mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-02 22:43:31 +00:00
fix(cdk): allow EB embedded extension write
This commit is contained in:
parent
156b7bbed6
commit
3f60730464
2 changed files with 20 additions and 0 deletions
|
|
@ -62,6 +62,13 @@ The role grants only:
|
||||||
the matching version-ACL write. The grant does not cover another
|
the matching version-ACL write. The grant does not cover another
|
||||||
environment, another application, source bundles, object content versions,
|
environment, another application, source bundles, object content versions,
|
||||||
non-version ACL mutation, tags, or retention.
|
non-version ACL mutation, tags, or retention.
|
||||||
|
- `s3:PutObject` on only
|
||||||
|
`elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*`.
|
||||||
|
After the runtime bundle copy and version-ACL operations succeeded, attempt 8
|
||||||
|
of run `30448885838` showed Elastic Beanstalk materializing the application's
|
||||||
|
embedded-extension manifest at this application-specific prefix. CloudTrail
|
||||||
|
recorded the exact denied action and object ARN. The grant does not include
|
||||||
|
reads, deletes, ACL mutation, another application, or another bucket.
|
||||||
- `s3:GetObjectAcl` on objects under the service-wide
|
- `s3:GetObjectAcl` on objects under the service-wide
|
||||||
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
||||||
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
||||||
|
|
|
||||||
|
|
@ -21,6 +21,9 @@ export class DeployDevStack extends cdk.Stack {
|
||||||
const runtimeVersionArn =
|
const runtimeVersionArn =
|
||||||
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
|
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
|
||||||
`/_runtime/_versions/${APPLICATION_NAME}/*`;
|
`/_runtime/_versions/${APPLICATION_NAME}/*`;
|
||||||
|
const embeddedExtensionArn =
|
||||||
|
`${bucketArn}/resources/_runtime/_embedded_extensions/` +
|
||||||
|
`${APPLICATION_NAME}/*`;
|
||||||
const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`;
|
const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`;
|
||||||
|
|
||||||
const deployRole = new iam.Role(this, 'GithubDeployRole', {
|
const deployRole = new iam.Role(this, 'GithubDeployRole', {
|
||||||
|
|
@ -167,6 +170,16 @@ export class DeployDevStack extends cdk.Stack {
|
||||||
}),
|
}),
|
||||||
);
|
);
|
||||||
|
|
||||||
|
deployRole.addToPolicy(
|
||||||
|
new iam.PolicyStatement({
|
||||||
|
effect: iam.Effect.ALLOW,
|
||||||
|
actions: ['s3:PutObject'],
|
||||||
|
// UpdateEnvironment materializes the application's embedded-extension
|
||||||
|
// manifest under this application-specific runtime prefix.
|
||||||
|
resources: [embeddedExtensionArn],
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
|
||||||
deployRole.addToPolicy(
|
deployRole.addToPolicy(
|
||||||
new iam.PolicyStatement({
|
new iam.PolicyStatement({
|
||||||
effect: iam.Effect.ALLOW,
|
effect: iam.Effect.ALLOW,
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue