fix(eks): let the provisioner decrypt the storage bucket's objects - #2495
Merged
Merged
Conversation
The aws-dev smoke failed in content delivery (RaesContentDeliveryError): the provisioner may s3:GetObject the storage bucket but held no grant on the bucket's SSE-KMS key, so downloading any delivered payload (the acquired Claude Code binary, pack content) failed. NGFW bootstrap uploads to the same bucket lacked kms:GenerateDataKey for the same reason. provisioner-iam now takes the bucket's KMS key and grants Decrypt and GenerateDataKey on exactly that key, only through S3; eks-provisioner-env resolves it from the portal storage alias. The simulator allows it under the role's permissions boundary, and the key policy delegates to account IAM. Refs #2463
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The aws-dev post-deploy smoke fails in content delivery:
The provisioner IRSA role may
s3:GetObjectthe storage bucket (provisioner-iams3-agent-read) but holds no grant on the bucket's SSE-KMS key (alias/shifter-<env>-portal-s3). Downloading any delivered payload (pack content, recipe-acquired feature artifacts) therefore fails. The simulator showedkms:DecryptasimplicitDenyfor the role. NGFW bootstrap uploads to the same bucket (s3-bootstrap-write) lackedkms:GenerateDataKeyfor the same reason.Change
provisioner-iamtakes a requiredagent_s3_kms_key_arnand grantskms:Decryptandkms:GenerateDataKeyon exactly that key, conditioned onkms:ViaService = s3.<region>.amazonaws.com.eks-provisioner-envresolves the key from the portal storage alias and passes it in.Verification
terraform test -filter=tests/native_ec2.tftest.hclinprovisioner-iampasses, with a new run pinning the statement to the key, the two actions, and the S3 via-service condition.terraform validatepasses foreks-provisioner-env.Refs #2463