From 6d9253d1e9819f4ce5fce3b882f7706268b09212 Mon Sep 17 00:00:00 2001 From: Tejas Kashinath Date: Wed, 30 Sep 2026 21:52:31 +0000 Subject: [PATCH] fix(project): set requires-python >=3.12 in the BMA template Mirrors #2491. Without a minimum, uv run client.py can pick the macOS system Python 3.9, which openai does not support. --- src/assets/templates/bedrock-managed-agents/README.md | 2 +- src/assets/templates/bedrock-managed-agents/pyproject.toml | 1 + src/core/project/templates/bedrockManagedAgents.test.ts | 3 +++ 3 files changed, 5 insertions(+), 1 deletion(-) diff --git a/src/assets/templates/bedrock-managed-agents/README.md b/src/assets/templates/bedrock-managed-agents/README.md index a5b74a3c33..a9968b875c 100644 --- a/src/assets/templates/bedrock-managed-agents/README.md +++ b/src/assets/templates/bedrock-managed-agents/README.md @@ -12,7 +12,7 @@ environment where BMA runs commands. The ACR has no model code. | `otel/collector.yaml` | The configuration of the CloudWatch agent. The agent gets the spans and logs of `codex exec-server`, puts the session ID on them, and sends them to X-Ray and CloudWatch Logs with the ACR role. To turn off observability, add `DISABLE_ADOT_OBSERVABILITY` with the value `true` to `envVars`. | | `plugins/acr-report` | A Codex plugin with the `acr-report` skill. The skill saves the Python version, the user ID, and the working directory in `acr-report.txt`. | | `bma-acr-policy.json` | Lets the ACR role call `bedrock-mantle:RegisterEnvironment` and `bedrock-mantle:ConnectEnvironment` on every Mantle project. To limit the role to your projects, change `Resource` to `arn:aws:bedrock-mantle:::project/`. | -| `pyproject.toml` | The Python dependencies. `aws-opentelemetry-distro` sends a span for each call from BMA and a child span for each step of the call, for example the state load or the exec-server start. `bedrock-agentcore` is the AgentCore SDK. The `dev` group has the dependencies of `client.py`, and the image does not install it. Each image build installs the latest Python and the latest releases. To pin them, run `uv lock` and keep `uv.lock` next to this file. | +| `pyproject.toml` | The Python dependencies. `aws-opentelemetry-distro` sends a span for each call from BMA and a child span for each step of the call, for example the state load or the exec-server start. `bedrock-agentcore` is the AgentCore SDK. The `dev` group has the dependencies of `client.py`, and the image does not install it. Each image build installs the latest Python and the latest releases. To pin them, run `uv lock` and keep `uv.lock` next to this file. `requires-python` sets only a minimum, 3.12, so that `uv run client.py` does not use an older system Python. | | `client.py` | A sample OpenAI SDK client. It creates a session in BMA, and BMA sends the session's commands to this ACR. | Do not change `lifecycle/server.py`. It must match the lifecycle calls that BMA makes. diff --git a/src/assets/templates/bedrock-managed-agents/pyproject.toml b/src/assets/templates/bedrock-managed-agents/pyproject.toml index 9bbb0ffa23..10a862ddd7 100644 --- a/src/assets/templates/bedrock-managed-agents/pyproject.toml +++ b/src/assets/templates/bedrock-managed-agents/pyproject.toml @@ -3,6 +3,7 @@ name = "{{ name }}" version = "0.1.0" description = "AgentCore Runtime environment for Bedrock Managed Agents" readme = "README.md" +requires-python = ">=3.12" dependencies = [ "aws-opentelemetry-distro", "bedrock-agentcore", diff --git a/src/core/project/templates/bedrockManagedAgents.test.ts b/src/core/project/templates/bedrockManagedAgents.test.ts index 3f044fea89..ad14cdd106 100644 --- a/src/core/project/templates/bedrockManagedAgents.test.ts +++ b/src/core/project/templates/bedrockManagedAgents.test.ts @@ -49,6 +49,8 @@ test("Bedrock Managed Agents assets preserve the environment and lifecycle contr expect(dockerfile).toContain("https://chatgpt.com/codex/install.sh"); expect(dockerfile).toContain("amazon-cloudwatch-agent.rpm"); expect(dockerfile).toContain("COPY --from=ghcr.io/astral-sh/uv:latest /uv /bin/"); + // Python is installed before pyproject.toml is copied, so requires-python sets a minimum and does not pin the image. + expect(dockerfile).toMatch(/RUN uv python install --default\n[\s\S]*COPY pyproject\.toml/); expect(dockerfile).toContain("RUN uv sync --no-dev"); expect(dockerfile).toContain("COPY lifecycle/ lifecycle/"); expect(dockerfile).toContain("COPY otel/ otel/"); @@ -82,6 +84,7 @@ test("Bedrock Managed Agents assets preserve the environment and lifecycle contr expect(pyproject).toContain('"aws-bedrock-token-generator>=1.1.0",'); expect(pyproject).toContain('"openai>=3.16.2",'); expect(pyproject).toContain("[tool.uv]\npackage = false"); + expect(pyproject).toContain('requires-python = ">=3.12"'); // BMA calls this protocol, and the server translates its failures into HTTP 200 bodies. expect(server).toContain(`BMA_VERSION = "${version}"`);