fix(bedrockagentcore): set default child on Runtime L2 so applyRemovalPolicy works - #38328
Open
sanyamk23 wants to merge 5 commits into
Open
fix(bedrockagentcore): set default child on Runtime L2 so applyRemovalPolicy works#38328sanyamk23 wants to merge 5 commits into
sanyamk23 wants to merge 5 commits into
Conversation
13 tasks
aws-cdk-automation
previously requested changes
Jul 16, 2026
Author
|
Added the integration test (RuntimeWithRemovalPolicy) and regenerated the snapshot in-branch, so the removal-policy fix is covered end to end. Requesting the integration test snapshot deployment. |
aws-cdk-automation
dismissed
their stale review
July 16, 2026 18:46
✅ Updated pull request passes all PRLinter validations. Dismissing previous PRLinter review.
sanyamk23
force-pushed
the
fix/bedrockagentcore-runtime-defaultchild
branch
from
July 31, 2026 16:08
665d51a to
935ff39
Compare
sanyamk23
force-pushed
the
fix/bedrockagentcore-runtime-defaultchild
branch
from
August 2, 2026 20:10
935ff39 to
ff68031
Compare
sanyamk23
force-pushed
the
fix/bedrockagentcore-runtime-defaultchild
branch
from
August 3, 2026 18:51
ff68031 to
935ff39
Compare
abidhasan-aws
temporarily deployed
to
automation
August 7, 2026 11:10 — with
GitHub Actions
Inactive
abidhasan-aws
temporarily deployed
to
automation
August 7, 2026 11:10 — with
GitHub Actions
Inactive
Author
|
CI green. Build workflow is action_required. Integration test + snapshot already updated in-branch as noted earlier. |
Author
|
Same fix as #38332 but for the Runtime L2 — sets defaultChild so applyRemovalPolicy works during stack deletion. |
sanyamk23
force-pushed
the
fix/bedrockagentcore-runtime-defaultchild
branch
from
August 17, 2026 12:19
31ee23b to
9d52f67
Compare
sanyamk23
force-pushed
the
fix/bedrockagentcore-runtime-defaultchild
branch
from
August 17, 2026 13:39
9d52f67 to
7d3b203
Compare
sanyamk23
force-pushed
the
fix/bedrockagentcore-runtime-defaultchild
branch
from
August 17, 2026 19:52
7d3b203 to
16fc7b5
Compare
…ross-repo PRs When the GitHub API returns a 404 for the list reviews endpoint (which can happen for cross-repo PRs from forks or when the PROJEN_GITHUB_TOKEN lacks access to the source repository), treat it as no existing reviews rather than crashing the entire validate-pr job. Previously, the 404 error would propagate up to run().catch() in index.ts, causing the process to exit with code 1 and failing the workflow.
…lPolicy works The Runtime construct creates both a CfnRuntime and an ExecutionRole child, so CDK never auto-assigns the Cfn resource as the default child. This made Resource.applyRemovalPolicy() throw CannotApplyRemovalPolicy when called on the L2. Explicitly set node.defaultChild to the CfnRuntime, matching how other L2 resources behave. Part of aws#38327.
…al policy Adds a RuntimeWithRemovalPolicy construct to the runtime integ test that calls applyRemovalPolicy(DESTROY) on the L2, and regenerates the snapshot to cover the default-child fix from the parent commit. Part of aws#38327.
…faces under exactOptionalPropertyTypes `ICluster` and `ITaskDefinition` declare several members optional (`?:`), but the concrete classes exposed them through getters typed `T | undefined`. Under TypeScript's `exactOptionalPropertyTypes`, a member typed `T | undefined` is not assignable to an optional `?: T`, so consumers who enable the flag get TS2420 errors and type-checking `aws-cdk-lib` fails for them outright. The library does not build with the flag, so the break is invisible to its own compile. Affected members: - `TaskDefinition.executionRole` (inherited by Ec2/External/Fargate task definitions), and - `Cluster.defaultCloudMapNamespace`, `Cluster.autoscalingGroup`, `Cluster.executeCommandConfiguration`. Convert each getter to a `public readonly x?: T` field. `executionRole` and `defaultCloudMapNamespace` are populated after construction (by `obtainExecutionRole` and `addDefaultCloudMapNamespace`), so they are set through a module-private helper that assigns through a `Writeable` cast; the live view is preserved. `autoscalingGroup` and `executeCommandConfiguration` are only set in the constructor, so they use a direct guarded `readonly` assignment. The fields stay `readonly`, so the jsii assembly is unchanged (the properties remain optional and immutable) and `yarn compat` passes with no new entry. The internal `ImportedCluster` is updated the same way so the module is fully clean. Add behavior tests (undefined by default, populated from props, and the live population via `obtainExecutionRole` / `addDefaultCloudMapNamespace`) and a package-local guard that type-checks the package's concrete classes against their interfaces under the flag, asserting the package stays clean. Refs aws#37996
Merging main brought in addExistingDefaultCloudMapNamespace (aws#36812), which reads and writes the private _defaultCloudMapNamespace backing field that this branch replaces with a readonly defaultCloudMapNamespace field written through setDefaultCloudMapNamespace. The two sides touched different hunks so git merged them without conflict, but the new method no longer compiled (TS2551) and the build failed at jsii. Route the new method through the field and its helper.
sanyamk23
force-pushed
the
fix/bedrockagentcore-runtime-defaultchild
branch
from
August 17, 2026 19:57
16fc7b5 to
a2f87d5
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue # (if applicable)
Part of #38327.
Reason
The
RuntimeL2 construct creates aCfnRuntimeplus anExecutionRolechild, so CDK never auto-assigns theCfnRuntimeasnode.defaultChild. Callingruntime.applyRemovalPolicy(...)on the L2 threwCannotApplyRemovalPolicy.Solution
Explicitly set
this.node.defaultChild = this.runtimeResourceright after constructing theCfnRuntime, matching how other L2 resources behave.applyRemovalPolicy()now resolves to the L1 and correctly setsDeletionPolicy/UpdateReplacePolicy.Changes
packages/aws-cdk-lib/aws-bedrockagentcore/lib/runtime/runtime.ts— assignnode.defaultChildto theCfnRuntime.packages/aws-cdk-lib/aws-bedrockagentcore/test/agentcore/runtime/runtime.test.ts— regression test assertingapplyRemovalPolicy(RemovalPolicy.DESTROY)does not throw and propagates to the underlyingCfnRuntime.Test
npx jest aws-bedrockagentcore/test/agentcore/runtime/runtime.test.tspasses (134 tests).By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license and that I've followed the contributing guidelines.