-
Notifications
You must be signed in to change notification settings - Fork 4.4k
feat(bedrock-agentcore-alpha): update resources on grantInvokeXXX for runtime #35864
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
(This review is outdated)
| // Create a single runtime (similar to the working strands example) | ||
| const runtime = new agentcore.Runtime(stack, 'TestRuntime', { | ||
| runtimeName: 'integ_test_runtime', | ||
| runtimeName: 'integTest_runtime', |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This change is not needed.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ack.
|
This PR has been in the CHANGES REQUESTED state for 3 weeks, and looks abandoned. Note that PRs with failing linting check or builds are not reviewed, please ensure your build is passing To prevent automatic closure:
This PR will automatically close in 14 days if no action is taken. |
✅ Updated pull request passes all PRLinter validations. Dismissing previous PRLinter review.
Pull request has been modified.
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
|
Comments on closed issues and PRs are hard for our team to see. |
Issue # (if applicable)
Reason for this change
The
grantInvoke,grantInvokeRuntime, andgrantInvokeRuntimeForUsermethods in the BedrockAgentRuntime were only granting permissions to the runtime ARN itself, but not to its sub-resources. This caused permission issues when trying to invoke runtime endpoints from an AWS resource like lambda, as the actual invocation happens on sub-resources (e.g., arn:aws:bedrock-agentcore:region:account:runtime/runtime-id/*).Description of changes
Updated the
resourceArnsparameter in three grant methods withinruntime-base.ts:Describe any new or updated permissions being added
The IAM permissions granted by these methods now include:
bedrock-agentcore:InvokeAgentRuntimeon both the runtime ARN and its sub-resourcesbedrock-agentcore:InvokeAgentRuntimeForUseron both the runtime ARN and its sub-resourcesDescription of how you validated changes
Manual and Integration test
Checklist
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license