fix(bma): create the BMA session role in client.py and pass it as role_arn - #2494
Open
siwachabhi wants to merge 1 commit into
Open
siwachabhi wants to merge 1 commit into
siwachabhi wants to merge 1 commit into
Conversation
Contributor
|
Claude Security Review: no high-confidence findings. (run) |
Contributor
There was a problem hiding this comment.
AgentCore Harness Review
Verdict: Looks good
Reviewed the full diff and traced the policy-file plumbing. The change is well-scoped: it moves bma-acr-policy.json under policies/, adds bma-session-trust.json / bma-session-policy.json, and extends client.py to create/repair a BmaSessionRole-<region> and pass it to BMA via extra_body={"role_arn": ...}.
Things I checked and found fine:
- ARN parsing in
session_role:runtime_arn.split(":")[:5]correctly maps to(arn, partition, service, region, account)for the AgentCore runtime ARN format. - Trust/policy equality checks:
role["AssumeRolePolicyDocument"]andget_role_policy(...)["PolicyDocument"]are returned as decoded dicts by boto3, so comparing againstjson.loads(trust)/json.loads(policy)is correct, and placeholder substitution runs beforejson.loads. ${AWS::...}substitution happens on the raw text before parsing, so the stored trust/inline policy never contains unexpanded placeholders.- Control flow around
--session-id/--role-arn:session_role()is only invoked when creating a new session and no--role-arnwas passed; the existing-session branch doesn't hitextra_body, matching the documented behavior. - Tests (
src/cli/templates/__tests__/bma.test.ts) use real file I/O against the template directory — no excessive mocking. - Telemetry: this PR only touches scaffolded template content (Python client, policy JSON, docs), so no CLI telemetry instrumentation is needed.
Nothing blocking. A couple of small things the author may want to consider as follow-ups (not required to merge):
boto3is added to thedevgroup ofpyproject.tomlwithout a version constraint, while the other entries use>=. Pinning a lower bound would be consistent.- The 15-second
time.sleepfor IAM eventual consistency is a known pragmatic workaround and is already documented in the README, so OK as-is.
Contributor
Coverage Report
|
siwachabhi
force-pushed
the
feat/bma-session-role
branch
from
October 1, 2026 01:57
2ab13c0 to
9f43fc0
Compare
Contributor
|
Claude Security Review: no high-confidence findings. (run) |
siwachabhi
had a problem deploying
to
e2e-testing
October 1, 2026 02:02 — with
GitHub Actions
Failure
…e_arn BMA needs a session role to call the model and the ACR. The template did not create it, so a new account failed on CreateAgentSession until the reader created BedrockManagedAgentsPreviewInferenceServiceRole by hand. client.py now creates or repairs BmaSessionRole-<region> from policies/bma-session-trust.json and policies/bma-session-policy.json, and sends its ARN with extra_body role_arn. --role-arn uses a role that the reader created. The ACR policy moves to policies/ with no change. Also override brace-expansion ^5.0.12, fast-uri ^3.1.8 and @humanfs/node ^0.16.8 so that npm audit --omit=dev passes (GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p, GHSA-hrr3-gc8f-f4qj, GHSA-p498-v437-472g).
siwachabhi
force-pushed
the
feat/bma-session-role
branch
from
October 1, 2026 03:02
9f43fc0 to
f1f14dd
Compare
siwachabhi
had a problem deploying
to
e2e-testing
October 1, 2026 03:02 — with
GitHub Actions
Failure
Contributor
|
Claude Security Review: no high-confidence findings. (run) |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Bedrock Managed Agents (BMA) assumes a session role to call the model and the AgentCore Runtime (ACR). The
BedrockManagedAgentstemplate did not create this role, andclient.pydid not send it. A new account failed inCreateAgentSessionwith a 400 error until the reader createdBedrockManagedAgentsPreviewInferenceServiceRoleby hand. No public page tells the reader to do that.This PR makes
client.pycreate the session role and send it asrole_arn. It needs no construct change and no construct release.When
client.pycreates a session and the reader does not give--role-arn, the client does these steps:policies/bma-session-trust.jsonandpolicies/bma-session-policy.json.BmaSessionRole-<region>does not exist, the client creates it.BmaSessionis not the same as the file, the client writes the file to the role.--role-arnuses a role that the reader created, and the client then makes no IAM calls. If the caller has no IAM permissions, the client stops and tells the reader to give--role-arn.The session policies are limited to the account and the Region of the ACR. They do not name one Runtime, because the Runtime ARN is not known when you create the role:
bedrock-mantle.amazonaws.com, withaws:SourceAccountandaws:SourceArnonsession/*andproject/*.bedrock-mantle:CreateInferenceon*,InvokeAgentRuntimeandStopRuntimeSessiononruntime/*andruntime/*/runtime-endpoint/*, andInvokeGatewayongateway/*.Changes:
client.py: add--role-arn, create or repair the session role with boto3, and send the role withextra_body={"role_arn": ...}, because the OpenAI SDK has norole_arnparameter.policies/bma-session-trust.jsonandpolicies/bma-session-policy.json: new.policies/bma-acr-policy.json: moved from the template root. The content is the same.bmaProfile.ts: the new path inadditionalPolicies.pyproject.toml: addboto3to thedevgroup.README.md(template) anddocs/frameworks.md: a "Session role" section. It says clearly thatclient.pycreates an IAM role in your account, thatagentcore removedoes not delete it, what the client repairs and what it does not change, and the IAM permissions of the caller.bma.test.tsand the asset snapshot.Related Issue
No issue. The problem came from the BMA launch tests on 2026-09-29.
Documentation PR
The AgentCore developer guide page
runtime-get-started-bmagets a matching change in a separate internal docs review.Type of Change
Testing
npm run test:unit(6,332 passed).npm run test:integnot run. The TUI integration suites need a terminal.npm run typecheckruff checkandruff format --checkonclient.pyEnd to end in one account in us-east-1, after I deleted
BedrockManagedAgentsPreviewInferenceServiceRole:--role-arn--session-idpolicies/bma-session-policy.json, then reverts it--role-arnwith a good role--role-arnvalidation_errorwithparam: role_arn.--role-arniam:PassRole, with--role-arniam:PassRoleiam:PassRole.--deleteCloudTrail showed 51
AssumeRolecalls frombedrock-mantle.amazonaws.comonBmaSessionRole-us-east-1. None failed, and none went to the preview role.Known limits, which the README states:
BmaSession. Another policy on the role, for example aDeny, stays.--session-iddoes not check the role. If the role is broken, the turn fails until a new session repairs it.Checklist