The @cdklabs/generative-ai-cdk-constructs VectorKnowledgeBase hardcodes
AllowFromPublic: true on the auto-created AOSS network policy and exposes
no prop to change it. Override the underlying CfnSecurityPolicy to set the
collection rule to AllowFromPublic: false with
SourceServices: ['bedrock.amazonaws.com'] — the latter is required to keep
Bedrock-managed retrieval working once public access is removed (a
SourceVPCEs-only policy returns 401 for Bedrock retrieve). Dashboard rule
kept public for console access; AWS services cannot reach Dashboards.
Same end state was applied live via update-security-policy and smoke-tested
(retrieve returns hits, top score ~0.40) so this deploy is a no-op convergence.
INFRA-92
- CDK stack for Sea Haven Industries internal Slack assistant
- Bedrock Agent (Claude 3.5 Sonnet) with QBO + Google Maps action groups
- VectorKnowledgeBase via @cdklabs/generative-ai-cdk-constructs (AOSS + S3)
- Slack webhook/processor Lambdas with DM-only filtering
- API Gateway HTTP API on bot.seahaven.com
- DynamoDB conversation log with 90-day TTL
- Secrets Manager references for Slack, QBO OAuth, and Google Maps