From 307a5ed661efc62cac0b9cefe9476eac4f55a479 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 4 Jun 2026 16:50:19 -0400 Subject: [PATCH] fix: grant bedrock:GetGuardrail to agent execution role (#39) The Bedrock Agents service fetches the guardrail config via GetGuardrail before applying it. The role only had ApplyGuardrail, so every agent invocation logged an AccessDenied and tripped the CIS 4.1 UnauthorizedAPICalls alarm. Scoped to the same guardrail ARNs already granted for ApplyGuardrail. Cross-reviewed (IAM change): APPROVE, no findings. --- lib/constructs/bedrock-agent.ts | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/lib/constructs/bedrock-agent.ts b/lib/constructs/bedrock-agent.ts index c23efa2..27d4607 100644 --- a/lib/constructs/bedrock-agent.ts +++ b/lib/constructs/bedrock-agent.ts @@ -249,7 +249,9 @@ Keep responses concise, professional, and actionable.`; guardrailVersion.addDependency(guardrail); agentRole.addToPolicy(new iam.PolicyStatement({ - actions: ['bedrock:ApplyGuardrail'], + // GetGuardrail: the Agents service fetches the guardrail config before applying it — + // without it every InvokeAgent logs an AccessDenied (trips CIS 4.1 alarm) + actions: ['bedrock:ApplyGuardrail', 'bedrock:GetGuardrail'], // Base ARN plus version-suffixed children — runtime applies the versioned guardrail resources: [guardrail.attrGuardrailArn, `${guardrail.attrGuardrailArn}/*`], }));