fix(bedrock): drop aws:UserAgent from OIDC web identity session policy

Boto3/botocore and SigV4+httpx do not send User-Agent litellm/*, so the
StringLike condition caused implicit deny on ApplyGuardrail and other
Bedrock calls after AssumeRoleWithWebIdentity. Keep SecureTransport and
Bedrock action allowlist.

Made-with: Cursor
This commit is contained in:
shivam 2026-03-21 15:07:27 -07:00
parent 108c64975c
commit 7a2ec85359

View file

@ -700,7 +700,7 @@ class BaseAWSLLM:
"RoleSessionName": aws_session_name,
"WebIdentityToken": oidc_token,
"DurationSeconds": 3600,
"Policy": '{"Version":"2012-10-17","Statement":[{"Sid":"BedrockLiteLLM","Effect":"Allow","Action":["bedrock:InvokeModel","bedrock:InvokeModelWithResponseStream","bedrock:ApplyGuardrail"],"Resource":"*","Condition":{"Bool":{"aws:SecureTransport":"true"},"StringLike":{"aws:UserAgent":"litellm/*"}}}]}',
"Policy": '{"Version":"2012-10-17","Statement":[{"Sid":"BedrockLiteLLM","Effect":"Allow","Action":["bedrock:InvokeModel","bedrock:InvokeModelWithResponseStream","bedrock:ApplyGuardrail"],"Resource":"*","Condition":{"Bool":{"aws:SecureTransport":"true"}}}]}',
}
# Add ExternalId parameter if provided