diff --git a/go.mod b/go.mod index 55bda52a6..a21248af1 100644 --- a/go.mod +++ b/go.mod @@ -53,13 +53,13 @@ require ( github.com/Masterminds/semver/v3 v3.4.0 // indirect github.com/Masterminds/sprig/v3 v3.3.0 // indirect github.com/apache/thrift v0.23.0 // indirect - github.com/aws/aws-sdk-go-v2 v1.41.6 // indirect - github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.9 // indirect + github.com/aws/aws-sdk-go-v2 v1.43.4 // indirect + github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16 // indirect github.com/aws/aws-sdk-go-v2/config v1.32.16 // indirect github.com/aws/aws-sdk-go-v2/credentials v1.19.15 // indirect github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.22 // indirect - github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.22 // indirect - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.22 // indirect + github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35 // indirect + github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35 // indirect github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.23 // indirect github.com/aws/aws-sdk-go-v2/service/ecs v1.78.1 // indirect github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.8 // indirect @@ -72,7 +72,7 @@ require ( github.com/aws/aws-sdk-go-v2/service/sso v1.30.16 // indirect github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.20 // indirect github.com/aws/aws-sdk-go-v2/service/sts v1.42.0 // indirect - github.com/aws/smithy-go v1.25.0 // indirect + github.com/aws/smithy-go v1.27.6 // indirect github.com/benbjohnson/clock v1.3.5 // indirect github.com/beorn7/perks v1.0.1 // indirect github.com/blang/semver/v4 v4.0.0 // indirect diff --git a/go.sum b/go.sum index 090dcab24..72137a572 100644 --- a/go.sum +++ b/go.sum @@ -53,20 +53,20 @@ github.com/alitto/pond v1.9.2/go.mod h1:xQn3P/sHTYcU/1BR3i86IGIrilcrGC2LiS+E2+CJ github.com/apache/thrift v0.16.0/go.mod h1:PHK3hniurgQaNMZYaCLEqXKsYK8upmhPbmdP2FXSqgU= github.com/apache/thrift v0.23.0 h1:wKR6YnefQSEnxpEfmgTPuJibNG4bF0p2TK34tHLWi3s= github.com/apache/thrift v0.23.0/go.mod h1:zPt6WxgvTOM6hF92y8C+MkEM5LMxZuk4JcQOiU4Esvs= -github.com/aws/aws-sdk-go-v2 v1.41.6 h1:1AX0AthnBQzMx1vbmir3Y4WsnJgiydmnJjiLu+LvXOg= -github.com/aws/aws-sdk-go-v2 v1.41.6/go.mod h1:dy0UzBIfwSeot4grGvY1AqFWN5zgziMmWGzysDnHFcQ= -github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.9 h1:adBsCIIpLbLmYnkQU+nAChU5yhVTvu5PerROm+/Kq2A= -github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.9/go.mod h1:uOYhgfgThm/ZyAuJGNQ5YgNyOlYfqnGpTHXvk3cpykg= +github.com/aws/aws-sdk-go-v2 v1.43.4 h1:b9FTvbRwy+JCsfp2Wp6wV/KbOx3Aj7nkoFb2cRX0IhE= +github.com/aws/aws-sdk-go-v2 v1.43.4/go.mod h1:70vwSy16txshwG+g55WkpgPKDIByzHI8ccBsOteo3bQ= +github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16 h1:aiuaKlDweRC5qExJondpWjOgyzMHpofpwspGXUtwn4c= +github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16/go.mod h1:nG/LOlmox9BDe9HvQnXWzgcK8uKbgBMZ/Hp5pVt/21I= github.com/aws/aws-sdk-go-v2/config v1.32.16 h1:Q0iQ7quUgJP0F/SCRTieScnaMdXr9h/2+wze1u3cNeM= github.com/aws/aws-sdk-go-v2/config v1.32.16/go.mod h1:duCCnJEFqpt2RC6no1iK6q+8HpwOAkiUua0pY507dQc= github.com/aws/aws-sdk-go-v2/credentials v1.19.15 h1:fyvgWTszojq8hEnMi8PPBTvZdTtEVmAVyo+NFLHBhH4= github.com/aws/aws-sdk-go-v2/credentials v1.19.15/go.mod h1:gJiYyMOjNg8OEdRWOf3CrFQxM2a98qmrtjx1zuiQfB8= github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.22 h1:IOGsJ1xVWhsi+ZO7/NW8OuZZBtMJLZbk4P5HDjJO0jQ= github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.22/go.mod h1:b+hYdbU+jGKfXE8kKM6g1+h+L/Go3vMvzlxBsiuGsxg= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.22 h1:GmLa5Kw1ESqtFpXsx5MmC84QWa/ZrLZvlJGa2y+4kcQ= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.22/go.mod h1:6sW9iWm9DK9YRpRGga/qzrzNLgKpT2cIxb7Vo2eNOp0= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.22 h1:dY4kWZiSaXIzxnKlj17nHnBcXXBfac6UlsAx2qL6XrU= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.22/go.mod h1:KIpEUx0JuRZLO7U6cbV204cWAEco2iC3l061IxlwLtI= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35 h1:kzVuGlatQtYinwBJEEyLAbggepCoavosiaHHX9+fD+c= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35/go.mod h1:0yLx0yEI+SfqeJMPvOtIEFoZbiQYXMGszBueiutQyaI= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35 h1:WK6CjihTuLisCjSKKbildJ79sGZZgbBz3iNa7VsKIhU= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35/go.mod h1:KYleN57luLoe97R7vTnx8PMcVrr9gAcRECtOjl91DNg= github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.23 h1:FPXsW9+gMuIeKmz7j6ENWcWtBGTe1kH8r9thNt5Uxx4= github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.23/go.mod h1:7J8iGMdRKk6lw2C+cMIphgAnT8uTwBwNOsGkyOCm80U= github.com/aws/aws-sdk-go-v2/service/ecs v1.78.1 h1:9zSVr4X6X8JNTxSMip2RORaBB+Mu0/IfzNu3iRWZE9c= @@ -91,8 +91,8 @@ github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.20 h1:oK/njaL8GtyEihkWMD4k3Vg github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.20/go.mod h1:JHs8/y1f3zY7U5WcuzoJ/yAYGYtNIVPKLIbp61euvmg= github.com/aws/aws-sdk-go-v2/service/sts v1.42.0 h1:ks8KBcZPh3PYISr5dAiXCM5/Thcuxk8l+PG4+A0exds= github.com/aws/aws-sdk-go-v2/service/sts v1.42.0/go.mod h1:pFw33T0WLvXU3rw1WBkpMlkgIn54eCB5FYLhjDc9Foo= -github.com/aws/smithy-go v1.25.0 h1:Sz/XJ64rwuiKtB6j98nDIPyYrV1nVNJ4YU74gttcl5U= -github.com/aws/smithy-go v1.25.0/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc= +github.com/aws/smithy-go v1.27.6 h1:0zjT8jgK3jbrTT7JJ3EE6JsMhX8JTrZ+f1sEndYDXrA= +github.com/aws/smithy-go v1.27.6/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc= github.com/benbjohnson/clock v0.0.0-20160125162948-a620c1cc9866/go.mod h1:UMqtWQTnOe4byzwe7Zhwh8f8s+36uszN51sJrSIZlTE= github.com/benbjohnson/clock v1.3.5 h1:VvXlSJBzZpA/zum6Sj74hxwYI2DIxRWuNIoXAzHZz5o= github.com/benbjohnson/clock v1.3.5/go.mod h1:J11/hYXuz8f4ySSvYwY0FKfm+ezbsZBKZxNJlLklBHA= diff --git a/internal/temporalcli/commands.gen.go b/internal/temporalcli/commands.gen.go index ffa688afe..0165f6e30 100644 --- a/internal/temporalcli/commands.gen.go +++ b/internal/temporalcli/commands.gen.go @@ -3733,6 +3733,10 @@ type TemporalWorkerDeploymentCreateVersionCommand struct { AwsLambdaAssumeRoleArn string AwsLambdaAssumeRoleExternalId string AwsLambdaSkipRoleAndExternalId bool + AwsAgentcoreEndpointArn string + AwsAgentcoreAssumeRoleArn string + AwsAgentcoreAssumeRoleExternalId string + AwsAgentcoreSkipRoleAndExternalId bool GcpCloudRunProject string GcpCloudRunRegion string GcpCloudRunWorkerPool string @@ -3751,15 +3755,19 @@ func NewTemporalWorkerDeploymentCreateVersionCommand(cctx *CommandContext, paren s.Command.Use = "create-version [flags]" s.Command.Short = "Create a new Worker Deployment Version" if hasHighlighting { - s.Command.Long = "\nCreate a new Worker Deployment Version:\n\n\x1b[1mtemporal worker deployment create-version [options]\x1b[0m\n\nConfigure a Worker Deployment Version's compute configuration as needed.\nFor example, pass compute provider information for an AWS Lambda function\nthat spawns a Worker in the Worker Deployment:\n\n\x1b[1mtemporal worker deployment create-version \\\n --namespace YourNamespaceName \\\n --deployment-name YourDeploymentName \\\n --build-id YourBuildID \\\n --aws-lambda-function-arn LambdaFunctionARN \\\n --aws-lambda-assume-role-arn LambdaAssumeRoleARN \\\n --aws-lambda-assume-role-external-id LambdaAssumeRoleExternalID\x1b[0m\n\nOr pass compute provider information for a GCP Cloud Run worker pool\nthat spawns a Worker in the Worker Deployment:\n\n\x1b[1mtemporal worker deployment create-version \\\n --namespace YourNamespaceName \\\n --deployment-name YourDeploymentName \\\n --build-id YourBuildID \\\n --gcp-cloud-run-project YourGCPProject \\\n --gcp-cloud-run-region us-central1 \\\n --gcp-cloud-run-worker-pool YourWorkerPool \\\n --gcp-cloud-run-service-account customer-sa@proj.iam.gserviceaccount.com \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\x1b[0m\n\nIf a Worker Deployment Version with the supplied BuildID already exists,\nthis command will return an error.\n\nReturns an error if all compute configuration fields are empty.\n\nNote: This is an experimental feature and may change in the future." + s.Command.Long = "\nCreate a new Worker Deployment Version:\n\n\x1b[1mtemporal worker deployment create-version [options]\x1b[0m\n\nConfigure a Worker Deployment Version's compute configuration as needed.\nFor example, pass compute provider information for an AWS Lambda function\nthat spawns a Worker in the Worker Deployment:\n\n\x1b[1mtemporal worker deployment create-version \\\n --namespace YourNamespaceName \\\n --deployment-name YourDeploymentName \\\n --build-id YourBuildID \\\n --aws-lambda-function-arn LambdaFunctionARN \\\n --aws-lambda-assume-role-arn LambdaAssumeRoleARN \\\n --aws-lambda-assume-role-external-id LambdaAssumeRoleExternalID\x1b[0m\n\nOr pass compute provider information for an AWS Bedrock Agentcore Runtime\nthat spawns a Worker in the Worker Deployment:\n\n\x1b[1mtemporal worker deployment create-version \\\n --namespace YourNamespaceName \\\n --deployment-name YourDeploymentName \\\n --build-id YourBuildID \\\n --aws-agentcore-endpoint-arn AgentcoreRuntimeEndpointARN \\\n --aws-agentcore-assume-role-arn AgentcoreAssumeRoleARN \\\n --aws-agentcore-assume-role-external-id AgentcoreAssumeRoleExternalID\x1b[0m\n\nOr pass compute provider information for a GCP Cloud Run worker pool\nthat spawns a Worker in the Worker Deployment:\n\n\x1b[1mtemporal worker deployment create-version \\\n --namespace YourNamespaceName \\\n --deployment-name YourDeploymentName \\\n --build-id YourBuildID \\\n --gcp-cloud-run-project YourGCPProject \\\n --gcp-cloud-run-region us-central1 \\\n --gcp-cloud-run-worker-pool YourWorkerPool \\\n --gcp-cloud-run-service-account customer-sa@proj.iam.gserviceaccount.com \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\x1b[0m\n\nIf a Worker Deployment Version with the supplied BuildID already exists,\nthis command will return an error.\n\nReturns an error if all compute configuration fields are empty.\n\nNote: This is an experimental feature and may change in the future." } else { - s.Command.Long = "\nCreate a new Worker Deployment Version:\n\n```\ntemporal worker deployment create-version [options]\n```\n\nConfigure a Worker Deployment Version's compute configuration as needed.\nFor example, pass compute provider information for an AWS Lambda function\nthat spawns a Worker in the Worker Deployment:\n\n```\ntemporal worker deployment create-version \\\n --namespace YourNamespaceName \\\n --deployment-name YourDeploymentName \\\n --build-id YourBuildID \\\n --aws-lambda-function-arn LambdaFunctionARN \\\n --aws-lambda-assume-role-arn LambdaAssumeRoleARN \\\n --aws-lambda-assume-role-external-id LambdaAssumeRoleExternalID\n```\n\nOr pass compute provider information for a GCP Cloud Run worker pool\nthat spawns a Worker in the Worker Deployment:\n\n```\ntemporal worker deployment create-version \\\n --namespace YourNamespaceName \\\n --deployment-name YourDeploymentName \\\n --build-id YourBuildID \\\n --gcp-cloud-run-project YourGCPProject \\\n --gcp-cloud-run-region us-central1 \\\n --gcp-cloud-run-worker-pool YourWorkerPool \\\n --gcp-cloud-run-service-account customer-sa@proj.iam.gserviceaccount.com \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\n```\n\nIf a Worker Deployment Version with the supplied BuildID already exists,\nthis command will return an error.\n\nReturns an error if all compute configuration fields are empty.\n\nNote: This is an experimental feature and may change in the future." + s.Command.Long = "\nCreate a new Worker Deployment Version:\n\n```\ntemporal worker deployment create-version [options]\n```\n\nConfigure a Worker Deployment Version's compute configuration as needed.\nFor example, pass compute provider information for an AWS Lambda function\nthat spawns a Worker in the Worker Deployment:\n\n```\ntemporal worker deployment create-version \\\n --namespace YourNamespaceName \\\n --deployment-name YourDeploymentName \\\n --build-id YourBuildID \\\n --aws-lambda-function-arn LambdaFunctionARN \\\n --aws-lambda-assume-role-arn LambdaAssumeRoleARN \\\n --aws-lambda-assume-role-external-id LambdaAssumeRoleExternalID\n```\n\nOr pass compute provider information for an AWS Bedrock Agentcore Runtime\nthat spawns a Worker in the Worker Deployment:\n\n```\ntemporal worker deployment create-version \\\n --namespace YourNamespaceName \\\n --deployment-name YourDeploymentName \\\n --build-id YourBuildID \\\n --aws-agentcore-endpoint-arn AgentcoreRuntimeEndpointARN \\\n --aws-agentcore-assume-role-arn AgentcoreAssumeRoleARN \\\n --aws-agentcore-assume-role-external-id AgentcoreAssumeRoleExternalID\n```\n\nOr pass compute provider information for a GCP Cloud Run worker pool\nthat spawns a Worker in the Worker Deployment:\n\n```\ntemporal worker deployment create-version \\\n --namespace YourNamespaceName \\\n --deployment-name YourDeploymentName \\\n --build-id YourBuildID \\\n --gcp-cloud-run-project YourGCPProject \\\n --gcp-cloud-run-region us-central1 \\\n --gcp-cloud-run-worker-pool YourWorkerPool \\\n --gcp-cloud-run-service-account customer-sa@proj.iam.gserviceaccount.com \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\n```\n\nIf a Worker Deployment Version with the supplied BuildID already exists,\nthis command will return an error.\n\nReturns an error if all compute configuration fields are empty.\n\nNote: This is an experimental feature and may change in the future." } s.Command.Args = cobra.NoArgs s.Command.Flags().StringVar(&s.AwsLambdaFunctionArn, "aws-lambda-function-arn", "", "Qualified (contains version suffix) or unqualified AWS Lambda function ARN to invoke when there are no active pollers for task queue targets in the Worker Deployment.") s.Command.Flags().StringVar(&s.AwsLambdaAssumeRoleArn, "aws-lambda-assume-role-arn", "", "AWS IAM role ARN that the Temporal server will assume when invoking the Lambda function that spawns a new Worker in this Worker Deployment Version. Required when --aws-lambda-function-arn is specified, and must be omitted when --aws-lambda-skip-role-and-external-id is passed.") s.Command.Flags().StringVar(&s.AwsLambdaAssumeRoleExternalId, "aws-lambda-assume-role-external-id", "", "Temporal server will enforce that the AWS IAM trust policy associated with the AWS IAM role specified in --aws-lambda-assume-role-arn has an aws:ExternalId condition that matches the supplied value. Required when --aws-lambda-function-arn is specified, and must be omitted when --aws-lambda-skip-role-and-external-id is passed.") s.Command.Flags().BoolVar(&s.AwsLambdaSkipRoleAndExternalId, "aws-lambda-skip-role-and-external-id", false, "When --aws-lambda-function-arn is specified, --aws-lambda-assume-role-arn and --aws-lambda-assume-role-external-id are required unless this flag is passed, in which case both must be omitted.") + s.Command.Flags().StringVar(&s.AwsAgentcoreEndpointArn, "aws-agentcore-endpoint-arn", "", "AWS Bedrock Agentcore Runtime endpoint ARN to invoke when there are no active pollers for task queue targets in the Worker Deployment. The endpoint ARN encodes the runtime, endpoint name, and region.") + s.Command.Flags().StringVar(&s.AwsAgentcoreAssumeRoleArn, "aws-agentcore-assume-role-arn", "", "AWS IAM role ARN that the Temporal server will assume when invoking the Agentcore Runtime that spawns a new Worker in this Worker Deployment Version. Required when --aws-agentcore-endpoint-arn is specified, and must be omitted when --aws-agentcore-skip-role-and-external-id is passed.") + s.Command.Flags().StringVar(&s.AwsAgentcoreAssumeRoleExternalId, "aws-agentcore-assume-role-external-id", "", "Temporal server will enforce that the AWS IAM trust policy associated with the AWS IAM role specified in --aws-agentcore-assume-role-arn has an aws:ExternalId condition that matches the supplied value. Required when --aws-agentcore-endpoint-arn is specified, and must be omitted when --aws-agentcore-skip-role-and-external-id is passed.") + s.Command.Flags().BoolVar(&s.AwsAgentcoreSkipRoleAndExternalId, "aws-agentcore-skip-role-and-external-id", false, "When --aws-agentcore-endpoint-arn is specified, --aws-agentcore-assume-role-arn and --aws-agentcore-assume-role-external-id are required unless this flag is passed, in which case both must be omitted.") s.Command.Flags().StringVar(&s.GcpCloudRunProject, "gcp-cloud-run-project", "", "GCP project ID hosting the Cloud Run worker pool. Required when --gcp-cloud-run-worker-pool is specified.") s.Command.Flags().StringVar(&s.GcpCloudRunRegion, "gcp-cloud-run-region", "", "Region of the Cloud Run worker pool. Required when --gcp-cloud-run-worker-pool is specified.") s.Command.Flags().StringVar(&s.GcpCloudRunWorkerPool, "gcp-cloud-run-worker-pool", "", "GCP Cloud Run worker pool name to scale when there are no active pollers for task queue targets in the Worker Deployment.") @@ -4077,6 +4085,10 @@ type TemporalWorkerDeploymentUpdateVersionComputeConfigCommand struct { AwsLambdaAssumeRoleArn string AwsLambdaAssumeRoleExternalId string AwsLambdaSkipRoleAndExternalId bool + AwsAgentcoreEndpointArn string + AwsAgentcoreAssumeRoleArn string + AwsAgentcoreAssumeRoleExternalId string + AwsAgentcoreSkipRoleAndExternalId bool GcpCloudRunProject string GcpCloudRunRegion string GcpCloudRunWorkerPool string @@ -4096,15 +4108,19 @@ func NewTemporalWorkerDeploymentUpdateVersionComputeConfigCommand(cctx *CommandC s.Command.Use = "update-version-compute-config [flags]" s.Command.Short = "Update compute configuration for a Version" if hasHighlighting { - s.Command.Long = "Update compute configuration associated with a Worker Deployment\nVersion.\n\nFor example, to update the AWS Lambda function ARN associated with an\nexisting Worker Deployment Version:\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --aws-lambda-function-arn UpdatedLambdaFunctionARN\x1b[0m\n\nTo update the AWS IAM role ARN that is assumed by the serverless worker\nmanager associated with an existing Worker Deployment Version:\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --aws-lambda-assume-role-arn UpdatedRoleARN\x1b[0m\n\nTo update the GCP Cloud Run worker pool associated with an existing\nWorker Deployment Version:\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --gcp-cloud-run-project YourGCPProject \\\n --gcp-cloud-run-region us-central1 \\\n --gcp-cloud-run-worker-pool UpdatedWorkerPool \\\n --gcp-cloud-run-service-account customer-sa@proj.iam.gserviceaccount.com \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\x1b[0m\n\nTo update only the scaling settings on an existing GCP Cloud Run Worker\nDeployment Version, supply the five scaler flags without the provider\nfields (all five must be set together):\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\x1b[0m\n\nProvider fields are only required when changing the compute provider.\nSwitching the provider resets the scaling settings for the new provider.\n\nIf --remove is specified, the compute configuration for the Worker\nDeployment Version will be removed:\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --remove\x1b[0m\n\nIf a Worker Deployment Version with the supplied BuildID does not exist,\nthis command will return an error.\n\nNote: This is an experimental feature and may change in the future." + s.Command.Long = "Update compute configuration associated with a Worker Deployment\nVersion.\n\nFor example, to update the AWS Lambda function ARN associated with an\nexisting Worker Deployment Version:\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --aws-lambda-function-arn UpdatedLambdaFunctionARN\x1b[0m\n\nTo update the AWS IAM role ARN that is assumed by the serverless worker\nmanager associated with an existing Worker Deployment Version:\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --aws-lambda-assume-role-arn UpdatedRoleARN\x1b[0m\n\nTo update the AWS Bedrock Agentcore Runtime endpoint associated with an\nexisting Worker Deployment Version:\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --aws-agentcore-endpoint-arn UpdatedAgentcoreRuntimeEndpointARN \\\n --aws-agentcore-assume-role-arn UpdatedRoleARN \\\n --aws-agentcore-assume-role-external-id UpdatedExternalID\x1b[0m\n\nTo update the GCP Cloud Run worker pool associated with an existing\nWorker Deployment Version:\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --gcp-cloud-run-project YourGCPProject \\\n --gcp-cloud-run-region us-central1 \\\n --gcp-cloud-run-worker-pool UpdatedWorkerPool \\\n --gcp-cloud-run-service-account customer-sa@proj.iam.gserviceaccount.com \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\x1b[0m\n\nTo update only the scaling settings on an existing GCP Cloud Run Worker\nDeployment Version, supply the five scaler flags without the provider\nfields (all five must be set together):\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\x1b[0m\n\nProvider fields are only required when changing the compute provider.\nSwitching the provider resets the scaling settings for the new provider.\n\nIf --remove is specified, the compute configuration for the Worker\nDeployment Version will be removed:\n\n\x1b[1m temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --remove\x1b[0m\n\nIf a Worker Deployment Version with the supplied BuildID does not exist,\nthis command will return an error.\n\nNote: This is an experimental feature and may change in the future." } else { - s.Command.Long = "Update compute configuration associated with a Worker Deployment\nVersion.\n\nFor example, to update the AWS Lambda function ARN associated with an\nexisting Worker Deployment Version:\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --aws-lambda-function-arn UpdatedLambdaFunctionARN\n```\n\nTo update the AWS IAM role ARN that is assumed by the serverless worker\nmanager associated with an existing Worker Deployment Version:\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --aws-lambda-assume-role-arn UpdatedRoleARN\n```\n\nTo update the GCP Cloud Run worker pool associated with an existing\nWorker Deployment Version:\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --gcp-cloud-run-project YourGCPProject \\\n --gcp-cloud-run-region us-central1 \\\n --gcp-cloud-run-worker-pool UpdatedWorkerPool \\\n --gcp-cloud-run-service-account customer-sa@proj.iam.gserviceaccount.com \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\n```\n\nTo update only the scaling settings on an existing GCP Cloud Run Worker\nDeployment Version, supply the five scaler flags without the provider\nfields (all five must be set together):\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\n```\n\nProvider fields are only required when changing the compute provider.\nSwitching the provider resets the scaling settings for the new provider.\n\nIf --remove is specified, the compute configuration for the Worker\nDeployment Version will be removed:\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --remove\n```\n\nIf a Worker Deployment Version with the supplied BuildID does not exist,\nthis command will return an error.\n\nNote: This is an experimental feature and may change in the future." + s.Command.Long = "Update compute configuration associated with a Worker Deployment\nVersion.\n\nFor example, to update the AWS Lambda function ARN associated with an\nexisting Worker Deployment Version:\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --aws-lambda-function-arn UpdatedLambdaFunctionARN\n```\n\nTo update the AWS IAM role ARN that is assumed by the serverless worker\nmanager associated with an existing Worker Deployment Version:\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --aws-lambda-assume-role-arn UpdatedRoleARN\n```\n\nTo update the AWS Bedrock Agentcore Runtime endpoint associated with an\nexisting Worker Deployment Version:\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --aws-agentcore-endpoint-arn UpdatedAgentcoreRuntimeEndpointARN \\\n --aws-agentcore-assume-role-arn UpdatedRoleARN \\\n --aws-agentcore-assume-role-external-id UpdatedExternalID\n```\n\nTo update the GCP Cloud Run worker pool associated with an existing\nWorker Deployment Version:\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --gcp-cloud-run-project YourGCPProject \\\n --gcp-cloud-run-region us-central1 \\\n --gcp-cloud-run-worker-pool UpdatedWorkerPool \\\n --gcp-cloud-run-service-account customer-sa@proj.iam.gserviceaccount.com \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\n```\n\nTo update only the scaling settings on an existing GCP Cloud Run Worker\nDeployment Version, supply the five scaler flags without the provider\nfields (all five must be set together):\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --gcp-cloud-run-min-instances 1 \\\n --gcp-cloud-run-max-instances 3 \\\n --gcp-cloud-run-initial-instances 1 \\\n --gcp-cloud-run-utilization-target 0.75 \\\n --gcp-cloud-run-scale-down-stabilization-duration 5m\n```\n\nProvider fields are only required when changing the compute provider.\nSwitching the provider resets the scaling settings for the new provider.\n\nIf --remove is specified, the compute configuration for the Worker\nDeployment Version will be removed:\n\n```\n temporal worker deployment update-version-compute-config \\\n --deployment-name YourDeploymentName --build-id YourBuildID \\\n --remove\n```\n\nIf a Worker Deployment Version with the supplied BuildID does not exist,\nthis command will return an error.\n\nNote: This is an experimental feature and may change in the future." } s.Command.Args = cobra.NoArgs s.Command.Flags().StringVar(&s.AwsLambdaFunctionArn, "aws-lambda-function-arn", "", "Qualified (contains version suffix) or unqualified AWS Lambda function ARN to invoke when there are no active pollers for task queue targets in the Worker Deployment.") s.Command.Flags().StringVar(&s.AwsLambdaAssumeRoleArn, "aws-lambda-assume-role-arn", "", "AWS IAM role ARN that the Temporal server will assume when invoking the Lambda function that spawns a new Worker in this Worker Deployment Version. Required when --aws-lambda-function-arn is specified, and must be omitted when --aws-lambda-skip-role-and-external-id is passed.") s.Command.Flags().StringVar(&s.AwsLambdaAssumeRoleExternalId, "aws-lambda-assume-role-external-id", "", "Temporal server will enforce that the AWS IAM trust policy associated with the AWS IAM role specified in --aws-lambda-assume-role-arn has an aws:ExternalId condition that matches the supplied value. Required when --aws-lambda-function-arn is specified, and must be omitted when --aws-lambda-skip-role-and-external-id is passed.") s.Command.Flags().BoolVar(&s.AwsLambdaSkipRoleAndExternalId, "aws-lambda-skip-role-and-external-id", false, "When --aws-lambda-function-arn is specified, --aws-lambda-assume-role-arn and --aws-lambda-assume-role-external-id are required unless this flag is passed, in which case both must be omitted.") + s.Command.Flags().StringVar(&s.AwsAgentcoreEndpointArn, "aws-agentcore-endpoint-arn", "", "AWS Bedrock Agentcore Runtime endpoint ARN to invoke when there are no active pollers for task queue targets in the Worker Deployment. The endpoint ARN encodes the runtime, endpoint name, and region.") + s.Command.Flags().StringVar(&s.AwsAgentcoreAssumeRoleArn, "aws-agentcore-assume-role-arn", "", "AWS IAM role ARN that the Temporal server will assume when invoking the Agentcore Runtime that spawns a new Worker in this Worker Deployment Version. Required when --aws-agentcore-endpoint-arn is specified, and must be omitted when --aws-agentcore-skip-role-and-external-id is passed.") + s.Command.Flags().StringVar(&s.AwsAgentcoreAssumeRoleExternalId, "aws-agentcore-assume-role-external-id", "", "Temporal server will enforce that the AWS IAM trust policy associated with the AWS IAM role specified in --aws-agentcore-assume-role-arn has an aws:ExternalId condition that matches the supplied value. Required when --aws-agentcore-endpoint-arn is specified, and must be omitted when --aws-agentcore-skip-role-and-external-id is passed.") + s.Command.Flags().BoolVar(&s.AwsAgentcoreSkipRoleAndExternalId, "aws-agentcore-skip-role-and-external-id", false, "When --aws-agentcore-endpoint-arn is specified, --aws-agentcore-assume-role-arn and --aws-agentcore-assume-role-external-id are required unless this flag is passed, in which case both must be omitted.") s.Command.Flags().StringVar(&s.GcpCloudRunProject, "gcp-cloud-run-project", "", "GCP project ID hosting the Cloud Run worker pool. Required when --gcp-cloud-run-worker-pool is specified.") s.Command.Flags().StringVar(&s.GcpCloudRunRegion, "gcp-cloud-run-region", "", "Region of the Cloud Run worker pool. Required when --gcp-cloud-run-worker-pool is specified.") s.Command.Flags().StringVar(&s.GcpCloudRunWorkerPool, "gcp-cloud-run-worker-pool", "", "GCP Cloud Run worker pool name to scale when there are no active pollers for task queue targets in the Worker Deployment.") diff --git a/internal/temporalcli/commands.worker.deployment.go b/internal/temporalcli/commands.worker.deployment.go index 6bc5f07f7..4d5aa6b5c 100644 --- a/internal/temporalcli/commands.worker.deployment.go +++ b/internal/temporalcli/commands.worker.deployment.go @@ -1035,8 +1035,9 @@ func awsLambdaProviderDetailsPayload( ) (*commonpb.Payload, error) { // Map keys from temporal-auto-scaled-workers: // https://github.com/temporalio/temporal-auto-scaled-workers/blob/c4a7e69b6504365d7e5326b0b8e6cd95e3293f96/wci/workflow/compute_provider/aws_lambda.go#L16-L20 - providerDetails := map[string]any{ - "arn": functionARN, + providerDetails := map[string]any{} + if functionARN != "" { + providerDetails["arn"] = functionARN } if assumeRoleARN != "" { providerDetails["role"] = assumeRoleARN @@ -1052,6 +1053,51 @@ func awsLambdaProviderDetailsPayload( return dc.ToPayload(&providerDetails) } +func validateAWSAgentcoreProviderDetails(details map[string]any, skipRoleAndExternalID bool) error { + if v, ok := details["endpoint_arn"].(string); !ok || v == "" { + return fmt.Errorf("missing required AWS Agentcore provider detail: endpoint_arn") + } + if skipRoleAndExternalID { + for _, key := range []string{"role", "role_external_id"} { + if _, ok := details[key]; ok { + return fmt.Errorf("AWS Agentcore provider detail %q must not be set when --aws-agentcore-skip-role-and-external-id is passed", key) + } + } + return nil + } + for _, key := range []string{"role", "role_external_id"} { + if v, ok := details[key].(string); !ok || v == "" { + return fmt.Errorf("missing required AWS Agentcore provider detail: %s", key) + } + } + return nil +} + +// awsAgentcoreProviderDetailsPayload validates the AWS AgentCore inputs and returns encoded payload +func awsAgentcoreProviderDetailsPayload( + endpointARN string, + assumeRoleARN string, + assumeRoleExternalID string, + skipRoleAndExternalID bool, +) (*commonpb.Payload, error) { + providerDetails := map[string]any{} + if endpointARN != "" { + providerDetails["endpoint_arn"] = endpointARN + } + if assumeRoleARN != "" { + providerDetails["role"] = assumeRoleARN + } + if assumeRoleExternalID != "" { + providerDetails["role_external_id"] = assumeRoleExternalID + } + err := validateAWSAgentcoreProviderDetails(providerDetails, skipRoleAndExternalID) + if err != nil { + return nil, err + } + dc := converter.GetDefaultDataConverter() + return dc.ToPayload(&providerDetails) +} + func validateGCPCloudRunProviderDetails(details map[string]any) error { for _, key := range []string{"project", "region", "worker_pool", "service_account"} { if v, ok := details[key].(string); !ok || v == "" { @@ -1087,43 +1133,87 @@ func gcpCloudRunProviderDetailsPayload( return dc.ToPayload(&providerDetails) } +// ComputeConfigArgs holds ComputeConfig specific args along with helpers for distinguishing between desired compute +// provider +type ComputeConfigArgs struct { + awsLambdaFunctionArn string + awsLambdaAssumeRoleArn string + awsLambdaAssumeRoleExternalId string + awsLambdaSkipRoleAndExternalId bool + awsAgentcoreEndpointArn string + awsAgentcoreAssumeRoleArn string + awsAgentcoreAssumeRoleExternalId string + awsAgentcoreSkipRoleAndExternalId bool + gcpCloudRunProject string + gcpCloudRunRegion string + gcpCloudRunWorkerPool string + gcpCloudRunServiceAccount string +} + +func (c *ComputeConfigArgs) hasAwsLambdaArgs() bool { + return c.awsLambdaFunctionArn != "" || + c.awsLambdaAssumeRoleArn != "" || + c.awsLambdaAssumeRoleExternalId != "" || + c.awsLambdaSkipRoleAndExternalId +} + +func (c *ComputeConfigArgs) hasAwsAgentcoreArgs() bool { + return c.awsAgentcoreEndpointArn != "" || + c.awsAgentcoreAssumeRoleArn != "" || + c.awsAgentcoreAssumeRoleExternalId != "" || + c.awsAgentcoreSkipRoleAndExternalId +} + +func (c *ComputeConfigArgs) hasGcpCloudRunArgs() bool { + return c.gcpCloudRunProject != "" || + c.gcpCloudRunRegion != "" || + c.gcpCloudRunWorkerPool != "" || + c.gcpCloudRunServiceAccount != "" +} + // computeProviderConfig selects the single compute provider for a Worker // Deployment Version's "default" scaling group from the command's flags. It -// enforces that AWS Lambda and GCP Cloud Run flags are not mixed, then -// dispatches on the trigger flag (--aws-lambda-function-arn / +// enforces that flags for different providers are not mixed, then dispatches on +// the trigger flag (--aws-lambda-function-arn / --aws-agentcore-endpoint-arn / // --gcp-cloud-run-worker-pool). Returns an empty providerType when no provider // flags are set, leaving the "no configuration" decision to the caller. -func computeProviderConfig( - awsLambdaFunctionARN string, - awsLambdaAssumeRoleARN string, - awsLambdaAssumeRoleExternalID string, - awsLambdaSkipRoleAndExternalID bool, - gcpCloudRunProject string, - gcpCloudRunRegion string, - gcpCloudRunWorkerPool string, - gcpCloudRunServiceAccount string, -) (providerType string, detailsPayload *commonpb.Payload, err error) { - awsSet := awsLambdaFunctionARN != "" || awsLambdaAssumeRoleARN != "" || awsLambdaAssumeRoleExternalID != "" - gcpSet := gcpCloudRunProject != "" || gcpCloudRunRegion != "" || gcpCloudRunWorkerPool != "" || gcpCloudRunServiceAccount != "" - if awsSet && gcpSet { - return "", nil, fmt.Errorf("cannot combine --aws-lambda-* and --gcp-cloud-run-* flags; a Worker Deployment Version supports a single compute provider") +func computeProviderConfig(c *ComputeConfigArgs) (providerType string, detailsPayload *commonpb.Payload, err error) { + awsLambdaSet := c.hasAwsLambdaArgs() + awsAgentcoreSet := c.hasAwsAgentcoreArgs() + gcpSet := c.hasGcpCloudRunArgs() + setCount := 0 + for _, set := range []bool{awsLambdaSet, awsAgentcoreSet, gcpSet} { + if set { + setCount++ + } + } + if setCount > 1 { + return "", nil, fmt.Errorf("cannot combine --aws-lambda-*, --aws-agentcore-*, and --gcp-cloud-run-* flags; a Worker Deployment Version supports a single compute provider") } switch { - case awsLambdaFunctionARN != "": + case c.hasAwsLambdaArgs(): p, err := awsLambdaProviderDetailsPayload( - awsLambdaFunctionARN, - awsLambdaAssumeRoleARN, - awsLambdaAssumeRoleExternalID, - awsLambdaSkipRoleAndExternalID, + c.awsLambdaFunctionArn, + c.awsLambdaAssumeRoleArn, + c.awsLambdaAssumeRoleExternalId, + c.awsLambdaSkipRoleAndExternalId, ) return "aws-lambda", p, err - case gcpCloudRunWorkerPool != "": + case c.hasAwsAgentcoreArgs(): + p, err := awsAgentcoreProviderDetailsPayload( + c.awsAgentcoreEndpointArn, + c.awsAgentcoreAssumeRoleArn, + c.awsAgentcoreAssumeRoleExternalId, + c.awsAgentcoreSkipRoleAndExternalId, + ) + return "aws-agentcore", p, err + case c.hasGcpCloudRunArgs(): p, err := gcpCloudRunProviderDetailsPayload( - gcpCloudRunProject, - gcpCloudRunRegion, - gcpCloudRunWorkerPool, - gcpCloudRunServiceAccount, + c.gcpCloudRunProject, + c.gcpCloudRunRegion, + c.gcpCloudRunWorkerPool, + c.gcpCloudRunServiceAccount, ) return "gcp-cloud-run", p, err default: @@ -1137,6 +1227,7 @@ func computeProviderConfig( // WCI rejects an incompatible pairing at CreateWorkerDeploymentVersion. var scalerTypeByProvider = map[string]string{ "aws-lambda": "no-sync", + "aws-agentcore": "no-sync", "gcp-cloud-run": "rate-based", } @@ -1258,16 +1349,20 @@ func (c *TemporalWorkerDeploymentCreateVersionCommand) run(cctx *CommandContext, deploymentName := c.DeploymentName requestID := uuid.NewString() - providerType, detailsPayload, err := computeProviderConfig( + providerType, detailsPayload, err := computeProviderConfig(&ComputeConfigArgs{ c.AwsLambdaFunctionArn, c.AwsLambdaAssumeRoleArn, c.AwsLambdaAssumeRoleExternalId, c.AwsLambdaSkipRoleAndExternalId, + c.AwsAgentcoreEndpointArn, + c.AwsAgentcoreAssumeRoleArn, + c.AwsAgentcoreAssumeRoleExternalId, + c.AwsAgentcoreSkipRoleAndExternalId, c.GcpCloudRunProject, c.GcpCloudRunRegion, c.GcpCloudRunWorkerPool, c.GcpCloudRunServiceAccount, - ) + }) if err != nil { return err } @@ -1351,24 +1446,29 @@ func (c *TemporalWorkerDeploymentUpdateVersionComputeConfigCommand) run(cctx *Co RequestId: requestID, } - if c.Remove { - if c.AwsLambdaFunctionArn != "" || c.AwsLambdaAssumeRoleArn != "" || c.AwsLambdaAssumeRoleExternalId != "" || - c.GcpCloudRunProject != "" || c.GcpCloudRunRegion != "" || c.GcpCloudRunWorkerPool != "" || c.GcpCloudRunServiceAccount != "" || - c.gcpScalerFlags().anySet() { - return fmt.Errorf("--remove cannot be combined with --aws-lambda-* or --gcp-cloud-run-* flags") - } - request.RemoveComputeConfigScalingGroups = []string{"default"} - } else { - providerType, detailsPayload, err := computeProviderConfig( + computeConfigArgs := &ComputeConfigArgs{ c.AwsLambdaFunctionArn, c.AwsLambdaAssumeRoleArn, c.AwsLambdaAssumeRoleExternalId, c.AwsLambdaSkipRoleAndExternalId, + c.AwsAgentcoreEndpointArn, + c.AwsAgentcoreAssumeRoleArn, + c.AwsAgentcoreAssumeRoleExternalId, + c.AwsAgentcoreSkipRoleAndExternalId, c.GcpCloudRunProject, c.GcpCloudRunRegion, c.GcpCloudRunWorkerPool, c.GcpCloudRunServiceAccount, - ) + } + + if c.Remove { + if computeConfigArgs.hasAwsLambdaArgs() || computeConfigArgs.hasAwsAgentcoreArgs() || computeConfigArgs.hasGcpCloudRunArgs() || + c.gcpScalerFlags().anySet() { + return fmt.Errorf("--remove cannot be combined with --aws-lambda-*, --aws-agentcore-*, or --gcp-cloud-run-* flags") + } + request.RemoveComputeConfigScalingGroups = []string{"default"} + } else { + providerType, detailsPayload, err := computeProviderConfig(computeConfigArgs) if err != nil { return err } diff --git a/internal/temporalcli/commands.worker.deployment.internal_test.go b/internal/temporalcli/commands.worker.deployment.internal_test.go index 18e0a6a08..f25603819 100644 --- a/internal/temporalcli/commands.worker.deployment.internal_test.go +++ b/internal/temporalcli/commands.worker.deployment.internal_test.go @@ -17,6 +17,7 @@ func TestScalerTypeForProvider(t *testing.T) { expectErr bool }{ {"aws-lambda is invoke-based -> no-sync", "aws-lambda", "no-sync", false}, + {"aws-agentcore is invoke-based -> no-sync", "aws-agentcore", "no-sync", false}, {"gcp-cloud-run is worker-set-based -> rate-based", "gcp-cloud-run", "rate-based", false}, {"unknown provider errors", "azure-container-apps", "", true}, {"empty provider errors", "", "", true}, @@ -38,7 +39,7 @@ func TestScalerTypeForProvider(t *testing.T) { // scaler mapping; a missing entry makes scalerTypeForProvider error before the // request is sent, so this guards against forgetting to map a newly-added provider. func TestScalerTypeByProviderCoversAllProviders(t *testing.T) { - for _, providerType := range []string{"aws-lambda", "gcp-cloud-run"} { + for _, providerType := range []string{"aws-lambda", "aws-agentcore", "gcp-cloud-run"} { _, ok := scalerTypeByProvider[providerType] require.Truef(t, ok, "provider %q has no scaler mapping", providerType) } diff --git a/internal/temporalcli/commands.worker.deployment_test.go b/internal/temporalcli/commands.worker.deployment_test.go index 7bc7f740c..db9c62661 100644 --- a/internal/temporalcli/commands.worker.deployment_test.go +++ b/internal/temporalcli/commands.worker.deployment_test.go @@ -1347,6 +1347,76 @@ func (s *SharedServerSuite) TestCreateWorkerDeploymentVersion_Errors() { s.Error(res.Err) s.ErrorContains(res.Err, "--aws-lambda-skip-role-and-external-id") + // AWS Agentcore: a single endpoint ARN drives the provider; role and external + // id are required (unless skipped) + agentcoreEndpointARN := "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/my-runtime-abc123/runtime-endpoint/DEFAULT" + + agentcoreMissingExternalIDBuildID := uuid.NewString() + res = s.Execute( + "worker", "deployment", "create-version", + "--address", s.Address(), + "--deployment-name", deploymentName, + "--build-id", agentcoreMissingExternalIDBuildID, + "--aws-agentcore-endpoint-arn", agentcoreEndpointARN, + "--aws-agentcore-assume-role-arn", assumeRoleARN, + ) + s.Error(res.Err) + s.ErrorContains(res.Err, "missing required AWS Agentcore provider detail: role_external_id") + + agentcoreMissingRoleBuildID := uuid.NewString() + res = s.Execute( + "worker", "deployment", "create-version", + "--address", s.Address(), + "--deployment-name", deploymentName, + "--build-id", agentcoreMissingRoleBuildID, + "--aws-agentcore-endpoint-arn", agentcoreEndpointARN, + "--aws-agentcore-assume-role-external-id", assumeRoleExternalID, + ) + s.Error(res.Err) + s.ErrorContains(res.Err, "missing required AWS Agentcore provider detail: role") + + // --aws-agentcore-skip-role-and-external-id and the role/external-id flags are + // mutually exclusive: passing both is rejected client-side. + agentcoreSkipWithRoleBuildID := uuid.NewString() + res = s.Execute( + "worker", "deployment", "create-version", + "--address", s.Address(), + "--deployment-name", deploymentName, + "--build-id", agentcoreSkipWithRoleBuildID, + "--aws-agentcore-endpoint-arn", agentcoreEndpointARN, + "--aws-agentcore-assume-role-arn", assumeRoleARN, + "--aws-agentcore-assume-role-external-id", assumeRoleExternalID, + "--aws-agentcore-skip-role-and-external-id", + ) + s.Error(res.Err) + s.ErrorContains(res.Err, "--aws-agentcore-skip-role-and-external-id") + + // AWS Agentcore and GCP Cloud Run providers are mutually exclusive on create. + agentcoreMixedProvidersBuildID := uuid.NewString() + res = s.Execute( + "worker", "deployment", "create-version", + "--address", s.Address(), + "--deployment-name", deploymentName, + "--build-id", agentcoreMixedProvidersBuildID, + "--aws-agentcore-endpoint-arn", agentcoreEndpointARN, + "--gcp-cloud-run-worker-pool", "my-worker-pool", + ) + s.Error(res.Err) + s.ErrorContains(res.Err, "cannot combine --aws-lambda-*, --aws-agentcore-*, and --gcp-cloud-run-* flags") + + // AWS Agentcore and Lambda providers are mutually exclusive on create. + res = s.Execute( + "worker", "deployment", "create-version", + "--address", s.Address(), + "--deployment-name", deploymentName, + "--build-id", agentcoreMixedProvidersBuildID, + "--aws-agentcore-endpoint-arn", agentcoreEndpointARN, + "--aws-lambda-assume-role-arn", assumeRoleARN, + "--aws-lambda-assume-role-external-id", assumeRoleExternalID, + ) + s.Error(res.Err) + s.ErrorContains(res.Err, "cannot combine --aws-lambda-*, --aws-agentcore-*, and --gcp-cloud-run-* flags") + // --gcp-cloud-run-worker-pool requires project, region, and // service-account; the first missing detail key is reported. missingGCPProjectBuildID := uuid.NewString() @@ -1388,7 +1458,7 @@ func (s *SharedServerSuite) TestCreateWorkerDeploymentVersion_Errors() { "--gcp-cloud-run-worker-pool", "my-worker-pool", ) s.Error(res.Err) - s.ErrorContains(res.Err, "cannot combine --aws-lambda-* and --gcp-cloud-run-* flags") + s.ErrorContains(res.Err, "cannot combine --aws-lambda-*, --aws-agentcore-*, and --gcp-cloud-run-* flags") // Attempting to update the compute config for a non-existent WDV // should fail. @@ -1428,7 +1498,7 @@ func (s *SharedServerSuite) TestCreateWorkerDeploymentVersion_Errors() { "--gcp-cloud-run-worker-pool", "my-worker-pool", ) s.Error(res.Err) - s.ErrorContains(res.Err, "cannot combine --aws-lambda-* and --gcp-cloud-run-* flags") + s.ErrorContains(res.Err, "cannot combine --aws-lambda-*, --aws-agentcore-*, and --gcp-cloud-run-* flags") // --remove cannot be combined with GCP Cloud Run flags. res = s.Execute( @@ -1923,6 +1993,124 @@ func (s *SharedServerSuite) TestCreateWorkerDeploymentVersion_LambdaComputeConfi s.Contains(res.Stdout.String(), "Successfully removed worker deployment version compute config") } +// TODO(jaypipes): Enable this test when we have a way of ensuring AWS resource +// fixtures since the CLI test harness uses a real Temporal Server and a real +// Temporal Server validates any supplied AWS Lambda Function and Assume Role +// ARNs are good... +func (s *SharedServerSuite) TestCreateWorkerDeploymentVersion_AgentCoreComputeConfig() { + s.T().Skip("AWS AgentCore Runtime, Endpoint and Assume Role fixtures needed.") + deploymentName := uuid.NewString() + taskQueue := uuid.NewString() + + lazyCreatedBuildID := uuid.NewString() + lazyCreatedVer := worker.WorkerDeploymentVersion{ + DeploymentName: deploymentName, + BuildID: lazyCreatedBuildID, + } + + // Create worker with explicit versioning. This will end up creating a + // WorkerDeployment with the specified name. We will then manually create a + // worker deployment version using the `temporal worker deployment + // create-version` command. + w1 := worker.New(s.Client, taskQueue, worker.Options{ + DeploymentOptions: worker.DeploymentOptions{ + UseVersioning: true, + Version: lazyCreatedVer, + }, + }) + + // Register a workflow with explicit Pinned versioning behavior to trigger + // creation of the worker deployment. + w1.RegisterWorkflowWithOptions( + func(ctx workflow.Context, input any) (any, error) { + workflow.GetSignalChannel(ctx, "complete-signal").Receive(ctx, nil) + return nil, nil + }, + workflow.RegisterOptions{ + Name: "TestCreateWorkerDeploymentVersion_AgentCoreComputeConfig", + VersioningBehavior: workflow.VersioningBehaviorPinned, + }, + ) + + s.NoError(w1.Start()) + + // Now that we know the worker deployment exists (because the above + // lazily-created worker deployment version ended up creating it), we will + // manually create a new worker deployment version using the `temporal + // worker deployment create-version` CLI command. + // + // Create a WDV with a valid Compute Config specified and verify that the + // compute config provider is displayed in the output of `temporal worker + // deployment describe-version` + computeConfigBuildID := uuid.NewString() + + endpointARN := "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/my-runtime-abc123/runtime-endpoint/myEndpoint" + assumeRoleARN := "arn:aws:iam::123456789012:role/MyServiceRole" + assumeRoleExternalID := "external-id" + + res := s.Execute( + "worker", "deployment", "create-version", + "--address", s.Address(), + "--deployment-name", deploymentName, + "--build-id", computeConfigBuildID, + "--aws-agentcore-endpoint-arn", endpointARN, + "--aws-agentcore-assume-role-arn", assumeRoleARN, + "--aws-agentcore-assume-role-external-id", assumeRoleExternalID, + ) + s.NoError(res.Err) + s.Contains(res.Stdout.String(), "Successfully created worker deployment version") + + // Wait for the deployment version to appear + s.EventuallyWithT(func(t *assert.CollectT) { + res := s.Execute( + "worker", "deployment", "describe-version", + "--address", s.Address(), + "--deployment-name", deploymentName, + "--build-id", computeConfigBuildID, + ) + assert.NoError(t, res.Err) + }, 30*time.Second, 100*time.Millisecond) + + // Check that there is a compute config returned for this WDV + res = s.Execute( + "worker", "deployment", "describe-version", + "--address", s.Address(), + "--deployment-name", deploymentName, + "--build-id", computeConfigBuildID, + "--output", "json", + ) + s.NoError(res.Err) + jsonOut := jsonDeploymentVersionInfoType{} + s.NoError(json.Unmarshal(res.Stdout.Bytes(), &jsonOut)) + s.NotNil(jsonOut.ComputeConfig, "ComputeConfig should not be nil.") + + // We should be able to update the compute config. + endpointARN2 := "arn:aws:bedrock-agentcore:us-east-1:123456789012:runtime/my-runtime-abc123/runtime-endpoint/myEndpoint2" + assumeRoleARN2 := "arn:aws:iam::123456789012:role/MyServiceRole2" + res = s.Execute( + "worker", "deployment", "update-version-compute-config", + "--address", s.Address(), + "--deployment-name", deploymentName, + "--build-id", computeConfigBuildID, + "--aws-agentcore-endpoint-arn", endpointARN2, + "--aws-agentcore-assume-role-arn", assumeRoleARN2, + "--aws-agentcore-assume-role-external-id", assumeRoleExternalID, + ) + s.NoError(res.Err) + s.Contains(res.Stdout.String(), "Successfully updated worker deployment version compute config") + + // As well as remove the compute config. + res = s.Execute( + "worker", "deployment", "update-version-compute-config", + "--address", s.Address(), + "--deployment-name", deploymentName, + "--build-id", computeConfigBuildID, + "--remove", + ) + s.NoError(res.Err) + s.Contains(res.Stdout.String(), "Successfully removed worker deployment version compute config") +} + // TODO(jaypipes): Enable this test when we have a way of ensuring GCP resource // fixtures since the CLI test harness uses a real Temporal Server and a real // Temporal Server validates that any supplied GCP Cloud Run worker pool and diff --git a/internal/temporalcli/commands.yaml b/internal/temporalcli/commands.yaml index f9ebe885b..6d24a8a00 100644 --- a/internal/temporalcli/commands.yaml +++ b/internal/temporalcli/commands.yaml @@ -1235,6 +1235,19 @@ commands: --aws-lambda-assume-role-external-id LambdaAssumeRoleExternalID ``` + Or pass compute provider information for an AWS Bedrock Agentcore Runtime + that spawns a Worker in the Worker Deployment: + + ``` + temporal worker deployment create-version \ + --namespace YourNamespaceName \ + --deployment-name YourDeploymentName \ + --build-id YourBuildID \ + --aws-agentcore-endpoint-arn AgentcoreRuntimeEndpointARN \ + --aws-agentcore-assume-role-arn AgentcoreAssumeRoleARN \ + --aws-agentcore-assume-role-external-id AgentcoreAssumeRoleExternalID + ``` + Or pass compute provider information for a GCP Cloud Run worker pool that spawns a Worker in the Worker Deployment: @@ -1292,6 +1305,34 @@ commands: --aws-lambda-assume-role-arn and --aws-lambda-assume-role-external-id are required unless this flag is passed, in which case both must be omitted. + - name: aws-agentcore-endpoint-arn + type: string + description: | + AWS Bedrock Agentcore Runtime endpoint ARN to invoke when there are + no active pollers for task queue targets in the Worker Deployment. + The endpoint ARN encodes the runtime, endpoint name, and region. + - name: aws-agentcore-assume-role-arn + type: string + description: | + AWS IAM role ARN that the Temporal server will assume when invoking + the Agentcore Runtime that spawns a new Worker in this Worker + Deployment Version. Required when --aws-agentcore-endpoint-arn is + specified, and must be omitted when + --aws-agentcore-skip-role-and-external-id is passed. + - name: aws-agentcore-assume-role-external-id + type: string + description: | + Temporal server will enforce that the AWS IAM trust policy associated + with the AWS IAM role specified in --aws-agentcore-assume-role-arn has an + aws:ExternalId condition that matches the supplied value. Required + when --aws-agentcore-endpoint-arn is specified, and must be omitted + when --aws-agentcore-skip-role-and-external-id is passed. + - name: aws-agentcore-skip-role-and-external-id + type: bool + description: | + When --aws-agentcore-endpoint-arn is specified, --aws-agentcore-assume-role-arn + and --aws-agentcore-assume-role-external-id are required unless this + flag is passed, in which case both must be omitted. - name: gcp-cloud-run-project type: string description: | @@ -1591,6 +1632,17 @@ commands: --aws-lambda-assume-role-arn UpdatedRoleARN ``` + To update the AWS Bedrock Agentcore Runtime endpoint associated with an + existing Worker Deployment Version: + + ``` + temporal worker deployment update-version-compute-config \ + --deployment-name YourDeploymentName --build-id YourBuildID \ + --aws-agentcore-endpoint-arn UpdatedAgentcoreRuntimeEndpointARN \ + --aws-agentcore-assume-role-arn UpdatedRoleARN \ + --aws-agentcore-assume-role-external-id UpdatedExternalID + ``` + To update the GCP Cloud Run worker pool associated with an existing Worker Deployment Version: @@ -1670,6 +1722,34 @@ commands: --aws-lambda-assume-role-arn and --aws-lambda-assume-role-external-id are required unless this flag is passed, in which case both must be omitted. + - name: aws-agentcore-endpoint-arn + type: string + description: | + AWS Bedrock Agentcore Runtime endpoint ARN to invoke when there are + no active pollers for task queue targets in the Worker Deployment. + The endpoint ARN encodes the runtime, endpoint name, and region. + - name: aws-agentcore-assume-role-arn + type: string + description: | + AWS IAM role ARN that the Temporal server will assume when invoking + the Agentcore Runtime that spawns a new Worker in this Worker + Deployment Version. Required when --aws-agentcore-endpoint-arn is + specified, and must be omitted when + --aws-agentcore-skip-role-and-external-id is passed. + - name: aws-agentcore-assume-role-external-id + type: string + description: | + Temporal server will enforce that the AWS IAM trust policy associated + with the AWS IAM role specified in --aws-agentcore-assume-role-arn has an + aws:ExternalId condition that matches the supplied value. Required + when --aws-agentcore-endpoint-arn is specified, and must be omitted + when --aws-agentcore-skip-role-and-external-id is passed. + - name: aws-agentcore-skip-role-and-external-id + type: bool + description: | + When --aws-agentcore-endpoint-arn is specified, --aws-agentcore-assume-role-arn + and --aws-agentcore-assume-role-external-id are required unless this + flag is passed, in which case both must be omitted. - name: gcp-cloud-run-project type: string description: |