From 0016e43013d2a8babd5889cc8b5e752b140d0bfc Mon Sep 17 00:00:00 2001 From: Shawn Li Date: Thu, 24 Sep 2026 23:04:15 +0000 Subject: [PATCH 1/8] feat: add China (aws-cn) regions to supported region enum Add cn-north-1 and cn-northwest-1 to AgentCoreRegionSchema and its region test. Without this, aws-cn deployment targets fail aws-targets.json validation, blocking every command that resolves a target in China regions. --- src/projectSchemas/aws-targets.test.ts | 2 ++ src/projectSchemas/aws-targets.ts | 2 ++ 2 files changed, 4 insertions(+) diff --git a/src/projectSchemas/aws-targets.test.ts b/src/projectSchemas/aws-targets.test.ts index 5cf2997540..2ad154abb7 100644 --- a/src/projectSchemas/aws-targets.test.ts +++ b/src/projectSchemas/aws-targets.test.ts @@ -54,6 +54,8 @@ describe("AWS deployment targets", () => { "ap-south-2", "ap-southeast-5", "ap-southeast-7", + "cn-north-1", + "cn-northwest-1", "eu-south-1", "eu-south-2", "us-gov-west-1", diff --git a/src/projectSchemas/aws-targets.ts b/src/projectSchemas/aws-targets.ts index b3dc0c5ec3..863e510061 100644 --- a/src/projectSchemas/aws-targets.ts +++ b/src/projectSchemas/aws-targets.ts @@ -13,6 +13,8 @@ export const AgentCoreRegionSchema = z.enum([ "ap-southeast-5", "ap-southeast-7", "ca-central-1", + "cn-north-1", + "cn-northwest-1", "eu-central-1", "eu-north-1", "eu-south-1", From cf49abe005006cc4e5512e91425794f80c7a850a Mon Sep 17 00:00:00 2001 From: Shawn Li Date: Thu, 24 Sep 2026 23:04:27 +0000 Subject: [PATCH 2/8] feat: gate unavailable features in China (aws-cn) regions MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit In aws-cn, Amazon Bedrock is not launched and Anthropic/OpenAI/Gemini are not reachable, and no telemetry collector exists there. Gate the affected features with clear regional behavior instead of letting them fail downstream: - Runtime templates: FsProjectManager.addResource rejects framework templates wired to Bedrock/Anthropic/OpenAI/Gemini with RegionUnsupportedFeatureError before scaffolding when any deployment target is in a China region (covers the flag handler and the TUI wizard). Provider-free scaffolds (agent-python-minimal, mcp-python-fastmcp) stay available as the bring-your-own-implementation path. - LiteLLM stays available in China as the routable-provider escape hatch, but requires an explicit model id there: its default model id routes to Bedrock. New --model-id flag on 'add runtime' threads into the template render context (generic optional override; per-provider defaults are unchanged commercially). - Bedrock Agent import (--type import): the add-runtime handler fails fast before any Bedrock call. - Telemetry: unconditionally disabled in a China context — ambient AWS region env vars OR any cn-* deployment target in aws-targets.json — regardless of config or endpoint overrides; the local audit-file sink is unaffected. The global-config default also flips to disabled under a China ambient region. - Add isChinaRegion()/isChinaContext() partition helpers and RegionUnsupportedFeatureError; document the China behavior in README. Known gap (as on main): project create scaffolds before targets exist, so the guards fire at add runtime where targets are known. --- README.md | 16 ++ command.md | 1 + .../agent-python-strands/model/load.py | 10 +- src/core/partition.test.ts | 81 ++++++++++ src/core/partition.ts | 51 ++++++ src/core/project/manager.test.ts | 152 +++++++++++++++++- src/core/project/manager.tsx | 43 +++++ src/core/project/templates/runtime.ts | 19 ++- src/errors/errors.tsx | 11 ++ src/errors/index.tsx | 1 + src/globalConfig/accessor.test.tsx | 56 +++++++ src/globalConfig/accessor.tsx | 18 ++- .../project/add/runtime/index.test.ts | 17 ++ src/handlers/project/add/runtime/index.ts | 41 +++-- src/handlers/project/shortcuts.ts | 2 + src/handlers/project/types.ts | 1 + src/telemetry/client.test.tsx | 38 +++++ src/telemetry/client.tsx | 7 +- 18 files changed, 541 insertions(+), 24 deletions(-) create mode 100644 src/core/partition.test.ts create mode 100644 src/core/partition.ts create mode 100644 src/globalConfig/accessor.test.tsx diff --git a/README.md b/README.md index 3135b17154..429b37435e 100644 --- a/README.md +++ b/README.md @@ -133,6 +133,22 @@ yourself. Note that `agentcore status` reports only the resources `agentcore.json` declares, not the ones you add in the stack. +## China (aws-cn) regions + +`cn-north-1` and `cn-northwest-1` are supported, with three differences: + +- **Templates:** Amazon Bedrock, Anthropic, OpenAI, and Gemini are not accessible from China + regions, so templates wired to those providers (and `--type import`, which reads from Amazon + Bedrock) are rejected when a deployment target is in `cn-*`. Bring your own agent + implementation instead: scaffold with `agent-python-minimal` or `mcp-python-fastmcp` and add + your own model connectivity, or use `--template agent-python-strands --model-provider litellm +--model-id ` with a [LiteLLM model](https://docs.litellm.ai/docs/providers) reachable + from China — no default model id is applied there. +- `agentcore create` scaffolds before any deployment target exists, so these restrictions are + enforced at `agentcore add runtime` (and in the TUI), where targets are known. +- **Telemetry** is always disabled when the ambient AWS region or any deployment target is a + China region. + ## Documentation - [Amazon Bedrock AgentCore documentation](https://docs.aws.amazon.com/bedrock-agentcore/): service guides and API references. diff --git a/command.md b/command.md index 8507b254ee..6417da9857 100644 --- a/command.md +++ b/command.md @@ -262,6 +262,7 @@ add a Runtime to the current project - `--template