@aws-cdk/aws-bedrock-agentcore-alpha
Version:
The CDK Construct Library for Amazon Bedrock
553 lines • 73.2 kB
JavaScript
"use strict";
var __esDecorate = (this && this.__esDecorate) || function (ctor, descriptorIn, decorators, contextIn, initializers, extraInitializers) {
function accept(f) { if (f !== void 0 && typeof f !== "function") throw new TypeError("Function expected"); return f; }
var kind = contextIn.kind, key = kind === "getter" ? "get" : kind === "setter" ? "set" : "value";
var target = !descriptorIn && ctor ? contextIn["static"] ? ctor : ctor.prototype : null;
var descriptor = descriptorIn || (target ? Object.getOwnPropertyDescriptor(target, contextIn.name) : {});
var _, done = false;
for (var i = decorators.length - 1; i >= 0; i--) {
var context = {};
for (var p in contextIn) context[p] = p === "access" ? {} : contextIn[p];
for (var p in contextIn.access) context.access[p] = contextIn.access[p];
context.addInitializer = function (f) { if (done) throw new TypeError("Cannot add initializers after decoration has completed"); extraInitializers.push(accept(f || null)); };
var result = (0, decorators[i])(kind === "accessor" ? { get: descriptor.get, set: descriptor.set } : descriptor[key], context);
if (kind === "accessor") {
if (result === void 0) continue;
if (result === null || typeof result !== "object") throw new TypeError("Object expected");
if (_ = accept(result.get)) descriptor.get = _;
if (_ = accept(result.set)) descriptor.set = _;
if (_ = accept(result.init)) initializers.unshift(_);
}
else if (_ = accept(result)) {
if (kind === "field") initializers.unshift(_);
else descriptor[key] = _;
}
}
if (target) Object.defineProperty(target, contextIn.name, descriptor);
done = true;
};
var __runInitializers = (this && this.__runInitializers) || function (thisArg, initializers, value) {
var useValue = arguments.length > 2;
for (var i = 0; i < initializers.length; i++) {
value = useValue ? initializers[i].call(thisArg, value) : initializers[i].call(thisArg);
}
return useValue ? value : void 0;
};
Object.defineProperty(exports, "__esModule", { value: true });
exports.CodeInterpreterCustom = exports.CodeInterpreterCustomBase = void 0;
const jsiiDeprecationWarnings = require("../../.warnings.jsii.js");
const JSII_RTTI_SYMBOL_1 = Symbol.for("jsii.rtti");
const aws_cdk_lib_1 = require("aws-cdk-lib");
const aws_cloudwatch_1 = require("aws-cdk-lib/aws-cloudwatch");
const iam = require("aws-cdk-lib/aws-iam");
const ec2 = require("aws-cdk-lib/aws-ec2");
const agent_core = require("aws-cdk-lib/aws-bedrockagentcore");
const metadata_resource_1 = require("aws-cdk-lib/core/lib/metadata-resource");
const prop_injectable_1 = require("aws-cdk-lib/core/lib/prop-injectable");
// Internal Libs
const perms = require("./perms");
const validation_helpers_1 = require("./validation-helpers");
const network_configuration_1 = require("../network/network-configuration");
/******************************************************************************
* CONSTANTS
*****************************************************************************/
/**
* Minimum length for code interpreter name
* @internal
*/
const CODE_INTERPRETER_NAME_MIN_LENGTH = 1;
/**
* Maximum length for code interpreter name
* @internal
*/
const CODE_INTERPRETER_NAME_MAX_LENGTH = 48;
/**
* Minimum length for code interpreter tag
* @internal
*/
const CODE_INTERPRETER_TAG_MIN_LENGTH = 1;
/**
* Maximum length for code interpreter tag
* @internal
*/
const CODE_INTERPRETER_TAG_MAX_LENGTH = 256;
/******************************************************************************
* ABSTRACT BASE CLASS
*****************************************************************************/
/**
* Abstract base class for a Code Interpreter.
* Contains methods and attributes valid for Code Interpreters either created with CDK or imported.
*/
class CodeInterpreterCustomBase extends aws_cdk_lib_1.Resource {
static [JSII_RTTI_SYMBOL_1] = { fqn: "@aws-cdk/aws-bedrock-agentcore-alpha.CodeInterpreterCustomBase", version: "2.227.0-alpha.0" };
/**
* An accessor for the Connections object that will fail if this Browser does not have a VPC
* configured.
*/
get connections() {
if (!this._connections) {
throw new aws_cdk_lib_1.ValidationError('Cannot manage network access without configuring a VPC', this);
}
return this._connections;
}
/**
* The actual Connections object for this Browser. This may be unset in the event that a VPC has not
* been configured.
* @internal
*/
_connections;
constructor(scope, id) {
super(scope, id);
}
/**
* Grants IAM actions to the IAM Principal
* @param grantee - The IAM principal to grant permissions to
* @param actions - The actions to grant
* @returns An IAM Grant object representing the granted permissions
*/
grant(grantee, ...actions) {
return iam.Grant.addToPrincipal({
grantee: grantee,
resourceArns: [this.codeInterpreterArn],
actions: actions,
});
}
/**
* Grant read permissions on this code interpreter to an IAM principal.
* This includes both read permissions on the specific code interpreter and list permissions on all code interpreters.
*
* @param grantee - The IAM principal to grant read permissions to
* @default - Default grant configuration:
* - actions: ['bedrock-agentcore:GetCodeInterpreter', 'bedrock-agentcore:GetCodeInterpreterSession'] on this.codeInterpreterArn
* - actions: ['bedrock-agentcore:ListCodeInterpreters', 'bedrock-agentcore:ListCodeInterpreterSessions'] on all resources (*)
* @returns An IAM Grant object representing the granted permissions
*/
grantRead(grantee) {
const resourceSpecificGrant = this.grant(grantee, ...perms.CODE_INTERPRETER_READ_PERMS);
const allResourceGrant = iam.Grant.addToPrincipal({
grantee: grantee,
resourceArns: ['*'],
actions: perms.CODE_INTERPRETER_LIST_PERMS,
});
// Return combined grant
return resourceSpecificGrant.combine(allResourceGrant);
}
/**
* Grant invoke permissions on this code interpreter to an IAM principal.
*
* @param grantee - The IAM principal to grant invoke permissions to
* @default - Default grant configuration:
* - actions: ['bedrock-agentcore:StartCodeInterpreterSession', 'bedrock-agentcore:InvokeCodeInterpreter', 'bedrock-agentcore:StopCodeInterpreterSession']
* - resourceArns: [this.codeInterpreterArn]
* @returns An IAM Grant object representing the granted permissions
*/
grantUse(grantee) {
return this.grant(grantee, ...perms.CODE_INTERPRETER_USE_PERMS);
}
/**
* Grant invoke permissions on this code interpreter to an IAM principal.
*
* @param grantee - The IAM principal to grant invoke permissions to
* @returns An IAM Grant object representing the granted permissions
* @default - Default grant configuration:
* - actions: ['bedrock-agentcore:InvokeCodeInterpreter']
* - resourceArns: [this.codeInterpreterArn]
*/
grantInvoke(grantee) {
return this.grant(grantee, ...perms.CODE_INTERPRETER_INVOKE_PERMS);
}
// ------------------------------------------------------
// Metrics
// ------------------------------------------------------
/**
* Return the given named metric for this code interpreter.
*
* By default, the metric will be calculated as a sum over a period of 5 minutes.
* You can customize this by using the `statistic` and `period` properties.
*/
metric(metricName, dimensions, props) {
const metricProps = {
namespace: 'AWS/Bedrock-AgentCore',
metricName,
dimensionsMap: { ...dimensions, Resource: this.codeInterpreterArn },
...props,
};
return this.configureMetric(metricProps);
}
/**
* Creates a CloudWatch metric for tracking code interpreter api operations..
*
* @param props - Configuration options for the metric
* @default - Default metric configuration:
* - namespace: 'AWS/Bedrock-AgentCore'
* - metricName: metricName
* - dimensionsMap: { CodeInterpreterId: this.codeInterpreterId }
* @returns A CloudWatch Metric configured for code interpreter api operations
*/
metricForApiOperation(metricName, operation, props) {
return this.metric(metricName, { Operation: operation }, props);
}
/**
* Creates a CloudWatch metric for tracking code interpreter latencies.
*
* @param props - Configuration options for the metric
* @default - Default metric configuration:
* - namespace: 'AWS/Bedrock-AgentCore'
* - metricName: Latency
* @returns A CloudWatch Metric configured for code interpreter latencies
*/
metricLatencyForApiOperation(operation, props) {
return this.metricForApiOperation('Latency', operation, { statistic: aws_cloudwatch_1.Stats.AVERAGE, ...props });
}
/**
* Creates a CloudWatch metric for tracking code interpreter invocations.
*
* @param props - Configuration options for the metric
* @default - Default metric configuration:
* - namespace: 'AWS/Bedrock-AgentCore'
* - metricName: Invocations
* @returns A CloudWatch Metric configured for code interpreter invocations
*/
metricInvocationsForApiOperation(operation, props) {
return this.metricForApiOperation('Invocations', operation, {
statistic: aws_cloudwatch_1.Stats.SUM,
...props,
});
}
/**
* Creates a CloudWatch metric for tracking code interpreter errors.
*
* @param props - Configuration options for the metric
* @default - Default metric configuration:
* - namespace: 'AWS/Bedrock-AgentCore'
* - metricName: Errors
* @returns A CloudWatch Metric configured for code interpreter errors
*/
metricErrorsForApiOperation(operation, props) {
return this.metricForApiOperation('Errors', operation, { statistic: aws_cloudwatch_1.Stats.SUM, ...props });
}
/**
* Creates a CloudWatch metric for tracking code interpreter throttles.
*
* @param props - Configuration options for the metric
* @default - Default metric configuration:
* - namespace: 'AWS/Bedrock-AgentCore'
* - metricName: Throttles
* @returns A CloudWatch Metric configured for code interpreter throttles
*/
metricThrottlesForApiOperation(operation, props) {
return this.metricForApiOperation('Throttles', operation, { statistic: aws_cloudwatch_1.Stats.SUM, ...props });
}
/**
* Creates a CloudWatch metric for tracking code interpreter system errors.
*
* @param props - Configuration options for the metric
* @default - Default metric configuration:
* - namespace: 'AWS/Bedrock-AgentCore'
* - metricName: SystemErrors
* @returns A CloudWatch Metric configured for code interpreter system errors
*/
metricSystemErrorsForApiOperation(operation, props) {
return this.metricForApiOperation('SystemErrors', operation, { statistic: aws_cloudwatch_1.Stats.SUM, ...props });
}
/**
* Creates a CloudWatch metric for tracking code interpreter user errors.
*
* @param props - Configuration options for the metric
* @default - Default metric configuration:
* - namespace: 'AWS/Bedrock-AgentCore'
* - metricName: UserErrors
* @returns A CloudWatch Metric configured for code interpreter user errors
*/
metricUserErrorsForApiOperation(operation, props) {
return this.metricForApiOperation('UserErrors', operation, { statistic: aws_cloudwatch_1.Stats.SUM, ...props });
}
/**
* Creates a CloudWatch metric for tracking code interpreter session duration.
*
* @param props - Configuration options for the metric
* @default - Default metric configuration:
* - namespace: 'AWS/Bedrock-AgentCore'
* - metricName: Duration
* @returns A CloudWatch Metric configured for code interpreter session duration
*/
metricSessionDuration(props) {
return this.metric('Duration', { Operation: 'CodeInterpreterSession' }, { statistic: aws_cloudwatch_1.Stats.AVERAGE, ...props });
}
/**
* Internal method to create a metric.
*
* @param props - Configuration options for the metric
* @returns A CloudWatch Metric configured for code interpreter api operations
*/
configureMetric(props) {
return new aws_cloudwatch_1.Metric({
...props,
region: props?.region ?? this.stack.region,
account: props?.account ?? this.stack.account,
});
}
}
exports.CodeInterpreterCustomBase = CodeInterpreterCustomBase;
/******************************************************************************
* Class
*****************************************************************************/
/**
* Custom code interpreter resource for AWS Bedrock Agent Core.
* Provides a sandboxed environment for code execution with configurable network access.
*
* @see https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter.html
* @resource AWS::BedrockAgentCore::CodeInterpreterCustom
*/
let CodeInterpreterCustom = (() => {
let _classDecorators = [prop_injectable_1.propertyInjectable];
let _classDescriptor;
let _classExtraInitializers = [];
let _classThis;
let _classSuper = CodeInterpreterCustomBase;
var CodeInterpreterCustom = class extends _classSuper {
static { _classThis = this; }
static {
const _metadata = typeof Symbol === "function" && Symbol.metadata ? Object.create(_classSuper[Symbol.metadata] ?? null) : void 0;
__esDecorate(null, _classDescriptor = { value: _classThis }, _classDecorators, { kind: "class", name: _classThis.name, metadata: _metadata }, null, _classExtraInitializers);
CodeInterpreterCustom = _classThis = _classDescriptor.value;
if (_metadata) Object.defineProperty(_classThis, Symbol.metadata, { enumerable: true, configurable: true, writable: true, value: _metadata });
}
static [JSII_RTTI_SYMBOL_1] = { fqn: "@aws-cdk/aws-bedrock-agentcore-alpha.CodeInterpreterCustom", version: "2.227.0-alpha.0" };
/** Uniquely identifies this class. */
static PROPERTY_INJECTION_ID = '@aws-cdk.aws-bedrock-agentcore-alpha.CodeInterpreterCustom';
/**
* Static Method for importing an existing Bedrock AgentCore Code Interpreter Custom.
*/
/**
* Creates an Code Interpreter Custom reference from an existing code interpreter's attributes.
*
* @param scope - The construct scope
* @param id - Identifier of the construct
* @param attrs - Attributes of the existing code interpreter custom
* @returns An ICodeInterpreterCustom reference to the existing code interpreter
*/
static fromCodeInterpreterCustomAttributes(scope, id, attrs) {
try {
jsiiDeprecationWarnings._aws_cdk_aws_bedrock_agentcore_alpha_CodeInterpreterCustomAttributes(attrs);
}
catch (error) {
if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
Error.captureStackTrace(error, this.fromCodeInterpreterCustomAttributes);
}
throw error;
}
class Import extends CodeInterpreterCustomBase {
codeInterpreterArn = attrs.codeInterpreterArn;
codeInterpreterId = aws_cdk_lib_1.Arn.split(attrs.codeInterpreterArn, aws_cdk_lib_1.ArnFormat.SLASH_RESOURCE_NAME).resourceName;
executionRole = iam.Role.fromRoleArn(scope, `${id}Role`, attrs.roleArn);
lastUpdatedAt = attrs.lastUpdatedAt;
grantPrincipal = this.executionRole;
status = attrs.status;
createdAt = attrs.createdAt;
constructor(s, i) {
super(s, i);
this.grantPrincipal = this.executionRole || new iam.UnknownPrincipal({ resource: this });
if (attrs.securityGroups) {
this._connections = new ec2.Connections({
securityGroups: attrs.securityGroups,
});
}
}
}
// Return new Code Interpreter Custom
return new Import(scope, id);
}
// ------------------------------------------------------
// Attributes
// ------------------------------------------------------
/**
* The ARN of the code interpreter resource
* @attribute
*/
codeInterpreterArn;
/**
* The id of the code interpreter
* @attribute
*/
codeInterpreterId;
/**
* The name of the code interpreter
*/
name;
/**
* The description of the code interpreter
*/
description;
/**
* The network configuration of the code interpreter
*/
networkConfiguration;
/**
* The status of the code interpreter
* @attribute
*/
status;
/**
* The created timestamp of the code interpreter
* @attribute
*/
createdAt;
/**
* The last updated timestamp of the code interpreter
* @attribute
*/
lastUpdatedAt;
/**
* The failure reason of the code interpreter
* @attribute
*/
failureReason;
/**
* The IAM role that provides permissions for the code interpreter to access AWS services.
*/
executionRole;
/**
* The principal to grant permissions to
*/
grantPrincipal;
/**
* Tags applied to this code interpreter resource
* A map of key-value pairs for resource tagging
* @default - No tags applied
*/
tags;
// ------------------------------------------------------
// Internal Only
// ------------------------------------------------------
__resource;
constructor(scope, id, props) {
super(scope, id);
try {
jsiiDeprecationWarnings._aws_cdk_aws_bedrock_agentcore_alpha_CodeInterpreterCustomProps(props);
}
catch (error) {
if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
Error.captureStackTrace(error, CodeInterpreterCustom);
}
throw error;
}
// Enhanced CDK Analytics Telemetry
(0, metadata_resource_1.addConstructMetadata)(this, props);
// ------------------------------------------------------
// Set properties and defaults
// ------------------------------------------------------
this.name = props.codeInterpreterCustomName;
this.description = props.description;
this.networkConfiguration = props.networkConfiguration ?? network_configuration_1.CodeInterpreterNetworkConfiguration.usingPublicNetwork();
this.executionRole = props.executionRole ?? this._createCodeInterpreterRole();
this.grantPrincipal = this.executionRole;
this.tags = props.tags;
// Validate code interpreter name
(0, validation_helpers_1.throwIfInvalid)(this._validateCodeInterpreterName, this.name);
// Validate code interpreter tags
(0, validation_helpers_1.throwIfInvalid)(this._validateCodeInterpreterTags, this.tags);
// Network configuration and validation is done in the network configuration class
// So we don't need to validate it here
// Set connections - create a shared connections object
if (this.networkConfiguration.connections) {
// Use the network configuration's connections as the shared object
this._connections = this.networkConfiguration.connections;
}
// ------------------------------------------------------
// CFN Props - With Lazy support
// ------------------------------------------------------
const cfnProps = {
name: this.name,
description: this.description,
networkConfiguration: aws_cdk_lib_1.Lazy.any({ produce: () => this.networkConfiguration._render(this._connections) }),
executionRoleArn: this.executionRole?.roleArn,
tags: this.tags,
};
// L1 instantiation
this.__resource = new agent_core.CfnCodeInterpreterCustom(this, 'Resource', cfnProps);
// Get attributes directly from the CloudFormation resource
this.codeInterpreterId = this.__resource.attrCodeInterpreterId;
this.codeInterpreterArn = this.__resource.attrCodeInterpreterArn;
this.status = this.__resource.attrStatus;
this.createdAt = this.__resource.attrCreatedAt;
this.lastUpdatedAt = this.__resource.attrLastUpdatedAt;
this.failureReason = this.__resource.attrFailureReason;
}
// ------------------------------------------------------
// Validators
// ------------------------------------------------------
/**
* Validates the code interpreter name format
* @param name The code interpreter name to validate
* @returns Array of validation error messages, empty if valid
* @internal This is an internal core function and should not be called directly.
*/
_validateCodeInterpreterName = (name) => {
let errors = [];
errors.push(...(0, validation_helpers_1.validateStringFieldLength)({
value: name,
fieldName: 'Code interpreter name',
minLength: CODE_INTERPRETER_NAME_MIN_LENGTH,
maxLength: CODE_INTERPRETER_NAME_MAX_LENGTH,
}));
// Check if name matches the AWS API pattern: [a-zA-Z][a-zA-Z0-9_]{0,47}
// Must start with a letter, followed by up to 47 letters, numbers, or underscores
const validNamePattern = /^[a-zA-Z][a-zA-Z0-9_]{0,47}$/;
errors.push(...(0, validation_helpers_1.validateFieldPattern)(name, 'Code interpreter name', validNamePattern));
return errors;
};
/**
* Validates the code interpreter tags format
* @param tags The tags object to validate
* @returns Array of validation error messages, empty if valid
* @internal This is an internal core function and should not be called directly.
*/
_validateCodeInterpreterTags = (tags) => {
let errors = [];
if (!tags) {
return errors; // Tags are optional
}
// Validate each tag key and value
for (const [key, value] of Object.entries(tags)) {
errors.push(...(0, validation_helpers_1.validateStringFieldLength)({
value: key,
fieldName: 'Tag key',
minLength: CODE_INTERPRETER_TAG_MIN_LENGTH,
maxLength: CODE_INTERPRETER_TAG_MAX_LENGTH,
}));
// Validate tag key pattern: ^[a-zA-Z0-9\s._:/=+@-]*$
const validKeyPattern = /^[a-zA-Z0-9\s._:/=+@-]*$/;
errors.push(...(0, validation_helpers_1.validateFieldPattern)(key, 'Tag key', validKeyPattern));
// Validate tag value
errors.push(...(0, validation_helpers_1.validateStringFieldLength)({
value: value,
fieldName: 'Tag value',
minLength: CODE_INTERPRETER_TAG_MIN_LENGTH,
maxLength: CODE_INTERPRETER_TAG_MAX_LENGTH,
}));
// Validate tag value pattern: ^[a-zA-Z0-9\s._:/=+@-]*$
const validValuePattern = /^[a-zA-Z0-9\s._:/=+@-]*$/;
errors.push(...(0, validation_helpers_1.validateFieldPattern)(value, 'Tag value', validValuePattern));
}
return errors;
};
/**
* Creates execution role needed for the code interpreter to access AWS services
* @returns The created role
* @internal This is an internal core function and should not be called directly.
*/
_createCodeInterpreterRole() {
const role = new iam.Role(this, 'ServiceRole', {
assumedBy: new iam.ServicePrincipal('bedrock-agentcore.amazonaws.com'),
});
return role;
}
static {
__runInitializers(_classThis, _classExtraInitializers);
}
};
return CodeInterpreterCustom = _classThis;
})();
exports.CodeInterpreterCustom = CodeInterpreterCustom;
//# sourceMappingURL=data:application/json;base64,