mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-09-30 09:23:11 +00:00
fix(iam): grant deploy roles s3 encryption-config actions
payments-dashboard's BoaRawBucket (first bucket in the org with an explicit BucketEncryption block) failed CREATE: the CFN execution role lacked s3:PutEncryptionConfiguration. Adds the Get/Put pair to the shared s3-management statement (bucket-level, existing * scope). Escalation review: the role holds no kms:* actions anywhere, so the PutEncryptionConfiguration + PutBucketPolicy combination cannot pivot to a role-controlled KMS key; SCPs permit the action (the original denial was identity-policy). GPT-4.1 cross-family review: FIX-level only, dispositioned above. Stack deployed before merge per README. Refs: payments-dashboard#76
This commit is contained in:
parent
a960fd8fd7
commit
1b21945c6e
1 changed files with 4 additions and 0 deletions
|
|
@ -417,6 +417,10 @@ Resources:
|
|||
- s3:PutLifecycleConfiguration
|
||||
- s3:GetBucketPublicAccessBlock
|
||||
- s3:PutBucketPublicAccessBlock
|
||||
# Explicit BucketEncryption blocks (first: payments-dashboard
|
||||
# BoaRawBucket, 2026-07-22) need the encryption config pair.
|
||||
- s3:GetEncryptionConfiguration
|
||||
- s3:PutEncryptionConfiguration
|
||||
- s3:GetBucketNotification
|
||||
- s3:PutBucketNotification
|
||||
- s3:GetBucketWebsite
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue