Skip to content

fix(eks): let the provisioner decrypt the storage bucket's objects - #2495

Merged
Brad-Edwards merged 1 commit into
devfrom
fix/eks-provisioner-storage-kms
Oct 5, 2026
Merged

Brad-Edwards merged 1 commit into
devfrom
fix/eks-provisioner-storage-kms

Conversation

@Brad-Edwards

Copy link
Copy Markdown
Owner

Problem

The aws-dev post-deploy smoke fails in content delivery:

range reached terminal status failed (...): cloud_operation_failed: raes range provision failed (RaesContentDeliveryError)

The provisioner IRSA role may s3:GetObject the storage bucket (provisioner-iam s3-agent-read) but holds no grant on the bucket's SSE-KMS key (alias/shifter-<env>-portal-s3). Downloading any delivered payload (pack content, recipe-acquired feature artifacts) therefore fails. The simulator showed kms:Decrypt as implicitDeny for the role. NGFW bootstrap uploads to the same bucket (s3-bootstrap-write) lacked kms:GenerateDataKey for the same reason.

Change

  • provisioner-iam takes a required agent_s3_kms_key_arn and grants kms:Decrypt and kms:GenerateDataKey on exactly that key, conditioned on kms:ViaService = s3.<region>.amazonaws.com.
  • eks-provisioner-env resolves the key from the portal storage alias and passes it in.

Verification

  • terraform test -filter=tests/native_ec2.tftest.hcl in provisioner-iam passes, with a new run pinning the statement to the key, the two actions, and the S3 via-service condition.
  • terraform validate passes for eks-provisioner-env.
  • IAM simulator: both actions allowed under the role's permissions boundary; the key policy delegates to account IAM.
  • Live: aws-dev redeploy with this change is running.

Refs #2463

The aws-dev smoke failed in content delivery (RaesContentDeliveryError): the
provisioner may s3:GetObject the storage bucket but held no grant on the
bucket's SSE-KMS key, so downloading any delivered payload (the acquired
Claude Code binary, pack content) failed. NGFW bootstrap uploads to the same
bucket lacked kms:GenerateDataKey for the same reason.

provisioner-iam now takes the bucket's KMS key and grants Decrypt and
GenerateDataKey on exactly that key, only through S3; eks-provisioner-env
resolves it from the portal storage alias. The simulator allows it under the
role's permissions boundary, and the key policy delegates to account IAM.

Refs #2463
@Brad-Edwards
Brad-Edwards merged commit abe9267 into dev Oct 5, 2026
113 checks passed
@Brad-Edwards
Brad-Edwards deleted the fix/eks-provisioner-storage-kms branch October 5, 2026 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant