shoc-backend/infra
Alexandre Brandizzi 4aef5b463b fix: grant staging deploy role the Support-confirmed Elastic Beanstalk S3 set
s3:PutObject on shoc-backend/* covered only the upload the deploy action
performs itself. AWS Support case 178526484500047 established that
UpdateEnvironment then reads, writes, versions, ACL-checks and removes
objects as the calling identity, across both the account bucket and
AWS-owned Elastic Beanstalk service buckets whose names cannot be
enumerated in advance. That is the failure the dev lane already hit, and
staging calls the same deploy action and the same rollback
update-environment, so the first OIDC deploy and every rollback would
have stopped there.

Brings the staging role to parity with deploy-dev-stack.ts.
elasticbeanstalk:UpdateEnvironment stays pinned to the staging
environment ARN, so the role still cannot update or terminate
shoc-backend-dev.
2026-08-31 10:57:04 -03:00
..
cdk fix: grant staging deploy role the Support-confirmed Elastic Beanstalk S3 set 2026-08-31 10:57:04 -03:00