Reference
Support envelope
Validated regions, status, open advisories and the known limitations each project documents, collected in one place for four samples centered on Amazon Bedrock and Amazon Bedrock AgentCore.
The support envelope applies to the exact tested implementation: the reference implementations, regions and configurations each project names. Replacements and other regions require independent validation (root README (opens in new tab)). The limitation bullets below are quoted from the project files without paraphrase.
Building an Enterprise Agentic AI Platform
| Fact | Value | Source |
|---|---|---|
| Validated regions | AWS-run events: us-west-2. Self-paced: us-west-2 (default), us-east-1, or eu-west-1. Other regions are not supported. The contentspec.yaml deployableRegions list is us-west-2, us-east-1 and eu-west-1. Workshop Studio events provision the account in us-west-2 (content/introduction/getting-started/aws-event.en.md). | contentspec.yaml (opens in new tab) |
| Default region | us-west-2 | README.md: Quick start (self-paced) (opens in new tab) |
| Status | Published on AWS Builder Center (Workshop Studio); last published 2026-08-18 Publication state and date come from the Workshop Studio catalog entry, not from the repository, which holds no publish record to quote. | Workshop Studio catalog (opens in new tab) |
| Version | not documented The workshop has no version badge, tag or CHANGELOG. contentspec.yaml declares only the Workshop Studio schema version 2.0. | none |
Open advisories
- Issue #2: ghcr.io instead of docker.litellm.ai (opens in new tab)
Open since 2026-06-30. The LLM Gateway CloudFormation template and THIRD_PARTY_LICENSES.md reference the LiteLLM image at docker.litellm.ai/berriai/litellm-database (tag v1.84.0). The issue asks for the image to be pulled from ghcr.io instead.
Known limitations, as documented
- Region lock
Other regions are not supported
Source: README.md: Prerequisites (self-paced) (opens in new tab)
- AgentCore Registry availability
the Amazon Bedrock AgentCore Registry control plane is not yet generally available everywhere, which breaks Modules 3b and 4.
Source: README.md: Prerequisites (self-paced) (opens in new tab)
- Model access
Model access must be granted per region.
Source: README.md: Prerequisites (self-paced) (opens in new tab)
- Where commands run
Run everything in the IDE terminal/notebooks, not your local machine.
Source: README.md (opens in new tab)
AgentCore Visual Workflow Platform
| Fact | Value | Source |
|---|---|---|
| Validated regions | Any AWS region; us-east-1 is the default Outside us-east-1 the WAF web ACL is REGIONAL on the Cognito user pool and the CloudFront distribution runs without an edge ACL. APAC regions may need the model ID set explicitly. | README.md: Prerequisites (opens in new tab) |
| Default region | us-east-1 | README.md: Quickstart (opens in new tab) |
| Status | Version 0.1.0 released 2026-07-17, with unreleased changes recorded in CHANGELOG.md | CHANGELOG.md (opens in new tab) |
| Version | 0.1.0 plus unreleased changes | CHANGELOG.md (opens in new tab) |
No open advisories are recorded for this project.
Known limitations, as documented
- WAF outside us-east-1
The same rule set as a
REGIONALWebACL on the Cognito user pool. The distribution runs without an edge ACLSource: README.md: Deploying to another region (opens in new tab)
- APAC inference prefixes
One region-specific caveat worth knowing before you pick a region: Bedrock's cross-region inference prefixes are
us.,eu.andapac., and theapac.family covers only the older Claude models. In APAC, current-generation models are published under country prefixes (jp.inap-northeast-1,au.inap-southeast-2) or asglobal., so an APAC deployment may need its model ID set explicitly.us-*andeu-*regions need no such adjustment.Source: README.md: Deploying to another region (opens in new tab)
- RBAC is advisory by default
Scope-based RBAC (
services/rbac.py) ships advisory by default (RBAC_ENFORCE=false): every request is allowed, but a request that would be denied logsRBAC advisory (would-deny): ....Source: RBAC_ROLLOUT.md: RBAC Enforcement Rollout Runbook (opens in new tab)
- Control plane has no VPC egress
The proxy must be reachable from the deploy Lambda. The control plane has no VPC egress, so a VPC-private LiteLLM cannot be probed and the deploy will fail at step 3 even though a VPC-mode Runtime could reach it at invoke time.
Source: README.md: As the gateway itself, per agent (opens in new tab)
Enterprise MCP Governance Gateway
| Fact | Value | Source |
|---|---|---|
| Validated regions | us-west-2 by default; configurable; no tested-regions list is published | README.md (opens in new tab) |
| Default region | us-west-2 | README.md: Deploy (opens in new tab) |
| Status | Sample and demonstration stack; not hardened for production | README.md: Security notes (opens in new tab) |
| Version | not documented No version badge, tag or CHANGELOG in the project folder. | none |
No open advisories are recorded for this project.
Known limitations, as documented
- Not hardened for production
This is a sample / demonstration stack. It is deployed to a real account and is safe to demo, but it is not hardened for production
- Access token versus ID token
Query F is a known demo limitation, not a bug.
custom:roletherefore never reaches the policy engine, so the role-gatedpermitnever fires.Source: README.md (opens in new tab)
- Tighten the gateway-resource IAM scope for multi-gateway accounts.
This sample deploys a single gateway, so the wildcard effectively resolves to it. If your account runs multiple gateways in the region, restrict the statement to the specific gateway ARN after the first deploy, or use a two-phase deploy (create the gateway, then update the policy with its exact ARN).
Source: README.md: Tracked production hardening (not in this sample) (opens in new tab)
- Env-based config profiles
ENFORCE+ noexceptionLevelfor prod (DEBUGreturns verbose denial reasons, useful only for a demo).Source: README.md: Tracked production hardening (not in this sample) (opens in new tab)
- Cognito pre-token-generation Lambda
A Cognito pre-token-generation Lambda to surface
custom:rolein the access token, so the role-based Cedar policies fire (todayrole/emaillive only in the ID token, which the gateway does not validate).Source: README.md: Tracked production hardening (not in this sample) (opens in new tab)
- Per-Lambda log retention
Per-Lambda log retention.
Source: README.md: Tracked production hardening (not in this sample) (opens in new tab)
Enterprise Agentic AI Platform Blueprint
| Fact | Value | Source |
|---|---|---|
| Validated regions | Validated in eu-west-1; SCP allow-list us-west-2, us-east-1, eu-west-1 The SCP region allow-list comes from PLATFORM_APPROVED_REGIONS in packages/platform-baselines/src/approved-regions.ts. A different Region is a new validation target, not a configuration-only substitution. | README.md: 5. Prerequisites (opens in new tab) |
| Default region | eu-west-1 | README.md: 6.1 One-time setup (opens in new tab) |
| Status | Version 1.0.0 (README badge); two open advisories (issues #29 and #30) | README.md (opens in new tab) |
| Version | 1.0.0 | README.md (opens in new tab) |
Open advisories
- Issue #29: enterprise blueprint: migrate Agent Registry before 2026-09-17 preview cutoff (opens in new tab)
Opened 2026-09-15. The blueprint still provisions and consumes Agent Registry through the preview bedrock-agentcore-control APIs, and AWS support for those APIs ended on 2026-09-17. Treat Registry-dependent paths as unverified until the issue is closed.
- Issue #30: enterprise blueprint: resolve npm audit findings before deployment (opens in new tab)
Opened 2026-09-15. The lockfile resolves aws-cdk-lib to 2.251.0; advisory GHSA-vcrf-j523-4mrf (CVE-2026-13760, high) is fixed in aws-cdk-lib 2.260.0. This is a build and deployment toolchain risk; run npm audit and update before deploying.
Evidence: package-lock.json (opens in new tab)
Live-validated reference envelope
What Blueprint states it has validated, quoted from its README (source (opens in new tab)). Anything outside this list is covered by the limitations below.
Platform and Workload pipelines through production.
AWS Agent Registry record resolution and governance.
Generated agents using LiteLLMModel and MCPClient.
AgentCore Identity, Runtime, Memory, Inference Gateway, and Tool Gateway.
Benign and adversarial Guardrail calls with exact admitted and blocked outcomes.
Exact HTTP 429 behavior for an unallocated model.
Direct cross-account Runtime denial.
Runtime update cancellation, rollback, and re-run while sampled sessions remained available.
Evaluation gates for regression, quality, tool success, refusal, latency, and cost.
Management queries across linked Platform and Workstream logs and metrics.
Gateway application-log and OTEL span correlation after regional propagation.
Dependency-ordered teardown and direct zero-residual inventories across all three account roles.
Known limitations, as documented
Any substituted LLM Gateway, Tool Gateway, runtime, memory, identity, registry, policy, delivery, observability, or safety implementation until its full contract matrix passes.
Source: README.md: Outside the current envelope (opens in new tab)
A demonstrated rollout to hundreds of engineers or a measured fleet-capacity benchmark.
Source: README.md: Outside the current envelope (opens in new tab)
Any Region other than
eu-west-1until independently validated.Source: README.md: Outside the current envelope (opens in new tab)
Legacy direct-Bedrock evaluation, online-evaluation, ECS LiteLLM, and direct circuit-breaker paths that rely on cross-Region profiles.
Source: README.md: Outside the current envelope (opens in new tab)
VPC Lattice private endpoints.
Source: README.md: Outside the current envelope (opens in new tab)
Transaction Search enabled by default.
Source: README.md: Outside the current envelope (opens in new tab)
Native Gateway rate limiting as a hard quota or authorization control.
Source: README.md: Outside the current envelope (opens in new tab)
Automatic retirement of the Lambda Cedar wrapper.
Source: README.md: Outside the current envelope (opens in new tab)
A compliance certification, availability SLA, or guarantee that future AWS changes preserve behavior.
Source: README.md: Outside the current envelope (opens in new tab)
- Runtime network posture
Network posture:
networkMode = PUBLIC, matching the live commit.Source: d03-workstream-runtime-memory-stack.ts (opens in new tab)
- Evaluation gate
This is a scaffolded implementation
- Region support
A Region is supportable only after independent service-availability, model and residency, IAM/SCP, availability-zone, strict synth, positive/adversarial, rollback, observability, and teardown gates pass there. Do not extrapolate from Ireland.
Source: README.md: Outside the current envelope (opens in new tab)