fix(cdk): allow EB extension verification

This commit is contained in:
brandizzi 2026-07-29 10:33:31 -03:00
parent 5b719a660e
commit c2f2c411d8
2 changed files with 13 additions and 0 deletions

View file

@ -73,6 +73,10 @@ The role grants only:
prefix. CloudTrail recorded both denied actions and object ARNs. The grant prefix. CloudTrail recorded both denied actions and object ARNs. The grant
does not include reads, deletes, ACL mutation, another application, does not include reads, deletes, ACL mutation, another application,
another environment, or another bucket. another environment, or another bucket.
- `s3:GetObject` on only the environment-specific embedded-extension prefix
above. Attempt 10 showed that Elastic Beanstalk verifies the materialized
environment copy with `HeadObject`, which S3 authorizes through
`s3:GetObject`. The shared embedded-extension prefix remains write-only.
- `s3:GetObjectAcl` on objects under the service-wide - `s3:GetObjectAcl` on objects under the service-wide
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case `arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating `178526484500047` confirmed that `UpdateEnvironment` uses the initiating

View file

@ -183,6 +183,15 @@ export class DeployDevStack extends cdk.Stack {
}), }),
); );
deployRole.addToPolicy(
new iam.PolicyStatement({
effect: iam.Effect.ALLOW,
actions: ['s3:GetObject'],
// Elastic Beanstalk verifies the environment copy with HeadObject.
resources: [environmentEmbeddedExtensionArn],
}),
);
deployRole.addToPolicy( deployRole.addToPolicy(
new iam.PolicyStatement({ new iam.PolicyStatement({
effect: iam.Effect.ALLOW, effect: iam.Effect.ALLOW,