diff --git a/README.md b/README.md index b6eef7d..3b90afe 100644 --- a/README.md +++ b/README.md @@ -439,7 +439,10 @@ job: existing site resources only after a no-replacement plan. Apply-role writes are limited to ordinary tags, `PutRolePolicy` on the exact deploy role, `PutBucketPolicy` on the exact bucket, `UpdateDistribution` on the exact - distribution, `UpdateFunction` and `PublishFunction` on the exact CloudFront + distribution, `CreateInvalidation`/`GetInvalidation` on the exact + distribution, `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` + on `.release/current`, + `UpdateFunction` and `PublishFunction` on the exact CloudFront function, and A/AAAA changes for the exact site name with CREATE/DELETE/UPSERT conditions. 5. For a future tf-poc, first provision and inventory the site outside these @@ -456,7 +459,10 @@ The apply roles explicitly deny role lifecycle/trust/boundary/managed-policy changes, `PassRole`, secret and parameter reads, CloudFront/S3 create and delete (including OAC mutation), and deletion of inline role or bucket policies. `UpdateDistribution` is allowed on the exact pinned distribution ARN. -`UpdateFunction` and `PublishFunction` are allowed on the exact pinned function +`CreateInvalidation` and `GetInvalidation` are allowed on that same ARN so the +Terraform invalidation action can run. `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` on +`.release/current` lets Terraform own the release pointer, including the +tag list `aws_s3_object` refreshes on every plan. `UpdateFunction` and `PublishFunction` are allowed on the exact pinned function ARN so Phase 2 ownership tags can apply; create, delete, and OAC updates stay denied. IAM does not expose a condition key for an inline policy name, so `PutRolePolicy` is constrained to the exact target-role ARN and requires the diff --git a/lib/terraform-substrate/shoc-frontend-resources.ts b/lib/terraform-substrate/shoc-frontend-resources.ts index 3c8ee7b..58b8dbf 100644 --- a/lib/terraform-substrate/shoc-frontend-resources.ts +++ b/lib/terraform-substrate/shoc-frontend-resources.ts @@ -113,6 +113,12 @@ const frontendReadPolicy = ( ], Resource: siteBucketArn, }, + { + Sid: "ReadReleasePointerObject", + Effect: "Allow", + Action: ["s3:GetObject", "s3:GetObjectTagging", "s3:GetObjectVersion"], + Resource: `${siteBucketArn}/.release/current`, + }, { Sid: "ReadExactCloudFrontResources", Effect: "Allow", @@ -343,6 +349,24 @@ const frontendApplyPolicy = ( Action: ["cloudfront:UpdateFunction", "cloudfront:PublishFunction"], Resource: functionArn(environment.functionName), }, + { + Sid: "InvalidateExactDistribution", + Effect: "Allow", + Action: ["cloudfront:CreateInvalidation", "cloudfront:GetInvalidation"], + Resource: distributionArn(environment.distributionId), + }, + { + Sid: "WriteReleasePointerObject", + Effect: "Allow", + Action: [ + "s3:GetObject", + "s3:GetObjectTagging", + "s3:GetObjectVersion", + "s3:PutObject", + "s3:PutObjectTagging", + ], + Resource: `${bucketArn(environment.bucketName)}/.release/current`, + }, { Sid: "ReplaceExactDeployInlinePolicy", Effect: "Allow",