Skip to content

Bug: agentcore deploy does not honor HTTP_PROXY / HTTPS_PROXY for internal AWS SDK clients #2431

Description

@yeslei

Description

gentcore deploy fails in corporate environments where outbound AWS traffic must go through an HTTP/HTTPS proxy.

The proxy environment variables are correctly configured and other AWS tooling works from the same environment.

Environment

OS: Windows

AgentCore CLI: 0.30.0

Corporate HTTP/HTTPS proxy

HTTP_PROXY configured

HTTPS_PROXY configured

ALL_PROXY configured

Working

aws sts get-caller-identity

works correctly through the corporate proxy.

AgentCore operations such as:

agentcore export harness

also work.

Failing

agentcore deploy

fails because some AWS SDK clients used internally during deployment do not appear to honor the configured proxy.

Expected behavior

All outbound AWS SDK requests performed by AgentCore CLI should honor standard proxy environment variables such as:

HTTPS_PROXY

HTTP_PROXY

ALL_PROXY

Investigation

I was able to make agentcore deploy work by explicitly configuring a Smithy NodeHttpHandler with HTTP/HTTPS proxy agents and passing the request handler to the AWS SDK clients used during deployment.

The affected paths include clients such as:

STSClient

CloudFormationClient

ResourceGroupsTaggingAPIClient

CDK Toolkit AWS SDK configuration

Conceptually:

const requestHandler = new NodeHttpHandler({
httpAgent,
httpsAgent,
});

new STSClient({
credentials,
region,
requestHandler,
});

After routing these clients through the proxy, agentcore deploy succeeds in the same corporate environment.

Suggested fix

AgentCore CLI should centralize AWS SDK client configuration and automatically configure proxy-aware request handlers when standard proxy environment variables are present.

I can submit a PR implementing this behavior and adding tests if this approach is acceptable.

Steps to Reproduce

  1. Configure a corporate HTTP/HTTPS proxy where direct outbound connections to AWS endpoints are not allowed.
  2. Configure the standard proxy environment variables:
    $env:HTTP_PROXY="http://127.0.0.1:3128"
    $env:HTTPS_PROXY="http://127.0.0.1:3128"
    $env:ALL_PROXY="http://127.0.0.1:3128"
    $env:NODE_USE_ENV_PROXY="1"
  3. Verify that AWS CLI connectivity works through the proxy:
    aws sts get-caller-identity
    The command succeeds.
  4. Verify that AgentCore can perform other operations:
    agentcore export harness
    The export succeeds.
  5. Validate the AgentCore project:
    agentcore validate
    The validation succeeds.
  6. Attempt to deploy the same project:
    agentcore deploy --verbose
  7. Observe that agentcore deploy fails when internal AWS SDK requests attempt to access AWS services without correctly using the configured corporate proxy.

Expected Behavior

agentcore deploy should honor the standard HTTP_PROXY, HTTPS_PROXY, and/or ALL_PROXY environment variables for all outbound AWS SDK requests.

Actual Behavior

AWS CLI and other AgentCore operations work in the same proxy-configured environment, but agentcore deploy fails.
As a workaround, explicitly configuring a proxy-aware Smithy NodeHttpHandler for the AWS SDK clients used by the deployment path makes agentcore deploy succeed.

CLI Version

0.30.0

Operating System

Windows

Additional Context

AWS CLI and other AgentCore operations work in the same proxy-configured environment, but agentcore deploy fails.
As a workaround, explicitly configuring a proxy-aware Smithy NodeHttpHandler for the AWS SDK clients used by the deployment path makes agentcore deploy succeed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions