fix: allow deployment bundle validation

This commit is contained in:
Alexandre Brandizzi 2026-07-28 11:12:39 -03:00
parent 8539c07f82
commit 34b5f09828
2 changed files with 5 additions and 3 deletions

View file

@ -41,8 +41,10 @@ The role grants only:
- `elasticbeanstalk:CreateApplicationVersion` on application `shoc-backend`.
- `elasticbeanstalk:UpdateEnvironment` on environment `shoc-backend-dev` only.
- `s3:ListBucket` on `elasticbeanstalk-us-east-1-396287094661` (the official
action's ownership-safe `HeadBucket` check) and `s3:PutObject` only under the
`shoc-backend/` object prefix.
action's ownership-safe `HeadBucket` check). Under the `shoc-backend/` object
prefix only: `s3:PutObject` plus `s3:GetObject` and `s3:GetObjectVersion`,
which the pinned official deployment action requires to validate the
`CreateApplicationVersion` source bundle after upload.
It grants **no** IAM mutation or `PassRole`, **no** RDS / EC2 / Secrets Manager
access, and **no** administrator policy. There are no wildcard mutation

View file

@ -81,7 +81,7 @@ export class DeployDevStack extends cdk.Stack {
deployRole.addToPolicy(
new iam.PolicyStatement({
effect: iam.Effect.ALLOW,
actions: ['s3:PutObject'],
actions: ['s3:GetObject', 's3:GetObjectVersion', 's3:PutObject'],
resources: [`${bucketArn}/${APPLICATION_NAME}/*`],
}),
);