INFRA-92: lock seahaven-kb AOSS network policy to private #49

Merged
amoussa1229 merged 1 commit from INFRA-92-lock-aoss-private into main 2026-06-08 22:01:09 +00:00
amoussa1229 commented 2026-06-08 21:59:59 +00:00 (Migrated from github.com)

What

Lock the live seahaven-kb AOSS collection (gv1540frh1crb79gtr4b, KB LSDCNHTH6O) network policy from public to private while keeping Bedrock-managed retrieval working.

The @cdklabs/generative-ai-cdk-constructs VectorKnowledgeBase hardcodes AllowFromPublic: true on the auto-created network policy and exposes no prop to change it. This overrides the underlying CfnSecurityPolicy via addPropertyOverride:

  • Collection rule: AllowFromPublic: false + SourceServices: ["bedrock.amazonaws.com"] — the source service is REQUIRED to keep Bedrock-managed retrieval working (a SourceVPCEs-only policy returns 401 for Bedrock retrieve).
  • Dashboard rule: kept public for console access (AWS services cannot reach Dashboards regardless, so this does not affect the data plane).

Same logical ID and physical name (networkpolicyseahactors97a89b9b) — in-place update, no replacement.

Already applied live

This same end state was already applied to the live resource via aws opensearchserverless update-security-policy (the KB is live production for the Slack bot + exec-aide; could not wait for merge to validate). Smoke tests after the flip:

  • AllowFromPublic confirmed false on the collection rule.
  • bedrock-agent-runtime retrieve against KB LSDCNHTH6O returns real hits across multiple content types (top scores 0.40–0.44, baseline ~0.40).

cdk synth of this branch produces a policy byte-identical to what is live, so the CI deploy on merge is a no-op convergence (no drift).

Notes

  • Hardened per cross-review (GPT-4.1): runtime guards on the NetworkPolicy child lookup and the resolved collectionName.
  • cdk diff also shows a SocketMode ECS task-def replacement and an OpenSearch CR provider Lambda asset-hash change — these are pre-existing local-build asset-hash drift unrelated to this change, which is why the policy change was applied via the AOSS API rather than a local full-stack cdk deploy. The CI runner builds assets cleanly.

Test plan

  • tsc --noEmit clean
  • cdk synth produces correct private policy
  • Live retrieve smoke test passes post-flip

INFRA-92

## What Lock the live `seahaven-kb` AOSS collection (`gv1540frh1crb79gtr4b`, KB `LSDCNHTH6O`) network policy from public to private while keeping Bedrock-managed retrieval working. The `@cdklabs/generative-ai-cdk-constructs` `VectorKnowledgeBase` hardcodes `AllowFromPublic: true` on the auto-created network policy and exposes no prop to change it. This overrides the underlying `CfnSecurityPolicy` via `addPropertyOverride`: - **Collection rule:** `AllowFromPublic: false` + `SourceServices: ["bedrock.amazonaws.com"]` — the source service is REQUIRED to keep Bedrock-managed retrieval working (a SourceVPCEs-only policy returns 401 for Bedrock `retrieve`). - **Dashboard rule:** kept public for console access (AWS services cannot reach Dashboards regardless, so this does not affect the data plane). Same logical ID and physical name (`networkpolicyseahactors97a89b9b`) — in-place update, no replacement. ## Already applied live This same end state was already applied to the live resource via `aws opensearchserverless update-security-policy` (the KB is live production for the Slack bot + exec-aide; could not wait for merge to validate). Smoke tests after the flip: - `AllowFromPublic` confirmed `false` on the collection rule. - `bedrock-agent-runtime retrieve` against KB `LSDCNHTH6O` returns real hits across multiple content types (top scores 0.40–0.44, baseline ~0.40). `cdk synth` of this branch produces a policy byte-identical to what is live, so the CI deploy on merge is a no-op convergence (no drift). ## Notes - Hardened per cross-review (GPT-4.1): runtime guards on the `NetworkPolicy` child lookup and the resolved `collectionName`. - `cdk diff` also shows a SocketMode ECS task-def replacement and an OpenSearch CR provider Lambda asset-hash change — these are pre-existing local-build asset-hash drift unrelated to this change, which is why the policy change was applied via the AOSS API rather than a local full-stack `cdk deploy`. The CI runner builds assets cleanly. ## Test plan - [x] `tsc --noEmit` clean - [x] `cdk synth` produces correct private policy - [x] Live `retrieve` smoke test passes post-flip INFRA-92
This repo is archived. You cannot comment on pull requests.
No description provided.