mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 07:13:12 +00:00
fix(cdk): allow EB runtime bundle copy
This commit is contained in:
parent
68162ef0fb
commit
b02787087e
2 changed files with 20 additions and 0 deletions
|
|
@ -48,6 +48,13 @@ The role grants only:
|
|||
`s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned
|
||||
official deployment action requires to validate the
|
||||
`CreateApplicationVersion` source bundle after upload.
|
||||
- `s3:PutObject` on only
|
||||
`elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`.
|
||||
Elastic Beanstalk copies each uploaded source bundle into this
|
||||
environment-specific runtime prefix during `UpdateEnvironment`. Run
|
||||
`30448885838` exposed the exact source and destination after the earlier ACL
|
||||
denial was resolved. The grant does not cover another environment, another
|
||||
application, bucket ACLs, object ACLs, tags, retention, deletion, or reads.
|
||||
- `s3:GetObjectAcl` on objects under the service-wide
|
||||
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
||||
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
||||
|
|
|
|||
|
|
@ -18,6 +18,9 @@ export class DeployDevStack extends cdk.Stack {
|
|||
const applicationArn = `arn:aws:elasticbeanstalk:${REGION}:${ACCOUNT_ID}:application/${APPLICATION_NAME}`;
|
||||
const environmentArn = `arn:aws:elasticbeanstalk:${REGION}:${ACCOUNT_ID}:environment/${APPLICATION_NAME}/${ENVIRONMENT_NAME}`;
|
||||
const bucketArn = `arn:aws:s3:::${BUCKET_NAME}`;
|
||||
const runtimeVersionArn =
|
||||
`${bucketArn}/resources/environments/${ENVIRONMENT_ID}` +
|
||||
`/_runtime/_versions/${APPLICATION_NAME}/*`;
|
||||
const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`;
|
||||
|
||||
const deployRole = new iam.Role(this, 'GithubDeployRole', {
|
||||
|
|
@ -147,6 +150,16 @@ export class DeployDevStack extends cdk.Stack {
|
|||
}),
|
||||
);
|
||||
|
||||
deployRole.addToPolicy(
|
||||
new iam.PolicyStatement({
|
||||
effect: iam.Effect.ALLOW,
|
||||
actions: ['s3:PutObject'],
|
||||
// UpdateEnvironment copies the uploaded source bundle into this
|
||||
// environment-specific runtime version prefix before deployment.
|
||||
resources: [runtimeVersionArn],
|
||||
}),
|
||||
);
|
||||
|
||||
deployRole.addToPolicy(
|
||||
new iam.PolicyStatement({
|
||||
effect: iam.Effect.ALLOW,
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue