From 424bf20f54092864737412bba780053e1b86bdcc Mon Sep 17 00:00:00 2001 From: brandizzi Date: Wed, 29 Jul 2026 09:21:28 -0300 Subject: [PATCH] fix(cdk): allow EB runtime verification --- infra/cdk/README.md | 14 ++++++++------ infra/cdk/deploy-dev-stack.ts | 6 +++--- 2 files changed, 11 insertions(+), 9 deletions(-) diff --git a/infra/cdk/README.md b/infra/cdk/README.md index 1102e63..e84694b 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -48,15 +48,17 @@ The role grants only: `s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned official deployment action requires to validate the `CreateApplicationVersion` source bundle after upload. -- `s3:PutObject` and `s3:DeleteObject` on only +- `s3:PutObject`, `s3:GetObject`, and `s3:DeleteObject` on only `elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`. Elastic Beanstalk copies each uploaded source bundle into this - environment-specific runtime prefix during `UpdateEnvironment` and removes - that temporary copy after the version is registered. Attempts 1 and 2 of run - `30448885838` exposed the exact source, destination, and cleanup denial after - the earlier ACL denial was resolved. The grant does not cover another + environment-specific runtime prefix during `UpdateEnvironment`, verifies it + with `HeadObject` (authorized by `s3:GetObject`), and removes the temporary + copy after the version is registered. Attempts 1 through 4 of run + `30448885838` exposed the exact source, destination, cleanup, and verification + operations after the earlier ACL denial was resolved. CloudTrail recorded + the exact `s3:GetObject` denial on attempt 4. The grant does not cover another environment, another application, source bundles, object versions, bucket - ACLs, object ACLs, tags, retention, or reads. + ACLs, object ACLs, tags, or retention. - `s3:GetObjectAcl` on objects under the service-wide `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `178526484500047` confirmed that `UpdateEnvironment` uses the initiating diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index ee5d6e4..88c6009 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -153,10 +153,10 @@ export class DeployDevStack extends cdk.Stack { deployRole.addToPolicy( new iam.PolicyStatement({ effect: iam.Effect.ALLOW, - actions: ['s3:DeleteObject', 's3:PutObject'], + actions: ['s3:DeleteObject', 's3:GetObject', 's3:PutObject'], // UpdateEnvironment copies the uploaded source bundle into this - // environment-specific runtime prefix and removes that temporary copy - // after the version is registered. + // environment-specific runtime prefix, verifies the temporary copy, + // and removes it after the version is registered. resources: [runtimeVersionArn], }), );