Repository navigation
Conversation
The `agentcore create` and `agentcore add runtime` wizards scaffolded every model-aware template with its Bedrock default: provider, model id and API key were flag-only (--model-provider / --model-id / --api-key). Add a `model provider` step, shown exactly for templates whose shortcut has supportsModelProviderOverride, mirroring the harness wizard's model step: provider radio → model id (prefilled from the shared default table) → API key file for the providers that need one. The answer is handed to resolveRuntimeTemplateShortcut as the same overrides the flags supply, so the wizard converges on the flag path's ScaffoldRuntimeInput (the default model id is not sent as an override). The API key is taken as a `file://` source and read at submit through the same SourceResolver as --api-key; a screen has no stdin, so '-' and inline values are refused with the resolver's messages. In a China region the step starts on LiteLLM with no model id (the LiteLLM default routes to Amazon Bedrock) and annotates the four blocked providers; the existing create/add gates remain the enforcement. The create handler's China memory strip moves into a shared helper so the wizard drops the default memory the same way the CLI does. DEFAULT_MODEL_IDS moves next to MODEL_PROVIDERS in projectSchemas/runtime so the wizard and the template renderer read one table.
…ds templates a2a-python-strands and agui-python-strands hardcoded the Bedrock model: their model/load.py was agent-python-strands' Bedrock branch with the id inlined, pyproject pinned plain strands-agents, and the shortcuts declared no override, so --model-provider/--model-id/--api-key (and now the wizard's model step) were refused. In a China region that left them unusable — the gates treat an override-less model template as Bedrock. Give both templates the strands model module (provider branches, safeJson model id, requires_api_key identity decorator) and the per-provider strands-agents[extra] dependency block, and flip supportsModelProviderOverride. The A2A resolver already wired the API-key credential scaffold but did not pass modelProvider/modelId to the renderer; the AG-UI resolver did neither — both now render and merge the model scaffold exactly like the HTTP strands template. Bedrock scaffolds are unchanged byte for byte. `--model-provider lite_llm --model-id deepseek/deepseek-chat` is now the China route for A2A and AG-UI agents, same as for agent-python-strands.
…pt strands providers Add `--api-base <url>` to `agentcore create` and `agentcore add runtime`, valid with `--model-provider open_ai`: it points the OpenAI client at any OpenAI-compatible endpoint instead of api.openai.com (Python: client_args base_url; TypeScript: clientConfig.baseURL). The URL is persisted as the runtime's `modelApiBase` in agentcore.json, next to modelProvider/modelId, so the deploy-time China gate can classify it. Other providers reject the flag — they keep their own APIs, and one escape hatch (plus LiteLLM) covers every OpenAI-format vendor. China (aws-cn): an OpenAI runtime pointed at a base URL passes the create, add and deploy gates; one without is refused (api.openai.com is not reachable). The three gates now share one rule, chinaModelProviderRestriction, so they cannot drift. Enable model-provider overrides on agent-typescript-strands. model/load.ts becomes a provider-branched template (Bedrock, Anthropic, OpenAI, Gemini via @strands-agents/sdk models/*), the API key is fetched through bedrock-agentcore/identity withApiKey in a new model/apiKey.ts (rendered only for API-key providers; LOCAL_DEV reads .env.local like the Python templates), and the provider's SDK peer dependency is added to package.json conditionally. LiteLLM is a Python library, so `lite_llm` is refused for TypeScript templates with a pointer to open_ai + --api-base; the wizard does not offer it there. Wizard: the model step gains an "API base URL" field for openai (optional, required in China regions); in China a TypeScript template starts on openai with an empty model id, a Python template on litellm as before.
… export telemetry Every pinned Python template carried `aws-opentelemetry-distro ~= 0.18.0` (langchain `~= 0.19.0`). Those releases build the default OTLP endpoints as `https://logs.<region>.amazonaws.com/v1/logs` (and the xray equivalent) whenever the runtime injects none — the AgentCore Runtime only injects endpoints on its local-collector path — so an agent in cn-north-1 or cn-northwest-1 logs a NameResolutionError on every export and delivers no logs or traces. 0.21.0 (2026-10-01) derives the partition suffix from the region (`amazonaws.com.cn` for `cn-*`) and accepts it in its endpoint patterns. Move all seven pinned templates to `~= 0.21.0`. Resolution verified with `uv lock` for the strands (LiteLLM) and langchain templates (opentelemetry-api 1.44.0, opentelemetry-instrumentation-langchain 0.62.4). bedrock-managed-agents was already unpinned.
FastAPI 0.142 configures OTLP export from the OTEL_* environment at
ASGI lifespan startup and adds its own exporters to the providers the
OpenTelemetry distro already set up. On the AgentCore Runtime the
distro signs its requests with SigV4; FastAPI's exporters do not, so
every trace and log batch was sent twice and the unsigned copy failed
with 403 MissingAuthenticationTokenException after each invocation.
ag_ui_strands.create_strands_app takes no FastAPI options, so the
AG-UI template now assembles the same app itself with
telemetry={"auto_configure": False}: the CORS middleware, the AG-UI
endpoint at /invocations, and /ping. fastapi is pinned to >= 0.142,
where the telemetry argument exists. The other templates are Starlette
apps and are unaffected.
|
Claude Security Review: no high-confidence findings. (run) |
There was a problem hiding this comment.
AgentCore Harness Review
Verdict: Looks good
Reviewed the five commits as a unit. The changes hang together: supportsModelProviderOverride is extended consistently (A2A, AG-UI, TypeScript strands), the shortcut resolver, scaffold schema, flag handlers, both wizards, the AG-UI app assembly fix, the OTel distro bump, and the China gates all move in lockstep. A few things I specifically looked for and liked:
- Gates share one rule.
chinaModelProviderRestrictionis used byvalidateCreateRegionSupport,FsProjectManager.addResource, and the deploy gate uses the same classification againstmodelApiBasepersisted inagentcore.json. No chance of the three places drifting. - Secret handling. The TUI never holds the API key — only the
file://source; the key is resolved viaSourceResolverat submit, so wizard output matches the--api-keyflag path. The review surface asserts the raw key is not rendered. - Scaffold parity. Both wizards hand the answer to
resolveRuntimeTemplateShortcut, and tests assert byte-for-byte equivalence with the flag path (inputsdeep-equals the shortcut result; default model id intentionally not sent as an override). - AG-UI fix is targeted. Replacing
create_strands_appwith explicitFastAPI(..., telemetry={"auto_configure": False})+add_strands_fastapi_endpoint/add_ping+fastapi >= 0.142is the smallest change that stops the double-export, and the test asserts both the pin and the absence ofcreate_strands_app(. - Memory module is always rendered now (previously filtered out when the scaffold had no memory). I confirmed
a2a-python-strands/memory/session.pyandagent-typescript-strands/memory/memory.tsboth returnNone/nullwhen the env var is missing, so the China path is unchanged behaviorally and the comment is accurate. - Tests use real temp dirs and real file I/O, no excessive mocking at module boundaries; the new tests (API-key file resolution, provider switching, China deploy gate for OpenAI with/without
modelApiBase, AG-UI assembly) exercise the actual scaffolder and project manager.
No telemetry instrumentation gap: this repo records command paths centrally in router/router.tsx (recordCommandPath), not per-handler, so there is nothing new to wire in the create/add handlers.
Nothing blocking from me. 🚢
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## refactor #2507 +/- ##
============================================
+ Coverage 97.39% 97.44% +0.04%
============================================
Files 642 644 +2
Lines 46910 47663 +753
============================================
+ Hits 45689 46446 +757
+ Misses 1221 1217 -4 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
When a value typed into a model-step field wraps onto a second row, the field grows and the content overflows the viewport by that row. The scroll-into-view callback then scrolled down, the measured viewport grew by exactly the offset scrolled, the callback re-derived its target from the anchor and scrolled back, the viewport shrank again — until React stopped it with "Maximum update depth exceeded" and the wizard went blank. CI hit it on macOS and Windows, whose temp paths are long enough for the file:// API-key path to wrap at 100 columns. The callback now scrolls back toward the anchor only if the field fits there after discounting the rows the viewport gained from the offset, otherwise stays put when the field is fully visible, and scrolls forward by the usual amount. Fields revealed before the viewport was measured still re-anchor once it has grown. Same change in the harness wizard's model field, which shares the callback. The two file:// tests compare the review row with whitespace removed, since the long path wraps there too, and a new test types a path that wraps.
|
Claude Security Review: no high-confidence findings. (run) |
Codecov on #2507 flagged the runtime model step's esc-on-the-list, arrow moves between fields, and the return-to-a-missing-field branch as untested. One wizard test walks all three.
|
Claude Security Review: no high-confidence findings. (run) |
Diffing every template's output against the pre-PR CLI showed three
rendering artifacts next to the intended changes:
- The TypeScript strands model module rendered its ids through safeJson
and so switched to double quotes, unlike the rest of that template. A
jsStr helper renders single-quoted string literals instead.
- The Python strands load.py left a stray space before the closing
brace when no --api-base was given ({{/if}} }). Handlebars reads }}}
as an unescaped close, so the space can only go with whitespace
control: {{/if~}} }.
- The strands-agents extras conditional in pyproject.toml rendered a
whitespace-only line (pre-existing for agent-python-strands, copied to
the A2A and AG-UI templates). It is now one line.
Default (Bedrock) scaffolds of every template and the pre-existing flag
paths now differ from the base CLI only by the distro pin, the AG-UI
FastAPI change, and the async TypeScript model loader.
|
Claude Security Review: no high-confidence findings. (run) |
`agentcore create --region cn-north-1` drops the strands template's default memory with a notice, but `agentcore add runtime` in that project before its first deploy added one back silently, and the deploy then failed with "'memories' in agentcore.json is not available in China regions". The add gate decided "China" from the project's deployment targets alone, and a never-deployed project has none, so the whole China block — memory drop, model-provider refusal, unsupported-family and connector refusals — was skipped until deploy. Reproduced with the TUI wizard on 2026-10-05. addResource now takes the CLI's resolved region as an option, the same way deploy synthesizes the default target from it: a defined target always wins, and the region stands in only while the project has no target at all, so a project with commercial targets is never treated as China by an ambient AWS_REGION. The flag path and every add wizard pass it. Messages and the deploy gate are unchanged; docs/china-regions.md states the new rule.
|
Claude Security Review: no high-confidence findings. (run) |
Resolves the conflict with #2511 (A2A template pins) in src/assets/templates/a2a-python-strands/pyproject.toml: take upstream's new pins (a2a-sdk 0.3.26, bedrock-agentcore 1.24, botocore 1.43.107, strands-agents 1.57.2) and keep this branch's aws-opentelemetry-distro 0.21 bump and the per-provider strands-agents extra. The two tests that spell out the A2A dependency list follow the merged values; the AG-UI template keeps its open strands range.
|
Claude Security Review: no high-confidence findings. (run) |
`bun audit` started failing on a newly published advisory against the transitive dev dependency source-map-js@1.2.1 (vitest > vite > postcss), an event-loop denial of service in indexed source-map handling. 1.2.2 is the patched release and sits inside postcss's ^1.2.1 range, so this is a lockfile-only bump via `bun audit fix`; no runtime or shipped code changes.
|
Claude Security Review: no high-confidence findings. (run) |
Conflicts resolved:
- .github/workflows/verify.yml: take refactor's `bun run audit` (the
braces GHSA ignore now lives in package.json's audit script).
- a2a/agui model/load.py, agent-typescript-strands model/load.ts: keep the
templated `{{safeJson modelId}}` / `{{jsStr modelId}}` lines; the default
model id comes from DEFAULT_MODEL_IDS in projectSchemas/runtime.ts.
- core/project/templates/runtime.ts: drop refactor's new DEFAULT_MODEL_IDS
block (this branch already imports the table from projectSchemas) and bump
that table to refactor's refreshed ids (claude-sonnet-5-5, gpt-6.1-sol,
gemini-3.8-flash, bedrock/global.anthropic.claude-sonnet-5-5).
- create.screen.test.tsx: take the refreshed harness default id, keep the
strands Bedrock id constant.
Follow-ups in the same merge: the create wizard's kind step now preselects
config-based (#2524), so this branch's code-based walks press down first;
command.md regenerated (logs rename, add-menu ordering, China notes).
|
Claude Security Review: no high-confidence findings. (run) |
Description
Lets every strands template reach any model provider, from the wizard as well as from flags, and
adds a provider for OpenAI-compatible endpoints so users in regions without Bedrock (aws-cn) have a
working path for Python and TypeScript alike. Along the way it fixes the defects that surfaced
while verifying those paths end to end in cn-north-1.
The wizards ask for a model provider
agentcore createandagentcore add runtimegain a model provider step for every templatethat accepts
--model-provider(the five strands templates). The step mirrors the harness wizard's:a provider radio, the model id prefilled from the shared default table, the API key as a
file://<path>source (resolved at submit through the sameSourceResolveras--api-key), and forthe OpenAI-compatible provider the endpoint's base URL. The answer is handed to the same
resolveRuntimeTemplateShortcutoverrides the flags use, so wizard and flags produce the sameScaffoldRuntimeInputbyte for byte (golden parity tests). Templates without an override keepskipping the step.
Every strands template takes the overrides
a2a-python-strands,agui-python-strandsandagent-typescript-strandswere Bedrock-only. Theynow render the same provider branches as
agent-python-strands. The TypeScript template gets@strands-agents/sdkmodels/anthropic|openai|google|bedrock, an identity-backedmodel/apiKey.ts(
bedrock-agentcore/identitywithApiKey;LOCAL_DEV=1reads.env.local) and the provider'sclient as a conditional dependency. LiteLLM is a Python library, so TypeScript templates are not
offered it; they are pointed at the OpenAI-compatible provider instead. Bedrock output of all
three templates is unchanged, verified by diffing scaffolds against the published rc.5.
New provider:
openai_compatible--model-provider openai_compatible(alsoopenai-compatible,OpenAICompatible) is the OpenAIclient pointed at a user-chosen endpoint: DeepSeek, Qwen, a self-hosted vLLM. It requires
--api-base <url>and--model-id <model>, because nothing is known about the endpoint until theuser names it;
--api-baseis refused with every other provider.open_aikeeps meaningapi.openai.com and its scaffold is byte-identical to today's. Python renders
client_args={"api_key": …, "base_url": …}, TypeScriptclientConfig: { baseURL: … }.agentcore.jsonrecordsmodelProvider: "OpenAICompatible", so the deploy-time China gate canclassify the runtime from the provider alone. An endpoint that ignores authentication still takes an
--api-keyfile with any placeholder value (documented). A dedicated provider was chosen overopen_ai --api-basebecause that mislabels the runtime inagentcore.json, in the gate and in thewizard, and over mapping
lite_llmonto the OpenAI client for TypeScript, which would mislabel thegenerated code.
China regions
Create, add and deploy share one rule (
chinaModelProviderRestriction): Bedrock, Anthropic,OpenAI and Gemini are refused; LiteLLM passes with an explicit non-
bedrock/model id;openai_compatiblepasses. Refusals on a template that takes an override name the blocked providerand say how to keep the template ("Amazon Bedrock is not accessible from China regions …, and
neither are Anthropic, OpenAI, Gemini. To use this template, point it at a model reachable from
China: --model-provider litellm --model-id <…>, or --model-provider openai_compatible --api-base <…>
--model-id "); Bedrock-only templates (langchain, vercel,
--type import) are told whichstrands templates to pick instead. In a China region the wizard starts on LiteLLM (Python) or
openai-compatible (TypeScript) with no model id prefilled and annotates the blocked rows; the
gates stay the enforcement.
createnow accepts the same provider spellings asadd runtime(
litellm,openai, any case), so the suggested commands can be pasted as printed. Connector-backedGateway Targets (
add gateway-connector:web-search,bedrock-knowledge-bases) are refused inChina at add and deploy time: the connector list is a static CLI enum, Bedrock Knowledge Bases do
not exist in aws-cn, and
web-searchis unconfirmed there; Runtime-backed and MCP-server Targetsare unaffected (the other target types — passthrough, OpenAPI, Lambda, Smithy, API Gateway — were
deployed to READY in cn-north-1). The
addsubcommands for families unavailable in China now say"(not available in China regions)" in their help and menu row, and the
addmenu shows an alertwhen the project has a China deployment target, so a China user no longer finds out at a wizard's
review step. The add gate now also runs before the first deploy: with no deployment target yet, the
resolved region decides (as deploy's default target would), so
add runtimein a fresh China projectdrops the default memory and refuses blocked providers instead of leaving a
memoriesentry for thedeploy gate to reject.
Fixes found while verifying live in cn-north-1
aws-opentelemetry-distro0.18/0.19 build the default OTLPendpoints with a hardcoded
.amazonaws.comsuffix; every Python template now pins~= 0.21.0,which is partition-aware.
the distro's; the unsigned copy failed with
403 MissingAuthenticationTokenExceptionafter eachinvocation (all partitions).
ag_ui_strands.create_strands_apptakes no FastAPI options, so thetemplate assembles the app itself with
telemetry={"auto_configure": False}and pinsfastapi >= 0.142.dropped
memory/while the entrypoints import it (as feat: add China (aws-cn) region support with feature gates #2426 fixed foragent-python-strands); themodule is always kept and degrades to no memory without its env var.
Windows, where temp paths are long): the scroll-into-view callback and the viewport re-measure fed
each other. The callback now discounts the rows the viewport gained from scrolling; the harness
wizard shares the fix.
jsStrhelper), a stray space in the Python OpenAI
client_args(Handlebars reads}}}as an unescapedclose), and a whitespace-only line from the
strands-agentsextras conditional.CI
bun auditfails the Linux verify job on every branch since GitHub reviewed GHSA-vfj7-8cjw-p6xm(
braces@3.0.3via@aws-cdk/toolkit-libandsecretlint) on 2026-10-02; no patchedbracesexists and the lockfile is untouched here. The audit step ignores that one advisory with a comment to
drop it once a fix ships. Happy to move this to its own PR.
Reviewing by commit
The 15 commits are ordered and each is green on its own: 1 wizard step · 2 A2A/AG-UI overrides ·
3 TypeScript providers and
--api-base· 4 ADOT pin · 5 FastAPI telemetry · 6 scroll loop ·7 key-handling tests · 8 scaffold tidy · 9
bun auditignore · 10 China refusal wording andcreatealiases · 11openai_compatibleprovider · 12 connector targets refused in China ·13 China notes in
addhelp and menu · 14 the notes derived from the manager's China allowlist(single source: a resource family added later is marked unavailable until verified) · 15 the China
add gate also applies before the first deploy (resolved region stands in while the project has no
target, so
add runtimeno longer re-adds the memory thatcreatedropped). Commit 11supersedes the
open_ai --api-basesurface that 3 and 10 describe; the sections above are the final behaviour. Merges from
refactor(2026-10-05 and 2026-10-07) and asource-map-jsaudit bump ride along; the 10-07 merge adopts the refreshed default model ids (#2545) through this branch's singleDEFAULT_MODEL_IDStable and adapts the wizard tests to the new preselectedconfig-basedtype (#2524).Related Issue
Closes #2506
Documentation PR
Included here:
README.md(create section),docs/china-regions.md,command.md(regenerated),src/assets/templates/agent-typescript-strands/README.md.Type of Change
refactor:open_aiand every default scaffold are unchanged)Testing
bun test— 4040 pass, 0 fail (57 new: wizard screens, create/add handlers, China gatesand refusal wording, provider aliases, template scaffolds for all five strands templates, AG-UI
app assembly, wrapped-input scroll, renderer helpers); also green with a macOS-length
TMPDIRbun run test:e2enot run; instead every path was verified live in cn-north-1 throughagentcore deployandagentcore invoke, from both the wizard and flags: Python strands onLiteLLM and on
openai_compatible, TypeScript strands onopenai_compatible, A2A and AG-UI onLiteLLM — each answered with 0 runtime errors and 0 OTLP export errors; the create, add and
deploy gates refused Bedrock, OpenAI and
bedrock/-routed LiteLLM before any CloudFormationcall; the Gateway, Gateway-target and credential wizards, root-TUI deploy, and the
gateway/identityscreens were walked in cn-north-1 (gateway → runtime round trip answered). Commercial scaffolds for the four touched templates diffed against the published rc.5:only the intended changes above remain.
bun run typecheckbun run lint:checkbun run format:checkbun run buildsrc/assets/modified; snapshots unaffected (manifests and runtime specs unchanged forBedrock scaffolds), full suite green without
--update-snapshotsChecklist