Skip to content

fix(bedrock-mantle): honor api_base for VPC endpoint routing on bedro… - #31141

Merged
shivamrawat1 merged 1 commit into
litellm_internal_stagingfrom
litellm_fix_mantle_vpc_endpoint
Jun 24, 2026
Merged

shivamrawat1 merged 1 commit into
litellm_internal_stagingfrom
litellm_fix_mantle_vpc_endpoint

Conversation

@shivamrawat1

@shivamrawat1 shivamrawat1 commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

Resolves LIT-3962

Summary
This PR fixes Mantle routing for bedrock/mantle/... so LiteLLM honors custom endpoint overrides (api_base, aws_bedrock_runtime_endpoint) instead of always using the public regional Mantle host.

Root cause
The bedrock/mantle/... integration overrides URL construction in both the chat and messages configs (AmazonMantleConfig and AmazonMantleMessagesConfig). Each override hardcoded:

https://bedrock-mantle.{region}.api.aws/anthropic/v1/messages

and returned it directly from get_complete_url, even though api_base was passed in. Standard Bedrock invoke paths do not have this problem because they call get_runtime_endpoint(...), which correctly prefers api_base and aws_bedrock_runtime_endpoint. Mantle was added with a separate hardcoded template and never wired into that endpoint resolution path, so VPC/VPCE/GovCloud customers could not redirect traffic even when they configured the endpoint correctly.

Fix
Added a shared helper, build_mantle_messages_url(...), in litellm/llms/bedrock/common_utils.py and used it from both Mantle configs. The helper resolves the endpoint in this order: api_base, then aws_bedrock_runtime_endpoint, then the existing public regional fallback. If the override is a host only, LiteLLM appends /anthropic/v1/messages; if the override already includes that path, it is used as-is (no duplication). Behavior without an override is unchanged.

Regression tests were added in tests/test_litellm/llms/bedrock/test_mantle.py for host override, full-path override, trailing slash, runtime-endpoint override, and an end-to-end litellm.anthropic_messages call asserting the request URL is the VPC host.

model_list:
  # Primary: host-only api_base (VPCE DNS); LiteLLM appends /anthropic/v1/messages
  - model_name: mantle-claude-vpce
    litellm_params:
      model: bedrock/mantle/anthropic.claude-mythos-preview
      api_base: https://vpce-REPLACE_ME.bedrock-mantle.us-gov-west-1.vpce.amazonaws.com
      aws_region_name: us-gov-west-1

Before:
Screenshot 2026-06-23 at 4 46 07 PM

After (can see it connect to vpc url):
Screenshot 2026-06-23 at 4 43 42 PM

…ck/mantle/...

The bedrock/mantle chat and messages paths hardcoded the public Mantle host and ignored api_base, so private VPC/VPCE/GovCloud endpoints could not be used. Route URL construction through a shared helper that prefers api_base and aws_bedrock_runtime_endpoint before falling back to the regional public host.

Co-authored-by: Cursor <cursoragent@cursor.com>
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


Shivam Rawat seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

@codecov

codecov Bot commented Jun 23, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@greptile-apps

greptile-apps Bot commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR fixes the Bedrock Mantle integration so that api_base and aws_bedrock_runtime_endpoint are honoured when constructing the request URL, enabling VPC/VPCE/GovCloud routing. Previously both AmazonMantleConfig and AmazonMantleMessagesConfig hardcoded the public regional URL and ignored any override.

  • Introduces build_mantle_messages_url in common_utils.py as a single, shared endpoint-resolution helper that prefers api_base, then aws_bedrock_runtime_endpoint, then the public regional fallback; handles trailing slashes and full-path overrides without duplication.
  • Both Mantle configs (chat/mantle/transformation.py and messages/mantle_transformation.py) now delegate to this helper instead of using the deleted MANTLE_ENDPOINT_TEMPLATE constant.
  • Six new mock-based tests cover host-only override, full-path override, trailing slash normalisation, aws_bedrock_runtime_endpoint override, and an end-to-end URL assertion through the litellm.anthropic_messages call path.

Confidence Score: 5/5

The change is safe to merge — it is a targeted, backward-compatible fix with no impact on callers that do not supply an endpoint override.

The fix is minimal and well-contained: a single new helper function with clear priority ordering, two one-line call-site changes, and thorough mock tests covering the new code paths. The fallback behaviour (no override provided) is identical to before, so existing deployments are unaffected. No auth logic, no database access, and no breaking changes are involved.

No files require special attention.

Important Files Changed

Filename Overview
litellm/llms/bedrock/common_utils.py Adds build_mantle_messages_url helper that resolves endpoint from api_base → aws_bedrock_runtime_endpoint → public regional fallback; logic is correct and handles trailing slashes and full-path overrides cleanly.
litellm/llms/bedrock/chat/mantle/transformation.py Replaces hardcoded MANTLE_ENDPOINT_TEMPLATE with a call to the new build_mantle_messages_url helper; straightforward and correct.
litellm/llms/bedrock/messages/mantle_transformation.py Same hardcoded-template replacement as the chat config; both configs now share the same endpoint-resolution logic via the helper.
tests/test_litellm/llms/bedrock/test_mantle.py Adds six new mock-only tests covering host override, full-path override, trailing slash, runtime-endpoint override, and an end-to-end URL assertion; no real network calls.

Reviews (2): Last reviewed commit: "fix(bedrock-mantle): honor api_base for ..." | Re-trigger Greptile

Comment thread tests/test_litellm/llms/bedrock/test_mantle.py
Comment thread litellm/llms/bedrock/common_utils.py
@veria-ai

veria-ai Bot commented Jun 23, 2026 •

Copy link
Copy Markdown
Contributor

PR overview

All previously flagged issues have been addressed. No open security concerns remain on this pull request.

Security review

No open security issues remain on this pull request.

Fixed/addressed: 1 · PR risk: 0/10

@mateo-berri mateo-berri left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Image

is this a legit concern?

@shivamrawat1

Copy link
Copy Markdown
Contributor Author

@greptile-apps isn't the P2 issue behavior something not introduced by this PR. So isn't that test out of scope?

@greptile-apps

greptile-apps Bot commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

You're right. The priority between api_base and aws_bedrock_runtime_endpoint isn't new behavior introduced by this PR — it's a trivial or in the new helper, and each branch is already covered independently by the existing tests. The combined precedence test is out of scope. Happy to drop this.

@shivamrawat1

Copy link
Copy Markdown
Contributor Author

@greptile-apps yes. update the score based on your last comment.

@mateo-berri mateo-berri left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM; thanks!

@shivamrawat1
shivamrawat1 merged commit 8dfe702 into litellm_internal_staging Jun 24, 2026
126 checks passed
@shivamrawat1
shivamrawat1 deleted the litellm_fix_mantle_vpc_endpoint branch June 24, 2026 00:32
@ishaan-berri ishaan-berri mentioned this pull request Jun 25, 2026
9 of 13 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants