Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions AGENTS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,13 +32,14 @@ These options are available on all commands:

- `create` - Create new AgentCore project
- `add` - Add resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target, policy-engine,
policy, payment-manager, payment-connector)
policy, payment-manager, payment-connector, capacity-provider)
- `remove` - Remove resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target,
policy-engine, policy, payment-manager, payment-connector, all)
policy-engine, policy, payment-manager, payment-connector, capacity-provider, all)
- `deploy` - Deploy infrastructure to AWS
- `status` - Check deployment status
- `dev` - Local development server (CodeZip: uvicorn with hot-reload; Container: Docker build + run with volume mount)
- `invoke` - Invoke agents (local or deployed)
- `capacity-provider delete-session` - Delete (deprovision) a live capacity provider session (data-plane)
- `run eval` - Run on-demand evaluation against agent sessions
- `evals history` - View past eval run results
- `fetch access` - Fetch access info for a deployed gateway or agent
Expand DownExpand Up@@ -90,6 +91,7 @@ Current primitives:
- `PolicyPrimitive` — Cedar policy creation/removal within policy engines
- `PaymentManagerPrimitive` — payment manager creation/removal with agent code wiring
- `PaymentConnectorPrimitive` — payment connector creation/removal with credential management
- `CapacityProviderPrimitive` — capacity provider creation/removal (customer-managed EC2 compute pool for runtimes)

Singletons are created in `registry.ts` and wired into CLI commands via `cli.ts`. See `src/cli/AGENTS.md` for details on
adding new primitives.
Expand Down
12 changes: 6 additions & 6 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -91,10 +91,10 @@ agentcore invoke

### Resource Management

| Command | Description |
| -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, runtime endpoints |
| `remove` | Remove any of the above resources from the project |
| Command | Description |
| -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, capacity providers, runtime endpoints |
| `remove` | Remove any of the above resources from the project |

> **Note**: Run `agentcore deploy` after `add` or `remove` to update resources in AWS.

Expand DownExpand Up@@ -264,8 +264,8 @@ my-project/
Projects use JSON schema files in the `agentcore/` directory:

- `agentcore.json` - Project resources (agents, memory, credentials, gateways, evaluators, online evals/insights,
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, config bundles, datasets,
runtime endpoints)
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, capacity providers, config
bundles, datasets, runtime endpoints)
- `deployed-state.json` - Runtime state in agentcore/.cli/ (auto-managed)
- `aws-targets.json` - Deployment targets (account, region)

Expand Down
85 changes: 85 additions & 0 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -318,6 +318,9 @@ agentcore add agent \
| `--client-secret <secret>` | OAuth client secret |
| `--request-header-allowlist <headers>` | Comma-separated list of inbound header names to forward to the agent. `X-*` names (e.g. `X-Api-Key`, `X-Custom-Signature`) pass through unchanged; bare names without an `X-` prefix are auto-prefixed with the legacy `X-Amzn-Bedrock-AgentCore-Runtime-Custom-` prefix for backward compatibility. |
| `--session-storage-mount-path <path>` | Absolute mount path for session filesystem storage (e.g. `/mnt/session-storage`) |
| `--capacity-provider <name-or-arn>` | Attach the runtime to a capacity provider (customer-managed EC2 compute). Accepts an in-project capacity-provider name or an external CP ARN. Mutually exclusive with `--network-mode VPC`. |
| `--cp-volume-name <name>` | Capacity provider volume name to mount (repeatable, paired by position with `--cp-volume-mount-path`). The name must match a volume defined on the attached capacity provider. |
| `--cp-volume-mount-path <path>` | Capacity provider volume mount path under `/mnt` (e.g. `/mnt/models`, repeatable, paired with `--cp-volume-name`) |
| `--with-config-bundle` | Wire a config bundle into the generated agent template |
| `--idle-timeout <seconds>` | Idle session timeout in seconds |
| `--max-lifetime <seconds>` | Max instance lifetime in seconds |
Expand DownExpand Up@@ -785,6 +788,58 @@ agentcore add config-bundle \
| `--commit-message <text>` | Commit message for this version |
| `--json` | JSON output |

### add capacity-provider

Add a capacity provider — a customer-managed pool of AWS-managed EC2 compute that agent runtimes can run on instead of
the default managed fleet. Everything except the description and tags is immutable after creation.

**Operator role.** AgentCore assumes an IAM _operator role_ to create and manage the EC2 compute on your behalf. Omit
`--operator-role-arn` and the CLI provisions one for you at deploy time — a role that trusts
`bedrock-agentcore.amazonaws.com` (scoped to your account and region) and carries the AWS managed policy
`BedrockAgentCoreRuntimeInstancesOperatorRolePolicy` (EC2/Auto Scaling/fleet management plus the
`agentcore-lifecycle-events-*` EventBridge permissions the service needs). Pass `--operator-role-arn` only when you want
to bring your own role; it must grant those same permissions, or capacity provider creation fails asynchronously
(surfaced by CloudFormation as `NotStabilized`).

```bash
# Minimal — operator role is created automatically
agentcore add capacity-provider \
--name MyCapacityProvider \
--subnets subnet-0123456789abcdef0 \
--security-groups sg-0123456789abcdef0 \
--instance-types c6a.large

# With a named EBS volume, lifecycle limits, and ARM64 (and a bring-your-own operator role)
agentcore add capacity-provider \
--name MyCapacityProvider \
--operator-role-arn arn:aws:iam::123456789012:role/MyOperatorRole \
--subnets subnet-0123456789abcdef0,subnet-0fedcba9876543210 \
--security-groups sg-0123456789abcdef0 \
--os LINUX_ARM64 \
--instance-types c7g.large,c7g.xlarge \
--volume-name data --volume-size 20 --volume-encrypted \
--idle-instance-timeout 3600 \
--max-lifetime 28800
```

| Flag | Description |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `--name <name>` | Capacity provider name (required); immutable after creation |
| `--operator-role-arn <arn>` | IAM role ARN AgentCore assumes to manage the capacity provider (optional — auto-created if omitted); immutable |
| `--description <desc>` | Description (the only mutable field besides tags) |
| `--subnets <subnets>` | Comma-separated subnet IDs, 1–16 (required) |
| `--security-groups <groups>` | Comma-separated security group IDs, 1–16 (required) |
| `--os <os>` | `LINUX_X86_64` (default) or `LINUX_ARM64` |
| `--instance-types <types>` | Comma-separated allowed EC2 instance types, 1–30 (required) |
| `--volume-name <name>` | Named EBS volume name (repeatable, max 5; paired with `--volume-size`) |
| `--volume-size <sizeGiB>` | EBS volume size in GiB (repeatable; paired with `--volume-name`) |
| `--volume-encrypted` | Encrypt EBS volumes |
| `--volume-kms-key <arn>` | KMS key ARN for EBS volume encryption |
| `--instance-profile-arn <arn>` | IAM instance profile ARN for launched instances |
| `--idle-instance-timeout <secs>` | Idle instance timeout in seconds (60–1209600) |
| `--max-lifetime <secs>` | Maximum instance lifetime in seconds (60–1209600) |
| `--json` | JSON output |

### remove

Remove resources from project.
Expand All@@ -804,6 +859,7 @@ agentcore remove dataset --name MyDataset
agentcore remove config-bundle --name MyBundle
agentcore remove payment-manager --name MyManager -y
agentcore remove payment-connector --name MyCDPConnector --manager MyManager -y
agentcore remove capacity-provider --name MyCapacityProvider -y

# Reset everything
agentcore remove all -y
Expand DownExpand Up@@ -853,6 +909,35 @@ agentcore dev call-tool --tool myTool --input '{"arg": "value"}'
| `-b, --no-browser` | Use terminal TUI instead of web-based chat UI |
| `--no-traces` | Disable local OTEL trace collection |

### capacity-provider delete-session

Delete (deprovision) a single live capacity provider session. This is a data-plane operation: it terminates the
session's EC2 instance and **permanently deletes any persistent EBS volumes** attached to the session (data loss). The
operation is asynchronous — it returns immediately with status `Deprovisioning`. You get the session id from `invoke`
(it echoes the session it used); there is no list-sessions API.

```bash
# By in-project capacity provider name (resolved to its id from deployed state)
agentcore capacity-provider delete-session --capacity-provider my-pool --session-id <sessionId>

# By capacity provider id, without a project (the data-plane API is keyed on the id)
agentcore capacity-provider delete-session \
--capacity-provider my-pool-a1b2c3d4e5 --session-id <sessionId> --region us-west-2 --yes

# By ARN (the id is extracted from it), without a project (region auto-detected from the ARN)
agentcore capacity-provider delete-session \
--capacity-provider arn:aws:bedrock-agentcore:us-west-2:123456789012:capacity-provider/my-pool-a1b2c3d4e5 \
--session-id <sessionId> --yes
```

| Option | Description |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--capacity-provider <name-id-or-arn>` | Capacity provider: an in-project name (resolved to its id via deployed state), a capacity provider id, or an ARN (id extracted from it). The API is keyed on the id. (**required**) |
| `--session-id <id>` | Session id to delete (**required**) |
| `--region <region>` | AWS region (auto-detected from the ARN / project otherwise; required with a bare id outside a project unless the environment sets one) |
| `--yes` | Skip the destructive confirmation prompt (required for non-interactive use) |
| `--json` | JSON output |

### invoke

Invoke a deployed agent endpoint.
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions AGENTS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,13 +32,14 @@ These options are available on all commands:

- `create` - Create new AgentCore project
- `add` - Add resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target, policy-engine,
policy, payment-manager, payment-connector)
policy, payment-manager, payment-connector, capacity-provider)
- `remove` - Remove resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target,
policy-engine, policy, payment-manager, payment-connector, all)
policy-engine, policy, payment-manager, payment-connector, capacity-provider, all)
- `deploy` - Deploy infrastructure to AWS
- `status` - Check deployment status
- `dev` - Local development server (CodeZip: uvicorn with hot-reload; Container: Docker build + run with volume mount)
- `invoke` - Invoke agents (local or deployed)
- `capacity-provider delete-session` - Delete (deprovision) a live capacity provider session (data-plane)
- `run eval` - Run on-demand evaluation against agent sessions
- `evals history` - View past eval run results
- `fetch access` - Fetch access info for a deployed gateway or agent
Expand DownExpand Up@@ -90,6 +91,7 @@ Current primitives:
- `PolicyPrimitive` — Cedar policy creation/removal within policy engines
- `PaymentManagerPrimitive` — payment manager creation/removal with agent code wiring
- `PaymentConnectorPrimitive` — payment connector creation/removal with credential management
- `CapacityProviderPrimitive` — capacity provider creation/removal (customer-managed EC2 compute pool for runtimes)

Singletons are created in `registry.ts` and wired into CLI commands via `cli.ts`. See `src/cli/AGENTS.md` for details on
adding new primitives.
Expand Down
12 changes: 6 additions & 6 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -91,10 +91,10 @@ agentcore invoke

### Resource Management

| Command | Description |
| -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, runtime endpoints |
| `remove` | Remove any of the above resources from the project |
| Command | Description |
| -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, capacity providers, runtime endpoints |
| `remove` | Remove any of the above resources from the project |

> **Note**: Run `agentcore deploy` after `add` or `remove` to update resources in AWS.

Expand DownExpand Up@@ -264,8 +264,8 @@ my-project/
Projects use JSON schema files in the `agentcore/` directory:

- `agentcore.json` - Project resources (agents, memory, credentials, gateways, evaluators, online evals/insights,
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, config bundles, datasets,
runtime endpoints)
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, capacity providers, config
bundles, datasets, runtime endpoints)
- `deployed-state.json` - Runtime state in agentcore/.cli/ (auto-managed)
- `aws-targets.json` - Deployment targets (account, region)

Expand Down
85 changes: 85 additions & 0 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -318,6 +318,9 @@ agentcore add agent \
| `--client-secret <secret>` | OAuth client secret |
| `--request-header-allowlist <headers>` | Comma-separated list of inbound header names to forward to the agent. `X-*` names (e.g. `X-Api-Key`, `X-Custom-Signature`) pass through unchanged; bare names without an `X-` prefix are auto-prefixed with the legacy `X-Amzn-Bedrock-AgentCore-Runtime-Custom-` prefix for backward compatibility. |
| `--session-storage-mount-path <path>` | Absolute mount path for session filesystem storage (e.g. `/mnt/session-storage`) |
| `--capacity-provider <name-or-arn>` | Attach the runtime to a capacity provider (customer-managed EC2 compute). Accepts an in-project capacity-provider name or an external CP ARN. Mutually exclusive with `--network-mode VPC`. |
| `--cp-volume-name <name>` | Capacity provider volume name to mount (repeatable, paired by position with `--cp-volume-mount-path`). The name must match a volume defined on the attached capacity provider. |
| `--cp-volume-mount-path <path>` | Capacity provider volume mount path under `/mnt` (e.g. `/mnt/models`, repeatable, paired with `--cp-volume-name`) |
| `--with-config-bundle` | Wire a config bundle into the generated agent template |
| `--idle-timeout <seconds>` | Idle session timeout in seconds |
| `--max-lifetime <seconds>` | Max instance lifetime in seconds |
Expand DownExpand Up@@ -785,6 +788,58 @@ agentcore add config-bundle \
| `--commit-message <text>` | Commit message for this version |
| `--json` | JSON output |

### add capacity-provider

Add a capacity provider — a customer-managed pool of AWS-managed EC2 compute that agent runtimes can run on instead of
the default managed fleet. Everything except the description and tags is immutable after creation.

**Operator role.** AgentCore assumes an IAM _operator role_ to create and manage the EC2 compute on your behalf. Omit
`--operator-role-arn` and the CLI provisions one for you at deploy time — a role that trusts
`bedrock-agentcore.amazonaws.com` (scoped to your account and region) and carries the AWS managed policy
`BedrockAgentCoreRuntimeInstancesOperatorRolePolicy` (EC2/Auto Scaling/fleet management plus the
`agentcore-lifecycle-events-*` EventBridge permissions the service needs). Pass `--operator-role-arn` only when you want
to bring your own role; it must grant those same permissions, or capacity provider creation fails asynchronously
(surfaced by CloudFormation as `NotStabilized`).

```bash
# Minimal — operator role is created automatically
agentcore add capacity-provider \
--name MyCapacityProvider \
--subnets subnet-0123456789abcdef0 \
--security-groups sg-0123456789abcdef0 \
--instance-types c6a.large

# With a named EBS volume, lifecycle limits, and ARM64 (and a bring-your-own operator role)
agentcore add capacity-provider \
--name MyCapacityProvider \
--operator-role-arn arn:aws:iam::123456789012:role/MyOperatorRole \
--subnets subnet-0123456789abcdef0,subnet-0fedcba9876543210 \
--security-groups sg-0123456789abcdef0 \
--os LINUX_ARM64 \
--instance-types c7g.large,c7g.xlarge \
--volume-name data --volume-size 20 --volume-encrypted \
--idle-instance-timeout 3600 \
--max-lifetime 28800
```

| Flag | Description |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `--name <name>` | Capacity provider name (required); immutable after creation |
| `--operator-role-arn <arn>` | IAM role ARN AgentCore assumes to manage the capacity provider (optional — auto-created if omitted); immutable |
| `--description <desc>` | Description (the only mutable field besides tags) |
| `--subnets <subnets>` | Comma-separated subnet IDs, 1–16 (required) |
| `--security-groups <groups>` | Comma-separated security group IDs, 1–16 (required) |
| `--os <os>` | `LINUX_X86_64` (default) or `LINUX_ARM64` |
| `--instance-types <types>` | Comma-separated allowed EC2 instance types, 1–30 (required) |
| `--volume-name <name>` | Named EBS volume name (repeatable, max 5; paired with `--volume-size`) |
| `--volume-size <sizeGiB>` | EBS volume size in GiB (repeatable; paired with `--volume-name`) |
| `--volume-encrypted` | Encrypt EBS volumes |
| `--volume-kms-key <arn>` | KMS key ARN for EBS volume encryption |
| `--instance-profile-arn <arn>` | IAM instance profile ARN for launched instances |
| `--idle-instance-timeout <secs>` | Idle instance timeout in seconds (60–1209600) |
| `--max-lifetime <secs>` | Maximum instance lifetime in seconds (60–1209600) |
| `--json` | JSON output |

### remove

Remove resources from project.
Expand All@@ -804,6 +859,7 @@ agentcore remove dataset --name MyDataset
agentcore remove config-bundle --name MyBundle
agentcore remove payment-manager --name MyManager -y
agentcore remove payment-connector --name MyCDPConnector --manager MyManager -y
agentcore remove capacity-provider --name MyCapacityProvider -y

# Reset everything
agentcore remove all -y
Expand DownExpand Up@@ -853,6 +909,35 @@ agentcore dev call-tool --tool myTool --input '{"arg": "value"}'
| `-b, --no-browser` | Use terminal TUI instead of web-based chat UI |
| `--no-traces` | Disable local OTEL trace collection |

### capacity-provider delete-session

Delete (deprovision) a single live capacity provider session. This is a data-plane operation: it terminates the
session's EC2 instance and **permanently deletes any persistent EBS volumes** attached to the session (data loss). The
operation is asynchronous — it returns immediately with status `Deprovisioning`. You get the session id from `invoke`
(it echoes the session it used); there is no list-sessions API.

```bash
# By in-project capacity provider name (resolved to its id from deployed state)
agentcore capacity-provider delete-session --capacity-provider my-pool --session-id <sessionId>

# By capacity provider id, without a project (the data-plane API is keyed on the id)
agentcore capacity-provider delete-session \
--capacity-provider my-pool-a1b2c3d4e5 --session-id <sessionId> --region us-west-2 --yes

# By ARN (the id is extracted from it), without a project (region auto-detected from the ARN)
agentcore capacity-provider delete-session \
--capacity-provider arn:aws:bedrock-agentcore:us-west-2:123456789012:capacity-provider/my-pool-a1b2c3d4e5 \
--session-id <sessionId> --yes
```

| Option | Description |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--capacity-provider <name-id-or-arn>` | Capacity provider: an in-project name (resolved to its id via deployed state), a capacity provider id, or an ARN (id extracted from it). The API is keyed on the id. (**required**) |
| `--session-id <id>` | Session id to delete (**required**) |
| `--region <region>` | AWS region (auto-detected from the ARN / project otherwise; required with a bare id outside a project unless the environment sets one) |
| `--yes` | Skip the destructive confirmation prompt (required for non-interactive use) |
| `--json` | JSON output |

### invoke

Invoke a deployed agent endpoint.
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions AGENTS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,13 +32,14 @@ These options are available on all commands:

- `create` - Create new AgentCore project
- `add` - Add resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target, policy-engine,
policy, payment-manager, payment-connector)
policy, payment-manager, payment-connector, capacity-provider)
- `remove` - Remove resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target,
policy-engine, policy, payment-manager, payment-connector, all)
policy-engine, policy, payment-manager, payment-connector, capacity-provider, all)
- `deploy` - Deploy infrastructure to AWS
- `status` - Check deployment status
- `dev` - Local development server (CodeZip: uvicorn with hot-reload; Container: Docker build + run with volume mount)
- `invoke` - Invoke agents (local or deployed)
- `capacity-provider delete-session` - Delete (deprovision) a live capacity provider session (data-plane)
- `run eval` - Run on-demand evaluation against agent sessions
- `evals history` - View past eval run results
- `fetch access` - Fetch access info for a deployed gateway or agent
Expand DownExpand Up@@ -90,6 +91,7 @@ Current primitives:
- `PolicyPrimitive` — Cedar policy creation/removal within policy engines
- `PaymentManagerPrimitive` — payment manager creation/removal with agent code wiring
- `PaymentConnectorPrimitive` — payment connector creation/removal with credential management
- `CapacityProviderPrimitive` — capacity provider creation/removal (customer-managed EC2 compute pool for runtimes)

Singletons are created in `registry.ts` and wired into CLI commands via `cli.ts`. See `src/cli/AGENTS.md` for details on
adding new primitives.
Expand Down
12 changes: 6 additions & 6 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -91,10 +91,10 @@ agentcore invoke

### Resource Management

| Command | Description |
| -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, runtime endpoints |
| `remove` | Remove any of the above resources from the project |
| Command | Description |
| -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, capacity providers, runtime endpoints |
| `remove` | Remove any of the above resources from the project |

> **Note**: Run `agentcore deploy` after `add` or `remove` to update resources in AWS.

Expand DownExpand Up@@ -264,8 +264,8 @@ my-project/
Projects use JSON schema files in the `agentcore/` directory:

- `agentcore.json` - Project resources (agents, memory, credentials, gateways, evaluators, online evals/insights,
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, config bundles, datasets,
runtime endpoints)
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, capacity providers, config
bundles, datasets, runtime endpoints)
- `deployed-state.json` - Runtime state in agentcore/.cli/ (auto-managed)
- `aws-targets.json` - Deployment targets (account, region)

Expand Down
85 changes: 85 additions & 0 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -318,6 +318,9 @@ agentcore add agent \
| `--client-secret <secret>` | OAuth client secret |
| `--request-header-allowlist <headers>` | Comma-separated list of inbound header names to forward to the agent. `X-*` names (e.g. `X-Api-Key`, `X-Custom-Signature`) pass through unchanged; bare names without an `X-` prefix are auto-prefixed with the legacy `X-Amzn-Bedrock-AgentCore-Runtime-Custom-` prefix for backward compatibility. |
| `--session-storage-mount-path <path>` | Absolute mount path for session filesystem storage (e.g. `/mnt/session-storage`) |
| `--capacity-provider <name-or-arn>` | Attach the runtime to a capacity provider (customer-managed EC2 compute). Accepts an in-project capacity-provider name or an external CP ARN. Mutually exclusive with `--network-mode VPC`. |
| `--cp-volume-name <name>` | Capacity provider volume name to mount (repeatable, paired by position with `--cp-volume-mount-path`). The name must match a volume defined on the attached capacity provider. |
| `--cp-volume-mount-path <path>` | Capacity provider volume mount path under `/mnt` (e.g. `/mnt/models`, repeatable, paired with `--cp-volume-name`) |
| `--with-config-bundle` | Wire a config bundle into the generated agent template |
| `--idle-timeout <seconds>` | Idle session timeout in seconds |
| `--max-lifetime <seconds>` | Max instance lifetime in seconds |
Expand DownExpand Up@@ -785,6 +788,58 @@ agentcore add config-bundle \
| `--commit-message <text>` | Commit message for this version |
| `--json` | JSON output |

### add capacity-provider

Add a capacity provider — a customer-managed pool of AWS-managed EC2 compute that agent runtimes can run on instead of
the default managed fleet. Everything except the description and tags is immutable after creation.

**Operator role.** AgentCore assumes an IAM _operator role_ to create and manage the EC2 compute on your behalf. Omit
`--operator-role-arn` and the CLI provisions one for you at deploy time — a role that trusts
`bedrock-agentcore.amazonaws.com` (scoped to your account and region) and carries the AWS managed policy
`BedrockAgentCoreRuntimeInstancesOperatorRolePolicy` (EC2/Auto Scaling/fleet management plus the
`agentcore-lifecycle-events-*` EventBridge permissions the service needs). Pass `--operator-role-arn` only when you want
to bring your own role; it must grant those same permissions, or capacity provider creation fails asynchronously
(surfaced by CloudFormation as `NotStabilized`).

```bash
# Minimal — operator role is created automatically
agentcore add capacity-provider \
--name MyCapacityProvider \
--subnets subnet-0123456789abcdef0 \
--security-groups sg-0123456789abcdef0 \
--instance-types c6a.large

# With a named EBS volume, lifecycle limits, and ARM64 (and a bring-your-own operator role)
agentcore add capacity-provider \
--name MyCapacityProvider \
--operator-role-arn arn:aws:iam::123456789012:role/MyOperatorRole \
--subnets subnet-0123456789abcdef0,subnet-0fedcba9876543210 \
--security-groups sg-0123456789abcdef0 \
--os LINUX_ARM64 \
--instance-types c7g.large,c7g.xlarge \
--volume-name data --volume-size 20 --volume-encrypted \
--idle-instance-timeout 3600 \
--max-lifetime 28800
```

| Flag | Description |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `--name <name>` | Capacity provider name (required); immutable after creation |
| `--operator-role-arn <arn>` | IAM role ARN AgentCore assumes to manage the capacity provider (optional — auto-created if omitted); immutable |
| `--description <desc>` | Description (the only mutable field besides tags) |
| `--subnets <subnets>` | Comma-separated subnet IDs, 1–16 (required) |
| `--security-groups <groups>` | Comma-separated security group IDs, 1–16 (required) |
| `--os <os>` | `LINUX_X86_64` (default) or `LINUX_ARM64` |
| `--instance-types <types>` | Comma-separated allowed EC2 instance types, 1–30 (required) |
| `--volume-name <name>` | Named EBS volume name (repeatable, max 5; paired with `--volume-size`) |
| `--volume-size <sizeGiB>` | EBS volume size in GiB (repeatable; paired with `--volume-name`) |
| `--volume-encrypted` | Encrypt EBS volumes |
| `--volume-kms-key <arn>` | KMS key ARN for EBS volume encryption |
| `--instance-profile-arn <arn>` | IAM instance profile ARN for launched instances |
| `--idle-instance-timeout <secs>` | Idle instance timeout in seconds (60–1209600) |
| `--max-lifetime <secs>` | Maximum instance lifetime in seconds (60–1209600) |
| `--json` | JSON output |

### remove

Remove resources from project.
Expand All@@ -804,6 +859,7 @@ agentcore remove dataset --name MyDataset
agentcore remove config-bundle --name MyBundle
agentcore remove payment-manager --name MyManager -y
agentcore remove payment-connector --name MyCDPConnector --manager MyManager -y
agentcore remove capacity-provider --name MyCapacityProvider -y

# Reset everything
agentcore remove all -y
Expand DownExpand Up@@ -853,6 +909,35 @@ agentcore dev call-tool --tool myTool --input '{"arg": "value"}'
| `-b, --no-browser` | Use terminal TUI instead of web-based chat UI |
| `--no-traces` | Disable local OTEL trace collection |

### capacity-provider delete-session

Delete (deprovision) a single live capacity provider session. This is a data-plane operation: it terminates the
session's EC2 instance and **permanently deletes any persistent EBS volumes** attached to the session (data loss). The
operation is asynchronous — it returns immediately with status `Deprovisioning`. You get the session id from `invoke`
(it echoes the session it used); there is no list-sessions API.

```bash
# By in-project capacity provider name (resolved to its id from deployed state)
agentcore capacity-provider delete-session --capacity-provider my-pool --session-id <sessionId>

# By capacity provider id, without a project (the data-plane API is keyed on the id)
agentcore capacity-provider delete-session \
--capacity-provider my-pool-a1b2c3d4e5 --session-id <sessionId> --region us-west-2 --yes

# By ARN (the id is extracted from it), without a project (region auto-detected from the ARN)
agentcore capacity-provider delete-session \
--capacity-provider arn:aws:bedrock-agentcore:us-west-2:123456789012:capacity-provider/my-pool-a1b2c3d4e5 \
--session-id <sessionId> --yes
```

| Option | Description |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--capacity-provider <name-id-or-arn>` | Capacity provider: an in-project name (resolved to its id via deployed state), a capacity provider id, or an ARN (id extracted from it). The API is keyed on the id. (**required**) |
| `--session-id <id>` | Session id to delete (**required**) |
| `--region <region>` | AWS region (auto-detected from the ARN / project otherwise; required with a bare id outside a project unless the environment sets one) |
| `--yes` | Skip the destructive confirmation prompt (required for non-interactive use) |
| `--json` | JSON output |

### invoke

Invoke a deployed agent endpoint.
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions AGENTS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,13 +32,14 @@ These options are available on all commands:

- `create` - Create new AgentCore project
- `add` - Add resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target, policy-engine,
policy, payment-manager, payment-connector)
policy, payment-manager, payment-connector, capacity-provider)
- `remove` - Remove resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target,
policy-engine, policy, payment-manager, payment-connector, all)
policy-engine, policy, payment-manager, payment-connector, capacity-provider, all)
- `deploy` - Deploy infrastructure to AWS
- `status` - Check deployment status
- `dev` - Local development server (CodeZip: uvicorn with hot-reload; Container: Docker build + run with volume mount)
- `invoke` - Invoke agents (local or deployed)
- `capacity-provider delete-session` - Delete (deprovision) a live capacity provider session (data-plane)
- `run eval` - Run on-demand evaluation against agent sessions
- `evals history` - View past eval run results
- `fetch access` - Fetch access info for a deployed gateway or agent
Expand DownExpand Up@@ -90,6 +91,7 @@ Current primitives:
- `PolicyPrimitive` — Cedar policy creation/removal within policy engines
- `PaymentManagerPrimitive` — payment manager creation/removal with agent code wiring
- `PaymentConnectorPrimitive` — payment connector creation/removal with credential management
- `CapacityProviderPrimitive` — capacity provider creation/removal (customer-managed EC2 compute pool for runtimes)

Singletons are created in `registry.ts` and wired into CLI commands via `cli.ts`. See `src/cli/AGENTS.md` for details on
adding new primitives.
Expand Down
12 changes: 6 additions & 6 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -91,10 +91,10 @@ agentcore invoke

### Resource Management

| Command | Description |
| -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, runtime endpoints |
| `remove` | Remove any of the above resources from the project |
| Command | Description |
| -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, capacity providers, runtime endpoints |
| `remove` | Remove any of the above resources from the project |

> **Note**: Run `agentcore deploy` after `add` or `remove` to update resources in AWS.

Expand DownExpand Up@@ -264,8 +264,8 @@ my-project/
Projects use JSON schema files in the `agentcore/` directory:

- `agentcore.json` - Project resources (agents, memory, credentials, gateways, evaluators, online evals/insights,
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, config bundles, datasets,
runtime endpoints)
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, capacity providers, config
bundles, datasets, runtime endpoints)
- `deployed-state.json` - Runtime state in agentcore/.cli/ (auto-managed)
- `aws-targets.json` - Deployment targets (account, region)

Expand Down
85 changes: 85 additions & 0 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -318,6 +318,9 @@ agentcore add agent \
| `--client-secret <secret>` | OAuth client secret |
| `--request-header-allowlist <headers>` | Comma-separated list of inbound header names to forward to the agent. `X-*` names (e.g. `X-Api-Key`, `X-Custom-Signature`) pass through unchanged; bare names without an `X-` prefix are auto-prefixed with the legacy `X-Amzn-Bedrock-AgentCore-Runtime-Custom-` prefix for backward compatibility. |
| `--session-storage-mount-path <path>` | Absolute mount path for session filesystem storage (e.g. `/mnt/session-storage`) |
| `--capacity-provider <name-or-arn>` | Attach the runtime to a capacity provider (customer-managed EC2 compute). Accepts an in-project capacity-provider name or an external CP ARN. Mutually exclusive with `--network-mode VPC`. |
| `--cp-volume-name <name>` | Capacity provider volume name to mount (repeatable, paired by position with `--cp-volume-mount-path`). The name must match a volume defined on the attached capacity provider. |
| `--cp-volume-mount-path <path>` | Capacity provider volume mount path under `/mnt` (e.g. `/mnt/models`, repeatable, paired with `--cp-volume-name`) |
| `--with-config-bundle` | Wire a config bundle into the generated agent template |
| `--idle-timeout <seconds>` | Idle session timeout in seconds |
| `--max-lifetime <seconds>` | Max instance lifetime in seconds |
Expand DownExpand Up@@ -785,6 +788,58 @@ agentcore add config-bundle \
| `--commit-message <text>` | Commit message for this version |
| `--json` | JSON output |

### add capacity-provider

Add a capacity provider — a customer-managed pool of AWS-managed EC2 compute that agent runtimes can run on instead of
the default managed fleet. Everything except the description and tags is immutable after creation.

**Operator role.** AgentCore assumes an IAM _operator role_ to create and manage the EC2 compute on your behalf. Omit
`--operator-role-arn` and the CLI provisions one for you at deploy time — a role that trusts
`bedrock-agentcore.amazonaws.com` (scoped to your account and region) and carries the AWS managed policy
`BedrockAgentCoreRuntimeInstancesOperatorRolePolicy` (EC2/Auto Scaling/fleet management plus the
`agentcore-lifecycle-events-*` EventBridge permissions the service needs). Pass `--operator-role-arn` only when you want
to bring your own role; it must grant those same permissions, or capacity provider creation fails asynchronously
(surfaced by CloudFormation as `NotStabilized`).

```bash
# Minimal — operator role is created automatically
agentcore add capacity-provider \
--name MyCapacityProvider \
--subnets subnet-0123456789abcdef0 \
--security-groups sg-0123456789abcdef0 \
--instance-types c6a.large

# With a named EBS volume, lifecycle limits, and ARM64 (and a bring-your-own operator role)
agentcore add capacity-provider \
--name MyCapacityProvider \
--operator-role-arn arn:aws:iam::123456789012:role/MyOperatorRole \
--subnets subnet-0123456789abcdef0,subnet-0fedcba9876543210 \
--security-groups sg-0123456789abcdef0 \
--os LINUX_ARM64 \
--instance-types c7g.large,c7g.xlarge \
--volume-name data --volume-size 20 --volume-encrypted \
--idle-instance-timeout 3600 \
--max-lifetime 28800
```

| Flag | Description |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `--name <name>` | Capacity provider name (required); immutable after creation |
| `--operator-role-arn <arn>` | IAM role ARN AgentCore assumes to manage the capacity provider (optional — auto-created if omitted); immutable |
| `--description <desc>` | Description (the only mutable field besides tags) |
| `--subnets <subnets>` | Comma-separated subnet IDs, 1–16 (required) |
| `--security-groups <groups>` | Comma-separated security group IDs, 1–16 (required) |
| `--os <os>` | `LINUX_X86_64` (default) or `LINUX_ARM64` |
| `--instance-types <types>` | Comma-separated allowed EC2 instance types, 1–30 (required) |
| `--volume-name <name>` | Named EBS volume name (repeatable, max 5; paired with `--volume-size`) |
| `--volume-size <sizeGiB>` | EBS volume size in GiB (repeatable; paired with `--volume-name`) |
| `--volume-encrypted` | Encrypt EBS volumes |
| `--volume-kms-key <arn>` | KMS key ARN for EBS volume encryption |
| `--instance-profile-arn <arn>` | IAM instance profile ARN for launched instances |
| `--idle-instance-timeout <secs>` | Idle instance timeout in seconds (60–1209600) |
| `--max-lifetime <secs>` | Maximum instance lifetime in seconds (60–1209600) |
| `--json` | JSON output |

### remove

Remove resources from project.
Expand All@@ -804,6 +859,7 @@ agentcore remove dataset --name MyDataset
agentcore remove config-bundle --name MyBundle
agentcore remove payment-manager --name MyManager -y
agentcore remove payment-connector --name MyCDPConnector --manager MyManager -y
agentcore remove capacity-provider --name MyCapacityProvider -y

# Reset everything
agentcore remove all -y
Expand DownExpand Up@@ -853,6 +909,35 @@ agentcore dev call-tool --tool myTool --input '{"arg": "value"}'
| `-b, --no-browser` | Use terminal TUI instead of web-based chat UI |
| `--no-traces` | Disable local OTEL trace collection |

### capacity-provider delete-session

Delete (deprovision) a single live capacity provider session. This is a data-plane operation: it terminates the
session's EC2 instance and **permanently deletes any persistent EBS volumes** attached to the session (data loss). The
operation is asynchronous — it returns immediately with status `Deprovisioning`. You get the session id from `invoke`
(it echoes the session it used); there is no list-sessions API.

```bash
# By in-project capacity provider name (resolved to its id from deployed state)
agentcore capacity-provider delete-session --capacity-provider my-pool --session-id <sessionId>

# By capacity provider id, without a project (the data-plane API is keyed on the id)
agentcore capacity-provider delete-session \
--capacity-provider my-pool-a1b2c3d4e5 --session-id <sessionId> --region us-west-2 --yes

# By ARN (the id is extracted from it), without a project (region auto-detected from the ARN)
agentcore capacity-provider delete-session \
--capacity-provider arn:aws:bedrock-agentcore:us-west-2:123456789012:capacity-provider/my-pool-a1b2c3d4e5 \
--session-id <sessionId> --yes
```

| Option | Description |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--capacity-provider <name-id-or-arn>` | Capacity provider: an in-project name (resolved to its id via deployed state), a capacity provider id, or an ARN (id extracted from it). The API is keyed on the id. (**required**) |
| `--session-id <id>` | Session id to delete (**required**) |
| `--region <region>` | AWS region (auto-detected from the ARN / project otherwise; required with a bare id outside a project unless the environment sets one) |
| `--yes` | Skip the destructive confirmation prompt (required for non-interactive use) |
| `--json` | JSON output |

### invoke

Invoke a deployed agent endpoint.
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions AGENTS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,13 +32,14 @@ These options are available on all commands:

- `create` - Create new AgentCore project
- `add` - Add resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target, policy-engine,
policy, payment-manager, payment-connector)
policy, payment-manager, payment-connector, capacity-provider)
- `remove` - Remove resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target,
policy-engine, policy, payment-manager, payment-connector, all)
policy-engine, policy, payment-manager, payment-connector, capacity-provider, all)
- `deploy` - Deploy infrastructure to AWS
- `status` - Check deployment status
- `dev` - Local development server (CodeZip: uvicorn with hot-reload; Container: Docker build + run with volume mount)
- `invoke` - Invoke agents (local or deployed)
- `capacity-provider delete-session` - Delete (deprovision) a live capacity provider session (data-plane)
- `run eval` - Run on-demand evaluation against agent sessions
- `evals history` - View past eval run results
- `fetch access` - Fetch access info for a deployed gateway or agent
Expand DownExpand Up@@ -90,6 +91,7 @@ Current primitives:
- `PolicyPrimitive` — Cedar policy creation/removal within policy engines
- `PaymentManagerPrimitive` — payment manager creation/removal with agent code wiring
- `PaymentConnectorPrimitive` — payment connector creation/removal with credential management
- `CapacityProviderPrimitive` — capacity provider creation/removal (customer-managed EC2 compute pool for runtimes)

Singletons are created in `registry.ts` and wired into CLI commands via `cli.ts`. See `src/cli/AGENTS.md` for details on
adding new primitives.
Expand Down
12 changes: 6 additions & 6 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -91,10 +91,10 @@ agentcore invoke

### Resource Management

| Command | Description |
| -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, runtime endpoints |
| `remove` | Remove any of the above resources from the project |
| Command | Description |
| -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, capacity providers, runtime endpoints |
| `remove` | Remove any of the above resources from the project |

> **Note**: Run `agentcore deploy` after `add` or `remove` to update resources in AWS.

Expand DownExpand Up@@ -264,8 +264,8 @@ my-project/
Projects use JSON schema files in the `agentcore/` directory:

- `agentcore.json` - Project resources (agents, memory, credentials, gateways, evaluators, online evals/insights,
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, config bundles, datasets,
runtime endpoints)
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, capacity providers, config
bundles, datasets, runtime endpoints)
- `deployed-state.json` - Runtime state in agentcore/.cli/ (auto-managed)
- `aws-targets.json` - Deployment targets (account, region)

Expand Down
85 changes: 85 additions & 0 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -318,6 +318,9 @@ agentcore add agent \
| `--client-secret <secret>` | OAuth client secret |
| `--request-header-allowlist <headers>` | Comma-separated list of inbound header names to forward to the agent. `X-*` names (e.g. `X-Api-Key`, `X-Custom-Signature`) pass through unchanged; bare names without an `X-` prefix are auto-prefixed with the legacy `X-Amzn-Bedrock-AgentCore-Runtime-Custom-` prefix for backward compatibility. |
| `--session-storage-mount-path <path>` | Absolute mount path for session filesystem storage (e.g. `/mnt/session-storage`) |
| `--capacity-provider <name-or-arn>` | Attach the runtime to a capacity provider (customer-managed EC2 compute). Accepts an in-project capacity-provider name or an external CP ARN. Mutually exclusive with `--network-mode VPC`. |
| `--cp-volume-name <name>` | Capacity provider volume name to mount (repeatable, paired by position with `--cp-volume-mount-path`). The name must match a volume defined on the attached capacity provider. |
| `--cp-volume-mount-path <path>` | Capacity provider volume mount path under `/mnt` (e.g. `/mnt/models`, repeatable, paired with `--cp-volume-name`) |
| `--with-config-bundle` | Wire a config bundle into the generated agent template |
| `--idle-timeout <seconds>` | Idle session timeout in seconds |
| `--max-lifetime <seconds>` | Max instance lifetime in seconds |
Expand DownExpand Up@@ -785,6 +788,58 @@ agentcore add config-bundle \
| `--commit-message <text>` | Commit message for this version |
| `--json` | JSON output |

### add capacity-provider

Add a capacity provider — a customer-managed pool of AWS-managed EC2 compute that agent runtimes can run on instead of
the default managed fleet. Everything except the description and tags is immutable after creation.

**Operator role.** AgentCore assumes an IAM _operator role_ to create and manage the EC2 compute on your behalf. Omit
`--operator-role-arn` and the CLI provisions one for you at deploy time — a role that trusts
`bedrock-agentcore.amazonaws.com` (scoped to your account and region) and carries the AWS managed policy
`BedrockAgentCoreRuntimeInstancesOperatorRolePolicy` (EC2/Auto Scaling/fleet management plus the
`agentcore-lifecycle-events-*` EventBridge permissions the service needs). Pass `--operator-role-arn` only when you want
to bring your own role; it must grant those same permissions, or capacity provider creation fails asynchronously
(surfaced by CloudFormation as `NotStabilized`).

```bash
# Minimal — operator role is created automatically
agentcore add capacity-provider \
--name MyCapacityProvider \
--subnets subnet-0123456789abcdef0 \
--security-groups sg-0123456789abcdef0 \
--instance-types c6a.large

# With a named EBS volume, lifecycle limits, and ARM64 (and a bring-your-own operator role)
agentcore add capacity-provider \
--name MyCapacityProvider \
--operator-role-arn arn:aws:iam::123456789012:role/MyOperatorRole \
--subnets subnet-0123456789abcdef0,subnet-0fedcba9876543210 \
--security-groups sg-0123456789abcdef0 \
--os LINUX_ARM64 \
--instance-types c7g.large,c7g.xlarge \
--volume-name data --volume-size 20 --volume-encrypted \
--idle-instance-timeout 3600 \
--max-lifetime 28800
```

| Flag | Description |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `--name <name>` | Capacity provider name (required); immutable after creation |
| `--operator-role-arn <arn>` | IAM role ARN AgentCore assumes to manage the capacity provider (optional — auto-created if omitted); immutable |
| `--description <desc>` | Description (the only mutable field besides tags) |
| `--subnets <subnets>` | Comma-separated subnet IDs, 1–16 (required) |
| `--security-groups <groups>` | Comma-separated security group IDs, 1–16 (required) |
| `--os <os>` | `LINUX_X86_64` (default) or `LINUX_ARM64` |
| `--instance-types <types>` | Comma-separated allowed EC2 instance types, 1–30 (required) |
| `--volume-name <name>` | Named EBS volume name (repeatable, max 5; paired with `--volume-size`) |
| `--volume-size <sizeGiB>` | EBS volume size in GiB (repeatable; paired with `--volume-name`) |
| `--volume-encrypted` | Encrypt EBS volumes |
| `--volume-kms-key <arn>` | KMS key ARN for EBS volume encryption |
| `--instance-profile-arn <arn>` | IAM instance profile ARN for launched instances |
| `--idle-instance-timeout <secs>` | Idle instance timeout in seconds (60–1209600) |
| `--max-lifetime <secs>` | Maximum instance lifetime in seconds (60–1209600) |
| `--json` | JSON output |

### remove

Remove resources from project.
Expand All@@ -804,6 +859,7 @@ agentcore remove dataset --name MyDataset
agentcore remove config-bundle --name MyBundle
agentcore remove payment-manager --name MyManager -y
agentcore remove payment-connector --name MyCDPConnector --manager MyManager -y
agentcore remove capacity-provider --name MyCapacityProvider -y

# Reset everything
agentcore remove all -y
Expand DownExpand Up@@ -853,6 +909,35 @@ agentcore dev call-tool --tool myTool --input '{"arg": "value"}'
| `-b, --no-browser` | Use terminal TUI instead of web-based chat UI |
| `--no-traces` | Disable local OTEL trace collection |

### capacity-provider delete-session

Delete (deprovision) a single live capacity provider session. This is a data-plane operation: it terminates the
session's EC2 instance and **permanently deletes any persistent EBS volumes** attached to the session (data loss). The
operation is asynchronous — it returns immediately with status `Deprovisioning`. You get the session id from `invoke`
(it echoes the session it used); there is no list-sessions API.

```bash
# By in-project capacity provider name (resolved to its id from deployed state)
agentcore capacity-provider delete-session --capacity-provider my-pool --session-id <sessionId>

# By capacity provider id, without a project (the data-plane API is keyed on the id)
agentcore capacity-provider delete-session \
--capacity-provider my-pool-a1b2c3d4e5 --session-id <sessionId> --region us-west-2 --yes

# By ARN (the id is extracted from it), without a project (region auto-detected from the ARN)
agentcore capacity-provider delete-session \
--capacity-provider arn:aws:bedrock-agentcore:us-west-2:123456789012:capacity-provider/my-pool-a1b2c3d4e5 \
--session-id <sessionId> --yes
```

| Option | Description |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--capacity-provider <name-id-or-arn>` | Capacity provider: an in-project name (resolved to its id via deployed state), a capacity provider id, or an ARN (id extracted from it). The API is keyed on the id. (**required**) |
| `--session-id <id>` | Session id to delete (**required**) |
| `--region <region>` | AWS region (auto-detected from the ARN / project otherwise; required with a bare id outside a project unless the environment sets one) |
| `--yes` | Skip the destructive confirmation prompt (required for non-interactive use) |
| `--json` | JSON output |

### invoke

Invoke a deployed agent endpoint.
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions AGENTS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,13 +32,14 @@ These options are available on all commands:

