mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 08:03:15 +00:00
* fix(infra): grant instance role BatchGetSecretValue + ListSecrets for .env materialization fetch-config.sh materializes the box's .env via `secretsmanager batch-get-secret-value --filters Key=name,Values=open-swe-<env>/`, but the instance role only granted GetSecretValue/DescribeSecret. BatchGetSecretValue is a distinct IAM action, so the call was AccessDenied and open-swe.service crash-looped (no .env written -> ExecStartPre exit 1). - Add secretsmanager:BatchGetSecretValue to the prefix-scoped ReadSecrets statement. - Add secretsmanager:ListSecrets on * (required by the name-prefix filtered batch call; the API has no resource-level scoping for the list action — fits the role's stated exception). Secret VALUES stay prefix-scoped; only names are enumerable. Reviews: GPT-4.1 IAM cross-review BLOCK=none; /sh-security-review iac-iam one LOW metadata residual (no critical/high), recorded as OSWE-IAC-SECRETS-LIST-01. Refs T7/T19 dev bring-up. * ci: lift Node heap cap for Playwright E2E build (vite OOM) The E2E job's Playwright globalSetup runs the real `bun run build`, whose vite bundle exceeds Node's default ~2 GB heap and OOMs (JavaScript heap out of memory) — the same failure fixed for build-artifacts.yml in #19. Set NODE_OPTIONS=--max-old-space-size=8192 on the Run E2E step.
118 lines
4.9 KiB
TypeScript
118 lines
4.9 KiB
TypeScript
import * as iam from "aws-cdk-lib/aws-iam";
|
|
import { Construct } from "constructs";
|
|
import { ACCOUNT, EnvName, REGION, prefix } from "../config";
|
|
|
|
/**
|
|
* Least-privilege EC2 instance role for the open-swe box (one per env).
|
|
*
|
|
* Grants exactly what the boot/runtime flow needs and NOTHING ELSE — no admin,
|
|
* no `*` resources except where the AWS action genuinely has no resource-level
|
|
* scoping. Per-env so the dev box can never read prod secrets/config and vice
|
|
* versa. Reviewed at T4 (GPT-4.1 IAM cross-review) / T5 (/sh-security-review)
|
|
* before it is ever deployed (T6).
|
|
*/
|
|
export class InstanceRole extends Construct {
|
|
public readonly role: iam.Role;
|
|
|
|
constructor(scope: Construct, id: string, env: EnvName) {
|
|
super(scope, id);
|
|
const p = prefix(env);
|
|
|
|
this.role = new iam.Role(this, "Role", {
|
|
roleName: `${p}-instance-role`,
|
|
assumedBy: new iam.ServicePrincipal("ec2.amazonaws.com"),
|
|
description: `EC2 instance role for the ${p} open-swe box (least-privilege).`,
|
|
});
|
|
|
|
// AWS-managed: lets the SSM agent register the instance and RECEIVE the
|
|
// app-deploy `ssm:SendCommand` from githubdeploy-open-swe-app. This is the
|
|
// standard Session-Manager / RunCommand grant and is the only managed
|
|
// policy on the role. DELIBERATE — flag for T4 confirmation.
|
|
this.role.addManagedPolicy(
|
|
iam.ManagedPolicy.fromAwsManagedPolicyName("AmazonSSMManagedInstanceCore"),
|
|
);
|
|
|
|
// Read the build artifact from the env's S3 asset bucket (deploy = pull).
|
|
// Scoped to releases/* — the only prefix CI writes and the box pulls — so a
|
|
// compromised box (or stolen IMDS creds) cannot read anything else that might
|
|
// ever land in the bucket (least-privilege; mirrors the app role's write scope).
|
|
this.role.addToPolicy(
|
|
new iam.PolicyStatement({
|
|
sid: "ReadArtifactObjects",
|
|
actions: ["s3:GetObject"],
|
|
resources: [`arn:aws:s3:::${p}-assets/releases/*`],
|
|
}),
|
|
);
|
|
this.role.addToPolicy(
|
|
new iam.PolicyStatement({
|
|
sid: "ListArtifactBucket",
|
|
actions: ["s3:ListBucket", "s3:GetBucketLocation"],
|
|
resources: [`arn:aws:s3:::${p}-assets`],
|
|
}),
|
|
);
|
|
|
|
// Read non-sensitive config from SSM Parameter Store under /open-swe-<env>/*.
|
|
this.role.addToPolicy(
|
|
new iam.PolicyStatement({
|
|
sid: "ReadSsmConfig",
|
|
actions: ["ssm:GetParameter", "ssm:GetParameters", "ssm:GetParametersByPath"],
|
|
resources: [`arn:aws:ssm:${REGION}:${ACCOUNT}:parameter/${p}/*`],
|
|
}),
|
|
);
|
|
|
|
// Read secrets from Secrets Manager under open-swe-<env>/*. Secret ARNs carry
|
|
// a random 6-char suffix, hence the trailing `*`. fetch-config.sh materializes
|
|
// the .env via `batch-get-secret-value` (one call instead of N), so the role
|
|
// needs BatchGetSecretValue (a DISTINCT action from GetSecretValue) in addition
|
|
// to the per-secret GetSecretValue/DescribeSecret. All three are scoped to the
|
|
// env prefix — the box can only read its own env's secret VALUES.
|
|
this.role.addToPolicy(
|
|
new iam.PolicyStatement({
|
|
sid: "ReadSecrets",
|
|
actions: [
|
|
"secretsmanager:GetSecretValue",
|
|
"secretsmanager:BatchGetSecretValue",
|
|
"secretsmanager:DescribeSecret",
|
|
],
|
|
resources: [`arn:aws:secretsmanager:${REGION}:${ACCOUNT}:secret:${p}/*`],
|
|
}),
|
|
);
|
|
|
|
// batch-get-secret-value with a name-prefix `--filters` additionally requires
|
|
// ListSecrets, which the AWS API does NOT support scoping by resource (it is a
|
|
// list-style action) — so it is `*`, matching this role's stated exception for
|
|
// actions that genuinely have no resource-level scoping. This grants only the
|
|
// ability to ENUMERATE secret names; reading a secret's VALUE still requires the
|
|
// prefix-scoped GetSecretValue above, so cross-env value isolation is preserved.
|
|
this.role.addToPolicy(
|
|
new iam.PolicyStatement({
|
|
sid: "ListSecretsForBatchFilter",
|
|
actions: ["secretsmanager:ListSecrets"],
|
|
resources: ["*"],
|
|
}),
|
|
);
|
|
|
|
// NOTE (T11): SSM SecureString + Secrets Manager here are assumed to use the
|
|
// AWS-managed keys (alias/aws/ssm, alias/aws/secretsmanager) for which the
|
|
// service grants Decrypt implicitly — so NO kms:Decrypt is granted. If T11
|
|
// moves these to a customer CMK, add a scoped `kms:Decrypt` on that key ARN
|
|
// ONLY (not `*`).
|
|
|
|
// Ship application logs to CloudWatch Logs under /open-swe/<env>/*.
|
|
this.role.addToPolicy(
|
|
new iam.PolicyStatement({
|
|
sid: "PutAppLogs",
|
|
actions: [
|
|
"logs:CreateLogGroup",
|
|
"logs:CreateLogStream",
|
|
"logs:PutLogEvents",
|
|
"logs:DescribeLogStreams",
|
|
],
|
|
resources: [
|
|
`arn:aws:logs:${REGION}:${ACCOUNT}:log-group:/open-swe/${env}/*`,
|
|
`arn:aws:logs:${REGION}:${ACCOUNT}:log-group:/open-swe/${env}/*:*`,
|
|
],
|
|
}),
|
|
);
|
|
}
|
|
}
|