mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-07 02:59:05 +00:00
fix(bedrock): drop aws:UserAgent from OIDC web identity session policy
Boto3/botocore and SigV4+httpx do not send User-Agent litellm/*, so the StringLike condition caused implicit deny on ApplyGuardrail and other Bedrock calls after AssumeRoleWithWebIdentity. Keep SecureTransport and Bedrock action allowlist. Made-with: Cursor
This commit is contained in:
parent
108c64975c
commit
7a2ec85359
1 changed files with 1 additions and 1 deletions
|
|
@ -700,7 +700,7 @@ class BaseAWSLLM:
|
|||
"RoleSessionName": aws_session_name,
|
||||
"WebIdentityToken": oidc_token,
|
||||
"DurationSeconds": 3600,
|
||||
"Policy": '{"Version":"2012-10-17","Statement":[{"Sid":"BedrockLiteLLM","Effect":"Allow","Action":["bedrock:InvokeModel","bedrock:InvokeModelWithResponseStream","bedrock:ApplyGuardrail"],"Resource":"*","Condition":{"Bool":{"aws:SecureTransport":"true"},"StringLike":{"aws:UserAgent":"litellm/*"}}}]}',
|
||||
"Policy": '{"Version":"2012-10-17","Statement":[{"Sid":"BedrockLiteLLM","Effect":"Allow","Action":["bedrock:InvokeModel","bedrock:InvokeModelWithResponseStream","bedrock:ApplyGuardrail"],"Resource":"*","Condition":{"Bool":{"aws:SecureTransport":"true"}}}]}',
|
||||
}
|
||||
|
||||
# Add ExternalId parameter if provided
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue