbucket) connect to CodePipeline through CodeConnections, so expect scenarios using both.

Amazon ECR stores Docker container images with built-in vulnerability scanning (scanOnPush), lifecycle policies for automatic cleanup of untagged images, and cross-region/cross-account replication. ECR integrates natively with ECS, EKS, and Lambda for container deployments.

Amazon S3 serves as general-purpose artifact storage for deployment packages, static assets, and pipeline outputs. Use versioning to preserve every artifact version and lifecycle policies to archive or delete old artifacts.

Exam Trap: CodePipeline's Source stage accepts CodeCommit, ECR, S3, and third-party providers (GitHub, Bitbucket) — but each has different trigger mechanisms. CodeCommit uses CloudWatch Events (EventBridge) for change detection, ECR source actions use an EventBridge rule on image push, and S3 uses CloudTrail event logging on PutObject (which then reaches the pipeline through an EventBridge rule). If CloudTrail isn't enabled for the S3 bucket, the pipeline won't trigger.

# CodePipeline source action for S3 (requires CloudTrail)
- Name: SourceAction
  ActionTypeId:
    Category: Source
    Provider: S3
  Configuration:
    S3Bucket: my-artifact-bucket
    S3ObjectKey: app/source.zip
    PollForSourceChanges: false  # Use CloudTrail events instead

💡 Tip: Use ECR lifecycle policies aggressively — untagged images accumulate fast and drive up storage costs. A common policy keeps only the last 10 tagged images per repository. A policy can hold several rules evaluated in rulePriority order (lowest number first); each selects images by tag status/tag prefix and expires them by count (imageCountMoreThan) or age (sinceImagePushed), and an image matched by a higher-priority rule can't be expired by a lower-priority one. ECR storage is not an S3 bucket you can attach S3 lifecycle rules to.

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications