feat(gateway-target): allow GATEWAY_IAM_ROLE outbound auth on mcpServer / openApiSchema targets (iamCredentialProvider)
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 50/100
- Issue 类型
- 功能
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- aws, typescript
- 领域
- authentication, cli, tooling
调研方向
从 src/schema/schemas/mcp.ts 开始,使用 agentcore validate 重现问题,然后检查 flag validator 和 L3 buildCredentialConfig()。同时检查 --help 的 Auth 表和 TUI 选项列表。当 mcpServer 和 openApiSchema 正确接受并输出 IAM auth、在不适用的地方拒绝它,并且 credential requirement 不再适用于 IAM 或 JWT passthrough 时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
Description
Gateway supports IAM outbound auth to MCP server and OpenAPI targets — the gateway signs with SigV4 via its service role. Per Set up outbound authorization for your gateway, these two target types take a GATEWAY_IAM_ROLE credential provider plus an iamCredentialProvider block (service required — bedrock-agentcore for MCP servers on AgentCore Runtime; region optional). Lambda / API Gateway / Smithy take the bare credentialProviderType with no iamCredentialProvider.
TARGET_TYPE_AUTH_CONFIG in src/schema/schemas/mcp.ts doesn't allow it: mcpServer is OAUTH | NONE, openApiSchema is OAUTH | API_KEY. Only passthrough gets GATEWAY_IAM_ROLE. So there's no way to put an IAM-auth MCP server hosted on AgentCore Runtime behind a gateway — it forces an OAuth provider in front of a runtime that already authenticates with SigV4.
It's a schema block, not just a missing flag — hand-editing agentcore.json fails too:
$ agentcore validate
- agentCoreGateways[0].targets[0].outboundAuth:
mcpServer targets do not support GATEWAY_IAM_ROLE outbound auth
Separately, the flag surface reports the wrong reason — the guard exempts only NONE, so GATEWAY_IAM_ROLE and JWT_PASSTHROUGH fall through into the OAuth credential requirement:
$ agentcore add gateway-target --type mcp-server --outbound-auth gateway-iam-role \
--signing-service bedrock-agentcore ...
--credential-name or inline OAuth fields (--oauth-client-id, --oauth-client-secret,
--oauth-discovery-url) required when outbound auth type is gateway-iam-role
Acceptance Criteria
-
TARGET_TYPE_AUTH_CONFIGallowsGATEWAY_IAM_ROLEonmcpServerandopenApiSchema, withservicerequired there and rejected for Lambda / API Gateway / Smithy -
--signing-service/--signing-regionaccepted for these types, not justpassthrough - flag validator exempts
GATEWAY_IAM_ROLE/JWT_PASSTHROUGHfrom the credential requirement - L3
buildCredentialConfig()emits theiamCredentialProviderblock for these types (today it returnsundefinedoutside the passthrough branch — the #1005 failure shape) -
--helpAuth table and TUI option list updated
Additional Context
@aws/agentcore0.28.1,@aws/agentcore-cdk0.1.0-alpha.50,aws-cdk-lib2.261.0.- Reproduced at config /
validatelevel only; I haven't run a liveCreateGatewayTargetwith this shape. - Related: #1359 (same map,
API_KEY). Note #1914/#1915 recorded "mcpServer supports only OAuth or none" — accurate to the validator, but the doc above allows IAM.
- 主要语言
- TypeScript
- 星标
- 298
- 派生
- 99
- 平均合并
- 18 小时 34 分钟
- 30 天内合并 PR
- 202
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
aws/agentcore-cli 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 70/100
aws/agentcore-cli#2395 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 75/100
aws/agentcore-cli#2392 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
aws/agentcore-cli#2267 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
aws/agentcore-cli#2258 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
aws/agentcore-cli#2176 ·
维护者通常 1 天内回复
查看 aws/agentcore-cli 的全部 Issue
相似的 Issue
-
refactor
难度 2/5 半天 新手友好度 84/100
维护者通常 5 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
OHDSI/Data2Evidence#3450 ·
维护者通常 2 天内回复
-
e2e-failure ready-to-code
难度 2/5 1-3 小时 新手友好度 90/100
redhat-developer/rhdh-plugin-export-overlays#4011 · 1 条评论 ·
维护者通常 1 天内回复
-
automation missing-model model-sync provider:ofox
难度 2/5 1-3 小时 新手友好度 72/100
anomalyco/models.dev#8421 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
维护者通常 1 天内回复