From 3f4dda4745ee966b77da038be75ff5d101fe77a9 Mon Sep 17 00:00:00 2001 From: roboomp Date: Tue, 11 Aug 2026 18:03:16 +0000 Subject: [PATCH] fix(ai): honored Bedrock skip-auth during model discovery Treat AWS_BEDROCK_SKIP_AUTH as configured authentication for the Amazon Bedrock registry entry before probing shared AWS credential files. Keep Bedrock Mantle gated on real AWS credentials. Fixes #8267 --- packages/ai/CHANGELOG.md | 4 ++++ packages/ai/src/registry/amazon-bedrock.ts | 2 +- packages/ai/src/registry/aws.ts | 5 +++-- packages/ai/test/aws-registry.test.ts | 17 +++++++++++++++++ 4 files changed, 25 insertions(+), 3 deletions(-) diff --git a/packages/ai/CHANGELOG.md b/packages/ai/CHANGELOG.md index 5253a5af6..e3341a2d2 100644 --- a/packages/ai/CHANGELOG.md +++ b/packages/ai/CHANGELOG.md @@ -2,6 +2,10 @@ ## [Unreleased] +### Fixed + +- Fixed `AWS_BEDROCK_SKIP_AUTH` failing to expose Amazon Bedrock models when AWS credential files are unavailable; the registry now recognizes the transport's explicit auth bypass without enabling the separate Bedrock Mantle provider ([#8267](https://github.com/can1357/oh-my-pi/issues/8267)). + ## [17.2.13] - 2026-08-11 ### Changed diff --git a/packages/ai/src/registry/amazon-bedrock.ts b/packages/ai/src/registry/amazon-bedrock.ts index 37e2c40c8..bb7a0fb58 100644 --- a/packages/ai/src/registry/amazon-bedrock.ts +++ b/packages/ai/src/registry/amazon-bedrock.ts @@ -5,7 +5,7 @@ export const amazonBedrockProvider = { id: "amazon-bedrock", name: "Amazon Bedrock", // Amazon Bedrock accepts bearer tokens, IAM keys, profiles, ECS/IRSA credential chains. - envKeys: resolveAwsRegistryApiKey, + envKeys: () => resolveAwsRegistryApiKey({ allowSkipAuth: true }), mapSimpleOptions: options => { const awsOptions = options.providerOptions as AwsBedrockProviderOptions | undefined; return { diff --git a/packages/ai/src/registry/aws.ts b/packages/ai/src/registry/aws.ts index 47d631c22..e0486e1cd 100644 --- a/packages/ai/src/registry/aws.ts +++ b/packages/ai/src/registry/aws.ts @@ -1,5 +1,5 @@ import * as fs from "node:fs"; -import { $env } from "@oh-my-pi/pi-utils"; +import { $env, $flag } from "@oh-my-pi/pi-utils"; import { hasConfiguredAwsProfile } from "../utils/aws-profile"; import { AUTHENTICATED_SENTINEL } from "./types"; @@ -53,7 +53,8 @@ export function hasAwsCredentialSource(): boolean { } /** Registry key marker for AWS transports that resolve their own bearer/IAM credentials. */ -export function resolveAwsRegistryApiKey(): string | undefined { +export function resolveAwsRegistryApiKey(options?: { allowSkipAuth?: boolean }): string | undefined { + if (options?.allowSkipAuth && $flag("AWS_BEDROCK_SKIP_AUTH")) return AUTHENTICATED_SENTINEL; return hasAwsCredentialSource() ? AUTHENTICATED_SENTINEL : undefined; } diff --git a/packages/ai/test/aws-registry.test.ts b/packages/ai/test/aws-registry.test.ts index 248565cba..927f561ce 100644 --- a/packages/ai/test/aws-registry.test.ts +++ b/packages/ai/test/aws-registry.test.ts @@ -10,6 +10,7 @@ const EMPTY_AWS_ENV = { AWS_ACCESS_KEY_ID: undefined, AWS_SECRET_ACCESS_KEY: undefined, AWS_BEARER_TOKEN_BEDROCK: undefined, + AWS_BEDROCK_SKIP_AUTH: undefined, AWS_PROFILE: undefined, AWS_SDK_LOAD_CONFIG: undefined, AWS_WEB_IDENTITY_TOKEN_FILE: undefined, @@ -21,6 +22,22 @@ const EMPTY_AWS_ENV = { }; describe("AWS provider availability", () => { + test("recognizes the Bedrock auth bypass without AWS credentials", async () => { + await withEnv( + { + ...EMPTY_AWS_ENV, + AWS_BEDROCK_SKIP_AUTH: "1", + AWS_SHARED_CREDENTIALS_FILE: "/missing/aws-credentials", + AWS_CONFIG_FILE: "/missing/aws-config", + AWS_EC2_METADATA_DISABLED: "true", + }, + async () => { + expect(getEnvApiKey("amazon-bedrock")).toBeDefined(); + expect(getEnvApiKey("bedrock-mantle")).toBeUndefined(); + }, + ); + }); + test("recognizes the default shared credentials file", async () => { const tmp = await fs.mkdtemp(path.join(os.tmpdir(), "aws-registry-")); try {