Skip to content

Commit 6721d12

Browse files
authored
Add required permission to retrieve OAuth2 Credential Provider client secret (#228)
1 parent 29bab2e commit 6721d12

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

src/bedrock_agentcore_starter_toolkit/utils/runtime/templates/execution_role_policy.json.j2

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -120,6 +120,16 @@
120120
"arn:aws:bedrock-agentcore:{{ region }}:{{ account_id }}:workload-identity-directory/default/workload-identity/{{ agent_name }}-*"
121121
]
122122
},
123+
{
124+
"Sid": "BedrockAgentCoreIdentityGetCredentialProviderClientSecret",
125+
"Effect": "Allow",
126+
"Action": [
127+
"secretsmanager:GetSecretValue"
128+
],
129+
"Resource": [
130+
"arn:aws:secretsmanager:{{ region }}:{{ account_id }}:secret:bedrock-agentcore-identity!default/oauth2/*"
131+
]
132+
},
123133
{
124134
"Sid": "BedrockAgentCoreIdentityGetResourceOauth2Token",
125135
"Effect": "Allow",

0 commit comments

Comments
 (0)