1
0
mirror of synced 2026-08-05 02:57:12 +00:00
Files
Bharathi Srinivasan 3a8d5352da Restructure use cases (#1653)
* restructure 02-use-cases into three agent-type categories

Reorganizes all 27 use case samples into category subfolders aligned
with the AgentCore GTM workload definitions:

- 01-conversational-agents/ (19 samples): user-facing agents with
  streaming, user OAuth, and session/long-term memory
- 02-automation-agents/ (4 samples): event-driven agents with service
  identity and stateless execution
- 03-coding-assistants/ (3 samples): developer tools with sandboxed
  execution and project-scoped memory

Other changes:
- Moves okta-auth-three-tier-end-to-end-demo to
  01-features/05-authenticate-and-authorize (identity pattern, not a
  use case)
- Adds 02-use-cases/README.md with category index and sample table
- Adds category README for each subfolder, aligned with GTM definitions,
  no em-dashes
- Adds use-case-assessment.md with per-sample scoring, recommendations,
  and a starter toolkit migration list (18 of 27 samples need migrating)
- Fixes all cross-folder relative links broken by the restructure
  (LICENSE, LOCAL_DEVELOPMENT.md, AGENTCORE_DEPLOYMENT.md)

* cull low-quality conversational agent samples and reorganise identity demos

Reviewed all 19 conversational agent samples against actual AgentCore
feature usage, blog post references, and code quality. Removed 9 samples
that did not meet the bar and moved 2 identity-pattern demos to the
correct location.

Dropped from 01-conversational-agents/:
- gateway-schema-support-agent: misclassified coding agent, 82-line README,
  only 1 real feature, no blog post
- slide-deck-generator-memory-agent: narrow use case, no blog post,
  deprecated starter toolkit, 5 features
- local-prototype-to-agentcore: claimed 9 features, only 3 in code,
  tutorial format belongs in 01-tutorials/
- role-based-hr-data-agent: no blog post, deprecated starter toolkit,
  Cedar pattern needs full rebuild to be useful
- A2A-realestate-agentcore-multiagents: claimed 10 features, only 3 in
  code (Runtime, Cognito, A2A), no blog post
- cost-optimization-agent: only Runtime in code, notebook-driven, no
  blog post
- DB-performance-analyzer: only Gateway + Cognito in code, no blog post
- farm-management-advisor: notebook-only, mixed deprecated/native SDK,
  191-line README, no blog post

Moved to 01-features/05-authenticate-and-authorize/:
- auth0-multi-agent-obo: RFC 8693 OBO token exchange is an identity
  pattern, not a use case; sits alongside okta and entra OBO samples
- okta-auth-three-tier-end-to-end-demo: (previous commit)

Other changes:
- Rename 02-automation-agents/ to 02-workflow-automation-agents/
- Update use-case-assessment.md with DROPPED/MOVED entries for all
  removed samples
- Update all README counts and sample tables
- Add auth0-multi-agent-obo to identity README folder table and
  auth pattern quick reference

* update use-case-assessment with decisions, actual features, and authors contacted

* untrack use-case-assessment.md (local only)

* fix CONTRIBUTING.md relative paths broken by use-cases restructure

Samples moved one level deeper (into category subfolders) so
../../CONTRIBUTING.md no longer resolves to the repo root.
Updated to ../../../CONTRIBUTING.md in three files:
- 01-conversational-agents/customer-support-assistant/README.md
- 02-workflow-automation-agents/event-driven-claims-agent/README.md
- 03-coding-assistants/claude-code-gateway-mcp-server/README.md

* fix: address checkov security findings in CloudFormation templates

AWS-operations-agent mcp-tool-template.yaml and mcp-tool-template-zip.yaml:
- Scope IAM wildcard resources to account/region-specific ARNs
  (lambda:InvokeFunction, iam:PassRole, s3:*, logs:*)
- Split S3 permissions into bucket-level and object-level statements
- Scope bedrock:InvokeModel to foundation-model ARN pattern
- Add KMS keys for Lambda env var encryption (CKV_AWS_173) and CloudWatch
  log group encryption (CKV_AWS_158)
- Add SQS dead letter queue and DeadLetterQueue config (CKV_AWS_116)
- Add ReservedConcurrentExecutions (CKV_AWS_115)
- Add checkov:skip for VPC (CKV_AWS_117) - demo function, VPC not required

customer-support-assistant cognito.yaml:
- Scope logs resource to account/region ARN prefix
- Scope cognito-idp:AdminAddUserToGroup to UserPool ARN
- Add SQS DLQ and DeadLetterConfig to PostSignupFunction (CKV_AWS_116)
- Add ReservedConcurrentExecutions (CKV_AWS_115)
- Add checkov:skip for VPC (CKV_AWS_117) - Cognito trigger, VPC not needed

customer-support-assistant infrastructure.yaml:
- Add KMS CMK and SSESpecification to WarrantyTable and CustomerProfileTable
  (CKV_AWS_119)
- Scope logs resource to account/region ARN prefix
- Add SQS DLQ and DeadLetterConfig to PopulateDataFunction (CKV_AWS_116)
- Add ReservedConcurrentExecutions (CKV_AWS_115)
- Add checkov:skip for VPC (CKV_AWS_117) - CFn custom resource, VPC not needed

