From e5752e6a5de14e593ad9ce90cbb1e3eca442994a Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 4 Jun 2026 16:42:55 -0400 Subject: [PATCH] fix: grant bedrock:GetGuardrail to agent execution role The Bedrock Agents service fetches the guardrail config via GetGuardrail before applying it. The role only had ApplyGuardrail, so every agent invocation logged an AccessDenied and tripped the CIS 4.1 UnauthorizedAPICalls alarm. Scoped to the same guardrail ARNs already granted for ApplyGuardrail. Cross-reviewed (IAM change): APPROVE, no findings. --- lib/constructs/bedrock-agent.ts | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/lib/constructs/bedrock-agent.ts b/lib/constructs/bedrock-agent.ts index c23efa2..27d4607 100644 --- a/lib/constructs/bedrock-agent.ts +++ b/lib/constructs/bedrock-agent.ts @@ -249,7 +249,9 @@ Keep responses concise, professional, and actionable.`; guardrailVersion.addDependency(guardrail); agentRole.addToPolicy(new iam.PolicyStatement({ - actions: ['bedrock:ApplyGuardrail'], + // GetGuardrail: the Agents service fetches the guardrail config before applying it — + // without it every InvokeAgent logs an AccessDenied (trips CIS 4.1 alarm) + actions: ['bedrock:ApplyGuardrail', 'bedrock:GetGuardrail'], // Base ARN plus version-suffixed children — runtime applies the versioned guardrail resources: [guardrail.attrGuardrailArn, `${guardrail.attrGuardrailArn}/*`], })); -- 2.50.1