Skip to content

Commit 96ae0e2

Browse files
committed
Add KMS wildcard permission suppressions for SlackBotManagedPolicy
1 parent 2de87f2 commit 96ae0e2

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

packages/cdk/nagSuppressions.ts

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -134,7 +134,9 @@ export const nagSuppressions = (stack: Stack) => {
134134
appliesTo: [
135135
`Resource::arn:aws:lambda:eu-west-2:${account}:function:*`,
136136
`Resource::arn:aws:bedrock:eu-west-2:${account}:guardrail/*`,
137-
`Resource::arn:aws:bedrock:eu-west-2:${account}:knowledge-base/*`
137+
`Resource::arn:aws:bedrock:eu-west-2:${account}:knowledge-base/*`,
138+
"Action::kms:GenerateDataKey*",
139+
"Action::kms:ReEncrypt*"
138140
]
139141
}
140142
]

0 commit comments

Comments
 (0)