The @cdklabs/generative-ai-cdk-constructs VectorKnowledgeBase hardcodes
AllowFromPublic: true on the auto-created AOSS network policy and exposes
no prop to change it. Override the underlying CfnSecurityPolicy to set the
collection rule to AllowFromPublic: false with
SourceServices: ['bedrock.amazonaws.com'] — the latter is required to keep
Bedrock-managed retrieval working once public access is removed (a
SourceVPCEs-only policy returns 401 for Bedrock retrieve). Dashboard rule
kept public for console access; AWS services cannot reach Dashboards.
Same end state was applied live via update-security-policy and smoke-tested
(retrieve returns hits, top score ~0.40) so this deploy is a no-op convergence.
INFRA-92
Adds an access log group (/aws/apigateway/seahaven-slack-webhook, 90-day
retention) with JSON access-log format and DefaultRouteSettings throttling
(rate 2 rps, burst 5) on the seahaven-slack-webhook HTTP API default stage,
applied via CfnStage property overrides. Matches the pattern landed on
seahaven-door-unlock-api.
Refs INFRA-29 (AWS audit M-18)
The Bedrock Agents service fetches the guardrail config via GetGuardrail
before applying it. The role only had ApplyGuardrail, so every agent
invocation logged an AccessDenied and tripped the CIS 4.1
UnauthorizedAPICalls alarm.
Scoped to the same guardrail ARNs already granted for ApplyGuardrail.
Cross-reviewed (IAM change): APPROVE, no findings.
Audit finding M-19: the employee-facing assistant had no guardrail
despite access to QBO, payments, WO/PO, and HR/SA8000 data.
Adds prompt-attack (HIGH input), content filters, and masking of
credential/financial identifiers (SSN, cards, bank numbers, keys).
Names/emails/phones deliberately unmasked - vendor contact lookup is
the bot's core function. MISCONDUCT output at MEDIUM so SA8000
misconduct-reporting questions are not suppressed.
Cross-reviewed (1 BLOCK fixed: ApplyGuardrail now covers version-
suffixed ARNs; explicit guardrail->version->agent dependencies added).
Alias description bump forces a new agent version (v10) so the live
alias snapshots the guardrail config.
fromAsset() builds for the host architecture by default. On x86_64
GitHub Actions runners, this produces an x86 image even with QEMU
installed — the Fargate ARM64 task then fails with exec format error.
Removes CloudFormation dynamic references for clientId/clientSecret
env vars. Credentials are now fetched from Secrets Manager at runtime
so secret updates don't require a redeploy.
Puts qbo-lookup and qbo-oauth Lambdas in seahaven-vpc private subnets
so all outbound traffic routes through NAT Gateway (52.202.83.13).
Required for Intuit app listing IP allowlist.
Adds /qbo/connect, /qbo/callback, /qbo/disconnect, and /qbo/launch
routes to bot.seahaven.com for Intuit app store compliance. Also
updates qbo-lookup to persist rotated refresh tokens automatically.
- Create SiteAssignments DynamoDB table with state GSI for site code and
state-based queries
- Add lookup_site function to wo-po-lookup action group lambda
- Add seed script (scripts/seed-sites.ts) to load site CSV into DynamoDB
- Upload site list markdown to KB S3 bucket for semantic search
- Update agent instruction to include site lookup capability
- Update README with site assignment docs and maintenance notes
The bot was suggesting Sea Haven as a vendor to contact because it didn't
understand it belongs to Sea Haven. Updated system prompt to make clear
that Sea Haven is our company and "local vendor" means a subcontractor.
Vector search couldn't match exact work order/PO numbers, so queries
always came back empty. This adds a dedicated lambda that queries
DynamoDB directly by ID, wired as a Bedrock Agent action group.
- Bump Lambda timeout from 5min to 15min (9k+ POs need more time)
- Upload S3 files 25x concurrently instead of sequentially
- Replace clear-then-write with overwrite-in-place + delete stale
to avoid S3 404s during concurrent KB ingestion jobs
Add a new Lambda and CDK construct that scans the WorkOrders and
WorkOrderComments DynamoDB tables (owned by workorder-ingest),
converts each work order + comment history to markdown, uploads
to S3 under the work-orders/ prefix, and triggers a Bedrock
Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.
Add a new Lambda and CDK construct that scans the purchase-orders
DynamoDB table (owned by po-ingest), converts each PO to markdown,
uploads to S3 under the purchase-orders/ prefix, and triggers a
Bedrock Knowledge Base ingestion job. Runs daily at 02:00 UTC via
EventBridge alongside the existing Notion sync.
Adds a scheduled Lambda that pulls all pages from the Office Operations
Notion teamspace, converts them to markdown, uploads to the KB S3 bucket
under a notion/ prefix, and triggers a Bedrock ingestion job. Runs daily
at 02:00 UTC via EventBridge. Notion API key stored in Secrets Manager at
seahaven/notion/api-key (placeholder — fill in post-deploy).
- Post '_Sea Haven Assistant is thinking..._' immediately on receipt,
then update the message with the real response (chat.update)
- Broaden Maps location parameter description so agent passes facility
names like 'Amazon BFI9' directly to Google Maps rather than asking
the user to provide a street address
- Update foundation model to us.anthropic.claude-sonnet-4-5-20250929-v1:0
(cross-region inference profile required for Claude 4.x on Bedrock Agents)
- Broaden agent role IAM policy to cover wildcard-region foundation model ARN
and inference profile ARN
- Force alias version bump via description change so CloudFormation creates
agent version 2 with the updated model
- Remove invalid includedType: 'contractor' from Google Maps Places API request
(caused 400 Bad Request — not a valid place type for searchText endpoint)
- CDK stack for Sea Haven Industries internal Slack assistant
- Bedrock Agent (Claude 3.5 Sonnet) with QBO + Google Maps action groups
- VectorKnowledgeBase via @cdklabs/generative-ai-cdk-constructs (AOSS + S3)
- Slack webhook/processor Lambdas with DM-only filtering
- API Gateway HTTP API on bot.seahaven.com
- DynamoDB conversation log with 90-day TTL
- Secrets Manager references for Slack, QBO OAuth, and Google Maps