mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 08:23:12 +00:00
fix(cdk): allow EB runtime manifest updates
This commit is contained in:
parent
b8db4a7e61
commit
76cdc70c18
2 changed files with 19 additions and 0 deletions
|
|
@ -78,6 +78,12 @@ The role grants only:
|
|||
above. Attempt 10 showed that Elastic Beanstalk verifies the materialized
|
||||
environment copy with `HeadObject`, which S3 authorizes through
|
||||
`s3:GetObject`. The shared embedded-extension prefix remains write-only.
|
||||
- `s3:GetObject` and `s3:PutObject` on only
|
||||
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/versions/*`.
|
||||
Attempt 12 showed Elastic Beanstalk reading the previous environment version
|
||||
manifest and writing its replacement under this exact dev-environment
|
||||
runtime prefix. The grant excludes deletes, ACL mutation, other environments,
|
||||
and application bundle content.
|
||||
- `s3:GetObjectAcl` on objects under the service-wide
|
||||
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
||||
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
||||
|
|
|
|||
|
|
@ -27,6 +27,9 @@ export class DeployDevStack extends cdk.Stack {
|
|||
const environmentEmbeddedExtensionArn =
|
||||
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
|
||||
`/_runtime/_embedded_extensions/${APPLICATION_NAME}/*`;
|
||||
const runtimeManifestArn =
|
||||
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
|
||||
'/_runtime/versions/*';
|
||||
const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`;
|
||||
|
||||
const deployRole = new iam.Role(this, 'GithubDeployRole', {
|
||||
|
|
@ -193,6 +196,16 @@ export class DeployDevStack extends cdk.Stack {
|
|||
}),
|
||||
);
|
||||
|
||||
deployRole.addToPolicy(
|
||||
new iam.PolicyStatement({
|
||||
effect: iam.Effect.ALLOW,
|
||||
actions: ['s3:GetObject', 's3:PutObject'],
|
||||
// UpdateEnvironment reads the prior environment version manifest and
|
||||
// writes its replacement under this environment-only runtime prefix.
|
||||
resources: [runtimeManifestArn],
|
||||
}),
|
||||
);
|
||||
|
||||
deployRole.addToPolicy(
|
||||
new iam.PolicyStatement({
|
||||
effect: iam.Effect.ALLOW,
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue