mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-07 11:39:03 +00:00
fix(cdk): allow EB runtime cleanup
This commit is contained in:
parent
b02787087e
commit
42d8772951
2 changed files with 10 additions and 7 deletions
|
|
@ -48,13 +48,15 @@ The role grants only:
|
||||||
`s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned
|
`s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned
|
||||||
official deployment action requires to validate the
|
official deployment action requires to validate the
|
||||||
`CreateApplicationVersion` source bundle after upload.
|
`CreateApplicationVersion` source bundle after upload.
|
||||||
- `s3:PutObject` on only
|
- `s3:PutObject` and `s3:DeleteObject` on only
|
||||||
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`.
|
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`.
|
||||||
Elastic Beanstalk copies each uploaded source bundle into this
|
Elastic Beanstalk copies each uploaded source bundle into this
|
||||||
environment-specific runtime prefix during `UpdateEnvironment`. Run
|
environment-specific runtime prefix during `UpdateEnvironment` and removes
|
||||||
`30448885838` exposed the exact source and destination after the earlier ACL
|
that temporary copy after the version is registered. Attempts 1 and 2 of run
|
||||||
denial was resolved. The grant does not cover another environment, another
|
`30448885838` exposed the exact source, destination, and cleanup denial after
|
||||||
application, bucket ACLs, object ACLs, tags, retention, deletion, or reads.
|
the earlier ACL denial was resolved. The grant does not cover another
|
||||||
|
environment, another application, source bundles, object versions, bucket
|
||||||
|
ACLs, object ACLs, tags, retention, or reads.
|
||||||
- `s3:GetObjectAcl` on objects under the service-wide
|
- `s3:GetObjectAcl` on objects under the service-wide
|
||||||
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
||||||
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
||||||
|
|
|
||||||
|
|
@ -153,9 +153,10 @@ export class DeployDevStack extends cdk.Stack {
|
||||||
deployRole.addToPolicy(
|
deployRole.addToPolicy(
|
||||||
new iam.PolicyStatement({
|
new iam.PolicyStatement({
|
||||||
effect: iam.Effect.ALLOW,
|
effect: iam.Effect.ALLOW,
|
||||||
actions: ['s3:PutObject'],
|
actions: ['s3:DeleteObject', 's3:PutObject'],
|
||||||
// UpdateEnvironment copies the uploaded source bundle into this
|
// UpdateEnvironment copies the uploaded source bundle into this
|
||||||
// environment-specific runtime version prefix before deployment.
|
// environment-specific runtime prefix and removes that temporary copy
|
||||||
|
// after the version is registered.
|
||||||
resources: [runtimeVersionArn],
|
resources: [runtimeVersionArn],
|
||||||
}),
|
}),
|
||||||
);
|
);
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue