Skip to content

feat(payment): add connector credential rotation - #2343

Merged
aidandaly24 merged 8 commits into
aws:refactorfrom
aidandaly24:feat/payment-connector-rotate-credentials
Sep 30, 2026
Merged

aidandaly24 merged 8 commits into
aws:refactorfrom
aidandaly24:feat/payment-connector-rotate-credentials

Conversation

@aidandaly24

@aidandaly24 aidandaly24 commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Description

Adds the headless agentcore payment connector rotate-credentials command for service-managed
Coinbase Quick Create credentials.

agentcore payment connector rotate-credentials \
  --manager-id "$MANAGER_ID" \
  --connector-id "$CONNECTOR_ID" \
  --secrets API_KEY WALLET_SECRET
  • Requires an explicit credential selection and supports an optional client token.
  • Uses the existing Handler -> CorePaymentClient -> PaymentClient -> injected SDK path.
  • Requires the published AWS SDK for JavaScript control-plane client, ^3.1143.0.
  • Adds no TUI, IAM provisioning, OAuth wizard, polling, custom retries, or signing implementation.

The original SDK-publication blocker is resolved. This revision is rebased onto refactor
at 17e442b3, including the latest credential wizards, update TUI, and version badge.
It leaves the README unchanged and includes the generated rotation command reference.
The rotation test no longer passes --endpoint-url, which upstream deliberately disabled.

The secret-backed Slack notification job skips fork PRs, which cannot receive its AWS role
secret. Build, test, and security checks remain enabled.
The earlier Harness-test compatibility commit was dropped because upstream #2480 supersedes it;
the Harness tests now match refactor exactly.

The PR's ready-for-review state is preserved. Live-rotation validation was not rerun during this repair.

Related Issue

Related to #2272.

Documentation PR

Only the generated command.md is updated. The dedicated rotation guide and README section/link
have been removed entirely as requested.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update
  • Other (please describe): SDK dependency update and fork-safe notification configuration

Testing

  • I ran bun test
  • I ran the relevant end-to-end tests with bun run test:e2e, or explained why they are not applicable
  • I ran bun run typecheck
  • I ran bun run lint:check
  • I ran bun run format:check
  • I ran bun run build
  • If I modified src/assets/, I updated affected snapshots with bun test <test-file> --update-snapshots and committed them

Code validation before the documentation-only removal:

  • RECORD=0 bun test --coverage --coverage-reporter=lcov: 3,915 passed, 0 failed, across 269 files.
  • Typecheck, lint, formatting, secret scan, and git diff --check passed.
  • Frozen-lockfile installation passed. bun audit reported no vulnerabilities.
  • Node bundle and compiled Linux binary both render rotation command help successfully.
  • The command reference was regenerated from the runnable CLI.

The subsequent documentation-only removal passed Markdown formatting and whitespace checks.
No source, test, dependency, workflow, or generated command-reference changes were made in that step.

The initial sandboxed run could not support normal subprocess/log-directory behavior; the full
suite and startup smoke tests were rerun successfully outside the sandbox.
No live credential rotation or AWS resource mutation was performed during this CI repair.
The repository's deployment E2E suite was not run: this update does not change deployment flows,
and live rotation requires a separately approved test connector. Offline tests exercise the real
router and Core with the SDK send boundary replaced, not a live service.
No assets were modified.

Checklist

  • I have read the CONTRIBUTING document
  • I have added any necessary tests that prove my fix is effective or my feature works
  • I have updated the documentation accordingly
  • I have added an appropriate example to the documentation to outline the feature, or no new docs are needed
  • My changes generate no new warnings
  • Any dependent changes have been merged and published

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the
terms of your choice.

@github-actions github-actions Bot added the size/m PR size: M label Sep 18, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress and removed agentcore-harness-reviewing AgentCore Harness review in progress labels Sep 18, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 18, 2026
@aidandaly24 aidandaly24 reopened this Sep 21, 2026
@github-actions github-actions Bot added size/m PR size: M and removed size/m PR size: M labels Sep 21, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added agentcore-harness-reviewing AgentCore Harness review in progress claude-security-reviewing Claude Code /security-review in progress labels Sep 21, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 21, 2026

@agentcore-devx-automation agentcore-devx-automation Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AgentCore Harness Review

Verdict: Looks good

Small, additive change that fits cleanly with the existing payment connector command family:

  • Handler mirrors the shape of the sibling get/list commands, and mocks at the AWS SDK client boundary (no over-mocking).
  • Zod validation covers the enum values, minimum selection, and duplicate rejection — the negative tests exercise all three.
  • Both single-secret and combined-secret paths are covered, plus error propagation.
  • Docs call out the non-atomicity and wallet-secret disruption risk, which is the right place to surface it for a command that has no TUI confirmation step.

Minor observations (non-blocking, author's call):

  • The test lives in payment.read.test.tsx but rotation is a mutating call; if you care about the naming split you may want to move the new cases into a payment.write.test.tsx (or rename the file). Not required.
  • No telemetry instrumentation, but the sibling read commands don't emit any either — consistent with the current payment surface.

Nothing here needs to change before merging.

@agentcore-devx-automation agentcore-devx-automation Bot removed the agentcore-harness-reviewing AgentCore Harness review in progress label Sep 21, 2026
@aidandaly24
aidandaly24 marked this pull request as ready for review September 21, 2026 22:49
@aidandaly24
aidandaly24 marked this pull request as draft September 21, 2026 22:49
@aidandaly24
aidandaly24 force-pushed the feat/payment-connector-rotate-credentials branch from 5a01201 to 3680e4b Compare September 30, 2026 15:13
@github-actions github-actions Bot added size/m PR size: M and removed size/m PR size: M labels Sep 30, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026
@codecov-commenter

codecov-commenter commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.38%. Comparing base (17e442b) to head (7a41959).

Additional details and impacted files
@@            Coverage Diff            @@
##           refactor    #2343   +/-   ##
=========================================
  Coverage     97.38%   97.38%           
=========================================
  Files           637      638    +1     
  Lines         46549    46594   +45     
=========================================
+ Hits          45330    45376   +46     
+ Misses         1219     1218    -1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@aidandaly24
aidandaly24 marked this pull request as ready for review September 30, 2026 17:54
@aidandaly24
aidandaly24 force-pushed the feat/payment-connector-rotate-credentials branch from 3680e4b to f9c0314 Compare September 30, 2026 18:05
@github-actions github-actions Bot added size/m PR size: M and removed size/m PR size: M labels Sep 30, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026
Comment thread README.md Outdated
Escape interrupts the local stream, not necessarily the remote process.
Use `runtime shell` for a native interactive terminal.

### Rotate Payment Connector Credentials

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can we not have this in the main readme? it's too specific. maybe somewhere in docs/?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved the detailed section to docs/payment-connector-credentials.md in cee9257. The main README now contains only a link in its documentation list, following the structure in #2483. No CLI implementation changes.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Update: removed the dedicated guide and its README link entirely in 7a41959, as requested. This PR now has no README changes and no separate rotation guide; only the generated command reference remains. The CLI implementation is unchanged.

Comment thread README.md Outdated
Comment on lines +114 to +117
Wallet-secret rotation can interrupt wallet operations while the new credential
is installed. Selecting both credentials rotates the API key first, then the
wallet secret; this is not atomic. An error does not guarantee that credentials
are unchanged.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

https://docs.aws.amazon.com/boto3/latest/reference/services/bedrock-agentcore-control/client/rotate_payment_connector_credentials.html

the SDK says a failed rotation leaves the existing creds unchanged and warns that every connector using the credential provider may be affected. it also does not promise API-key-first ordering.

can we just align with what it says?

again, I would rather this whole section be removed

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated the new guide to cite the SDK reference you linked: documented failed rotations leave the connector and its existing credential unchanged, and every connector sharing the credential provider is affected. Removed the API-key-first ordering and non-atomicity claims. The example now uses API_KEY for routine rotation; WALLET_SECRET is described as lost/compromised-only with the documented possible signing interruption. The whole detailed section is removed from the main README. Commit: cee9257.

notgitika
notgitika previously approved these changes Sep 30, 2026
@github-actions github-actions Bot added size/m PR size: M and removed size/m PR size: M labels Sep 30, 2026
@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026
@github-actions github-actions Bot added size/m PR size: M and removed size/m PR size: M labels Sep 30, 2026

@notgitika notgitika left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks this looks good to me

@agentcore-devx-automation agentcore-devx-automation Bot added the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026
@agentcore-devx-automation

Copy link
Copy Markdown
Contributor

Claude Security Review: no high-confidence findings. (run)

@agentcore-devx-automation agentcore-devx-automation Bot removed the claude-security-reviewing Claude Code /security-review in progress label Sep 30, 2026
@aidandaly24
aidandaly24 merged commit a6cd82b into aws:refactor Sep 30, 2026
23 of 24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/m PR size: M

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants