Repository navigation
feat: Add ldcli aws-devops-agent setup - #847
Conversation
…aunchdarkly/ldcli into devin/1791208089-aws-devops-agent-core
- disassociate a registered service everywhere before deregistering it - look up an existing LaunchDarkly MCP server even with no access token - refresh the trust policy on reused IAM roles - follow NextToken on every list API - fail setup when a prompted MCP registration errors
be9a79f to
b36a8fd
Compare
Trust agent spaces in every region, leave roles this CLI did not create alone, check an access token before the old MCP registration is removed, and identify the MCP server by its endpoint rather than its name.
| return ServiceToken{}, err | ||
| } | ||
| req.Header.Set("Authorization", token) | ||
| req.Header.Set("Content-Type", "application/json") |
There was a problem hiding this comment.
Token client omits API version
Medium Severity
CreateServiceToken is a new LaunchDarkly HTTP path that never sets LD-API-Version: 20240415. Without it, the create-token request uses whatever default version is stored on --access-token or the config token, so setup can diverge from ldcli login and other commands when that default is old or retiring.
Triggered by learned rule: Both HTTP clients must send LD-API-Version: 20240415
Reviewed by Cursor Bugbot for commit 3654d6e. Configure here.
|
not an expert on this, got some bullet points in my ai review that may be of interest though:
|
This reverts commit 3654d6e.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
There are 2 total unresolved issues (including 1 from previous review).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 03b6e0a. Configure here.
| AuthorizationConfig: &agenttypes.MCPServerAuthorizationConfigMemberBearerToken{ | ||
| Value: agenttypes.MCPServerBearerTokenConfig{ | ||
| TokenName: aws.String("launchdarkly-api-token"), | ||
| TokenValue: aws.String(opts.LDAccessToken), |
There was a problem hiding this comment.
First register skips token validation
Medium Severity
First-time MCP registration writes LDAccessToken to AWS without calling ValidateAccessToken. An expired config or ldcli login session is stored write-only, setup still reports success, and the agent then fails with unauthorized until --replace-mcp-token is used.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 03b6e0a. Configure here.


This is a CLI command for setting up the aws devops agent with the launchdarkly MCP. It's a utility over some AWS cli calls.
Requirements
Related issues
Provide links to any issues in this repository or elsewhere relating to this pull request.
Describe the solution you've provided
Provide a clear and concise description of what you expect to happen.
Describe alternatives you've considered
Provide a clear and concise description of any alternative solutions or features you've considered.
Additional context
Add any other context about the pull request here.
Note
Overview
Adds
ldcli aws-devops-agentwithsetupandstatusto provision the AWS DevOps Agent integration in the caller’s AWS account (using the ambient AWS session via AWS SDK v2, not LaunchDarkly API auth).setupcreates or reuses tagged IAM roles, an agent space, the AWS account association, the operator web app (IAM/IDC/IDP auth), and registration/association of the LaunchDarkly MCP server—with idempotent reuse, retries for role assumability and MCP reachability, optional interactive service-token entry, and safe MCP token rotation (--replace-mcp-tokenvalidates the token with LaunchDarkly before deregistering).statusreports provisioned resources (plaintext or JSON).The command is registered on the root CLI, listed in help templates, and exempt from requiring
--access-token. README documents usage, regions, and MCP behavior. Broad unit tests cover setup/status edge cases via fakes.Reviewed by Cursor Bugbot for commit 03b6e0a. Bugbot is set up for automated code reviews on this repo. Configure here.