awslabs / awslabs/agentcore-samples

Enhancement: Add Policy-Based Access Control to Lab 3

Open
#878 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
3.4k
Forks
1.3k
Avg merge
1d 22h
Merged PRs (30d)
30

Description

Customer Request
Following the AgentCore Policy announcement at re:Invent 2024, customers attending workshops are asking to see policy-based access control demonstrated with AgentCore Gateway. They want to understand how to govern tool usage with declarative policies in production scenarios.

Proposed Solution
Add optional "Step 10: Policy Engine for Access Control" demonstrating:
- Policy Engine setup with Cedar policies
- Natural language to policy generation
- Allow/deny rules for tools and parameters
- Policy enforcement testing

Why This Matters
- Customer demand: Direct feedback from workshop participants
- Governance: Shows declarative policy patterns for tool access control
- Flexibility: Demonstrates condition-based rules (e.g., block specific parameters)
- Zero breaking changes: Completely optional section

Contributor guide

Open the contributing guide

Research direction

Start by locating Lab 3 and reviewing its existing AgentCore Gateway setup and workshop flow. Define an optional Step 10 covering Cedar policy setup, natural-language policy generation, allow/deny rules for tools and parameters, and enforcement testing. Done means the lab demonstrates these policy-based access-control scenarios without changing the existing steps.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, python
Domain
authorization, documentation, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.