Start

Frequently asked questions

Answers about the four samples for agentic AI on Amazon Bedrock and Amazon Bedrock AgentCore, seeded from the README notices and the open GitHub issues. Each answer links to the repository text it rests on.

Is the workshop published, and where do I run it?

  • Workshop

Yes. The workshop is published on AWS Builder Center (Workshop Studio). Open it there to follow the guide. At an AWS event the account is provided; self-paced, you clone this repository and run one deploy script in your own account. The workshop content is not reproduced on this site.

Source: README.md (opens in new tab)

What does it cost to run these projects?

  • Workshop
  • Self-Service
  • MCP Gateway
  • Blueprint

All four deploy real, billable AWS resources. The workshop estimates about $15 to $30 for a one-day self-paced run in us-west-2. The Self-Service platform infrastructure is estimated at about $0.02 to $0.39 per month at low to moderate usage, excluding agent inference, AgentCore usage, vector stores and the WAF web ACL. The MCP Gateway and the Blueprint publish no cost figure. Tear down when you finish.

Sources: index.en.md: Cost (opens in new tab); COSTS.md: Monthly Cost Estimates (opens in new tab); README.md: Costs (opens in new tab)

Can I run the workshop in eu-central-1 or ap-southeast-1?

  • Workshop

No. The validated regions are us-west-2 (default), us-east-1 and eu-west-1. Elsewhere the Amazon Bedrock AgentCore Registry control plane returns an internal error, which breaks Modules 3b and 4. Model access must also be granted in the region you pick.

Source: self-service.en.md: Region (opens in new tab)

Can I deploy the Self-Service platform outside us-east-1?

  • Self-Service

Yes, any region works by setting AWS_REGION. Two things differ. Outside us-east-1 the WAF rule set is attached as a REGIONAL web ACL on the Cognito user pool, and the CloudFront distribution runs without an edge ACL unless you pass CLOUDFRONT_WEB_ACL_ARN for one created in us-east-1. Account-global names also get a region suffix. In APAC regions, current-generation models use country or global prefixes, so the model ID may need to be set explicitly.

Sources: README.md: Deploying to another region (opens in new tab); README.md: Deploying to another region (opens in new tab)

Why is my new Self-Service user read-only after signing in?

  • Self-Service

COGNITO_USERS pre-creates Cognito users but assigns them to no group, and group membership grants the capability scopes. Add the user to groups such as g-admins-super, t-admin and registry-admin (or g-users-default and t-user) with the AWS CLI, passing the region you deployed to, then sign out and back in so the new scopes are read from the ID token.

Sources: README.md (opens in new tab); README.md (opens in new tab)

Why does the workshop LLM Gateway pull LiteLLM from docker.litellm.ai (issue #2)?

  • Workshop

The LLM Gateway CloudFormation template pins the image docker.litellm.ai/berriai/litellm-database at the tag in the LiteLLMImageTag parameter (default v1.84.0), as recorded in THIRD_PARTY_LICENSES.md. Issue #2, open since 2026-06-30, asks for the image to come from ghcr.io instead. Until it is resolved, the deploy pulls from docker.litellm.ai.

Sources: THIRD_PARTY_LICENSES.md (opens in new tab); workshop-llm-gateway-stack.yaml (opens in new tab)

Does the Blueprint still work after the Agent Registry preview API cutoff (issue #29)?

  • Blueprint

Treat it as unverified. Issue #29, opened 2026-09-15, reports that the Blueprint still provisions and consumes Agent Registry through the preview bedrock-agentcore-control APIs, and AWS support for those APIs ended on 2026-09-17. The README envelope lists AWS Agent Registry record resolution and governance as live-validated, but that validation predates the cutoff. Check the issue before relying on Registry-dependent paths.

Source: README.md: Live-validated reference envelope (opens in new tab)

Are there known dependency findings in the Blueprint (issue #30)?

  • Blueprint

Yes. Issue #30, opened 2026-09-15, reports that the lockfile resolves aws-cdk-lib to 2.251.0 while GHSA-vcrf-j523-4mrf (CVE-2026-13760, high) is fixed in 2.260.0, plus transitive findings. It is a build and deployment toolchain risk rather than evidence of a remotely exploitable deployed workload. Run npm audit and update before deploying.

Source: package-lock.json (opens in new tab)

Is the MCP Governance Gateway production-ready?

  • MCP Gateway

No. The README calls it a sample and demonstration stack that is safe to demo but not hardened for production. It lists what to change first. Tighten the gateway-resource IAM scope for multi-gateway accounts. Use ENFORCE without exceptionLevel in production. Add a Cognito pre-token-generation Lambda so role-based policies fire. Set per-Lambda log retention. Federate the pool to your own IdP.

Source: README.md: Security notes (opens in new tab)

Why do role-based Cedar policies never fire in the MCP Gateway demo?

  • MCP Gateway

Cognito issues two tokens. The gateway validates the access token, which carries sub, username and scope. The custom:role attribute and the email claim live only in the ID token, and the gateway rejects ID tokens because they have no scope claim. So a permit gated on role never matches for demo users; the README documents this as a known limitation and names a pre-token-generation Lambda as the production fix.

Source: README.md (opens in new tab)

Is this an AWS service or a supported product?

No. This is sample code under the MIT-0 license. It is not an AWS service, an AppSec-reviewed product, or a compliance attestation. Review the architecture, security posture and costs before use, and file bugs and feature requests through GitHub issues.

Source: README.md: What This Is (opens in new tab)

How do I report a security issue?

Use the AWS vulnerability reporting page. Do not open a public GitHub issue for a potential security problem. Each project README repeats this instruction.

Source: CONTRIBUTING.md: Security issue notifications (opens in new tab)