mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-10 03:30:59 +00:00
Adds **Amazon Bedrock** as an opt-in built-in provider, over Bedrock's unified **Converse / ConverseStream** API. One codec serves every Converse-capable family — Claude, Amazon Nova, Meta Llama, Mistral, DeepSeek, Moonshot Kimi, Z.AI GLM, MiniMax, NVIDIA Nemotron, and OpenAI gpt-oss — because AWS translates the envelope to each model's native dialect server-side. Auth is either **AWS SigV4** (the default credential chain — env / profile / IMDS / IRSA / SSO, resolved per request so sessions refresh) or a **Bedrock API key** (`AWS_BEARER_TOKEN_BEDROCK`, bearer). Disabled by default (the Ollama / OpenRouter opt-in pattern). This is the redo of #459's original Claude-only `InvokeModel` adapter, rebuilt on the gateway-refactor seams (#481–#497). @depopry's SigV4 signer, AWS event-stream frame decoder, `BedrockAuth`, the `aws_sigv4` credential grammar, `AdapterKind::Bedrock`, region-from-base_url, and the lean-deps decision are preserved and authored by him on the first two commits; the per-family `BedrockCodec` trait he wrote turned out to be the crate-wide `Codec` seam in miniature, so the refactor promoted exactly that shape. The original Claude-only description is preserved in a comment below. ## What's here - **`AdapterKind::Bedrock` × `CodecKind::BedrockConverse`** on the route, plus the `aws_sigv4` credential source (no static secret — the adapter signs at request time; `fabro-auth` stays AWS-free). *(@depopry)* - **SigV4 signer + AWS event-stream `FrameDecoder`** on the lean AWS stack (no `aws-sdk-bedrockruntime`; transport stays on `fabro-http`). Re-targeted at Converse's direct-JSON stream frames; the signer resolves credentials per request. *(@depopry)* - **`bedrock_converse` codec** — Converse envelope (`system[]`, typed content blocks, `inferenceConfig`, `toolConfig`), prompt caching via `cachePoint`, thinking-signature round-trip through `reasoningContent`, usage mapped onto the disjoint `TokenCounts` buckets, `provider_options.bedrock` passthrough. Plus the adapter shell and an event-stream byte loop beside the transport's shared SSE loop. - **Catalog**: `bedrock.toml` (Claude incl. Fable 5, Nova 2, Llama 4, Mistral, DeepSeek, Kimi, GLM, MiniMax, Nemotron, gpt-oss — cross-region inference-profile ids, per-model `billing_policy` so Claude bills Anthropic-style) and a companion **`bedrock-openai`** provider for GPT-5.5/5.4 over the `bedrock-mantle` Responses endpoint (pure config over the existing `openai_responses` codec, zero new code). - Secrets registry (`AWS_BEARER_TOKEN_BEDROCK`), gitleaks rules for both Bedrock key formats, the `docs/integrations/bedrock` guide, and live e2e tests. ## Live verification (confirmed end-to-end against a real AWS account) Verified on a real Bedrock account (us-east-2, SigV4 + bearer): - **SigV4 + Converse** — multiple families (Claude, Nova, DeepSeek, …) via the full settings → catalog → route → adapter → codec path. - **ConverseStream** — streaming deltas through the workflow engine. - **Multi-turn tool use** — agent loop with tool calls round-tripping (no-arg tools included). - **Multi-model routing** — Claude + DeepSeek pinned in one run through the single Converse codec. - **mantle Responses** — `openai.gpt-5.5` answered via the `bedrock-openai` provider (bearer auth). The exercise caught and fixed several issues that unit tests (static creds, mocked transports) could not — see the follow-up commits below. ## Follow-up fixes from live testing (commits on top of the foundation) 1. **Worker AWS env** — the workflow worker scrubs its env to an allowlist, so SigV4 (which re-resolves from the ambient chain per request) couldn't work through `fabro run`. The AWS credential-chain inputs now cross into the worker. 2. **Vault bearer key** — Bedrock was the only key-based provider missing a `vault:` credential ref, so `fabro secret set AWS_BEARER_TOKEN_BEDROCK` silently didn't feed it. Now resolves env → vault → SigV4. 3. **Converse tool-encoding hardening** — a no-arg tool call's `toolUse.input` is now a `{}` object (Bedrock rejects null), and every tool `inputSchema` gets a top-level `type: "object"` (strict families like DeepSeek reject a typeless schema Claude tolerates). 4. **Nova output cap** — `amazon.nova-2-lite` max_output 65536 → 65535 (Bedrock's per-request limit). Earlier fixes already folded into the foundation commits: the `aws-config` sleep-impl (default chain panicked) and AWS error-body decoding (top-level `message`/`Message`/`__type` → proper messages instead of "Unknown error"). ## Manual testing & setup See `docs/integrations/bedrock` — now documents the non-obvious account setup that live testing surfaced: the per-Region Anthropic use-case approval, `aws-marketplace:Subscribe` for third-party models, the Fable 5 / Mythos-class data-sharing opt-in, and the bearer-vs-SigV4 precedence override for running Converse + mantle side by side. ## Open decision / discussion - **Model-id naming** — Bedrock rows use dotted ids mirroring Bedrock's native inference-profile ids (`us.anthropic.claude-sonnet-4-6`, `openai.gpt-5.5`), which also makes them the wire `api_id`. Third scheme alongside bare ids and OpenRouter's `vendor/model` slashes. No collision risk (enforced at catalog build). Open to a uniform scheme if preferred. - **`BEDROCK_API_KEY` alias** — see the comment thread; the AWS console hands some users `export BEDROCK_API_KEY=` while the SDK-standard var is `AWS_BEARER_TOKEN_BEDROCK`. Question of whether to accept both. ## Deferred (named follow-ups) - **`qwen.qwen3-coder-next`** — omitted pending a verified Bedrock model/inference-profile id (its fabro id isn't a valid Bedrock identifier; needs an explicit `api_id`). Re-add once confirmed via `aws bedrock list-inference-profiles`. - **Claude Mythos 5** — Anthropic-Messages-only on `bedrock-mantle` (limited preview). - **Converse structured output** (`response_format` rejected with a clear error). - **`reasoning_effort` on Converse rows** via `additionalModelRequestFields` (the `bedrock-openai` GPT rows already accept effort levels). - **CountTokens** route (`count_input_tokens` returns `None`). ## Verification `cargo nextest run --workspace`: green except the pre-existing environment-dependent fabro-workflow failures (identical on main). clippy `-D warnings` + pinned-nightly fmt clean. Codec unit tests + adapter httpmock tests + frame-decoder/signer locks. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Scott Werner <scott@sublayer.com> Co-authored-by: Scott Werner <stwerner@vt.edu>
172 lines
5.7 KiB
TOML
172 lines
5.7 KiB
TOML
[workspace]
|
|
members = ["lib/crates/*", "test/twin/openai", "test/twin/github"]
|
|
default-members = ["lib/crates/fabro-cli"]
|
|
resolver = "2"
|
|
|
|
[workspace.package]
|
|
edition = "2021"
|
|
version = "0.260.0-nightly.0"
|
|
license = "MIT"
|
|
|
|
[workspace.dependencies]
|
|
agent-client-protocol = { version = "0.11.1", features = ["unstable_session_usage"] }
|
|
agent-client-protocol-tokio = "0.11.1"
|
|
anyhow = "1"
|
|
axum = { version = "0.8" }
|
|
axum-extra = { version = "0.10", features = ["cookie-private", "query"] }
|
|
cookie = { version = "0.18", features = ["percent-encode", "private", "signed", "key-expansion"] }
|
|
croner = "3.0.1"
|
|
thiserror = "2"
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = { version = "1", features = ["preserve_order"] }
|
|
tokio = { version = "1", features = ["full"] }
|
|
reqwest = { version = "0.13", default-features = false, features = ["json", "stream", "rustls", "query", "form", "multipart"] }
|
|
sse-stream = "0.2"
|
|
ulid = "1"
|
|
uuid = { version = "1", features = ["v4", "v7", "v8"] }
|
|
rand = "0.9"
|
|
dotenvy = "0.15"
|
|
futures = "0.3"
|
|
tokio-stream = "0.1"
|
|
async-trait = "0.1"
|
|
fs2 = "0.4"
|
|
base64 = "0.22"
|
|
bytes = "1"
|
|
tokio-util = "0.7"
|
|
# AWS building blocks for the native Bedrock adapter. Lean stack: request
|
|
# signing + credential chain + event-stream decode only. Transport for the
|
|
# actual Bedrock inference calls stays on fabro-http; the full
|
|
# aws-sdk-bedrockruntime (and its parallel hyper stack) is not pulled in.
|
|
# aws-config keeps its DEFAULT features on purpose: `rt-tokio` supplies the
|
|
# TokioSleep impl the credential chain's retry requires (without it,
|
|
# resolving the default chain panics with "an async sleep implementation is
|
|
# required"), and `sso`/`credentials-process` make from_default_chain's
|
|
# documented SSO/credential-process support real. `rustls` pins the TLS
|
|
# backend for credential-resolution HTTP.
|
|
aws-config = { version = "1", features = ["behavior-version-latest", "rustls"] }
|
|
aws-credential-types = { version = "1", features = ["hardcoded-credentials"] }
|
|
aws-sigv4 = "1"
|
|
aws-smithy-eventstream = "0.60"
|
|
aws-smithy-runtime-api = "1"
|
|
aws-smithy-types = "1"
|
|
clap = { version = "4", features = ["derive", "env"] }
|
|
clap_complete = "4"
|
|
jsonschema = { version = "0.42", default-features = false }
|
|
chrono = { version = "0.4", features = ["clock", "serde"] }
|
|
dashmap = "6"
|
|
bollard = "0.18"
|
|
tar = "0.4"
|
|
cli-table = { version = "0.5", default-features = false }
|
|
console = "0.15"
|
|
dialoguer = "0.12"
|
|
git2 = { version = "0.20", default-features = false, features = ["vendored-libgit2", "vendored-openssl", "https"] }
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["fmt", "env-filter"] }
|
|
tracing-appender = "0.2"
|
|
rmcp = { version = "1.4", default-features = false }
|
|
walkdir = "2"
|
|
regex = "1"
|
|
semver = "1"
|
|
aho-corasick = "1"
|
|
globset = "0.4"
|
|
dirs = "6"
|
|
mac_address = "1"
|
|
md5 = "0.7"
|
|
mime_guess = "2"
|
|
indicatif = "0.18"
|
|
termimad = "0.34"
|
|
toml = "0.8"
|
|
toml_edit = "0.22"
|
|
jsonwebtoken = { version = "10", features = ["aws_lc_rs"] }
|
|
hkdf = "0.12"
|
|
hmac = "0.12"
|
|
sha2 = "0.10"
|
|
hex = "0.4"
|
|
insta = "1"
|
|
fabro-test = { path = "lib/crates/fabro-test" }
|
|
twin-openai = { path = "test/twin/openai" }
|
|
twin-github = { path = "test/twin/github" }
|
|
tokio-tungstenite = { version = "0.26", features = ["rustls-tls-webpki-roots"] }
|
|
futures-util = "0.3"
|
|
daytona-sdk = { git = "https://github.com/brynary/daytona-sdk-rust", rev = "fc58e22f7f25183df6264276ee186bbc32635738", package = "daytona-sdk" }
|
|
daytona-api-client = { git = "https://github.com/brynary/daytona-sdk-rust", rev = "fc58e22f7f25183df6264276ee186bbc32635738", package = "daytona-api-client" }
|
|
sentry = { version = "0.35", default-features = false, features = ["backtrace", "contexts", "ureq", "rustls"] }
|
|
fork = "0.2"
|
|
exec = "0.3"
|
|
slatedb = { version = "0.11.2", features = ["zstd"] }
|
|
object_store = { version = "0.12.5", features = ["aws"] }
|
|
rust-embed = "8"
|
|
percent-encoding = "2"
|
|
minijinja = "=2.19.0"
|
|
miette = { version = "7.6", features = ["fancy"] }
|
|
fabro-http = { path = "lib/crates/fabro-http" }
|
|
fabro-environment = { path = "lib/crates/fabro-environment" }
|
|
fabro-options-metadata = { path = "lib/crates/fabro-options-metadata" }
|
|
fabro-redact = { path = "lib/crates/fabro-redact" }
|
|
fabro-static = { path = "lib/crates/fabro-static" }
|
|
graphviz-sys = { git = "https://github.com/fabro-sh/graphviz-sys" }
|
|
ref-cast = "1"
|
|
strum = { version = "0.28", features = ["derive"] }
|
|
url = "2"
|
|
zeroize = "1"
|
|
|
|
[workspace.lints.rust]
|
|
unsafe_code = "deny"
|
|
unreachable_pub = "warn"
|
|
|
|
[workspace.lints.clippy]
|
|
pedantic = { level = "warn", priority = -2 }
|
|
allow_attributes_without_reason = "warn"
|
|
# Allowed pedantic lints
|
|
implicit_hasher = "allow"
|
|
missing_errors_doc = "allow"
|
|
missing_panics_doc = "allow"
|
|
module_name_repetitions = "allow"
|
|
must_use_candidate = "allow"
|
|
similar_names = "allow"
|
|
struct_excessive_bools = "allow"
|
|
too_many_arguments = "allow"
|
|
too_many_lines = "allow"
|
|
cast_precision_loss = "allow"
|
|
doc_markdown = "allow"
|
|
# Disallowed restriction lints
|
|
print_stdout = "warn"
|
|
print_stderr = "warn"
|
|
dbg_macro = "warn"
|
|
empty_drop = "warn"
|
|
empty_structs_with_brackets = "warn"
|
|
disallowed_methods = "deny"
|
|
exit = "warn"
|
|
get_unwrap = "warn"
|
|
unwrap_used = "deny"
|
|
rc_buffer = "warn"
|
|
rc_mutex = "warn"
|
|
rest_pat_in_fully_bound_structs = "warn"
|
|
use_self = "warn"
|
|
# Project-specific lints
|
|
wildcard_imports = "warn"
|
|
absolute_paths = "warn"
|
|
|
|
[profile.release]
|
|
lto = "thin"
|
|
strip = true
|
|
|
|
[profile.dev]
|
|
debug = "line-tables-only"
|
|
split-debuginfo = "off"
|
|
|
|
[profile.test]
|
|
debug = "line-tables-only"
|
|
split-debuginfo = "off"
|
|
|
|
[profile.dev.package."*"]
|
|
debug = false # Disable debug info for all dependencies
|
|
opt-level = 1 # Shrinks monomorphized generics, reducing test binary size
|
|
|
|
# regex is extremely slow in debug builds (~10s to compile gitleaks patterns)
|
|
[profile.dev.package.regex]
|
|
opt-level = 2
|
|
[profile.dev.package.regex-automata]
|
|
opt-level = 2
|
|
[profile.dev.package.regex-syntax]
|
|
opt-level = 2
|