Commit graph

3 commits

Author SHA1 Message Date
Adam Moussa
5175d39eb9
fix(kb): lock AOSS network policy to private with Bedrock source service (#49)
The @cdklabs/generative-ai-cdk-constructs VectorKnowledgeBase hardcodes
AllowFromPublic: true on the auto-created AOSS network policy and exposes
no prop to change it. Override the underlying CfnSecurityPolicy to set the
collection rule to AllowFromPublic: false with
SourceServices: ['bedrock.amazonaws.com'] — the latter is required to keep
Bedrock-managed retrieval working once public access is removed (a
SourceVPCEs-only policy returns 401 for Bedrock retrieve). Dashboard rule
kept public for console access; AWS services cannot reach Dashboards.

Same end state was applied live via update-security-policy and smoke-tested
(retrieve returns hits, top score ~0.40) so this deploy is a no-op convergence.

INFRA-92
2026-06-08 18:01:08 -04:00
Adam Moussa
510834533b Add work order and purchase order lookups to Bedrock agent instructions
The agent's system prompt and KB description didn't mention WO/PO data,
so it refused queries even though the data was already in the knowledge base.
2026-04-13 17:05:26 -04:00
Adam Moussa
f7e63e50c9 Initial scaffold: Bedrock-backed Slack DM bot
- CDK stack for Sea Haven Industries internal Slack assistant
- Bedrock Agent (Claude 3.5 Sonnet) with QBO + Google Maps action groups
- VectorKnowledgeBase via @cdklabs/generative-ai-cdk-constructs (AOSS + S3)
- Slack webhook/processor Lambdas with DM-only filtering
- API Gateway HTTP API on bot.seahaven.com
- DynamoDB conversation log with 90-day TTL
- Secrets Manager references for Slack, QBO OAuth, and Google Maps
2026-04-11 23:15:15 -04:00