fix: make deploy artifacts immutable

This commit is contained in:
Alexandre Brandizzi 2026-07-28 10:38:38 -03:00
parent 73b525a685
commit da29dcf983
2 changed files with 6 additions and 3 deletions

View file

@ -109,13 +109,13 @@ jobs:
aws-region: us-east-1
application-name: shoc-backend
environment-name: shoc-backend-dev
version-label: ${{ github.sha }}
version-label: ${{ github.sha }}-${{ github.run_id }}-${{ github.run_attempt }}
deployment-package-path: .artifacts/elastic-beanstalk/site.zip
s3-bucket-name: elasticbeanstalk-us-east-1-396287094661
create-application-if-not-exists: "false"
create-environment-if-not-exists: "false"
create-s3-bucket-if-not-exists: "false"
use-existing-application-version-if-available: "true"
use-existing-application-version-if-available: "false"
wait-for-deployment: "true"
wait-for-environment-recovery: "true"

View file

@ -55,7 +55,10 @@ export class DeployDevStack extends cdk.Stack {
new iam.PolicyStatement({
effect: iam.Effect.ALLOW,
actions: ['elasticbeanstalk:CreateApplicationVersion'],
resources: [applicationArn],
resources: [
applicationArn,
`arn:aws:elasticbeanstalk:${REGION}:${ACCOUNT_ID}:applicationversion/${APPLICATION_NAME}/*`,
],
}),
);