Repository navigation
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
enyst
left a comment
There was a problem hiding this comment.
I'm an AI agent based on Opus 5.5, helping Engel Nyst (@enyst) with project work.
- Rebase: main removed
llms.txtandllms-full.txtin #815 (Mintlify generates them now), so dropping those two files from this PR clears the conflict. #879 adds a card at the same spot inintegrations/overview.mdx, and #872/#879 change the samedocs.jsonline. - Checked: the Replicated fields and per-line
bedrock/<id>routes (openhands.yaml#L1091), and thelitellm-helm.serviceAccountkeys. - Two points inline. The credential claim on line 9 doesn't hold for Replicated, and the profile settings differ from #872 and #879.
|
|
||
| OpenHands Enterprise can use Amazon Bedrock through its bundled LiteLLM | ||
| gateway. Configure the gateway according to how you installed OpenHands. | ||
| The IAM identity that calls Bedrock belongs to the **LiteLLM pod**, not to an |
There was a problem hiding this comment.
This holds for the Helm IRSA setup, but not for Replicated:
- With
Access Key + Secret, the installer also copies the keys intoglobal.agentServerEnv, which is the sandbox environment (openhands.yaml#L1074-L1077). - With
EC2 Instance Profileand a hop limit of 2, any pod on the node can reach IMDS, sandboxes included. The chart ships no NetworkPolicy.
Could you limit this sentence to the Helm path, or describe the Replicated behavior? Admins may scope IAM permissions based on it.
There was a problem hiding this comment.
Thank you for catching this distinction. Updated the introduction to limit the IAM statement to the Helm IRSA example, and added the Replicated credential behavior separately. The note now explains that static AWS keys also reach sandbox environments and that an EC2 response hop limit of 2 does not provide gateway-only credential isolation.
| | --- | --- | | ||
| | Profile Name | `Bedrock-Haiku-4-5` | | ||
| | Custom Model | `litellm_proxy/bedrock-haiku-4-5` | | ||
| | Base URL | `http://openhands-litellm.openhands.svc.cluster.local:4000/v1` | |
There was a problem hiding this comment.
#872 and #879 use openhands/<alias> with a base URL that exactly matches LITE_LLM_API_URL (no /v1). The app treats that form as the managed proxy: it compares the base URL exactly (saas_settings_store.py#L110-L113) and stores bundled-proxy routes as openhands/<route> (constants.py#L243-L256). The /v1 form evidently works, since you tested it, but the three guides would be less confusing if they matched:
| | Base URL | `http://openhands-litellm.openhands.svc.cluster.local:4000/v1` | | |
| | Base URL | `http://openhands-litellm.openhands.svc.cluster.local:4000` | |
Then use openhands/bedrock-haiku-4-5 on line 158 and openhands/bedrock-sonnet-4-5 on line 165, and drop "/v1" on line 188.
There was a problem hiding this comment.
We validated litellm_proxy/... through working conversations on both Helm and Replicated. Additional testing confirmed that openhands/... works after an explicit profile switch, but the EKS profile-save workflow removed the gateway URL and the initial conversation failed authentication. We’re retaining the validated setup instructions until the replacement workflow passes end to end.
Adds an AWS Bedrock guide for both Replicated and licensed Helm installations. The Helm path explains how to give the bundled LiteLLM pod a scoped EKS IAM role, configure a Bedrock inference-profile route, select it in OpenHands, and verify a sandbox conversation. It links the guide from the enterprise integration overview, Helm install guide, and existing VM Admin Console configuration without removing the Replicated instructions.
Validation:
mint broken-linksandgit diff --checkpassed.pwdin a sandbox, and returned/workspace/project.This is a companion to the Azure gateway guide in #872. The Bedrock example is based on the documented Helm values and an IRSA-backed EKS test; other Kubernetes credential mechanisms are mentioned but were not tested here.