') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); feat(capacity-provider): capacity provider support by xxuam · Pull Request #2068 · aws/agentcore-cli · GitHub
Skip to content

feat(capacity-provider): capacity provider support - #2068

Open
xxuam wants to merge 3 commits into
mainfrom
feat/capacity-provider-devex
Open

feat(capacity-provider): capacity provider support#2068
xxuam wants to merge 3 commits into
mainfrom
feat/capacity-provider-devex

Conversation

@xxuam

Copy link
Copy Markdown
Contributor

Description

Completes the AgentCore Capacity Provider feature end to end and brings its DevEx to parity with the rest of the CLI.

This PR carries two commits — the revert-of-revert that restores Journey 1, plus a new commit adding Journeys 2–4 and the DevEx polish — so it delivers the full feature:

  • J1 — create/remove a capacity provider as a first-class project resource (add capacity-provider / remove capacity-provider), persisted to agentcore.json and synthesized to an
    AWS::BedrockAgentCore::CapacityProvider CloudFormation resource (VPC, launch parameters, named EBS volumes, lifecycle, auto-created operator role), with deploy/status integration. (Restored here via
    revert-of-revert; originally feat(capacity-provider): add capacity-provider resource (Journey 1) #2030, reverted in revert: remove capacity-provider Journey 1 #2045 for release timing.)
  • J2 — attach a runtime to a capacity provider by in-project name or external ARN (add agent --capacity-provider <name-or-arn>), rendered as capacityProviderConfiguration on the runtime (network config
    is mutually exclusive and omitted).
  • J3 — mount capacity-provider volumes into a runtime (--cp-volume-name / --cp-volume-mount-path), routed through the existing filesystem-mount framework.
  • J4 — capacity-provider delete-session data-plane command to deprovision a live CP session (destructive confirm, --yes, name/id/ARN resolution).
  • TUI parity: full interactive add capacity-provider wizard (named volumes, EBS encryption + KMS key, instance profile, lifecycle timeouts); capacity-provider attach is now available in the agent
    create/template flow (and agentcore create) as well as the BYO flow.
  • DevEx polish: paired --volume-name / --volume-size flags (replacing --volume name:sizeGiB, for consistency with the other paired flags); a referential-integrity guard that blocks removing a capacity
    provider still referenced by a runtime; and removal of the [preview] label from the CP add/remove menus.
  • Bumps @aws-sdk/client-bedrock-agentcore to a version that ships DeleteCapacityProviderSessionCommand.

Related Issue

Closes #

Documentation PR

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Details:

  • Unit: full suite green (6219 tests). Added coverage for the paired volume flags, the advanced parity flags (instance-profile / encryption+KMS / lifecycle), the buildCreateAgentConfig mapping, the
    useGenerateWizard CP flow, the wizard buildSteps sequencing, and a duplicate-menu guard.
  • Integ: capacity-provider add/remove and add-agent-attach integ tests pass against the real CLI binary.
  • Typecheck + lint: clean (no new warnings).
  • Interactive TUI (harness): drove the add capacity-provider wizard (forward + back-navigation, including encrypt→KMS→back→No), the agent create/template CP attach, agentcore create with a CP-by-ARN, and
    the BYO CP flow.
  • Live end-to-end (us-west-2): deployed a template agent on an arm64 capacity provider with a mounted volume → CP + runtime READY, invoke returned a response, delete-session deprovisioned the session,
    and teardown removed the stack cleanly.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

⚠️Dependent change / merge order: this PR consumes capacity-provider support from @aws/agentcore-cdk (the L3 constructs), which is a separate PR (feat/capacity-provider-attach in
agentcore-l3-cdk-constructs). That L3 PR must merge and publish a new alpha, and the @aws/agentcore-cdk pin here must be bumped to it, before capacity-provider deploys work off the pinned version. (Verified
locally against a bundled build of the L3 branch.)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@xxuam
xxuam requested a review from a teamAugust 22, 2026 03:09
@github-actionsgithub-actionsBot added size/xl PR size: XL agentcore-harness-reviewing AgentCore Harness review in progress labels Aug 22, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 22, 2026
@github-actionsgithub-actionsBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 22, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@github-actions

github-actionsBot commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines41.09%15754 / 38332
🔵Statements40.35%16802 / 41631
🔵Functions35.2%2713 / 7706
🔵Branches34.26%10537 / 30750
Generated in workflow #4430 for commit 8d4a59f by the Vitest Coverage Report Action

@xxuamxxuam changed the title Feat/capacity provider devexfeat(capacity-provider): capacity provider supportAug 22, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 22, 2026
@xxuam
xxuamforce-pushed the feat/capacity-provider-devex branch from 9c6e3cc to f311e1cCompareAugust 24, 2026 20:33
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 24, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 24, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 24, 2026
@xxuam
xxuamforce-pushed the feat/capacity-provider-devex branch from f311e1c to 9f363aaCompareAugust 24, 2026 22:35
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 24, 2026
…d DevEx polish
- J2/J3: attach a runtime to a capacity provider by name or ARN, and mount CP volumes
- J4: `capacity-provider delete-session` data-plane command
- TUI: full add-capacity-provider wizard (volumes, encryption/KMS, instance profile,
lifecycle timeouts); capacity-provider attach in the agent create/template and BYO flows
- paired `--volume-name`/`--volume-size` flags (replacing `--volume name:sizeGiB`)
- referential-integrity guard: block removing a capacity provider still referenced by a runtime
- drop `[preview]` from the capacity-provider add/remove menus
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xxuam
xxuamforce-pushed the feat/capacity-provider-devex branch from 40553ef to 68cba4dCompareAugust 25, 2026 00:26
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 25, 2026
@agentcore-devx-automationagentcore-devx-automationBot added the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 25, 2026
Comment threadsrc/cli/tui/screens/agent/useAddAgent.ts
Comment threadsrc/cli/commands/capacity-provider/action.ts Outdated
Comment threadsrc/cli/primitives/AgentPrimitive.tsx
Comment threadsrc/cli/commands/create/command.tsx
Comment threadsrc/cli/tui/screens/generate/useGenerateWizard.ts
Comment threadsrc/cli/tui/screens/capacity-provider/AddCapacityProviderScreen.tsx Outdated
Comment threadsrc/schema/schemas/primitives/capacity-provider.ts Outdated
- BYO mapper (mapByoConfigToAgent) omits networkMode when a CP is attached —
the AgentEnvSpec schema rejects a capacityProviderConfiguration combined with
any networkMode, so a BYO CP submission was failing to persist.
- delete-session by-name resolution collects all deployed-state matches and
disambiguates by region (resolve within --region; reject cross-region
ambiguity) instead of blindly taking the first target.
- forward capacityProviderConfiguration + volumes through the import path
(executeImportAgent params + AgentPrimitive/useAddAgent/create callers).
- create rejects the capacity-provider name form (a new project has no sibling
to resolve); only an external ARN can attach at create time.
- generate + BYO wizard advanced-settings routing matches the steps memo when
network and capacityProvider are both selected (CP wins; no skipped screen).
- preserve an explicit volumeEncrypted=false in the CP wizard so the primitive
emits Encrypted:false (service default is true).
- tighten CAPACITY_PROVIDER_ARN_PATTERN to {name}-{10 alnum} so malformed
external ARNs fail at validate time (kept in sync with @aws/agentcore-cdk).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All review comments are addressed on this head, including the mirrored ARN validation in aws/agentcore-l3-cdk-constructs#336. Focused validation passes. The red web-search E2E check is unrelated to this change and failed on an internal service response.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@xxuam@tejaskash