Skip to content

Commit d0a4424

Browse files
committed
Add bucket
1 parent 02da0e1 commit d0a4424

File tree

1 file changed

+14
-2
lines changed

1 file changed

+14
-2
lines changed

org-formation/300-account-defaults/bedrock-agent-role.yaml

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,15 @@ AWSTemplateFormatVersion: '2010-09-09'
22
Description: Enables executing a Bedrock model
33

44
Resources:
5+
bedrockAgentResourcesBucket:
6+
Type: AWS::S3::Bucket
7+
Properties:
8+
BucketName: bedrock-agent-resources
9+
PublicAccessBlockConfiguration:
10+
BlockPublicAcls: true
11+
BlockPublicPolicy: true
12+
IgnorePublicAcls: true
13+
RestrictPublicBuckets: true
514
# https://docs.aws.amazon.com/bedrock/latest/userguide/agents-permissions.html
615
bedrockAgentRole:
716
Type: AWS::IAM::Role
@@ -37,8 +46,11 @@ Resources:
3746
- "s3:GetObjectVersion"
3847
- "s3:ListBucket"
3948
Resource:
40-
- !Sub "arn:aws:s3:::*"
41-
- !Sub "arn:aws:s3:::*/*"
49+
# delete first two lines after migrating
50+
- !Sub "arn:aws:s3:::lolrus-bukkit"
51+
- !Sub "arn:aws:s3:::lolrus-bukkit/*"
52+
- !Sub "arn:aws:s3:::bedrock-agent-resources"
53+
- !Sub "arn:aws:s3:::bedrock-agent-resources/*"
4254

4355
Outputs:
4456
BedrockAgentRoleArn:

0 commit comments

Comments
 (0)