fix: grant bedrock:GetGuardrail to agent execution role (#39)

The Bedrock Agents service fetches the guardrail config via GetGuardrail
before applying it. The role only had ApplyGuardrail, so every agent
invocation logged an AccessDenied and tripped the CIS 4.1
UnauthorizedAPICalls alarm.

Scoped to the same guardrail ARNs already granted for ApplyGuardrail.
Cross-reviewed (IAM change): APPROVE, no findings.
This commit is contained in:
Adam Moussa 2026-06-04 16:50:19 -04:00 • committed by GitHub
parent d7b37e7ad0
commit 307a5ed661
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -249,7 +249,9 @@ Keep responses concise, professional, and actionable.`;
guardrailVersion.addDependency(guardrail);
agentRole.addToPolicy(new iam.PolicyStatement({
actions: ['bedrock:ApplyGuardrail'],
// GetGuardrail: the Agents service fetches the guardrail config before applying it —
// without it every InvokeAgent logs an AccessDenied (trips CIS 4.1 alarm)
actions: ['bedrock:ApplyGuardrail', 'bedrock:GetGuardrail'],
// Base ARN plus version-suffixed children — runtime applies the versioned guardrail
resources: [guardrail.attrGuardrailArn, `${guardrail.attrGuardrailArn}/*`],
}));