diff --git a/infra/lib/compute-stack.ts b/infra/lib/compute-stack.ts index 95b88b0..867d38c 100644 --- a/infra/lib/compute-stack.ts +++ b/infra/lib/compute-stack.ts @@ -86,6 +86,17 @@ export class ComputeStack extends cdk.Stack { resources: [`arn:aws:bedrock:us-east-1::foundation-model/amazon.titan-embed-text-v2:0`], })); + // Bedrock validates the Aurora vector-store config at KB-create time by calling + // rds:DescribeDBClusters — required or CreateKnowledgeBase 400s with "storage + // configuration provided is invalid" / rds:DescribeDBClusters AccessDenied. + // NOTE: rds:DescribeDBClusters does NOT support resource-level permissions (it is an + // account/region list action), so it must be Resource:* — scoping to the cluster ARN + // grants nothing. Read-only metadata; the role's sensitive actions stay scoped. + kbRole.addToPolicy(new iam.PolicyStatement({ + actions: ['rds:DescribeDBClusters'], + resources: ['*'], + })); + // KB queries the pgvector table via the RDS Data API as bedrock_user. kbRole.addToPolicy(new iam.PolicyStatement({ actions: [