From b02787087eb1aacc48329a6a65f3bd671d049027 Mon Sep 17 00:00:00 2001 From: brandizzi Date: Wed, 29 Jul 2026 08:56:19 -0300 Subject: [PATCH] fix(cdk): allow EB runtime bundle copy --- infra/cdk/README.md | 7 +++++++ infra/cdk/deploy-dev-stack.ts | 13 +++++++++++++ 2 files changed, 20 insertions(+) diff --git a/infra/cdk/README.md b/infra/cdk/README.md index 37446c4..4a61dc1 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -48,6 +48,13 @@ The role grants only: `s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned official deployment action requires to validate the `CreateApplicationVersion` source bundle after upload. +- `s3:PutObject` on only + `elasticbeanstalk-us-east-1-396287094661/resources/environments/e-hehnrqjjrt/_runtime/_versions/shoc-backend/*`. + Elastic Beanstalk copies each uploaded source bundle into this + environment-specific runtime prefix during `UpdateEnvironment`. Run + `30448885838` exposed the exact source and destination after the earlier ACL + denial was resolved. The grant does not cover another environment, another + application, bucket ACLs, object ACLs, tags, retention, deletion, or reads. - `s3:GetObjectAcl` on objects under the service-wide `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `178526484500047` confirmed that `UpdateEnvironment` uses the initiating diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index 36addaf..3047287 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -18,6 +18,9 @@ export class DeployDevStack extends cdk.Stack { const applicationArn = `arn:aws:elasticbeanstalk:${REGION}:${ACCOUNT_ID}:application/${APPLICATION_NAME}`; const environmentArn = `arn:aws:elasticbeanstalk:${REGION}:${ACCOUNT_ID}:environment/${APPLICATION_NAME}/${ENVIRONMENT_NAME}`; const bucketArn = `arn:aws:s3:::${BUCKET_NAME}`; + const runtimeVersionArn = + `${bucketArn}/resources/environments/${ENVIRONMENT_ID}` + + `/_runtime/_versions/${APPLICATION_NAME}/*`; const oidcProviderArn = `arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com`; const deployRole = new iam.Role(this, 'GithubDeployRole', { @@ -147,6 +150,16 @@ export class DeployDevStack extends cdk.Stack { }), ); + deployRole.addToPolicy( + new iam.PolicyStatement({ + effect: iam.Effect.ALLOW, + actions: ['s3:PutObject'], + // UpdateEnvironment copies the uploaded source bundle into this + // environment-specific runtime version prefix before deployment. + resources: [runtimeVersionArn], + }), + ); + deployRole.addToPolicy( new iam.PolicyStatement({ effect: iam.Effect.ALLOW,