From fd775556fc543362e8656366bf3f07ecaa8b06d9 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Mon, 8 Jun 2026 17:59:33 -0400 Subject: [PATCH] fix(kb): lock AOSS network policy to private with Bedrock source service MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The @cdklabs/generative-ai-cdk-constructs VectorKnowledgeBase hardcodes AllowFromPublic: true on the auto-created AOSS network policy and exposes no prop to change it. Override the underlying CfnSecurityPolicy to set the collection rule to AllowFromPublic: false with SourceServices: ['bedrock.amazonaws.com'] — the latter is required to keep Bedrock-managed retrieval working once public access is removed (a SourceVPCEs-only policy returns 401 for Bedrock retrieve). Dashboard rule kept public for console access; AWS services cannot reach Dashboards. Same end state was applied live via update-security-policy and smoke-tested (retrieve returns hits, top score ~0.40) so this deploy is a no-op convergence. INFRA-92 --- lib/constructs/knowledge-base.ts | 52 ++++++++++++++++++++++++++++++++ 1 file changed, 52 insertions(+) diff --git a/lib/constructs/knowledge-base.ts b/lib/constructs/knowledge-base.ts index d412e46..0fc9f3c 100644 --- a/lib/constructs/knowledge-base.ts +++ b/lib/constructs/knowledge-base.ts @@ -1,6 +1,7 @@ import * as cdk from 'aws-cdk-lib'; import { Construct } from 'constructs'; import * as s3 from 'aws-cdk-lib/aws-s3'; +import * as oss from 'aws-cdk-lib/aws-opensearchserverless'; import { bedrock } from '@cdklabs/generative-ai-cdk-constructs'; export interface KnowledgeBaseProps { @@ -37,6 +38,57 @@ export class KnowledgeBaseConstruct extends Construct { instruction: 'Use this knowledge base to answer questions about Sea Haven Industries company policies, SOPs, SA8000 social accountability compliance requirements, approved vendor lists, the employee handbook, work order status and history, and purchase order details.', }); + // Lock the auto-created AOSS network policy to private (INFRA-92). + // @cdklabs/generative-ai-cdk-constructs hardcodes AllowFromPublic: true on the + // VectorCollection's network policy and exposes no prop to change it, so we reach + // the underlying CfnSecurityPolicy via the construct tree and override its Policy. + // SourceServices: ['bedrock.amazonaws.com'] is REQUIRED — it is what keeps + // Bedrock-managed retrieval working once public access is removed. A SourceVPCEs-only + // policy returns 401 for Bedrock retrieval. Dashboard rule kept for console access + // (AWS services cannot reach Dashboards regardless). + const vectorCollection = this.knowledgeBase.vectorStore as Construct; + const networkPolicy = vectorCollection.node.findChild('NetworkPolicy'); + if (!(networkPolicy instanceof oss.CfnSecurityPolicy)) { + throw new Error( + "Expected child 'NetworkPolicy' of the AOSS VectorCollection to be a CfnSecurityPolicy. " + + 'The @cdklabs/generative-ai-cdk-constructs internals may have changed — review knowledge-base.ts (INFRA-92).', + ); + } + const collectionName = (this.knowledgeBase.vectorStore as { collectionName?: string }).collectionName; + if (!collectionName) { + throw new Error( + 'Could not resolve the AOSS collection name from vectorStore — check the @cdklabs construct API (INFRA-92).', + ); + } + // Policy is typed as a JSON string on the L1 CfnSecurityPolicy, so it must be stringified. + networkPolicy.addPropertyOverride( + 'Policy', + JSON.stringify([ + { + Rules: [ + { + ResourceType: 'collection', + Resource: [`collection/${collectionName}`], + }, + ], + AllowFromPublic: false, + SourceServices: ['bedrock.amazonaws.com'], + }, + { + Rules: [ + { + ResourceType: 'dashboard', + Resource: [`collection/${collectionName}`], + }, + ], + // INFRA-92: dashboard endpoint intentionally left public for console access. + // AWS services (incl. Bedrock) cannot reach Dashboards regardless, so this does + // not affect the data plane. Remove this rule to fully lock down console access. + AllowFromPublic: true, + }, + ]), + ); + // S3 data source — chunking configured via ChunkingStrategy.fixedSize() this.dataSource = new bedrock.S3DataSource(this, 'S3DataSource', { bucket: this.docsBucket, -- 2.50.1