fix: grant bedrock:GetGuardrail to agent execution role #39
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#39
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "fix/guardrail-get-permission"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
bedrock:GetGuardrailto the agent execution role's guardrail statement, scoped to the same guardrail ARNs as the existingApplyGuardrailgrant.Why
The Bedrock Agents service fetches the guardrail config (
GetGuardrail) before applying it. Since the guardrail was added in #38, every invocation of seahaven-alex has logged anAccessDenied, tripping thecis-UnauthorizedAPICallsalarm (2 denials at 16:05 UTC today = today's alarm).Cross-review
IAM change — cross-reviewed via orchestrator
cross_reviewer: APPROVE, no findings. Read-only describe action, no over-scoping; role updates in-place, no agent version bump needed.Verification
Deploy-before-merge: deployed from this branch, then confirmed agent invocation produces no new
AccessDeniedevents in the trail log group.