From 45ffa68dfa52986086902a0ee399eeb04a4ec137 Mon Sep 17 00:00:00 2001 From: Alexandre Brandizzi Date: Tue, 28 Jul 2026 12:51:20 -0300 Subject: [PATCH] fix: allow Elastic Beanstalk bucket setup check (#36) --- infra/cdk/README.md | 19 ++++++++++++++++--- infra/cdk/deploy-dev-stack.ts | 2 +- 2 files changed, 17 insertions(+), 4 deletions(-) diff --git a/infra/cdk/README.md b/infra/cdk/README.md index 5421714..7555c73 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -41,11 +41,24 @@ The role grants only: - `elasticbeanstalk:CreateApplicationVersion` on application `shoc-backend`. - `elasticbeanstalk:UpdateEnvironment` on environment `shoc-backend-dev` only. - `s3:ListBucket` on `elasticbeanstalk-us-east-1-396287094661` (the official - action's ownership-safe `HeadBucket` check). Under the `shoc-backend/` object - prefix only: `s3:PutObject` plus `s3:GetObject` and `s3:GetObjectVersion`, - which the pinned official deployment action requires to validate the + action's ownership-safe `HeadBucket` check), plus `s3:CreateBucket` on the + same bucket-level ARN. Under the `shoc-backend/` object prefix only: + `s3:PutObject` plus `s3:GetObject` and `s3:GetObjectVersion`, which the + pinned official deployment action requires to validate the `CreateApplicationVersion` source bundle after upload. + `s3:CreateBucket` is part of the pinned + `aws-actions/aws-elasticbeanstalk-deploy@cfad3e5e...` (v1.0.6) IAM + contract even though the workflow sets + `create-s3-bucket-if-not-exists: "false"`. That input prevents the + action's explicit bucket-creation helper; it does not remove the permission + required by the subsequent Elastic Beanstalk update path. A live deployment + confirmed this boundary: `CreateApplicationVersion` succeeded, then + `UpdateEnvironment` was denied because the caller lacked + `s3:CreateBucket` on the service bucket. The permission is scoped to that + exact bucket-level ARN only (no object prefix, no wildcard resource), so it + cannot create any other bucket. + It grants **no** IAM mutation or `PassRole`, **no** RDS / EC2 / Secrets Manager access, and **no** administrator policy. There are no wildcard mutation surfaces. diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index 45291b3..b1e188c 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -73,7 +73,7 @@ export class DeployDevStack extends cdk.Stack { deployRole.addToPolicy( new iam.PolicyStatement({ effect: iam.Effect.ALLOW, - actions: ['s3:ListBucket'], + actions: ['s3:ListBucket', 's3:CreateBucket'], resources: [bucketArn], }), );