-
Notifications
You must be signed in to change notification settings - Fork 4.4k
fix(bedrock-agentcore-alpha): default Cognito User Pool for AgentCore Gateway is not set up for M2M authentication. #36323
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
mazyu36
wants to merge
5
commits into
aws:main
Choose a base branch
from
mazyu36:fix/agentcore-gateway
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
f50496f to
e7953de
Compare
e7953de to
50a727d
Compare
Contributor
|
||||||||||||||||||||||||||
Contributor
|
||||||||||||||||||||||||||
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
distinguished-contributor
[Pilot] contributed 50+ PRs to the CDK
p2
pr/needs-community-review
This PR needs a review from a Trusted Community Member or Core Team Member.
pr/needs-further-review
PR requires additional review from our team specialists due to the scope or complexity of changes.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Issue # (if applicable)
N/A
Reason for this change
Gateway requires M2M authentication for service-to-service communication. The default Cognito authorizer was missing OAuth 2.0 client credentials flow configuration, making Gateway unusable for its intended purpose.
Description of changes
Updated the default Cognito authorizer configuration to support M2M authentication:
readandwritescopesuserPool,userPoolClient,userPoolDomain,resourceServer) as public properties for Runtime integrationRef:
Describe any new or updated permissions being added
N/A
Description of how you validated changes
Add unit tests and an integ test.
BREAKING CHANGE: The User Pool Client will be replaced and new Resource Server and Domain resources will be added for existing Gateway stacks using the default Cognito authorizer.
Checklist
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license