Skip to content

Commit 76df7be

Browse files
committed
Remove appliesTo in Bedrock execution role policy suppressions
1 parent ccbbb4f commit 76df7be

File tree

1 file changed

+1
-9
lines changed

1 file changed

+1
-9
lines changed

packages/cdk/nagSuppressions.ts

Lines changed: 1 addition & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -109,15 +109,7 @@ export const nagSuppressions = (stack: Stack) => {
109109
[
110110
{
111111
id: "AwsSolutions-IAM5",
112-
reason: "Bedrock Knowledge Base requires these permissions to access S3 documents and OpenSearch collection.",
113-
appliesTo: [
114-
"Resource::<StorageDocsBucketepsamDocsF25F63F1.Arn>/*",
115-
"Resource::<StorageDocsBucketepsampr20Docs075F648F.Arn>/*",
116-
"Action::bedrock:Delete*",
117-
`Resource::arn:aws:bedrock:eu-west-2:${account}:knowledge-base/*`,
118-
`Resource::arn:aws:aoss:eu-west-2:${account}:collection/*`,
119-
"Resource::*"
120-
]
112+
reason: "Bedrock Knowledge Base requires these permissions to access S3 documents and OpenSearch collection."
121113
}
122114
]
123115
)

0 commit comments

Comments
 (0)