fix: grant bedrock:GetGuardrail to agent execution role #39

Merged
amoussa1229 merged 1 commit from fix/guardrail-get-permission into main 2026-06-04 20:50:20 +00:00
amoussa1229 commented 2026-06-04 20:43:16 +00:00 (Migrated from github.com)

Summary

  • Adds bedrock:GetGuardrail to the agent execution role's guardrail statement, scoped to the same guardrail ARNs as the existing ApplyGuardrail grant.

Why

The Bedrock Agents service fetches the guardrail config (GetGuardrail) before applying it. Since the guardrail was added in #38, every invocation of seahaven-alex has logged an AccessDenied, tripping the cis-UnauthorizedAPICalls alarm (2 denials at 16:05 UTC today = today's alarm).

Cross-review

IAM change — cross-reviewed via orchestrator cross_reviewer: APPROVE, no findings. Read-only describe action, no over-scoping; role updates in-place, no agent version bump needed.

Verification

Deploy-before-merge: deployed from this branch, then confirmed agent invocation produces no new AccessDenied events in the trail log group.

## Summary - Adds `bedrock:GetGuardrail` to the agent execution role's guardrail statement, scoped to the same guardrail ARNs as the existing `ApplyGuardrail` grant. ## Why The Bedrock Agents service fetches the guardrail config (`GetGuardrail`) before applying it. Since the guardrail was added in #38, every invocation of seahaven-alex has logged an `AccessDenied`, tripping the `cis-UnauthorizedAPICalls` alarm (2 denials at 16:05 UTC today = today's alarm). ## Cross-review IAM change — cross-reviewed via orchestrator `cross_reviewer`: **APPROVE**, no findings. Read-only describe action, no over-scoping; role updates in-place, no agent version bump needed. ## Verification Deploy-before-merge: deployed from this branch, then confirmed agent invocation produces no new `AccessDenied` events in the trail log group.
This repo is archived. You cannot comment on pull requests.
No description provided.