Skip to content

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) - #2133

Merged
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean
Aug 27, 2026
Merged

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)#2133
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean

Conversation

@xxuam

Copy link
Copy Markdown
Contributor

Description

Completes the AgentCore Capacity Provider feature end to end and brings its DevEx to parity with the rest of the CLI.

This PR carries two commits — the revert-of-revert that restores Journey 1, plus a new commit adding Journeys 2–4 and the DevEx polish — so it delivers the full feature:

  • J1 — create/remove a capacity provider as a first-class project resource (add capacity-provider / remove capacity-provider), persisted to agentcore.json and synthesized to an
    AWS::BedrockAgentCore::CapacityProvider CloudFormation resource (VPC, launch parameters, named EBS volumes, lifecycle, auto-created operator role), with deploy/status integration. (Restored here via
    revert-of-revert; originally feat(capacity-provider): add capacity-provider resource (Journey 1) #2030, reverted in revert: remove capacity-provider Journey 1 #2045 for release timing.)
  • J2 — attach a runtime to a capacity provider by in-project name or external ARN (add agent --capacity-provider <name-or-arn>), rendered as capacityProviderConfiguration on the runtime (network config
    is mutually exclusive and omitted).
  • J3 — mount capacity-provider volumes into a runtime (--cp-volume-name / --cp-volume-mount-path), routed through the existing filesystem-mount framework.
  • J4 — capacity-provider delete-session data-plane command to deprovision a live CP session (destructive confirm, --yes, name/id/ARN resolution).
  • TUI parity: full interactive add capacity-provider wizard (named volumes, EBS encryption + KMS key, instance profile, lifecycle timeouts); capacity-provider attach is now available in the agent
    create/template flow (and agentcore create) as well as the BYO flow.
  • DevEx polish: paired --volume-name / --volume-size flags (replacing --volume name:sizeGiB, for consistency with the other paired flags); a referential-integrity guard that blocks removing a capacity
    provider still referenced by a runtime; and removal of the [preview] label from the CP add/remove menus.
  • Bumps @aws-sdk/client-bedrock-agentcore to a version that ships DeleteCapacityProviderSessionCommand.

Related Issue

Closes #

Documentation PR

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Details:

  • Unit: full suite green (6219 tests). Added coverage for the paired volume flags, the advanced parity flags (instance-profile / encryption+KMS / lifecycle), the buildCreateAgentConfig mapping, the
    useGenerateWizard CP flow, the wizard buildSteps sequencing, and a duplicate-menu guard.
  • Integ: capacity-provider add/remove and add-agent-attach integ tests pass against the real CLI binary.
  • Typecheck + lint: clean (no new warnings).
  • Interactive TUI (harness): drove the add capacity-provider wizard (forward + back-navigation, including encrypt→KMS→back→No), the agent create/template CP attach, agentcore create with a CP-by-ARN, and
    the BYO CP flow.
  • Live end-to-end (us-west-2): deployed a template agent on an arm64 capacity provider with a mounted volume → CP + runtime READY, invoke returned a response, delete-session deprovisioned the session,
    and teardown removed the stack cleanly.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

⚠️Dependent change / merge order: this PR consumes capacity-provider support from @aws/agentcore-cdk (the L3 constructs), which is a separate PR (feat/capacity-provider-attach in
agentcore-l3-cdk-constructs). That L3 PR must merge and publish a new alpha, and the @aws/agentcore-cdk pin here must be bumped to it, before capacity-provider deploys work off the pinned version. (Verified
locally against a bundled build of the L3 branch.)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

xxuamand others added 2 commits August 27, 2026 20:28
…d DevEx polish
- J2/J3: attach a runtime to a capacity provider by name or ARN, and mount CP volumes
- J4: `capacity-provider delete-session` data-plane command
- TUI: full add-capacity-provider wizard (volumes, encryption/KMS, instance profile,
lifecycle timeouts); capacity-provider attach in the agent create/template and BYO flows
- paired `--volume-name`/`--volume-size` flags (replacing `--volume name:sizeGiB`)
- referential-integrity guard: block removing a capacity provider still referenced by a runtime
- drop `[preview]` from the capacity-provider add/remove menus
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- BYO mapper (mapByoConfigToAgent) omits networkMode when a CP is attached —
the AgentEnvSpec schema rejects a capacityProviderConfiguration combined with
any networkMode, so a BYO CP submission was failing to persist.
- delete-session by-name resolution collects all deployed-state matches and
disambiguates by region (resolve within --region; reject cross-region
ambiguity) instead of blindly taking the first target.
- forward capacityProviderConfiguration + volumes through the import path
(executeImportAgent params + AgentPrimitive/useAddAgent/create callers).
- create rejects the capacity-provider name form (a new project has no sibling
to resolve); only an external ARN can attach at create time.
- generate + BYO wizard advanced-settings routing matches the steps memo when
network and capacityProvider are both selected (CP wins; no skipped screen).
- preserve an explicit volumeEncrypted=false in the CP wizard so the primitive
emits Encrypted:false (service default is true).
- tighten CAPACITY_PROVIDER_ARN_PATTERN to {name}-{10 alnum} so malformed
external ARNs fail at validate time (kept in sync with @aws/agentcore-cdk).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xxuam
xxuam requested a review from a teamAugust 27, 2026 20:39
@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 27, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 27, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice work — this PR is thorough and well-covered. Highlights I looked at closely:

  • Schema invariants (CapacityProviderConfiguration exactly-one, mutual exclusion with networkMode/networkConfig, capacityProviderVolume requires an attachment, referential integrity for in-project sibling references + volume names in AgentCoreProjectSpecSchema) all have matching tests.
  • resolveDeleteTarget disambiguates a by-name CP across regions correctly, prefers the ARN-derived region, and never mixes an id from one target with a region from another. Nice guards.
  • Destructive prompt: refuses to proceed on non-TTY, defaults to N on bare Enter, and requires --yes for non-interactive. Session-id and CP-id/ARN validation happen before any network call.
  • Telemetry is instrumented for capacity-provider.delete-session, plus has_capacity_provider / capacity_provider_by_arn / cp_volume_mount_count on create and add.agent in both the CLI and TUI paths.
  • Wizard sequencing: computeByoSteps / useGenerateWizard correctly drop network steps when CP is selected (CP wins), and both the BYO screen's onSelect handlers and the TUI dispatch match that precedence — with tests, including the duplicate-menu guard.
  • Deploy flow: useDeployFlow was updated to parse CP outputs so TUI deploys populate deployed-state (needed for the by-name path of delete-session).
  • The --volume name:sizeGiB → paired --volume-name / --volume-size migration is a breaking flag change, but the PR body calls it out as intentional pre-GA polish (the [preview] label is also being removed in this PR), and the integ tests + snapshots are updated to match.

The PR body notes a merge-order dependency on the L3 constructs PR (@aws/agentcore-cdk pin bump) before capacity-provider deploys work off the pinned version — worth confirming that lands before this ships, but that's an author-flagged coordination item, not a code issue.

No changes requested.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines41.09%15754 / 38332
🔵Statements40.35%16802 / 41631
🔵Functions35.2%2713 / 7706
🔵Branches34.26%10537 / 30750
Generated in workflow #4439 for commit a1a48e8 by the Vitest Coverage Report Action

@tejaskashtejaskash changed the title feat(capacity-provider): CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)Aug 27, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 27, 2026

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the clean head after the earlier capacity-provider findings were addressed. The fixes for network-mode exclusivity, regional target resolution, import/create forwarding, wizard routing, explicit false encryption, and ARN validation are present with focused coverage; the broader CI and e2e suites are green.

@tejaskash
tejaskash merged commit cbce862 into mainAug 27, 2026
83 of 85 checks passed
@tejaskash
tejaskash deleted the feat/capacity-provider-devex-clean branch August 27, 2026 21:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@xxuam@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) by xxuam · Pull Request #2133 · aws/agentcore-cli · GitHub
Skip to content

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) - #2133

Merged
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean
Aug 27, 2026
Merged

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)#2133
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean

Conversation

@xxuam

Copy link
Copy Markdown
Contributor

Description

Completes the AgentCore Capacity Provider feature end to end and brings its DevEx to parity with the rest of the CLI.

This PR carries two commits — the revert-of-revert that restores Journey 1, plus a new commit adding Journeys 2–4 and the DevEx polish — so it delivers the full feature:

  • J1 — create/remove a capacity provider as a first-class project resource (add capacity-provider / remove capacity-provider), persisted to agentcore.json and synthesized to an
    AWS::BedrockAgentCore::CapacityProvider CloudFormation resource (VPC, launch parameters, named EBS volumes, lifecycle, auto-created operator role), with deploy/status integration. (Restored here via
    revert-of-revert; originally feat(capacity-provider): add capacity-provider resource (Journey 1) #2030, reverted in revert: remove capacity-provider Journey 1 #2045 for release timing.)
  • J2 — attach a runtime to a capacity provider by in-project name or external ARN (add agent --capacity-provider <name-or-arn>), rendered as capacityProviderConfiguration on the runtime (network config
    is mutually exclusive and omitted).
  • J3 — mount capacity-provider volumes into a runtime (--cp-volume-name / --cp-volume-mount-path), routed through the existing filesystem-mount framework.
  • J4 — capacity-provider delete-session data-plane command to deprovision a live CP session (destructive confirm, --yes, name/id/ARN resolution).
  • TUI parity: full interactive add capacity-provider wizard (named volumes, EBS encryption + KMS key, instance profile, lifecycle timeouts); capacity-provider attach is now available in the agent
    create/template flow (and agentcore create) as well as the BYO flow.
  • DevEx polish: paired --volume-name / --volume-size flags (replacing --volume name:sizeGiB, for consistency with the other paired flags); a referential-integrity guard that blocks removing a capacity
    provider still referenced by a runtime; and removal of the [preview] label from the CP add/remove menus.
  • Bumps @aws-sdk/client-bedrock-agentcore to a version that ships DeleteCapacityProviderSessionCommand.

Related Issue

Closes #

Documentation PR

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Details:

  • Unit: full suite green (6219 tests). Added coverage for the paired volume flags, the advanced parity flags (instance-profile / encryption+KMS / lifecycle), the buildCreateAgentConfig mapping, the
    useGenerateWizard CP flow, the wizard buildSteps sequencing, and a duplicate-menu guard.
  • Integ: capacity-provider add/remove and add-agent-attach integ tests pass against the real CLI binary.
  • Typecheck + lint: clean (no new warnings).
  • Interactive TUI (harness): drove the add capacity-provider wizard (forward + back-navigation, including encrypt→KMS→back→No), the agent create/template CP attach, agentcore create with a CP-by-ARN, and
    the BYO CP flow.
  • Live end-to-end (us-west-2): deployed a template agent on an arm64 capacity provider with a mounted volume → CP + runtime READY, invoke returned a response, delete-session deprovisioned the session,
    and teardown removed the stack cleanly.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

⚠️Dependent change / merge order: this PR consumes capacity-provider support from @aws/agentcore-cdk (the L3 constructs), which is a separate PR (feat/capacity-provider-attach in
agentcore-l3-cdk-constructs). That L3 PR must merge and publish a new alpha, and the @aws/agentcore-cdk pin here must be bumped to it, before capacity-provider deploys work off the pinned version. (Verified
locally against a bundled build of the L3 branch.)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

xxuamand others added 2 commits August 27, 2026 20:28
…d DevEx polish
- J2/J3: attach a runtime to a capacity provider by name or ARN, and mount CP volumes
- J4: `capacity-provider delete-session` data-plane command
- TUI: full add-capacity-provider wizard (volumes, encryption/KMS, instance profile,
lifecycle timeouts); capacity-provider attach in the agent create/template and BYO flows
- paired `--volume-name`/`--volume-size` flags (replacing `--volume name:sizeGiB`)
- referential-integrity guard: block removing a capacity provider still referenced by a runtime
- drop `[preview]` from the capacity-provider add/remove menus
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- BYO mapper (mapByoConfigToAgent) omits networkMode when a CP is attached —
the AgentEnvSpec schema rejects a capacityProviderConfiguration combined with
any networkMode, so a BYO CP submission was failing to persist.
- delete-session by-name resolution collects all deployed-state matches and
disambiguates by region (resolve within --region; reject cross-region
ambiguity) instead of blindly taking the first target.
- forward capacityProviderConfiguration + volumes through the import path
(executeImportAgent params + AgentPrimitive/useAddAgent/create callers).
- create rejects the capacity-provider name form (a new project has no sibling
to resolve); only an external ARN can attach at create time.
- generate + BYO wizard advanced-settings routing matches the steps memo when
network and capacityProvider are both selected (CP wins; no skipped screen).
- preserve an explicit volumeEncrypted=false in the CP wizard so the primitive
emits Encrypted:false (service default is true).
- tighten CAPACITY_PROVIDER_ARN_PATTERN to {name}-{10 alnum} so malformed
external ARNs fail at validate time (kept in sync with @aws/agentcore-cdk).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xxuam
xxuam requested a review from a teamAugust 27, 2026 20:39
@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 27, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 27, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice work — this PR is thorough and well-covered. Highlights I looked at closely:

  • Schema invariants (CapacityProviderConfiguration exactly-one, mutual exclusion with networkMode/networkConfig, capacityProviderVolume requires an attachment, referential integrity for in-project sibling references + volume names in AgentCoreProjectSpecSchema) all have matching tests.
  • resolveDeleteTarget disambiguates a by-name CP across regions correctly, prefers the ARN-derived region, and never mixes an id from one target with a region from another. Nice guards.
  • Destructive prompt: refuses to proceed on non-TTY, defaults to N on bare Enter, and requires --yes for non-interactive. Session-id and CP-id/ARN validation happen before any network call.
  • Telemetry is instrumented for capacity-provider.delete-session, plus has_capacity_provider / capacity_provider_by_arn / cp_volume_mount_count on create and add.agent in both the CLI and TUI paths.
  • Wizard sequencing: computeByoSteps / useGenerateWizard correctly drop network steps when CP is selected (CP wins), and both the BYO screen's onSelect handlers and the TUI dispatch match that precedence — with tests, including the duplicate-menu guard.
  • Deploy flow: useDeployFlow was updated to parse CP outputs so TUI deploys populate deployed-state (needed for the by-name path of delete-session).
  • The --volume name:sizeGiB → paired --volume-name / --volume-size migration is a breaking flag change, but the PR body calls it out as intentional pre-GA polish (the [preview] label is also being removed in this PR), and the integ tests + snapshots are updated to match.

The PR body notes a merge-order dependency on the L3 constructs PR (@aws/agentcore-cdk pin bump) before capacity-provider deploys work off the pinned version — worth confirming that lands before this ships, but that's an author-flagged coordination item, not a code issue.

No changes requested.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines41.09%15754 / 38332
🔵Statements40.35%16802 / 41631
🔵Functions35.2%2713 / 7706
🔵Branches34.26%10537 / 30750
Generated in workflow #4439 for commit a1a48e8 by the Vitest Coverage Report Action

@tejaskashtejaskash changed the title feat(capacity-provider): CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)Aug 27, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 27, 2026

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the clean head after the earlier capacity-provider findings were addressed. The fixes for network-mode exclusivity, regional target resolution, import/create forwarding, wizard routing, explicit false encryption, and ARN validation are present with focused coverage; the broader CI and e2e suites are green.

@tejaskash
tejaskash merged commit cbce862 into mainAug 27, 2026
83 of 85 checks passed
@tejaskash
tejaskash deleted the feat/capacity-provider-devex-clean branch August 27, 2026 21:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@xxuam@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) by xxuam · Pull Request #2133 · aws/agentcore-cli · GitHub
Skip to content

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) - #2133

Merged
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean
Aug 27, 2026
Merged

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)#2133
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean

Conversation

@xxuam

Copy link
Copy Markdown
Contributor

Description

Completes the AgentCore Capacity Provider feature end to end and brings its DevEx to parity with the rest of the CLI.

This PR carries two commits — the revert-of-revert that restores Journey 1, plus a new commit adding Journeys 2–4 and the DevEx polish — so it delivers the full feature:

  • J1 — create/remove a capacity provider as a first-class project resource (add capacity-provider / remove capacity-provider), persisted to agentcore.json and synthesized to an
    AWS::BedrockAgentCore::CapacityProvider CloudFormation resource (VPC, launch parameters, named EBS volumes, lifecycle, auto-created operator role), with deploy/status integration. (Restored here via
    revert-of-revert; originally feat(capacity-provider): add capacity-provider resource (Journey 1) #2030, reverted in revert: remove capacity-provider Journey 1 #2045 for release timing.)
  • J2 — attach a runtime to a capacity provider by in-project name or external ARN (add agent --capacity-provider <name-or-arn>), rendered as capacityProviderConfiguration on the runtime (network config
    is mutually exclusive and omitted).
  • J3 — mount capacity-provider volumes into a runtime (--cp-volume-name / --cp-volume-mount-path), routed through the existing filesystem-mount framework.
  • J4 — capacity-provider delete-session data-plane command to deprovision a live CP session (destructive confirm, --yes, name/id/ARN resolution).
  • TUI parity: full interactive add capacity-provider wizard (named volumes, EBS encryption + KMS key, instance profile, lifecycle timeouts); capacity-provider attach is now available in the agent
    create/template flow (and agentcore create) as well as the BYO flow.
  • DevEx polish: paired --volume-name / --volume-size flags (replacing --volume name:sizeGiB, for consistency with the other paired flags); a referential-integrity guard that blocks removing a capacity
    provider still referenced by a runtime; and removal of the [preview] label from the CP add/remove menus.
  • Bumps @aws-sdk/client-bedrock-agentcore to a version that ships DeleteCapacityProviderSessionCommand.

Related Issue

Closes #

Documentation PR

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Details:

  • Unit: full suite green (6219 tests). Added coverage for the paired volume flags, the advanced parity flags (instance-profile / encryption+KMS / lifecycle), the buildCreateAgentConfig mapping, the
    useGenerateWizard CP flow, the wizard buildSteps sequencing, and a duplicate-menu guard.
  • Integ: capacity-provider add/remove and add-agent-attach integ tests pass against the real CLI binary.
  • Typecheck + lint: clean (no new warnings).
  • Interactive TUI (harness): drove the add capacity-provider wizard (forward + back-navigation, including encrypt→KMS→back→No), the agent create/template CP attach, agentcore create with a CP-by-ARN, and
    the BYO CP flow.
  • Live end-to-end (us-west-2): deployed a template agent on an arm64 capacity provider with a mounted volume → CP + runtime READY, invoke returned a response, delete-session deprovisioned the session,
    and teardown removed the stack cleanly.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

⚠️Dependent change / merge order: this PR consumes capacity-provider support from @aws/agentcore-cdk (the L3 constructs), which is a separate PR (feat/capacity-provider-attach in
agentcore-l3-cdk-constructs). That L3 PR must merge and publish a new alpha, and the @aws/agentcore-cdk pin here must be bumped to it, before capacity-provider deploys work off the pinned version. (Verified
locally against a bundled build of the L3 branch.)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

xxuamand others added 2 commits August 27, 2026 20:28
…d DevEx polish
- J2/J3: attach a runtime to a capacity provider by name or ARN, and mount CP volumes
- J4: `capacity-provider delete-session` data-plane command
- TUI: full add-capacity-provider wizard (volumes, encryption/KMS, instance profile,
lifecycle timeouts); capacity-provider attach in the agent create/template and BYO flows
- paired `--volume-name`/`--volume-size` flags (replacing `--volume name:sizeGiB`)
- referential-integrity guard: block removing a capacity provider still referenced by a runtime
- drop `[preview]` from the capacity-provider add/remove menus
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- BYO mapper (mapByoConfigToAgent) omits networkMode when a CP is attached —
the AgentEnvSpec schema rejects a capacityProviderConfiguration combined with
any networkMode, so a BYO CP submission was failing to persist.
- delete-session by-name resolution collects all deployed-state matches and
disambiguates by region (resolve within --region; reject cross-region
ambiguity) instead of blindly taking the first target.
- forward capacityProviderConfiguration + volumes through the import path
(executeImportAgent params + AgentPrimitive/useAddAgent/create callers).
- create rejects the capacity-provider name form (a new project has no sibling
to resolve); only an external ARN can attach at create time.
- generate + BYO wizard advanced-settings routing matches the steps memo when
network and capacityProvider are both selected (CP wins; no skipped screen).
- preserve an explicit volumeEncrypted=false in the CP wizard so the primitive
emits Encrypted:false (service default is true).
- tighten CAPACITY_PROVIDER_ARN_PATTERN to {name}-{10 alnum} so malformed
external ARNs fail at validate time (kept in sync with @aws/agentcore-cdk).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xxuam
xxuam requested a review from a teamAugust 27, 2026 20:39
@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 27, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 27, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice work — this PR is thorough and well-covered. Highlights I looked at closely:

  • Schema invariants (CapacityProviderConfiguration exactly-one, mutual exclusion with networkMode/networkConfig, capacityProviderVolume requires an attachment, referential integrity for in-project sibling references + volume names in AgentCoreProjectSpecSchema) all have matching tests.
  • resolveDeleteTarget disambiguates a by-name CP across regions correctly, prefers the ARN-derived region, and never mixes an id from one target with a region from another. Nice guards.
  • Destructive prompt: refuses to proceed on non-TTY, defaults to N on bare Enter, and requires --yes for non-interactive. Session-id and CP-id/ARN validation happen before any network call.
  • Telemetry is instrumented for capacity-provider.delete-session, plus has_capacity_provider / capacity_provider_by_arn / cp_volume_mount_count on create and add.agent in both the CLI and TUI paths.
  • Wizard sequencing: computeByoSteps / useGenerateWizard correctly drop network steps when CP is selected (CP wins), and both the BYO screen's onSelect handlers and the TUI dispatch match that precedence — with tests, including the duplicate-menu guard.
  • Deploy flow: useDeployFlow was updated to parse CP outputs so TUI deploys populate deployed-state (needed for the by-name path of delete-session).
  • The --volume name:sizeGiB → paired --volume-name / --volume-size migration is a breaking flag change, but the PR body calls it out as intentional pre-GA polish (the [preview] label is also being removed in this PR), and the integ tests + snapshots are updated to match.

The PR body notes a merge-order dependency on the L3 constructs PR (@aws/agentcore-cdk pin bump) before capacity-provider deploys work off the pinned version — worth confirming that lands before this ships, but that's an author-flagged coordination item, not a code issue.

No changes requested.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines41.09%15754 / 38332
🔵Statements40.35%16802 / 41631
🔵Functions35.2%2713 / 7706
🔵Branches34.26%10537 / 30750
Generated in workflow #4439 for commit a1a48e8 by the Vitest Coverage Report Action

@tejaskashtejaskash changed the title feat(capacity-provider): CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)Aug 27, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 27, 2026

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the clean head after the earlier capacity-provider findings were addressed. The fixes for network-mode exclusivity, regional target resolution, import/create forwarding, wizard routing, explicit false encryption, and ARN validation are present with focused coverage; the broader CI and e2e suites are green.

@tejaskash
tejaskash merged commit cbce862 into mainAug 27, 2026
83 of 85 checks passed
@tejaskash
tejaskash deleted the feat/capacity-provider-devex-clean branch August 27, 2026 21:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@xxuam@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) by xxuam · Pull Request #2133 · aws/agentcore-cli · GitHub
Skip to content

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) - #2133

Merged
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean
Aug 27, 2026
Merged

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)#2133
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean

Conversation

@xxuam

Copy link
Copy Markdown
Contributor

Description

Completes the AgentCore Capacity Provider feature end to end and brings its DevEx to parity with the rest of the CLI.

This PR carries two commits — the revert-of-revert that restores Journey 1, plus a new commit adding Journeys 2–4 and the DevEx polish — so it delivers the full feature:

  • J1 — create/remove a capacity provider as a first-class project resource (add capacity-provider / remove capacity-provider), persisted to agentcore.json and synthesized to an
    AWS::BedrockAgentCore::CapacityProvider CloudFormation resource (VPC, launch parameters, named EBS volumes, lifecycle, auto-created operator role), with deploy/status integration. (Restored here via
    revert-of-revert; originally feat(capacity-provider): add capacity-provider resource (Journey 1) #2030, reverted in revert: remove capacity-provider Journey 1 #2045 for release timing.)
  • J2 — attach a runtime to a capacity provider by in-project name or external ARN (add agent --capacity-provider <name-or-arn>), rendered as capacityProviderConfiguration on the runtime (network config
    is mutually exclusive and omitted).
  • J3 — mount capacity-provider volumes into a runtime (--cp-volume-name / --cp-volume-mount-path), routed through the existing filesystem-mount framework.
  • J4 — capacity-provider delete-session data-plane command to deprovision a live CP session (destructive confirm, --yes, name/id/ARN resolution).
  • TUI parity: full interactive add capacity-provider wizard (named volumes, EBS encryption + KMS key, instance profile, lifecycle timeouts); capacity-provider attach is now available in the agent
    create/template flow (and agentcore create) as well as the BYO flow.
  • DevEx polish: paired --volume-name / --volume-size flags (replacing --volume name:sizeGiB, for consistency with the other paired flags); a referential-integrity guard that blocks removing a capacity
    provider still referenced by a runtime; and removal of the [preview] label from the CP add/remove menus.
  • Bumps @aws-sdk/client-bedrock-agentcore to a version that ships DeleteCapacityProviderSessionCommand.

Related Issue

Closes #

Documentation PR

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Details:

  • Unit: full suite green (6219 tests). Added coverage for the paired volume flags, the advanced parity flags (instance-profile / encryption+KMS / lifecycle), the buildCreateAgentConfig mapping, the
    useGenerateWizard CP flow, the wizard buildSteps sequencing, and a duplicate-menu guard.
  • Integ: capacity-provider add/remove and add-agent-attach integ tests pass against the real CLI binary.
  • Typecheck + lint: clean (no new warnings).
  • Interactive TUI (harness): drove the add capacity-provider wizard (forward + back-navigation, including encrypt→KMS→back→No), the agent create/template CP attach, agentcore create with a CP-by-ARN, and
    the BYO CP flow.
  • Live end-to-end (us-west-2): deployed a template agent on an arm64 capacity provider with a mounted volume → CP + runtime READY, invoke returned a response, delete-session deprovisioned the session,
    and teardown removed the stack cleanly.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

⚠️Dependent change / merge order: this PR consumes capacity-provider support from @aws/agentcore-cdk (the L3 constructs), which is a separate PR (feat/capacity-provider-attach in
agentcore-l3-cdk-constructs). That L3 PR must merge and publish a new alpha, and the @aws/agentcore-cdk pin here must be bumped to it, before capacity-provider deploys work off the pinned version. (Verified
locally against a bundled build of the L3 branch.)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

xxuamand others added 2 commits August 27, 2026 20:28
…d DevEx polish
- J2/J3: attach a runtime to a capacity provider by name or ARN, and mount CP volumes
- J4: `capacity-provider delete-session` data-plane command
- TUI: full add-capacity-provider wizard (volumes, encryption/KMS, instance profile,
lifecycle timeouts); capacity-provider attach in the agent create/template and BYO flows
- paired `--volume-name`/`--volume-size` flags (replacing `--volume name:sizeGiB`)
- referential-integrity guard: block removing a capacity provider still referenced by a runtime
- drop `[preview]` from the capacity-provider add/remove menus
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- BYO mapper (mapByoConfigToAgent) omits networkMode when a CP is attached —
the AgentEnvSpec schema rejects a capacityProviderConfiguration combined with
any networkMode, so a BYO CP submission was failing to persist.
- delete-session by-name resolution collects all deployed-state matches and
disambiguates by region (resolve within --region; reject cross-region
ambiguity) instead of blindly taking the first target.
- forward capacityProviderConfiguration + volumes through the import path
(executeImportAgent params + AgentPrimitive/useAddAgent/create callers).
- create rejects the capacity-provider name form (a new project has no sibling
to resolve); only an external ARN can attach at create time.
- generate + BYO wizard advanced-settings routing matches the steps memo when
network and capacityProvider are both selected (CP wins; no skipped screen).
- preserve an explicit volumeEncrypted=false in the CP wizard so the primitive
emits Encrypted:false (service default is true).
- tighten CAPACITY_PROVIDER_ARN_PATTERN to {name}-{10 alnum} so malformed
external ARNs fail at validate time (kept in sync with @aws/agentcore-cdk).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xxuam
xxuam requested a review from a teamAugust 27, 2026 20:39
@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 27, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 27, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice work — this PR is thorough and well-covered. Highlights I looked at closely:

  • Schema invariants (CapacityProviderConfiguration exactly-one, mutual exclusion with networkMode/networkConfig, capacityProviderVolume requires an attachment, referential integrity for in-project sibling references + volume names in AgentCoreProjectSpecSchema) all have matching tests.
  • resolveDeleteTarget disambiguates a by-name CP across regions correctly, prefers the ARN-derived region, and never mixes an id from one target with a region from another. Nice guards.
  • Destructive prompt: refuses to proceed on non-TTY, defaults to N on bare Enter, and requires --yes for non-interactive. Session-id and CP-id/ARN validation happen before any network call.
  • Telemetry is instrumented for capacity-provider.delete-session, plus has_capacity_provider / capacity_provider_by_arn / cp_volume_mount_count on create and add.agent in both the CLI and TUI paths.
  • Wizard sequencing: computeByoSteps / useGenerateWizard correctly drop network steps when CP is selected (CP wins), and both the BYO screen's onSelect handlers and the TUI dispatch match that precedence — with tests, including the duplicate-menu guard.
  • Deploy flow: useDeployFlow was updated to parse CP outputs so TUI deploys populate deployed-state (needed for the by-name path of delete-session).
  • The --volume name:sizeGiB → paired --volume-name / --volume-size migration is a breaking flag change, but the PR body calls it out as intentional pre-GA polish (the [preview] label is also being removed in this PR), and the integ tests + snapshots are updated to match.

The PR body notes a merge-order dependency on the L3 constructs PR (@aws/agentcore-cdk pin bump) before capacity-provider deploys work off the pinned version — worth confirming that lands before this ships, but that's an author-flagged coordination item, not a code issue.

No changes requested.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines41.09%15754 / 38332
🔵Statements40.35%16802 / 41631
🔵Functions35.2%2713 / 7706
🔵Branches34.26%10537 / 30750
Generated in workflow #4439 for commit a1a48e8 by the Vitest Coverage Report Action

@tejaskashtejaskash changed the title feat(capacity-provider): CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)Aug 27, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 27, 2026

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the clean head after the earlier capacity-provider findings were addressed. The fixes for network-mode exclusivity, regional target resolution, import/create forwarding, wizard routing, explicit false encryption, and ARN validation are present with focused coverage; the broader CI and e2e suites are green.

@tejaskash
tejaskash merged commit cbce862 into mainAug 27, 2026
83 of 85 checks passed
@tejaskash
tejaskash deleted the feat/capacity-provider-devex-clean branch August 27, 2026 21:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@xxuam@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) by xxuam · Pull Request #2133 · aws/agentcore-cli · GitHub
Skip to content

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) - #2133

Merged
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean
Aug 27, 2026
Merged

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)#2133
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean

Conversation

@xxuam

Copy link
Copy Markdown
Contributor

Description

Completes the AgentCore Capacity Provider feature end to end and brings its DevEx to parity with the rest of the CLI.

This PR carries two commits — the revert-of-revert that restores Journey 1, plus a new commit adding Journeys 2–4 and the DevEx polish — so it delivers the full feature:

  • J1 — create/remove a capacity provider as a first-class project resource (add capacity-provider / remove capacity-provider), persisted to agentcore.json and synthesized to an
    AWS::BedrockAgentCore::CapacityProvider CloudFormation resource (VPC, launch parameters, named EBS volumes, lifecycle, auto-created operator role), with deploy/status integration. (Restored here via
    revert-of-revert; originally feat(capacity-provider): add capacity-provider resource (Journey 1) #2030, reverted in revert: remove capacity-provider Journey 1 #2045 for release timing.)
  • J2 — attach a runtime to a capacity provider by in-project name or external ARN (add agent --capacity-provider <name-or-arn>), rendered as capacityProviderConfiguration on the runtime (network config
    is mutually exclusive and omitted).
  • J3 — mount capacity-provider volumes into a runtime (--cp-volume-name / --cp-volume-mount-path), routed through the existing filesystem-mount framework.
  • J4 — capacity-provider delete-session data-plane command to deprovision a live CP session (destructive confirm, --yes, name/id/ARN resolution).
  • TUI parity: full interactive add capacity-provider wizard (named volumes, EBS encryption + KMS key, instance profile, lifecycle timeouts); capacity-provider attach is now available in the agent
    create/template flow (and agentcore create) as well as the BYO flow.
  • DevEx polish: paired --volume-name / --volume-size flags (replacing --volume name:sizeGiB, for consistency with the other paired flags); a referential-integrity guard that blocks removing a capacity
    provider still referenced by a runtime; and removal of the [preview] label from the CP add/remove menus.
  • Bumps @aws-sdk/client-bedrock-agentcore to a version that ships DeleteCapacityProviderSessionCommand.

Related Issue

Closes #

Documentation PR

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Details:

  • Unit: full suite green (6219 tests). Added coverage for the paired volume flags, the advanced parity flags (instance-profile / encryption+KMS / lifecycle), the buildCreateAgentConfig mapping, the
    useGenerateWizard CP flow, the wizard buildSteps sequencing, and a duplicate-menu guard.
  • Integ: capacity-provider add/remove and add-agent-attach integ tests pass against the real CLI binary.
  • Typecheck + lint: clean (no new warnings).
  • Interactive TUI (harness): drove the add capacity-provider wizard (forward + back-navigation, including encrypt→KMS→back→No), the agent create/template CP attach, agentcore create with a CP-by-ARN, and
    the BYO CP flow.
  • Live end-to-end (us-west-2): deployed a template agent on an arm64 capacity provider with a mounted volume → CP + runtime READY, invoke returned a response, delete-session deprovisioned the session,
    and teardown removed the stack cleanly.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

⚠️Dependent change / merge order: this PR consumes capacity-provider support from @aws/agentcore-cdk (the L3 constructs), which is a separate PR (feat/capacity-provider-attach in
agentcore-l3-cdk-constructs). That L3 PR must merge and publish a new alpha, and the @aws/agentcore-cdk pin here must be bumped to it, before capacity-provider deploys work off the pinned version. (Verified
locally against a bundled build of the L3 branch.)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

xxuamand others added 2 commits August 27, 2026 20:28
…d DevEx polish
- J2/J3: attach a runtime to a capacity provider by name or ARN, and mount CP volumes
- J4: `capacity-provider delete-session` data-plane command
- TUI: full add-capacity-provider wizard (volumes, encryption/KMS, instance profile,
lifecycle timeouts); capacity-provider attach in the agent create/template and BYO flows
- paired `--volume-name`/`--volume-size` flags (replacing `--volume name:sizeGiB`)
- referential-integrity guard: block removing a capacity provider still referenced by a runtime
- drop `[preview]` from the capacity-provider add/remove menus
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- BYO mapper (mapByoConfigToAgent) omits networkMode when a CP is attached —
the AgentEnvSpec schema rejects a capacityProviderConfiguration combined with
any networkMode, so a BYO CP submission was failing to persist.
- delete-session by-name resolution collects all deployed-state matches and
disambiguates by region (resolve within --region; reject cross-region
ambiguity) instead of blindly taking the first target.
- forward capacityProviderConfiguration + volumes through the import path
(executeImportAgent params + AgentPrimitive/useAddAgent/create callers).
- create rejects the capacity-provider name form (a new project has no sibling
to resolve); only an external ARN can attach at create time.
- generate + BYO wizard advanced-settings routing matches the steps memo when
network and capacityProvider are both selected (CP wins; no skipped screen).
- preserve an explicit volumeEncrypted=false in the CP wizard so the primitive
emits Encrypted:false (service default is true).
- tighten CAPACITY_PROVIDER_ARN_PATTERN to {name}-{10 alnum} so malformed
external ARNs fail at validate time (kept in sync with @aws/agentcore-cdk).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xxuam
xxuam requested a review from a teamAugust 27, 2026 20:39
@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 27, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 27, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice work — this PR is thorough and well-covered. Highlights I looked at closely:

  • Schema invariants (CapacityProviderConfiguration exactly-one, mutual exclusion with networkMode/networkConfig, capacityProviderVolume requires an attachment, referential integrity for in-project sibling references + volume names in AgentCoreProjectSpecSchema) all have matching tests.
  • resolveDeleteTarget disambiguates a by-name CP across regions correctly, prefers the ARN-derived region, and never mixes an id from one target with a region from another. Nice guards.
  • Destructive prompt: refuses to proceed on non-TTY, defaults to N on bare Enter, and requires --yes for non-interactive. Session-id and CP-id/ARN validation happen before any network call.
  • Telemetry is instrumented for capacity-provider.delete-session, plus has_capacity_provider / capacity_provider_by_arn / cp_volume_mount_count on create and add.agent in both the CLI and TUI paths.
  • Wizard sequencing: computeByoSteps / useGenerateWizard correctly drop network steps when CP is selected (CP wins), and both the BYO screen's onSelect handlers and the TUI dispatch match that precedence — with tests, including the duplicate-menu guard.
  • Deploy flow: useDeployFlow was updated to parse CP outputs so TUI deploys populate deployed-state (needed for the by-name path of delete-session).
  • The --volume name:sizeGiB → paired --volume-name / --volume-size migration is a breaking flag change, but the PR body calls it out as intentional pre-GA polish (the [preview] label is also being removed in this PR), and the integ tests + snapshots are updated to match.

The PR body notes a merge-order dependency on the L3 constructs PR (@aws/agentcore-cdk pin bump) before capacity-provider deploys work off the pinned version — worth confirming that lands before this ships, but that's an author-flagged coordination item, not a code issue.

No changes requested.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines41.09%15754 / 38332
🔵Statements40.35%16802 / 41631
🔵Functions35.2%2713 / 7706
🔵Branches34.26%10537 / 30750
Generated in workflow #4439 for commit a1a48e8 by the Vitest Coverage Report Action

@tejaskashtejaskash changed the title feat(capacity-provider): CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)Aug 27, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 27, 2026

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the clean head after the earlier capacity-provider findings were addressed. The fixes for network-mode exclusivity, regional target resolution, import/create forwarding, wizard routing, explicit false encryption, and ARN validation are present with focused coverage; the broader CI and e2e suites are green.

@tejaskash
tejaskash merged commit cbce862 into mainAug 27, 2026
83 of 85 checks passed
@tejaskash
tejaskash deleted the feat/capacity-provider-devex-clean branch August 27, 2026 21:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@xxuam@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) by xxuam · Pull Request #2133 · aws/agentcore-cli · GitHub
Skip to content

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) - #2133

Merged
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean
Aug 27, 2026
Merged

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)#2133
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean

Conversation

@xxuam

Copy link
Copy Markdown
Contributor

Description

Completes the AgentCore Capacity Provider feature end to end and brings its DevEx to parity with the rest of the CLI.

This PR carries two commits — the revert-of-revert that restores Journey 1, plus a new commit adding Journeys 2–4 and the DevEx polish — so it delivers the full feature:

  • J1 — create/remove a capacity provider as a first-class project resource (add capacity-provider / remove capacity-provider), persisted to agentcore.json and synthesized to an
    AWS::BedrockAgentCore::CapacityProvider CloudFormation resource (VPC, launch parameters, named EBS volumes, lifecycle, auto-created operator role), with deploy/status integration. (Restored here via
    revert-of-revert; originally feat(capacity-provider): add capacity-provider resource (Journey 1) #2030, reverted in revert: remove capacity-provider Journey 1 #2045 for release timing.)
  • J2 — attach a runtime to a capacity provider by in-project name or external ARN (add agent --capacity-provider <name-or-arn>), rendered as capacityProviderConfiguration on the runtime (network config
    is mutually exclusive and omitted).
  • J3 — mount capacity-provider volumes into a runtime (--cp-volume-name / --cp-volume-mount-path), routed through the existing filesystem-mount framework.
  • J4 — capacity-provider delete-session data-plane command to deprovision a live CP session (destructive confirm, --yes, name/id/ARN resolution).
  • TUI parity: full interactive add capacity-provider wizard (named volumes, EBS encryption + KMS key, instance profile, lifecycle timeouts); capacity-provider attach is now available in the agent
    create/template flow (and agentcore create) as well as the BYO flow.
  • DevEx polish: paired --volume-name / --volume-size flags (replacing --volume name:sizeGiB, for consistency with the other paired flags); a referential-integrity guard that blocks removing a capacity
    provider still referenced by a runtime; and removal of the [preview] label from the CP add/remove menus.
  • Bumps @aws-sdk/client-bedrock-agentcore to a version that ships DeleteCapacityProviderSessionCommand.

Related Issue

Closes #

Documentation PR

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Details:

  • Unit: full suite green (6219 tests). Added coverage for the paired volume flags, the advanced parity flags (instance-profile / encryption+KMS / lifecycle), the buildCreateAgentConfig mapping, the
    useGenerateWizard CP flow, the wizard buildSteps sequencing, and a duplicate-menu guard.
  • Integ: capacity-provider add/remove and add-agent-attach integ tests pass against the real CLI binary.
  • Typecheck + lint: clean (no new warnings).
  • Interactive TUI (harness): drove the add capacity-provider wizard (forward + back-navigation, including encrypt→KMS→back→No), the agent create/template CP attach, agentcore create with a CP-by-ARN, and
    the BYO CP flow.
  • Live end-to-end (us-west-2): deployed a template agent on an arm64 capacity provider with a mounted volume → CP + runtime READY, invoke returned a response, delete-session deprovisioned the session,
    and teardown removed the stack cleanly.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

⚠️Dependent change / merge order: this PR consumes capacity-provider support from @aws/agentcore-cdk (the L3 constructs), which is a separate PR (feat/capacity-provider-attach in
agentcore-l3-cdk-constructs). That L3 PR must merge and publish a new alpha, and the @aws/agentcore-cdk pin here must be bumped to it, before capacity-provider deploys work off the pinned version. (Verified
locally against a bundled build of the L3 branch.)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

xxuamand others added 2 commits August 27, 2026 20:28
…d DevEx polish
- J2/J3: attach a runtime to a capacity provider by name or ARN, and mount CP volumes
- J4: `capacity-provider delete-session` data-plane command
- TUI: full add-capacity-provider wizard (volumes, encryption/KMS, instance profile,
lifecycle timeouts); capacity-provider attach in the agent create/template and BYO flows
- paired `--volume-name`/`--volume-size` flags (replacing `--volume name:sizeGiB`)
- referential-integrity guard: block removing a capacity provider still referenced by a runtime
- drop `[preview]` from the capacity-provider add/remove menus
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- BYO mapper (mapByoConfigToAgent) omits networkMode when a CP is attached —
the AgentEnvSpec schema rejects a capacityProviderConfiguration combined with
any networkMode, so a BYO CP submission was failing to persist.
- delete-session by-name resolution collects all deployed-state matches and
disambiguates by region (resolve within --region; reject cross-region
ambiguity) instead of blindly taking the first target.
- forward capacityProviderConfiguration + volumes through the import path
(executeImportAgent params + AgentPrimitive/useAddAgent/create callers).
- create rejects the capacity-provider name form (a new project has no sibling
to resolve); only an external ARN can attach at create time.
- generate + BYO wizard advanced-settings routing matches the steps memo when
network and capacityProvider are both selected (CP wins; no skipped screen).
- preserve an explicit volumeEncrypted=false in the CP wizard so the primitive
emits Encrypted:false (service default is true).
- tighten CAPACITY_PROVIDER_ARN_PATTERN to {name}-{10 alnum} so malformed
external ARNs fail at validate time (kept in sync with @aws/agentcore-cdk).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xxuam
xxuam requested a review from a teamAugust 27, 2026 20:39
@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 27, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 27, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice work — this PR is thorough and well-covered. Highlights I looked at closely:

  • Schema invariants (CapacityProviderConfiguration exactly-one, mutual exclusion with networkMode/networkConfig, capacityProviderVolume requires an attachment, referential integrity for in-project sibling references + volume names in AgentCoreProjectSpecSchema) all have matching tests.
  • resolveDeleteTarget disambiguates a by-name CP across regions correctly, prefers the ARN-derived region, and never mixes an id from one target with a region from another. Nice guards.
  • Destructive prompt: refuses to proceed on non-TTY, defaults to N on bare Enter, and requires --yes for non-interactive. Session-id and CP-id/ARN validation happen before any network call.
  • Telemetry is instrumented for capacity-provider.delete-session, plus has_capacity_provider / capacity_provider_by_arn / cp_volume_mount_count on create and add.agent in both the CLI and TUI paths.
  • Wizard sequencing: computeByoSteps / useGenerateWizard correctly drop network steps when CP is selected (CP wins), and both the BYO screen's onSelect handlers and the TUI dispatch match that precedence — with tests, including the duplicate-menu guard.
  • Deploy flow: useDeployFlow was updated to parse CP outputs so TUI deploys populate deployed-state (needed for the by-name path of delete-session).
  • The --volume name:sizeGiB → paired --volume-name / --volume-size migration is a breaking flag change, but the PR body calls it out as intentional pre-GA polish (the [preview] label is also being removed in this PR), and the integ tests + snapshots are updated to match.

The PR body notes a merge-order dependency on the L3 constructs PR (@aws/agentcore-cdk pin bump) before capacity-provider deploys work off the pinned version — worth confirming that lands before this ships, but that's an author-flagged coordination item, not a code issue.

No changes requested.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines41.09%15754 / 38332
🔵Statements40.35%16802 / 41631
🔵Functions35.2%2713 / 7706
🔵Branches34.26%10537 / 30750
Generated in workflow #4439 for commit a1a48e8 by the Vitest Coverage Report Action

@tejaskashtejaskash changed the title feat(capacity-provider): CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)Aug 27, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 27, 2026

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the clean head after the earlier capacity-provider findings were addressed. The fixes for network-mode exclusivity, regional target resolution, import/create forwarding, wizard routing, explicit false encryption, and ARN validation are present with focused coverage; the broader CI and e2e suites are green.

@tejaskash
tejaskash merged commit cbce862 into mainAug 27, 2026
83 of 85 checks passed
@tejaskash
tejaskash deleted the feat/capacity-provider-devex-clean branch August 27, 2026 21:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@xxuam@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) by xxuam · Pull Request #2133 · aws/agentcore-cli · GitHub
Skip to content

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) - #2133

Merged
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean
Aug 27, 2026
Merged

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)#2133
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean

Conversation

@xxuam

Copy link
Copy Markdown
Contributor

Description

Completes the AgentCore Capacity Provider feature end to end and brings its DevEx to parity with the rest of the CLI.

This PR carries two commits — the revert-of-revert that restores Journey 1, plus a new commit adding Journeys 2–4 and the DevEx polish — so it delivers the full feature:

  • J1 — create/remove a capacity provider as a first-class project resource (add capacity-provider / remove capacity-provider), persisted to agentcore.json and synthesized to an
    AWS::BedrockAgentCore::CapacityProvider CloudFormation resource (VPC, launch parameters, named EBS volumes, lifecycle, auto-created operator role), with deploy/status integration. (Restored here via
    revert-of-revert; originally feat(capacity-provider): add capacity-provider resource (Journey 1) #2030, reverted in revert: remove capacity-provider Journey 1 #2045 for release timing.)
  • J2 — attach a runtime to a capacity provider by in-project name or external ARN (add agent --capacity-provider <name-or-arn>), rendered as capacityProviderConfiguration on the runtime (network config
    is mutually exclusive and omitted).
  • J3 — mount capacity-provider volumes into a runtime (--cp-volume-name / --cp-volume-mount-path), routed through the existing filesystem-mount framework.
  • J4 — capacity-provider delete-session data-plane command to deprovision a live CP session (destructive confirm, --yes, name/id/ARN resolution).
  • TUI parity: full interactive add capacity-provider wizard (named volumes, EBS encryption + KMS key, instance profile, lifecycle timeouts); capacity-provider attach is now available in the agent
    create/template flow (and agentcore create) as well as the BYO flow.
  • DevEx polish: paired --volume-name / --volume-size flags (replacing --volume name:sizeGiB, for consistency with the other paired flags); a referential-integrity guard that blocks removing a capacity
    provider still referenced by a runtime; and removal of the [preview] label from the CP add/remove menus.
  • Bumps @aws-sdk/client-bedrock-agentcore to a version that ships DeleteCapacityProviderSessionCommand.

Related Issue

Closes #

Documentation PR

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Details:

  • Unit: full suite green (6219 tests). Added coverage for the paired volume flags, the advanced parity flags (instance-profile / encryption+KMS / lifecycle), the buildCreateAgentConfig mapping, the
    useGenerateWizard CP flow, the wizard buildSteps sequencing, and a duplicate-menu guard.
  • Integ: capacity-provider add/remove and add-agent-attach integ tests pass against the real CLI binary.
  • Typecheck + lint: clean (no new warnings).
  • Interactive TUI (harness): drove the add capacity-provider wizard (forward + back-navigation, including encrypt→KMS→back→No), the agent create/template CP attach, agentcore create with a CP-by-ARN, and
    the BYO CP flow.
  • Live end-to-end (us-west-2): deployed a template agent on an arm64 capacity provider with a mounted volume → CP + runtime READY, invoke returned a response, delete-session deprovisioned the session,
    and teardown removed the stack cleanly.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

⚠️Dependent change / merge order: this PR consumes capacity-provider support from @aws/agentcore-cdk (the L3 constructs), which is a separate PR (feat/capacity-provider-attach in
agentcore-l3-cdk-constructs). That L3 PR must merge and publish a new alpha, and the @aws/agentcore-cdk pin here must be bumped to it, before capacity-provider deploys work off the pinned version. (Verified
locally against a bundled build of the L3 branch.)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

xxuamand others added 2 commits August 27, 2026 20:28
…d DevEx polish
- J2/J3: attach a runtime to a capacity provider by name or ARN, and mount CP volumes
- J4: `capacity-provider delete-session` data-plane command
- TUI: full add-capacity-provider wizard (volumes, encryption/KMS, instance profile,
lifecycle timeouts); capacity-provider attach in the agent create/template and BYO flows
- paired `--volume-name`/`--volume-size` flags (replacing `--volume name:sizeGiB`)
- referential-integrity guard: block removing a capacity provider still referenced by a runtime
- drop `[preview]` from the capacity-provider add/remove menus
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- BYO mapper (mapByoConfigToAgent) omits networkMode when a CP is attached —
the AgentEnvSpec schema rejects a capacityProviderConfiguration combined with
any networkMode, so a BYO CP submission was failing to persist.
- delete-session by-name resolution collects all deployed-state matches and
disambiguates by region (resolve within --region; reject cross-region
ambiguity) instead of blindly taking the first target.
- forward capacityProviderConfiguration + volumes through the import path
(executeImportAgent params + AgentPrimitive/useAddAgent/create callers).
- create rejects the capacity-provider name form (a new project has no sibling
to resolve); only an external ARN can attach at create time.
- generate + BYO wizard advanced-settings routing matches the steps memo when
network and capacityProvider are both selected (CP wins; no skipped screen).
- preserve an explicit volumeEncrypted=false in the CP wizard so the primitive
emits Encrypted:false (service default is true).
- tighten CAPACITY_PROVIDER_ARN_PATTERN to {name}-{10 alnum} so malformed
external ARNs fail at validate time (kept in sync with @aws/agentcore-cdk).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xxuam
xxuam requested a review from a teamAugust 27, 2026 20:39
@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 27, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 27, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice work — this PR is thorough and well-covered. Highlights I looked at closely:

  • Schema invariants (CapacityProviderConfiguration exactly-one, mutual exclusion with networkMode/networkConfig, capacityProviderVolume requires an attachment, referential integrity for in-project sibling references + volume names in AgentCoreProjectSpecSchema) all have matching tests.
  • resolveDeleteTarget disambiguates a by-name CP across regions correctly, prefers the ARN-derived region, and never mixes an id from one target with a region from another. Nice guards.
  • Destructive prompt: refuses to proceed on non-TTY, defaults to N on bare Enter, and requires --yes for non-interactive. Session-id and CP-id/ARN validation happen before any network call.
  • Telemetry is instrumented for capacity-provider.delete-session, plus has_capacity_provider / capacity_provider_by_arn / cp_volume_mount_count on create and add.agent in both the CLI and TUI paths.
  • Wizard sequencing: computeByoSteps / useGenerateWizard correctly drop network steps when CP is selected (CP wins), and both the BYO screen's onSelect handlers and the TUI dispatch match that precedence — with tests, including the duplicate-menu guard.
  • Deploy flow: useDeployFlow was updated to parse CP outputs so TUI deploys populate deployed-state (needed for the by-name path of delete-session).
  • The --volume name:sizeGiB → paired --volume-name / --volume-size migration is a breaking flag change, but the PR body calls it out as intentional pre-GA polish (the [preview] label is also being removed in this PR), and the integ tests + snapshots are updated to match.

The PR body notes a merge-order dependency on the L3 constructs PR (@aws/agentcore-cdk pin bump) before capacity-provider deploys work off the pinned version — worth confirming that lands before this ships, but that's an author-flagged coordination item, not a code issue.

No changes requested.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines41.09%15754 / 38332
🔵Statements40.35%16802 / 41631
🔵Functions35.2%2713 / 7706
🔵Branches34.26%10537 / 30750
Generated in workflow #4439 for commit a1a48e8 by the Vitest Coverage Report Action

@tejaskashtejaskash changed the title feat(capacity-provider): CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)Aug 27, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 27, 2026

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the clean head after the earlier capacity-provider findings were addressed. The fixes for network-mode exclusivity, regional target resolution, import/create forwarding, wizard routing, explicit false encryption, and ARN validation are present with focused coverage; the broader CI and e2e suites are green.

@tejaskash
tejaskash merged commit cbce862 into mainAug 27, 2026
83 of 85 checks passed
@tejaskash
tejaskash deleted the feat/capacity-provider-devex-clean branch August 27, 2026 21:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@xxuam@tejaskash
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) by xxuam · Pull Request #2133 · aws/agentcore-cli · GitHub
Skip to content

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) - #2133

Merged
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean
Aug 27, 2026
Merged

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)#2133
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean

Conversation

@xxuam

Copy link
Copy Markdown
Contributor

Description

Completes the AgentCore Capacity Provider feature end to end and brings its DevEx to parity with the rest of the CLI.

