mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-10-03 10:23:17 +00:00
fix(infra): grant KB role rds:DescribeDBClusters (prod deploy blocker) (#229)
The seahaven-prod deploy failed at CreateKnowledgeBase: the Bedrock KB execution role (proposal-system-kb-role) was denied rds:DescribeDBClusters, which Bedrock calls to validate the Aurora pgvector store config. Add it. rds:DescribeDBClusters does NOT support resource-level scoping (account/region list action) so it must be Resource:*; the role's sensitive actions (rds-data:*, s3, InvokeModel, secret) stay tightly scoped. GPT-4.1 cross-review APPROVE (caught the Resource:* requirement).
This commit is contained in:
parent
0c5b294ffc
commit
590f0c075c
1 changed files with 11 additions and 0 deletions
|
|
@ -86,6 +86,17 @@ export class ComputeStack extends cdk.Stack {
|
||||||
resources: [`arn:aws:bedrock:us-east-1::foundation-model/amazon.titan-embed-text-v2:0`],
|
resources: [`arn:aws:bedrock:us-east-1::foundation-model/amazon.titan-embed-text-v2:0`],
|
||||||
}));
|
}));
|
||||||
|
|
||||||
|
// Bedrock validates the Aurora vector-store config at KB-create time by calling
|
||||||
|
// rds:DescribeDBClusters — required or CreateKnowledgeBase 400s with "storage
|
||||||
|
// configuration provided is invalid" / rds:DescribeDBClusters AccessDenied.
|
||||||
|
// NOTE: rds:DescribeDBClusters does NOT support resource-level permissions (it is an
|
||||||
|
// account/region list action), so it must be Resource:* — scoping to the cluster ARN
|
||||||
|
// grants nothing. Read-only metadata; the role's sensitive actions stay scoped.
|
||||||
|
kbRole.addToPolicy(new iam.PolicyStatement({
|
||||||
|
actions: ['rds:DescribeDBClusters'],
|
||||||
|
resources: ['*'],
|
||||||
|
}));
|
||||||
|
|
||||||
// KB queries the pgvector table via the RDS Data API as bedrock_user.
|
// KB queries the pgvector table via the RDS Data API as bedrock_user.
|
||||||
kbRole.addToPolicy(new iam.PolicyStatement({
|
kbRole.addToPolicy(new iam.PolicyStatement({
|
||||||
actions: [
|
actions: [
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue