AgentCoreMemorySessionManager discards the two boto3 clients MemoryClient builds; boto_session and boto_client_config are not passed through
Maintainers usually reply within 1 day
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 84/100
Research direction
Start in src/bedrock_agentcore/memory/integrations/strands/session_manager.py at AgentCoreMemorySessionManager.init, then inspect MemoryClient.init in memory/client.py:76-80. Run the supplied no-session and warm-session reproduction; done means MemoryClient uses the same session as the override clients, without public signature changes, and the reported timing and region behavior are corrected.
Written by the indexing model from the issue text.
Description
Describe the bug
AgentCoreMemorySessionManager.__init__ builds its MemoryClient without a boto3 session, then overwrites both clients MemoryClient just created with clients from a different session.
# src/bedrock_agentcore/memory/integrations/strands/session_manager.py, 1.23.1
self.memory_client = MemoryClient(region_name=region_name) # :151
session = boto_session or boto3.Session(region_name=region_name) # :152
...
self.memory_client.gmcp_client = session.client( # :195
"bedrock-agentcore-control", region_name=..., config=client_config
)
self.memory_client.gmdp_client = session.client( # :198
"bedrock-agentcore", region_name=..., config=client_config
)
MemoryClient.__init__ accepts boto3_session (memory/client.py:76-80) and would use it. Since it isn't passed, MemoryClient creates its own boto3.Session() and builds bedrock-agentcore-control and bedrock-agentcore clients from it. Lines 195 and 198 then replace both. Those two clients are built and thrown away on every instantiation.
botocore caches the parsed service model per boto3.Session, so a fresh session pays that load again every time.
boto_session and boto_client_config are both in the signature and documented in the docstring. Neither reaches MemoryClient.
Cost
We build a session manager per invoke, so this runs on every turn. We also pass a long-lived boto_session, which is what the parameter is for, and that's where this hurts most. The injected session only reaches the override clients. MemoryClient still cold-builds its own session, and that cold build is nearly all of the remaining time.
Medians over 10 iterations after a warm-up, from the script below:
| caller | as shipped | with the fix below |
|---|---|---|
passes boto_session (a long-lived session) |
42 ms | 3.3 ms |
passes no boto_session |
97 ms | 41 ms |
Five consecutive runs ranged 40.3 to 43.9 ms against 3.2 to 3.5 ms for the first row, and 95.3 to 98.9 ms against 39.9 to 44.1 ms for the second.
These are from an M-series laptop. On a warm AgentCore runtime the per-turn cost is in the same range, 37 to 51 ms. The first construction on a cold container is higher, because the service-model load and credential resolution happen then.
To Reproduce
import os, statistics, time
os.environ["AWS_CONFIG_FILE"] = "/dev/null"
os.environ["AWS_SHARED_CREDENTIALS_FILE"] = "/dev/null"
os.environ["AWS_ACCESS_KEY_ID"] = "AKIAIOSFODNN7EXAMPLE"
os.environ["AWS_SECRET_ACCESS_KEY"] = "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
os.environ["AWS_EC2_METADATA_DISABLED"] = "true"
import boto3
from botocore.config import Config
from bedrock_agentcore.memory.client import MemoryClient
REGION = "us-west-2"
CFG = Config(user_agent_extra="strands-agents") # what :184-192 builds
def pair(s): # the :195/:198 overrides
s.client("bedrock-agentcore-control", region_name=REGION, config=CFG)
s.client("bedrock-agentcore", region_name=REGION, config=CFG)
# A long-lived session the caller passes as boto_session, primed once.
WARM = boto3.Session(region_name=REGION)
pair(WARM)
def no_session_shipped(): # boto_session=None, as shipped
MemoryClient(region_name=REGION)
pair(boto3.Session(region_name=REGION))
def no_session_fixed():
s = boto3.Session(region_name=REGION)
MemoryClient(region_name=REGION, boto3_session=s)
pair(s)
def warm_session_shipped(): # boto_session=WARM, as shipped
MemoryClient(region_name=REGION)
pair(WARM)
def warm_session_fixed():
MemoryClient(region_name=REGION, boto3_session=WARM)
pair(WARM)
for name, fn in (("no session, shipped", no_session_shipped),
("no session, fixed", no_session_fixed),
("warm session, shipped", warm_session_shipped),
("warm session, fixed", warm_session_fixed)):
fn() # warm-up
samples = []
for _ in range(10):
t0 = time.perf_counter(); fn()
samples.append((time.perf_counter() - t0) * 1000)
print(f"{name:22s} {statistics.median(samples):6.1f} ms")
Run it with no AWS profile set. It makes no network calls, so the dummy keys only stop botocore from searching for real ones.
Expected behavior
MemoryClient should be built from the same session the overrides use. Hoisting line 152 above line 151 and passing the session through is enough:
session = boto_session or boto3.Session(region_name=region_name)
self.memory_client = MemoryClient(region_name=region_name, boto3_session=session)
No public signature changes. Callers who pass boto_session get the 42 to 3.3 ms drop, and callers who don't still save the second service-model load.
Two related points:
-
boto_client_configcan't be forwarded the same way.MemoryClient.__init__takes onlyregion_name,integration_sourceandboto3_session, and builds its ownConfig(user_agent_extra=...)internally. Honouring the documentedboto_client_configmeans adding a parameter there. Until then, retry and timeout config can't be set on the memory client at all. -
With
region_name=Noneand aboto_sessionpinned to one region,MemoryClient.region_nameresolves from a fresh default session while the clients actually used come fromboto_session. The attribute can disagree with the region serving the calls. Passing the session fixes that too.
Happy to test a patch against our workload. I didn't open a PR because CONTRIBUTING.md says the repo isn't accepting external ones.
Environment
bedrock-agentcore1.23.1. Also present onmainat cc980d14, the most recent commit to touch this file.- boto3 1.43.101, botocore 1.43.101
- Python 3.13.13, macOS
- Also reproduces on 1.18.1
- Dominant language
- Python
- Stars
- 776
- Forks
- 153
- Avg merge
- 1d 8h
- Merged PRs (30d)
- 15
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from aws/bedrock-agentcore-sdk-python
-
bug high-severity
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
aws/bedrock-agentcore-sdk-python#698 ·
Maintainers usually reply within 1 day
-
bug high-severity
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
aws/bedrock-agentcore-sdk-python#680 ·
Maintainers usually reply within 1 day
-
[Bug] update_message fails with parameter validation error when SessionMessage.message_id is a Strands positional integer indexPossibly taken @citizen204 claimed this 100 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
aws/bedrock-agentcore-sdk-python#556 ·
Maintainers usually reply within 1 day
-
CodeInterpreter should not require a region argumentPossibly taken @citizen204 claimed this 114 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
aws/bedrock-agentcore-sdk-python#511 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
aws/bedrock-agentcore-sdk-python#496 · 1 comment ·
Maintainers usually reply within 1 day
All issues in aws/bedrock-agentcore-sdk-python
Similar issues
-
Difficulty 1/5 1-3 hours Newbie friendliness 85/100
pytest-dev/pluggy#757 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 1-3 hours Newbie friendliness 85/100
NousResearch/hermes-agent#134960 ·
Maintainers usually reply within 1 day
-
HTML backend: `<br>` leaks the internal sentinel U+E000 into list items, headings and captionsPossibly taken @morten-lagabote claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 67/100
docling-project/docling#4671 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Maintainers usually reply within 1 day
-
good first issue hacktoberfest infra
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day