This repository has been archived on 2026-08-04. You can view files and clone it, but cannot push or open issues or pull requests.
seahaven-slack-bot/lib/constructs
Adam Moussa fd775556fc fix(kb): lock AOSS network policy to private with Bedrock source service
The @cdklabs/generative-ai-cdk-constructs VectorKnowledgeBase hardcodes
AllowFromPublic: true on the auto-created AOSS network policy and exposes
no prop to change it. Override the underlying CfnSecurityPolicy to set the
collection rule to AllowFromPublic: false with
SourceServices: ['bedrock.amazonaws.com'] — the latter is required to keep
Bedrock-managed retrieval working once public access is removed (a
SourceVPCEs-only policy returns 401 for Bedrock retrieve). Dashboard rule
kept public for console access; AWS services cannot reach Dashboards.

Same end state was applied live via update-security-policy and smoke-tested
(retrieve returns hits, top score ~0.40) so this deploy is a no-op convergence.

INFRA-92
2026-06-08 17:59:33 -04:00
..
bedrock-agent.ts fix: grant bedrock:GetGuardrail to agent execution role (#39) 2026-06-04 16:50:19 -04:00
conversation-log.ts feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions 2026-04-30 16:38:54 -04:00
knowledge-base.ts fix(kb): lock AOSS network policy to private with Bedrock source service 2026-06-08 17:59:33 -04:00
notion-sync.ts feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions 2026-04-30 16:38:54 -04:00
po-sync.ts feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions 2026-04-30 16:38:54 -04:00
slack-handler.ts feat(api): add access logging and throttling to webhook HTTP API (#46) 2026-06-05 17:47:44 -04:00
socket-mode.ts Set explicit arm64 platform on Docker image build (#30) 2026-05-08 17:58:28 -04:00
workorder-sync.ts feat: Alex rollout — persona, Socket Mode, payments, channels, App Home, unanswered questions 2026-04-30 16:38:54 -04:00