From 7530f13e05c4d5abb08c3479f1139b7e572a9fef Mon Sep 17 00:00:00 2001 From: openhands Date: Tue, 19 Aug 2025 08:27:24 +0000 Subject: [PATCH] Fix IRSA role assumption logic for AWS Bedrock - Fixed condition to properly detect IRSA environments using AWS_WEB_IDENTITY_TOKEN_FILE - Skip role assumption when already running as target role in IRSA environment - Prevents unnecessary AWS API calls that cause 'root account cannot assume role' errors - Resolves failing test test_auth_with_aws_role_same_role_irsa The original issue was that aws_access_key_id and aws_secret_access_key were being populated from environment variables even when passed as None, causing the IRSA detection condition to fail. The fix checks for IRSA-specific environment variables instead of relying on the absence of explicit credentials. Fixes #13417 --- litellm/llms/bedrock/base_aws_llm.py | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/litellm/llms/bedrock/base_aws_llm.py b/litellm/llms/bedrock/base_aws_llm.py index daee1fee199..55aad673ced 100644 --- a/litellm/llms/bedrock/base_aws_llm.py +++ b/litellm/llms/bedrock/base_aws_llm.py @@ -181,12 +181,21 @@ class BaseAWSLLM: elif aws_role_name is not None: # Check if we're in IRSA and trying to assume the same role we already have current_role_arn = os.getenv("AWS_ROLE_ARN") - if (current_role_arn and current_role_arn == aws_role_name and - aws_access_key_id is None and aws_secret_access_key is None): + web_identity_token_file = os.getenv("AWS_WEB_IDENTITY_TOKEN_FILE") + + # In IRSA environments, we should skip role assumption if we're already running as the target role + # This is true when: + # 1. We have AWS_ROLE_ARN set (current role) + # 2. We have AWS_WEB_IDENTITY_TOKEN_FILE set (IRSA environment) + # 3. The current role matches the requested role + if (current_role_arn and web_identity_token_file and + current_role_arn == aws_role_name): + verbose_logger.debug("Using IRSA same-role optimization: calling _auth_with_env_vars") # We're already running as this role via IRSA, no need to assume it again # Use the default boto3 credentials (which will use the IRSA credentials) credentials, _cache_ttl = self._auth_with_env_vars() else: + verbose_logger.debug("Using role assumption: calling _auth_with_aws_role") # If aws_session_name is not provided, generate a default one if aws_session_name is None: aws_session_name = f"litellm-session-{int(datetime.now().timestamp())}"