From 9f54399e63e044c49e0dc9ac5cf0689760531d70 Mon Sep 17 00:00:00 2001 From: brandizzi Date: Wed, 29 Jul 2026 09:26:12 -0300 Subject: [PATCH] fix(cdk): allow EB runtime version ACL read --- infra/cdk/README.md | 10 ++++++---- infra/cdk/deploy-dev-stack.ts | 7 ++++++- 2 files changed, 12 insertions(+), 5 deletions(-) diff --git a/infra/cdk/README.md b/infra/cdk/README.md index e84694b..7588086 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -48,7 +48,8 @@ The role grants only: `s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned official deployment action requires to validate the `CreateApplicationVersion` source bundle after upload. -- `s3:PutObject`, `s3:GetObject`, and `s3:DeleteObject` on only +- `s3:PutObject`, `s3:GetObject`, `s3:GetObjectVersionAcl`, and + `s3:DeleteObject` on only `elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`. Elastic Beanstalk copies each uploaded source bundle into this environment-specific runtime prefix during `UpdateEnvironment`, verifies it @@ -56,9 +57,10 @@ The role grants only: copy after the version is registered. Attempts 1 through 4 of run `30448885838` exposed the exact source, destination, cleanup, and verification operations after the earlier ACL denial was resolved. CloudTrail recorded - the exact `s3:GetObject` denial on attempt 4. The grant does not cover another - environment, another application, source bundles, object versions, bucket - ACLs, object ACLs, tags, or retention. + the exact `s3:GetObject` denial on attempt 4; attempt 6 then exposed the + version-specific ACL read performed on the copied object. The grant does not + cover another environment, another application, source bundles, object + content versions, ACL mutation, tags, or retention. - `s3:GetObjectAcl` on objects under the service-wide `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `178526484500047` confirmed that `UpdateEnvironment` uses the initiating diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index 88c6009..97350e7 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -153,7 +153,12 @@ export class DeployDevStack extends cdk.Stack { deployRole.addToPolicy( new iam.PolicyStatement({ effect: iam.Effect.ALLOW, - actions: ['s3:DeleteObject', 's3:GetObject', 's3:PutObject'], + actions: [ + 's3:DeleteObject', + 's3:GetObject', + 's3:GetObjectVersionAcl', + 's3:PutObject', + ], // UpdateEnvironment copies the uploaded source bundle into this // environment-specific runtime prefix, verifies the temporary copy, // and removes it after the version is registered.