Each capability has a contract that any implementation must preserve. The products named below, Amazon Bedrock AgentCore services among them, are the reference choices in this repository, not requirements.
Contracts versus implementations
Labels like LLM Gateway, Tool Gateway, agent runtime, memory, identity, registry, policy engine, delivery pipeline, and observability describe architectural capabilities. A capability contract defines the outcomes and controls that any chosen implementation must preserve, regardless of product. The repository supplies one integrated implementation so that the contracts can be deployed and tested end to end.
A substitute is not automatically a drop-in configuration change. It can require new adapters, IaC, runbooks, threat-model updates, and migration logic. The substitute becomes supported only after the same positive and adversarial, mutation, load, rollback, observability, and teardown obligations pass for that implementation.
The root README lists 10 capabilities. Each card names the capability, what it does, the reference implementations in this repository, and what a replacement must keep.
LLM Gateway
Governed access to foundation models with authentication, routing, policy enforcement, and usage attribution.
Reference implementations
AgentCore Gateway inference targets
LiteLLM
Contract
Central, non-bypassable authentication with tenant context, model allow-listing, and telemetry.
The table states how strongly each project delivers each capability in its tested form. Postures are coarse on purpose; the text in each cell carries the nuance and links to the file it comes from.
EnforcedActive in the deployed reference implementation.
Advisory by defaultPresent, but logs or opt-in rather than blocking until you switch it on.
IllustrativeTaught or demonstrated; not positioned as a production control.
Outside envelopeDocumented by the project as outside its tested support envelope.
Not applicableNot part of this project.
The table is wider than the screen. Scroll it sideways to see every project.
No LLM gateway layer. Agents call one of 13 model providers directly (Bedrock by default). LiteLLM appears only as an optional MCP gateway or registry catalog.
Module 3a layers an AgentCore Tools Gateway over the MCP Gateway & Registry for JWT auth, audit and guardrails; Module 3b uses AgentCore Gateway with Lambda targets.
No agent runtime. An external MCP client such as Kiro or Claude Code drives the gateway; only the optional Atlassian connector runs a server on AgentCore Runtime.
Module 3b Part C creates an AgentCore Policy Engine with Cedar policies and attaches it in LOG_ONLY mode; in this setup ENFORCE would empty tools/list.
GitHub, CodeConnections, CodePipeline, CodeBuild and ECR; digest-bound image scanning blocks Critical or High findings; human approval after deployed-runtime evaluation.