Repository navigation
fix(bedrock-mantle): honor api_base for VPC endpoint routing on bedro… - #31141
Conversation
…ck/mantle/... The bedrock/mantle chat and messages paths hardcoded the public Mantle host and ignored api_base, so private VPC/VPCE/GovCloud endpoints could not be used. Route URL construction through a shared helper that prefers api_base and aws_bedrock_runtime_endpoint before falling back to the regional public host. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Shivam Rawat seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account. You have signed the CLA already but the status is still pending? Let us recheck it. |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Greptile SummaryThis PR fixes the Bedrock Mantle integration so that
Confidence Score: 5/5The change is safe to merge — it is a targeted, backward-compatible fix with no impact on callers that do not supply an endpoint override. The fix is minimal and well-contained: a single new helper function with clear priority ordering, two one-line call-site changes, and thorough mock tests covering the new code paths. The fallback behaviour (no override provided) is identical to before, so existing deployments are unaffected. No auth logic, no database access, and no breaking changes are involved. No files require special attention.
|
| Filename | Overview |
|---|---|
| litellm/llms/bedrock/common_utils.py | Adds build_mantle_messages_url helper that resolves endpoint from api_base → aws_bedrock_runtime_endpoint → public regional fallback; logic is correct and handles trailing slashes and full-path overrides cleanly. |
| litellm/llms/bedrock/chat/mantle/transformation.py | Replaces hardcoded MANTLE_ENDPOINT_TEMPLATE with a call to the new build_mantle_messages_url helper; straightforward and correct. |
| litellm/llms/bedrock/messages/mantle_transformation.py | Same hardcoded-template replacement as the chat config; both configs now share the same endpoint-resolution logic via the helper. |
| tests/test_litellm/llms/bedrock/test_mantle.py | Adds six new mock-only tests covering host override, full-path override, trailing slash, runtime-endpoint override, and an end-to-end URL assertion; no real network calls. |
Reviews (2): Last reviewed commit: "fix(bedrock-mantle): honor api_base for ..." | Re-trigger Greptile
PR overviewAll previously flagged issues have been addressed. No open security concerns remain on this pull request. Security reviewNo open security issues remain on this pull request. Fixed/addressed: 1 · PR risk: 0/10 |
|
@greptile-apps isn't the P2 issue behavior something not introduced by this PR. So isn't that test out of scope? |
|
You're right. The priority between |
|
@greptile-apps yes. update the score based on your last comment. |

Resolves LIT-3962
Summary
This PR fixes Mantle routing for bedrock/mantle/... so LiteLLM honors custom endpoint overrides (api_base, aws_bedrock_runtime_endpoint) instead of always using the public regional Mantle host.
Root cause
The bedrock/mantle/... integration overrides URL construction in both the chat and messages configs (AmazonMantleConfig and AmazonMantleMessagesConfig). Each override hardcoded:
https://bedrock-mantle.{region}.api.aws/anthropic/v1/messages
and returned it directly from get_complete_url, even though api_base was passed in. Standard Bedrock invoke paths do not have this problem because they call get_runtime_endpoint(...), which correctly prefers api_base and aws_bedrock_runtime_endpoint. Mantle was added with a separate hardcoded template and never wired into that endpoint resolution path, so VPC/VPCE/GovCloud customers could not redirect traffic even when they configured the endpoint correctly.
Fix
Added a shared helper, build_mantle_messages_url(...), in litellm/llms/bedrock/common_utils.py and used it from both Mantle configs. The helper resolves the endpoint in this order: api_base, then aws_bedrock_runtime_endpoint, then the existing public regional fallback. If the override is a host only, LiteLLM appends /anthropic/v1/messages; if the override already includes that path, it is used as-is (no duplication). Behavior without an override is unchanged.
Regression tests were added in tests/test_litellm/llms/bedrock/test_mantle.py for host override, full-path override, trailing slash, runtime-endpoint override, and an end-to-end litellm.anthropic_messages call asserting the request URL is the VPC host.
Before:

After (can see it connect to vpc url):
