From 34b5f09828b8128370d24a773f6ca2286365b49c Mon Sep 17 00:00:00 2001 From: Alexandre Brandizzi Date: Tue, 28 Jul 2026 11:12:39 -0300 Subject: [PATCH] fix: allow deployment bundle validation --- infra/cdk/README.md | 6 ++++-- infra/cdk/deploy-dev-stack.ts | 2 +- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/infra/cdk/README.md b/infra/cdk/README.md index d285409..5421714 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -41,8 +41,10 @@ The role grants only: - `elasticbeanstalk:CreateApplicationVersion` on application `shoc-backend`. - `elasticbeanstalk:UpdateEnvironment` on environment `shoc-backend-dev` only. - `s3:ListBucket` on `elasticbeanstalk-us-east-1-396287094661` (the official - action's ownership-safe `HeadBucket` check) and `s3:PutObject` only under the - `shoc-backend/` object prefix. + action's ownership-safe `HeadBucket` check). Under the `shoc-backend/` object + prefix only: `s3:PutObject` plus `s3:GetObject` and `s3:GetObjectVersion`, + which the pinned official deployment action requires to validate the + `CreateApplicationVersion` source bundle after upload. It grants **no** IAM mutation or `PassRole`, **no** RDS / EC2 / Secrets Manager access, and **no** administrator policy. There are no wildcard mutation diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index 0137db0..45291b3 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -81,7 +81,7 @@ export class DeployDevStack extends cdk.Stack { deployRole.addToPolicy( new iam.PolicyStatement({ effect: iam.Effect.ALLOW, - actions: ['s3:PutObject'], + actions: ['s3:GetObject', 's3:GetObjectVersion', 's3:PutObject'], resources: [`${bucketArn}/${APPLICATION_NAME}/*`], }), );