diff --git a/evals/reviewer/config.toml b/evals/reviewer/config.toml index d8e659f5..86364682 100644 --- a/evals/reviewer/config.toml +++ b/evals/reviewer/config.toml @@ -9,8 +9,9 @@ langsmith_project = "open-swe-evals" # Leave blank to use LANGGRAPH_URL or local dev. langgraph_url = "" assistant_id = "reviewer" -# models: openai:gpt-5.5, anthropic:claude-opus-4-8, google_genai:gemini-3.5-flash -model_id = "google_genai:gemini-3.5-flash" +# models (post Bedrock/Fireworks migration): bedrock_converse:us.anthropic.claude-opus-4-8, +# or any fireworks:* id in agent/dashboard/options.py SUPPORTED_MODELS. +model_id = "bedrock_converse:us.anthropic.claude-opus-4-8" reasoning_effort = "medium" # score_mode: diff --git a/infra/README.md b/infra/README.md index b5c866a8..fc49e49b 100644 --- a/infra/README.md +++ b/infra/README.md @@ -156,7 +156,7 @@ Three buckets: | `DASHBOARD_BASE_URL` | `https://openswe-dev.seahaven.com` *(confirm host)* | `https://openswe.seahaven.com` *(confirm host)* | | `DASHBOARD_API_BASE_URL` | same as base | same as base | | `DASHBOARD_ALLOWED_ORIGINS` | same as base | same as base | - | `LLM_MODEL_ID` | `anthropic:claude-opus-4-8` *(confirm)* | `anthropic:claude-opus-4-8` *(confirm)* | + | `LLM_MODEL_ID` | `bedrock_converse:us.anthropic.claude-opus-4-8` | `bedrock_converse:us.anthropic.claude-opus-4-8` | 3. **Out-of-band SSM config — NOT created by CDK.** Operationally-variable or env-specific-unknown values listed in `OUT_OF_BAND_SSM` and populated by diff --git a/infra/lib/constructs/config-store.ts b/infra/lib/constructs/config-store.ts index 4bc79a52..4cae862c 100644 --- a/infra/lib/constructs/config-store.ts +++ b/infra/lib/constructs/config-store.ts @@ -142,8 +142,12 @@ export function iacManagedSsm(env: EnvName): Record { DASHBOARD_BASE_URL: host, DASHBOARD_API_BASE_URL: host, DASHBOARD_ALLOWED_ORIGINS: host, - // Primary builder model (project memory team_settings: anthropic:claude-opus-4-8). - LLM_MODEL_ID: "anthropic:claude-opus-4-8", + // Primary builder model. seed_store.sh's `pick` precedence is + // OPENSWE_AGENT_MODEL > SEED_AGENT_MODEL > LLM_MODEL_ID > script default, so this + // SSM value overrides the seed-script default — it MUST be a supported id. Post + // Bedrock/Fireworks migration the only Bedrock-Claude id is the inference profile; + // `anthropic:claude-opus-4-8` was removed from SUPPORTED_MODELS. + LLM_MODEL_ID: "bedrock_converse:us.anthropic.claude-opus-4-8", }; // Dev e2e smoke: seed the owner's user_mapping so an @openswe comment from the // triggering GitHub login resolves (an unmapped commenter is silently skipped). diff --git a/infra/lib/constructs/instance-role.ts b/infra/lib/constructs/instance-role.ts index 4a32de9a..21d18859 100644 --- a/infra/lib/constructs/instance-role.ts +++ b/infra/lib/constructs/instance-role.ts @@ -117,6 +117,29 @@ export class InstanceRole extends Construct { // moves these to a customer CMK, add a scoped `kms:Decrypt` on that key ARN // ONLY (not `*`). + // Invoke the Bedrock Claude model. DEFAULT_MODEL_ID is + // `bedrock_converse:us.anthropic.claude-opus-4-8`, and the model runs in the + // LangGraph server PROCESS on this box (not in the sandbox), so the EC2 + // instance role is the calling principal. The `us.` cross-region inference + // profile fans out to us-east-1 / us-east-2 / us-west-2, and Bedrock authorizes + // InvokeModel against BOTH the inference-profile ARN AND the underlying + // foundation-model ARN in each routed region — all four resources are required + // or the call AccessDenies. Scoped to opus-4-8 ONLY (least-privilege): adding a + // new Bedrock model to SUPPORTED_MODELS means extending this resource list. + // IAM change — flag for T4 (GPT-4.1 IAM cross-review) / T5 (/sh-security-review). + this.role.addToPolicy( + new iam.PolicyStatement({ + sid: "InvokeBedrockClaude", + actions: ["bedrock:InvokeModel", "bedrock:InvokeModelWithResponseStream"], + resources: [ + `arn:aws:bedrock:${REGION}:${ACCOUNT}:inference-profile/us.anthropic.claude-opus-4-8`, + "arn:aws:bedrock:us-east-1::foundation-model/anthropic.claude-opus-4-8", + "arn:aws:bedrock:us-east-2::foundation-model/anthropic.claude-opus-4-8", + "arn:aws:bedrock:us-west-2::foundation-model/anthropic.claude-opus-4-8", + ], + }), + ); + // Ship application logs to CloudWatch Logs under /open-swe//*. this.role.addToPolicy( new iam.PolicyStatement({