Learn the platform patterns hands-on

Learn

Building an Enterprise Agentic AI Platform

Hands-on AWS workshop for building an enterprise landing-zone pattern for agentic AI on Amazon Bedrock and Amazon Bedrock AgentCore.

First deploy
About 30 to 45 minutes for the self-paced deploy script (five CloudFormation stacks) source for first deploy (opens in new tab)
Validated regions
AWS-run events: us-west-2. Self-paced: us-west-2 (default), us-east-1, or eu-west-1. Other regions are not supported. source for validated regions (opens in new tab)
Infrastructure as code
CloudFormation, run by the self-paced deploy script; Module 4 deploys the FAST agent with the AWS CDK from inside the IDE source for infrastructure as code (opens in new tab)
Agentic AI Platform architecture

What it is

  • Five modules (1, 2, 3a, 3b, 4) with a track selector at the end of Module 1
  • Three workshop tracks: Fast Path, Build the Platform, Full Journey
  • Hands-on with real AWS resources in a browser-based Code Editor IDE
  • Run it at an AWS event or self-paced in your own account with one deploy script
  • CLI walkthrough or notebook walkthrough for most module sections

Source: README.md: What you'll build (opens in new tab)

Status

Version
not documented The workshop has no version badge, tag or CHANGELOG. contentspec.yaml declares only the Workshop Studio schema version 2.0.
Status
Published on AWS Builder Center (Workshop Studio); last published 2026-08-18 Workshop Studio catalog (opens in new tab) Publication state and date come from the Workshop Studio catalog entry, not from the repository, which holds no publish record to quote.

Recent changes: commit history for workshop-building-agentic-ai-platform on GitHub (opens in new tab)

Advisory: GitHub issue #2

Open since 2026-06-30. The LLM Gateway CloudFormation template and THIRD_PARTY_LICENSES.md reference the LiteLLM image at docker.litellm.ai/berriai/litellm-database (tag v1.84.0). The issue asks for the image to be pulled from ghcr.io instead.

ghcr.io instead of docker.litellm.ai (opens in new tab)

Evidence: THIRD_PARTY_LICENSES.md (opens in new tab)

At a glance

Workshop facts with a source for every value
FactValueSource
Validated regionsAWS-run events: us-west-2. Self-paced: us-west-2 (default), us-east-1, or eu-west-1. Other regions are not supported. The contentspec.yaml deployableRegions list is us-west-2, us-east-1 and eu-west-1. Workshop Studio events provision the account in us-west-2 (content/introduction/getting-started/aws-event.en.md).contentspec.yaml (opens in new tab)
Default regionus-west-2README.md: Quick start (self-paced) (opens in new tab)
What it deploysFive CloudFormation stacks: LLM Gateway, MCP Registry, Tools Gateway, AgentCore, Code Editor IDEREADME.md: Quick start (self-paced) (opens in new tab)
First deployAbout 30 to 45 minutes for the self-paced deploy script (five CloudFormation stacks) The self-paced guide (content/introduction/getting-started/self-service.en.md) notes that the Registry stack alone takes 20 to 30 minutes. At an AWS event the account arrives pre-provisioned, so there is nothing to deploy.README.md: Quick start (self-paced) (opens in new tab)
Hands-on time1.5 to 4 hours depending on the trackcontentspec.yaml (opens in new tab)
CostAbout $15 to $30 for a one-day run in us-west-2 (workshop estimate) At an AWS-run event the account is provided and the cost is covered. Cost accrues per hour whether or not the environment is in use.index.en.md: Cost (opens in new tab)
Infrastructure as codeCloudFormation, run by the self-paced deploy script; Module 4 deploys the FAST agent with the AWS CDK from inside the IDEREADME.md: Quick start (self-paced) (opens in new tab)
Account topologySingle AWS account; a dedicated, disposable account is recommendedREADME.md: Prerequisites (self-paced) (opens in new tab)
Auth and policyCognito JWT on the Tools Gateway and the AgentCore Registry; group-based access in interceptors and Cedar policies (Module 3b); scoped IAM deploy policies Module 3b Part C creates an AgentCore Policy Engine with Cedar policies. The CLI path stops short of attaching it to the Gateway; the notebook attaches it in LOG_ONLY mode, not ENFORCE, because ENFORCE would empty tools/list in that setup (content/module-3b/step-7/index.en.md).README.md: What you'll build (opens in new tab)
StatusPublished on AWS Builder Center (Workshop Studio); last published 2026-08-18 Publication state and date come from the Workshop Studio catalog entry, not from the repository, which holds no publish record to quote.Workshop Studio catalog (opens in new tab)
TeardownFollow the workshop Cleanup module for Module 4 and Module 3a resources, then run ./deploy-cfn.sh destroy from the workshop folder. At an AWS event Workshop Studio cleans up the account automatically.README.md: Delete Everything (opens in new tab)
Versionnot documented The workshop has no version badge, tag or CHANGELOG. contentspec.yaml declares only the Workshop Studio schema version 2.0.none

Compare all four projects

Quickstart

At an AWS event

Prerequisites: Workshop prerequisites on the Start pages.

Workshop Studio provisions a pre-configured account for you. There is nothing to deploy.

Expected time: No deploy; start the modules as soon as you have the account README.md: Running the workshop (opens in new tab)

  1. Open the workshop (opens in new tab)

    The workshop guide is published on AWS Builder Center (Workshop Studio).

    Source: README.md (opens in new tab)

  2. Sign in to the pre-provisioned AWS account

    All workshop resources are deployed to us-west-2. Log out of other AWS console sessions first.

    Source: aws-event.en.md: Before you start (opens in new tab)

  3. Open the workshop IDE from the Event outputs

    On the Event dashboard, find the row with stack name code-editor and open the URL value.

    Source: aws-event.en.md: Open the workshop IDE (opens in new tab)

  4. Start at Module 1 and pick a track

    Module 1 ends with a track selector: Fast Path, Build the Platform, or Full Journey.

    Source: README.md: Choose your track (opens in new tab)

Self-paced in your own account

Prerequisites: Workshop prerequisites on the Start pages.

One deploy script provisions the same five CloudFormation stacks and browser IDE that events use. Use a dedicated account you can tear down.

Expected time: About 30 to 45 minutes for the self-paced deploy script (five CloudFormation stacks) README.md: Quick start (self-paced) (opens in new tab) The self-paced guide (content/introduction/getting-started/self-service.en.md) notes that the Registry stack alone takes 20 to 30 minutes. At an AWS event the account arrives pre-provisioned, so there is nothing to deploy.

  1. Clone the repository and enter the project folder

    git clone https://github.com/aws-samples/sample-ai-agent-factory.git
    cd sample-ai-agent-factory/workshop-building-agentic-ai-platform

    Folder names are exact and case-sensitive.

    Source: README.md: Quick start (self-paced) (opens in new tab)

  2. Set a validated region

    aws configure set region us-west-2   # or us-east-1, eu-west-1

    us-west-2 is the default. us-east-1 and eu-west-1 are also validated. Other regions are not supported.

    Source: README.md: Quick start (self-paced) (opens in new tab)

  3. Deploy all five stacks

    ./scripts/self-service-deploy.sh

    About 30 to 45 minutes. The script runs a preflight check, then prints the IDE URL and password at the end.

    Source: README.md: Quick start (self-paced) (opens in new tab)

  4. Verify the environment

    ./scripts/self-test.sh -r "$(aws configure get region)"

    Expect 5 passed, 0 failed.

    Source: README.md: Quick start (self-paced) (opens in new tab)

  5. Open the IDE and start at Module 1

    Sign in with the generated IdePassword. Run every module command inside the IDE terminal or notebooks, not on your laptop.

    Source: README.md: Quick start (self-paced) (opens in new tab)

Tracks

The workshop has three tracks of its own. All tracks share Module 1, which ends with a track selector.

The three workshop tracks, from the README track table
TrackBest forYou doDuration
1. Fast PathAI/ML engineers who want to build an agentJump straight to Module 4; the platform is pre-deployedAbout 1.5 to 2 hours
2. Build the PlatformPlatform engineersModules 1, 2, 3a, 3b (stops before the agent)About 2 to 3 hours
3. Full JourneySolutions architects, tech leadsModules 1, 2, 3a, 3b, 4 end-to-endAbout 3 to 4 hours

Source: README.md: Choose your track (opens in new tab)

Modules

  1. Module 1: The Vision. Why enterprises need a platform approach to agentic AI, not just individual agents (all tracks).
  2. Module 2: LLM Gateway. Deploy LiteLLM Proxy on ECS Fargate for governed, cost-attributed access to Amazon Bedrock models.
  3. Module 3a: MCP Registry + Tools Gateway. Register tools in the MCP Gateway & Registry, then layer an AgentCore Tools Gateway on top for JWT auth, audit, and guardrails.
  4. Module 3b: AgentCore Registry & Gateway. AWS-native tool governance with Amazon Bedrock AgentCore, Cedar-based authorization, and EventBridge-driven approval workflows.Not the same as the MCP Gateway project on this site: Module 3b attaches its Cedar policy in LOG_ONLY mode and teaches the Registry approval workflow, while the MCP Gateway project runs its policy engine in ENFORCE mode. See MCP Gateway in the glossary. Source: index.en.md (opens in new tab), README.md: Verified architecture (opens in new tab)
  5. Module 4: Build Your Agent. Deploy a full-stack travel agent using FAST (Fullstack AgentCore Solution Template) on Amazon Bedrock AgentCore, wired to the platform via either the MCP path or the AgentCore path.

Source: README.md: What you'll build (opens in new tab)

Notebooks

The notebooks run inside the browser Code Editor IDE that the workshop provisions, not on your laptop. Open them from /workshop/source/<module>/notebooks/ in the IDE and select the workshop kernel (workshop-fast for Module 4b). README.md (opens in new tab)

Folder names under source/ predate the module renumbering: module-4a-tools-gateway holds the Module 3a Tools Gateway notebooks. Source: README.md: Repository structure (opens in new tab)

module-3a-mcp-registry

Architecture and figures

The image in the page header is the platform architecture from the README. README.md (opens in new tab)

FAST architecture: AgentCore Runtime with Amplify frontend, Cognito auth, Gateway tools, and Memory
FAST (Fullstack AgentCore Solution Template) architecture, from the workshop Module 4 page. index.en.md (opens in new tab)

Architecture across all four projects

Known limitations and support envelope

Each item is copied from the project README or docs without paraphrase.

Support envelope for all projects

Evidence

A self-paced deployment is checked by a post-deploy health check; the workshop content and its infrastructure copies are guarded by parity scripts that run against the repository.

What runs against live AWS

self-test.sh runs against the deployed account: it verifies the four platform stacks plus the IDE and that key endpoints respond, and exits non-zero if any check fails. The parity scripts and the module unit tests need no AWS account.

Source: self-test.sh (opens in new tab)

Post-deploy health check (scripts/self-test.sh)

./scripts/self-test.sh -r "$(aws configure get region)"   # expect: 5 passed, 0 failed

What a pass proves: The five stacks are deployed in the region you chose and their key endpoints respond. Expect 5 passed, 0 failed before starting Module 1.

Source: workshop-building-agentic-ai-platform/README.md: Quick start (self-paced) (opens in new tab), workshop-building-agentic-ai-platform/README.md: Repository structure (opens in new tab)

CLI and notebook parity (scripts/verify-walkthrough-parity.py)

What a pass proves: A CLI walkthrough page and its notebook write the same source files, so participants on either path run identical code.

Source: verify-walkthrough-parity.py (opens in new tab)

Assets bucket parity (scripts/verify-assets-parity.py)

What a pass proves: The assets/ copy served from the shared assets bucket matches the git-tracked static/ and content/ sources, so a fix pushed to git cannot leave a stale copy behind.

Source: verify-assets-parity.py (opens in new tab)

Participant IAM policy parity (scripts/verify-ide-policy-parity.py)

What a pass proves: The five participant IAM policy files match the copies embedded in code-editor.yaml, and each stays under the IAM managed-policy size quota.

Source: verify-ide-policy-parity.py (opens in new tab)

Contributor gates: cfn-lint and the module unit tests

What a pass proves: Changed CloudFormation templates lint clean and the module unit tests pass before a change is pushed.

Source: README.md: Content guidelines (opens in new tab)

Documentation on this site

  • README: Building an enterprise agentic AI platform on Amazon Bedrock AgentCore

Teardown

At an AWS event

Nothing to do. Workshop Studio cleans up the account when the event ends.

Source: index.en.md (opens in new tab)

Self-paced in your own account

Tear everything down to stop charges.

./deploy-cfn.sh destroy

Source: README.md: Delete Everything (opens in new tab)

Costs and cleanup for all projects