INFRA-92: lock seahaven-kb AOSS network policy to private #49
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#49
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "INFRA-92-lock-aoss-private"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Lock the live
seahaven-kbAOSS collection (gv1540frh1crb79gtr4b, KBLSDCNHTH6O) network policy from public to private while keeping Bedrock-managed retrieval working.The
@cdklabs/generative-ai-cdk-constructsVectorKnowledgeBasehardcodesAllowFromPublic: trueon the auto-created network policy and exposes no prop to change it. This overrides the underlyingCfnSecurityPolicyviaaddPropertyOverride:AllowFromPublic: false+SourceServices: ["bedrock.amazonaws.com"]— the source service is REQUIRED to keep Bedrock-managed retrieval working (a SourceVPCEs-only policy returns 401 for Bedrockretrieve).Same logical ID and physical name (
networkpolicyseahactors97a89b9b) — in-place update, no replacement.Already applied live
This same end state was already applied to the live resource via
aws opensearchserverless update-security-policy(the KB is live production for the Slack bot + exec-aide; could not wait for merge to validate). Smoke tests after the flip:AllowFromPublicconfirmedfalseon the collection rule.bedrock-agent-runtime retrieveagainst KBLSDCNHTH6Oreturns real hits across multiple content types (top scores 0.40–0.44, baseline ~0.40).cdk synthof this branch produces a policy byte-identical to what is live, so the CI deploy on merge is a no-op convergence (no drift).Notes
NetworkPolicychild lookup and the resolvedcollectionName.cdk diffalso shows a SocketMode ECS task-def replacement and an OpenSearch CR provider Lambda asset-hash change — these are pre-existing local-build asset-hash drift unrelated to this change, which is why the policy change was applied via the AOSS API rather than a local full-stackcdk deploy. The CI runner builds assets cleanly.Test plan
tsc --noEmitcleancdk synthproduces correct private policyretrievesmoke test passes post-flipINFRA-92