From 42d877295108645ea051b779b61f2e2e219fbd6e Mon Sep 17 00:00:00 2001 From: brandizzi Date: Wed, 29 Jul 2026 09:05:44 -0300 Subject: [PATCH] fix(cdk): allow EB runtime cleanup --- infra/cdk/README.md | 12 +++++++----- infra/cdk/deploy-dev-stack.ts | 5 +++-- 2 files changed, 10 insertions(+), 7 deletions(-) diff --git a/infra/cdk/README.md b/infra/cdk/README.md index 4a61dc1..1102e63 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -48,13 +48,15 @@ The role grants only: `s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned official deployment action requires to validate the `CreateApplicationVersion` source bundle after upload. -- `s3:PutObject` on only +- `s3:PutObject` and `s3:DeleteObject` on only `elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`. Elastic Beanstalk copies each uploaded source bundle into this - environment-specific runtime prefix during `UpdateEnvironment`. Run - `30448885838` exposed the exact source and destination after the earlier ACL - denial was resolved. The grant does not cover another environment, another - application, bucket ACLs, object ACLs, tags, retention, deletion, or reads. + environment-specific runtime prefix during `UpdateEnvironment` and removes + that temporary copy after the version is registered. Attempts 1 and 2 of run + `30448885838` exposed the exact source, destination, and cleanup denial after + the earlier ACL denial was resolved. The grant does not cover another + environment, another application, source bundles, object versions, bucket + ACLs, object ACLs, tags, retention, or reads. - `s3:GetObjectAcl` on objects under the service-wide `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `178526484500047` confirmed that `UpdateEnvironment` uses the initiating diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index 3047287..ee5d6e4 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -153,9 +153,10 @@ export class DeployDevStack extends cdk.Stack { deployRole.addToPolicy( new iam.PolicyStatement({ effect: iam.Effect.ALLOW, - actions: ['s3:PutObject'], + actions: ['s3:DeleteObject', 's3:PutObject'], // UpdateEnvironment copies the uploaded source bundle into this - // environment-specific runtime version prefix before deployment. + // environment-specific runtime prefix and removes that temporary copy + // after the version is registered. resources: [runtimeVersionArn], }), );