aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

feat(compute): extended tool capability tiers

Offen
#454 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement infra-cdk security
Vorherrschende Sprache
TypeScript
Sterne
143
Forks
46
Ø Merge
3 T. 10 Std.
Gemergte PRs (30 T.)
24

Beschreibung

**Context:** ROADMAP.md → Security → Tool capability tiers
**Related:** #422 (HITL elevation), #429, #246

---

## Component

CDK / infrastructure

## Describe the feature

Opt-in **extended** tool profile per repo: MCP servers, plugins, and additional Gateway-mediated tools beyond the default minimal surface. Enforced at **Gateway** and **Cedar policy** layers.

## Use case

Default minimal tool surface is safe but limiting. Power users need MCP integrations with explicit opt-in and policy gates—not silent expansion.

## Proposed solution

1. Blueprint flag: `tool_profile: minimal | extended`.
2. Gateway allowlist of tool names/MCP servers per profile.
3. Cedar policies for extended-only actions.
4. Audit when profile is elevated mid-task (#422).
5. Document in `docs/design/COMPUTE.md`.

## Other information

- #422 covers runtime elevation via HITL; this covers **static profile definition**.
- Pairs with **MCP supply-chain controls** (#429).
- Design context: `docs/design/COMPUTE.md`, `docs/design/CEDAR_HITL_GATES.md`.

- [ ] This might be a breaking change

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne mit der Lektüre von docs/design/COMPUTE.md und docs/design/CEDAR_HITL_GATES.md und prüfe anschließend die verwandten Issues #422, #429 und #246, um statische Profile von Laufzeiterhöhung und Supply-Chain-Kontrollen zu trennen. Als abgeschlossen gilt die Aufgabe, wenn das blueprint flag, die Gateway allowlist, die Cedar gates, das elevation audit behavior und die Dokumentation definiert und implementiert sind, ohne das Standardprofil stillschweigend zu erweitern.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
aws, typescript
Bereich
infrastructure, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
32/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.