diff --git a/README.md b/README.md index c1de6ce..3b90afe 100644 --- a/README.md +++ b/README.md @@ -440,7 +440,8 @@ job: are limited to ordinary tags, `PutRolePolicy` on the exact deploy role, `PutBucketPolicy` on the exact bucket, `UpdateDistribution` on the exact distribution, `CreateInvalidation`/`GetInvalidation` on the exact - distribution, `GetObject`/`PutObject` on `.release/current`, + distribution, `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` + on `.release/current`, `UpdateFunction` and `PublishFunction` on the exact CloudFront function, and A/AAAA changes for the exact site name with CREATE/DELETE/UPSERT conditions. @@ -459,8 +460,9 @@ changes, `PassRole`, secret and parameter reads, CloudFront/S3 create and delete (including OAC mutation), and deletion of inline role or bucket policies. `UpdateDistribution` is allowed on the exact pinned distribution ARN. `CreateInvalidation` and `GetInvalidation` are allowed on that same ARN so the -Terraform invalidation action can run. `GetObject`/`PutObject` on -`.release/current` lets Terraform own the release pointer. `UpdateFunction` and `PublishFunction` are allowed on the exact pinned function +Terraform invalidation action can run. `GetObject`/`GetObjectTagging`/`PutObject`/`PutObjectTagging` on +`.release/current` lets Terraform own the release pointer, including the +tag list `aws_s3_object` refreshes on every plan. `UpdateFunction` and `PublishFunction` are allowed on the exact pinned function ARN so Phase 2 ownership tags can apply; create, delete, and OAC updates stay denied. IAM does not expose a condition key for an inline policy name, so `PutRolePolicy` is constrained to the exact target-role ARN and requires the diff --git a/lib/terraform-substrate/shoc-frontend-resources.ts b/lib/terraform-substrate/shoc-frontend-resources.ts index 4cdbcaa..58b8dbf 100644 --- a/lib/terraform-substrate/shoc-frontend-resources.ts +++ b/lib/terraform-substrate/shoc-frontend-resources.ts @@ -116,7 +116,7 @@ const frontendReadPolicy = ( { Sid: "ReadReleasePointerObject", Effect: "Allow", - Action: ["s3:GetObject", "s3:GetObjectVersion"], + Action: ["s3:GetObject", "s3:GetObjectTagging", "s3:GetObjectVersion"], Resource: `${siteBucketArn}/.release/current`, }, { @@ -358,7 +358,13 @@ const frontendApplyPolicy = ( { Sid: "WriteReleasePointerObject", Effect: "Allow", - Action: ["s3:GetObject", "s3:GetObjectVersion", "s3:PutObject"], + Action: [ + "s3:GetObject", + "s3:GetObjectTagging", + "s3:GetObjectVersion", + "s3:PutObject", + "s3:PutObjectTagging", + ], Resource: `${bucketArn(environment.bucketName)}/.release/current`, }, {