Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

feat(gateway-target): allow GATEWAY_IAM_ROLE outbound auth on mcpServer / openApiSchema targets (iamCredentialProvider)

未关闭
#2,245 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
50/100
Issue 类型
功能
描述清晰度
描述清楚
活跃度
活跃
技术栈
aws, typescript

调研方向

从 src/schema/schemas/mcp.ts 开始,使用 agentcore validate 重现问题,然后检查 flag validator 和 L3 buildCredentialConfig()。同时检查 --help 的 Auth 表和 TUI 选项列表。当 mcpServer 和 openApiSchema 正确接受并输出 IAM auth、在不适用的地方拒绝它,并且 credential requirement 不再适用于 IAM 或 JWT passthrough 时,即表示完成。

由索引模型根据 Issue 内容生成。

描述

Description

Gateway supports IAM outbound auth to MCP server and OpenAPI targets — the gateway signs with SigV4 via its service role. Per Set up outbound authorization for your gateway, these two target types take a GATEWAY_IAM_ROLE credential provider plus an iamCredentialProvider block (service required — bedrock-agentcore for MCP servers on AgentCore Runtime; region optional). Lambda / API Gateway / Smithy take the bare credentialProviderType with no iamCredentialProvider.

TARGET_TYPE_AUTH_CONFIG in src/schema/schemas/mcp.ts doesn't allow it: mcpServer is OAUTH | NONE, openApiSchema is OAUTH | API_KEY. Only passthrough gets GATEWAY_IAM_ROLE. So there's no way to put an IAM-auth MCP server hosted on AgentCore Runtime behind a gateway — it forces an OAuth provider in front of a runtime that already authenticates with SigV4.

It's a schema block, not just a missing flag — hand-editing agentcore.json fails too:

$ agentcore validate
  - agentCoreGateways[0].targets[0].outboundAuth:
    mcpServer targets do not support GATEWAY_IAM_ROLE outbound auth

Separately, the flag surface reports the wrong reason — the guard exempts only NONE, so GATEWAY_IAM_ROLE and JWT_PASSTHROUGH fall through into the OAuth credential requirement:

$ agentcore add gateway-target --type mcp-server --outbound-auth gateway-iam-role \
    --signing-service bedrock-agentcore ...
--credential-name or inline OAuth fields (--oauth-client-id, --oauth-client-secret,
--oauth-discovery-url) required when outbound auth type is gateway-iam-role
Acceptance Criteria
  • TARGET_TYPE_AUTH_CONFIG allows GATEWAY_IAM_ROLE on mcpServer and openApiSchema, with service required there and rejected for Lambda / API Gateway / Smithy
  • --signing-service / --signing-region accepted for these types, not just passthrough
  • flag validator exempts GATEWAY_IAM_ROLE / JWT_PASSTHROUGH from the credential requirement
  • L3 buildCredentialConfig() emits the iamCredentialProvider block for these types (today it returns undefined outside the passthrough branch — the #1005 failure shape)
  • --help Auth table and TUI option list updated
Additional Context
  • @aws/agentcore 0.28.1, @aws/agentcore-cdk 0.1.0-alpha.50, aws-cdk-lib 2.261.0.
  • Reproduced at config / validate level only; I haven't run a live CreateGatewayTarget with this shape.
  • Related: #1359 (same map, API_KEY). Note #1914/#1915 recorded "mcpServer supports only OAuth or none" — accurate to the validator, but the doc above allows IAM.
主要语言
TypeScript
星标
298
派生
99
平均合并
18 小时 34 分钟
30 天内合并 PR
202

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

aws/agentcore-cli 的其他 Issue

查看 aws/agentcore-cli 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。