From c2f2c411d8927455a6d990dbaf5b50e4ff3daab3 Mon Sep 17 00:00:00 2001 From: brandizzi Date: Wed, 29 Jul 2026 10:33:31 -0300 Subject: [PATCH] fix(cdk): allow EB extension verification --- infra/cdk/README.md | 4 ++++ infra/cdk/deploy-dev-stack.ts | 9 +++++++++ 2 files changed, 13 insertions(+) diff --git a/infra/cdk/README.md b/infra/cdk/README.md index 0b9da58..c790ad8 100644 --- a/infra/cdk/README.md +++ b/infra/cdk/README.md @@ -73,6 +73,10 @@ The role grants only: prefix. CloudTrail recorded both denied actions and object ARNs. The grant does not include reads, deletes, ACL mutation, another application, another environment, or another bucket. +- `s3:GetObject` on only the environment-specific embedded-extension prefix + above. Attempt 10 showed that Elastic Beanstalk verifies the materialized + environment copy with `HeadObject`, which S3 authorizes through + `s3:GetObject`. The shared embedded-extension prefix remains write-only. - `s3:GetObjectAcl` on objects under the service-wide `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `178526484500047` confirmed that `UpdateEnvironment` uses the initiating diff --git a/infra/cdk/deploy-dev-stack.ts b/infra/cdk/deploy-dev-stack.ts index 78c1fdf..e0f3853 100644 --- a/infra/cdk/deploy-dev-stack.ts +++ b/infra/cdk/deploy-dev-stack.ts @@ -183,6 +183,15 @@ export class DeployDevStack extends cdk.Stack { }), ); + deployRole.addToPolicy( + new iam.PolicyStatement({ + effect: iam.Effect.ALLOW, + actions: ['s3:GetObject'], + // Elastic Beanstalk verifies the environment copy with HeadObject. + resources: [environmentEmbeddedExtensionArn], + }), + ); + deployRole.addToPolicy( new iam.PolicyStatement({ effect: iam.Effect.ALLOW,