Skip to content

Commit 696a644

Browse files
committed
Add exact resource ID for StorageDocsBucket
1 parent 0d0a04c commit 696a644

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

packages/cdk/nagSuppressions.ts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -95,8 +95,8 @@ export const nagSuppressions = (stack: Stack) => {
9595
id: "AwsSolutions-IAM5",
9696
reason: "Bedrock Knowledge Base requires these permissions to access S3 documents and OpenSearch collection.",
9797
appliesTo: [
98-
"Resource::<StorageDocsBucket*Docs*.Arn>/*",
9998
"Action::bedrock:Delete*",
99+
"Resource::<StorageDocsBucketepsampr16Docs240CC945.Arn>/*",
100100
"Resource::arn:aws:bedrock:eu-west-2:undefined:knowledge-base/*",
101101
"Resource::arn:aws:bedrock:eu-west-2:591291862413:knowledge-base/*",
102102
"Resource::arn:aws:aoss:eu-west-2:undefined:collection/*",

0 commit comments

Comments
 (0)