- `create` - Create new AgentCore project
- `add` - Add resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target, policy-engine,
policy, payment-manager, payment-connector)
policy, payment-manager, payment-connector, capacity-provider)
- `remove` - Remove resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target,
policy-engine, policy, payment-manager, payment-connector, all)
policy-engine, policy, payment-manager, payment-connector, capacity-provider, all)
- `deploy` - Deploy infrastructure to AWS
- `status` - Check deployment status
- `dev` - Local development server (CodeZip: uvicorn with hot-reload; Container: Docker build + run with volume mount)
- `invoke` - Invoke agents (local or deployed)
- `capacity-provider delete-session` - Delete (deprovision) a live capacity provider session (data-plane)
- `run eval` - Run on-demand evaluation against agent sessions
- `evals history` - View past eval run results
- `fetch access` - Fetch access info for a deployed gateway or agent
Expand DownExpand Up@@ -90,6 +91,7 @@ Current primitives:
- `PolicyPrimitive` — Cedar policy creation/removal within policy engines
- `PaymentManagerPrimitive` — payment manager creation/removal with agent code wiring
- `PaymentConnectorPrimitive` — payment connector creation/removal with credential management
- `CapacityProviderPrimitive` — capacity provider creation/removal (customer-managed EC2 compute pool for runtimes)

Singletons are created in `registry.ts` and wired into CLI commands via `cli.ts`. See `src/cli/AGENTS.md` for details on
adding new primitives.
Expand Down
12 changes: 6 additions & 6 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -91,10 +91,10 @@ agentcore invoke

### Resource Management

| Command | Description |
| -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, runtime endpoints |
| `remove` | Remove any of the above resources from the project |
| Command | Description |
| -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, capacity providers, runtime endpoints |
| `remove` | Remove any of the above resources from the project |

> **Note**: Run `agentcore deploy` after `add` or `remove` to update resources in AWS.

Expand DownExpand Up@@ -264,8 +264,8 @@ my-project/
Projects use JSON schema files in the `agentcore/` directory:

- `agentcore.json` - Project resources (agents, memory, credentials, gateways, evaluators, online evals/insights,
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, config bundles, datasets,
runtime endpoints)
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, capacity providers, config
bundles, datasets, runtime endpoints)
- `deployed-state.json` - Runtime state in agentcore/.cli/ (auto-managed)
- `aws-targets.json` - Deployment targets (account, region)

Expand Down
85 changes: 85 additions & 0 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -318,6 +318,9 @@ agentcore add agent \
| `--client-secret <secret>` | OAuth client secret |
| `--request-header-allowlist <headers>` | Comma-separated list of inbound header names to forward to the agent. `X-*` names (e.g. `X-Api-Key`, `X-Custom-Signature`) pass through unchanged; bare names without an `X-` prefix are auto-prefixed with the legacy `X-Amzn-Bedrock-AgentCore-Runtime-Custom-` prefix for backward compatibility. |
| `--session-storage-mount-path <path>` | Absolute mount path for session filesystem storage (e.g. `/mnt/session-storage`) |
| `--capacity-provider <name-or-arn>` | Attach the runtime to a capacity provider (customer-managed EC2 compute). Accepts an in-project capacity-provider name or an external CP ARN. Mutually exclusive with `--network-mode VPC`. |
| `--cp-volume-name <name>` | Capacity provider volume name to mount (repeatable, paired by position with `--cp-volume-mount-path`). The name must match a volume defined on the attached capacity provider. |
| `--cp-volume-mount-path <path>` | Capacity provider volume mount path under `/mnt` (e.g. `/mnt/models`, repeatable, paired with `--cp-volume-name`) |
| `--with-config-bundle` | Wire a config bundle into the generated agent template |
| `--idle-timeout <seconds>` | Idle session timeout in seconds |
| `--max-lifetime <seconds>` | Max instance lifetime in seconds |
Expand DownExpand Up@@ -785,6 +788,58 @@ agentcore add config-bundle \
| `--commit-message <text>` | Commit message for this version |
| `--json` | JSON output |

### add capacity-provider

Add a capacity provider — a customer-managed pool of AWS-managed EC2 compute that agent runtimes can run on instead of
the default managed fleet. Everything except the description and tags is immutable after creation.

**Operator role.** AgentCore assumes an IAM _operator role_ to create and manage the EC2 compute on your behalf. Omit
`--operator-role-arn` and the CLI provisions one for you at deploy time — a role that trusts
`bedrock-agentcore.amazonaws.com` (scoped to your account and region) and carries the AWS managed policy
`BedrockAgentCoreRuntimeInstancesOperatorRolePolicy` (EC2/Auto Scaling/fleet management plus the
`agentcore-lifecycle-events-*` EventBridge permissions the service needs). Pass `--operator-role-arn` only when you want
to bring your own role; it must grant those same permissions, or capacity provider creation fails asynchronously
(surfaced by CloudFormation as `NotStabilized`).

```bash
# Minimal — operator role is created automatically
agentcore add capacity-provider \
--name MyCapacityProvider \
--subnets subnet-0123456789abcdef0 \
--security-groups sg-0123456789abcdef0 \
--instance-types c6a.large

# With a named EBS volume, lifecycle limits, and ARM64 (and a bring-your-own operator role)
agentcore add capacity-provider \
--name MyCapacityProvider \
--operator-role-arn arn:aws:iam::123456789012:role/MyOperatorRole \
--subnets subnet-0123456789abcdef0,subnet-0fedcba9876543210 \
--security-groups sg-0123456789abcdef0 \
--os LINUX_ARM64 \
--instance-types c7g.large,c7g.xlarge \
--volume-name data --volume-size 20 --volume-encrypted \
--idle-instance-timeout 3600 \
--max-lifetime 28800
```

| Flag | Description |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `--name <name>` | Capacity provider name (required); immutable after creation |
| `--operator-role-arn <arn>` | IAM role ARN AgentCore assumes to manage the capacity provider (optional — auto-created if omitted); immutable |
| `--description <desc>` | Description (the only mutable field besides tags) |
| `--subnets <subnets>` | Comma-separated subnet IDs, 1–16 (required) |
| `--security-groups <groups>` | Comma-separated security group IDs, 1–16 (required) |
| `--os <os>` | `LINUX_X86_64` (default) or `LINUX_ARM64` |
| `--instance-types <types>` | Comma-separated allowed EC2 instance types, 1–30 (required) |
| `--volume-name <name>` | Named EBS volume name (repeatable, max 5; paired with `--volume-size`) |
| `--volume-size <sizeGiB>` | EBS volume size in GiB (repeatable; paired with `--volume-name`) |
| `--volume-encrypted` | Encrypt EBS volumes |
| `--volume-kms-key <arn>` | KMS key ARN for EBS volume encryption |
| `--instance-profile-arn <arn>` | IAM instance profile ARN for launched instances |
| `--idle-instance-timeout <secs>` | Idle instance timeout in seconds (60–1209600) |
| `--max-lifetime <secs>` | Maximum instance lifetime in seconds (60–1209600) |
| `--json` | JSON output |

### remove

Remove resources from project.
Expand All@@ -804,6 +859,7 @@ agentcore remove dataset --name MyDataset
agentcore remove config-bundle --name MyBundle
agentcore remove payment-manager --name MyManager -y
agentcore remove payment-connector --name MyCDPConnector --manager MyManager -y
agentcore remove capacity-provider --name MyCapacityProvider -y

# Reset everything
agentcore remove all -y
Expand DownExpand Up@@ -853,6 +909,35 @@ agentcore dev call-tool --tool myTool --input '{"arg": "value"}'
| `-b, --no-browser` | Use terminal TUI instead of web-based chat UI |
| `--no-traces` | Disable local OTEL trace collection |

### capacity-provider delete-session

Delete (deprovision) a single live capacity provider session. This is a data-plane operation: it terminates the
session's EC2 instance and **permanently deletes any persistent EBS volumes** attached to the session (data loss). The
operation is asynchronous — it returns immediately with status `Deprovisioning`. You get the session id from `invoke`
(it echoes the session it used); there is no list-sessions API.

```bash
# By in-project capacity provider name (resolved to its id from deployed state)
agentcore capacity-provider delete-session --capacity-provider my-pool --session-id <sessionId>

# By capacity provider id, without a project (the data-plane API is keyed on the id)
agentcore capacity-provider delete-session \
--capacity-provider my-pool-a1b2c3d4e5 --session-id <sessionId> --region us-west-2 --yes

# By ARN (the id is extracted from it), without a project (region auto-detected from the ARN)
agentcore capacity-provider delete-session \
--capacity-provider arn:aws:bedrock-agentcore:us-west-2:123456789012:capacity-provider/my-pool-a1b2c3d4e5 \
--session-id <sessionId> --yes
```

| Option | Description |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--capacity-provider <name-id-or-arn>` | Capacity provider: an in-project name (resolved to its id via deployed state), a capacity provider id, or an ARN (id extracted from it). The API is keyed on the id. (**required**) |
| `--session-id <id>` | Session id to delete (**required**) |
| `--region <region>` | AWS region (auto-detected from the ARN / project otherwise; required with a bare id outside a project unless the environment sets one) |
| `--yes` | Skip the destructive confirmation prompt (required for non-interactive use) |
| `--json` | JSON output |

### invoke

Invoke a deployed agent endpoint.
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions AGENTS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,13 +32,14 @@ These options are available on all commands:

- `create` - Create new AgentCore project
- `add` - Add resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target, policy-engine,
policy, payment-manager, payment-connector)
policy, payment-manager, payment-connector, capacity-provider)
- `remove` - Remove resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target,
policy-engine, policy, payment-manager, payment-connector, all)
policy-engine, policy, payment-manager, payment-connector, capacity-provider, all)
- `deploy` - Deploy infrastructure to AWS
- `status` - Check deployment status
- `dev` - Local development server (CodeZip: uvicorn with hot-reload; Container: Docker build + run with volume mount)
- `invoke` - Invoke agents (local or deployed)
- `capacity-provider delete-session` - Delete (deprovision) a live capacity provider session (data-plane)
- `run eval` - Run on-demand evaluation against agent sessions
- `evals history` - View past eval run results
- `fetch access` - Fetch access info for a deployed gateway or agent
Expand DownExpand Up@@ -90,6 +91,7 @@ Current primitives:
- `PolicyPrimitive` — Cedar policy creation/removal within policy engines
- `PaymentManagerPrimitive` — payment manager creation/removal with agent code wiring
- `PaymentConnectorPrimitive` — payment connector creation/removal with credential management
- `CapacityProviderPrimitive` — capacity provider creation/removal (customer-managed EC2 compute pool for runtimes)

Singletons are created in `registry.ts` and wired into CLI commands via `cli.ts`. See `src/cli/AGENTS.md` for details on
adding new primitives.
Expand Down
12 changes: 6 additions & 6 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -91,10 +91,10 @@ agentcore invoke

### Resource Management

| Command | Description |
| -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, runtime endpoints |
| `remove` | Remove any of the above resources from the project |
| Command | Description |
| -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, capacity providers, runtime endpoints |
| `remove` | Remove any of the above resources from the project |

> **Note**: Run `agentcore deploy` after `add` or `remove` to update resources in AWS.

Expand DownExpand Up@@ -264,8 +264,8 @@ my-project/
Projects use JSON schema files in the `agentcore/` directory:

- `agentcore.json` - Project resources (agents, memory, credentials, gateways, evaluators, online evals/insights,
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, config bundles, datasets,
runtime endpoints)
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, capacity providers, config
bundles, datasets, runtime endpoints)
- `deployed-state.json` - Runtime state in agentcore/.cli/ (auto-managed)
- `aws-targets.json` - Deployment targets (account, region)

Expand Down
85 changes: 85 additions & 0 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -318,6 +318,9 @@ agentcore add agent \
| `--client-secret <secret>` | OAuth client secret |
| `--request-header-allowlist <headers>` | Comma-separated list of inbound header names to forward to the agent. `X-*` names (e.g. `X-Api-Key`, `X-Custom-Signature`) pass through unchanged; bare names without an `X-` prefix are auto-prefixed with the legacy `X-Amzn-Bedrock-AgentCore-Runtime-Custom-` prefix for backward compatibility. |
| `--session-storage-mount-path <path>` | Absolute mount path for session filesystem storage (e.g. `/mnt/session-storage`) |
| `--capacity-provider <name-or-arn>` | Attach the runtime to a capacity provider (customer-managed EC2 compute). Accepts an in-project capacity-provider name or an external CP ARN. Mutually exclusive with `--network-mode VPC`. |
| `--cp-volume-name <name>` | Capacity provider volume name to mount (repeatable, paired by position with `--cp-volume-mount-path`). The name must match a volume defined on the attached capacity provider. |
| `--cp-volume-mount-path <path>` | Capacity provider volume mount path under `/mnt` (e.g. `/mnt/models`, repeatable, paired with `--cp-volume-name`) |
| `--with-config-bundle` | Wire a config bundle into the generated agent template |
| `--idle-timeout <seconds>` | Idle session timeout in seconds |
| `--max-lifetime <seconds>` | Max instance lifetime in seconds |
Expand DownExpand Up@@ -785,6 +788,58 @@ agentcore add config-bundle \
| `--commit-message <text>` | Commit message for this version |
| `--json` | JSON output |

### add capacity-provider

Add a capacity provider — a customer-managed pool of AWS-managed EC2 compute that agent runtimes can run on instead of
the default managed fleet. Everything except the description and tags is immutable after creation.

**Operator role.** AgentCore assumes an IAM _operator role_ to create and manage the EC2 compute on your behalf. Omit
`--operator-role-arn` and the CLI provisions one for you at deploy time — a role that trusts
`bedrock-agentcore.amazonaws.com` (scoped to your account and region) and carries the AWS managed policy
`BedrockAgentCoreRuntimeInstancesOperatorRolePolicy` (EC2/Auto Scaling/fleet management plus the
`agentcore-lifecycle-events-*` EventBridge permissions the service needs). Pass `--operator-role-arn` only when you want
to bring your own role; it must grant those same permissions, or capacity provider creation fails asynchronously
(surfaced by CloudFormation as `NotStabilized`).

```bash
# Minimal — operator role is created automatically
agentcore add capacity-provider \
--name MyCapacityProvider \
--subnets subnet-0123456789abcdef0 \
--security-groups sg-0123456789abcdef0 \
--instance-types c6a.large

# With a named EBS volume, lifecycle limits, and ARM64 (and a bring-your-own operator role)
agentcore add capacity-provider \
--name MyCapacityProvider \
--operator-role-arn arn:aws:iam::123456789012:role/MyOperatorRole \
--subnets subnet-0123456789abcdef0,subnet-0fedcba9876543210 \
--security-groups sg-0123456789abcdef0 \
--os LINUX_ARM64 \
--instance-types c7g.large,c7g.xlarge \
--volume-name data --volume-size 20 --volume-encrypted \
--idle-instance-timeout 3600 \
--max-lifetime 28800
```

| Flag | Description |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `--name <name>` | Capacity provider name (required); immutable after creation |
| `--operator-role-arn <arn>` | IAM role ARN AgentCore assumes to manage the capacity provider (optional — auto-created if omitted); immutable |
| `--description <desc>` | Description (the only mutable field besides tags) |
| `--subnets <subnets>` | Comma-separated subnet IDs, 1–16 (required) |
| `--security-groups <groups>` | Comma-separated security group IDs, 1–16 (required) |
| `--os <os>` | `LINUX_X86_64` (default) or `LINUX_ARM64` |
| `--instance-types <types>` | Comma-separated allowed EC2 instance types, 1–30 (required) |
| `--volume-name <name>` | Named EBS volume name (repeatable, max 5; paired with `--volume-size`) |
| `--volume-size <sizeGiB>` | EBS volume size in GiB (repeatable; paired with `--volume-name`) |
| `--volume-encrypted` | Encrypt EBS volumes |
| `--volume-kms-key <arn>` | KMS key ARN for EBS volume encryption |
| `--instance-profile-arn <arn>` | IAM instance profile ARN for launched instances |
| `--idle-instance-timeout <secs>` | Idle instance timeout in seconds (60–1209600) |
| `--max-lifetime <secs>` | Maximum instance lifetime in seconds (60–1209600) |
| `--json` | JSON output |

### remove

Remove resources from project.
Expand All@@ -804,6 +859,7 @@ agentcore remove dataset --name MyDataset
agentcore remove config-bundle --name MyBundle
agentcore remove payment-manager --name MyManager -y
agentcore remove payment-connector --name MyCDPConnector --manager MyManager -y
agentcore remove capacity-provider --name MyCapacityProvider -y

# Reset everything
agentcore remove all -y
Expand DownExpand Up@@ -853,6 +909,35 @@ agentcore dev call-tool --tool myTool --input '{"arg": "value"}'
| `-b, --no-browser` | Use terminal TUI instead of web-based chat UI |
| `--no-traces` | Disable local OTEL trace collection |

### capacity-provider delete-session

Delete (deprovision) a single live capacity provider session. This is a data-plane operation: it terminates the
session's EC2 instance and **permanently deletes any persistent EBS volumes** attached to the session (data loss). The
operation is asynchronous — it returns immediately with status `Deprovisioning`. You get the session id from `invoke`
(it echoes the session it used); there is no list-sessions API.

```bash
# By in-project capacity provider name (resolved to its id from deployed state)
agentcore capacity-provider delete-session --capacity-provider my-pool --session-id <sessionId>

# By capacity provider id, without a project (the data-plane API is keyed on the id)
agentcore capacity-provider delete-session \
--capacity-provider my-pool-a1b2c3d4e5 --session-id <sessionId> --region us-west-2 --yes

# By ARN (the id is extracted from it), without a project (region auto-detected from the ARN)
agentcore capacity-provider delete-session \
--capacity-provider arn:aws:bedrock-agentcore:us-west-2:123456789012:capacity-provider/my-pool-a1b2c3d4e5 \
--session-id <sessionId> --yes
```

| Option | Description |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--capacity-provider <name-id-or-arn>` | Capacity provider: an in-project name (resolved to its id via deployed state), a capacity provider id, or an ARN (id extracted from it). The API is keyed on the id. (**required**) |
| `--session-id <id>` | Session id to delete (**required**) |
| `--region <region>` | AWS region (auto-detected from the ARN / project otherwise; required with a bare id outside a project unless the environment sets one) |
| `--yes` | Skip the destructive confirmation prompt (required for non-interactive use) |
| `--json` | JSON output |

### invoke

Invoke a deployed agent endpoint.
Expand Down
Loading
Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 4 additions & 2 deletions AGENTS.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -32,13 +32,14 @@ These options are available on all commands:

