mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-06 04:12:14 +00:00
fix(cdk): allow EB runtime version ACL write
This commit is contained in:
parent
9f54399e63
commit
156b7bbed6
2 changed files with 8 additions and 6 deletions
|
|
@ -48,8 +48,8 @@ The role grants only:
|
||||||
`s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned
|
`s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned
|
||||||
official deployment action requires to validate the
|
official deployment action requires to validate the
|
||||||
`CreateApplicationVersion` source bundle after upload.
|
`CreateApplicationVersion` source bundle after upload.
|
||||||
- `s3:PutObject`, `s3:GetObject`, `s3:GetObjectVersionAcl`, and
|
- `s3:PutObject`, `s3:GetObject`, `s3:GetObjectVersionAcl`,
|
||||||
`s3:DeleteObject` on only
|
`s3:PutObjectVersionAcl`, and `s3:DeleteObject` on only
|
||||||
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`.
|
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`.
|
||||||
Elastic Beanstalk copies each uploaded source bundle into this
|
Elastic Beanstalk copies each uploaded source bundle into this
|
||||||
environment-specific runtime prefix during `UpdateEnvironment`, verifies it
|
environment-specific runtime prefix during `UpdateEnvironment`, verifies it
|
||||||
|
|
@ -58,9 +58,10 @@ The role grants only:
|
||||||
`30448885838` exposed the exact source, destination, cleanup, and verification
|
`30448885838` exposed the exact source, destination, cleanup, and verification
|
||||||
operations after the earlier ACL denial was resolved. CloudTrail recorded
|
operations after the earlier ACL denial was resolved. CloudTrail recorded
|
||||||
the exact `s3:GetObject` denial on attempt 4; attempt 6 then exposed the
|
the exact `s3:GetObject` denial on attempt 4; attempt 6 then exposed the
|
||||||
version-specific ACL read performed on the copied object. The grant does not
|
version-specific ACL read performed on the copied object; attempt 7 exposed
|
||||||
cover another environment, another application, source bundles, object
|
the matching version-ACL write. The grant does not cover another
|
||||||
content versions, ACL mutation, tags, or retention.
|
environment, another application, source bundles, object content versions,
|
||||||
|
non-version ACL mutation, tags, or retention.
|
||||||
- `s3:GetObjectAcl` on objects under the service-wide
|
- `s3:GetObjectAcl` on objects under the service-wide
|
||||||
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
||||||
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
||||||
|
|
|
||||||
|
|
@ -158,10 +158,11 @@ export class DeployDevStack extends cdk.Stack {
|
||||||
's3:GetObject',
|
's3:GetObject',
|
||||||
's3:GetObjectVersionAcl',
|
's3:GetObjectVersionAcl',
|
||||||
's3:PutObject',
|
's3:PutObject',
|
||||||
|
's3:PutObjectVersionAcl',
|
||||||
],
|
],
|
||||||
// UpdateEnvironment copies the uploaded source bundle into this
|
// UpdateEnvironment copies the uploaded source bundle into this
|
||||||
// environment-specific runtime prefix, verifies the temporary copy,
|
// environment-specific runtime prefix, verifies the temporary copy,
|
||||||
// and removes it after the version is registered.
|
// preserves its version ACL, and removes it after registration.
|
||||||
resources: [runtimeVersionArn],
|
resources: [runtimeVersionArn],
|
||||||
}),
|
}),
|
||||||
);
|
);
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue