From 1b21945c6e86b0aec967f67c34f91e2bca0df492 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Wed, 22 Jul 2026 16:11:12 -0400 Subject: [PATCH] fix(iam): grant deploy roles s3 encryption-config actions payments-dashboard's BoaRawBucket (first bucket in the org with an explicit BucketEncryption block) failed CREATE: the CFN execution role lacked s3:PutEncryptionConfiguration. Adds the Get/Put pair to the shared s3-management statement (bucket-level, existing * scope). Escalation review: the role holds no kms:* actions anywhere, so the PutEncryptionConfiguration + PutBucketPolicy combination cannot pivot to a role-controlled KMS key; SCPs permit the action (the original denial was identity-policy). GPT-4.1 cross-family review: FIX-level only, dispositioned above. Stack deployed before merge per README. Refs: payments-dashboard#76 --- oidc-deploy-roles.yaml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/oidc-deploy-roles.yaml b/oidc-deploy-roles.yaml index 17d5818..70c1e7d 100644 --- a/oidc-deploy-roles.yaml +++ b/oidc-deploy-roles.yaml @@ -417,6 +417,10 @@ Resources: - s3:PutLifecycleConfiguration - s3:GetBucketPublicAccessBlock - s3:PutBucketPublicAccessBlock + # Explicit BucketEncryption blocks (first: payments-dashboard + # BoaRawBucket, 2026-07-22) need the encryption config pair. + - s3:GetEncryptionConfiguration + - s3:PutEncryptionConfiguration - s3:GetBucketNotification - s3:PutBucketNotification - s3:GetBucketWebsite