fix: set iamRoleFallback to true for lambda gateway targets - #1086

Merged
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config
May 5, 2026
Merged

fix: set iamRoleFallback to true for lambda gateway targets#1086
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

Summary

  • Syncs TARGET_TYPE_AUTH_CONFIG with @aws/agentcore-cdk — sets iamRoleFallback: true for the lambda target type, matching lambdaFunctionArn.
  • Without this, the CLI's auth config would disagree with the CDK constructs on whether lambda targets use IAM role fallback.

Closes#1005

Companion CDK PR: https://github.com/aws/agentcore-l3-cdk-constructs/pull/197

Test plan

  • Existing tests pass — schema change only affects CDK synthesis behavior (handled by CDK PR)
  • Merge CDK PR first, then this one

@tejaskash
tejaskash requested a review from a teamMay 1, 2026 17:55
Keep TARGET_TYPE_AUTH_CONFIG in sync with @aws/agentcore-cdk — lambda
targets need GATEWAY_IAM_ROLE just like lambdaFunctionArn targets.
Related: #1005
@tejaskash
tejaskashforce-pushed the fix-lambda-cred-config branch from 107a4d2 to aa1a775CompareMay 1, 2026 18:00
@github-actionsgithub-actionsBot added size/xs PR size: XS agentcore-harness-reviewing AgentCore Harness review in progress and removed size/xs PR size: XS labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Thanks for the fix — the schema sync is correct and the lambda target type logically belongs in the iamRoleFallback: true group alongside apiGateway / lambdaFunctionArn.

One concern about the rollout, though: the actual user-facing fix (the one from issue #1005) lives in the CDK synthesizer — Gateway.ts currently passes credentialProviderConfigurations straight through from buildCredentialConfig(target) in the Lambda-compute branch (around line 537) without applying the authConfig.iamRoleFallback branch that's used for openApi/smithy (line 443) and apiGateway (line 323). The CLI schema change in this PR is a no-op on its own — iamRoleFallback is never read inside the CLI, only by the CDK at synth time.

src/assets/cdk/package.json pins "@aws/agentcore-cdk": "^0.1.0-alpha.19". If this PR merges and a new CLI version is published without bumping that pin to whatever version ships the companion CDK fix, users running agentcore create will still resolve the old CDK from npm and agentcore deploy will continue to fail with CredentialProviderConfigurations is required for Lambda targets.

A couple of options:

  1. Bump the @aws/agentcore-cdk version range in src/assets/cdk/package.json in this PR (or a stacked follow-up) to require the minimum version that contains the companion fix, and land them together.
  2. Merge this PR but block the next CLI release until the CDK version bump PR lands, with a note on the release checklist.

Option 1 is safer since it makes the coordination explicit in the repo rather than relying on release discipline.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.89%8936 / 20830
🔵Statements42.17%9485 / 22491
🔵Functions39.66%1537 / 3875
🔵Branches39.82%5769 / 14486
Generated in workflow #2308 for commit 10c1a6d by the Vitest Coverage Report Action

@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@tejaskash
tejaskash merged commit 639adf1 into mainMay 5, 2026
24 checks passed
@tejaskash
tejaskash deleted the fix-lambda-cred-config branch May 5, 2026 19:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xsPR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GatewayTarget creation fails for lambda (compute) targets

3 participants

@tejaskash@agentcore-cli-automation@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: set iamRoleFallback to true for lambda gateway targets - #1086

Merged
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config
May 5, 2026
Merged

fix: set iamRoleFallback to true for lambda gateway targets#1086
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

Summary

  • Syncs TARGET_TYPE_AUTH_CONFIG with @aws/agentcore-cdk — sets iamRoleFallback: true for the lambda target type, matching lambdaFunctionArn.
  • Without this, the CLI's auth config would disagree with the CDK constructs on whether lambda targets use IAM role fallback.

Closes#1005

Companion CDK PR: https://github.com/aws/agentcore-l3-cdk-constructs/pull/197

Test plan

  • Existing tests pass — schema change only affects CDK synthesis behavior (handled by CDK PR)
  • Merge CDK PR first, then this one

@tejaskash
tejaskash requested a review from a teamMay 1, 2026 17:55
Keep TARGET_TYPE_AUTH_CONFIG in sync with @aws/agentcore-cdk — lambda
targets need GATEWAY_IAM_ROLE just like lambdaFunctionArn targets.
Related: #1005
@tejaskash
tejaskashforce-pushed the fix-lambda-cred-config branch from 107a4d2 to aa1a775CompareMay 1, 2026 18:00
@github-actionsgithub-actionsBot added size/xs PR size: XS agentcore-harness-reviewing AgentCore Harness review in progress and removed size/xs PR size: XS labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Thanks for the fix — the schema sync is correct and the lambda target type logically belongs in the iamRoleFallback: true group alongside apiGateway / lambdaFunctionArn.

One concern about the rollout, though: the actual user-facing fix (the one from issue #1005) lives in the CDK synthesizer — Gateway.ts currently passes credentialProviderConfigurations straight through from buildCredentialConfig(target) in the Lambda-compute branch (around line 537) without applying the authConfig.iamRoleFallback branch that's used for openApi/smithy (line 443) and apiGateway (line 323). The CLI schema change in this PR is a no-op on its own — iamRoleFallback is never read inside the CLI, only by the CDK at synth time.

src/assets/cdk/package.json pins "@aws/agentcore-cdk": "^0.1.0-alpha.19". If this PR merges and a new CLI version is published without bumping that pin to whatever version ships the companion CDK fix, users running agentcore create will still resolve the old CDK from npm and agentcore deploy will continue to fail with CredentialProviderConfigurations is required for Lambda targets.

A couple of options:

  1. Bump the @aws/agentcore-cdk version range in src/assets/cdk/package.json in this PR (or a stacked follow-up) to require the minimum version that contains the companion fix, and land them together.
  2. Merge this PR but block the next CLI release until the CDK version bump PR lands, with a note on the release checklist.

Option 1 is safer since it makes the coordination explicit in the repo rather than relying on release discipline.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.89%8936 / 20830
🔵Statements42.17%9485 / 22491
🔵Functions39.66%1537 / 3875
🔵Branches39.82%5769 / 14486
Generated in workflow #2308 for commit 10c1a6d by the Vitest Coverage Report Action

@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@tejaskash
tejaskash merged commit 639adf1 into mainMay 5, 2026
24 checks passed
@tejaskash
tejaskash deleted the fix-lambda-cred-config branch May 5, 2026 19:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xsPR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GatewayTarget creation fails for lambda (compute) targets

3 participants

@tejaskash@agentcore-cli-automation@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: set iamRoleFallback to true for lambda gateway targets - #1086

Merged
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config
May 5, 2026
Merged

fix: set iamRoleFallback to true for lambda gateway targets#1086
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

Summary

  • Syncs TARGET_TYPE_AUTH_CONFIG with @aws/agentcore-cdk — sets iamRoleFallback: true for the lambda target type, matching lambdaFunctionArn.
  • Without this, the CLI's auth config would disagree with the CDK constructs on whether lambda targets use IAM role fallback.

Closes#1005

Companion CDK PR: https://github.com/aws/agentcore-l3-cdk-constructs/pull/197

Test plan

  • Existing tests pass — schema change only affects CDK synthesis behavior (handled by CDK PR)
  • Merge CDK PR first, then this one

@tejaskash
tejaskash requested a review from a teamMay 1, 2026 17:55
Keep TARGET_TYPE_AUTH_CONFIG in sync with @aws/agentcore-cdk — lambda
targets need GATEWAY_IAM_ROLE just like lambdaFunctionArn targets.
Related: #1005
@tejaskash
tejaskashforce-pushed the fix-lambda-cred-config branch from 107a4d2 to aa1a775CompareMay 1, 2026 18:00
@github-actionsgithub-actionsBot added size/xs PR size: XS agentcore-harness-reviewing AgentCore Harness review in progress and removed size/xs PR size: XS labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Thanks for the fix — the schema sync is correct and the lambda target type logically belongs in the iamRoleFallback: true group alongside apiGateway / lambdaFunctionArn.

One concern about the rollout, though: the actual user-facing fix (the one from issue #1005) lives in the CDK synthesizer — Gateway.ts currently passes credentialProviderConfigurations straight through from buildCredentialConfig(target) in the Lambda-compute branch (around line 537) without applying the authConfig.iamRoleFallback branch that's used for openApi/smithy (line 443) and apiGateway (line 323). The CLI schema change in this PR is a no-op on its own — iamRoleFallback is never read inside the CLI, only by the CDK at synth time.

src/assets/cdk/package.json pins "@aws/agentcore-cdk": "^0.1.0-alpha.19". If this PR merges and a new CLI version is published without bumping that pin to whatever version ships the companion CDK fix, users running agentcore create will still resolve the old CDK from npm and agentcore deploy will continue to fail with CredentialProviderConfigurations is required for Lambda targets.

A couple of options:

  1. Bump the @aws/agentcore-cdk version range in src/assets/cdk/package.json in this PR (or a stacked follow-up) to require the minimum version that contains the companion fix, and land them together.
  2. Merge this PR but block the next CLI release until the CDK version bump PR lands, with a note on the release checklist.

Option 1 is safer since it makes the coordination explicit in the repo rather than relying on release discipline.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.89%8936 / 20830
🔵Statements42.17%9485 / 22491
🔵Functions39.66%1537 / 3875
🔵Branches39.82%5769 / 14486
Generated in workflow #2308 for commit 10c1a6d by the Vitest Coverage Report Action

@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@tejaskash
tejaskash merged commit 639adf1 into mainMay 5, 2026
24 checks passed
@tejaskash
tejaskash deleted the fix-lambda-cred-config branch May 5, 2026 19:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xsPR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GatewayTarget creation fails for lambda (compute) targets

3 participants

@tejaskash@agentcore-cli-automation@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: set iamRoleFallback to true for lambda gateway targets - #1086

Merged
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config
May 5, 2026
Merged

fix: set iamRoleFallback to true for lambda gateway targets#1086
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

Summary

  • Syncs TARGET_TYPE_AUTH_CONFIG with @aws/agentcore-cdk — sets iamRoleFallback: true for the lambda target type, matching lambdaFunctionArn.
  • Without this, the CLI's auth config would disagree with the CDK constructs on whether lambda targets use IAM role fallback.

Closes#1005

Companion CDK PR: https://github.com/aws/agentcore-l3-cdk-constructs/pull/197

Test plan

  • Existing tests pass — schema change only affects CDK synthesis behavior (handled by CDK PR)
  • Merge CDK PR first, then this one

@tejaskash
tejaskash requested a review from a teamMay 1, 2026 17:55
Keep TARGET_TYPE_AUTH_CONFIG in sync with @aws/agentcore-cdk — lambda
targets need GATEWAY_IAM_ROLE just like lambdaFunctionArn targets.
Related: #1005
@tejaskash
tejaskashforce-pushed the fix-lambda-cred-config branch from 107a4d2 to aa1a775CompareMay 1, 2026 18:00
@github-actionsgithub-actionsBot added size/xs PR size: XS agentcore-harness-reviewing AgentCore Harness review in progress and removed size/xs PR size: XS labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Thanks for the fix — the schema sync is correct and the lambda target type logically belongs in the iamRoleFallback: true group alongside apiGateway / lambdaFunctionArn.

One concern about the rollout, though: the actual user-facing fix (the one from issue #1005) lives in the CDK synthesizer — Gateway.ts currently passes credentialProviderConfigurations straight through from buildCredentialConfig(target) in the Lambda-compute branch (around line 537) without applying the authConfig.iamRoleFallback branch that's used for openApi/smithy (line 443) and apiGateway (line 323). The CLI schema change in this PR is a no-op on its own — iamRoleFallback is never read inside the CLI, only by the CDK at synth time.

src/assets/cdk/package.json pins "@aws/agentcore-cdk": "^0.1.0-alpha.19". If this PR merges and a new CLI version is published without bumping that pin to whatever version ships the companion CDK fix, users running agentcore create will still resolve the old CDK from npm and agentcore deploy will continue to fail with CredentialProviderConfigurations is required for Lambda targets.

A couple of options:

  1. Bump the @aws/agentcore-cdk version range in src/assets/cdk/package.json in this PR (or a stacked follow-up) to require the minimum version that contains the companion fix, and land them together.
  2. Merge this PR but block the next CLI release until the CDK version bump PR lands, with a note on the release checklist.

Option 1 is safer since it makes the coordination explicit in the repo rather than relying on release discipline.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.89%8936 / 20830
🔵Statements42.17%9485 / 22491
🔵Functions39.66%1537 / 3875
🔵Branches39.82%5769 / 14486
Generated in workflow #2308 for commit 10c1a6d by the Vitest Coverage Report Action

@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@tejaskash
tejaskash merged commit 639adf1 into mainMay 5, 2026
24 checks passed
@tejaskash
tejaskash deleted the fix-lambda-cred-config branch May 5, 2026 19:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xsPR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GatewayTarget creation fails for lambda (compute) targets

3 participants

@tejaskash@agentcore-cli-automation@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: set iamRoleFallback to true for lambda gateway targets - #1086

Merged
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config
May 5, 2026
Merged

fix: set iamRoleFallback to true for lambda gateway targets#1086
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

Summary

  • Syncs TARGET_TYPE_AUTH_CONFIG with @aws/agentcore-cdk — sets iamRoleFallback: true for the lambda target type, matching lambdaFunctionArn.
  • Without this, the CLI's auth config would disagree with the CDK constructs on whether lambda targets use IAM role fallback.

Closes#1005

Companion CDK PR: https://github.com/aws/agentcore-l3-cdk-constructs/pull/197

Test plan

  • Existing tests pass — schema change only affects CDK synthesis behavior (handled by CDK PR)
  • Merge CDK PR first, then this one

@tejaskash
tejaskash requested a review from a teamMay 1, 2026 17:55
Keep TARGET_TYPE_AUTH_CONFIG in sync with @aws/agentcore-cdk — lambda
targets need GATEWAY_IAM_ROLE just like lambdaFunctionArn targets.
Related: #1005
@tejaskash
tejaskashforce-pushed the fix-lambda-cred-config branch from 107a4d2 to aa1a775CompareMay 1, 2026 18:00
@github-actionsgithub-actionsBot added size/xs PR size: XS agentcore-harness-reviewing AgentCore Harness review in progress and removed size/xs PR size: XS labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Thanks for the fix — the schema sync is correct and the lambda target type logically belongs in the iamRoleFallback: true group alongside apiGateway / lambdaFunctionArn.

One concern about the rollout, though: the actual user-facing fix (the one from issue #1005) lives in the CDK synthesizer — Gateway.ts currently passes credentialProviderConfigurations straight through from buildCredentialConfig(target) in the Lambda-compute branch (around line 537) without applying the authConfig.iamRoleFallback branch that's used for openApi/smithy (line 443) and apiGateway (line 323). The CLI schema change in this PR is a no-op on its own — iamRoleFallback is never read inside the CLI, only by the CDK at synth time.

src/assets/cdk/package.json pins "@aws/agentcore-cdk": "^0.1.0-alpha.19". If this PR merges and a new CLI version is published without bumping that pin to whatever version ships the companion CDK fix, users running agentcore create will still resolve the old CDK from npm and agentcore deploy will continue to fail with CredentialProviderConfigurations is required for Lambda targets.

A couple of options:

  1. Bump the @aws/agentcore-cdk version range in src/assets/cdk/package.json in this PR (or a stacked follow-up) to require the minimum version that contains the companion fix, and land them together.
  2. Merge this PR but block the next CLI release until the CDK version bump PR lands, with a note on the release checklist.

Option 1 is safer since it makes the coordination explicit in the repo rather than relying on release discipline.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.89%8936 / 20830
🔵Statements42.17%9485 / 22491
🔵Functions39.66%1537 / 3875
🔵Branches39.82%5769 / 14486
Generated in workflow #2308 for commit 10c1a6d by the Vitest Coverage Report Action

@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@tejaskash
tejaskash merged commit 639adf1 into mainMay 5, 2026
24 checks passed
@tejaskash
tejaskash deleted the fix-lambda-cred-config branch May 5, 2026 19:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xsPR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GatewayTarget creation fails for lambda (compute) targets

3 participants

@tejaskash@agentcore-cli-automation@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: set iamRoleFallback to true for lambda gateway targets - #1086

Merged
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config
May 5, 2026
Merged

fix: set iamRoleFallback to true for lambda gateway targets#1086
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

Summary

  • Syncs TARGET_TYPE_AUTH_CONFIG with @aws/agentcore-cdk — sets iamRoleFallback: true for the lambda target type, matching lambdaFunctionArn.
  • Without this, the CLI's auth config would disagree with the CDK constructs on whether lambda targets use IAM role fallback.

Closes#1005

Companion CDK PR: https://github.com/aws/agentcore-l3-cdk-constructs/pull/197

Test plan

  • Existing tests pass — schema change only affects CDK synthesis behavior (handled by CDK PR)
  • Merge CDK PR first, then this one

@tejaskash
tejaskash requested a review from a teamMay 1, 2026 17:55
Keep TARGET_TYPE_AUTH_CONFIG in sync with @aws/agentcore-cdk — lambda
targets need GATEWAY_IAM_ROLE just like lambdaFunctionArn targets.
Related: #1005
@tejaskash
tejaskashforce-pushed the fix-lambda-cred-config branch from 107a4d2 to aa1a775CompareMay 1, 2026 18:00
@github-actionsgithub-actionsBot added size/xs PR size: XS agentcore-harness-reviewing AgentCore Harness review in progress and removed size/xs PR size: XS labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Thanks for the fix — the schema sync is correct and the lambda target type logically belongs in the iamRoleFallback: true group alongside apiGateway / lambdaFunctionArn.

One concern about the rollout, though: the actual user-facing fix (the one from issue #1005) lives in the CDK synthesizer — Gateway.ts currently passes credentialProviderConfigurations straight through from buildCredentialConfig(target) in the Lambda-compute branch (around line 537) without applying the authConfig.iamRoleFallback branch that's used for openApi/smithy (line 443) and apiGateway (line 323). The CLI schema change in this PR is a no-op on its own — iamRoleFallback is never read inside the CLI, only by the CDK at synth time.

src/assets/cdk/package.json pins "@aws/agentcore-cdk": "^0.1.0-alpha.19". If this PR merges and a new CLI version is published without bumping that pin to whatever version ships the companion CDK fix, users running agentcore create will still resolve the old CDK from npm and agentcore deploy will continue to fail with CredentialProviderConfigurations is required for Lambda targets.

A couple of options:

  1. Bump the @aws/agentcore-cdk version range in src/assets/cdk/package.json in this PR (or a stacked follow-up) to require the minimum version that contains the companion fix, and land them together.
  2. Merge this PR but block the next CLI release until the CDK version bump PR lands, with a note on the release checklist.

Option 1 is safer since it makes the coordination explicit in the repo rather than relying on release discipline.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.89%8936 / 20830
🔵Statements42.17%9485 / 22491
🔵Functions39.66%1537 / 3875
🔵Branches39.82%5769 / 14486
Generated in workflow #2308 for commit 10c1a6d by the Vitest Coverage Report Action

@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@tejaskash
tejaskash merged commit 639adf1 into mainMay 5, 2026
24 checks passed
@tejaskash
tejaskash deleted the fix-lambda-cred-config branch May 5, 2026 19:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xsPR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GatewayTarget creation fails for lambda (compute) targets

3 participants

@tejaskash@agentcore-cli-automation@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: set iamRoleFallback to true for lambda gateway targets - #1086

Merged
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config
May 5, 2026
Merged

fix: set iamRoleFallback to true for lambda gateway targets#1086
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

Summary

  • Syncs TARGET_TYPE_AUTH_CONFIG with @aws/agentcore-cdk — sets iamRoleFallback: true for the lambda target type, matching lambdaFunctionArn.
  • Without this, the CLI's auth config would disagree with the CDK constructs on whether lambda targets use IAM role fallback.

Closes#1005

Companion CDK PR: https://github.com/aws/agentcore-l3-cdk-constructs/pull/197

Test plan

  • Existing tests pass — schema change only affects CDK synthesis behavior (handled by CDK PR)
  • Merge CDK PR first, then this one

@tejaskash
tejaskash requested a review from a teamMay 1, 2026 17:55
Keep TARGET_TYPE_AUTH_CONFIG in sync with @aws/agentcore-cdk — lambda
targets need GATEWAY_IAM_ROLE just like lambdaFunctionArn targets.
Related: #1005
@tejaskash
tejaskashforce-pushed the fix-lambda-cred-config branch from 107a4d2 to aa1a775CompareMay 1, 2026 18:00
@github-actionsgithub-actionsBot added size/xs PR size: XS agentcore-harness-reviewing AgentCore Harness review in progress and removed size/xs PR size: XS labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Thanks for the fix — the schema sync is correct and the lambda target type logically belongs in the iamRoleFallback: true group alongside apiGateway / lambdaFunctionArn.

One concern about the rollout, though: the actual user-facing fix (the one from issue #1005) lives in the CDK synthesizer — Gateway.ts currently passes credentialProviderConfigurations straight through from buildCredentialConfig(target) in the Lambda-compute branch (around line 537) without applying the authConfig.iamRoleFallback branch that's used for openApi/smithy (line 443) and apiGateway (line 323). The CLI schema change in this PR is a no-op on its own — iamRoleFallback is never read inside the CLI, only by the CDK at synth time.

src/assets/cdk/package.json pins "@aws/agentcore-cdk": "^0.1.0-alpha.19". If this PR merges and a new CLI version is published without bumping that pin to whatever version ships the companion CDK fix, users running agentcore create will still resolve the old CDK from npm and agentcore deploy will continue to fail with CredentialProviderConfigurations is required for Lambda targets.

A couple of options:

  1. Bump the @aws/agentcore-cdk version range in src/assets/cdk/package.json in this PR (or a stacked follow-up) to require the minimum version that contains the companion fix, and land them together.
  2. Merge this PR but block the next CLI release until the CDK version bump PR lands, with a note on the release checklist.

Option 1 is safer since it makes the coordination explicit in the repo rather than relying on release discipline.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.89%8936 / 20830
🔵Statements42.17%9485 / 22491
🔵Functions39.66%1537 / 3875
🔵Branches39.82%5769 / 14486
Generated in workflow #2308 for commit 10c1a6d by the Vitest Coverage Report Action

@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@tejaskash
tejaskash merged commit 639adf1 into mainMay 5, 2026
24 checks passed
@tejaskash
tejaskash deleted the fix-lambda-cred-config branch May 5, 2026 19:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xsPR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GatewayTarget creation fails for lambda (compute) targets

