fix(cdk): allow EB runtime version ACL read

This commit is contained in:
brandizzi 2026-07-29 09:26:12 -03:00
parent 424bf20f54
commit 9f54399e63
2 changed files with 12 additions and 5 deletions

View file

@ -48,7 +48,8 @@ The role grants only:
`s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned `s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned
official deployment action requires to validate the official deployment action requires to validate the
`CreateApplicationVersion` source bundle after upload. `CreateApplicationVersion` source bundle after upload.
- `s3:PutObject`, `s3:GetObject`, and `s3:DeleteObject` on only - `s3:PutObject`, `s3:GetObject`, `s3:GetObjectVersionAcl`, and
`s3:DeleteObject` on only
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`. `elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`.
Elastic Beanstalk copies each uploaded source bundle into this Elastic Beanstalk copies each uploaded source bundle into this
environment-specific runtime prefix during `UpdateEnvironment`, verifies it environment-specific runtime prefix during `UpdateEnvironment`, verifies it
@ -56,9 +57,10 @@ The role grants only:
copy after the version is registered. Attempts 1 through 4 of run copy after the version is registered. Attempts 1 through 4 of run
`30448885838` exposed the exact source, destination, cleanup, and verification `30448885838` exposed the exact source, destination, cleanup, and verification
operations after the earlier ACL denial was resolved. CloudTrail recorded operations after the earlier ACL denial was resolved. CloudTrail recorded
the exact `s3:GetObject` denial on attempt 4. The grant does not cover another the exact `s3:GetObject` denial on attempt 4; attempt 6 then exposed the
environment, another application, source bundles, object versions, bucket version-specific ACL read performed on the copied object. The grant does not
ACLs, object ACLs, tags, or retention. cover another environment, another application, source bundles, object
content versions, ACL mutation, tags, or retention.
- `s3:GetObjectAcl` on objects under the service-wide - `s3:GetObjectAcl` on objects under the service-wide
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating `178526484500047` confirmed that `UpdateEnvironment` uses the initiating

View file

@ -153,7 +153,12 @@ export class DeployDevStack extends cdk.Stack {
deployRole.addToPolicy( deployRole.addToPolicy(
new iam.PolicyStatement({ new iam.PolicyStatement({
effect: iam.Effect.ALLOW, effect: iam.Effect.ALLOW,
actions: ['s3:DeleteObject', 's3:GetObject', 's3:PutObject'], actions: [
's3:DeleteObject',
's3:GetObject',
's3:GetObjectVersionAcl',
's3:PutObject',
],
// UpdateEnvironment copies the uploaded source bundle into this // UpdateEnvironment copies the uploaded source bundle into this
// environment-specific runtime prefix, verifies the temporary copy, // environment-specific runtime prefix, verifies the temporary copy,
// and removes it after the version is registered. // and removes it after the version is registered.