Skip to content

[WIP] Fix Kiro CLI auth failures due to network allow-list gap - #50555

Closed
pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/aw-failures-fix-kiro-allow-list
Closed

pelikhan with Copilot wants to merge 1 commit into
mainfrom
copilot/aw-failures-fix-kiro-allow-list

Conversation

Copilot AI commented Aug 5, 2026 •

Copy link
Copy Markdown
Contributor
  • Inspect the reported CI failure context and relevant workflow guidance
  • Update Kiro network allow-list and Kiro/Cursor secret fallbacks
  • Recompile generated workflow locks and validate the focused changes
  • Review, scan, and publish the minimal change

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Hey 👋 — thanks for working on the Kiro/Cursor CLI auth fix! This PR addresses the confirmed root causes identified in #50519 (stale network allow-list + missing SECRET_ fallback). A few things to keep moving forward:

  • Complete the diff — The PR is currently in draft with 0 changed files. The issue diagnostic clearly outlines the changes needed:

    1. Add q.us-east-1.amazonaws.com and client-telemetry.us-east-1.amazonaws.com to network.defaults in shared/kiro.md
    2. Update harness-scripts in both shared/kiro.md and shared/cursor.md to fall back to SECRET_KIRO_API_KEY / SECRET_CURSOR_API_KEY env vars
    3. Regenerate smoke-kiro.lock.yml and smoke-cursor.lock.yml via gh aw compile
  • Add test coverage — The issue specifies success criteria: 10 consecutive Smoke Kiro and Smoke Cursor runs with zero Execute {Kiro,Cursor} CLI failures, plus audit-diff validation for zero denied entries.

  • Update PR description — Once the diff is complete, update the PR body with a summary of actual changes made and a link to the validation results.

This is a minimal, high-confidence fix targeting a clear infrastructure issue. Once the checklist items above are complete, this should be ready for rapid review and merge.

Complete the network allow-list and secret fallback fixes for Kiro/Cursor CLI auth:

1. Edit shared/kiro.md: Add q.us-east-1.amazonaws.com and client-telemetry.us-east-1.amazonaws.com to network.defaults
2. Edit shared/kiro.md harness-script: Change process.env.KIRO_API_KEY reads to use fallback: process.env.KIRO_API_KEY || process.env.SECRET_KIRO_API_KEY
3. Edit shared/cursor.md harness-script: Apply equivalent CURSOR_API_KEY/SECRET_CURSOR_API_KEY fallback
4. Run: gh aw compile
5. Verify: Run smoke tests and confirm zero denied entries for the two added domains in audit-diff output

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • patchdiff.githubusercontent.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "patchdiff.githubusercontent.com"

See Network Configuration for more information.

Generated by ✅ Contribution Check · auto · 54.1 AIC · ⌖ 3.87 AIC · ⊞ 8.8K · ◷

@pelikhan pelikhan closed this Aug 5, 2026
@github-actions
github-actions Bot deleted the copilot/aw-failures-fix-kiro-allow-list branch August 13, 2026 02:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[aw-failures] Kiro/Cursor CLI auth fails intermittently — network allow-list gap + missing SECRET_ fallback

2 participants