Skip to content

feat: add AWS Bedrock LLM provider via native Converse API - #345

Closed
cgorski wants to merge 6 commits into
nearai:mainfrom
cgorski:cgorski-bedrock
Closed

cgorski wants to merge 6 commits into
nearai:mainfrom
cgorski:cgorski-bedrock

Conversation

@cgorski

@cgorski cgorski commented Feb 24, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions github-actions Bot added scope: llm LLM integration scope: config Configuration scope: setup Onboarding / setup scope: docs Documentation scope: dependencies Dependency updates size: XL 500+ changed lines risk: high Safety, secrets, auth, or critical infrastructure contributor: new First-time contributor labels Feb 24, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello @cgorski, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request introduces a significant new feature by integrating AWS Bedrock as a first-class LLM provider. This allows users to leverage Bedrock's capabilities, including its native Converse API and diverse model offerings, within the application. The implementation focuses on providing a robust and flexible authentication experience, accommodating various AWS credential management strategies, and ensuring a smooth setup process through updated configuration and wizard flows.

Highlights

  • New LLM Provider: AWS Bedrock: Added support for AWS Bedrock as a new Large Language Model (LLM) provider, leveraging its native Converse API for interactions.
  • Flexible Authentication for Bedrock: Implemented support for various AWS Bedrock authentication methods, including bearer tokens, IAM credentials, SSO profiles, and EC2/ECS instance roles, all handled transparently by the AWS SDK credential chain.
  • Native Converse API Integration: Integrated directly with the AWS Bedrock Converse API, allowing for advanced features like system messages, tool use, and robust error handling specific to Bedrock.
  • Enhanced Configuration and Setup: Updated documentation, configuration structures, and the interactive setup wizard to seamlessly guide users through setting up AWS Bedrock, including region selection, cross-region inference, and model ID specification.
Changelog
  • CHANGELOG.md
    • Added an entry for the new AWS Bedrock LLM provider with native Converse API support.
  • CLAUDE.md
    • Updated documentation to include configuration examples for AWS Bedrock, detailing environment variables for region, model ID, cross-region settings, and authentication methods.
  • Cargo.lock
    • Updated dependency lock file to include numerous new AWS SDK crates and their transitive dependencies required for AWS Bedrock integration.
  • Cargo.toml
    • Added new dependencies for AWS Bedrock integration, specifically aws-config, aws-sdk-bedrockruntime, and aws-smithy-types.
  • FEATURE_PARITY.md
    • Updated the feature parity table to reflect full support (✅) for AWS Bedrock as an LLM provider and for tool usage.
  • docs/LLM_PROVIDERS.md
    • Added AWS Bedrock to the list of supported LLM providers, including its backend identifier and authentication methods.
    • Included a new detailed section for AWS Bedrock, explaining how to configure it with API keys, AWS credentials, and cross-region inference, along with popular model IDs.
  • src/config/llm.rs
    • Added a Bedrock variant to the LlmBackend enum to represent the new provider.
    • Introduced BedrockConfig struct to hold specific configuration parameters for AWS Bedrock, such as region, model, cross-region settings, and AWS profile.
    • Modified the LlmConfig::from_env_and_settings method to parse and populate BedrockConfig when LLM_BACKEND is set to bedrock.
  • src/config/mod.rs
    • Exported the new BedrockConfig struct.
    • Added bedrock_api_key to the list of secrets that can be injected from the secrets store.
  • src/llm/bedrock.rs
    • Added a new module implementing BedrockProvider for AWS Bedrock's native Converse API.
    • Implemented message conversion logic to adapt internal chat message formats to Bedrock's Converse API requirements, including system blocks and tool results.
    • Provided utility functions for converting between serde_json::Value and aws_smithy_types::Document.
    • Included comprehensive unit tests for message conversion, tool configuration, and error mapping.
  • src/llm/mod.rs
    • Imported the new bedrock module.
    • Added create_bedrock_provider function to instantiate the BedrockProvider based on configuration.
  • src/settings.rs
    • Added bedrock_region and bedrock_cross_region fields to the Settings struct to store AWS Bedrock specific configurations.
  • src/setup/README.md
    • Updated the setup README to include AWS Bedrock as a configurable LLM provider, specifying its API key and environment variable.
  • src/setup/wizard.rs
    • Updated the setup wizard to include AWS Bedrock as a selectable LLM provider option.
    • Implemented setup_bedrock and setup_bedrock_cross_region functions to guide users through configuring Bedrock region, authentication methods (API key, default credentials, named profiles), and cross-region inference settings.
    • Modified model selection logic to prompt for a Bedrock model ID when Bedrock is the chosen backend.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces support for AWS Bedrock as an LLM provider, including updates to configuration, documentation, and the setup wizard. The core implementation in src/llm/bedrock.rs is well-structured and includes comprehensive tests. I've provided a few suggestions to improve robustness and maintainability, including consolidating duplicated logic as per repository guidelines. Notably, there's a syntax issue in the setup wizard that might cause build failures on stable Rust. Overall, this is a great addition.

Comment thread src/setup/wizard.rs
Comment thread src/llm/bedrock.rs Outdated
Comment thread src/llm/bedrock.rs Outdated

@serrrfirat serrrfirat left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

Substantial PR adding AWS Bedrock support via native Converse API. The core implementation — message conversion (with strict user/assistant alternation), tool call handling, Document<->JSON conversion, response extraction, and error mapping — is solid and has good unit test coverage (20+ tests). However, the bearer token (API key) auth path is completely non-functional: AWS_BEARER_TOKEN_BEDROCK is collected and stored but never wired to the AWS SDK client, which does not recognize this env var in the Rust SDK (unlike Python/JS SDKs). This is the auth method advertised as 'simplest' in the wizard. IAM and SSO auth paths work correctly. Additionally, the wizard doesn't persist AWS_PROFILE for named profile auth (inconsistent with other settings), and there's an unsafe u32→i32 cast for max_tokens. Recommend blocking on f-1 (bearer token) and f-2 (profile persistence) before merge.

General findings

[NIT] Settings doc comment doesn't mention bedrock as a valid backend (src/settings.rs:51)

The doc comment on llm_backend field says: 'LLM backend: "nearai", "anthropic", "openai", "ollama", "openai_compatible"' — missing 'bedrock' and 'tinfoil'.

Suggested fix:

Update the comment to: 'LLM backend: "nearai", "anthropic", "openai", "ollama", "openai_compatible", "tinfoil", "bedrock"'.

Comment thread src/llm/bedrock.rs
Comment thread src/setup/wizard.rs
Comment thread src/llm/bedrock.rs Outdated
Comment thread src/llm/bedrock.rs
Comment thread src/llm/bedrock.rs Outdated
Comment thread src/llm/bedrock.rs
Comment thread src/config/llm.rs

@zmanian zmanian left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review: AWS Bedrock LLM Provider

The core bedrock.rs implementation is well-structured and handles the Bedrock Converse API correctly. However, there are two blockers preventing merge.

Blocker

  1. Bearer token auth is non-functional — The AWS_BEARER_TOKEN_BEDROCK environment variable is read and a Token credential is constructed, but the AWS Rust SDK's Bedrock client doesn't recognize this credential type for the Converse API. Bearer token auth only works with specific AWS services (like CodeCatalyst), not Bedrock. This auth path will silently fail at runtime. Either remove it and document the supported auth methods (env creds, profile, IMDS), or verify it actually works with a test.

  2. 36 new crate dependencies with no feature gate — This PR adds 36 new transitive dependencies including aws-lc-sys which requires cmake and a C compiler to build. This significantly increases build times and system requirements for all users, even those not using Bedrock. This must be behind a bedrock feature flag (like the existing libsql feature pattern) so it's opt-in.

High Priority

  1. Unsafe u32 as i32 cast — Token usage values are cast with as i32 which silently truncates on overflow. Use i32::try_from(val).unwrap_or(i32::MAX) or similar safe conversion.

  2. Fragile error detection — Error handling uses contains("Error:") string matching which is brittle. Match on the actual error variants from the SDK types instead.

Medium Priority

  1. Setup wizard integration — The wizard step for Bedrock should only appear when the bedrock feature is enabled, consistent with how other optional backends work.

  2. Missing region validation — AWS_REGION defaults to us-east-1 silently. Consider at least logging when the default is used, since Bedrock model availability varies significantly by region.

What's Good

  • Clean separation of Bedrock-specific types
  • Proper streaming support via Converse Stream API
  • Tool use / function calling implementation looks correct
  • Good error type mapping

Recommendation

Add a bedrock feature flag to gate the AWS dependencies, remove or fix the bearer token auth path, and this will be close to mergeable. The core implementation quality is solid.

cgorski added 6 commits March 2, 2026 06:47
- Safe u32→i32 cast for max_tokens using try_from with clamp
- Remove brittle string-based error detection fallback for tool results
- Validate BEDROCK_CROSS_REGION against allowed values (us/eu/apac/global)
- Validate message list is non-empty before Converse API call
- Log when using default us-east-1 region
- Update llm_backend doc comment to list all backends
- Add tests for build_inference_config and empty message handling
The wizard collected the profile name but only printed a hint to set
it manually. Now it saves to settings and writes AWS_PROFILE to the
bootstrap .env, consistent with how BEDROCK_REGION and other Bedrock
settings are persisted.
The AWS SDK dependencies (aws-config, aws-sdk-bedrockruntime,
aws-smithy-types) require cmake and a C compiler to build aws-lc-sys.
Gate them behind an opt-in `bedrock` feature flag so default builds
are unaffected.

Build with: cargo build --features bedrock
All config, settings, and wizard code stays unconditional (no AWS deps)
so users can configure Bedrock even without the feature compiled — they
get a clear error at startup directing them to rebuild.
@cgorski

cgorski commented Mar 2, 2026 •

Copy link
Copy Markdown
Contributor Author

All PR comments addressed, ready for merge consideration

@cgorski
cgorski requested review from serrrfirat and zmanian March 2, 2026 17:12
ilblackdragon added a commit that referenced this pull request Mar 8, 2026
…rchitecture (takeover #345)

- Resolve merge conflicts with main's registry-based provider system
- Add missing cache_creation_input_tokens/cache_read_input_tokens fields
- Add missing content_parts field in test ChatMessage
- Fix string literal type mismatches in wizard env_vars (.to_string())
- Remove non-functional bearer token auth (AWS_BEARER_TOKEN_BEDROCK) from
  wizard and documentation per reviewer feedback from @zmanian and @serrrfirat
- Remove stale BEDROCK_ACCESS_KEY proxy entry from provider table
- Update Bedrock provider to use is_bedrock string check (LlmBackend enum removed)
- Add bedrock_profile fallback from settings in config resolution

[skip-regression-check]

Co-Authored-By: cgorski <cgorski@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@ilblackdragon

Copy link
Copy Markdown
Member

Thanks for the work on this, @cgorski! I've picked up your changes and continued them in #713.

The new PR includes your original work plus:

  • Merge with latest main (resolved 7 conflicts from the registry-based provider refactor)
  • Adapted to new RegistryProviderConfig / string-based backend system
  • Added missing struct fields from recent main changes (cache tokens, content_parts)
  • Removed non-functional bearer token auth per reviewer feedback from @zmanian and @serrrfirat
  • Fixed type mismatches in wizard

You're credited as co-author on all commits. Feel free to review the new PR!

@ilblackdragon

Copy link
Copy Markdown
Member

Thanks for contribution! Taking over in #713 to update to the new format and resolve left over comments.

ilblackdragon added a commit that referenced this pull request Mar 9, 2026
* feat: add AWS Bedrock LLM provider via native Converse API

* fix: use JSON parsing for tool result error detection instead of brittle substring matching

* refactor: extract duplicated inference config builder into helper function

* fix: address review feedback — safe casts, input validation, and tests

- Safe u32→i32 cast for max_tokens using try_from with clamp
- Remove brittle string-based error detection fallback for tool results
- Validate BEDROCK_CROSS_REGION against allowed values (us/eu/apac/global)
- Validate message list is non-empty before Converse API call
- Log when using default us-east-1 region
- Update llm_backend doc comment to list all backends
- Add tests for build_inference_config and empty message handling

* fix: persist AWS_PROFILE for Bedrock named profile auth

The wizard collected the profile name but only printed a hint to set
it manually. Now it saves to settings and writes AWS_PROFILE to the
bootstrap .env, consistent with how BEDROCK_REGION and other Bedrock
settings are persisted.

