fix(cdk): allow EB environment extension write

This commit is contained in:
brandizzi 2026-07-29 09:55:58 -03:00
parent 3f60730464
commit 5b719a660e
2 changed files with 14 additions and 7 deletions

View file

@ -62,13 +62,17 @@ The role grants only:
the matching version-ACL write. The grant does not cover another the matching version-ACL write. The grant does not cover another
environment, another application, source bundles, object content versions, environment, another application, source bundles, object content versions,
non-version ACL mutation, tags, or retention. non-version ACL mutation, tags, or retention.
- `s3:PutObject` on only - `s3:PutObject` on only the two embedded-extension prefixes
`elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*`. `elasticbeanstalk-us-east-1-396287094661/resources/_runtime/_embedded_extensions/shoc-backend/*`
and
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_embedded_extensions/shoc-backend/*`.
After the runtime bundle copy and version-ACL operations succeeded, attempt 8 After the runtime bundle copy and version-ACL operations succeeded, attempt 8
of run `30448885838` showed Elastic Beanstalk materializing the application's of run `30448885838` showed Elastic Beanstalk materializing the application's
embedded-extension manifest at this application-specific prefix. CloudTrail embedded-extension manifest at the application-specific shared prefix.
recorded the exact denied action and object ARN. The grant does not include Attempt 9 then showed the matching write into the exact dev-environment
reads, deletes, ACL mutation, another application, or another bucket. prefix. CloudTrail recorded both denied actions and object ARNs. The grant
does not include reads, deletes, ACL mutation, another application,
another environment, or another bucket.
- `s3:GetObjectAcl` on objects under the service-wide - `s3:GetObjectAcl` on objects under the service-wide
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating `178526484500047` confirmed that `UpdateEnvironment` uses the initiating

View file

@ -24,6 +24,9 @@ export class DeployDevStack extends cdk.Stack {
const embeddedExtensionArn = const embeddedExtensionArn =
`${bucketArn}/resources/_runtime/_embedded_extensions/` + `${bucketArn}/resources/_runtime/_embedded_extensions/` +
`${APPLICATION_NAME}/*`; `${APPLICATION_NAME}/*`;
const environmentEmbeddedExtensionArn =
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
`/_runtime/_embedded_extensions/${APPLICATION_NAME}/*`;
const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`; const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`;
const deployRole = new iam.Role(this, 'GithubDeployRole', { const deployRole = new iam.Role(this, 'GithubDeployRole', {
@ -175,8 +178,8 @@ export class DeployDevStack extends cdk.Stack {
effect: iam.Effect.ALLOW, effect: iam.Effect.ALLOW,
actions: ['s3:PutObject'], actions: ['s3:PutObject'],
// UpdateEnvironment materializes the application's embedded-extension // UpdateEnvironment materializes the application's embedded-extension
// manifest under this application-specific runtime prefix. // manifest under the shared and environment-specific runtime prefixes.
resources: [embeddedExtensionArn], resources: [embeddedExtensionArn, environmentEmbeddedExtensionArn],
}), }),
); );