import * as cdk from "aws-cdk-lib"; import * as iam from "aws-cdk-lib/aws-iam"; import * as logs from "aws-cdk-lib/aws-logs"; import { Construct } from "constructs"; /** * Regional Bedrock model-invocation logging destination + delivery role * (INFRA-91). Bedrock invocation logging is account-level *per region*, so * extending the us-east-1 coverage (lib/bedrock-logging.ts) to the other * regions where Bedrock is reachable (us-west-2, us-east-2) requires a separate * regional stack with its own log group + delivery role per region. * * This codifies the out-of-band CLI state applied 2026-06 to MATCH exactly so * the adoption diff is minimal: * - IAM role seahaven-bedrock-invocation-logging- * - log group /aws/bedrock/model-invocations (90d) * - CloudWatch-only delivery (no S3 leg — unlike us-east-1, these regions log * to CloudWatch only; the large-payload S3 bucket is us-east-1 only). * * Like us-east-1, the account-level logging configuration itself has no CFN * resource type (`PutModelInvocationLoggingConfiguration`); it is applied via * CLI per region (already live — see README). This construct owns only the * destinations + role the live config references. */ export class BedrockLoggingRegional extends Construct { public readonly logGroup: logs.LogGroup; public readonly deliveryRole: iam.Role; constructor(scope: Construct, id: string) { super(scope, id); const stack = cdk.Stack.of(this); this.logGroup = new logs.LogGroup(this, "InvocationLogGroup", { logGroupName: "/aws/bedrock/model-invocations", retention: logs.RetentionDays.THREE_MONTHS, removalPolicy: cdk.RemovalPolicy.RETAIN, }); // Region-suffixed role name matches the live CLI-created role so CFN can // adopt it by import rather than creating a colliding new one. this.deliveryRole = new iam.Role(this, "DeliveryRole", { roleName: `seahaven-bedrock-invocation-logging-${stack.region}`, assumedBy: new iam.ServicePrincipal("bedrock.amazonaws.com", { conditions: { StringEquals: { "aws:SourceAccount": stack.account }, ArnLike: { "aws:SourceArn": `arn:aws:bedrock:${stack.region}:${stack.account}:*`, }, }, }), }); this.deliveryRole.addToPolicy( new iam.PolicyStatement({ actions: ["logs:CreateLogStream", "logs:PutLogEvents"], resources: [ this.logGroup.logGroupArn, `${this.logGroup.logGroupArn}:log-stream:*`, ], }), ); new cdk.CfnOutput(this, "BedrockLogGroupName", { value: this.logGroup.logGroupName, }); new cdk.CfnOutput(this, "BedrockLoggingRoleArn", { value: this.deliveryRole.roleArn, }); } }