diff --git a/infra/cdk/README.md b/infra/cdk/README.md index d285409..5421714 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -41,8 +41,10 @@ The role grants only: - `elasticbeanstalk:CreateApplicationVersion` on application `shoc-backend`. - `elasticbeanstalk:UpdateEnvironment` on environment `shoc-backend-dev` only. - `s3:ListBucket` on `elasticbeanstalk-us-east-1-396287094661` (the official - action's ownership-safe `HeadBucket` check) and `s3:PutObject` only under the - `shoc-backend/` object prefix. + action's ownership-safe `HeadBucket` check). Under the `shoc-backend/` object + prefix only: `s3:PutObject` plus `s3:GetObject` and `s3:GetObjectVersion`, + which the pinned official deployment action requires to validate the + `CreateApplicationVersion` source bundle after upload. It grants **no** IAM mutation or `PassRole`, **no** RDS / EC2 / Secrets Manager access, and **no** administrator policy. There are no wildcard mutation diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index 0137db0..45291b3 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -81,7 +81,7 @@ export class DeployDevStack extends cdk.Stack { deployRole.addToPolicy( new iam.PolicyStatement({ effect: iam.Effect.ALLOW, - actions: ['s3:PutObject'], + actions: ['s3:GetObject', 's3:GetObjectVersion', 's3:PutObject'], resources: [`${bucketArn}/${APPLICATION_NAME}/*`], }), );