Skip to content

fix: Bedrock auth regression — "<authenticated>" sent as bearer token - #97

Merged
grrowl merged 2 commits into
mainfrom
fix/bedrock-auth-regression
Jul 28, 2026
Merged

grrowl merged 2 commits into
mainfrom
fix/bedrock-auth-regression

Conversation

@grrowl

@grrowl grrowl commented Jul 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Urgent: production is currently broken. PR #96 was squash-merged at commit 834d3c9d, missing the final fix commit (748abb98) on the branch, and the deploy of e49eac3f has already completed — so the live ECS task has this bug and every Bedrock request will fail auth.

The bug

Agent.getApiKey is not inert (as PR #96 review had concluded):

  1. pi-agent-core calls getApiKey before every model request and forwards the result as options.apiKey into the stream function.
  2. ModelRuntime.prepareRequest() treats an explicit apiKey as an auth override, short-circuiting ambient credential resolution.
  3. The Bedrock provider uses options.apiKey as an AWS_BEARER_TOKEN_BEDROCK bearer token: bearerToken = options.bearerToken || options.apiKey || ...

Net effect: every request authenticates with the literal string "<authenticated>" instead of SigV4 task-role auth.

Found by an adversarial Codex (gpt-5.6-sol) review; each link verified against the installed 0.82.1 packages.

The fix

  • Remove getApiKey from the Agent config — ModelRuntime resolves ambient ECS credentials itself, which also restores normal AWS SDK temporary-credential refresh during long tasks.
  • Keep the fail-loud credential check as a boot-time assert, expanded to cover the full credential-chain modes the provider supports (AWS_CONTAINER_CREDENTIALS_FULL_URI, AWS_WEB_IDENTITY_TOKEN_FILE, AWS_BEARER_TOKEN_BEDROCK).
  • Do not cache a rejected ModelRuntime.create() promise — a transient init failure would wedge every channel until the ECS task restarts.
  • engines: node >=22 (file-type 22 requires it; Docker/CI already run 22).

Test results

234/234 tests passing, npm run check clean. Note the suite mocks streaming, so nothing in CI exercises the real auth path — worth watching the bot's first Bedrock call after this deploys.

🤖 Generated with Claude Code


Summary by cubic

Fixes a Bedrock auth regression that sent the literal "" as a bearer token, restoring SigV4 task‑role auth and normal credential refresh. Also tightens the web‑identity boot guard to require AWS_ROLE_ARN.

  • Bug Fixes

    • Removed getApiKey from the Agent config so ModelRuntime resolves AWS credentials.
    • Added a boot-time assert that fails fast if no AWS creds are detected; supports ECS task role, profiles, static keys, bearer token, and requires both AWS_WEB_IDENTITY_TOKEN_FILE and AWS_ROLE_ARN for web identity.
    • Avoid caching a rejected ModelRuntime.create() promise to prevent wedging channels after transient init failures.
  • Dependencies

    • Set engines.node to ">=22.0.0".

Written for commit cc60dd4. Summary will update on new commits.

Review in cubic

Codex (gpt-5.6-sol) adversarial review caught an auth regression the
earlier review had cleared as inert: pi-agent-core calls
Agent.getApiKey before every request and forwards the result as
options.apiKey. ModelRuntime.prepareRequest treats an explicit apiKey
as an auth override, and the Bedrock provider uses options.apiKey as
an AWS_BEARER_TOKEN_BEDROCK bearer token — so every ECS request would
have sent the literal string "<authenticated>" instead of SigV4
task-role auth.

- Remove getApiKey from the Agent config; ModelRuntime resolves
  ambient AWS credentials itself.
- Keep the fail-loud credential check as a boot-time assert, expanded
  to the full credential-chain modes the provider supports.
- Do not cache a rejected ModelRuntime.create() promise (transient
  init failure would wedge all channels until task restart).
- engines: node >=22 (file-type 22 requires it).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files

Heads up: you’re close to your included review allowance. Set a flex budget so reviews don’t pause.

Fix all with cubic | Re-trigger cubic

Comment thread src/agent/setup.ts Outdated
AWS_WEB_IDENTITY_TOKEN_FILE alone can't authenticate — the SDK's
fromTokenFile needs AWS_ROLE_ARN too (EKS IRSA sets both). Without
this the guard passes on a config that fails at first request,
defeating the fail-loud intent. Flagged by cubic on #97.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@grrowl
grrowl merged commit 566d3eb into main Jul 28, 2026
5 checks passed
@grrowl
grrowl deleted the fix/bedrock-auth-regression branch July 28, 2026 01:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant