Start
Frequently asked questions
Answers about the four samples for agentic AI on Amazon Bedrock and Amazon Bedrock AgentCore, seeded from the README notices and the open GitHub issues. Each answer links to the repository text it rests on.
Is the workshop published, and where do I run it?
- Workshop
Yes. The workshop is published on AWS Builder Center (Workshop Studio). Open it there to follow the guide. At an AWS event the account is provided; self-paced, you clone this repository and run one deploy script in your own account. The workshop content is not reproduced on this site.
What does it cost to run these projects?
- Workshop
- Self-Service
- MCP Gateway
- Blueprint
All four deploy real, billable AWS resources. The workshop estimates about $15 to $30 for a one-day self-paced run in us-west-2. The Self-Service platform infrastructure is estimated at about $0.02 to $0.39 per month at low to moderate usage, excluding agent inference, AgentCore usage, vector stores and the WAF web ACL. The MCP Gateway and the Blueprint publish no cost figure. Tear down when you finish.
Can I run the workshop in eu-central-1 or ap-southeast-1?
- Workshop
No. The validated regions are us-west-2 (default), us-east-1 and eu-west-1. Elsewhere the Amazon Bedrock AgentCore Registry control plane returns an internal error, which breaks Modules 3b and 4. Model access must also be granted in the region you pick.
Can I deploy the Self-Service platform outside us-east-1?
- Self-Service
Yes, any region works by setting AWS_REGION. Two things differ. Outside us-east-1 the WAF rule set is attached as a REGIONAL web ACL on the Cognito user pool, and the CloudFront distribution runs without an edge ACL unless you pass CLOUDFRONT_WEB_ACL_ARN for one created in us-east-1. Account-global names also get a region suffix. In APAC regions, current-generation models use country or global prefixes, so the model ID may need to be set explicitly.
Why is my new Self-Service user read-only after signing in?
- Self-Service
COGNITO_USERS pre-creates Cognito users but assigns them to no group, and group membership grants the capability scopes. Add the user to groups such as g-admins-super, t-admin and registry-admin (or g-users-default and t-user) with the AWS CLI, passing the region you deployed to, then sign out and back in so the new scopes are read from the ID token.
Why does the workshop LLM Gateway pull LiteLLM from docker.litellm.ai (issue #2)?
- Workshop
The LLM Gateway CloudFormation template pins the image docker.litellm.ai/berriai/litellm-database at the tag in the LiteLLMImageTag parameter (default v1.84.0), as recorded in THIRD_PARTY_LICENSES.md. Issue #2, open since 2026-06-30, asks for the image to come from ghcr.io instead. Until it is resolved, the deploy pulls from docker.litellm.ai.
Does the Blueprint still work after the Agent Registry preview API cutoff (issue #29)?
- Blueprint
Treat it as unverified. Issue #29, opened 2026-09-15, reports that the Blueprint still provisions and consumes Agent Registry through the preview bedrock-agentcore-control APIs, and AWS support for those APIs ended on 2026-09-17. The README envelope lists AWS Agent Registry record resolution and governance as live-validated, but that validation predates the cutoff. Check the issue before relying on Registry-dependent paths.
Are there known dependency findings in the Blueprint (issue #30)?
- Blueprint
Yes. Issue #30, opened 2026-09-15, reports that the lockfile resolves aws-cdk-lib to 2.251.0 while GHSA-vcrf-j523-4mrf (CVE-2026-13760, high) is fixed in 2.260.0, plus transitive findings. It is a build and deployment toolchain risk rather than evidence of a remotely exploitable deployed workload. Run npm audit and update before deploying.
Is the MCP Governance Gateway production-ready?
- MCP Gateway
No. The README calls it a sample and demonstration stack that is safe to demo but not hardened for production. It lists what to change first. Tighten the gateway-resource IAM scope for multi-gateway accounts. Use ENFORCE without exceptionLevel in production. Add a Cognito pre-token-generation Lambda so role-based policies fire. Set per-Lambda log retention. Federate the pool to your own IdP.
Why do role-based Cedar policies never fire in the MCP Gateway demo?
- MCP Gateway
Cognito issues two tokens. The gateway validates the access token, which carries sub, username and scope. The custom:role attribute and the email claim live only in the ID token, and the gateway rejects ID tokens because they have no scope claim. So a permit gated on role never matches for demo users; the README documents this as a known limitation and names a pre-token-generation Lambda as the production fix.
Is this an AWS service or a supported product?
No. This is sample code under the MIT-0 license. It is not an AWS service, an AppSec-reviewed product, or a compliance attestation. Review the architecture, security posture and costs before use, and file bugs and feature requests through GitHub issues.
How do I report a security issue?
Use the AWS vulnerability reporting page. Do not open a public GitHub issue for a potential security problem. Each project README repeats this instruction.