fix(cdk): allow EB runtime cleanup

This commit is contained in:
brandizzi 2026-07-29 09:05:44 -03:00
parent b02787087e
commit 42d8772951
2 changed files with 10 additions and 7 deletions

View file

@ -48,13 +48,15 @@ The role grants only:
`s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned `s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned
official deployment action requires to validate the official deployment action requires to validate the
`CreateApplicationVersion` source bundle after upload. `CreateApplicationVersion` source bundle after upload.
- `s3:PutObject` on only - `s3:PutObject` and `s3:DeleteObject` on only
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`. `elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`.
Elastic Beanstalk copies each uploaded source bundle into this Elastic Beanstalk copies each uploaded source bundle into this
environment-specific runtime prefix during `UpdateEnvironment`. Run environment-specific runtime prefix during `UpdateEnvironment` and removes
`30448885838` exposed the exact source and destination after the earlier ACL that temporary copy after the version is registered. Attempts 1 and 2 of run
denial was resolved. The grant does not cover another environment, another `30448885838` exposed the exact source, destination, and cleanup denial after
application, bucket ACLs, object ACLs, tags, retention, deletion, or reads. the earlier ACL denial was resolved. The grant does not cover another
environment, another application, source bundles, object versions, bucket
ACLs, object ACLs, tags, retention, or reads.
- `s3:GetObjectAcl` on objects under the service-wide - `s3:GetObjectAcl` on objects under the service-wide
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating `178526484500047` confirmed that `UpdateEnvironment` uses the initiating

View file

@ -153,9 +153,10 @@ export class DeployDevStack extends cdk.Stack {
deployRole.addToPolicy( deployRole.addToPolicy(
new iam.PolicyStatement({ new iam.PolicyStatement({
effect: iam.Effect.ALLOW, effect: iam.Effect.ALLOW,
actions: ['s3:PutObject'], actions: ['s3:DeleteObject', 's3:PutObject'],
// UpdateEnvironment copies the uploaded source bundle into this // UpdateEnvironment copies the uploaded source bundle into this
// environment-specific runtime version prefix before deployment. // environment-specific runtime prefix and removes that temporary copy
// after the version is registered.
resources: [runtimeVersionArn], resources: [runtimeVersionArn],
}), }),
); );