From 3f607304643084bd82bfdbacbdc36eece5d8a978 Mon Sep 17 00:00:00 2001 From: brandizzi Date: Wed, 29 Jul 2026 09:45:45 -0300 Subject: [PATCH] fix(cdk): allow EB embedded extension write --- infra/cdk/README.md | 7 +++++++ infra/cdk/deploy-dev-stack.ts | 13 +++++++++++++ 2 files changed, 20 insertions(+) diff --git a/infra/cdk/README.md b/infra/cdk/README.md index 5036031..492db5b 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -62,6 +62,13 @@ The role grants only: the matching version-ACL write. The grant does not cover another environment, another application, source bundles, object content versions, non-version ACL mutation, tags, or retention. +- `s3:PutObject` on only + `elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*`. + After the runtime bundle copy and version-ACL operations succeeded, attempt 8 + of run `30448885838` showed Elastic Beanstalk materializing the application's + embedded-extension manifest at this application-specific prefix. CloudTrail + recorded the exact denied action and object ARN. The grant does not include + reads, deletes, ACL mutation, another application, or another bucket. - `s3:GetObjectAcl` on objects under the service-wide `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `178526484500047` confirmed that `UpdateEnvironment` uses the initiating diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index df96f05..433d3b2 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -21,6 +21,9 @@ export class DeployDevStack extends cdk.Stack { const runtimeVersionArn = `${bucketArn}/resources/environments/${ENVIRONMENT_ID}` + `/_runtime/_versions/${APPLICATION_NAME}/*`; + const embeddedExtensionArn = + `${bucketArn}/resources/_runtime/_embedded_extensions/` + + `${APPLICATION_NAME}/*`; const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`; const deployRole = new iam.Role(this, 'GithubDeployRole', { @@ -167,6 +170,16 @@ export class DeployDevStack extends cdk.Stack { }), ); + deployRole.addToPolicy( + new iam.PolicyStatement({ + effect: iam.Effect.ALLOW, + actions: ['s3:PutObject'], + // UpdateEnvironment materializes the application's embedded-extension + // manifest under this application-specific runtime prefix. + resources: [embeddedExtensionArn], + }), + ); + deployRole.addToPolicy( new iam.PolicyStatement({ effect: iam.Effect.ALLOW,