diff --git a/lib/org-governance-stack.ts b/lib/org-governance-stack.ts index a6faf3a..a2ed2c2 100644 --- a/lib/org-governance-stack.ts +++ b/lib/org-governance-stack.ts @@ -143,6 +143,16 @@ export class OrgGovernanceStack extends cdk.Stack { // are carved out of the general deny and re-denied only outside // {us-east-1, us-west-2, us-east-2} so cross-region inference profiles // (us.anthropic.*) that route to us-east-2 are not blocked. + // chatbot:* is exempted because AWS Chatbot ("Amazon Q Developer in chat + // applications") is a global management service: the console setup flow + // hits its control plane in us-east-2 (observed deny: + // chatbot:GetSlackOauthParameters at aws:RequestedRegion=us-east-2), which + // is outside the approved region set, so without this exemption the region + // deny blocks Slack workspace/channel setup for site-alerts → Slack. A + // full-prefix NotAction (region-agnostic, like iam:*/cloudfront:*) is the + // right shape: it names a global management service, not a workload running + // in an unapproved region. The notification-side resources (the site-alerts + // SNS topic, alarms) stay in us-east-1 and remain region-locked. const workloadsRegionLock = new organizations.CfnPolicy(this, "WorkloadsRegionLock", { name: "workloads-region-lock", type: "SERVICE_CONTROL_POLICY", @@ -160,7 +170,7 @@ export class OrgGovernanceStack extends cdk.Stack { "route53domains:*", "cloudfront:*", "waf:*", "shield:*", "globalaccelerator:*", "budgets:*", "ce:*", "cur:*", "health:*", "support:*", "supportplans:*", "trustedadvisor:*", "artifact:*", - "aws-portal:*", + "aws-portal:*", "chatbot:*", ...BEDROCK_INVOKE_ACTIONS, ], Resource: "*",