diff --git a/infra/cdk/README.md b/infra/cdk/README.md index 7588086..5036031 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -48,8 +48,8 @@ The role grants only: `s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned official deployment action requires to validate the `CreateApplicationVersion` source bundle after upload. -- `s3:PutObject`, `s3:GetObject`, `s3:GetObjectVersionAcl`, and - `s3:DeleteObject` on only +- `s3:PutObject`, `s3:GetObject`, `s3:GetObjectVersionAcl`, + `s3:PutObjectVersionAcl`, and `s3:DeleteObject` on only `elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`. Elastic Beanstalk copies each uploaded source bundle into this environment-specific runtime prefix during `UpdateEnvironment`, verifies it @@ -58,9 +58,10 @@ The role grants only: `30448885838` exposed the exact source, destination, cleanup, and verification operations after the earlier ACL denial was resolved. CloudTrail recorded the exact `s3:GetObject` denial on attempt 4; attempt 6 then exposed the - version-specific ACL read performed on the copied object. The grant does not - cover another environment, another application, source bundles, object - content versions, ACL mutation, tags, or retention. + version-specific ACL read performed on the copied object; attempt 7 exposed + the matching version-ACL write. The grant does not cover another + environment, another application, source bundles, object content versions, + non-version ACL mutation, tags, or retention. - `s3:GetObjectAcl` on objects under the service-wide `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `178526484500047` confirmed that `UpdateEnvironment` uses the initiating diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index 97350e7..df96f05 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -158,10 +158,11 @@ export class DeployDevStack extends cdk.Stack { 's3:GetObject', 's3:GetObjectVersionAcl', 's3:PutObject', + 's3:PutObjectVersionAcl', ], // UpdateEnvironment copies the uploaded source bundle into this // environment-specific runtime prefix, verifies the temporary copy, - // and removes it after the version is registered. + // preserves its version ACL, and removes it after registration. resources: [runtimeVersionArn], }), );