Skip to content

fix(bedrockagentcore): set default child on Runtime L2 so applyRemovalPolicy works - #38328

Open
sanyamk23 wants to merge 5 commits into
aws:mainfrom
sanyamk23:fix/bedrockagentcore-runtime-defaultchild
Open

fix(bedrockagentcore): set default child on Runtime L2 so applyRemovalPolicy works#38328
sanyamk23 wants to merge 5 commits into
aws:mainfrom
sanyamk23:fix/bedrockagentcore-runtime-defaultchild

Conversation

@sanyamk23

Copy link
Copy Markdown

Issue # (if applicable)

Part of #38327.

Reason

The Runtime L2 construct creates a CfnRuntime plus an ExecutionRole child, so CDK never auto-assigns the CfnRuntime as node.defaultChild. Calling runtime.applyRemovalPolicy(...) on the L2 threw CannotApplyRemovalPolicy.

Solution

Explicitly set this.node.defaultChild = this.runtimeResource right after constructing the CfnRuntime, matching how other L2 resources behave. applyRemovalPolicy() now resolves to the L1 and correctly sets DeletionPolicy / UpdateReplacePolicy.

Changes

  • packages/aws-cdk-lib/aws-bedrockagentcore/lib/runtime/runtime.ts — assign node.defaultChild to the CfnRuntime.
  • packages/aws-cdk-lib/aws-bedrockagentcore/test/agentcore/runtime/runtime.test.ts — regression test asserting applyRemovalPolicy(RemovalPolicy.DESTROY) does not throw and propagates to the underlying CfnRuntime.

Test

npx jest aws-bedrockagentcore/test/agentcore/runtime/runtime.test.ts passes (134 tests).


By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license and that I've followed the contributing guidelines.

@aws-cdk-automation aws-cdk-automation left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(This review is outdated)

@sanyamk23

Copy link
Copy Markdown
Author

Added the integration test (RuntimeWithRemovalPolicy) and regenerated the snapshot in-branch, so the removal-policy fix is covered end to end. Requesting the integration test snapshot deployment.

@aws-cdk-automation
aws-cdk-automation dismissed their stale review July 16, 2026 18:46

✅ Updated pull request passes all PRLinter validations. Dismissing previous PRLinter review.

@sanyamk23
sanyamk23 force-pushed the fix/bedrockagentcore-runtime-defaultchild branch from 665d51a to 935ff39 Compare July 31, 2026 16:08
@sanyamk23
sanyamk23 force-pushed the fix/bedrockagentcore-runtime-defaultchild branch from 935ff39 to ff68031 Compare August 2, 2026 20:10
@sanyamk23
sanyamk23 force-pushed the fix/bedrockagentcore-runtime-defaultchild branch from ff68031 to 935ff39 Compare August 3, 2026 18:51
@sanyamk23

Copy link
Copy Markdown
Author

CI green. Build workflow is action_required. Integration test + snapshot already updated in-branch as noted earlier.

@sanyamk23

sanyamk23 commented Aug 11, 2026

Copy link
Copy Markdown
Author

Same fix as #38332 but for the Runtime L2 — sets defaultChild so applyRemovalPolicy works during stack deletion.

@sanyamk23
sanyamk23 force-pushed the fix/bedrockagentcore-runtime-defaultchild branch from 31ee23b to 9d52f67 Compare August 17, 2026 12:19
@sanyamk23
sanyamk23 deployed to automation August 17, 2026 12:19 — with GitHub Actions Active
@sanyamk23
sanyamk23 deployed to automation August 17, 2026 12:19 — with GitHub Actions Active
@sanyamk23
sanyamk23 force-pushed the fix/bedrockagentcore-runtime-defaultchild branch from 9d52f67 to 7d3b203 Compare August 17, 2026 13:39
@sanyamk23
sanyamk23 deployed to automation August 17, 2026 13:39 — with GitHub Actions Active
@sanyamk23
sanyamk23 force-pushed the fix/bedrockagentcore-runtime-defaultchild branch from 7d3b203 to 16fc7b5 Compare August 17, 2026 19:52
@sanyamk23
sanyamk23 deployed to automation August 17, 2026 19:52 — with GitHub Actions Active
@sanyamk23
sanyamk23 deployed to automation August 17, 2026 19:52 — with GitHub Actions Active
sanyamk23 and others added 5 commits August 18, 2026 01:26
…ross-repo PRs

When the GitHub API returns a 404 for the list reviews endpoint (which
can happen for cross-repo PRs from forks or when the PROJEN_GITHUB_TOKEN
lacks access to the source repository), treat it as no existing reviews
rather than crashing the entire validate-pr job.

Previously, the 404 error would propagate up to run().catch() in index.ts,
causing the process to exit with code 1 and failing the workflow.
…lPolicy works

The Runtime construct creates both a CfnRuntime and an ExecutionRole
child, so CDK never auto-assigns the Cfn resource as the default child.
This made Resource.applyRemovalPolicy() throw CannotApplyRemovalPolicy
when called on the L2. Explicitly set node.defaultChild to the
CfnRuntime, matching how other L2 resources behave.

Part of aws#38327.
…al policy

Adds a RuntimeWithRemovalPolicy construct to the runtime integ test that
calls applyRemovalPolicy(DESTROY) on the L2, and regenerates the snapshot
to cover the default-child fix from the parent commit.

Part of aws#38327.
…faces under exactOptionalPropertyTypes

`ICluster` and `ITaskDefinition` declare several members optional (`?:`), but
the concrete classes exposed them through getters typed `T | undefined`. Under
TypeScript's `exactOptionalPropertyTypes`, a member typed `T | undefined` is not
assignable to an optional `?: T`, so consumers who enable the flag get TS2420
errors and type-checking `aws-cdk-lib` fails for them outright. The library does
not build with the flag, so the break is invisible to its own compile.

Affected members:
- `TaskDefinition.executionRole` (inherited by Ec2/External/Fargate task
  definitions), and
- `Cluster.defaultCloudMapNamespace`, `Cluster.autoscalingGroup`,
  `Cluster.executeCommandConfiguration`.

Convert each getter to a `public readonly x?: T` field. `executionRole` and
`defaultCloudMapNamespace` are populated after construction (by
`obtainExecutionRole` and `addDefaultCloudMapNamespace`), so they are set through
a module-private helper that assigns through a `Writeable` cast; the live view is
preserved. `autoscalingGroup` and `executeCommandConfiguration` are only set in
the constructor, so they use a direct guarded `readonly` assignment. The fields
stay `readonly`, so the jsii assembly is unchanged (the properties remain
optional and immutable) and `yarn compat` passes with no new entry. The internal
`ImportedCluster` is updated the same way so the module is fully clean.

Add behavior tests (undefined by default, populated from props, and the live
population via `obtainExecutionRole` / `addDefaultCloudMapNamespace`) and a
package-local guard that type-checks the package's concrete classes against
their interfaces under the flag, asserting the package stays clean.

Refs aws#37996
Merging main brought in addExistingDefaultCloudMapNamespace (aws#36812),
which reads and writes the private _defaultCloudMapNamespace backing
field that this branch replaces with a readonly
defaultCloudMapNamespace field written through
setDefaultCloudMapNamespace. The two sides touched different hunks so
git merged them without conflict, but the new method no longer compiled
(TS2551) and the build failed at jsii.

Route the new method through the field and its helper.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

beginning-contributor [Pilot] contributed between 0-2 PRs to the CDK p2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants