Skip to content

feat: Add ldcli aws-devops-agent setup - #847

Merged
ffantl-ld merged 11 commits into
mainfrom
devin/1791208089-aws-devops-agent-core
Oct 9, 2026
Merged

ffantl-ld merged 11 commits into
mainfrom
devin/1791208089-aws-devops-agent-core

Conversation

@Andrewjeska

@Andrewjeska Andrewjeska commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

This is a CLI command for setting up the aws devops agent with the launchdarkly MCP. It's a utility over some AWS cli calls.

➜  ldcli git:(devin/1791208089-aws-devops-agent-core) ./ldcli aws-devops-agent setup --region us-east-1 --profile launchdarkly-development_Administrator
Using the access token from your ldcli configuration for the MCP server. Pass --access-token with a service token if that one expires
Agent space role ready: arn:aws:iam::506919356135:role/DevOpsAgentRole-AgentSpace
Operator app role ready: arn:aws:iam::506919356135:role/DevOpsAgentRole-WebappAdmin
Reusing agent space launchdarkly (ffbe1e78-9149-4505-80a9-6dcf16fe575f); pass --new-agent-space to create another
Account 506919356135 is already associated with the agent space
Operator app available at https://ffbe1e78-9149-4505-80a9-6dcf16fe575f.aidevops.global.app.aws
Reusing the LaunchDarkly MCP server already registered on this account (5fedf953-aaf8-4ead-afac-79f9db4598a3); it keeps the access token it was registered with, so pass --access-token --replace-mcp-token to change it
The LaunchDarkly MCP server is already associated with the agent space

Agent space ffbe1e78-9149-4505-80a9-6dcf16fe575f is ready in us-east-1 (account 506919356135).

Open the DevOps Agent at:
  https://ffbe1e78-9149-4505-80a9-6dcf16fe575f.aidevops.global.app.aws
Manage it in the AWS console at:
  https://us-east-1.console.aws.amazon.com/aidevops/home?region=us-east-1

Requirements

  • I have added test coverage for new or changed functionality
  • I have followed the repository's pull request submission guidelines
  • I have validated my changes against all supported platform versions

Related issues

Provide links to any issues in this repository or elsewhere relating to this pull request.

Describe the solution you've provided

Provide a clear and concise description of what you expect to happen.

Describe alternatives you've considered

Provide a clear and concise description of any alternative solutions or features you've considered.

Additional context

Add any other context about the pull request here.


Note

Overview
Adds ldcli aws-devops-agent with setup and status to provision the AWS DevOps Agent integration in the caller’s AWS account (using the ambient AWS session via AWS SDK v2, not LaunchDarkly API auth).

setup creates or reuses tagged IAM roles, an agent space, the AWS account association, the operator web app (IAM/IDC/IDP auth), and registration/association of the LaunchDarkly MCP server—with idempotent reuse, retries for role assumability and MCP reachability, optional interactive service-token entry, and safe MCP token rotation (--replace-mcp-token validates the token with LaunchDarkly before deregistering). status reports provisioned resources (plaintext or JSON).

The command is registered on the root CLI, listed in help templates, and exempt from requiring --access-token. README documents usage, regions, and MCP behavior. Broad unit tests cover setup/status edge cases via fakes.

Reviewed by Cursor Bugbot for commit 03b6e0a. Bugbot is set up for automated code reviews on this repo. Configure here.

@Andrewjeska Andrewjeska changed the title Add ldcli aws-devops-agent setup, status and teardown feat: Add ldcli aws-devops-agent setup, status and teardown Oct 5, 2026
@Andrewjeska
Andrewjeska marked this pull request as ready for review October 5, 2026 15:27
@Andrewjeska
Andrewjeska requested a review from a team as a code owner October 5, 2026 15:27

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread internal/awsdevops/setup.go
Comment thread internal/awsdevops/setup.go
Comment thread internal/awsdevops/setup.go
Comment thread internal/awsdevops/teardown.go Outdated
Comment thread cmd/aws_devops_agent/setup.go Outdated
- disassociate a registered service everywhere before deregistering it
- look up an existing LaunchDarkly MCP server even with no access token
- refresh the trust policy on reused IAM roles
- follow NextToken on every list API
- fail setup when a prompted MCP registration errors

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread internal/awsdevops/setup.go
@Andrewjeska
Andrewjeska requested a review from ffantl-ld October 5, 2026 18:27
Comment thread internal/awsdevops/teardown.go Outdated
Comment thread .github/workflows/aws-devops-agent-smoke.yml Outdated

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread internal/awsdevops/live_test.go Outdated
@devin-ai-integration
devin-ai-integration Bot force-pushed the devin/1791208089-aws-devops-agent-core branch from be9a79f to b36a8fd Compare October 6, 2026 15:13
@Andrewjeska
Andrewjeska requested a review from ffantl-ld October 7, 2026 16:12
@Andrewjeska Andrewjeska changed the title feat: Add ldcli aws-devops-agent setup, status and teardown feat: Add ldcli aws-devops-agent setup Oct 7, 2026
Trust agent spaces in every region, leave roles this CLI did not create
alone, check an access token before the old MCP registration is removed,
and identify the MCP server by its endpoint rather than its name.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread internal/awsdevops/token.go
Comment thread internal/awsdevops/status.go

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread internal/awsdevops/token.go Outdated
return ServiceToken{}, err
}
req.Header.Set("Authorization", token)
req.Header.Set("Content-Type", "application/json")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Token client omits API version

Medium Severity

CreateServiceToken is a new LaunchDarkly HTTP path that never sets LD-API-Version: 20240415. Without it, the create-token request uses whatever default version is stored on --access-token or the config token, so setup can diverge from ldcli login and other commands when that default is old or retiring.

Fix in Cursor Fix in Web

Triggered by learned rule: Both HTTP clients must send LD-API-Version: 20240415

Reviewed by Cursor Bugbot for commit 3654d6e. Configure here.

@ld-ahartmann

Copy link
Copy Markdown

not an expert on this, got some bullet points in my ai review that may be of interest though:

  • Stop registering a built-in writer service token. Give AWS a credential that can only do what the allowlist allows: list-projects, list-flags, get-flag, and toggle-flag.
  • Register the hosted MCP server with OAuth 3LO and dynamic client registration, the same way the AWS and LaunchDarkly docs do. Drop the bearer-token registration.
  • If toggle-flag stays, keep it classified as MUTATIVE and turn on directed actions for the agent space. Otherwise remove it and use a read-only token.
  • Set LD-API-Version: 20240415 on both LaunchDarkly HTTP calls in internal/awsdevops/token.go.
  • Collapse the three pagination loops in internal/awsdevops/lookup.go into one helper.
  • Collapse associateAWSAccount and registerWithRetry into one backoff helper.
  • Share one HTTP helper between ValidateAccessToken and CreateServiceToken.

@devin-ai-integration
devin-ai-integration Bot removed the request for review from a team October 8, 2026 17:44

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

There are 2 total unresolved issues (including 1 from previous review).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 03b6e0a. Configure here.

AuthorizationConfig: &agenttypes.MCPServerAuthorizationConfigMemberBearerToken{
Value: agenttypes.MCPServerBearerTokenConfig{
TokenName: aws.String("launchdarkly-api-token"),
TokenValue: aws.String(opts.LDAccessToken),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First register skips token validation

Medium Severity

First-time MCP registration writes LDAccessToken to AWS without calling ValidateAccessToken. An expired config or ldcli login session is stored write-only, setup still reports success, and the agent then fails with unauthorized until --replace-mcp-token is used.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 03b6e0a. Configure here.

@ffantl-ld
ffantl-ld merged commit b818ae4 into main Oct 9, 2026
10 checks passed
@ffantl-ld
ffantl-ld deleted the devin/1791208089-aws-devops-agent-core branch October 9, 2026 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants