Reference

Security

Security controls by project for four samples centered on Amazon Bedrock and Amazon Bedrock AgentCore: what to review before production, where each project's security documentation lives, and how to report a vulnerability.

Security controls by project

Each cell states the control as the project ships it, with a link to the file that says so. Postures are coarse on purpose; read the cell text before relying on a control.

  • EnforcedActive in the deployed reference implementation.
  • Advisory by defaultPresent, but logs or opt-in rather than blocking until you switch it on.
  • IllustrativeTaught or demonstrated; not positioned as a production control.
  • Outside envelopeDocumented by the project as outside its tested support envelope.
  • Not applicableNot part of this project.

The table is wider than the screen. Scroll it sideways to see every project.

Security control posture by project, with sources
ControlWorkshopLearnSelf-ServiceBuildMCP GatewayGovernBlueprintScale
AuthenticationIllustrative

Cognito JWT on the Tools Gateway and the AgentCore Registry; Admin, Publisher and Consumer IAM persona roles; the scoped WSParticipantRole at events.

module-3b/index.en.md: Steps (opens in new tab)

Enforced

Cognito user pool with SRP only (USER_PASSWORD_AUTH disabled) and user-existence errors prevented; OIDC federation available.

SECURITY_HARDENING.md: Infrastructure Hardening (opens in new tab)

Enforced

CUSTOM_JWT authorizer validates Cognito access tokens against the OIDC discovery URL; the demo app client allows only the IAM-gated ADMIN_USER_PASSWORD_AUTH flow.

README.md: Identity & secrets (opens in new tab)

Enforced

AWS_IAM (SigV4) for the Tool Gateway; AgentCore Identity and Cognito M2M CUSTOM_JWT for inference.

README.md: 14. Architecture decision record (opens in new tab)

AuthorizationIllustrative

A request interceptor enforces a TOOL_ACCESS_POLICY by Cognito group; Cedar policies on a Policy Engine run in LOG_ONLY mode (Module 3b).

step-7/index.en.md: Part B: Group-based tool access control (opens in new tab)

Advisory by default

Scope-based RBAC ships advisory by default (RBAC_ENFORCE=false); owner-scoped tenant isolation is always enforced; Cedar ENFORCE applies per Policy node.

RBAC_ROLLOUT.md: RBAC Enforcement Rollout Runbook (opens in new tab)

Enforced

Cedar ENFORCE per tool call with default deny. Role-gated permits never fire for demo users because custom:role is only in the ID token.

README.md (opens in new tab)

Enforced

Organizations SCPs, AgentCore PolicyEngine, the retained Lambda Cedar wrapper, exact Lambda alias ARNs and exact role principals.

README.md: 10.1 Control summary (opens in new tab)

EncryptionIllustrative

The registry data stack creates a customer-managed KMS key for the DocumentDB store; see the CloudFormation templates under static/cfn for the other stores.

data-stack.yaml (opens in new tab)

Enforced

DynamoDB tables use AWS-managed SSE; S3 buckets block public access and enforce SSL; the SNS topic uses SSE with enforced TLS; CloudFront requires TLS 1.2.

DATA_RETENTION.md: Encryption (opens in new tab)

Enforced

One customer-managed KMS key with annual rotation for the gateway, the policy engine and its policies, and the demo credential secret.

README.md: Identity & secrets (opens in new tab)

Enforced

Customer-managed KMS keys for Memory and per-cell resources; Secrets Manager and KMS for secrets.

README.md: 10.1 Control summary (opens in new tab)

NetworkIllustrative

Two VPCs (LLM gateway and registry), each with its own NAT gateway; public load balancers and CloudFront for the IDE.

self-service.en.md: Service quota headroom (opens in new tab)

Enforced

WAF web ACL (CLOUDFRONT scope in us-east-1, REGIONAL on the Cognito pool elsewhere); the control plane has no VPC egress; runtimes can use VPC egress through named profiles; optional PrivateLink ingress add-on.

README.md: Deploying to another region (opens in new tab)

Not applicable

No network isolation is described. The gateway is a public AgentCore endpoint authenticated by JWT.

README.md (opens in new tab)

Enforced

Private VPC with three AZs and private-isolated subnets only (no internet gateway, no NAT) reaching AWS services through interface endpoints. The live-validated Workstream Runtime stack sets networkMode PUBLIC; VPC network mode is documented as a follow-on. VPC Lattice private endpoints are outside the envelope.

agentic-vpc-construct.ts (opens in new tab)

AuditIllustrative

Request and response interceptors write audit trails for tool calls in Modules 3a and 3b.

module-3b/index.en.md: What you will learn (opens in new tab)

Enforced

An audit table stores one row per control-plane write (actor sub, action, path, status) with a 90-day TTL; readable by super-admins only.

DATA_RETENTION.md (opens in new tab)

Enforced

Structured request_audit and request_blocked records per call; refused calls are audited; the user is the Cognito sub; argument values are never logged.

README.md: 3. See the audit trail (opens in new tab)

Enforced

CloudTrail and retained audit data corroborate control-plane actions; OAM links make telemetry queryable from Management.

README.md: Telemetry and assurance flow (opens in new tab)

GuardrailsIllustrative

Module 3b step 7 wires a Bedrock guardrail to the response interceptor to screen tool output; the Module 2 LLM Gateway carries guardrails too.

step-7/index.en.md: Part A: Bedrock Guardrails on tool output (opens in new tab)

Enforced

A Guardrails node on the canvas with contextual grounding, regex and injection-defense configurations; guardrail creation is idempotent.

DEPLOYMENT_INTERNALS.md (opens in new tab)

Enforced

Managed Bedrock Guardrail via ApplyGuardrail on requests (prompt attack, content filters) and responses (PII anonymized). It uses the unpinned DRAFT version, and a guardrail API error is logged while the local regex controls still apply.

README.md: Managed guardrail (Amazon Bedrock Guardrails) (opens in new tab)

Enforced

Mandatory Bedrock Guardrail request interceptor on the Inference Gateway; SCP-02 enforces Guardrail use and SCP-05 denies Guardrail modification.

README.md: 10.1 Control summary (opens in new tab)

Before production use

Before deploying any of these projects to a production environment, review:

  • IAM policies and trust relationships in each stack
  • Network configuration and egress patterns
  • Data classification and retention requirements
  • Compliance obligations for your organization
  • Cost projections and budget alerts
  • Backup and disaster recovery plans
  • Incident response procedures
  • Known limitations documented in each project README, collected on the support envelope page

Security documentation on this site

Rendered documents open on this site. README sections open on the rendered README page, with a GitHub link beside each. Files the site does not render link straight to GitHub.

Reporting

Security vulnerabilities: do not open a public GitHub issue. Report them through the AWS vulnerability reporting page (opens in new tab), as the repository's contributing guidelines ask.

Bugs and documentation problems: open an issue in the GitHub issue tracker (opens in new tab).