Start
Prerequisites
What each of the four samples for agentic AI on Amazon Bedrock and Amazon Bedrock AgentCore needs before its first deploy, copied from its README, plus the infrastructure tooling and the regions it was validated in. The four lists differ enough that there is no single shared list.
1. LearnBuilding an Enterprise Agentic AI Platform
- AWS CLI v2
- yq (the deploy script reads contentspec.yaml with it)
- Git and a modern browser
- A dedicated, disposable AWS account with AdministratorAccess or the seven scoped deploy policies under static/cfn (the self-paced getting-started page lists seven files; the README prerequisites section still says four)
- A validated region: us-west-2 (default), us-east-1, or eu-west-1, with Bedrock model access granted there
- Familiarity with IAM, Lambda, CloudFormation, ECS Fargate, API Gateway, Cognito, and CloudWatch
- Familiarity with Amazon Bedrock and how LLMs use tools (function or tool calling)
| Fact | Value | Source |
|---|---|---|
| Infrastructure as code | CloudFormation, run by the self-paced deploy script; Module 4 deploys the FAST agent with the AWS CDK from inside the IDE | README.md: Quick start (self-paced) (opens in new tab) |
| Validated regions | AWS-run events: us-west-2. Self-paced: us-west-2 (default), us-east-1, or eu-west-1. Other regions are not supported. The contentspec.yaml deployableRegions list is us-west-2, us-east-1 and eu-west-1. Workshop Studio events provision the account in us-west-2 (content/introduction/getting-started/aws-event.en.md). | contentspec.yaml (opens in new tab) |
| Default region | us-west-2 | README.md: Quick start (self-paced) (opens in new tab) |
2. BuildAgentCore Visual Workflow Platform
- AWS CLI v2 configured for the target account
- Node.js 20+ (CI runs on 22)
- Python 3.12+
- Any AWS region; us-east-1 is the default and the only region with a CloudFront-scoped WAF
- No Docker required; CDK runs through npx
| Fact | Value | Source |
|---|---|---|
| Infrastructure as code | AWS CDK (Python) run through npx; serverless stack of API Gateway, Lambda, Step Functions, DynamoDB, S3 and CloudFront | README.md: Quickstart (opens in new tab) |
| Validated regions | Any AWS region; us-east-1 is the default Outside us-east-1 the WAF web ACL is REGIONAL on the Cognito user pool and the CloudFront distribution runs without an edge ACL. APAC regions may need the model ID set explicitly. | README.md: Prerequisites (opens in new tab) |
| Default region | us-east-1 | README.md: Quickstart (opens in new tab) |
3. GovernEnterprise MCP Governance Gateway
- Node.js and the AWS CDK CLI pinned to 2.1129.0 (npm install -g aws-cdk@2.1129.0)
- Python 3.12+ with the CDK Python dependencies in a virtualenv
- AWS credentials for the target account; us-west-2 by default
- A running container runtime (Docker, Finch, or Podman) for the optional connector stacks only
| Fact | Value | Source |
|---|---|---|
| Infrastructure as code | AWS CDK (Python) with AWS::BedrockAgentCore L1 constructs; CDK CLI pinned to 2.1129.0 | README.md: Quickstart (opens in new tab) |
| Validated regions | us-west-2 by default; configurable; no tested-regions list is published | README.md (opens in new tab) |
| Default region | us-west-2 | README.md: Deploy (opens in new tab) |
4. ScaleEnterprise Agentic AI Platform Blueprint
- Node.js 20 or later and Python 3.12 or later
- AWS CLI v2 and AWS CDK v2
- An AWS Organizations landing zone with at least Management, Platform, and Workstream account roles
- A GitHub organization, repository strategy, and an AWS CodeConnections connection
- Access to the selected Bedrock model in the target Region (eu-west-1 is the validated reference)
- Administrator access for the initial bootstrap only; pipelines use generated scoped execution policies
| Fact | Value | Source |
|---|---|---|
| Infrastructure as code | AWS CDK (TypeScript) with CDK Pipelines; 12 service control policies; Python and shell utilities | README.md (opens in new tab) |
| Validated regions | Validated in eu-west-1; SCP allow-list us-west-2, us-east-1, eu-west-1 The SCP region allow-list comes from PLATFORM_APPROVED_REGIONS in packages/platform-baselines/src/approved-regions.ts. A different Region is a new validation target, not a configuration-only substitution. | README.md: 5. Prerequisites (opens in new tab) |
| Default region | eu-west-1 | README.md: 6.1 One-time setup (opens in new tab) |