Skip to content

[aw-failures] Kiro/Cursor CLI auth fails intermittently — network allow-list gap + missing SECRET_ fallback #50519

Description

@github-actions

Fix the Kiro allow-list before touching anything else — it's the confirmed cause

audit-diff between a failed and a passing Kiro run proves the firewall is denying two domains kiro-cli calls on every run; the auth harness also has no fallback for the AWF entrypoint's secret-renaming behavior. Both are one-sentence, low-risk config fixes.

Affected workflows / runs

Probable root cause

  1. Stale network allow-list. shared/kiro.md's network.defaults lists codewhisperer.us-east-1.amazonaws.com, cognito-identity.us-east-1.amazonaws.com, prod.us-east-1.telemetry.kiro.aws.dev, prod.assets.shortbread.aws.dev, and wildcard *.kiro.dev. It's missing q.us-east-1.amazonaws.com and client-telemetry.us-east-1.amazonaws.com. audit-diff (base=30974811087, compare=30977137021) shows:
    {"domain":"q.us-east-1.amazonaws.com:443","status":"new","is_anomaly":true,"run2_blocked":42,"run2_status":"denied"}
    {"domain":"client-telemetry.us-east-1.amazonaws.com:443","status":"volume_changed","run1_blocked":2,"run2_blocked":36,"volume_change":"+1700%"}
    Even the passing run had 42+36 denied calls to these two domains — kiro-cli tolerates some of this, but it's plausible the auth-relevant call among them is what fails intermittently.
  2. No secret-rename fallback. The AWF firewall entrypoint logs Unsetting sensitive tokens from parent shell environment... and renames KIRO_API_KEY→SECRET_KIRO_API_KEY, CURSOR_API_KEY→SECRET_CURSOR_API_KEY before the harness-script runs. Neither shared/kiro.md nor shared/cursor.md's harness-script reads the SECRET_-prefixed fallback name — both use process.env.KIRO_API_KEY / process.env.CURSOR_API_KEY directly (shared/kiro.md line ~138, shared/cursor.md equivalent). When the primary auth path fails (e.g. due to rejig docs #1), kiro-cli falls back to interactive device-flow login and fails with error: Failed to open URL; cursor-agent fails with Error: Authentication required... or set CURSOR_API_KEY environment variable.

Proposed remediation

  1. Add q.us-east-1.amazonaws.com and client-telemetry.us-east-1.amazonaws.com to network.defaults in shared/kiro.md.
  2. In shared/kiro.md's harness-script, change the model/auth read to fall back: process.env.KIRO_API_KEY || process.env.SECRET_KIRO_API_KEY. Apply the equivalent fallback for CURSOR_API_KEY/SECRET_CURSOR_API_KEY in shared/cursor.md.
  3. Re-run gh aw compile to regenerate smoke-kiro.lock.yml / smoke-cursor.lock.yml.

Success criteria / verification

Generated by 🔍 [aw] Failure Investigator (6h) · agent · 259.3 AIC · ⌖ 40.8 AIC · ⊞ 5.2K · ◷

  • expires on Aug 11, 2026, 11:58 PM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions