Skip to content

fix: add missing Kiro network domains and SECRET_ auth key fallbacks - #50573

Merged
pelikhan merged 1 commit into
mainfrom
copilot/fix-issue-50519
Aug 5, 2026
Merged

pelikhan merged 1 commit into
mainfrom
copilot/fix-issue-50519

Conversation

Copilot AI commented Aug 5, 2026 •

Copy link
Copy Markdown
Contributor

Kiro CLI auth fails intermittently because two AWS domains are missing from the firewall allow-list, and neither Kiro nor Cursor harness scripts handle the SECRET_-prefixed env var rename that the AWF entrypoint applies to sensitive tokens.

Network allow-list (shared/kiro.md)

  • Add q.us-east-1.amazonaws.com and client-telemetry.us-east-1.amazonaws.com — audit-diff showed 42+ blocked calls per run to these domains

Auth key fallback (shared/kiro.md, shared/cursor.md)

The AWF entrypoint renames KIRO_API_KEY → SECRET_KIRO_API_KEY (same for Cursor) before the harness runs. Added fallback at harness startup:

if (!process.env.KIRO_API_KEY && process.env.SECRET_KIRO_API_KEY) {
  process.env.KIRO_API_KEY = process.env.SECRET_KIRO_API_KEY;
}

Without this, when the network deny causes the primary auth path to fail, kiro-cli falls back to interactive device-flow login and errors with Failed to open URL; cursor-agent errors with Authentication required.

…keys

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title fix: add missing Kiro network domains and SECRET_ fallbacks for auth keys fix: add missing Kiro network domains and SECRET_ auth key fallbacks Aug 5, 2026
Copilot AI requested a review from pelikhan August 5, 2026 14:21
@pelikhan
pelikhan marked this pull request as ready for review August 5, 2026 14:38
Copilot AI balanced review requested due to automatic review settings August 5, 2026 14:38
@pelikhan
pelikhan merged commit 65d4422 into main Aug 5, 2026
@pelikhan
pelikhan deleted the copilot/fix-issue-50519 branch August 5, 2026 14:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds reliable authentication and network access for Kiro and Cursor workflow engines.

Changes:

  • Allows required Kiro AWS API and telemetry domains.
  • Restores API keys from AWF’s SECRET_-prefixed variables.
  • Regenerates affected smoke-test workflow lock files.
Show a summary per file
File Description
.github/workflows/shared/kiro.md Adds domains and Kiro key fallback.
.github/workflows/shared/cursor.md Adds Cursor key fallback.
.github/workflows/smoke-kiro.lock.yml Regenerates the Kiro workflow.
.github/workflows/smoke-cursor.lock.yml Regenerates the Cursor workflow.

Review details

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 4/4 changed files
  • Comments generated: 0
  • Review effort level: Balanced

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.85.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants