Skip to content

Conversation

@xschildw
Copy link
Contributor

This PR adds permissions for a bedrock agent to access S3

@xschildw xschildw requested a review from a team as a code owner January 10, 2025 01:30
Comment on lines 34 to 36
- Effect: Allow
Action: "s3:*"
Resource: "*"
Copy link
Contributor

@zaro0508 zaro0508 Jan 10, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

why not use just apply the AmazonS3FullAccess managed policy?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good idea! Updated.

@xschildw xschildw requested a review from zaro0508 January 22, 2025 17:01
ArnLike:
aws:SourceArn: !Sub "arn:aws:bedrock:${AWS::Region}:${AWS::AccountId}:agent/*"
ManagedPolicyArns:
- arn:aws:iam::aws:policy/AmazonS3FullAccess
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you can also replace your bedrockAgentPolicy with the AWS managed AWSLambdaRole policy..
image

@zaro0508 zaro0508 requested a review from a team April 29, 2025 21:59
@zaro0508 zaro0508 removed the request for review from a team September 8, 2025 16:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants