fix(policy): scope target guardrails to gateway tools - #2423
Open
rksharma-owg wants to merge 1 commit into
Open
rksharma-owg wants to merge 1 commit into
rksharma-owg wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Fixes tool-scoped guardrail policies generated by
agentcore add policy --target. The generated Cedar statement now uses the target's single known tool name (for example,websearch___WebSearch) and resolves the containing deployed gateway when--gatewayis omitted, producing the required ARN-scoped resource constraint. Ambiguous target-to-gateway mappings are rejected instead of guessed.Root cause
The form-mode policy command passed only the target name to Cedar synthesis, which hard-coded
POST:/invocationsand omitted the gateway ARN unless--gatewaywas explicitly supplied. AgentCore policy validation requires the target tool action identifier and a concrete gateway resource for tool-scoped policies.Testing
npx vitest run src/cli/tui/screens/policy/__tests__/synthesize-cedar.test.ts src/cli/primitives/__tests__/PolicyPrimitive.test.tsnpm run buildnpm run format:checknpm run lint(existing warnings only)Local repository-wide
npm run typecheckis blocked by pre-existing fetch/stream typing errors, but the same check passed in the fork preflight above.Related Issue
Closes #2395