Skip to content

feat(endpoints): support AWS China (aws-cn) partition - #684

Merged
notgitika merged 1 commit into
mainfrom
feat/aws-cn-partition-support
Sep 28, 2026
Merged

notgitika merged 1 commit into
mainfrom
feat/aws-cn-partition-support

Conversation

@JasonZhang1993

Copy link
Copy Markdown
Contributor

Summary

Regionalizes the SDK for AWS China (aws-cn). Endpoint DNS suffixes are derived from botocore partition data instead of a hardcoded .amazonaws.com, so data/control/gateway endpoints resolve to amazonaws.com.cn in cn-north-1 / cn-northwest-1. Commercial partitions are unchanged.

Changes

  • _utils/endpoints.py: partition-aware DNS suffix via a cached public botocore EndpointResolver; warns (rather than silently falling back) on unknown regions; adds known_partitions()
  • runtime/utils.py: is_valid_partition backed by botocore's partition list
  • runtime/a2a.py: build_runtime_url derives the suffix (region-based contract)
  • payments/{client,manager}.py, config_bundle/client.py, batch runner: resolve endpoints natively (partition-correct) while still honouring the BEDROCK_AGENTCORE_{CP,DP}_ENDPOINT override via conditional endpoint_url
  • .pre-commit-config.yaml: pygrep hook forbidding a hardcoded .amazonaws.com suffix right after an interpolated value
  • tests: CN endpoint-builder + aws-cn ARN coverage; override on/off cases

Testing

  • Unit: affected suites green (test_region_validation, runtime/test_utils, config_bundle, unit/runtime); ruff + pre-commit hook clean.
  • Live (cn-north-1, cn-northwest-1, us-east-1 regression) on the equivalent change: runtime CP/DP incl. InvokeAgentRuntime→200, tools (browser + code-interpreter) CP+DP, gateway CP + MCP-URL, identity CP; all endpoints *.amazonaws.com.cn.

Derive endpoint DNS suffixes from botocore partition data instead of hardcoding
.amazonaws.com, so data/control/gateway endpoints resolve to amazonaws.com.cn in
cn-north-1 / cn-northwest-1. Commercial partitions are unchanged.

- _utils/endpoints.py: partition-aware DNS suffix via a cached public botocore
  EndpointResolver; warns (rather than silently falling back) on unknown
  regions; exposes known_partitions()
- runtime/utils.py: is_valid_partition backed by botocore's partition list
- runtime/a2a.py: build_runtime_url derives the suffix (region-based contract)
- payments/{client,manager}.py, config_bundle/client.py, batch runner: resolve
  endpoints natively (partition-correct) while still honouring the
  BEDROCK_AGENTCORE_{CP,DP}_ENDPOINT override via conditional endpoint_url
- .pre-commit-config.yaml: pygrep hook forbidding a hardcoded .amazonaws.com
  suffix immediately after an interpolated value
- tests: CN endpoint-builder + aws-cn ARN coverage; override on/off cases
@github-actions

Copy link
Copy Markdown
Contributor

⚠️ Breaking Change Warning

Found 1 potential breaking change(s) in this PR:

�[1msrc/bedrock_agentcore/payments/client.py�[0m:276: PaymentClient.payments_cp_client: �[33mAttribute value was changed�[39m: boto3.client('bedrock-agentcore-control', region_name=self.region_name, endpoint_url=get_control_plane_endpoint(self.region_name), config=client_config) -> boto3.client('bedrock-agentcore-control', **cp_kwargs)


Note: This is an automated static analysis check. Some flagged changes may be intentional.
Please confirm each item is expected and, if so, add a migration note to CHANGELOG.md.

@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Sep 28, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 28, 2026
@notgitika

Copy link
Copy Markdown
Contributor

On the breaking-change bot: that's a false positive from the kwargs refactor. payments_cp_client is still a bedrock-agentcore-control client, and botocore's default ruleset resolves to the same bedrock-agentcore-control.{region}.amazonaws.com host for commercial regions, so nothing changes for existing users. The only difference is FIPS/dual-stack config is now honoured instead of bypassed, which matches how the identity client already behaves

@notgitika notgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM thanks!

@notgitika

Copy link
Copy Markdown
Contributor

Merging as all CI green

@notgitika
notgitika merged commit 35c315e into main Sep 28, 2026
44 checks passed

This branch was successfully deployed

1 active deployment
auto-approve — d793c162 Deployed Sep 28, 2026 by JasonZhang1993 via Test (tools) #1606
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/m PR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants