Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat: add VPC network mode to schema [1/3] by tejaskash · Pull Request #424 · aws/agentcore-cli · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: add VPC network mode to schema [1/3] by tejaskash · Pull Request #424 · aws/agentcore-cli · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: add VPC network mode to schema [1/3] by tejaskash · Pull Request #424 · aws/agentcore-cli · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat: add VPC network mode to schema [1/3] by tejaskash · Pull Request #424 · aws/agentcore-cli · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: add VPC network mode to schema [1/3] by tejaskash · Pull Request #424 · aws/agentcore-cli · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); feat: add VPC network mode to schema [1/3] by tejaskash · Pull Request #424 · aws/agentcore-cli · GitHub
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading