{"version":"2.1.281","anchor":"bedrock-upstream-supports-assume-role-credentials-and-a-guar","canonical_anchor":"bedrock-upstream-supports-assume-role-credentials-and-a-guar","heading":"Self-hosted gateway: Bedrock guardrails and assume_role, plus telemetry and Desktop policy options","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/bedrock-upstream-supports-assume-role-credentials-and-a-guar","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Self-hosted gateway: Bedrock guardrails and assume_role, plus telemetry and Desktop policy options\n\nGateway Bedrock upstreams can now apply a Bedrock Guardrail and assume an AWS role; telemetry gains resource_attributes and policies gain serve_to_desktop\n\n**Unclear.** The finding does not say what the `guardrail: true` flag does on its own in this client or how a user sets `assumeRole`.\n\n**What**\n\nClaude Code includes a gateway that organisations can run to route requests to model providers. An upstream is one of the providers the gateway forwards to. The gateway config gained several options.\n\n- Bedrock upstreams accept an optional `guardrail` with `id` and `version`. When set, every request to that upstream carries the `X-Amzn-Bedrock-GuardrailIdentifier` and `X-Amzn-Bedrock-GuardrailVersion` headers.\n\n- The guardrail must be set on all Bedrock upstreams or none. Config validation refuses a partial setup, because failover could otherwise send requests to a Bedrock upstream without the guardrail.\n\n- On `\/v1\/messages`, clients can no longer supply their own `amazon-bedrock-*` fields; such requests are rejected with a 400 error.\n\n- Bedrock upstreams accept `assume_role` with `role_arn`, `external_id` and `session_name` (email or sub). The gateway then calls `sts:AssumeRole` using access keys or the ambient AWS credential chain, and the Bedrock client uses the resulting shared credentials. An STS temporary-credentials provider was added for this.\n\n- `assume_role` cannot be combined with `aws_bearer_token`: the error says it needs SigV4 source credentials, which a bearer token cannot provide.\n\n- `telemetry` gains `resource_attributes`.\n\n- `managed.policies` gains `serve_to_desktop`. When a request's user-agent identifies Claude Desktop, a policy is withheld unless it sets `serve_to_desktop`.\n\n**Why**\n\nAdmins who route Claude Code through the gateway can enforce Bedrock Guardrails centrally without clients being able to override or strip them, use cross-account AWS roles for Bedrock, and choose which policies reach Claude Desktop sessions."}