mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 07:13:12 +00:00
fix(cdk): allow EB extension verification
This commit is contained in:
parent
5b719a660e
commit
c2f2c411d8
2 changed files with 13 additions and 0 deletions
|
|
@ -73,6 +73,10 @@ The role grants only:
|
|||
prefix. CloudTrail recorded both denied actions and object ARNs. The grant
|
||||
does not include reads, deletes, ACL mutation, another application,
|
||||
another environment, or another bucket.
|
||||
- `s3:GetObject` on only the environment-specific embedded-extension prefix
|
||||
above. Attempt 10 showed that Elastic Beanstalk verifies the materialized
|
||||
environment copy with `HeadObject`, which S3 authorizes through
|
||||
`s3:GetObject`. The shared embedded-extension prefix remains write-only.
|
||||
- `s3:GetObjectAcl` on objects under the service-wide
|
||||
`arn:aws:s3:::elasticbeanstalk-*/*` namespace. AWS Support case
|
||||
`178526484500047` confirmed that `UpdateEnvironment` uses the initiating
|
||||
|
|
|
|||
|
|
@ -183,6 +183,15 @@ export class DeployDevStack extends cdk.Stack {
|
|||
}),
|
||||
);
|
||||
|
||||
deployRole.addToPolicy(
|
||||
new iam.PolicyStatement({
|
||||
effect: iam.Effect.ALLOW,
|
||||
actions: ['s3:GetObject'],
|
||||
// Elastic Beanstalk verifies the environment copy with HeadObject.
|
||||
resources: [environmentEmbeddedExtensionArn],
|
||||
}),
|
||||
);
|
||||
|
||||
deployRole.addToPolicy(
|
||||
new iam.PolicyStatement({
|
||||
effect: iam.Effect.ALLOW,
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue