mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-05 22:22:13 +00:00
fix(cdk): allow EB runtime manifest updates
This commit is contained in:
parent
b8db4a7e61
commit
76cdc70c18
2 changed files with 19 additions and 0 deletions
|
|
@ -78,6 +78,12 @@ The role grants only:
|
||||||
above. Attempt 10 showed that Elastic Beanstalk verifies the materialized
|
above. Attempt 10 showed that Elastic Beanstalk verifies the materialized
|
||||||
environment copy with `HeadObject`, which S3 authorizes through
|
environment copy with `HeadObject`, which S3 authorizes through
|
||||||
`s3:GetObject`. The shared embedded-extension prefix remains write-only.
|
`s3:GetObject`. The shared embedded-extension prefix remains write-only.
|
||||||
|
- `s3:GetObject` and `s3:PutObject` on only
|
||||||
|
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/versions/*`.
|
||||||
|
Attempt 12 showed Elastic Beanstalk reading the previous environment version
|
||||||
|
manifest and writing its replacement under this exact dev-environment
|
||||||
|
runtime prefix. The grant excludes deletes, ACL mutation, other environments,
|
||||||
|
and application bundle content.
|
||||||
- `s3:GetObjectAcl` on objects under the service-wide
|
- `s3:GetObjectAcl` on objects under the service-wide
|
||||||
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
||||||
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
||||||
|
|
|
||||||
|
|
@ -27,6 +27,9 @@ export class DeployDevStack extends cdk.Stack {
|
||||||
const environmentEmbeddedExtensionArn =
|
const environmentEmbeddedExtensionArn =
|
||||||
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
|
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
|
||||||
`/_runtime/_embedded_extensions/${APPLICATION_NAME}/*`;
|
`/_runtime/_embedded_extensions/${APPLICATION_NAME}/*`;
|
||||||
|
const runtimeManifestArn =
|
||||||
|
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
|
||||||
|
'/_runtime/versions/*';
|
||||||
const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`;
|
const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`;
|
||||||
|
|
||||||
const deployRole = new iam.Role(this, 'GithubDeployRole', {
|
const deployRole = new iam.Role(this, 'GithubDeployRole', {
|
||||||
|
|
@ -193,6 +196,16 @@ export class DeployDevStack extends cdk.Stack {
|
||||||
}),
|
}),
|
||||||
);
|
);
|
||||||
|
|
||||||
|
deployRole.addToPolicy(
|
||||||
|
new iam.PolicyStatement({
|
||||||
|
effect: iam.Effect.ALLOW,
|
||||||
|
actions: ['s3:GetObject', 's3:PutObject'],
|
||||||
|
// UpdateEnvironment reads the prior environment version manifest and
|
||||||
|
// writes its replacement under this environment-only runtime prefix.
|
||||||
|
resources: [runtimeManifestArn],
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
|
||||||
deployRole.addToPolicy(
|
deployRole.addToPolicy(
|
||||||
new iam.PolicyStatement({
|
new iam.PolicyStatement({
|
||||||
effect: iam.Effect.ALLOW,
|
effect: iam.Effect.ALLOW,
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue