mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-10-05 20:02:09 +00:00
fix(iam): let staging githubdeploy GetObject the release zip (#154)
* fix(iam): let staging githubdeploy GetObject the release zip * fix(iam): allow staging githubdeploy to cache EB processed extensions * fix(iam): allow staging githubdeploy GetObjectAcl for EB updates * fix(iam): grant staging githubdeploy named S3 reads on EB resources prefix * fix(iam): allow staging githubdeploy to delete EB version cache objects * fix(iam): scope staging githubdeploy S3 object access to the EB bucket * fix(iam): allow staging githubdeploy PutObjectVersionAcl on EB artifacts * fix(iam): allow staging githubdeploy GetBucketPolicy on the EB bucket * fix(iam): scope staging githubdeploy S3 objects to SHOC and staging EB prefixes
This commit is contained in:
parent
90303f0e40
commit
facc6ef71e
1 changed files with 25 additions and 5 deletions
|
|
@ -292,17 +292,37 @@ data "aws_iam_policy_document" "deploy" {
|
||||||
dynamic "statement" {
|
dynamic "statement" {
|
||||||
for_each = local.use_legacy_s3_policy ? [] : [1]
|
for_each = local.use_legacy_s3_policy ? [] : [1]
|
||||||
content {
|
content {
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
actions = ["s3:PutObject"]
|
actions = [
|
||||||
resources = ["arn:aws:s3:::${local.eb_bucket_name}/${var.eb_application_name}/*"]
|
"s3:PutObject",
|
||||||
|
"s3:PutObjectAcl",
|
||||||
|
"s3:PutObjectVersionAcl",
|
||||||
|
"s3:GetObject",
|
||||||
|
"s3:GetObjectAcl",
|
||||||
|
"s3:GetObjectVersion",
|
||||||
|
"s3:GetObjectVersionAcl",
|
||||||
|
"s3:DeleteObject",
|
||||||
|
]
|
||||||
|
resources = [
|
||||||
|
"arn:aws:s3:::${local.eb_bucket_name}/${var.eb_application_name}/*",
|
||||||
|
"arn:aws:s3:::${local.eb_bucket_name}/resources/_runtime/_embedded_extensions/${var.eb_application_name}/*",
|
||||||
|
"arn:aws:s3:::${local.eb_bucket_name}/resources/environments/${var.eb_environment_id}/*",
|
||||||
|
]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
dynamic "statement" {
|
dynamic "statement" {
|
||||||
for_each = local.use_legacy_s3_policy ? [] : [1]
|
for_each = local.use_legacy_s3_policy ? [] : [1]
|
||||||
content {
|
content {
|
||||||
effect = "Allow"
|
effect = "Allow"
|
||||||
actions = ["s3:GetBucketLocation", "s3:ListBucket"]
|
actions = [
|
||||||
|
"s3:GetBucketLocation",
|
||||||
|
"s3:ListBucket",
|
||||||
|
"s3:GetBucketPolicy",
|
||||||
|
"s3:GetBucketAcl",
|
||||||
|
"s3:GetBucketVersioning",
|
||||||
|
"s3:GetBucketOwnershipControls",
|
||||||
|
]
|
||||||
resources = ["arn:aws:s3:::${local.eb_bucket_name}"]
|
resources = ["arn:aws:s3:::${local.eb_bucket_name}"]
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue