The @cdklabs/generative-ai-cdk-constructs VectorKnowledgeBase hardcodes AllowFromPublic: true on the auto-created AOSS network policy and exposes no prop to change it. Override the underlying CfnSecurityPolicy to set the collection rule to AllowFromPublic: false with SourceServices: ['bedrock.amazonaws.com'] — the latter is required to keep Bedrock-managed retrieval working once public access is removed (a SourceVPCEs-only policy returns 401 for Bedrock retrieve). Dashboard rule kept public for console access; AWS services cannot reach Dashboards. Same end state was applied live via update-security-policy and smoke-tested (retrieve returns hits, top score ~0.40) so this deploy is a no-op convergence. INFRA-92 |
||
|---|---|---|
| .. | ||
| bedrock-agent.ts | ||
| conversation-log.ts | ||
| knowledge-base.ts | ||
| notion-sync.ts | ||
| po-sync.ts | ||
| slack-handler.ts | ||
| socket-mode.ts | ||
| workorder-sync.ts | ||