JuliusBrussee/caveman · error

bedrock request path %q is not allowed

Error message

bedrock request path %q is not allowed

What it means

Error "bedrock request path %q is not allowed" thrown in JuliusBrussee/caveman.

Source

Thrown at proxy/providers/bedrock/routing.go:197

		}
		base.Path = strings.TrimRight(base.Path, "/") + strings.TrimPrefix(req.URL.Path, "/bedrock")
	case endpointMantle:
		if !env.Bool("CAVE_BEDROCK_MANTLE_ENABLED", false) {
			return nil, fmt.Errorf("bedrock Mantle endpoint is not enabled")
		}
		if !MantleRegionAllowed(region) {
			return nil, fmt.Errorf("bedrock Mantle region %q is not on the allowlist", region)
		}
		if !mantleActionAllowed(req.URL.Path) {
			return nil, fmt.Errorf("bedrock Mantle path %q is not allowed", req.URL.Path)
		}
		base, err = resolveMantleBase(base, region)
		if err != nil {
			return nil, err
		}
		base.Path = strings.TrimRight(base.Path, "/") + strings.TrimPrefix(req.URL.Path, "/bedrock")
	default:
		return nil, fmt.Errorf("bedrock request path %q is not allowed", req.URL.Path)
	}
	base.RawQuery = req.URL.RawQuery

	if env.IsProduction() {
		if err := ssrf.ValidateURL(ctx, base.String(), ssrf.ManagedConfig()); err != nil {
			return nil, err
		}
		hostKind, _, ok := bedrockHostKind(base.Hostname())
		if !ok || hostKind != kind {
			return nil, fmt.Errorf("bedrock endpoint host %q does not match endpoint kind %q", base.Hostname(), kind)
		}
	}
	return base, nil
}

func endpointKindForPath(path string) string {
	switch {
	case strings.HasPrefix(path, "/bedrock/model/"):

View on GitHub (pinned to 27d5a3981a)

Solutions

  1. Use an allowed Bedrock request path.

When it happens

Trigger: Thrown at proxy/providers/bedrock/routing.go:197 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of JuliusBrussee/caveman@27d5a3981a (2026-08-15). Data as JSON: /api/errors/8be7a04322647ca4. Report an issue: GitHub.