SYSTEM Cited by 2 sources
Amazon Bedrock AgentCore¶
What it is¶
Amazon Bedrock AgentCore is a framework-agnostic managed runtime for hosting AI agents in production. It supports agents built with Strands, LangChain, or custom Python, providing compute, session management, security, and observability without requiring infrastructure management.
Key capabilities¶
- MicroVM session isolation — each agent session runs in a dedicated, ephemeral MicroVM environment with no cross-session data leakage.
- Long-running sessions — supports discovery sessions up to 8 hours.
- Built-in observability — traces, logs, and metrics integrate natively with CloudWatch.
- Tool gateway — provides controlled, secure access to AWS APIs during agent execution.
- Stateful working context — maintains tool state and memory across multi-step workflows.
- Framework-agnostic — supports Strands, LangChain, or custom Python agents.
- Scaling — handles scaling automatically without infrastructure provisioning.
Role in resilience framework¶
In the AI-powered resilience framework, AgentCore hosts the custom discovery agent that queries AWS service APIs, analyzes CloudFormation/Terraform templates, and scans code repositories for hard-coded dependencies, connection strings, and timeout configurations. The agent operates with scoped, read-only IAM roles following least-privilege principles (Source: sources/2026-06-22-aws-architecting-ai-powered-resilience-framework-on-aws).
Seen in¶
- sources/2026-06-22-aws-architecting-ai-powered-resilience-framework-on-aws — hosts discovery and test-generation agents in the resilience framework
- sources/2026-08-31-redpanda-corebreak-proves-agent-guardrails-need-to-live-outside-the-a-6ef5e77e — named (with the Strands SDK) as one of the three agent stacks affected by the CoreBreak harness vulnerability disclosed at Black Hat 2026. AWS patched CVE-2026-18830 (CVSS 8.6). Per Redpanda, the harness "had put enforcement where the agent could reach it" — a forged tool call or forged approval injected into the message history executes while the model and its guardrails never fire; the structural fix is out-of-band enforcement.
Related¶
- systems/strands-agents-sdk — the SDK on the patched AWS harness.
- concepts/prompt-injection — the vulnerability class.
- out-of-band-agent-enforcement — the structural fix the CVE patches converged on.
- concepts/least-privileged-access — the scoped read-only IAM role posture AgentCore agents run under.