fix(bedrock): grant the AgentCore for-user invoke action in the web identity session policy

The chat and A2A AgentCore handlers send X-Amzn-Bedrock-AgentCore-Runtime-User-Id
when runtimeUserId is set, and AWS requires bedrock-agentcore:InvokeAgentRuntimeForUser
alongside InvokeAgentRuntime on that call, so the ceiling now carries both. The role
identity policy still decides whether a given role may use it

The invalid-token test now uses a neutral example audience
This commit is contained in:
mateo-berri 2026-09-14 21:31:45 -07:00
parent 0a0a9509dc
commit 1111658e16
2 changed files with 5 additions and 1 deletions

View file

@ -133,6 +133,7 @@ _WEB_IDENTITY_SESSION_POLICY_ACTIONS: Final[Mapping[str, tuple[str, ...]]] = Map
),
"BedrockAgentCoreLiteLLM": (
"bedrock-agentcore:InvokeAgentRuntime",
"bedrock-agentcore:InvokeAgentRuntimeForUser",
"bedrock-agentcore:InvokeGateway",
),
"ClaudePlatformLiteLLM": (

View file

@ -230,7 +230,7 @@ class TestInvalidIdentityTokenSurfacesAudience:
operator can diagnose the mismatch without enabling LITELLM_LOG=DEBUG on a
prod instance."""
_AUD = "https://guidepoint.litellm-prod.ai"
_AUD = "https://gateway.example.com"
_ISS = "https://accounts.google.com"
_STS_MESSAGE = (
"An error occurred (InvalidIdentityToken) when calling the "
@ -322,6 +322,9 @@ _BEDROCK_ROUTE_ACTIONS: Final = MappingProxyType(
"knowledgebases": "bedrock:ListKnowledgeBases",
"agents/{agent_id}/agentAliases/{alias_id}/sessions/{session_id}/text": "bedrock:InvokeAgent",
"runtimes/{agent_runtime_arn}/invocations": "bedrock-agentcore:InvokeAgentRuntime",
"runtimes/{agent_runtime_arn}/invocations with X-Amzn-Bedrock-AgentCore-Runtime-User-Id": (
"bedrock-agentcore:InvokeAgentRuntimeForUser"
),
"mcp": "bedrock-agentcore:InvokeGateway",
}
)