diff --git a/infra/cdk/README.md b/infra/cdk/README.md index 4a61dc1..1102e63 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -48,13 +48,15 @@ The role grants only: `s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned official deployment action requires to validate the `CreateApplicationVersion` source bundle after upload. -- `s3:PutObject` on only +- `s3:PutObject` and `s3:DeleteObject` on only `elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`. Elastic Beanstalk copies each uploaded source bundle into this - environment-specific runtime prefix during `UpdateEnvironment`. Run - `30448885838` exposed the exact source and destination after the earlier ACL - denial was resolved. The grant does not cover another environment, another - application, bucket ACLs, object ACLs, tags, retention, deletion, or reads. + environment-specific runtime prefix during `UpdateEnvironment` and removes + that temporary copy after the version is registered. Attempts 1 and 2 of run + `30448885838` exposed the exact source, destination, and cleanup denial after + the earlier ACL denial was resolved. The grant does not cover another + environment, another application, source bundles, object versions, bucket + ACLs, object ACLs, tags, retention, or reads. - `s3:GetObjectAcl` on objects under the service-wide `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `178526484500047` confirmed that `UpdateEnvironment` uses the initiating diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index 3047287..ee5d6e4 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -153,9 +153,10 @@ export class DeployDevStack extends cdk.Stack { deployRole.addToPolicy( new iam.PolicyStatement({ effect: iam.Effect.ALLOW, - actions: ['s3:PutObject'], + actions: ['s3:DeleteObject', 's3:PutObject'], // UpdateEnvironment copies the uploaded source bundle into this - // environment-specific runtime version prefix before deployment. + // environment-specific runtime prefix and removes that temporary copy + // after the version is registered. resources: [runtimeVersionArn], }), );