Skip to content

feat(bma): pass CDK managed role to BMA session - #2497

Open
nborges-aws wants to merge 1 commit into
refactorfrom
bma-iam-role
Open

nborges-aws wants to merge 1 commit into
refactorfrom
bma-iam-role

Conversation

@nborges-aws

Copy link
Copy Markdown
Contributor

Description

Add bedrockManagedAgents to the runtime configuration and set it in newly scaffolded BMA projects. After deployment, capture the CDK-managed session role ARN and associated runtime ARNs in deployed state. This PR also updates the BMA client to select and pass the role for its runtime when creating a session. This client no longer creates or modifies the IAM role.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • bun run test (3955 pass, 0 fail)
  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@github-actions github-actions Bot added the size/m PR size: M label Oct 1, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Oct 1, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Oct 1, 2026

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice, well-scoped change. The schema addition, CDK output capture + state recording, graceful error for an outdated @aws/agentcore-cdk, and the simplified China-region gate are all tested. client.py correctly resolves the project root (parents[2] from app/<runtime>/client.py lands at the project root), the state-file path matches DEPLOYED_STATE_RELATIVE_PATH, and the removal path (bedrockManagedAgents: false) clearing bmaSession works because the shallow spread drops undefined keys at JSON.stringify time.

A couple of minor things worth being aware of (not blockers):

  • src/core/project/backends/cdk.ts ~L374–402: updateTargetState clears bmaSession before describeStack, so a transient CloudFormation error (as opposed to missing outputs) will leave the project with no recorded BMA role until the next successful deploy. Acceptable since the user retries, but you could narrow the window by only clearing when bmaRuntimes.length === 0 and otherwise overwriting in the single final updateTargetState.
  • Dropping the tag/policy heuristics in manager.tsx means projects scaffolded by an older CLI that still have the agentcore:template=BedrockManagedAgents tag + bma-acr-policy.json but no bedrockManagedAgents: true will no longer be blocked from deploying to China and won't get a session role recorded. That seems intentional (the China deploy will fail at CFN time anyway), but worth confirming there's a migration note or that no in-the-wild projects fall into that gap.

Neither needs changes before merging.

@agentcore-devx-automation agentcore-devx-automation Bot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/m PR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants