aws-samples / aws-samples/sample-for-amazon-bda-agents

Document required permissions to run the notebook

Open
#1 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
8
Forks
1
PR merge metrics
No merged PRs in 30d

Description

It would be helpful to document the permissions needed for this solution and/or provide a policy file that can be attached to the role of the user who is running the notebook. For example, I ran the `bedrock-data-automation-with-agents.ipynb` in SageMaker Unified Studio under the generated AmazonSageMakerUserIAMExecutionRole, which has limited permissions. When I ran the cell that called the `BedrockKnowledgeBase` constructor, I had to work through a series of AccessDenied errors. Here's a list of permissions I needed for that cell and for uploading files to S3:

* aoss:APIAccessAll
* aoss:BatchGetCollection
* aoss:CreateAccessPolicy
* aoss:CreateCollection
* aoss:CreateIndex
* iam:CreateRole
* aoss:CreateSecurityPolicy
* aoss:GetAccessPolicy
* aoss:GetSecurityPolicy
* iam:CreatePolicy
* iam:GetPolicy
* s3:CreateBucket
* s3:PutObject
* iam:AttachRolePolicy
* iam:PassRole

These are all in addition to the default permissions in the role, a few of which might also be needed for the notebook (iam:GetRole, iam:ListRoles, sts:AssumeRole, for example).

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.