This PR carries two commits — the revert-of-revert that restores Journey 1, plus a new commit adding Journeys 2–4 and the DevEx polish — so it delivers the full feature:

  • J1 — create/remove a capacity provider as a first-class project resource (add capacity-provider / remove capacity-provider), persisted to agentcore.json and synthesized to an
    AWS::BedrockAgentCore::CapacityProvider CloudFormation resource (VPC, launch parameters, named EBS volumes, lifecycle, auto-created operator role), with deploy/status integration. (Restored here via
    revert-of-revert; originally feat(capacity-provider): add capacity-provider resource (Journey 1) #2030, reverted in revert: remove capacity-provider Journey 1 #2045 for release timing.)
  • J2 — attach a runtime to a capacity provider by in-project name or external ARN (add agent --capacity-provider <name-or-arn>), rendered as capacityProviderConfiguration on the runtime (network config
    is mutually exclusive and omitted).
  • J3 — mount capacity-provider volumes into a runtime (--cp-volume-name / --cp-volume-mount-path), routed through the existing filesystem-mount framework.
  • J4 — capacity-provider delete-session data-plane command to deprovision a live CP session (destructive confirm, --yes, name/id/ARN resolution).
  • TUI parity: full interactive add capacity-provider wizard (named volumes, EBS encryption + KMS key, instance profile, lifecycle timeouts); capacity-provider attach is now available in the agent
    create/template flow (and agentcore create) as well as the BYO flow.
  • DevEx polish: paired --volume-name / --volume-size flags (replacing --volume name:sizeGiB, for consistency with the other paired flags); a referential-integrity guard that blocks removing a capacity
    provider still referenced by a runtime; and removal of the [preview] label from the CP add/remove menus.
  • Bumps @aws-sdk/client-bedrock-agentcore to a version that ships DeleteCapacityProviderSessionCommand.

Related Issue

Closes #

Documentation PR

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Details:

  • Unit: full suite green (6219 tests). Added coverage for the paired volume flags, the advanced parity flags (instance-profile / encryption+KMS / lifecycle), the buildCreateAgentConfig mapping, the
    useGenerateWizard CP flow, the wizard buildSteps sequencing, and a duplicate-menu guard.
  • Integ: capacity-provider add/remove and add-agent-attach integ tests pass against the real CLI binary.
  • Typecheck + lint: clean (no new warnings).
  • Interactive TUI (harness): drove the add capacity-provider wizard (forward + back-navigation, including encrypt→KMS→back→No), the agent create/template CP attach, agentcore create with a CP-by-ARN, and
    the BYO CP flow.
  • Live end-to-end (us-west-2): deployed a template agent on an arm64 capacity provider with a mounted volume → CP + runtime READY, invoke returned a response, delete-session deprovisioned the session,
    and teardown removed the stack cleanly.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

⚠️Dependent change / merge order: this PR consumes capacity-provider support from @aws/agentcore-cdk (the L3 constructs), which is a separate PR (feat/capacity-provider-attach in
agentcore-l3-cdk-constructs). That L3 PR must merge and publish a new alpha, and the @aws/agentcore-cdk pin here must be bumped to it, before capacity-provider deploys work off the pinned version. (Verified
locally against a bundled build of the L3 branch.)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

xxuamand others added 2 commits August 27, 2026 20:28
…d DevEx polish
- J2/J3: attach a runtime to a capacity provider by name or ARN, and mount CP volumes
- J4: `capacity-provider delete-session` data-plane command
- TUI: full add-capacity-provider wizard (volumes, encryption/KMS, instance profile,
lifecycle timeouts); capacity-provider attach in the agent create/template and BYO flows
- paired `--volume-name`/`--volume-size` flags (replacing `--volume name:sizeGiB`)
- referential-integrity guard: block removing a capacity provider still referenced by a runtime
- drop `[preview]` from the capacity-provider add/remove menus
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- BYO mapper (mapByoConfigToAgent) omits networkMode when a CP is attached —
the AgentEnvSpec schema rejects a capacityProviderConfiguration combined with
any networkMode, so a BYO CP submission was failing to persist.
- delete-session by-name resolution collects all deployed-state matches and
disambiguates by region (resolve within --region; reject cross-region
ambiguity) instead of blindly taking the first target.
- forward capacityProviderConfiguration + volumes through the import path
(executeImportAgent params + AgentPrimitive/useAddAgent/create callers).
- create rejects the capacity-provider name form (a new project has no sibling
to resolve); only an external ARN can attach at create time.
- generate + BYO wizard advanced-settings routing matches the steps memo when
network and capacityProvider are both selected (CP wins; no skipped screen).
- preserve an explicit volumeEncrypted=false in the CP wizard so the primitive
emits Encrypted:false (service default is true).
- tighten CAPACITY_PROVIDER_ARN_PATTERN to {name}-{10 alnum} so malformed
external ARNs fail at validate time (kept in sync with @aws/agentcore-cdk).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xxuam
xxuam requested a review from a teamAugust 27, 2026 20:39
@github-actionsgithub-actionsBot added the size/xl PR size: XL label Aug 27, 2026
@agentcore-devx-automationagentcore-devx-automationBot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 27, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automationagentcore-devx-automationBot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026

@agentcore-devx-automationagentcore-devx-automationBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice work — this PR is thorough and well-covered. Highlights I looked at closely:

  • Schema invariants (CapacityProviderConfiguration exactly-one, mutual exclusion with networkMode/networkConfig, capacityProviderVolume requires an attachment, referential integrity for in-project sibling references + volume names in AgentCoreProjectSpecSchema) all have matching tests.
  • resolveDeleteTarget disambiguates a by-name CP across regions correctly, prefers the ARN-derived region, and never mixes an id from one target with a region from another. Nice guards.
  • Destructive prompt: refuses to proceed on non-TTY, defaults to N on bare Enter, and requires --yes for non-interactive. Session-id and CP-id/ARN validation happen before any network call.
  • Telemetry is instrumented for capacity-provider.delete-session, plus has_capacity_provider / capacity_provider_by_arn / cp_volume_mount_count on create and add.agent in both the CLI and TUI paths.
  • Wizard sequencing: computeByoSteps / useGenerateWizard correctly drop network steps when CP is selected (CP wins), and both the BYO screen's onSelect handlers and the TUI dispatch match that precedence — with tests, including the duplicate-menu guard.
  • Deploy flow: useDeployFlow was updated to parse CP outputs so TUI deploys populate deployed-state (needed for the by-name path of delete-session).
  • The --volume name:sizeGiB → paired --volume-name / --volume-size migration is a breaking flag change, but the PR body calls it out as intentional pre-GA polish (the [preview] label is also being removed in this PR), and the integ tests + snapshots are updated to match.

The PR body notes a merge-order dependency on the L3 constructs PR (@aws/agentcore-cdk pin bump) before capacity-provider deploys work off the pinned version — worth confirming that lands before this ships, but that's an author-flagged coordination item, not a code issue.

No changes requested.

@agentcore-devx-automationagentcore-devx-automationBot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

StatusCategoryPercentageCovered / Total
🔵Lines41.09%15754 / 38332
🔵Statements40.35%16802 / 41631
🔵Functions35.2%2713 / 7706
🔵Branches34.26%10537 / 30750
Generated in workflow #4439 for commit a1a48e8 by the Vitest Coverage Report Action

@tejaskashtejaskash changed the title feat(capacity-provider): CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)Aug 27, 2026
@github-actionsgithub-actionsBot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 27, 2026

@tejaskashtejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the clean head after the earlier capacity-provider findings were addressed. The fixes for network-mode exclusivity, regional target resolution, import/create forwarding, wizard routing, explicit false encryption, and ARN validation are present with focused coverage; the broader CI and e2e suites are green.

@tejaskash
tejaskash merged commit cbce862 into mainAug 27, 2026
83 of 85 checks passed
@tejaskash
tejaskash deleted the feat/capacity-provider-devex-clean branch August 27, 2026 21:25
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xlPR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@xxuam@tejaskash