feat(bedrock-agentcore): add grantInvokeWithWebSocketStream method to Runtime#37508
Open
feat(bedrock-agentcore): add grantInvokeWithWebSocketStream method to Runtime#37508
Conversation
… Runtime Add `grantInvokeWithWebSocketStream` to `IBedrockAgentRuntime` and `RuntimeBase` to grant `bedrock-agentcore:InvokeAgentRuntimeWithWebSocketStream` permission, enabling WebSocket stream invocation of AgentCore Runtimes. Closes aws#37495
aws-cdk-automation
requested changes
Apr 2, 2026
Collaborator
There was a problem hiding this comment.
The pull request linter fails with the following errors:
❌ Features must contain a change to an integration test file and the resulting snapshot.
If you believe this pull request should receive an exemption, please comment and provide a justification. A comment requesting an exemption should contain the text Exemption Request. Additionally, if clarification is needed, add Clarification Request to a comment.
✅ A exemption request has been requested. Please wait for a maintainer's review.
Contributor
Author
|
Exemption Request: the change only adds a different IAM action string to an existing grant pattern. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue # (if applicable)
Closes #37495
Reason for this change
grantInvokedoes not grantbedrock-agentcore:InvokeAgentRuntimeWithWebSocketStream, so roles cannot invoke AgentCore Runtimes via WebSocket stream.Description of changes
Add two new grant methods to
IBedrockAgentRuntimeandRuntimeBase:grantInvokeWithWebSocketStream— grantsbedrock-agentcore:InvokeAgentRuntimeWithWebSocketStreamgrantInvokeWithWebSocketStreamForUser— grantsbedrock-agentcore:InvokeAgentRuntimeWithWebSocketStreamForUserThis follows the same pattern as the existing
grantInvokeRuntime/grantInvokeRuntimeForUsermethods, and is consistent with how CDK separates invocation channels (e.g. Lambda'sgrantInvokevsgrantInvokeUrl, API Gateway v2'sgrantManageConnections).grantInvokeis intentionally left unchanged — users who need WebSocket stream access can call the new methods explicitly.References:
Description of how you validated changes
grantInvokeWithWebSocketStream: permission grant, imported runtime, Grant objectgrantInvokeWithWebSocketStreamForUser: permission grant, imported runtime, Grant objectChecklist
grantInvokeWithWebSocketStreamandgrantInvokeWithWebSocketStreamForUserBy submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license