Large bedrockModels overrides can move already documented Bedrock permissions onto AgentSessionRole/Role/OverflowPolicy1, where the AwsSolutions-IAM5 suppression applied during construction does not follow CDK's later policy split. The result is an error-level cdk-nag finding that blocks CLI synthesis even though the resource count remains within the 490-resource budget.
This is the separate follow-up identified in the review of PR #912, under the broader capacity work in #852. It is separate from the three-AZ budget coverage fix.
Verified structurally on PR #912 at 8720df284c5ed8116870455faa7e65d774d0a3c9, with unchanged dependencies, two-zone auto-pin, global inference profiles, and managed Blueprint provisioning:
| Extra model IDs beyond the four shipped defaults |
Application resources |
Error-level IAM5 annotations |
| 7 |
490 |
2 |
| 8 |
490 |
3 |
The reproduction uses literal synthetic IDs anthropic.claude-census-extra-0 through anthropic.claude-census-extra-6 or -7. These are policy-size fixtures; they do not claim model availability. The threshold depends on serialized IAM size and model-ID lengths, so eleven models is not a general model-count limit.
To reproduce from the PR worktree, run the following in cdk/, changing extraCount to 8 for the second case:
CDK_CONTEXT_JSON='{"aws:cdk:bundling-stacks":[]}' \
mise exec -- node -r ts-node/register/transpile-only <<'NODE'
const fs = require('node:fs');
const os = require('node:os');
const path = require('node:path');
const { buildApp } = require('./src/main');
const { DEFAULT_BEDROCK_MODEL_IDS } = require('./src/handlers/shared/bedrock-model-constants');
const { inspectAssembly } = require('./src/synthesis/assembly');
const { FIXTURE, STRUCTURAL_CONTEXT, synthesisProfiles } = require('./src/synthesis/profiles');
(async () => {
const extraCount = 7;
const profile = synthesisProfiles('managed').find(p =>
p.name === 'lambda-microvm-gw1-reg1-vault1-managed-email-fork');
const outdir = fs.mkdtempSync(path.join(os.tmpdir(), 'abca-model-overflow-'));
const app = await buildApp({
account: FIXTURE.account,
region: FIXTURE.region,
describeAzs: async () => [...FIXTURE.zones],
resolveCallerAccount: async () => FIXTURE.account,
appProps: {
outdir,
autoSynth: false,
postCliContext: STRUCTURAL_CONTEXT,
context: {
...profile.context,
bedrockModels: [...DEFAULT_BEDROCK_MODEL_IDS,
...Array.from({ length: extraCount }, (_, i) => `anthropic.claude-census-extra-${i}`)],
},
},
});
app.synth();
const census = inspectAssembly(outdir);
console.log(census.templates.map(({ file, resources }) => ({ file, resources })));
console.log(census.errors);
})().catch(error => { console.error(error); process.exitCode = 1; });
NODE
The missing annotations are on /backgroundagent-dev/AgentSessionRole/Role/OverflowPolicy1/Resource, for bedrock:InvokeModel* and the cross-region foundation-model ARN resources.
Acceptance criteria:
- Apply evidence-backed suppression to the specific CDK-generated SessionRole overflow policies before cdk-nag checks them, including future
OverflowPolicy<N> children.
- Preserve the emitted IAM permissions: explicit model/inference-profile ARNs, tenant-scoped S3 paths, and DynamoDB leading-key conditions. Do not broaden grants or suppress unrelated roles.
- Add a boundary regression with a policy-size fixture that forces overflow and checks error-level annotations on both network topologies.
- Keep the resource budget enforced, and verify the ordinary model set remains clean.
- Run the focused regression and the normal build.
Large
bedrockModelsoverrides can move already documented Bedrock permissions ontoAgentSessionRole/Role/OverflowPolicy1, where theAwsSolutions-IAM5suppression applied during construction does not follow CDK's later policy split. The result is an error-level cdk-nag finding that blocks CLI synthesis even though the resource count remains within the 490-resource budget.This is the separate follow-up identified in the review of PR #912, under the broader capacity work in #852. It is separate from the three-AZ budget coverage fix.
Verified structurally on PR #912 at
8720df284c5ed8116870455faa7e65d774d0a3c9, with unchanged dependencies, two-zone auto-pin, global inference profiles, and managed Blueprint provisioning:The reproduction uses literal synthetic IDs
anthropic.claude-census-extra-0throughanthropic.claude-census-extra-6or-7. These are policy-size fixtures; they do not claim model availability. The threshold depends on serialized IAM size and model-ID lengths, so eleven models is not a general model-count limit.To reproduce from the PR worktree, run the following in
cdk/, changingextraCountto 8 for the second case:The missing annotations are on
/backgroundagent-dev/AgentSessionRole/Role/OverflowPolicy1/Resource, forbedrock:InvokeModel*and the cross-region foundation-model ARN resources.Acceptance criteria:
OverflowPolicy<N>children.