open-swe/infra/lib/constructs
Adam Moussa 3c69dd9de6
Some checks are pending
Infra CD / Infra CI (pre-deploy) (push) Waiting to run
Infra CD / Deploy open-swe-dev (push) Blocked by required conditions
Infra CD / Deploy open-swe-prod (push) Blocked by required conditions
CI / Lint (push) Waiting to run
CI / Format check (push) Waiting to run
CI / Unit tests (push) Waiting to run
CI / Playwright E2E (push) Waiting to run
Build & publish app artifacts / Publish + deploy (dev) (push) Waiting to run
Build & publish app artifacts / Publish + deploy (prod) (push) Waiting to run
fix: BatchGetSecretValue must be granted on * (corrects #48, fixes dev crash-loop) (#50)
#48 (OSWE-IAC-SECRETS-LIST-01) scoped secretsmanager:BatchGetSecretValue
to the open-swe-<env>/* ARN on the theory that an explicit --secret-id-list
batch authorizes per-secret. That is FALSE: BatchGetSecretValue is a
collection action AWS authorizes against the account (*), regardless of
--filters vs --secret-id-list. A prefix-scoped grant AccessDenies the whole
call. The dev box passed right after #48 only because the prior broad grant
had not finished propagating; once it lapsed, fetch-config got AccessDenied
-> loaded 0 secrets -> FAIL-FAST -> open-swe.service crash-loop. Verified on
the live dev box (i-0af4e03e8bf70e6c3): the exact call returned
'not authorized to perform: secretsmanager:BatchGetSecretValue'; restoring
the * grant recovered it.

Move BatchGetSecretValue back to Resource:* (its own statement); keep
GetSecretValue + DescribeSecret prefix-scoped (those gate VALUE access, so
cross-env isolation holds). The surviving win from #48: --secret-id-list
needs no name filter, so ListSecrets stays dropped -> no account-wide name
enumeration. fetch-config.sh is unchanged (--secret-id-list is correct).

The /sh-security-review finding OSWE-IAC-IAM-01 called this out and was
wrongly refuted; the reference_secretsmanager_batch_get memory was wrong.
2026-06-28 22:08:02 -04:00
..
ami-cache.ts feat: stand up dev properly — assets bucket + artifact CD + baked AMI + on-box uv sync (T7+T19+T14) (#18) 2026-06-26 18:49:09 -04:00
app-service.ts fix(deploy): use %%...%% for CDK user-data tokens (don't collide with @@ sed) (#21) 2026-06-26 19:06:37 -04:00
assets-bucket.ts feat: stand up dev properly — assets bucket + artifact CD + baked AMI + on-box uv sync (T7+T19+T14) (#18) 2026-06-26 18:49:09 -04:00
config-store.ts Point dev agent at seahaven-open-swe-dev org + un-pin the owner guard (#27) 2026-06-27 19:29:03 -04:00
github-deploy-roles.ts ci: gate dev→prod promotion on green checks + add rollback safety net (#28) 2026-06-27 20:21:59 -04:00
instance-role.ts fix: BatchGetSecretValue must be granted on * (corrects #48, fixes dev crash-loop) (#50) 2026-06-28 22:08:02 -04:00