Skip to content

feat(rerank): support Amazon Bedrock Agent Runtime rerank - #3958

Open
bigdu332 wants to merge 3 commits into
Tencent:mainfrom
bigdu332:feat/bedrock-rerank-3512
Open

bigdu332 wants to merge 3 commits into
Tencent:mainfrom
bigdu332:feat/bedrock-rerank-3512

Conversation

@bigdu332

@bigdu332 bigdu332 commented Oct 3, 2026

Copy link
Copy Markdown

Part of #3512. This is an independent PR adding Amazon Bedrock Agent Runtime reranking (not Bedrock Runtime chat APIs).

What changed

  • Register a rerank-only Amazon Bedrock provider and catalog entries for amazon.rerank-v1:0 and cohere.rerank-v3-5:0.
  • Use the official AWS SDK v2 bedrockagentruntime.Rerank action with per-model AWS Access Key ID / Secret Access Key, regional SigV4 signing, and the existing SSRF-safe HTTP transport.
  • Map ordered source indexes/scores back to input documents, including pagination and malformed/duplicate response checks.
  • Keep the model's own secret for the rerank test-connection path instead of borrowing WeKnora Cloud tenant credentials.

Credentials / scope

This implementation supports static AWS AK/SK pairs only. Temporary credentials with a session token, IAM role chains and ADC-style host credentials are intentionally not used, to avoid cross-tenant credential fallback. The model secret uses the existing AppSecret storage path; encryption at rest requires the deployment's SYSTEM_AES_KEY configuration. AWS-side permissions/model access are still required. No live AWS account was available for end-to-end verification.

Validation

  • go test ./internal/models/api/bedrockrank ./internal/models/rerank ./internal/models/providers — pass
  • Targeted model parity, catalog transport, wire-shape and region/signing tests — pass
  • Targeted handler credential-selection tests — pass
  • python3 scripts/model-catalog/generate.py --check — pass
  • git diff --check — pass

The full parity suite is not runnable in this environment because its unrelated vendor-host SSRF tests require DNS resolution to public endpoints. The full handler suite has an existing unrelated failure in TestPutTenantParserConfigAdminPreservesRedactedSecrets (expected 200, got 400); the Bedrock-specific handler tests pass.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant