Skip to content

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) - #2133

Merged
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean
Aug 27, 2026
Merged

feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session)#2133
tejaskash merged 2 commits into
mainfrom
feat/capacity-provider-devex-clean

Conversation

@xxuam

@xxuam xxuam commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Description

Completes the AgentCore Capacity Provider feature end to end and brings its DevEx to parity with the rest of the CLI.

This PR carries two commits — the revert-of-revert that restores Journey 1, plus a new commit adding Journeys 2–4 and the DevEx polish — so it delivers the full feature:

  • J1 — create/remove a capacity provider as a first-class project resource (add capacity-provider / remove capacity-provider), persisted to agentcore.json and synthesized to an
    AWS::BedrockAgentCore::CapacityProvider CloudFormation resource (VPC, launch parameters, named EBS volumes, lifecycle, auto-created operator role), with deploy/status integration. (Restored here via
    revert-of-revert; originally feat(capacity-provider): add capacity-provider resource (Journey 1) #2030, reverted in revert: remove capacity-provider Journey 1 #2045 for release timing.)
  • J2 — attach a runtime to a capacity provider by in-project name or external ARN (add agent --capacity-provider <name-or-arn>), rendered as capacityProviderConfiguration on the runtime (network config
    is mutually exclusive and omitted).
  • J3 — mount capacity-provider volumes into a runtime (--cp-volume-name / --cp-volume-mount-path), routed through the existing filesystem-mount framework.
  • J4 — capacity-provider delete-session data-plane command to deprovision a live CP session (destructive confirm, --yes, name/id/ARN resolution).
  • TUI parity: full interactive add capacity-provider wizard (named volumes, EBS encryption + KMS key, instance profile, lifecycle timeouts); capacity-provider attach is now available in the agent
    create/template flow (and agentcore create) as well as the BYO flow.
  • DevEx polish: paired --volume-name / --volume-size flags (replacing --volume name:sizeGiB, for consistency with the other paired flags); a referential-integrity guard that blocks removing a capacity
    provider still referenced by a runtime; and removal of the [preview] label from the CP add/remove menus.
  • Bumps @aws-sdk/client-bedrock-agentcore to a version that ships DeleteCapacityProviderSessionCommand.

Related Issue

Closes #

Documentation PR

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe):

Testing

How have you tested the change?

  • I ran npm run test:unit and npm run test:integ
  • I ran npm run typecheck
  • I ran npm run lint
  • If I modified src/assets/, I ran npm run test:update-snapshots and committed the updated snapshots

Details:

  • Unit: full suite green (6219 tests). Added coverage for the paired volume flags, the advanced parity flags (instance-profile / encryption+KMS / lifecycle), the buildCreateAgentConfig mapping, the
    useGenerateWizard CP flow, the wizard buildSteps sequencing, and a duplicate-menu guard.
  • Integ: capacity-provider add/remove and add-agent-attach integ tests pass against the real CLI binary.
  • Typecheck + lint: clean (no new warnings).
  • Interactive TUI (harness): drove the add capacity-provider wizard (forward + back-navigation, including encrypt→KMS→back→No), the agent create/template CP attach, agentcore create with a CP-by-ARN, and
    the BYO CP flow.
  • Live end-to-end (us-west-2): deployed a template agent on an arm64 capacity provider with a mounted volume → CP + runtime READY, invoke returned a response, delete-session deprovisioned the session,
    and teardown removed the stack cleanly.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

⚠️ Dependent change / merge order: this PR consumes capacity-provider support from @aws/agentcore-cdk (the L3 constructs), which is a separate PR (feat/capacity-provider-attach in
agentcore-l3-cdk-constructs). That L3 PR must merge and publish a new alpha, and the @aws/agentcore-cdk pin here must be bumped to it, before capacity-provider deploys work off the pinned version. (Verified
locally against a bundled build of the L3 branch.)


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

xxuam and others added 2 commits August 27, 2026 20:28
…d DevEx polish

- J2/J3: attach a runtime to a capacity provider by name or ARN, and mount CP volumes
- J4: `capacity-provider delete-session` data-plane command
- TUI: full add-capacity-provider wizard (volumes, encryption/KMS, instance profile,
  lifecycle timeouts); capacity-provider attach in the agent create/template and BYO flows
- paired `--volume-name`/`--volume-size` flags (replacing `--volume name:sizeGiB`)
- referential-integrity guard: block removing a capacity provider still referenced by a runtime
- drop `[preview]` from the capacity-provider add/remove menus

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- BYO mapper (mapByoConfigToAgent) omits networkMode when a CP is attached —
  the AgentEnvSpec schema rejects a capacityProviderConfiguration combined with
  any networkMode, so a BYO CP submission was failing to persist.
- delete-session by-name resolution collects all deployed-state matches and
  disambiguates by region (resolve within --region; reject cross-region
  ambiguity) instead of blindly taking the first target.
- forward capacityProviderConfiguration + volumes through the import path
  (executeImportAgent params + AgentPrimitive/useAddAgent/create callers).
- create rejects the capacity-provider name form (a new project has no sibling
  to resolve); only an external ARN can attach at create time.
- generate + BYO wizard advanced-settings routing matches the steps memo when
  network and capacityProvider are both selected (CP wins; no skipped screen).
- preserve an explicit volumeEncrypted=false in the CP wizard so the primitive
  emits Encrypted:false (service default is true).
- tighten CAPACITY_PROVIDER_ARN_PATTERN to {name}-{10 alnum} so malformed
  external ARNs fail at validate time (kept in sync with @aws/agentcore-cdk).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xxuam
xxuam requested a review from a team August 27, 2026 20:39
@github-actions github-actions Bot added the size/xl PR size: XL label Aug 27, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Aug 27, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Aug 27, 2026

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Nice work — this PR is thorough and well-covered. Highlights I looked at closely:

  • Schema invariants (CapacityProviderConfiguration exactly-one, mutual exclusion with networkMode/networkConfig, capacityProviderVolume requires an attachment, referential integrity for in-project sibling references + volume names in AgentCoreProjectSpecSchema) all have matching tests.
  • resolveDeleteTarget disambiguates a by-name CP across regions correctly, prefers the ARN-derived region, and never mixes an id from one target with a region from another. Nice guards.
  • Destructive prompt: refuses to proceed on non-TTY, defaults to N on bare Enter, and requires --yes for non-interactive. Session-id and CP-id/ARN validation happen before any network call.
  • Telemetry is instrumented for capacity-provider.delete-session, plus has_capacity_provider / capacity_provider_by_arn / cp_volume_mount_count on create and add.agent in both the CLI and TUI paths.
  • Wizard sequencing: computeByoSteps / useGenerateWizard correctly drop network steps when CP is selected (CP wins), and both the BYO screen's onSelect handlers and the TUI dispatch match that precedence — with tests, including the duplicate-menu guard.
  • Deploy flow: useDeployFlow was updated to parse CP outputs so TUI deploys populate deployed-state (needed for the by-name path of delete-session).
  • The --volume name:sizeGiB → paired --volume-name / --volume-size migration is a breaking flag change, but the PR body calls it out as intentional pre-GA polish (the [preview] label is also being removed in this PR), and the integ tests + snapshots are updated to match.

The PR body notes a merge-order dependency on the L3 constructs PR (@aws/agentcore-cdk pin bump) before capacity-provider deploys work off the pinned version — worth confirming that lands before this ships, but that's an author-flagged coordination item, not a code issue.

No changes requested.

@agentcore-devx-automation agentcore-devx-automation Bot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Aug 27, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 41.09% 15754 / 38332
🔵 Statements 40.35% 16802 / 41631
🔵 Functions 35.2% 2713 / 7706
🔵 Branches 34.26% 10537 / 30750
Generated in workflow #4439 for commit a1a48e8 by the Vitest Coverage Report Action

@tejaskash tejaskash changed the title feat(capacity-provider): CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) feat(capacity-provider): complete CLI DevEx for journeys 2-4 (attach, volumes, TUI wizard, J4 delete-session) Aug 27, 2026
@github-actions github-actions Bot added size/xl PR size: XL and removed size/xl PR size: XL labels Aug 27, 2026

@tejaskash tejaskash left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed the clean head after the earlier capacity-provider findings were addressed. The fixes for network-mode exclusivity, regional target resolution, import/create forwarding, wizard routing, explicit false encryption, and ARN validation are present with focused coverage; the broader CI and e2e suites are green.

@tejaskash
tejaskash merged commit cbce862 into main Aug 27, 2026
83 of 85 checks passed
@tejaskash
tejaskash deleted the feat/capacity-provider-devex-clean branch August 27, 2026 21:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/xl PR size: XL

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants