fix: grant bedrock:GetGuardrail to agent execution role

The Bedrock Agents service fetches the guardrail config via GetGuardrail
before applying it. The role only had ApplyGuardrail, so every agent
invocation logged an AccessDenied and tripped the CIS 4.1
UnauthorizedAPICalls alarm.

Scoped to the same guardrail ARNs already granted for ApplyGuardrail.
Cross-reviewed (IAM change): APPROVE, no findings.
This commit is contained in:
Adam Moussa 2026-06-04 16:42:55 -04:00
parent d7b37e7ad0
commit e5752e6a5d

View file

@ -249,7 +249,9 @@ Keep responses concise, professional, and actionable.`;
guardrailVersion.addDependency(guardrail);
agentRole.addToPolicy(new iam.PolicyStatement({
actions: ['bedrock:ApplyGuardrail'],
// GetGuardrail: the Agents service fetches the guardrail config before applying it —
// without it every InvokeAgent logs an AccessDenied (trips CIS 4.1 alarm)
actions: ['bedrock:ApplyGuardrail', 'bedrock:GetGuardrail'],
// Base ARN plus version-suffixed children — runtime applies the versioned guardrail
resources: [guardrail.attrGuardrailArn, `${guardrail.attrGuardrailArn}/*`],
}));