s3:PutObject on shoc-backend/* covered only the upload the deploy action
performs itself. AWS Support case 178526484500047 established that
UpdateEnvironment then reads, writes, versions, ACL-checks and removes
objects as the calling identity, across both the account bucket and
AWS-owned Elastic Beanstalk service buckets whose names cannot be
enumerated in advance. That is the failure the dev lane already hit, and
staging calls the same deploy action and the same rollback
update-environment, so the first OIDC deploy and every rollback would
have stopped there.
Brings the staging role to parity with deploy-dev-stack.ts.
elasticbeanstalk:UpdateEnvironment stays pinned to the staging
environment ARN, so the role still cannot update or terminate
shoc-backend-dev.