aws / aws/bedrock-agentcore-sdk-python

Add user identity (enduser.id) attribute to OpenTelemetry

Offen
#592 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
enhancement
Vorherrschende Sprache
Python
Sterne
761
Forks
147
Ø Merge
1 T. 23 Std.
Gemergte PRs (30 T.)
7

Beschreibung

### Feature Description

Currently, the OpenTelemetry (OTel) traces and spans generated during AgentCore invocation (`InvokeAgentRuntime` / `gen_ai` execution) capture telemetry metrics and session identifiers, but do not consistently populate user identity in the span attributes.

We request adding support to automatically populate user identity (or allow passing custom user identity metadata) onto OTel span attributes, following the OpenTelemetry Semantic Conventions for user attributes (`enduser.id`).

---

### Use Case & Impact

1. **User-level Observability & Debugging**: When troubleshooting agent execution failures or slow agent runs in observability platforms (e.g., Datadog, Grafana, Dynatrace, OpenSearch), SREs and developers need to trace issues back to specific end-users.
2. **Auditability & Compliance**: Enterprise compliance standards often require linking LLM invocations and tool calls directly to the initiating user identity.
3. **Usage Attribution & Quotas**: Facilitates per-user telemetry tracking, token usage analytics, and user-level rate limiting.

---

### Proposed Solution

- **Standard Attribute**: Set the span attribute `enduser.id` on root invocation spans and downstream tool/model execution spans according to the [OpenTelemetry Semantic Conventions for User Attributes](https://opentelemetry.io/docs/specs/semconv/general/attributes/#user-attributes).
- **Configuration / Propagation**:
- Extract the user ID automatically from Inbound Authentication JWT tokens (e.g., Cognito `sub` or custom claim) if passed via AgentCore Identity/Auth headers.
- Expose a mechanism in `BedrockAgentCoreApp` or request context context/metadata to explicitly inject `user_id` when initializing or handling incoming requests.

---

### Example / Expected Behavior

When an agent invocation span is generated, the resulting OpenTelemetry span attributes should include:

```json
{
"gen_ai.system": "aws.bedrock",
"enduser.id": "usr_987654321",
"session.id": "session_12345"
}

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne damit, die Erstellung von OpenTelemetry-Spans für InvokeAgentRuntime und die gen_ai-Ausführung nachzuverfolgen. Untersuche anschließend die Request-Verarbeitung von BedrockAgentCoreApp sowie die Identity/Auth-Header von AgentCore. Vergleiche den verfügbaren Identity-Kontext mit der OpenTelemetry-Konvention für enduser.id. Als erledigt gilt die Aufgabe, wenn Root- und nachgelagerte Spans die angeforderte Identität konsistent offenlegen, einschließlich ausdrücklich übergebener Benutzermetadaten.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
aws, python
Bereich
authentication, observability
Issue-Typ
Feature
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
48/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.