fix(cdk): allow EB bucket policy read

This commit is contained in:
brandizzi 2026-07-29 11:02:30 -03:00
parent c2f2c411d8
commit b8db4a7e61
2 changed files with 3 additions and 1 deletions

View file

@ -42,7 +42,8 @@ The role grants only:
- `elasticbeanstalk:UpdateEnvironment` on environment `shoc-backend-dev` only.
- `s3:ListBucket` and `s3:GetBucketLocation` on
`elasticbeanstalk-us-east-1-396287094661` (the official action's
ownership-safe bucket checks), plus `s3:CreateBucket` and
ownership-safe bucket checks), `s3:GetBucketPolicy` for the policy inspection
observed in attempt 11 of run `30448885838`, plus `s3:CreateBucket` and
`s3:PutBucketOwnershipControls` on the same bucket-level ARN. Under the
`shoc-backend/` object prefix only:
`s3:PutObject`, `s3:GetObject`, and `s3:GetObjectVersion`, which the pinned

View file

@ -143,6 +143,7 @@ export class DeployDevStack extends cdk.Stack {
's3:CreateBucket',
's3:PutBucketOwnershipControls',
's3:GetBucketLocation',
's3:GetBucketPolicy',
],
resources: [bucketArn],
}),