aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

fix(cli): platform doctor probes the foundation-model catalog, never the inference profile it will actually invoke

オープン
#804 コメント 0 件 リアクション 0 件 担当者 1 名 @isadeks が担当を希望しています GitHub で見る
approved bug
主要言語
TypeScript
スター
143
フォーク
46
平均マージ
3日 10時間
マージ済み PR(30日)
24

説明

## Problem

`platform doctor`'s Bedrock check calls `GetFoundationModel` on the **bare** model id, stripped from the platform default. That answers "is this model in the catalog in this Region" — which is not the question that decides whether tasks work.

At invoke time the agent calls a **cross-Region inference profile** (`.anthropic.…`), and the IAM grant is scoped to explicit profile ARNs. So a stack can be granted profiles the account cannot invoke, and `doctor` still reports healthy.

## Why it matters now

`bedrockGeoRegion` (#746) makes the geography a deploy-time choice, so there are more ways for the configured profile and the account's entitlements to disagree. Two failure modes `doctor` currently cannot see:

- the model has no profile published in the configured geography;
- the account's Bedrock access does not cover that geography's entitlements.

Both surface as `AccessDenied` at turn 0, with nothing in `doctor` pointing at the cause. Observed while verifying #747: `doctor` passed reporting `anthropic.claude-sonnet-4-6` visible in `us-east-1` while the deployment was configured for `global.anthropic.claude-opus-5` — two different models *and* a geography it never looked at.

## Suggested change

Probe what will actually be invoked:

1. Resolve the configured geography (`bedrockGeoRegion`, default `us`) — from stack outputs, or the same context resolution the CDK uses.
2. Check the profile, not just the catalog: `GetInferenceProfile` on `.`, or a minimal `InvokeModel` if a real entitlement check is wanted.
3. Report the profile id in the check label, so the output states what was verified.

Keep the catalog check as a second, narrower signal — it distinguishes "model does not exist here" from "profile exists but you cannot invoke it", and those need different fixes.

## Scope

`cli/src/platform-doctor.ts` (`checkBedrockModel`), plus `cli/test/platform-doctor.test.ts`.

## Not this issue

The geo-prefix strip in the same function was broken for `global.`/`us-gov.`/`jp.`/`au.` and is fixed in #800 — that was a straight regression. This issue is the larger question of *what* the check probes, which is a behaviour change to `doctor`'s output and deserves its own review.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。