JuliusBrussee/caveman · error
bedrock action %q is not allowed
Error message
bedrock action %q is not allowed
What it means
Error "bedrock action %q is not allowed" thrown in JuliusBrussee/caveman.
Source
Thrown at proxy/providers/bedrock/routing.go:175
if err != nil {
return nil, err
}
kind := endpointKindForPath(req.URL.Path)
if configuredKind := strings.ToLower(strings.TrimSpace(route.EndpointKind)); configuredKind != "" && configuredKind != kind {
return nil, fmt.Errorf("bedrock configured endpoint kind %q does not allow request kind %q", configuredKind, kind)
}
switch kind {
case endpointRuntime:
if !RegionAllowed(region) {
return nil, fmt.Errorf("bedrock region %q is not on the allowlist", region)
}
modelID, action := parseModelPath(req.URL.Path)
if modelID == "" || action == "" {
return nil, fmt.Errorf("bedrock request path %q does not name a model and action", req.URL.Path)
}
if !actionAllowed(action) {
return nil, fmt.Errorf("bedrock action %q is not allowed", action)
}
if !modelAllowed(modelID) {
return nil, fmt.Errorf("bedrock model %q is not on the allowlist", modelID)
}
base.Path = strings.TrimRight(base.Path, "/") + strings.TrimPrefix(req.URL.Path, "/bedrock")
case endpointMantle:
if !env.Bool("CAVE_BEDROCK_MANTLE_ENABLED", false) {
return nil, fmt.Errorf("bedrock Mantle endpoint is not enabled")
}
if !MantleRegionAllowed(region) {
return nil, fmt.Errorf("bedrock Mantle region %q is not on the allowlist", region)
}
if !mantleActionAllowed(req.URL.Path) {
return nil, fmt.Errorf("bedrock Mantle path %q is not allowed", req.URL.Path)
}
base, err = resolveMantleBase(base, region)
if err != nil {
return nil, errView on GitHub (pinned to 27d5a3981a)
Solutions
- Use an allowed Bedrock action.
When it happens
Trigger: Thrown at proxy/providers/bedrock/routing.go:175 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of JuliusBrussee/caveman@27d5a3981a (2026-08-15).
Data as JSON: /api/errors/e395014d52a28066.
Report an issue: GitHub.