Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[Feature Request] Support configuring a custom IAM permissions boundary for generated roles

Đang mở
#2,246 2 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
52/100
Loại issue
Tính năng
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
aws, typescript
Lĩnh vực
cloud, infrastructure

Hướng nghiên cứu

Bắt đầu bằng cách lần theo entry point bin/cdk.ts được tạo qua CLI template và luồng materialization của cdk/ được agentcore deploy sử dụng. Kiểm tra cách các role của harness và runtime được tổng hợp, sau đó xác minh rằng một boundary đã được cấu hình sẽ áp dụng cho mọi role được tạo hoặc được L3 tạo ra, mặc định không tồn tại và vẫn được duy trì sau khi tạo lại và deployment.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

enhancement
Description

Please add first-class support for attaching a custom IAM permissions boundary to every IAM role that AgentCore generates during agentcore deploy.

Many enterprise and partner AWS accounts enforce an organization-managed permissions boundary on all IAM principals. A common form of this guardrail is an explicit Deny on iam:CreateRole unless the new role attaches a specific policy as its own permissions boundary.

In such accounts, agentcore deploy fails at role creation. Example error when deploying a project with a single harness:

User: arn:aws:sts::<acct>:assumed-role/cdk-hnb659fds-cfn-exec-role-<acct>-<region>/AWSCloudFormation
is not authorized to perform: iam:CreateRole
on resource: arn:aws:iam::<acct>:role/<project>_<harness>
with an explicit deny in a permissions boundary: arn:aws:iam::<acct>:policy/<OrgBoundaryPolicy>
(Status Code: 403; HandlerErrorCode: UnauthorizedTaggingOperation)

The generated roles have no PermissionsBoundary property, so CloudFormation's iam:CreateRole call is denied and the whole stack rolls back. There is currently no supported configuration (CLI flag, aws-targets.json field, env var, or agentcore.json field) to inject a boundary.

I confirmed the root cause is the "must attach boundary on create" rule (creating a probe role with the boundary succeeds; without it 403s). I patched the generated bin/cdk.ts to apply an App-wide boundary via the CDK IAM aspect:

import * as iam from 'aws-cdk-lib/aws-iam';

iam.PermissionsBoundary.of(app).apply(
  iam.ManagedPolicy.fromManagedPolicyArn(
    app,
    'OrgPermissionsBoundary',
    'arn:aws:iam::<acct>:policy/<OrgBoundaryPolicy>'
  )
);

This makes the deploy succeed (stack reaches CREATE_COMPLETE), but it is not viable long-term because agentcore deploy re-materializes the cdk/ directory from CLI templates and overwrites the patch. I must deploy via raw cdk deploy instead, which leaves AgentCore's local state (.cli/deployed-state.json) out of sync.

Acceptance Criteria
  • When configured, every generated IAM role (harness/runtime execution roles, and any L3-created roles) is synthesized with the specified PermissionsBoundary.
  • Works through the standard agentcore deploy flow with no manual edits to generated cdk/ files.
  • Survives cdk/ regeneration/materialization.
  • No boundary is applied when the setting is absent (backward compatible).
Additional Context
  • @aws/agentcore CLI: 0.28.1
  • CDK (bundled): 2.1126.0
  • Node.js: 22.x
  • Deploy target: single-harness project, PYTHON runtime, region <region>
Ngôn ngữ chính
TypeScript
Star
291
Fork
96
Merge trung bình
20 giờ 50 phút
Pull request đã merge (30 ngày)
214

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của aws/agentcore-cli

Tất cả issue của aws/agentcore-cli

Issue tương tự

Thêm issue về TypeScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.