mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 10:43:13 +00:00
New React Backend Repository
s3:PutObject on shoc-backend/* covered only the upload the deploy action performs itself. AWS Support case 178526484500047 established that UpdateEnvironment then reads, writes, versions, ACL-checks and removes objects as the calling identity, across both the account bucket and AWS-owned Elastic Beanstalk service buckets whose names cannot be enumerated in advance. That is the failure the dev lane already hit, and staging calls the same deploy action and the same rollback update-environment, so the first OIDC deploy and every rollback would have stopped there. Brings the staging role to parity with deploy-dev-stack.ts. elasticbeanstalk:UpdateEnvironment stays pinned to the staging environment ARN, so the role still cannot update or terminate shoc-backend-dev. |
||
|---|---|---|
| .ebextensions | ||
| .github | ||
| .security-review | ||
| Api.SeaHavenIndustries | ||
| Api.SeaHavenIndustries.Tests | ||
| Data.SeaHavenIndustries | ||
| docs | ||
| infra/cdk | ||
| scripts | ||
| SeaHaven.DataServices | ||
| SeaHaven.Services | ||
| SeaHaven.Services.Tests | ||
| SeaHavenIndustries | ||
| SeaHavenIndustries.Tests | ||
| .env.example | ||
| .gitattributes | ||
| .gitignore | ||
| AGENTS.md | ||
| ARCHITECTURE_AND_CODE_QUALITY.md | ||
| BACKEND_ARCHITECTURE.md | ||
| QUALITY_GATES.md | ||
| REVIEW_AND_PR_FRAMEWORK.md | ||
| SeaHavenIndustries.sln | ||
| TODO.md | ||