- `create` - Create new AgentCore project
- `add` - Add resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target, policy-engine,
policy, payment-manager, payment-connector)
policy, payment-manager, payment-connector, capacity-provider)
- `remove` - Remove resources (agent, memory, credential, evaluator, online-eval, gateway, gateway-target,
policy-engine, policy, payment-manager, payment-connector, all)
policy-engine, policy, payment-manager, payment-connector, capacity-provider, all)
- `deploy` - Deploy infrastructure to AWS
- `status` - Check deployment status
- `dev` - Local development server (CodeZip: uvicorn with hot-reload; Container: Docker build + run with volume mount)
- `invoke` - Invoke agents (local or deployed)
- `capacity-provider delete-session` - Delete (deprovision) a live capacity provider session (data-plane)
- `run eval` - Run on-demand evaluation against agent sessions
- `evals history` - View past eval run results
- `fetch access` - Fetch access info for a deployed gateway or agent
Expand DownExpand Up@@ -90,6 +91,7 @@ Current primitives:
- `PolicyPrimitive` — Cedar policy creation/removal within policy engines
- `PaymentManagerPrimitive` — payment manager creation/removal with agent code wiring
- `PaymentConnectorPrimitive` — payment connector creation/removal with credential management
- `CapacityProviderPrimitive` — capacity provider creation/removal (customer-managed EC2 compute pool for runtimes)

Singletons are created in `registry.ts` and wired into CLI commands via `cli.ts`. See `src/cli/AGENTS.md` for details on
adding new primitives.
Expand Down
12 changes: 6 additions & 6 deletions README.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -91,10 +91,10 @@ agentcore invoke

### Resource Management

| Command | Description |
| -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, runtime endpoints |
| `remove` | Remove any of the above resources from the project |
| Command | Description |
| -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `add` | Add harnesses, agents, memory, credentials, gateways and gateway-targets, evaluators, online evals, online insights, knowledge bases, config bundles, datasets, policy engines and policies, payment managers and payment connectors, capacity providers, runtime endpoints |
| `remove` | Remove any of the above resources from the project |

> **Note**: Run `agentcore deploy` after `add` or `remove` to update resources in AWS.

Expand DownExpand Up@@ -264,8 +264,8 @@ my-project/
Projects use JSON schema files in the `agentcore/` directory:

- `agentcore.json` - Project resources (agents, memory, credentials, gateways, evaluators, online evals/insights,
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, config bundles, datasets,
runtime endpoints)
knowledge bases, harnesses, policy engines and policies, payment managers and connectors, capacity providers, config
bundles, datasets, runtime endpoints)
- `deployed-state.json` - Runtime state in agentcore/.cli/ (auto-managed)
- `aws-targets.json` - Deployment targets (account, region)

Expand Down
85 changes: 85 additions & 0 deletions docs/commands.md
Original file line numberDiff line numberDiff line change
Expand Up@@ -318,6 +318,9 @@ agentcore add agent \
| `--client-secret <secret>` | OAuth client secret |
| `--request-header-allowlist <headers>` | Comma-separated list of inbound header names to forward to the agent. `X-*` names (e.g. `X-Api-Key`, `X-Custom-Signature`) pass through unchanged; bare names without an `X-` prefix are auto-prefixed with the legacy `X-Amzn-Bedrock-AgentCore-Runtime-Custom-` prefix for backward compatibility. |
| `--session-storage-mount-path <path>` | Absolute mount path for session filesystem storage (e.g. `/mnt/session-storage`) |
| `--capacity-provider <name-or-arn>` | Attach the runtime to a capacity provider (customer-managed EC2 compute). Accepts an in-project capacity-provider name or an external CP ARN. Mutually exclusive with `--network-mode VPC`. |
| `--cp-volume-name <name>` | Capacity provider volume name to mount (repeatable, paired by position with `--cp-volume-mount-path`). The name must match a volume defined on the attached capacity provider. |
| `--cp-volume-mount-path <path>` | Capacity provider volume mount path under `/mnt` (e.g. `/mnt/models`, repeatable, paired with `--cp-volume-name`) |
| `--with-config-bundle` | Wire a config bundle into the generated agent template |
| `--idle-timeout <seconds>` | Idle session timeout in seconds |
| `--max-lifetime <seconds>` | Max instance lifetime in seconds |
Expand DownExpand Up@@ -785,6 +788,58 @@ agentcore add config-bundle \
| `--commit-message <text>` | Commit message for this version |
| `--json` | JSON output |

### add capacity-provider

Add a capacity provider — a customer-managed pool of AWS-managed EC2 compute that agent runtimes can run on instead of
the default managed fleet. Everything except the description and tags is immutable after creation.

**Operator role.** AgentCore assumes an IAM _operator role_ to create and manage the EC2 compute on your behalf. Omit
`--operator-role-arn` and the CLI provisions one for you at deploy time — a role that trusts
`bedrock-agentcore.amazonaws.com` (scoped to your account and region) and carries the AWS managed policy
`BedrockAgentCoreRuntimeInstancesOperatorRolePolicy` (EC2/Auto Scaling/fleet management plus the
`agentcore-lifecycle-events-*` EventBridge permissions the service needs). Pass `--operator-role-arn` only when you want
to bring your own role; it must grant those same permissions, or capacity provider creation fails asynchronously
(surfaced by CloudFormation as `NotStabilized`).

```bash
# Minimal — operator role is created automatically
agentcore add capacity-provider \
--name MyCapacityProvider \
--subnets subnet-0123456789abcdef0 \
--security-groups sg-0123456789abcdef0 \
--instance-types c6a.large

# With a named EBS volume, lifecycle limits, and ARM64 (and a bring-your-own operator role)
agentcore add capacity-provider \
--name MyCapacityProvider \
--operator-role-arn arn:aws:iam::123456789012:role/MyOperatorRole \
--subnets subnet-0123456789abcdef0,subnet-0fedcba9876543210 \
--security-groups sg-0123456789abcdef0 \
--os LINUX_ARM64 \
--instance-types c7g.large,c7g.xlarge \
--volume-name data --volume-size 20 --volume-encrypted \
--idle-instance-timeout 3600 \
--max-lifetime 28800
```

| Flag | Description |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| `--name <name>` | Capacity provider name (required); immutable after creation |
| `--operator-role-arn <arn>` | IAM role ARN AgentCore assumes to manage the capacity provider (optional — auto-created if omitted); immutable |
| `--description <desc>` | Description (the only mutable field besides tags) |
| `--subnets <subnets>` | Comma-separated subnet IDs, 1–16 (required) |
| `--security-groups <groups>` | Comma-separated security group IDs, 1–16 (required) |
| `--os <os>` | `LINUX_X86_64` (default) or `LINUX_ARM64` |
| `--instance-types <types>` | Comma-separated allowed EC2 instance types, 1–30 (required) |
| `--volume-name <name>` | Named EBS volume name (repeatable, max 5; paired with `--volume-size`) |
| `--volume-size <sizeGiB>` | EBS volume size in GiB (repeatable; paired with `--volume-name`) |
| `--volume-encrypted` | Encrypt EBS volumes |
| `--volume-kms-key <arn>` | KMS key ARN for EBS volume encryption |
| `--instance-profile-arn <arn>` | IAM instance profile ARN for launched instances |
| `--idle-instance-timeout <secs>` | Idle instance timeout in seconds (60–1209600) |
| `--max-lifetime <secs>` | Maximum instance lifetime in seconds (60–1209600) |
| `--json` | JSON output |

### remove

Remove resources from project.
Expand All@@ -804,6 +859,7 @@ agentcore remove dataset --name MyDataset
agentcore remove config-bundle --name MyBundle
agentcore remove payment-manager --name MyManager -y
agentcore remove payment-connector --name MyCDPConnector --manager MyManager -y
agentcore remove capacity-provider --name MyCapacityProvider -y

# Reset everything
agentcore remove all -y
Expand DownExpand Up@@ -853,6 +909,35 @@ agentcore dev call-tool --tool myTool --input '{"arg": "value"}'
| `-b, --no-browser` | Use terminal TUI instead of web-based chat UI |
| `--no-traces` | Disable local OTEL trace collection |

### capacity-provider delete-session

Delete (deprovision) a single live capacity provider session. This is a data-plane operation: it terminates the
session's EC2 instance and **permanently deletes any persistent EBS volumes** attached to the session (data loss). The
operation is asynchronous — it returns immediately with status `Deprovisioning`. You get the session id from `invoke`
(it echoes the session it used); there is no list-sessions API.

```bash
# By in-project capacity provider name (resolved to its id from deployed state)
agentcore capacity-provider delete-session --capacity-provider my-pool --session-id <sessionId>

# By capacity provider id, without a project (the data-plane API is keyed on the id)
agentcore capacity-provider delete-session \
--capacity-provider my-pool-a1b2c3d4e5 --session-id <sessionId> --region us-west-2 --yes

# By ARN (the id is extracted from it), without a project (region auto-detected from the ARN)
agentcore capacity-provider delete-session \
--capacity-provider arn:aws:bedrock-agentcore:us-west-2:123456789012:capacity-provider/my-pool-a1b2c3d4e5 \
--session-id <sessionId> --yes
```

| Option | Description |
| -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--capacity-provider <name-id-or-arn>` | Capacity provider: an in-project name (resolved to its id via deployed state), a capacity provider id, or an ARN (id extracted from it). The API is keyed on the id. (**required**) |
| `--session-id <id>` | Session id to delete (**required**) |
| `--region <region>` | AWS region (auto-detected from the ARN / project otherwise; required with a bare id outside a project unless the environment sets one) |
| `--yes` | Skip the destructive confirmation prompt (required for non-interactive use) |
| `--json` | JSON output |

### invoke

Invoke a deployed agent endpoint.
Expand Down
Loading
Loading