mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-07 16:19:09 +00:00
deploy(bedrock): grant instance-role Bedrock invoke + repoint LLM_MODEL_ID / eval model ids
Deployment-readiness for the Bedrock migration (PR #62): - instance-role.ts: least-privilege bedrock:InvokeModel[WithResponseStream] on the us.anthropic.claude-opus-4-8 inference-profile ARN + the foundation-model ARN in each routed region (us-east-1/2, us-west-2). The model runs in the server process on the box, so the EC2 instance role is the principal. Simulator-verified (allowed for opus-4-8, implicitDeny for other models) and synth-verified. Passed the mandatory GPT-4.1 IAM cross-review (no blockers, least-privilege confirmed). - config-store.ts: IaC SSM LLM_MODEL_ID anthropic:claude-opus-4-8 -> bedrock_converse:us.anthropic.claude-opus-4-8. This SSM value overrides seed_store.sh's default via pick precedence, so the seed-script fix alone was insufficient — both sources now point at the supported Bedrock id. - infra/README.md + evals/reviewer/config.toml: repoint stale anthropic:/google_genai: ids to the Bedrock id (config.toml's model_id was an active, now-broken value). AWS_REGION is already wired via user-data.sh (IMDS -> boot.env), so no change needed there.
This commit is contained in:
parent
7b26ab9516
commit
adaf1abcd4
4 changed files with 33 additions and 5 deletions
|
|
@ -9,8 +9,9 @@ langsmith_project = "open-swe-evals"
|
|||
# Leave blank to use LANGGRAPH_URL or local dev.
|
||||
langgraph_url = ""
|
||||
assistant_id = "reviewer"
|
||||
# models: openai:gpt-5.5, anthropic:claude-opus-4-8, google_genai:gemini-3.5-flash
|
||||
model_id = "google_genai:gemini-3.5-flash"
|
||||
# models (post Bedrock/Fireworks migration): bedrock_converse:us.anthropic.claude-opus-4-8,
|
||||
# or any fireworks:* id in agent/dashboard/options.py SUPPORTED_MODELS.
|
||||
model_id = "bedrock_converse:us.anthropic.claude-opus-4-8"
|
||||
reasoning_effort = "medium"
|
||||
|
||||
# score_mode:
|
||||
|
|
|
|||
|
|
@ -156,7 +156,7 @@ Three buckets:
|
|||
| `DASHBOARD_BASE_URL` | `https://openswe-dev.seahaven.com` *(confirm host)* | `https://openswe.seahaven.com` *(confirm host)* |
|
||||
| `DASHBOARD_API_BASE_URL` | same as base | same as base |
|
||||
| `DASHBOARD_ALLOWED_ORIGINS` | same as base | same as base |
|
||||
| `LLM_MODEL_ID` | `anthropic:claude-opus-4-8` *(confirm)* | `anthropic:claude-opus-4-8` *(confirm)* |
|
||||
| `LLM_MODEL_ID` | `bedrock_converse:us.anthropic.claude-opus-4-8` | `bedrock_converse:us.anthropic.claude-opus-4-8` |
|
||||
|
||||
3. **Out-of-band SSM config — NOT created by CDK.** Operationally-variable or
|
||||
env-specific-unknown values listed in `OUT_OF_BAND_SSM` and populated by
|
||||
|
|
|
|||
|
|
@ -142,8 +142,12 @@ export function iacManagedSsm(env: EnvName): Record<string, string> {
|
|||
DASHBOARD_BASE_URL: host,
|
||||
DASHBOARD_API_BASE_URL: host,
|
||||
DASHBOARD_ALLOWED_ORIGINS: host,
|
||||
// Primary builder model (project memory team_settings: anthropic:claude-opus-4-8).
|
||||
LLM_MODEL_ID: "anthropic:claude-opus-4-8",
|
||||
// Primary builder model. seed_store.sh's `pick` precedence is
|
||||
// OPENSWE_AGENT_MODEL > SEED_AGENT_MODEL > LLM_MODEL_ID > script default, so this
|
||||
// SSM value overrides the seed-script default — it MUST be a supported id. Post
|
||||
// Bedrock/Fireworks migration the only Bedrock-Claude id is the inference profile;
|
||||
// `anthropic:claude-opus-4-8` was removed from SUPPORTED_MODELS.
|
||||
LLM_MODEL_ID: "bedrock_converse:us.anthropic.claude-opus-4-8",
|
||||
};
|
||||
// Dev e2e smoke: seed the owner's user_mapping so an @openswe comment from the
|
||||
// triggering GitHub login resolves (an unmapped commenter is silently skipped).
|
||||
|
|
|
|||
|
|
@ -117,6 +117,29 @@ export class InstanceRole extends Construct {
|
|||
// moves these to a customer CMK, add a scoped `kms:Decrypt` on that key ARN
|
||||
// ONLY (not `*`).
|
||||
|
||||
// Invoke the Bedrock Claude model. DEFAULT_MODEL_ID is
|
||||
// `bedrock_converse:us.anthropic.claude-opus-4-8`, and the model runs in the
|
||||
// LangGraph server PROCESS on this box (not in the sandbox), so the EC2
|
||||
// instance role is the calling principal. The `us.` cross-region inference
|
||||
// profile fans out to us-east-1 / us-east-2 / us-west-2, and Bedrock authorizes
|
||||
// InvokeModel against BOTH the inference-profile ARN AND the underlying
|
||||
// foundation-model ARN in each routed region — all four resources are required
|
||||
// or the call AccessDenies. Scoped to opus-4-8 ONLY (least-privilege): adding a
|
||||
// new Bedrock model to SUPPORTED_MODELS means extending this resource list.
|
||||
// IAM change — flag for T4 (GPT-4.1 IAM cross-review) / T5 (/sh-security-review).
|
||||
this.role.addToPolicy(
|
||||
new iam.PolicyStatement({
|
||||
sid: "InvokeBedrockClaude",
|
||||
actions: ["bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream"],
|
||||
resources: [
|
||||
`arn:aws:bedrock:${REGION}:${ACCOUNT}:inference-profile/us.anthropic.claude-opus-4-8`,
|
||||
"arn:aws:bedrock:us-east-1::foundation-model/anthropic.claude-opus-4-8",
|
||||
"arn:aws:bedrock:us-east-2::foundation-model/anthropic.claude-opus-4-8",
|
||||
"arn:aws:bedrock:us-west-2::foundation-model/anthropic.claude-opus-4-8",
|
||||
],
|
||||
}),
|
||||
);
|
||||
|
||||
// Ship application logs to CloudWatch Logs under /open-swe/<env>/*.
|
||||
this.role.addToPolicy(
|
||||
new iam.PolicyStatement({
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue