fix(import/export): harden generated Python container recipes - #2500
Conversation
There was a problem hiding this comment.
AgentCore Harness Review
Verdict: Looks good
Narrow, well-scoped follow-up to #2496. Changes are limited to Dockerfile text generated/suggested for three paths and align with the already-hardened shared template at src/assets/container/python/Dockerfile:
import/actions.ts— replacing the inline Dockerfile string withcopyAndRenderDir(getTemplatePath('container', 'python'), …)is a nice de-duplication. Theexclude: new Set(['.dockerignore'])correctly cooperates withresolveTemplateName(which mapsdockerignore.template→.dockerignore) so a customer-provided.dockerignorecopied earlier viacopyDirRecursiveis preserved. Behavior when the source has no.dockerignoreis unchanged from pre-PR (none is written), so no regression.export/harness-action.ts—writeDockerfileStubaddsUV_NO_CACHE=1and the finalpip uninstall -y uv, matching the shared template.buildCustomDockerfileNotepicks up the same cleanup and asks the user to refresh the base OS with the appropriate package manager.- Tests use real temp dirs and only mock
execSyncand env — no excessive mocking. Telemetry is already wired viawithCommandRunTelemetry; this PR adds no new feature paths that would need additional attributes.
One minor caveat worth noting (not blocking, already called out in the generated comments): the writeDockerfileStub installs uv with whatever pip is on PATH but uninstalls via a hardcoded /usr/local/bin/python -m pip uninstall -y uv. For arbitrary containerUri base images those can be different interpreters, which would make the uninstall a no-op or error. The adjacent comments explicitly tell the user to adjust the path, so this is a documented best-effort tradeoff — fine to merge as-is.
Package TarballHow to installgh release download pr-2500-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.31.0.tgz |
|
Claude Security Review: no high-confidence findings. (run) |
|
Looks good, thanks! |
Description
Follow-up to #2496 covering the reachable Dockerfile generation paths identified in review.
.dockerignore.containerUriexports disable uv caching and remove the global uv installation after the final frozen sync.No docs, README, dependency-version, or refactor-branch changes are included.
Related Issue
Follow-up to #2496, addressing this review comment.
Documentation PR
Not applicable. Guidance is updated only in the existing generated export notes and Dockerfile comments.
Type of Change
Testing
.dockerignore.npm run typecheck,npm run lint,npm run format:check, andnpm run buildpass.No AWS deployment or new Inspector scan was performed. This follow-up tests generated artifacts and preserves the previously validated shared recipe.
npm run typechecknpm run lintExisting Project Remediation
A CLI upgrade or unchanged redeploy alone does not update an existing project's files. For release/support handoff:
pyproject.tomlconstraints to allow patched dependencies, including MCP>=1.28.1,<2and AgentCore SDK>=1.18.1. For Strands Memory integrations, enable the SDK'sstrands-agentsextra and remove incompatible old Strands minor pins.uv lock --upgradein the agent's code directory.UV_NO_CACHE=1, and post-sync global uv cleanup to the existing Dockerfile as appropriate for its base. Preserve uv if the custom runtime needs it.--pull --no-cache; for CodeBuild, ensure the build does not reuse stale base or OS-update layers.These steps are handoff guidance, not migration automation or a claim that all findings are exploitable or resolved.
Checklist
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.