aws / aws/bedrock-agentcore-sdk-python

Add user identity (enduser.id) attribute to OpenTelemetry

Đang mở
#592 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
enhancement
Ngôn ngữ chính
Python
Star
764
Fork
148
Merge trung bình
1 ngày 23 giờ
Pull request đã merge (30 ngày)
7

Mô tả

### Feature Description

Currently, the OpenTelemetry (OTel) traces and spans generated during AgentCore invocation (`InvokeAgentRuntime` / `gen_ai` execution) capture telemetry metrics and session identifiers, but do not consistently populate user identity in the span attributes.

We request adding support to automatically populate user identity (or allow passing custom user identity metadata) onto OTel span attributes, following the OpenTelemetry Semantic Conventions for user attributes (`enduser.id`).

---

### Use Case & Impact

1. **User-level Observability & Debugging**: When troubleshooting agent execution failures or slow agent runs in observability platforms (e.g., Datadog, Grafana, Dynatrace, OpenSearch), SREs and developers need to trace issues back to specific end-users.
2. **Auditability & Compliance**: Enterprise compliance standards often require linking LLM invocations and tool calls directly to the initiating user identity.
3. **Usage Attribution & Quotas**: Facilitates per-user telemetry tracking, token usage analytics, and user-level rate limiting.

---

### Proposed Solution

- **Standard Attribute**: Set the span attribute `enduser.id` on root invocation spans and downstream tool/model execution spans according to the [OpenTelemetry Semantic Conventions for User Attributes](https://opentelemetry.io/docs/specs/semconv/general/attributes/#user-attributes).
- **Configuration / Propagation**:
- Extract the user ID automatically from Inbound Authentication JWT tokens (e.g., Cognito `sub` or custom claim) if passed via AgentCore Identity/Auth headers.
- Expose a mechanism in `BedrockAgentCoreApp` or request context context/metadata to explicitly inject `user_id` when initializing or handling incoming requests.

---

### Example / Expected Behavior

When an agent invocation span is generated, the resulting OpenTelemetry span attributes should include:

```json
{
"gen_ai.system": "aws.bedrock",
"enduser.id": "usr_987654321",
"session.id": "session_12345"
}

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Bắt đầu bằng cách lần theo việc tạo span OpenTelemetry cho InvokeAgentRuntime và quá trình thực thi gen_ai, sau đó kiểm tra cách BedrockAgentCoreApp xử lý request cũng như các header Identity/Auth của AgentCore. So sánh ngữ cảnh identity hiện có với quy ước enduser.id của OpenTelemetry; được xem là hoàn tất khi các span root và downstream nhất quán hiển thị identity được yêu cầu, bao gồm cả metadata người dùng được cung cấp rõ ràng.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
aws, python
Lĩnh vực
authentication, observability
Loại issue
Tính năng
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
48/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.