* feat: gate AWS Bedrock behind optional `bedrock` feature flag

The AWS SDK dependencies (aws-config, aws-sdk-bedrockruntime,
aws-smithy-types) require cmake and a C compiler to build aws-lc-sys.
Gate them behind an opt-in `bedrock` feature flag so default builds
are unaffected.

Build with: cargo build --features bedrock
All config, settings, and wizard code stays unconditional (no AWS deps)
so users can configure Bedrock even without the feature compiled — they
get a clear error at startup directing them to rebuild.

* fix: address review feedback and adapt Bedrock provider to registry architecture (takeover #345)

- Resolve merge conflicts with main's registry-based provider system
- Add missing cache_creation_input_tokens/cache_read_input_tokens fields
- Add missing content_parts field in test ChatMessage
- Fix string literal type mismatches in wizard env_vars (.to_string())
- Remove non-functional bearer token auth (AWS_BEARER_TOKEN_BEDROCK) from
  wizard and documentation per reviewer feedback from @zmanian and @serrrfirat
- Remove stale BEDROCK_ACCESS_KEY proxy entry from provider table
- Update Bedrock provider to use is_bedrock string check (LlmBackend enum removed)
- Add bedrock_profile fallback from settings in config resolution

[skip-regression-check]

Co-Authored-By: cgorski <cgorski@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: use main's Cargo.lock as base to preserve dependency versions

Regenerating Cargo.lock from scratch caused transitive dependency version
drift that broke the html_to_markdown fixture test in CI.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: bedrock config bugs — spurious warning, alias normalization, profile fallback

- Move is_bedrock check before unknown-backend warning to prevent
  spurious "unknown backend" log for bedrock users
- Normalize backend aliases ("aws", "aws_bedrock") to "bedrock" so
  the provider factory matches correctly
- Add settings.bedrock_profile fallback for AWS_PROFILE, consistent
  with region and cross_region resolution

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address Copilot review feedback — bearer token cleanup, stop_sequences, model dedup

- Remove stale bearer token refs from setup README and CHANGELOG
- Remove dead bedrock_api_key secret injection mapping
- Pass stop_sequences through to Bedrock InferenceConfiguration
- Remove "API key" from wizard menu description (bearer token removed)
- Skip duplicate LLM_MODEL write for bedrock backend in wizard
- Fix cargo fmt formatting

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address review feedback — async new(), remove LiteLLM entry, wizard fixes

- Remove dead LiteLLM-based bedrock entry from providers.json (native
  Converse API intercepts before registry lookup)
- Make BedrockProvider::new() async to avoid block_in_place panic in
  current_thread runtimes; propagate async to create_llm_provider,
  build_provider_chain, and init_llm
- Document CMake build prerequisite in docs/LLM_PROVIDERS.md
- Clear bedrock_profile when user selects "default credentials" in wizard
- Fix selected_model clearing to match established pattern (conditional
  on provider switch, not unconditional)
- Add regression tests for bedrock model preservation and profile clearing

Addresses review feedback from @zmanian on PR #713.
Streaming support tracked in #741.

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address remaining review comments — CLAUDE.md backends, wizard UX

- Add `bedrock` to CLAUDE.md inline backend list (#10)
- Skip full setup re-run when keeping existing Bedrock config (#11)
- Clear stale bedrock_profile on empty named-profile input (#12)
- Add regression test for empty profile clearing

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Chris Gorski <cgorski@cgorski.org>
Co-authored-by: cgorski <cgorski@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
bkutasi pushed a commit to bkutasi/ironclaw that referenced this pull request Mar 28, 2026
* feat: add AWS Bedrock LLM provider via native Converse API

* fix: use JSON parsing for tool result error detection instead of brittle substring matching

* refactor: extract duplicated inference config builder into helper function

* fix: address review feedback — safe casts, input validation, and tests

- Safe u32→i32 cast for max_tokens using try_from with clamp
- Remove brittle string-based error detection fallback for tool results
- Validate BEDROCK_CROSS_REGION against allowed values (us/eu/apac/global)
- Validate message list is non-empty before Converse API call
- Log when using default us-east-1 region
- Update llm_backend doc comment to list all backends
- Add tests for build_inference_config and empty message handling

* fix: persist AWS_PROFILE for Bedrock named profile auth

The wizard collected the profile name but only printed a hint to set
it manually. Now it saves to settings and writes AWS_PROFILE to the
bootstrap .env, consistent with how BEDROCK_REGION and other Bedrock
settings are persisted.

* feat: gate AWS Bedrock behind optional `bedrock` feature flag

The AWS SDK dependencies (aws-config, aws-sdk-bedrockruntime,
aws-smithy-types) require cmake and a C compiler to build aws-lc-sys.
Gate them behind an opt-in `bedrock` feature flag so default builds
are unaffected.

Build with: cargo build --features bedrock
All config, settings, and wizard code stays unconditional (no AWS deps)
so users can configure Bedrock even without the feature compiled — they
get a clear error at startup directing them to rebuild.

* fix: address review feedback and adapt Bedrock provider to registry architecture (takeover nearai#345)

- Resolve merge conflicts with main's registry-based provider system
- Add missing cache_creation_input_tokens/cache_read_input_tokens fields
- Add missing content_parts field in test ChatMessage
- Fix string literal type mismatches in wizard env_vars (.to_string())
- Remove non-functional bearer token auth (AWS_BEARER_TOKEN_BEDROCK) from
  wizard and documentation per reviewer feedback from @zmanian and @serrrfirat
- Remove stale BEDROCK_ACCESS_KEY proxy entry from provider table
- Update Bedrock provider to use is_bedrock string check (LlmBackend enum removed)
- Add bedrock_profile fallback from settings in config resolution

[skip-regression-check]

Co-Authored-By: cgorski <cgorski@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: use main's Cargo.lock as base to preserve dependency versions

Regenerating Cargo.lock from scratch caused transitive dependency version
drift that broke the html_to_markdown fixture test in CI.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: bedrock config bugs — spurious warning, alias normalization, profile fallback

- Move is_bedrock check before unknown-backend warning to prevent
  spurious "unknown backend" log for bedrock users
- Normalize backend aliases ("aws", "aws_bedrock") to "bedrock" so
  the provider factory matches correctly
- Add settings.bedrock_profile fallback for AWS_PROFILE, consistent
  with region and cross_region resolution

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address Copilot review feedback — bearer token cleanup, stop_sequences, model dedup

- Remove stale bearer token refs from setup README and CHANGELOG
- Remove dead bedrock_api_key secret injection mapping
- Pass stop_sequences through to Bedrock InferenceConfiguration
- Remove "API key" from wizard menu description (bearer token removed)
- Skip duplicate LLM_MODEL write for bedrock backend in wizard
- Fix cargo fmt formatting

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address review feedback — async new(), remove LiteLLM entry, wizard fixes

- Remove dead LiteLLM-based bedrock entry from providers.json (native
  Converse API intercepts before registry lookup)
- Make BedrockProvider::new() async to avoid block_in_place panic in
  current_thread runtimes; propagate async to create_llm_provider,
  build_provider_chain, and init_llm
- Document CMake build prerequisite in docs/LLM_PROVIDERS.md
- Clear bedrock_profile when user selects "default credentials" in wizard
- Fix selected_model clearing to match established pattern (conditional
  on provider switch, not unconditional)
- Add regression tests for bedrock model preservation and profile clearing

Addresses review feedback from @zmanian on PR nearai#713.
Streaming support tracked in nearai#741.

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address remaining review comments — CLAUDE.md backends, wizard UX

- Add `bedrock` to CLAUDE.md inline backend list (nearai#10)
- Skip full setup re-run when keeping existing Bedrock config (nearai#11)
- Clear stale bedrock_profile on empty named-profile input (nearai#12)
- Add regression test for empty profile clearing

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Chris Gorski <cgorski@cgorski.org>
Co-authored-by: cgorski <cgorski@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
* feat: add AWS Bedrock LLM provider via native Converse API

* fix: use JSON parsing for tool result error detection instead of brittle substring matching

* refactor: extract duplicated inference config builder into helper function

* fix: address review feedback — safe casts, input validation, and tests

- Safe u32→i32 cast for max_tokens using try_from with clamp
- Remove brittle string-based error detection fallback for tool results
- Validate BEDROCK_CROSS_REGION against allowed values (us/eu/apac/global)
- Validate message list is non-empty before Converse API call
- Log when using default us-east-1 region
- Update llm_backend doc comment to list all backends
- Add tests for build_inference_config and empty message handling

* fix: persist AWS_PROFILE for Bedrock named profile auth

The wizard collected the profile name but only printed a hint to set
it manually. Now it saves to settings and writes AWS_PROFILE to the
bootstrap .env, consistent with how BEDROCK_REGION and other Bedrock
settings are persisted.

* feat: gate AWS Bedrock behind optional `bedrock` feature flag

The AWS SDK dependencies (aws-config, aws-sdk-bedrockruntime,
aws-smithy-types) require cmake and a C compiler to build aws-lc-sys.
Gate them behind an opt-in `bedrock` feature flag so default builds
are unaffected.

Build with: cargo build --features bedrock
All config, settings, and wizard code stays unconditional (no AWS deps)
so users can configure Bedrock even without the feature compiled — they
get a clear error at startup directing them to rebuild.

* fix: address review feedback and adapt Bedrock provider to registry architecture (takeover nearai#345)

- Resolve merge conflicts with main's registry-based provider system
- Add missing cache_creation_input_tokens/cache_read_input_tokens fields
- Add missing content_parts field in test ChatMessage
- Fix string literal type mismatches in wizard env_vars (.to_string())
- Remove non-functional bearer token auth (AWS_BEARER_TOKEN_BEDROCK) from
  wizard and documentation per reviewer feedback from @zmanian and @serrrfirat
- Remove stale BEDROCK_ACCESS_KEY proxy entry from provider table
- Update Bedrock provider to use is_bedrock string check (LlmBackend enum removed)
- Add bedrock_profile fallback from settings in config resolution

[skip-regression-check]

Co-Authored-By: cgorski <cgorski@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: use main's Cargo.lock as base to preserve dependency versions

Regenerating Cargo.lock from scratch caused transitive dependency version
drift that broke the html_to_markdown fixture test in CI.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: bedrock config bugs — spurious warning, alias normalization, profile fallback

- Move is_bedrock check before unknown-backend warning to prevent
  spurious "unknown backend" log for bedrock users
- Normalize backend aliases ("aws", "aws_bedrock") to "bedrock" so
  the provider factory matches correctly
- Add settings.bedrock_profile fallback for AWS_PROFILE, consistent
  with region and cross_region resolution

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address Copilot review feedback — bearer token cleanup, stop_sequences, model dedup

- Remove stale bearer token refs from setup README and CHANGELOG
- Remove dead bedrock_api_key secret injection mapping
- Pass stop_sequences through to Bedrock InferenceConfiguration
- Remove "API key" from wizard menu description (bearer token removed)
- Skip duplicate LLM_MODEL write for bedrock backend in wizard
- Fix cargo fmt formatting

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address review feedback — async new(), remove LiteLLM entry, wizard fixes

- Remove dead LiteLLM-based bedrock entry from providers.json (native
  Converse API intercepts before registry lookup)
- Make BedrockProvider::new() async to avoid block_in_place panic in
  current_thread runtimes; propagate async to create_llm_provider,
  build_provider_chain, and init_llm
- Document CMake build prerequisite in docs/LLM_PROVIDERS.md
- Clear bedrock_profile when user selects "default credentials" in wizard
- Fix selected_model clearing to match established pattern (conditional
  on provider switch, not unconditional)
- Add regression tests for bedrock model preservation and profile clearing

Addresses review feedback from @zmanian on PR nearai#713.
Streaming support tracked in nearai#741.

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: address remaining review comments — CLAUDE.md backends, wizard UX

- Add `bedrock` to CLAUDE.md inline backend list (nearai#10)
- Skip full setup re-run when keeping existing Bedrock config (nearai#11)
- Clear stale bedrock_profile on empty named-profile input (nearai#12)
- Add regression test for empty profile clearing

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Chris Gorski <cgorski@cgorski.org>
Co-authored-by: cgorski <cgorski@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: new First-time contributor risk: high Safety, secrets, auth, or critical infrastructure scope: config Configuration scope: dependencies Dependency updates scope: docs Documentation scope: llm LLM integration scope: setup Onboarding / setup size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants