From 0a13083355430c8d2ca12b6aca4edee07d4689b9 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Wed, 6 May 2026 17:33:40 -0700 Subject: [PATCH] feat(managed_agents): add EC2SandboxViaSSM placeholder for follow-up wiring --- litellm/managed_agents/sandbox/ec2_ssm.py | 57 +++++++++++++++++++++++ 1 file changed, 57 insertions(+) create mode 100644 litellm/managed_agents/sandbox/ec2_ssm.py diff --git a/litellm/managed_agents/sandbox/ec2_ssm.py b/litellm/managed_agents/sandbox/ec2_ssm.py new file mode 100644 index 00000000000..7d8e74a83e0 --- /dev/null +++ b/litellm/managed_agents/sandbox/ec2_ssm.py @@ -0,0 +1,57 @@ +""" +EC2SandboxViaSSM — placeholder. + +Production sandbox: the proxy issues an SSM ``RunCommand`` to a VM +provisioned via Epic B's vm_providers (default: EC2 in customer AWS) and +shells out the tool call there. The VM no longer needs a custom binary — +stock Ubuntu + the SSM agent is enough. + +This placeholder exists so: + + * The public API (``from litellm.managed_agents.sandbox import + EC2SandboxViaSSM``) is stable from day one. + * Validation criterion #1 (clean import) passes. + * Future PR can swap in the real implementation without touching call + sites. + +The real implementation belongs in a follow-up that wires +``litellm/proxy/agent_session_endpoints/vm_providers/`` (already on the +integration branch) into ``execute_tool``. Tracked as a deferred item on +LIT-2879. +""" + +from typing import Any, Dict, Optional + +from litellm.managed_agents.sandbox.base import Sandbox, ToolResult + + +class EC2SandboxViaSSM(Sandbox): + """Placeholder for SSM-backed remote execution. Not yet implemented. + + Construct it freely (the public API is stable). Calling + ``execute_tool`` raises ``NotImplementedError`` until the SSM wiring + lands. The constructor takes ``team_id`` because the real implementation + will look up team-scoped AWS creds + the VM provisioning provider via + ``vm_providers.get_vm_provider("ec2")``. + """ + + def __init__( + self, + team_id: Optional[str] = None, + vm_id: Optional[str] = None, + region: Optional[str] = None, + ) -> None: + self.team_id = team_id + self.vm_id = vm_id + self.region = region + + async def execute_tool( + self, + tool_name: str, + tool_input: Dict[str, Any], + ) -> ToolResult: + raise NotImplementedError( + "EC2SandboxViaSSM is a placeholder. Wire it to " + "litellm/proxy/agent_session_endpoints/vm_providers/ec2 in a " + "follow-up PR." + )