feat(gateway-target): allow GATEWAY_IAM_ROLE outbound auth on mcpServer / openApiSchema targets (iamCredentialProvider)
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 50/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- aws, typescript
- Lĩnh vực
- authentication, cli, tooling
Hướng nghiên cứu
Bắt đầu với src/schema/schemas/mcp.ts và tái hiện vấn đề bằng agentcore validate, sau đó kiểm tra flag validator và L3 buildCredentialConfig(). Đồng thời kiểm tra bảng Auth của --help và danh sách tùy chọn của TUI. Hoàn tất khi IAM auth được chấp nhận và phát ra đúng cho mcpServer và openApiSchema, bị từ chối ở nơi không phù hợp, và credential requirement không còn áp dụng cho IAM hoặc JWT passthrough.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Description
Gateway supports IAM outbound auth to MCP server and OpenAPI targets — the gateway signs with SigV4 via its service role. Per Set up outbound authorization for your gateway, these two target types take a GATEWAY_IAM_ROLE credential provider plus an iamCredentialProvider block (service required — bedrock-agentcore for MCP servers on AgentCore Runtime; region optional). Lambda / API Gateway / Smithy take the bare credentialProviderType with no iamCredentialProvider.
TARGET_TYPE_AUTH_CONFIG in src/schema/schemas/mcp.ts doesn't allow it: mcpServer is OAUTH | NONE, openApiSchema is OAUTH | API_KEY. Only passthrough gets GATEWAY_IAM_ROLE. So there's no way to put an IAM-auth MCP server hosted on AgentCore Runtime behind a gateway — it forces an OAuth provider in front of a runtime that already authenticates with SigV4.
It's a schema block, not just a missing flag — hand-editing agentcore.json fails too:
$ agentcore validate
- agentCoreGateways[0].targets[0].outboundAuth:
mcpServer targets do not support GATEWAY_IAM_ROLE outbound auth
Separately, the flag surface reports the wrong reason — the guard exempts only NONE, so GATEWAY_IAM_ROLE and JWT_PASSTHROUGH fall through into the OAuth credential requirement:
$ agentcore add gateway-target --type mcp-server --outbound-auth gateway-iam-role \
--signing-service bedrock-agentcore ...
--credential-name or inline OAuth fields (--oauth-client-id, --oauth-client-secret,
--oauth-discovery-url) required when outbound auth type is gateway-iam-role
Acceptance Criteria
-
TARGET_TYPE_AUTH_CONFIGallowsGATEWAY_IAM_ROLEonmcpServerandopenApiSchema, withservicerequired there and rejected for Lambda / API Gateway / Smithy -
--signing-service/--signing-regionaccepted for these types, not justpassthrough - flag validator exempts
GATEWAY_IAM_ROLE/JWT_PASSTHROUGHfrom the credential requirement - L3
buildCredentialConfig()emits theiamCredentialProviderblock for these types (today it returnsundefinedoutside the passthrough branch — the #1005 failure shape) -
--helpAuth table and TUI option list updated
Additional Context
@aws/agentcore0.28.1,@aws/agentcore-cdk0.1.0-alpha.50,aws-cdk-lib2.261.0.- Reproduced at config /
validatelevel only; I haven't run a liveCreateGatewayTargetwith this shape. - Related: #1359 (same map,
API_KEY). Note #1914/#1915 recorded "mcpServer supports only OAuth or none" — accurate to the validator, but the doc above allows IAM.
- Ngôn ngữ chính
- TypeScript
- Star
- 291
- Fork
- 96
- Merge trung bình
- 20 giờ 50 phút
- Pull request đã merge (30 ngày)
- 214
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của aws/agentcore-cli
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
aws/agentcore-cli#2395 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
aws/agentcore-cli#2392 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
aws/agentcore-cli#2267 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
aws/agentcore-cli#2258 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
aws/agentcore-cli#2176 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của aws/agentcore-cli
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
melgarafael/DeskcommCRM#1812 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
prisma/prisma-cli#309 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
gregwebs/pi-quota-dispatcher#26 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
openwatersio/slackwater.xyz#124 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent-reported area/browser area/docs documentation good first issue hacktoberfest help wanted P2
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
Maintainer thường phản hồi trong vòng 2 ngày