3 participants

@tejaskash@agentcore-cli-automation@jesseturner21
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: set iamRoleFallback to true for lambda gateway targets - #1086

Merged
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config
May 5, 2026
Merged

fix: set iamRoleFallback to true for lambda gateway targets#1086
tejaskash merged 3 commits into
mainfrom
fix-lambda-cred-config

Conversation

@tejaskash

Copy link
Copy Markdown
Contributor

Summary

  • Syncs TARGET_TYPE_AUTH_CONFIG with @aws/agentcore-cdk — sets iamRoleFallback: true for the lambda target type, matching lambdaFunctionArn.
  • Without this, the CLI's auth config would disagree with the CDK constructs on whether lambda targets use IAM role fallback.

Closes#1005

Companion CDK PR: https://github.com/aws/agentcore-l3-cdk-constructs/pull/197

Test plan

  • Existing tests pass — schema change only affects CDK synthesis behavior (handled by CDK PR)
  • Merge CDK PR first, then this one

@tejaskash
tejaskash requested a review from a teamMay 1, 2026 17:55
Keep TARGET_TYPE_AUTH_CONFIG in sync with @aws/agentcore-cdk — lambda
targets need GATEWAY_IAM_ROLE just like lambdaFunctionArn targets.
Related: #1005
@tejaskash
tejaskashforce-pushed the fix-lambda-cred-config branch from 107a4d2 to aa1a775CompareMay 1, 2026 18:00
@github-actionsgithub-actionsBot added size/xs PR size: XS agentcore-harness-reviewing AgentCore Harness review in progress and removed size/xs PR size: XS labels May 1, 2026
@agentcore-cli-automation

Copy link
Copy Markdown

Thanks for the fix — the schema sync is correct and the lambda target type logically belongs in the iamRoleFallback: true group alongside apiGateway / lambdaFunctionArn.

One concern about the rollout, though: the actual user-facing fix (the one from issue #1005) lives in the CDK synthesizer — Gateway.ts currently passes credentialProviderConfigurations straight through from buildCredentialConfig(target) in the Lambda-compute branch (around line 537) without applying the authConfig.iamRoleFallback branch that's used for openApi/smithy (line 443) and apiGateway (line 323). The CLI schema change in this PR is a no-op on its own — iamRoleFallback is never read inside the CLI, only by the CDK at synth time.

src/assets/cdk/package.json pins "@aws/agentcore-cdk": "^0.1.0-alpha.19". If this PR merges and a new CLI version is published without bumping that pin to whatever version ships the companion CDK fix, users running agentcore create will still resolve the old CDK from npm and agentcore deploy will continue to fail with CredentialProviderConfigurations is required for Lambda targets.

A couple of options:

  1. Bump the @aws/agentcore-cdk version range in src/assets/cdk/package.json in this PR (or a stacked follow-up) to require the minimum version that contains the companion fix, and land them together.
  2. Merge this PR but block the next CLI release until the CDK version bump PR lands, with a note on the release checklist.

Option 1 is safer since it makes the coordination explicit in the repo rather than relying on release discipline.

@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label May 1, 2026
@github-actions

github-actionsBot commented May 1, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines42.89%8936 / 20830
🔵Statements42.17%9485 / 22491
🔵Functions39.66%1537 / 3875
🔵Branches39.82%5769 / 14486
Generated in workflow #2308 for commit 10c1a6d by the Vitest Coverage Report Action

@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@github-actionsgithub-actionsBot added size/xs PR size: XS and removed size/xs PR size: XS labels May 1, 2026
@tejaskash
tejaskash merged commit 639adf1 into mainMay 5, 2026
24 checks passed
@tejaskash
tejaskash deleted the fix-lambda-cred-config branch May 5, 2026 19:44
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xsPR size: XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

GatewayTarget creation fails for lambda (compute) targets

3 participants

@tejaskash@agentcore-cli-automation@jesseturner21