bug(policy): add policy --target generates an undeployable Cedar statement (wrong action id suffix, resource scope not narrowed)
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 70/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- aws, cli, typescript
調査の方向性
問題は synthesizeCedar 関数にあり、おそらく dist/cdk/.../synthesizeCedar にあります。アクションIDサフィックス ___POST:/invocations がハードコードされている場所と、gatewayArn オプションが渡されていない場所を探してください。修正には、アクションサフィックスをツール名を使用するように更新し、正しいリソース制約を生成するためにゲートウェイARNを渡すことが含まれます。再現手順を実行し、agentcore.json で生成されたCedarステートメントが期待される形式と一致することを確認してテストしてください。
索引モデルが issue の本文から書いたものです。
説明
Description
agentcore add policy --target <target-name> generates a Cedar statement that the AgentCore Control API always rejects, so a tool-scoped policy can never be deployed. Two independent defects in the same generated statement:
- Wrong action id suffix. The CLI emits
AgentCore::Action::"<target>___POST:/invocations". The service expectsAgentCore::Action::"<target>___<toolName>"and even suggests the correct value in its error. - Resource scope not narrowed. The CLI emits
resource is AgentCore::Gateway. For a tool-scoped policy the service requires a concrete gateway ARN (resource == AgentCore::Gateway::"<arn>").
synthesizeCedar already accepts a gatewayArn option and produces the ARN-scoped form when it is supplied, but add policy never passes it.
Both defects must be fixed by hand in agentcore.json before agentcore deploy succeeds, which makes add policy --target unusable as shipped.
Steps to Reproduce
agentcore create --name gwprobe2 --no-agent
cd gwprobe2
agentcore add gateway --name toolgw --protocol-type MCP --authorizer-type AWS_IAM
agentcore add gateway-target --type connector --connector web-search \
--gateway toolgw --name websearch
agentcore add policy-engine --name toolpe --attach-to-gateways toolgw --attach-mode ENFORCE
agentcore add policy --name blockViolence --engine toolpe \
--form-category contentFilter --form-filters VIOLENCE --form-effect forbid \
--target websearch
agentcore deploy -y
Generated statement in agentcore.json:
forbid (principal, action == AgentCore::Action::"websearch___POST:/invocations",
resource is AgentCore::Gateway)
when guardrails { BedrockGuardrails::ContentFilter(["VIOLENCE"], [context.input.prompt])["VIOLENCE"].confidenceScore.greaterThan(decimal("0.2")) };
Expected Behavior
agentcore deploy creates the AWS::BedrockAgentCore::Policy resource.
Actual Behavior
Deploy fails at CreatePolicy. Defect 1 surfaces first:
Resource handler returned message: "Multiple errors occurred during policy parsing/validation:
* for policy `blockViolence_..._0`, unrecognized action
`AgentCore::Action::"websearch___POST:/invocations"` at line 1, column 30
did you mean `AgentCore::Action::"websearch___WebSearch"`?
* for policy `blockViolence_..._0`, unable to find an applicable action given the
policy scope constraints
(Service: Bedrock AgentCore Control; Operation: CreatePolicy; Status Code: 400;
Error Code: ValidationException)"
After correcting the action id by hand, defect 2 surfaces:
Resource handler returned message: "When parsing the policy statement, a constrained
action scope was encountered, please constrain the resource to a specific
AgentCore::Gateway resource when creating tool-specific policies.
(Service: Bedrock AgentCore Control; Operation: CreatePolicy; Status Code: 400;
Error Code: ValidationException)"
Both corrections applied by hand, the policy deploys and enforces correctly — confirming the statement is the only problem:
forbid (principal, action == AgentCore::Action::"websearch___WebSearch",
resource == AgentCore::Gateway::"arn:aws:bedrock-agentcore:ap-northeast-1:<account>:gateway/gwprobe2-toolgw-<id>")
when { context.input.query like "*forbidden*" };
Verified end to end over the gateway's MCP endpoint (SigV4):
query = "washing machine error code"→isError: false, results returnedquery = "this is forbidden content"→Tool Execution Denied: Tool call not allowed due to policy enforcement [Policy evaluation denied due to <policy-id>]
CLI Version
0.30.0
Operating System
macOS
Additional Context
- Region:
ap-northeast-1. GatewayauthorizerType: AWS_IAM, target typeconnector/web-search. @aws/agentcore-cdk0.1.0-alpha.53. Indist/cdk/.../synthesizeCedar, thegatewayArnoption already selectsresource == AgentCore::Gateway::"${arn}"overresource is AgentCore::Gateway, so defect 2 looks like a missing call-site argument rather than a missing feature.- The action id suffix appears as a literal
___POST:/invocationstemplate in the same function. - Related but distinct: #1571 (same shape — accepted locally, rejected by CFN — but about a contentFilter enum value), #1910 (
EnforcementModenot emitted by the CDK package), #1658 (--generategateway lookup, closed). - Docs for this area are still open as #1581, which is why the correct action-id and resource-scope forms are not discoverable today.
- 主要言語
- TypeScript
- スター
- 291
- フォーク
- 96
- 平均マージ
- 18時間 34分
- マージ済み PR(30日)
- 202
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
aws/agentcore-cli のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
aws/agentcore-cli#2392 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
aws/agentcore-cli#2267 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
aws/agentcore-cli#2258 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
aws/agentcore-cli#2176 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
aws/agentcore-cli#2140 ·
メンテナーはふだん 1 日以内に返信
aws/agentcore-cli の issue をすべて見る
似ている issue
-
priority: P2
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
prime-radiant-inc/evener#3291 ·
メンテナーはふだん 1 日以内に返信
-
accessibility bug revealjs
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
quarto-dev/quarto-cli#14961 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
supabase/agent-skills#614 ·
-
Content
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
RunestoneInteractive/rs#1559 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信