fix: grant bedrock:GetGuardrail to agent execution role #39
1 changed files with 3 additions and 1 deletions
|
|
@ -249,7 +249,9 @@ Keep responses concise, professional, and actionable.`;
|
|||
guardrailVersion.addDependency(guardrail);
|
||||
|
||||
agentRole.addToPolicy(new iam.PolicyStatement({
|
||||
actions: ['bedrock:ApplyGuardrail'],
|
||||
// GetGuardrail: the Agents service fetches the guardrail config before applying it —
|
||||
// without it every InvokeAgent logs an AccessDenied (trips CIS 4.1 alarm)
|
||||
actions: ['bedrock:ApplyGuardrail', 'bedrock:GetGuardrail'],
|
||||
// Base ARN plus version-suffixed children — runtime applies the versioned guardrail
|
||||
resources: [guardrail.attrGuardrailArn, `${guardrail.attrGuardrailArn}/*`],
|
||||
}));
|
||||
|
|
|
|||
Reference in a new issue