Skip to content

fix(cdk): carry AgentSessionRole IAM5 suppressions onto model-policy overflow #916

Description

@krokoko

Large bedrockModels overrides can move already documented Bedrock permissions onto AgentSessionRole/Role/OverflowPolicy1, where the AwsSolutions-IAM5 suppression applied during construction does not follow CDK's later policy split. The result is an error-level cdk-nag finding that blocks CLI synthesis even though the resource count remains within the 490-resource budget.

This is the separate follow-up identified in the review of PR #912, under the broader capacity work in #852. It is separate from the three-AZ budget coverage fix.

Verified structurally on PR #912 at 8720df284c5ed8116870455faa7e65d774d0a3c9, with unchanged dependencies, two-zone auto-pin, global inference profiles, and managed Blueprint provisioning:

Extra model IDs beyond the four shipped defaults Application resources Error-level IAM5 annotations
7 490 2
8 490 3

The reproduction uses literal synthetic IDs anthropic.claude-census-extra-0 through anthropic.claude-census-extra-6 or -7. These are policy-size fixtures; they do not claim model availability. The threshold depends on serialized IAM size and model-ID lengths, so eleven models is not a general model-count limit.

To reproduce from the PR worktree, run the following in cdk/, changing extraCount to 8 for the second case:

CDK_CONTEXT_JSON='{"aws:cdk:bundling-stacks":[]}' \
  mise exec -- node -r ts-node/register/transpile-only <<'NODE'
const fs = require('node:fs');
const os = require('node:os');
const path = require('node:path');
const { buildApp } = require('./src/main');
const { DEFAULT_BEDROCK_MODEL_IDS } = require('./src/handlers/shared/bedrock-model-constants');
const { inspectAssembly } = require('./src/synthesis/assembly');
const { FIXTURE, STRUCTURAL_CONTEXT, synthesisProfiles } = require('./src/synthesis/profiles');

(async () => {
  const extraCount = 7;
  const profile = synthesisProfiles('managed').find(p =>
    p.name === 'lambda-microvm-gw1-reg1-vault1-managed-email-fork');
  const outdir = fs.mkdtempSync(path.join(os.tmpdir(), 'abca-model-overflow-'));
  const app = await buildApp({
    account: FIXTURE.account,
    region: FIXTURE.region,
    describeAzs: async () => [...FIXTURE.zones],
    resolveCallerAccount: async () => FIXTURE.account,
    appProps: {
      outdir,
      autoSynth: false,
      postCliContext: STRUCTURAL_CONTEXT,
      context: {
        ...profile.context,
        bedrockModels: [...DEFAULT_BEDROCK_MODEL_IDS,
          ...Array.from({ length: extraCount }, (_, i) => `anthropic.claude-census-extra-${i}`)],
      },
    },
  });
  app.synth();
  const census = inspectAssembly(outdir);
  console.log(census.templates.map(({ file, resources }) => ({ file, resources })));
  console.log(census.errors);
})().catch(error => { console.error(error); process.exitCode = 1; });
NODE

The missing annotations are on /backgroundagent-dev/AgentSessionRole/Role/OverflowPolicy1/Resource, for bedrock:InvokeModel* and the cross-region foundation-model ARN resources.

Acceptance criteria:

  • Apply evidence-backed suppression to the specific CDK-generated SessionRole overflow policies before cdk-nag checks them, including future OverflowPolicy<N> children.
  • Preserve the emitted IAM permissions: explicit model/inference-profile ARNs, tenant-scoped S3 paths, and DynamoDB leading-key conditions. Do not broaden grants or suppress unrelated roles.
  • Add a boundary regression with a policy-size fixture that forces overflow and checks error-level annotations on both network topologies.
  • Keep the resource budget enforced, and verify the ordinary model set remains clean.
  • Run the focused regression and the normal build.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinginfra-cdkCDK stacks/constructs, bootstrap, deploy topology, tags, IAM wiring, teardown

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions