Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions src/cli/commands/dev/command.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -144,6 +144,12 @@ export const registerDev = (program: Command) => {
const targetAgent = project.agents.find(a => a.name === config.agentName);
const providerInfo = targetAgent?.modelProvider ?? '(see agent code)';

if (targetAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}

console.log(`Starting dev server...`);
console.log(`Agent: ${config.agentName}`);
console.log(`Provider: ${providerInfo}`);
Expand DownExpand Up@@ -178,6 +184,20 @@ export const registerDev = (program: Command) => {
await new Promise(() => {});
}

// Warn if the target agent uses VPC mode
{
const vpcAgent = opts.agent
? project.agents.find(a => a.name === opts.agent)
: project.agents.length === 1
? project.agents[0]
: undefined;
if (vpcAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}
}

// Enter alternate screen buffer for fullscreen mode
process.stdout.write(ENTER_ALT_SCREEN);

Expand Down
6 changes: 6 additions & 0 deletions src/cli/commands/invoke/action.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,6 +67,12 @@ export async function handleInvoke(context: InvokeContext, options: InvokeOption
return { success: false, error: 'No agents defined in configuration' };
}

if (agentSpec.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Invocation may require setting up VPC Endpoints for S3, ECR, Bedrock. If your agent uses a non-Bedrock model provider, VPC will require public internet access.'
);
}

// Get the deployed state for this specific agent
const agentState = targetState?.resources?.agents?.[agentSpec.name];

Expand Down
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions src/cli/commands/dev/command.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -144,6 +144,12 @@ export const registerDev = (program: Command) => {
const targetAgent = project.agents.find(a => a.name === config.agentName);
const providerInfo = targetAgent?.modelProvider ?? '(see agent code)';

if (targetAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}

console.log(`Starting dev server...`);
console.log(`Agent: ${config.agentName}`);
console.log(`Provider: ${providerInfo}`);
Expand DownExpand Up@@ -178,6 +184,20 @@ export const registerDev = (program: Command) => {
await new Promise(() => {});
}

// Warn if the target agent uses VPC mode
{
const vpcAgent = opts.agent
? project.agents.find(a => a.name === opts.agent)
: project.agents.length === 1
? project.agents[0]
: undefined;
if (vpcAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}
}

// Enter alternate screen buffer for fullscreen mode
process.stdout.write(ENTER_ALT_SCREEN);

Expand Down
6 changes: 6 additions & 0 deletions src/cli/commands/invoke/action.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,6 +67,12 @@ export async function handleInvoke(context: InvokeContext, options: InvokeOption
return { success: false, error: 'No agents defined in configuration' };
}

if (agentSpec.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Invocation may require setting up VPC Endpoints for S3, ECR, Bedrock. If your agent uses a non-Bedrock model provider, VPC will require public internet access.'
);
}

// Get the deployed state for this specific agent
const agentState = targetState?.resources?.agents?.[agentSpec.name];

Expand Down
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions src/cli/commands/dev/command.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -144,6 +144,12 @@ export const registerDev = (program: Command) => {
const targetAgent = project.agents.find(a => a.name === config.agentName);
const providerInfo = targetAgent?.modelProvider ?? '(see agent code)';

if (targetAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}

console.log(`Starting dev server...`);
console.log(`Agent: ${config.agentName}`);
console.log(`Provider: ${providerInfo}`);
Expand DownExpand Up@@ -178,6 +184,20 @@ export const registerDev = (program: Command) => {
await new Promise(() => {});
}

// Warn if the target agent uses VPC mode
{
const vpcAgent = opts.agent
? project.agents.find(a => a.name === opts.agent)
: project.agents.length === 1
? project.agents[0]
: undefined;
if (vpcAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}
}

// Enter alternate screen buffer for fullscreen mode
process.stdout.write(ENTER_ALT_SCREEN);

Expand Down
6 changes: 6 additions & 0 deletions src/cli/commands/invoke/action.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,6 +67,12 @@ export async function handleInvoke(context: InvokeContext, options: InvokeOption
return { success: false, error: 'No agents defined in configuration' };
}

if (agentSpec.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Invocation may require setting up VPC Endpoints for S3, ECR, Bedrock. If your agent uses a non-Bedrock model provider, VPC will require public internet access.'
);
}

// Get the deployed state for this specific agent
const agentState = targetState?.resources?.agents?.[agentSpec.name];

Expand Down
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions src/cli/commands/dev/command.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -144,6 +144,12 @@ export const registerDev = (program: Command) => {
const targetAgent = project.agents.find(a => a.name === config.agentName);
const providerInfo = targetAgent?.modelProvider ?? '(see agent code)';

if (targetAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}

console.log(`Starting dev server...`);
console.log(`Agent: ${config.agentName}`);
console.log(`Provider: ${providerInfo}`);
Expand DownExpand Up@@ -178,6 +184,20 @@ export const registerDev = (program: Command) => {
await new Promise(() => {});
}

// Warn if the target agent uses VPC mode
{
const vpcAgent = opts.agent
? project.agents.find(a => a.name === opts.agent)
: project.agents.length === 1
? project.agents[0]
: undefined;
if (vpcAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}
}

// Enter alternate screen buffer for fullscreen mode
process.stdout.write(ENTER_ALT_SCREEN);

Expand Down
6 changes: 6 additions & 0 deletions src/cli/commands/invoke/action.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,6 +67,12 @@ export async function handleInvoke(context: InvokeContext, options: InvokeOption
return { success: false, error: 'No agents defined in configuration' };
}

if (agentSpec.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Invocation may require setting up VPC Endpoints for S3, ECR, Bedrock. If your agent uses a non-Bedrock model provider, VPC will require public internet access.'
);
}

// Get the deployed state for this specific agent
const agentState = targetState?.resources?.agents?.[agentSpec.name];

Expand Down
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions src/cli/commands/dev/command.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -144,6 +144,12 @@ export const registerDev = (program: Command) => {
const targetAgent = project.agents.find(a => a.name === config.agentName);
const providerInfo = targetAgent?.modelProvider ?? '(see agent code)';

if (targetAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}

console.log(`Starting dev server...`);
console.log(`Agent: ${config.agentName}`);
console.log(`Provider: ${providerInfo}`);
Expand DownExpand Up@@ -178,6 +184,20 @@ export const registerDev = (program: Command) => {
await new Promise(() => {});
}

// Warn if the target agent uses VPC mode
{
const vpcAgent = opts.agent
? project.agents.find(a => a.name === opts.agent)
: project.agents.length === 1
? project.agents[0]
: undefined;
if (vpcAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}
}

// Enter alternate screen buffer for fullscreen mode
process.stdout.write(ENTER_ALT_SCREEN);

Expand Down
6 changes: 6 additions & 0 deletions src/cli/commands/invoke/action.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,6 +67,12 @@ export async function handleInvoke(context: InvokeContext, options: InvokeOption
return { success: false, error: 'No agents defined in configuration' };
}

if (agentSpec.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Invocation may require setting up VPC Endpoints for S3, ECR, Bedrock. If your agent uses a non-Bedrock model provider, VPC will require public internet access.'
);
}

// Get the deployed state for this specific agent
const agentState = targetState?.resources?.agents?.[agentSpec.name];

Expand Down
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions src/cli/commands/dev/command.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -144,6 +144,12 @@ export const registerDev = (program: Command) => {
const targetAgent = project.agents.find(a => a.name === config.agentName);
const providerInfo = targetAgent?.modelProvider ?? '(see agent code)';

if (targetAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}

console.log(`Starting dev server...`);
console.log(`Agent: ${config.agentName}`);
console.log(`Provider: ${providerInfo}`);
Expand DownExpand Up@@ -178,6 +184,20 @@ export const registerDev = (program: Command) => {
await new Promise(() => {});
}

// Warn if the target agent uses VPC mode
{
const vpcAgent = opts.agent
? project.agents.find(a => a.name === opts.agent)
: project.agents.length === 1
? project.agents[0]
: undefined;
if (vpcAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}
}

// Enter alternate screen buffer for fullscreen mode
process.stdout.write(ENTER_ALT_SCREEN);

Expand Down
6 changes: 6 additions & 0 deletions src/cli/commands/invoke/action.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,6 +67,12 @@ export async function handleInvoke(context: InvokeContext, options: InvokeOption
return { success: false, error: 'No agents defined in configuration' };
}

if (agentSpec.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Invocation may require setting up VPC Endpoints for S3, ECR, Bedrock. If your agent uses a non-Bedrock model provider, VPC will require public internet access.'
);
}

// Get the deployed state for this specific agent
const agentState = targetState?.resources?.agents?.[agentSpec.name];

Expand Down
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions src/cli/commands/dev/command.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -144,6 +144,12 @@ export const registerDev = (program: Command) => {
const targetAgent = project.agents.find(a => a.name === config.agentName);
const providerInfo = targetAgent?.modelProvider ?? '(see agent code)';

if (targetAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}

console.log(`Starting dev server...`);
console.log(`Agent: ${config.agentName}`);
console.log(`Provider: ${providerInfo}`);
Expand DownExpand Up@@ -178,6 +184,20 @@ export const registerDev = (program: Command) => {
await new Promise(() => {});
}

// Warn if the target agent uses VPC mode
{
const vpcAgent = opts.agent
? project.agents.find(a => a.name === opts.agent)
: project.agents.length === 1
? project.agents[0]
: undefined;
if (vpcAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}
}

// Enter alternate screen buffer for fullscreen mode
process.stdout.write(ENTER_ALT_SCREEN);

Expand Down
6 changes: 6 additions & 0 deletions src/cli/commands/invoke/action.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,6 +67,12 @@ export async function handleInvoke(context: InvokeContext, options: InvokeOption
return { success: false, error: 'No agents defined in configuration' };
}

if (agentSpec.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Invocation may require setting up VPC Endpoints for S3, ECR, Bedrock. If your agent uses a non-Bedrock model provider, VPC will require public internet access.'
);
}

// Get the deployed state for this specific agent
const agentState = targetState?.resources?.agents?.[agentSpec.name];

Expand Down
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions src/cli/commands/dev/command.tsx
Original file line numberDiff line numberDiff line change
Expand Up@@ -144,6 +144,12 @@ export const registerDev = (program: Command) => {
const targetAgent = project.agents.find(a => a.name === config.agentName);
const providerInfo = targetAgent?.modelProvider ?? '(see agent code)';

if (targetAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}

console.log(`Starting dev server...`);
console.log(`Agent: ${config.agentName}`);
console.log(`Provider: ${providerInfo}`);
Expand DownExpand Up@@ -178,6 +184,20 @@ export const registerDev = (program: Command) => {
await new Promise(() => {});
}

// Warn if the target agent uses VPC mode
{
const vpcAgent = opts.agent
? project.agents.find(a => a.name === opts.agent)
: project.agents.length === 1
? project.agents[0]
: undefined;
if (vpcAgent?.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Local dev server runs outside your VPC. Network behavior may differ from deployed environment.'
);
}
}

// Enter alternate screen buffer for fullscreen mode
process.stdout.write(ENTER_ALT_SCREEN);

Expand Down
6 changes: 6 additions & 0 deletions src/cli/commands/invoke/action.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -67,6 +67,12 @@ export async function handleInvoke(context: InvokeContext, options: InvokeOption
return { success: false, error: 'No agents defined in configuration' };
}

if (agentSpec.networkMode === 'VPC') {
console.warn(
'Warning: This agent uses VPC network mode. Invocation may require setting up VPC Endpoints for S3, ECR, Bedrock. If your agent uses a non-Bedrock model provider, VPC will require public internet access.'
);
}

// Get the deployed state for this specific agent
const agentState = targetState?.resources?.agents?.[agentSpec.name];

Expand Down
6 changes: 3 additions & 3 deletions src/schema/__tests__/constants.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -74,12 +74,12 @@ describe('NetworkModeSchema', () => {
expect(NetworkModeSchema.safeParse('PUBLIC').success).toBe(true);
});

it('accepts PRIVATE', () => {
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(true);
it('accepts VPC', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(true);
});

it('rejects other modes', () => {
expect(NetworkModeSchema.safeParse('VPC').success).toBe(false);
expect(NetworkModeSchema.safeParse('PRIVATE').success).toBe(false);
});
});

Expand Down
2 changes: 1 addition & 1 deletion src/schema/constants.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -139,5 +139,5 @@ export type NodeRuntime = z.infer<typeof NodeRuntimeSchema>;
export const RuntimeVersionSchema = z.union([PythonRuntimeSchema, NodeRuntimeSchema]);
export type RuntimeVersion = z.infer<typeof RuntimeVersionSchema>;

export const NetworkModeSchema = z.enum(['PUBLIC', 'PRIVATE']);
export const NetworkModeSchema = z.enum(['PUBLIC', 'VPC']);
export type NetworkMode = z.infer<typeof NetworkModeSchema>;
12 changes: 11 additions & 1 deletion src/schema/llm-compacted/agentcore.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -26,10 +26,19 @@ type BuildType = 'CodeZip' | 'Container';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type RuntimeVersion = PythonRuntime | NodeRuntime;
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
type MemoryStrategyType = 'SEMANTIC' | 'SUMMARIZATION' | 'USER_PREFERENCE';
type ModelProvider = 'Bedrock' | 'Gemini' | 'OpenAI' | 'Anthropic';

// ─────────────────────────────────────────────────────────────────────────────
// NETWORK CONFIG
// ─────────────────────────────────────────────────────────────────────────────

interface NetworkConfig {
subnets: string[]; // @regex ^subnet-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
securityGroups: string[]; // @regex ^sg-[0-9a-zA-Z]{8,17}$ @min 1 @max 16
}

// ─────────────────────────────────────────────────────────────────────────────
// AGENT
// ─────────────────────────────────────────────────────────────────────────────
Expand All@@ -43,6 +52,7 @@ interface AgentEnvSpec {
runtimeVersion: RuntimeVersion;
envVars?: EnvVar[];
networkMode?: NetworkMode; // default 'PUBLIC'
networkConfig?: NetworkConfig; // Required when networkMode is 'VPC'
instrumentation?: Instrumentation; // OTel settings
modelProvider?: ModelProvider; // Model provider used by this agent
}
Expand Down
2 changes: 1 addition & 1 deletion src/schema/llm-compacted/mcp.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -145,4 +145,4 @@ interface IamPolicyDocument {
type GatewayTargetType = 'lambda' | 'mcpServer' | 'openApiSchema' | 'smithyModel';
type PythonRuntime = 'PYTHON_3_10' | 'PYTHON_3_11' | 'PYTHON_3_12' | 'PYTHON_3_13';
type NodeRuntime = 'NODE_18' | 'NODE_20' | 'NODE_22';
type NetworkMode = 'PUBLIC' | 'PRIVATE';
type NetworkMode = 'PUBLIC' | 'VPC';
91 changes: 90 additions & 1 deletion src/schema/schemas/__tests__/agent-env.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -7,6 +7,7 @@ import {
EnvVarSchema,
GatewayNameSchema,
InstrumentationSchema,
NetworkConfigSchema,
} from '../agent-env.js';
import { describe, expect, it } from 'vitest';

Expand DownExpand Up@@ -235,13 +236,51 @@ describe('AgentEnvSpecSchema', () => {

it('accepts agent with network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PUBLIC' }).success).toBe(true);
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(true);
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'VPC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(true);
});

it('rejects invalid network mode', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'PRIVATE' }).success).toBe(false);
});

it('rejects VPC mode without networkConfig', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, networkMode: 'VPC' }).success).toBe(false);
});

it('rejects networkConfig without VPC mode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkMode: 'PUBLIC',
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('rejects networkConfig with missing networkMode', () => {
expect(
AgentEnvSpecSchema.safeParse({
...validPythonAgent,
networkConfig: {
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
},
}).success
).toBe(false);
});

it('accepts agent with instrumentation config', () => {
const result = AgentEnvSpecSchema.safeParse({
...validPythonAgent,
Expand All@@ -259,3 +298,53 @@ describe('AgentEnvSpecSchema', () => {
expect(AgentEnvSpecSchema.safeParse({ ...validPythonAgent, name: undefined }).success).toBe(false);
});
});

describe('NetworkConfigSchema', () => {
it('accepts valid network config', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(true);
});

it('accepts multiple subnets and security groups', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678', 'subnet-abcdef12'],
securityGroups: ['sg-12345678', 'sg-abcdef12'],
});
expect(result.success).toBe(true);
});

it('rejects empty subnets array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: [],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects empty security groups array', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: [],
});
expect(result.success).toBe(false);
});

it('rejects invalid subnet format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['invalid-subnet'],
securityGroups: ['sg-12345678'],
});
expect(result.success).toBe(false);
});

it('rejects invalid security group format', () => {
const result = NetworkConfigSchema.safeParse({
subnets: ['subnet-12345678'],
securityGroups: ['invalid-sg'],
});
expect(result.success).toBe(false);
});
});
4 changes: 2 additions & 2 deletions src/schema/schemas/__tests__/mcp.test.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -238,8 +238,8 @@ describe('RuntimeConfigSchema', () => {
}
});

it('accepts explicit PRIVATE networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'PRIVATE' });
it('accepts explicit VPC networkMode', () => {
const result = RuntimeConfigSchema.safeParse({ ...validRuntime, networkMode: 'VPC' });
expect(result.success).toBe(true);
});

Expand Down
67 changes: 51 additions & 16 deletions src/schema/schemas/agent-env.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -103,25 +103,60 @@ export const InstrumentationSchema = z.object({
});
export type Instrumentation = z.infer<typeof InstrumentationSchema>;

/**
* VPC network configuration for agents running in VPC mode.
* Requires at least one subnet and one security group.
*/
export const NetworkConfigSchema = z.object({
subnets: z
.array(z.string().regex(/^subnet-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
securityGroups: z
.array(z.string().regex(/^sg-[0-9a-zA-Z]{8,17}$/))
.min(1)
.max(16),
});
export type NetworkConfig = z.infer<typeof NetworkConfigSchema>;

/**
* AgentEnvSpec - represents an AgentCore Runtime.
* This is a top-level resource in the schema.
*/
export const AgentEnvSpecSchema = z.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
});
export const AgentEnvSpecSchema = z
.object({
type: AgentTypeSchema,
name: AgentNameSchema,
build: BuildTypeSchema,
entrypoint: EntrypointSchema,
codeLocation: DirectoryPathSchema,
runtimeVersion: RuntimeVersionSchemaFromConstants,
/** Environment variables to set on the runtime */
envVars: z.array(EnvVarSchema).optional(),
/** Network mode for the runtime. Defaults to PUBLIC. */
networkMode: NetworkModeSchema.optional(),
/** VPC network configuration. Required when networkMode is VPC. */
networkConfig: NetworkConfigSchema.optional(),
/** Instrumentation settings for observability. Defaults to OTel enabled. */
instrumentation: InstrumentationSchema.optional(),
/** Model provider used by this agent. Optional for backwards compatibility. */
modelProvider: ModelProviderSchema.optional(),
})
.superRefine((data, ctx) => {
if (data.networkMode === 'VPC' && !data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is required when networkMode is VPC',
});
}
if (data.networkMode !== 'VPC' && data.networkConfig) {
ctx.addIssue({
code: 'custom',
path: ['networkConfig'],
message: 'networkConfig is only allowed when networkMode is VPC',
});
}
});

export type AgentEnvSpec = z.infer<typeof AgentEnvSpecSchema>;
Loading