diff --git a/.changeset/fix-bedrock-cache.md b/.changeset/fix-bedrock-cache.md new file mode 100644 index 0000000000..da7a54aca1 --- /dev/null +++ b/.changeset/fix-bedrock-cache.md @@ -0,0 +1,7 @@ +--- +"claude-dev": patch +--- + +fix(bedrock): Use ignoreCache for profile-based AWS credential loading + +Ensures that AWS Bedrock provider always fetches fresh credentials when using IAM profiles by setting `ignoreCache: true` for `fromNodeProviderChain`. This resolves issues where externally updated credentials (e.g., by AWS Identity Manager) were not detected by Cline, requiring an extension restart. Manual credential handling remains unchanged. diff --git a/src/api/providers/bedrock.ts b/src/api/providers/bedrock.ts index f6a61c9c10..ad5661ee70 100644 --- a/src/api/providers/bedrock.ts +++ b/src/api/providers/bedrock.ts @@ -223,8 +223,19 @@ export class AwsBedrockHandler implements ApiHandler { secretAccessKey: string sessionToken?: string }> { + // Configure provider options + const providerOptions: any = {} + if (this.options.awsUseProfile) { + // For profile-based auth, always use ignoreCache to detect credential file changes + // This solves the AWS Identity Manager issue where credential files change externally + providerOptions.ignoreCache = true + if (this.options.awsProfile) { + providerOptions.profile = this.options.awsProfile + } + } + // Create AWS credentials by executing an AWS provider chain - const providerChain = fromNodeProviderChain() + const providerChain = fromNodeProviderChain(providerOptions) return await AwsBedrockHandler.withTempEnv( () => { AwsBedrockHandler.setEnv("AWS_REGION", this.options.awsRegion)