Skip to content

fix(import/export): harden generated Python container recipes - #2500

Merged
aidandaly24 merged 3 commits into
aws:mainfrom
aidandaly24:fix/container-import-export-hardening
Oct 1, 2026
Merged

aidandaly24 merged 3 commits into
aws:mainfrom
aidandaly24:fix/container-import-export-hardening

Conversation

@aidandaly24

Copy link
Copy Markdown
Contributor

Description

Follow-up to #2496 covering the reachable Dockerfile generation paths identified in review.

  • Import's fallback now renders the shared hardened Python template, preserving the imported entrypoint and any existing .dockerignore.
  • containerUri exports disable uv caching and remove the global uv installation after the final frozen sync.
  • Custom Dockerfile export guidance provides the same cache/tool cleanup and explicitly requires refreshing the base OS using its appropriate package manager and privileges.
  • Custom Dockerfiles remain copied unchanged; generated guidance explains when to adjust the global Python path or retain uv for custom runtime requirements.

No docs, README, dependency-version, or refactor-branch changes are included.

Related Issue

Follow-up to #2496, addressing this review comment.

Documentation PR

Not applicable. Guidance is updated only in the existing generated export notes and Dockerfile comments.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

  • 616 tests passed across the import/export, template-rendering, and rendered-Dockerfile suites.
  • Regression coverage calls the actual import/export handlers and inspects the files they generate.
  • Verified imported fallback hardening and preservation of a customer .dockerignore.
  • Verified exported base URI preservation, uv cleanup, OS-refresh guidance, and unchanged custom Dockerfile contents.
  • npm run typecheck, npm run lint, npm run format:check, and npm run build pass.

No AWS deployment or new Inspector scan was performed. This follow-up tests generated artifacts and preserves the previously validated shared recipe.

  • I ran the relevant unit suites
  • I ran npm run typecheck
  • I ran npm run lint
  • No template assets or snapshots were modified

Existing Project Remediation

A CLI upgrade or unchanged redeploy alone does not update an existing project's files. For release/support handoff:

  1. Update affected pyproject.toml constraints to allow patched dependencies, including MCP >=1.28.1,<2 and AgentCore SDK >=1.18.1. For Strands Memory integrations, enable the SDK's strands-agents extra and remove incompatible old Strands minor pins.
  2. Run uv lock --upgrade in the agent's code directory.
  3. Apply the OS update, UV_NO_CACHE=1, and post-sync global uv cleanup to the existing Dockerfile as appropriate for its base. Preserve uv if the custom runtime needs it.
  4. Rebuild with refreshed base/OS layers, then redeploy the changed image. For manual Docker builds, use --pull --no-cache; for CodeBuild, ensure the build does not reuse stale base or OS-update layers.
  5. Verify the deployed image digest, installed versions, application behavior, and unsuppressed scan results. Unfixed/applicability-dependent findings are not automatically eliminated by this change.

These steps are handoff guidance, not migration automation or a claim that all findings are exploitable or resolved.

Checklist


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@aidandaly24
aidandaly24 requested a review from a team October 1, 2026 18:19
@github-actions github-actions Bot added the size/m PR size: M label Oct 1, 2026
@aidandaly24
aidandaly24 deployed to e2e-testing October 1, 2026 18:20 — with GitHub Actions Active
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Oct 1, 2026

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Narrow, well-scoped follow-up to #2496. Changes are limited to Dockerfile text generated/suggested for three paths and align with the already-hardened shared template at src/assets/container/python/Dockerfile:

  • import/actions.ts — replacing the inline Dockerfile string with copyAndRenderDir(getTemplatePath('container', 'python'), …) is a nice de-duplication. The exclude: new Set(['.dockerignore']) correctly cooperates with resolveTemplateName (which maps dockerignore.template → .dockerignore) so a customer-provided .dockerignore copied earlier via copyDirRecursive is preserved. Behavior when the source has no .dockerignore is unchanged from pre-PR (none is written), so no regression.
  • export/harness-action.ts — writeDockerfileStub adds UV_NO_CACHE=1 and the final pip uninstall -y uv, matching the shared template. buildCustomDockerfileNote picks up the same cleanup and asks the user to refresh the base OS with the appropriate package manager.
  • Tests use real temp dirs and only mock execSync and env — no excessive mocking. Telemetry is already wired via withCommandRunTelemetry; this PR adds no new feature paths that would need additional attributes.

One minor caveat worth noting (not blocking, already called out in the generated comments): the writeDockerfileStub installs uv with whatever pip is on PATH but uninstalls via a hardcoded /usr/local/bin/python -m pip uninstall -y uv. For arbitrary containerUri base images those can be different interpreters, which would make the uninstall a no-op or error. The adjacent comments explicitly tell the user to adjust the path, so this is a documented best-effort tradeoff — fine to merge as-is.

@agentcore-devx-automation agentcore-devx-automation Bot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Package Tarball

aws-agentcore-0.31.0.tgz

How to install

gh release download pr-2500-tarball --repo aws/agentcore-cli --pattern "*.tgz" --dir /tmp/pr-tarball
npm install -g /tmp/pr-tarball/aws-agentcore-0.31.0.tgz

@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Oct 1, 2026
@notgitika

Copy link
Copy Markdown
Contributor

Looks good, thanks!

@aidandaly24
aidandaly24 merged commit 66d1762 into aws:main Oct 1, 2026
36 of 40 checks passed

This branch was successfully deployed

1 active deployment
e2e-testing — a32e2bfa Deployed Oct 1, 2026 by aidandaly24 via e2e #3362
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/m PR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants