fix(cdk): allow EB runtime verification

This commit is contained in:
brandizzi 2026-07-29 09:21:28 -03:00
parent 42d8772951
commit 424bf20f54
2 changed files with 11 additions and 9 deletions

View file

@ -48,15 +48,17 @@ The role grants only:
`s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned
official deployment action requires to validate the
`CreateApplicationVersion` source bundle after upload.
- `s3:PutObject` and `s3:DeleteObject` on only
- `s3:PutObject`, `s3:GetObject`, and `s3:DeleteObject` on only
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`.
Elastic Beanstalk copies each uploaded source bundle into this
environment-specific runtime prefix during `UpdateEnvironment` and removes
that temporary copy after the version is registered. Attempts 1 and 2 of run
`30448885838` exposed the exact source, destination, and cleanup denial after
the earlier ACL denial was resolved. The grant does not cover another
environment-specific runtime prefix during `UpdateEnvironment`, verifies it
with `HeadObject` (authorized by `s3:GetObject`), and removes the temporary
copy after the version is registered. Attempts 1 through 4 of run
`30448885838` exposed the exact source, destination, cleanup, and verification
operations after the earlier ACL denial was resolved. CloudTrail recorded
the exact `s3:GetObject` denial on attempt 4. The grant does not cover another
environment, another application, source bundles, object versions, bucket
ACLs, object ACLs, tags, retention, or reads.
ACLs, object ACLs, tags, or retention.
- `s3:GetObjectAcl` on objects under the service-wide
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating

View file

@ -153,10 +153,10 @@ export class DeployDevStack extends cdk.Stack {
deployRole.addToPolicy(
new iam.PolicyStatement({
effect: iam.Effect.ALLOW,
actions: ['s3:DeleteObject', 's3:PutObject'],
actions: ['s3:DeleteObject', 's3:GetObject', 's3:PutObject'],
// UpdateEnvironment copies the uploaded source bundle into this
// environment-specific runtime prefix and removes that temporary copy
// after the version is registered.
// environment-specific runtime prefix, verifies the temporary copy,
// and removes it after the version is registered.
resources: [runtimeVersionArn],
}),
);