mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 09:33:13 +00:00
fix(cdk): allow EB embedded extension write
This commit is contained in:
parent
156b7bbed6
commit
3f60730464
2 changed files with 20 additions and 0 deletions
|
|
@ -62,6 +62,13 @@ The role grants only:
|
|||
the matching version-ACL write. The grant does not cover another
|
||||
environment, another application, source bundles, object content versions,
|
||||
non-version ACL mutation, tags, or retention.
|
||||
- `s3:PutObject` on only
|
||||
`elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*`.
|
||||
After the runtime bundle copy and version-ACL operations succeeded, attempt 8
|
||||
of run `30448885838` showed Elastic Beanstalk materializing the application's
|
||||
embedded-extension manifest at this application-specific prefix. CloudTrail
|
||||
recorded the exact denied action and object ARN. The grant does not include
|
||||
reads, deletes, ACL mutation, another application, or another bucket.
|
||||
- `s3:GetObjectAcl` on objects under the service-wide
|
||||
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
||||
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
||||
|
|
|
|||
|
|
@ -21,6 +21,9 @@ export class DeployDevStack extends cdk.Stack {
|
|||
const runtimeVersionArn =
|
||||
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
|
||||
`/_runtime/_versions/${APPLICATION_NAME}/*`;
|
||||
const embeddedExtensionArn =
|
||||
`${bucketArn}/resources/_runtime/_embedded_extensions/` +
|
||||
`${APPLICATION_NAME}/*`;
|
||||
const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`;
|
||||
|
||||
const deployRole = new iam.Role(this, 'GithubDeployRole', {
|
||||
|
|
@ -167,6 +170,16 @@ export class DeployDevStack extends cdk.Stack {
|
|||
}),
|
||||
);
|
||||
|
||||
deployRole.addToPolicy(
|
||||
new iam.PolicyStatement({
|
||||
effect: iam.Effect.ALLOW,
|
||||
actions: ['s3:PutObject'],
|
||||
// UpdateEnvironment materializes the application's embedded-extension
|
||||
// manifest under this application-specific runtime prefix.
|
||||
resources: [embeddedExtensionArn],
|
||||
}),
|
||||
);
|
||||
|
||||
deployRole.addToPolicy(
|
||||
new iam.PolicyStatement({
|
||||
effect: iam.Effect.ALLOW,
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue