mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-04 23:02:10 +00:00
fix: allow Elastic Beanstalk bucket setup check (#36)
This commit is contained in:
parent
8f41190a74
commit
45ffa68dfa
2 changed files with 17 additions and 4 deletions
|
|
@ -41,11 +41,24 @@ The role grants only:
|
||||||
- `elasticbeanstalk:CreateApplicationVersion` on application `shoc-backend`.
|
- `elasticbeanstalk:CreateApplicationVersion` on application `shoc-backend`.
|
||||||
- `elasticbeanstalk:UpdateEnvironment` on environment `shoc-backend-dev` only.
|
- `elasticbeanstalk:UpdateEnvironment` on environment `shoc-backend-dev` only.
|
||||||
- `s3:ListBucket` on `elasticbeanstalk-us-east-1-396287094661` (the official
|
- `s3:ListBucket` on `elasticbeanstalk-us-east-1-396287094661` (the official
|
||||||
action's ownership-safe `HeadBucket` check). Under the `shoc-backend/` object
|
action's ownership-safe `HeadBucket` check), plus `s3:CreateBucket` on the
|
||||||
prefix only: `s3:PutObject` plus `s3:GetObject` and `s3:GetObjectVersion`,
|
same bucket-level ARN. Under the `shoc-backend/` object prefix only:
|
||||||
which the pinned official deployment action requires to validate the
|
`s3:PutObject` plus `s3:GetObject` and `s3:GetObjectVersion`, which the
|
||||||
|
pinned official deployment action requires to validate the
|
||||||
`CreateApplicationVersion` source bundle after upload.
|
`CreateApplicationVersion` source bundle after upload.
|
||||||
|
|
||||||
|
`s3:CreateBucket` is part of the pinned
|
||||||
|
`aws-actions/aws-elasticbeanstalk-deploy@cfad3e5e...` (v1.0.6) IAM
|
||||||
|
contract even though the workflow sets
|
||||||
|
`create-s3-bucket-if-not-exists: "false"`. That input prevents the
|
||||||
|
action's explicit bucket-creation helper; it does not remove the permission
|
||||||
|
required by the subsequent Elastic Beanstalk update path. A live deployment
|
||||||
|
confirmed this boundary: `CreateApplicationVersion` succeeded, then
|
||||||
|
`UpdateEnvironment` was denied because the caller lacked
|
||||||
|
`s3:CreateBucket` on the service bucket. The permission is scoped to that
|
||||||
|
exact bucket-level ARN only (no object prefix, no wildcard resource), so it
|
||||||
|
cannot create any other bucket.
|
||||||
|
|
||||||
It grants **no** IAM mutation or `PassRole`, **no** RDS / EC2 / Secrets Manager
|
It grants **no** IAM mutation or `PassRole`, **no** RDS / EC2 / Secrets Manager
|
||||||
access, and **no** administrator policy. There are no wildcard mutation
|
access, and **no** administrator policy. There are no wildcard mutation
|
||||||
surfaces.
|
surfaces.
|
||||||
|
|
|
||||||
|
|
@ -73,7 +73,7 @@ export class DeployDevStack extends cdk.Stack {
|
||||||
deployRole.addToPolicy(
|
deployRole.addToPolicy(
|
||||||
new iam.PolicyStatement({
|
new iam.PolicyStatement({
|
||||||
effect: iam.Effect.ALLOW,
|
effect: iam.Effect.ALLOW,
|
||||||
actions: ['s3:ListBucket'],
|
actions: ['s3:ListBucket', 's3:CreateBucket'],
|
||||||
resources: [bucketArn],
|
resources: [bucketArn],
|
||||||
}),
|
}),
|
||||||
);
|
);
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue