fix(bedrock_guardrails): warn when _normalize_checks receives unknown keys

Previously, unrecognized check keys (e.g. snake_case typos like
`content_filter` instead of `contentFilter`) were silently dropped,
causing the guardrail to fall back to ApplyGuardrail mode without any
indication. Now logs a WARNING listing the unknown keys and the valid
set, so operators can catch misconfigurations before they reach Bedrock.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Sameer Kankute 2026-06-25 12:16:00 +05:30
parent 6916277174
commit ca1d2d01e4
No known key found for this signature in database
2 changed files with 26 additions and 0 deletions

View file

@ -265,6 +265,14 @@ class BedrockGuardrail(CustomGuardrail, BaseAWSLLM):
checks = checks.model_dump(exclude_none=True)
if not isinstance(checks, dict):
return None
unknown_keys = set(checks.keys()) - _BEDROCK_CHECKS_KNOWN_KEYS
if unknown_keys:
verbose_proxy_logger.warning(
"BedrockGuardrail: unrecognized check key(s) %s will be ignored. "
"Known keys: %s. Guardrail will fall back to ApplyGuardrail mode.",
sorted(unknown_keys),
sorted(_BEDROCK_CHECKS_KNOWN_KEYS),
)
cleaned = {
key: value
for key, value in checks.items()

View file

@ -20,6 +20,24 @@ def test_bedrock_normalize_checks_keeps_empty_known_check_config():
}
def test_bedrock_normalize_checks_warns_on_unknown_keys(caplog):
import logging
with caplog.at_level(logging.WARNING, logger="LiteLLM Proxy"):
result = BedrockGuardrail._normalize_checks({"contentFilter": {}, "typo_key": True})
assert result == {"contentFilter": {}}
assert any("typo_key" in m for m in caplog.messages)
def test_bedrock_normalize_checks_all_unknown_returns_none_with_warning(caplog):
import logging
with caplog.at_level(logging.WARNING, logger="LiteLLM Proxy"):
result = BedrockGuardrail._normalize_checks({"snake_case_typo": True})
assert result is None
assert any("snake_case_typo" in m for m in caplog.messages)
@pytest.mark.asyncio
async def test_bedrock_guardrails_pii_masking():
# Create proper mock objects