mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-09-30 05:23:14 +00:00
fix(infra): grant KB role rds:DescribeDBClusters (prod deploy blocker) (#229)
The seahaven-prod deploy failed at CreateKnowledgeBase: the Bedrock KB execution role (proposal-system-kb-role) was denied rds:DescribeDBClusters, which Bedrock calls to validate the Aurora pgvector store config. Add it. rds:DescribeDBClusters does NOT support resource-level scoping (account/region list action) so it must be Resource:*; the role's sensitive actions (rds-data:*, s3, InvokeModel, secret) stay tightly scoped. GPT-4.1 cross-review APPROVE (caught the Resource:* requirement).
This commit is contained in:
parent
0c5b294ffc
commit
590f0c075c
1 changed files with 11 additions and 0 deletions
|
|
@ -86,6 +86,17 @@ export class ComputeStack extends cdk.Stack {
|
|||
resources: [`arn:aws:bedrock:us-east-1::foundation-model/amazon.titan-embed-text-v2:0`],
|
||||
}));
|
||||
|
||||
// Bedrock validates the Aurora vector-store config at KB-create time by calling
|
||||
// rds:DescribeDBClusters — required or CreateKnowledgeBase 400s with "storage
|
||||
// configuration provided is invalid" / rds:DescribeDBClusters AccessDenied.
|
||||
// NOTE: rds:DescribeDBClusters does NOT support resource-level permissions (it is an
|
||||
// account/region list action), so it must be Resource:* — scoping to the cluster ARN
|
||||
// grants nothing. Read-only metadata; the role's sensitive actions stay scoped.
|
||||
kbRole.addToPolicy(new iam.PolicyStatement({
|
||||
actions: ['rds:DescribeDBClusters'],
|
||||
resources: ['*'],
|
||||
}));
|
||||
|
||||
// KB queries the pgvector table via the RDS Data API as bedrock_user.
|
||||
kbRole.addToPolicy(new iam.PolicyStatement({
|
||||
actions: [
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue