bug(policy): add policy --target generates an undeployable Cedar statement (wrong action id suffix, resource scope not narrowed)
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 70/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- aws, cli, typescript
- Domain
- backend-api-design, cli, security
Research direction
The issue is in the synthesizeCedar function, likely in dist/cdk/.../synthesizeCedar. Look for where the action ID suffix ___POST:/invocations is hardcoded and where the gatewayArn option is not being passed. The fix involves updating the action suffix to use the tool name and passing the gateway ARN to generate the correct resource constraint. Test by running the reproduction steps and verifying the generated Cedar statement in agentcore.json matches the expected format.
Written by the indexing model from the issue text.
Description
Description
agentcore add policy --target <target-name> generates a Cedar statement that the AgentCore Control API always rejects, so a tool-scoped policy can never be deployed. Two independent defects in the same generated statement:
- Wrong action id suffix. The CLI emits
AgentCore::Action::"<target>___POST:/invocations". The service expectsAgentCore::Action::"<target>___<toolName>"and even suggests the correct value in its error. - Resource scope not narrowed. The CLI emits
resource is AgentCore::Gateway. For a tool-scoped policy the service requires a concrete gateway ARN (resource == AgentCore::Gateway::"<arn>").
synthesizeCedar already accepts a gatewayArn option and produces the ARN-scoped form when it is supplied, but add policy never passes it.
Both defects must be fixed by hand in agentcore.json before agentcore deploy succeeds, which makes add policy --target unusable as shipped.
Steps to Reproduce
agentcore create --name gwprobe2 --no-agent
cd gwprobe2
agentcore add gateway --name toolgw --protocol-type MCP --authorizer-type AWS_IAM
agentcore add gateway-target --type connector --connector web-search \
--gateway toolgw --name websearch
agentcore add policy-engine --name toolpe --attach-to-gateways toolgw --attach-mode ENFORCE
agentcore add policy --name blockViolence --engine toolpe \
--form-category contentFilter --form-filters VIOLENCE --form-effect forbid \
--target websearch
agentcore deploy -y
Generated statement in agentcore.json:
forbid (principal, action == AgentCore::Action::"websearch___POST:/invocations",
resource is AgentCore::Gateway)
when guardrails { BedrockGuardrails::ContentFilter(["VIOLENCE"], [context.input.prompt])["VIOLENCE"].confidenceScore.greaterThan(decimal("0.2")) };
Expected Behavior
agentcore deploy creates the AWS::BedrockAgentCore::Policy resource.
Actual Behavior
Deploy fails at CreatePolicy. Defect 1 surfaces first:
Resource handler returned message: "Multiple errors occurred during policy parsing/validation:
* for policy `blockViolence_..._0`, unrecognized action
`AgentCore::Action::"websearch___POST:/invocations"` at line 1, column 30
did you mean `AgentCore::Action::"websearch___WebSearch"`?
* for policy `blockViolence_..._0`, unable to find an applicable action given the
policy scope constraints
(Service: Bedrock AgentCore Control; Operation: CreatePolicy; Status Code: 400;
Error Code: ValidationException)"
After correcting the action id by hand, defect 2 surfaces:
Resource handler returned message: "When parsing the policy statement, a constrained
action scope was encountered, please constrain the resource to a specific
AgentCore::Gateway resource when creating tool-specific policies.
(Service: Bedrock AgentCore Control; Operation: CreatePolicy; Status Code: 400;
Error Code: ValidationException)"
Both corrections applied by hand, the policy deploys and enforces correctly — confirming the statement is the only problem:
forbid (principal, action == AgentCore::Action::"websearch___WebSearch",
resource == AgentCore::Gateway::"arn:aws:bedrock-agentcore:ap-northeast-1:<account>:gateway/gwprobe2-toolgw-<id>")
when { context.input.query like "*forbidden*" };
Verified end to end over the gateway's MCP endpoint (SigV4):
query = "washing machine error code"→isError: false, results returnedquery = "this is forbidden content"→Tool Execution Denied: Tool call not allowed due to policy enforcement [Policy evaluation denied due to <policy-id>]
CLI Version
0.30.0
Operating System
macOS
Additional Context
- Region:
ap-northeast-1. GatewayauthorizerType: AWS_IAM, target typeconnector/web-search. @aws/agentcore-cdk0.1.0-alpha.53. Indist/cdk/.../synthesizeCedar, thegatewayArnoption already selectsresource == AgentCore::Gateway::"${arn}"overresource is AgentCore::Gateway, so defect 2 looks like a missing call-site argument rather than a missing feature.- The action id suffix appears as a literal
___POST:/invocationstemplate in the same function. - Related but distinct: #1571 (same shape — accepted locally, rejected by CFN — but about a contentFilter enum value), #1910 (
EnforcementModenot emitted by the CDK package), #1658 (--generategateway lookup, closed). - Docs for this area are still open as #1581, which is why the correct action-id and resource-scope forms are not discoverable today.
- Dominant language
- TypeScript
- Stars
- 291
- Forks
- 96
- Avg merge
- 21h 31m
- Merged PRs (30d)
- 217
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from aws/agentcore-cli
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
aws/agentcore-cli#2392 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
aws/agentcore-cli#2267 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
aws/agentcore-cli#2258 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
aws/agentcore-cli#2176 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
aws/agentcore-cli#2140 ·
All issues in aws/agentcore-cli
Similar issues
-
bug(cli): hapi doctor inline-media prints a fabricated B:\ helper-script path in packaged installs Open
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
Crush Open
Difficulty 1/5 Under an hour Newbie friendliness 85/100
catppuccin/catppuccin#3125 ·
-
Add a SECURITY.md Open
Difficulty 1/5 Under an hour Newbie friendliness 90/100
ElementsProject/cln-application#167 · 1 comment · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Quantco/pnpm-licenses#17 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100