Commit graph

3 commits

Author SHA1 Message Date
Alexandre Brandizzi
4aef5b463b fix: grant staging deploy role the Support-confirmed Elastic Beanstalk S3 set
s3:PutObject on shoc-backend/* covered only the upload the deploy action
performs itself. AWS Support case 178526484500047 established that
UpdateEnvironment then reads, writes, versions, ACL-checks and removes
objects as the calling identity, across both the account bucket and
AWS-owned Elastic Beanstalk service buckets whose names cannot be
enumerated in advance. That is the failure the dev lane already hit, and
staging calls the same deploy action and the same rollback
update-environment, so the first OIDC deploy and every rollback would
have stopped there.

Brings the staging role to parity with deploy-dev-stack.ts.
elasticbeanstalk:UpdateEnvironment stays pinned to the staging
environment ARN, so the role still cannot update or terminate
shoc-backend-dev.
2026-08-31 10:57:04 -03:00
Alexandre Brandizzi
caa8970b17 fix: scope staging release bucket access 2026-08-27 20:45:12 -03:00
Alexandre Brandizzi
2fb9540aa0 ci: add protected staging deployment lane 2026-08-27 20:26:46 -03:00