mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 07:13:12 +00:00
fix(cdk): allow EB extension verification
This commit is contained in:
parent
5b719a660e
commit
c2f2c411d8
2 changed files with 13 additions and 0 deletions
|
|
@ -73,6 +73,10 @@ The role grants only:
|
||||||
prefix. CloudTrail recorded both denied actions and object ARNs. The grant
|
prefix. CloudTrail recorded both denied actions and object ARNs. The grant
|
||||||
does not include reads, deletes, ACL mutation, another application,
|
does not include reads, deletes, ACL mutation, another application,
|
||||||
another environment, or another bucket.
|
another environment, or another bucket.
|
||||||
|
- `s3:GetObject` on only the environment-specific embedded-extension prefix
|
||||||
|
above. Attempt 10 showed that Elastic Beanstalk verifies the materialized
|
||||||
|
environment copy with `HeadObject`, which S3 authorizes through
|
||||||
|
`s3:GetObject`. The shared embedded-extension prefix remains write-only.
|
||||||
- `s3:GetObjectAcl` on objects under the service-wide
|
- `s3:GetObjectAcl` on objects under the service-wide
|
||||||
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
||||||
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
||||||
|
|
|
||||||
|
|
@ -183,6 +183,15 @@ export class DeployDevStack extends cdk.Stack {
|
||||||
}),
|
}),
|
||||||
);
|
);
|
||||||
|
|
||||||
|
deployRole.addToPolicy(
|
||||||
|
new iam.PolicyStatement({
|
||||||
|
effect: iam.Effect.ALLOW,
|
||||||
|
actions: ['s3:GetObject'],
|
||||||
|
// Elastic Beanstalk verifies the environment copy with HeadObject.
|
||||||
|
resources: [environmentEmbeddedExtensionArn],
|
||||||
|
}),
|
||||||
|
);
|
||||||
|
|
||||||
deployRole.addToPolicy(
|
deployRole.addToPolicy(
|
||||||
new iam.PolicyStatement({
|
new iam.PolicyStatement({
|
||||||
effect: iam.Effect.ALLOW,
|
effect: iam.Effect.ALLOW,
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue