mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 07:13:12 +00:00
fix(cdk): allow EB environment extension write
This commit is contained in:
parent
3f60730464
commit
5b719a660e
2 changed files with 14 additions and 7 deletions
|
|
@ -62,13 +62,17 @@ The role grants only:
|
|||
the matching version-ACL write. The grant does not cover another
|
||||
environment, another application, source bundles, object content versions,
|
||||
non-version ACL mutation, tags, or retention.
|
||||
- `s3:PutObject` on only
|
||||
`elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*`.
|
||||
- `s3:PutObject` on only the two embedded-extension prefixes
|
||||
`elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*`
|
||||
and
|
||||
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_embedded_extensions/shoc-backend/*`.
|
||||
After the runtime bundle copy and version-ACL operations succeeded, attempt 8
|
||||
of run `30448885838` showed Elastic Beanstalk materializing the application's
|
||||
embedded-extension manifest at this application-specific prefix. CloudTrail
|
||||
recorded the exact denied action and object ARN. The grant does not include
|
||||
reads, deletes, ACL mutation, another application, or another bucket.
|
||||
embedded-extension manifest at the application-specific shared prefix.
|
||||
Attempt 9 then showed the matching write into the exact dev-environment
|
||||
prefix. CloudTrail recorded both denied actions and object ARNs. The grant
|
||||
does not include reads, deletes, ACL mutation, another application,
|
||||
another environment, or another bucket.
|
||||
- `s3:GetObjectAcl` on objects under the service-wide
|
||||
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
||||
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
||||
|
|
|
|||
|
|
@ -24,6 +24,9 @@ export class DeployDevStack extends cdk.Stack {
|
|||
const embeddedExtensionArn =
|
||||
`${bucketArn}/resources/_runtime/_embedded_extensions/` +
|
||||
`${APPLICATION_NAME}/*`;
|
||||
const environmentEmbeddedExtensionArn =
|
||||
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
|
||||
`/_runtime/_embedded_extensions/${APPLICATION_NAME}/*`;
|
||||
const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`;
|
||||
|
||||
const deployRole = new iam.Role(this, 'GithubDeployRole', {
|
||||
|
|
@ -175,8 +178,8 @@ export class DeployDevStack extends cdk.Stack {
|
|||
effect: iam.Effect.ALLOW,
|
||||
actions: ['s3:PutObject'],
|
||||
// UpdateEnvironment materializes the application's embedded-extension
|
||||
// manifest under this application-specific runtime prefix.
|
||||
resources: [embeddedExtensionArn],
|
||||
// manifest under the shared and environment-specific runtime prefixes.
|
||||
resources: [embeddedExtensionArn, environmentEmbeddedExtensionArn],
|
||||
}),
|
||||
);
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue