awslabs / awslabs/agentcore-samples
Enhancement: Add Policy-Based Access Control to Lab 3
- Dominant language
- Python
- Stars
- 3.4k
- Forks
- 1.3k
- Avg merge
- 1d 22h
- Merged PRs (30d)
- 30
Description
Customer Request
Following the AgentCore Policy announcement at re:Invent 2024, customers attending workshops are asking to see policy-based access control demonstrated with AgentCore Gateway. They want to understand how to govern tool usage with declarative policies in production scenarios.
Proposed Solution
Add optional "Step 10: Policy Engine for Access Control" demonstrating:
- Policy Engine setup with Cedar policies
- Natural language to policy generation
- Allow/deny rules for tools and parameters
- Policy enforcement testing
Why This Matters
- Customer demand: Direct feedback from workshop participants
- Governance: Shows declarative policy patterns for tool access control
- Flexibility: Demonstrates condition-based rules (e.g., block specific parameters)
- Zero breaking changes: Completely optional section
Contributor guide
Research direction
Start by locating Lab 3 and reviewing its existing AgentCore Gateway setup and workshop flow. Define an optional Step 10 covering Cedar policy setup, natural-language policy generation, allow/deny rules for tools and parameters, and enforcement testing. Done means the lab demonstrates these policy-based access-control scenarios without changing the existing steps.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, python
- Domain
- authorization, documentation, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100