fix(cdk): allow EB runtime version ACL read

This commit is contained in:
brandizzi 2026-07-29 09:26:12 -03:00
parent 424bf20f54
commit 9f54399e63
2 changed files with 12 additions and 5 deletions

View file

@ -48,7 +48,8 @@ The role grants only:
`s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned
official deployment action requires to validate the
`CreateApplicationVersion` source bundle after upload.
- `s3:PutObject`, `s3:GetObject`, and `s3:DeleteObject` on only
- `s3:PutObject`, `s3:GetObject`, `s3:GetObjectVersionAcl`, and
`s3:DeleteObject` on only
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`.
Elastic Beanstalk copies each uploaded source bundle into this
environment-specific runtime prefix during `UpdateEnvironment`, verifies it
@ -56,9 +57,10 @@ The role grants only:
copy after the version is registered. Attempts 1 through 4 of run
`30448885838` exposed the exact source, destination, cleanup, and verification
operations after the earlier ACL denial was resolved. CloudTrail recorded
the exact `s3:GetObject` denial on attempt 4. The grant does not cover another
environment, another application, source bundles, object versions, bucket
ACLs, object ACLs, tags, or retention.
the exact `s3:GetObject` denial on attempt 4; attempt 6 then exposed the
version-specific ACL read performed on the copied object. The grant does not
cover another environment, another application, source bundles, object
content versions, ACL mutation, tags, or retention.
- `s3:GetObjectAcl` on objects under the service-wide
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating

View file

@ -153,7 +153,12 @@ export class DeployDevStack extends cdk.Stack {
deployRole.addToPolicy(
new iam.PolicyStatement({
effect: iam.Effect.ALLOW,
actions: ['s3:DeleteObject', 's3:GetObject', 's3:PutObject'],
actions: [
's3:DeleteObject',
's3:GetObject',
's3:GetObjectVersionAcl',
's3:PutObject',
],
// UpdateEnvironment copies the uploaded source bundle into this
// environment-specific runtime prefix, verifies the temporary copy,
// and removes it after the version is registered.