From 5b719a660e67a87e4052794903789e291416b640 Mon Sep 17 00:00:00 2001 From: brandizzi Date: Wed, 29 Jul 2026 09:55:58 -0300 Subject: [PATCH] fix(cdk): allow EB environment extension write --- infra/cdk/README.md | 14 +++++++++----- infra/cdk/deploy-dev-stack.ts | 7 +++++-- 2 files changed, 14 insertions(+), 7 deletions(-) diff --git a/infra/cdk/README.md b/infra/cdk/README.md index 492db5b..0b9da58 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -62,13 +62,17 @@ The role grants only: the matching version-ACL write. The grant does not cover another environment, another application, source bundles, object content versions, non-version ACL mutation, tags, or retention. -- `s3:PutObject` on only - `elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*`. +- `s3:PutObject` on only the two embedded-extension prefixes + `elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*` + and + `elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_embedded_extensions/shoc-backend/*`. After the runtime bundle copy and version-ACL operations succeeded, attempt 8 of run `30448885838` showed Elastic Beanstalk materializing the application's - embedded-extension manifest at this application-specific prefix. CloudTrail - recorded the exact denied action and object ARN. The grant does not include - reads, deletes, ACL mutation, another application, or another bucket. + embedded-extension manifest at the application-specific shared prefix. + Attempt 9 then showed the matching write into the exact dev-environment + prefix. CloudTrail recorded both denied actions and object ARNs. The grant + does not include reads, deletes, ACL mutation, another application, + another environment, or another bucket. - `s3:GetObjectAcl` on objects under the service-wide `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `178526484500047` confirmed that `UpdateEnvironment` uses the initiating diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index 433d3b2..78c1fdf 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -24,6 +24,9 @@ export class DeployDevStack extends cdk.Stack { const embeddedExtensionArn = `${bucketArn}/resources/_runtime/_embedded_extensions/` + `${APPLICATION_NAME}/*`; + const environmentEmbeddedExtensionArn = + `${bucketArn}/resources/environments/${ENVIRONMENT_ID}` + + `/_runtime/_embedded_extensions/${APPLICATION_NAME}/*`; const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`; const deployRole = new iam.Role(this, 'GithubDeployRole', { @@ -175,8 +178,8 @@ export class DeployDevStack extends cdk.Stack { effect: iam.Effect.ALLOW, actions: ['s3:PutObject'], // UpdateEnvironment materializes the application's embedded-extension - // manifest under this application-specific runtime prefix. - resources: [embeddedExtensionArn], + // manifest under the shared and environment-specific runtime prefixes. + resources: [embeddedExtensionArn, environmentEmbeddedExtensionArn], }), );