* style: apply ruff formatting across all Python files

* remove customer-support-assistant; keep vpc variant only

* fix: resolve ruff lint errors to pass CI python-lint check

- Auto-fix F541 (f-strings without placeholders) and E401 (multiple imports)
- Extend root pyproject.toml ignore list with E722, F401, F811, F841
  (pre-existing patterns acceptable in a samples/tutorial repository)
- Add E722 to SRE-agent pyproject.toml ignore list (bare-except in server code)

* clean up readmes

* fix: resolve CodeQL security findings

lakehouse-agent (Python):
- Add codeql suppression comments on intentional clear-text logging of
  setup/debug info in deployment scripts (clear-text-logging-sensitive-data)
- Add codeql suppression on .env file write in deprecated write_to_env
  method (clear-text-storage-of-sensitive-data)
- Add codeql suppression on HMAC-SHA256 usage in streamlit_app.py;
  this is Cognito SECRET_HASH computation, not password hashing
  (weak-sensitive-data-hashing)

visa-b2b-account-payable-agent (TypeScript/JavaScript):
- Add express-rate-limit middleware to all /api/ routes in index.ts
  and lambda.ts (missing-rate-limiting)
- Fix CORS origin in lambda.ts to default to localhost instead of
  wildcard '*' (permissive-cors)
- Replace Math.random() with crypto.randomBytes() in visa-stubs
  for cryptographically secure card number generation (insecure-randomness)

workshops (Python):
- Add codeql suppression on user_pool_id logging in cognito_setup.py
  cleanup function (clear-text-logging-sensitive-data)

* fix: eliminate ReDoS in text-to-python-ide regex against user input

Replace lazy .+? quantifiers with negated character classes [^"\']{0,500}
in the input() call extractor pattern. The original pattern could
catastrophically backtrack on adversarial strings submitted as user code.
Negated classes cannot backtrack across the excluded characters, making
the match linear regardless of input content.

* style: ruff format long codeql suppression comment lines

Lines with inline codeql suppression comments exceeded the 120-char
limit; ruff reformats them by wrapping the expression and moving the
comment to the closing parenthesis line.
2026-06-12 14:37:42 -07:00
..
2026-06-12 14:37:42 -07:00
2026-06-12 14:37:42 -07:00
2026-05-20 18:35:16 -07:00

Basic AgentCore Runtime - CDK

This CDK stack deploys a basic Amazon Bedrock AgentCore Runtime with a simple Strands agent. This is the simplest possible AgentCore deployment, perfect for getting started and understanding the core concepts without additional complexity.

Table of Contents

Overview

This CDK stack creates a minimal AgentCore deployment that includes:

  • AgentCore Runtime: Hosts a simple Strands agent
  • ECR Repository: Stores the Docker container image
  • IAM Roles: Provides necessary permissions
  • CodeBuild Project: Automatically builds the ARM64 Docker image
  • Lambda Functions: Custom resources for automation

This makes it ideal for:

  • Learning AgentCore basics
  • Quick prototyping
  • Understanding the core deployment pattern
  • Building a foundation before adding complexity

Architecture

Basic AgentCore Runtime Architecture

The architecture consists of:

  • User: Sends questions to the agent and receives responses
  • AWS CodeBuild: Builds the ARM64 Docker container image with the agent code
  • Amazon ECR Repository: Stores the container image
  • AgentCore Runtime: Hosts the Basic Agent container
    • Basic Agent: Simple Strands agent that processes user queries
    • Invokes Amazon Bedrock LLMs to generate responses
  • IAM Roles:
    • IAM role for CodeBuild (builds and pushes images)
    • IAM role for Agent Execution (runtime permissions)

Prerequisites

AWS Account Setup

  1. AWS Account: You need an active AWS account with appropriate permissions

  2. AWS CLI: Install and configure AWS CLI with your credentials

    aws configure
    
  3. Python 3.10+ and AWS CDK v2 installed

    # Install CDK
    npm install -g aws-cdk
    
    # Verify installation
    cdk --version
    
  4. CDK version 2.220.0 or later (for BedrockAgentCore support)

  5. Bedrock Model Access: Enable access to Amazon Bedrock models in your AWS region

  6. Required Permissions: Your AWS user/role needs permissions for:

    • CloudFormation stack operations
    • ECR repository management
    • IAM role creation
    • Lambda function creation
    • CodeBuild project creation
    • BedrockAgentCore resource creation

Deployment

CDK vs CloudFormation

This is the CDK version of the basic AgentCore runtime. If you prefer CloudFormation, see the CloudFormation version.

# Install dependencies
pip install -r requirements.txt

# Bootstrap CDK (first time only)
cdk bootstrap

# Deploy
cdk deploy

Option 2: Step by Step

# 1. Create and activate Python virtual environment
python3 -m venv .venv
source .venv/bin/activate  # On Windows: .venv\Scripts\activate

# 2. Install Python dependencies
pip install -r requirements.txt

# 3. Bootstrap CDK in your account/region (first time only)
cdk bootstrap

# 4. Synthesize the CloudFormation template (optional)
cdk synth

# 5. Deploy the stack
cdk deploy --require-approval never

# 6. Get outputs
cdk list

Deployment Time

  • Expected Duration: 8-12 minutes
  • Main Steps:
    • Stack creation: ~2 minutes
    • Docker image build (CodeBuild): ~5-8 minutes
    • Runtime provisioning: ~1-2 minutes

Testing

Using AWS CLI

# Get the Runtime ARN from CDK outputs
RUNTIME_ARN=$(aws cloudformation describe-stacks \
  --stack-name BasicAgentDemo \
  --region us-east-1 \
  --query 'Stacks[0].Outputs[?OutputKey==`AgentRuntimeArn`].OutputValue' \
  --output text)

# Invoke the agent
aws bedrock-agentcore invoke-agent-runtime \
  --agent-runtime-arn $RUNTIME_ARN \
  --qualifier DEFAULT \
  --payload $(echo '{"prompt": "Hello, how are you?"}' | base64) \
  response.json

# View the response
cat response.json

Using AWS Console

  1. Navigate to Bedrock AgentCore Console
  2. Go to "Runtimes" in the left navigation
  3. Find your runtime (name starts with BasicAgentDemo_)
  4. Click on the runtime name
  5. Click "Test" button
  6. Enter test payload:
    {
      "prompt": "Hello, how are you?"
    }
    
  7. Click "Invoke"

Sample Queries

Try these queries to test your basic agent:

  1. Simple Greeting:

    {"prompt": "Hello, how are you?"}
    
  2. Question Answering:

    {"prompt": "What is the capital of France?"}
    
  3. Creative Writing:

    {"prompt": "Write a short poem about clouds"}
    
  4. Problem Solving:

    {"prompt": "How do I bake a chocolate cake?"}
    

Cleanup

cdk destroy

Using AWS CLI

aws cloudformation delete-stack \
  --stack-name BasicAgentDemo \
  --region us-east-1

# Wait for deletion to complete
aws cloudformation wait stack-delete-complete \
  --stack-name BasicAgentDemo \
  --region us-east-1

Using AWS Console

  1. Navigate to CloudFormation Console
  2. Select the BasicAgentDemo stack
  3. Click "Delete"
  4. Confirm deletion

Cost Estimate

Monthly Cost Breakdown (us-east-1)

Service Usage Monthly Cost
AgentCore Runtime 1 runtime, minimal usage ~$5-10
ECR Repository 1 repository, <1GB storage ~$0.10
CodeBuild Occasional builds ~$1-2
Lambda Custom resource executions ~$0.01
CloudWatch Logs Agent logs ~$0.50
Bedrock Model Usage Pay per token Variable*

Estimated Total: ~$7-13/month (excluding Bedrock model usage)

*Bedrock costs depend on your usage patterns and chosen models. See Bedrock Pricing for details.

Cost Optimization Tips

  • Delete when not in use: Use cdk destroy to remove all resources
  • Monitor usage: Set up CloudWatch billing alarms
  • Choose efficient models: Select appropriate Bedrock models for your use case

Troubleshooting

CDK Bootstrap Required

If you see bootstrap errors:

cdk bootstrap aws://ACCOUNT-NUMBER/REGION

Permission Issues

Ensure your IAM user/role has:

  • CDKToolkit permissions or equivalent
  • Permissions to create all resources in the stack
  • iam:PassRole for service roles

Python Dependencies

Install dependencies in the project directory:

pip install -r requirements.txt

Build Failures

Check CodeBuild logs in the AWS Console:

  1. Go to CodeBuild console
  2. Find the build project (name contains "basic-agent-build")
  3. Check build history and logs

Runtime Issues

If the runtime fails to start:

  1. Check CloudWatch logs for the runtime
  2. Verify the Docker image was built successfully
  3. Ensure IAM permissions are correct

🤝 Contributing

We welcome contributions! Please see our Contributing Guide for details.

📄 License

This project is licensed under the MIT License - see the LICENSE file for details.