fix(iam): let staging githubdeploy GetObject the release zip (#154)
Some checks are pending
Architecture and changed-file quality / architecture (push) Waiting to run
Terraform CI / terraform (push) Waiting to run
Backend CI / Build and test (push) Waiting to run

* fix(iam): let staging githubdeploy GetObject the release zip

* fix(iam): allow staging githubdeploy to cache EB processed extensions

* fix(iam): allow staging githubdeploy GetObjectAcl for EB updates

* fix(iam): grant staging githubdeploy named S3 reads on EB resources prefix

* fix(iam): allow staging githubdeploy to delete EB version cache objects

* fix(iam): scope staging githubdeploy S3 object access to the EB bucket

* fix(iam): allow staging githubdeploy PutObjectVersionAcl on EB artifacts

* fix(iam): allow staging githubdeploy GetBucketPolicy on the EB bucket

* fix(iam): scope staging githubdeploy S3 objects to SHOC and staging EB prefixes
This commit is contained in:
Adam Moussa 2026-09-18 14:29:15 -04:00 • committed by GitHub
parent 90303f0e40
commit facc6ef71e
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -292,17 +292,37 @@ data "aws_iam_policy_document" "deploy" {
dynamic "statement" {
for_each = local.use_legacy_s3_policy ? [] : [1]
content {
effect = "Allow"
actions = ["s3:PutObject"]
resources = ["arn:aws:s3:::${local.eb_bucket_name}/${var.eb_application_name}/*"]
effect = "Allow"
actions = [
"s3:PutObject",
"s3:PutObjectAcl",
"s3:PutObjectVersionAcl",
"s3:GetObject",
"s3:GetObjectAcl",
"s3:GetObjectVersion",
"s3:GetObjectVersionAcl",
"s3:DeleteObject",
]
resources = [
"arn:aws:s3:::${local.eb_bucket_name}/${var.eb_application_name}/*",
"arn:aws:s3:::${local.eb_bucket_name}/resources/_runtime/_embedded_extensions/${var.eb_application_name}/*",
"arn:aws:s3:::${local.eb_bucket_name}/resources/environments/${var.eb_environment_id}/*",
]
}
}
dynamic "statement" {
for_each = local.use_legacy_s3_policy ? [] : [1]
content {
effect = "Allow"
actions = ["s3:GetBucketLocation", "s3:ListBucket"]
effect = "Allow"
actions = [
"s3:GetBucketLocation",
"s3:ListBucket",
"s3:GetBucketPolicy",
"s3:GetBucketAcl",
"s3:GetBucketVersioning",
"s3:GetBucketOwnershipControls",
]
resources = ["arn:aws:s3:::${local.eb_bucket_name}"]
}
}