Skip to content

Correct regional ECS task-definition inspection permission - #58

Merged
jckail merged 1 commit into
masterfrom
codex/pointup-ecs-read-permission
Oct 7, 2026
Merged

jckail merged 1 commit into
masterfrom
codex/pointup-ecs-read-permission

Conversation

@jckail

@jckail jckail commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

The first hosted production qualification created the inactive AWS stack, then CloudTrail recorded AccessDenied for ecs:DescribeTaskDefinition. AWS authorizes that read API against Resource "*" rather than task-definition ARNs.

Use the supported resource scope for this single read action and restrict it to the deployment region. Preserve production OIDC trust, all other IAM statements, and rollout checks that bind the returned task definition to the exact account and candidate. No database secret-value access is added.

Validation: seven targeted deployment IAM checks and diff checks pass. Exact0293080 CI37559019609 and CodeQL37559019618 passed, including application bundles, actual Docker/PostgreSQL smoke and infrastructure checks. The reviewed AWS change set modified only the existing inline IAM policy without replacement; live policy matches source and simulation allows us-east-1 while denying us-west-2. The current application stack is CREATE_COMPLETE with actual ECS desired/running/pending capacity zero; migration proof remains pending.

@jckail
jckail merged commit f3f5977 into master Oct 7, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant