Skip to content

feat(bma): pass CDK managed role to BMA session - #2497

Open
nborges-aws wants to merge 1 commit into
refactorfrom
bma-iam-role
Open

nborges-aws wants to merge 1 commit into
refactorfrom
bma-iam-role

Conversation

@nborges-aws

Copy link
Copy Markdown
Contributor

Description

Add bedrockManagedAgents to the runtime configuration and set it in newly scaffolded BMA projects. After deployment, capture the CDK-managed session role ARN and associated runtime ARNs in deployed state. This PR also updates the BMA client to select and pass the role for its runtime when creating a session. This client no longer creates or modifies the IAM role.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • bun run test (3955 pass, 0 fail)
  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@github-actions github-actions Bot added the size/m PR size: M label Oct 1, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Oct 1, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Oct 1, 2026

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice, well-scoped change. The schema addition, CDK output capture + state recording, graceful error for an outdated @aws/agentcore-cdk, and the simplified China-region gate are all tested. client.py correctly resolves the project root (parents[2] from app/<runtime>/client.py lands at the project root), the state-file path matches DEPLOYED_STATE_RELATIVE_PATH, and the removal path (bedrockManagedAgents: false) clearing bmaSession works because the shallow spread drops undefined keys at JSON.stringify time.

A couple of minor things worth being aware of (not blockers):

  • src/core/project/backends/cdk.ts ~L374–402: updateTargetState clears bmaSession before describeStack, so a transient CloudFormation error (as opposed to missing outputs) will leave the project with no recorded BMA role until the next successful deploy. Acceptable since the user retries, but you could narrow the window by only clearing when bmaRuntimes.length === 0 and otherwise overwriting in the single final updateTargetState.
  • Dropping the tag/policy heuristics in manager.tsx means projects scaffolded by an older CLI that still have the agentcore:template=BedrockManagedAgents tag + bma-acr-policy.json but no bedrockManagedAgents: true will no longer be blocked from deploying to China and won't get a session role recorded. That seems intentional (the China deploy will fail at CFN time anyway), but worth confirming there's a migration note or that no in-the-wild projects fall into that gap.

Neither needs changes before merging.

@agentcore-devx-automation agentcore-devx-automation Bot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Oct 1, 2026
aidandaly24
aidandaly24 previously approved these changes Oct 1, 2026
@github-actions github-actions Bot added size/m PR size: M and removed size/m PR size: M labels Oct 2, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Oct 2, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Oct 2, 2026
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.40%. Comparing base (8e330f9) to head (e862d98).

Additional details and impacted files
@@            Coverage Diff            @@
##           refactor    #2497   +/-   ##
=========================================
  Coverage     97.40%   97.40%           
=========================================
  Files           642      642           
  Lines         46865    46905   +40     
=========================================
+ Hits          45647    45687   +40     
  Misses         1218     1218           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/m PR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants