Concepts

Capability contracts

Each capability has a contract that any implementation must preserve. The products named below, Amazon Bedrock AgentCore services among them, are the reference choices in this repository, not requirements.

Contracts versus implementations

Labels like LLM Gateway, Tool Gateway, agent runtime, memory, identity, registry, policy engine, delivery pipeline, and observability describe architectural capabilities. A capability contract defines the outcomes and controls that any chosen implementation must preserve, regardless of product. The repository supplies one integrated implementation so that the contracts can be deployed and tested end to end.

A substitute is not automatically a drop-in configuration change. It can require new adapters, IaC, runbooks, threat-model updates, and migration logic. The substitute becomes supported only after the same positive and adversarial, mutation, load, rollback, observability, and teardown obligations pass for that implementation.

Source: README.md: Capability Architecture (opens in new tab)

The capabilities

The root README lists 10 capabilities. Each card names the capability, what it does, the reference implementations in this repository, and what a replacement must keep.

LLM Gateway

Governed access to foundation models with authentication, routing, policy enforcement, and usage attribution.

Reference implementations
  • AgentCore Gateway inference targets
  • LiteLLM
Contract
Central, non-bypassable authentication with tenant context, model allow-listing, and telemetry.
See LLM Gateway by project

Tool Gateway

Authenticated MCP discovery and invocation with least-privilege execution and policy enforcement.

Reference implementations
  • AgentCore Gateway (AWS_IAM in the Blueprint; Cognito JWT authorizer in the Workshop, Self-Service and MCP Gateway)
Contract
Exact approved targets, tenant propagation, audit, and failure isolation.
See Tool Gateway by project

Agent Runtime

Immutable deployable agent execution with workload identity, isolation, and invocation contracts.

Reference implementations
  • AgentCore Runtime
Contract
Health, scaling, logs, safe update, and rollback capabilities.
See Agent Runtime by project

Agent Memory

Actor-scoped event storage with encryption and retention policies.

Reference implementations
  • AgentCore Memory with CMK
Contract
Actor isolation, encryption, deletion lifecycle, and auditable access.
See Agent Memory by project

Identity

Short-lived credentials with tenant binding and traceable identity exchange.

Reference implementations
  • AgentCore Identity
  • Cognito M2M
Contract
Tenant binding, rotation, revocation, and no secret exposure.
See Identity by project

Registry

Ownership, lifecycle state, and approval separation for agents and tools.

Reference implementations
  • AWS Agent Registry
Contract
Immutable descriptor identity, versioning, and prevention of unapproved use.
See Registry by project

Policy Engine

Fail-closed authorization with explicit context, versioning, and decision telemetry.

Reference implementations
  • AgentCore PolicyEngine
  • Cedar
Contract
Positive and negative tests and rollback capability.
See Policy Engine by project

Delivery

Reviewed source, reproducible build, scanning, promotion gates, and rollback.

Reference implementations
  • CodePipeline
  • CodeBuild
  • ECR
Contract
Image scanning, nonproduction proof, approval, and rollback.
See Delivery by project

Observability

Correlated logs, metrics, and traces with cell and fleet views.

Reference implementations
  • CloudWatch
  • X-Ray
  • OAM
Contract
Access separation, retention, alarms, and request attribution.
See Observability by project

Cost

Attribution by application, agent, tenant, and environment with budgets.

Reference implementations
  • Allocation tags
  • Budgets
  • CUR
Contract
Shared-cost policy, anomaly response, and portfolio reporting.
See Cost by project

Capability by project

The table states how strongly each project delivers each capability in its tested form. Postures are coarse on purpose; the text in each cell carries the nuance and links to the file it comes from.

  • EnforcedActive in the deployed reference implementation.
  • Advisory by defaultPresent, but logs or opt-in rather than blocking until you switch it on.
  • IllustrativeTaught or demonstrated; not positioned as a production control.
  • Outside envelopeDocumented by the project as outside its tested support envelope.
  • Not applicableNot part of this project.

The table is wider than the screen. Scroll it sideways to see every project.

Capability posture by project, with sources
CapabilityWorkshopLearnSelf-ServiceBuildMCP GatewayGovernBlueprintScale
LLM GatewayIllustrative

Module 2 deploys LiteLLM Proxy on ECS Fargate for governed, cost-attributed access to Amazon Bedrock models.

README.md: What you'll build (opens in new tab)

Not applicable

No LLM gateway layer. Agents call one of 13 model providers directly (Bedrock by default). LiteLLM appears only as an optional MCP gateway or registry catalog.

README.md: Key Features (opens in new tab)

Not applicable

Governs tool calls only; model access is out of scope.

README.md (opens in new tab)

Enforced

AgentCore Gateway inference targets with a mandatory Guardrail interceptor and a model allow-list; LiteLLMModel is the agent client.

README.md: Capability contracts and replaceable implementations (opens in new tab)

Tool GatewayIllustrative

Module 3a layers an AgentCore Tools Gateway over the MCP Gateway & Registry for JWT auth, audit and guardrails; Module 3b uses AgentCore Gateway with Lambda targets.

README.md: What you'll build (opens in new tab)

Enforced

Selected tools deploy as a single Lambda behind an AgentCore Gateway with Cognito OAuth2; agents discover them at runtime via tools/list.

README.md: Key Features (opens in new tab)

Enforced

AgentCore Gateway with a CUSTOM_JWT (Cognito) authorizer in front of two sample Lambda targets; one governed MCP endpoint.

README.md (opens in new tab)

Enforced

An AWS_IAM AgentCore Tool Gateway per Workstream cell; targets derived from approved Registry records.

README.md: 2.3 Repeatable Workstream cell (opens in new tab)

Agent RuntimeIllustrative

Module 4 deploys a FAST travel agent on AgentCore Runtime, wired to the platform through the MCP path or the AgentCore path.

README.md: What you'll build (opens in new tab)

Enforced

Canvas agents deploy as code-generated AgentCore Runtime or as a config-driven AgentCore Harness.

README.md: Key Features (opens in new tab)

Not applicable

No agent runtime. An external MCP client such as Kiro or Claude Code drives the gateway; only the optional Atlassian connector runs a server on AgentCore Runtime.

README.md (opens in new tab)

Enforced

Nonproduction and production AgentCore Runtime per Workstream cell, deployed as immutable revisions with rollback.

README.md: 2.3 Repeatable Workstream cell (opens in new tab)

Agent MemoryIllustrative

The Module 4 FAST agent ships with conversation memory.

module-4/index.en.md: The scenario (opens in new tab)

Enforced

A Memory node on the canvas; teardown removes the memories it created.

README.md: Key Features (opens in new tab)

Not applicable

Not part of this project.

Enforced

AgentCore Memory with actor-scoped events and customer-managed KMS keys.

README.md: Capability contracts and replaceable implementations (opens in new tab)

IdentityIllustrative

Cognito and WorkloadIdentity provide human and machine identity in Module 3b; three IAM persona roles separate duties.

module-3b/index.en.md: What you will learn (opens in new tab)

Enforced

Cognito user pool for people, an Identity node for agents, and connector credentials that live only in Secrets Manager.

README.md: Key Features (opens in new tab)

Enforced

Cognito OIDC JWT inbound authentication; per-user OAuth 3LO for the optional connectors.

README.md (opens in new tab)

Enforced

AgentCore Identity plus Cognito M2M short-lived credentials.

README.md: 10.1 Control summary (opens in new tab)

RegistryIllustrative

Module 3a uses the open-source MCP Gateway & Registry; Module 3b creates an AgentCore Registry with a Publisher and Admin approval workflow.

module-3b/index.en.md (opens in new tab)

Enforced

Built-in agent registry with an approval workflow (registry-admin and registry-developer personas); a LiteLLM proxy can become the catalog.

README.md: Key Features (opens in new tab)

Not applicable

No registry. The README positions the gateway a layer below platforms that manage which agents and servers exist.

README.md: Related projects (opens in new tab)

Enforced

AWS Agent Registry governance records drive Gateway targets. See advisory for issue #29 on the preview API cutoff.

README.md: Capability contracts and replaceable implementations (opens in new tab)

Policy EngineIllustrative

Module 3b Part C creates an AgentCore Policy Engine with Cedar policies and attaches it in LOG_ONLY mode; in this setup ENFORCE would empty tools/list.

step-7/index.en.md (opens in new tab)

Enforced

Cedar ENFORCE per Policy node (fail-closed, converge-in-place); scope-based RBAC is advisory by default.

ENTERPRISE_CAPABILITIES.md: Agent lifecycle & quality (opens in new tab)

Enforced

Cedar ENFORCE at the gateway with one policy per statement; policies are created with validationMode IGNORE_ALL_FINDINGS.

manifest.json (opens in new tab)

Enforced

AgentCore Policy Engine plus a retained Lambda Cedar wrapper; 12 SCPs for model, Region, Guardrail, Registry, Gateway and deployment boundaries.

README.md: Capability contracts and replaceable implementations (opens in new tab)

DeliveryNot applicable

Not covered. The five stacks deploy through a shell wrapper with a preflight check.

README.md: Repository structure (opens in new tab)

Enforced

A Step Functions deployment pipeline (validate, codegen, IAM, runtime, evaluation) with versioning and rollback; no source-review gate.

COSTS.md: AWS Resources Created (opens in new tab)

Not applicable

Deployed with cdk deploy from a workstation; no pipeline.

README.md: Quickstart (opens in new tab)

Enforced

GitHub, CodeConnections, CodePipeline, CodeBuild and ECR; digest-bound image scanning blocks Critical or High findings; human approval after deployed-runtime evaluation.

README.md: 10.1 Control summary (opens in new tab)

ObservabilityIllustrative

Grafana dashboards backed by Amazon Managed Service for Prometheus in Module 3a; Module 4 inspects traces, logs and memory.

module-3a/index.en.md: What's already deployed (opens in new tab)

Enforced

Per-canvas and platform-level OTEL modes; OTLP traces from every platform Lambda and deployed agent can go to a backend such as Langfuse.

README.md: Quickstart (opens in new tab)

Enforced

One structured request_audit record per call in the interceptor logs; refused calls are audited too.

README.md: 3. See the audit trail (opens in new tab)

Enforced

CloudWatch OAM links for centralized Logs, Metrics and Traces; Transaction Search is opt-in.

README.md: 10.1 Control summary (opens in new tab)

CostIllustrative

The Module 2 LLM Gateway gives cost-attributed model access through LiteLLM virtual keys and budgets.

module-4/index.en.md: The scenario (opens in new tab)

Enforced

Cost budgets, usage events and audit analytics; a budget breach emits a CloudWatch metric.

README.md: Key Features (opens in new tab)

Not applicable

No cost attribution controls in this sample.

Enforced

Five allocation tags, per-application budgets, account-level Bedrock quotas and CUR reconciliation.

README.md: 10.1 Control summary (opens in new tab)

Replacing an implementation

When replacing a reference implementation with an alternative:

  • The replacement must preserve the stated security, identity, tenancy, lifecycle, and evidence contracts.
  • All positive and adversarial tests must pass with the replacement.
  • The live support envelope applies only to the exact reference implementation that was tested.
  • Documentation, runbooks, and threat models may need updates.

The tested regions, versions and known limitations per project are collected on the support envelope page.