Skip to content

Latest commit

 

History

22 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

# Akto for Amazon Bedrock AgentCore Gateway

Add Akto guardrails to an AgentCore Gateway interceptor without copying the
integration implementation into your Lambda.

For AWS Management Console steps (new Lambda vs existing interceptor), see
[docs/manual-deployment.md](docs/manual-deployment.md).

## Existing interceptor

1. Attach the versioned Akto layer ARN for your AWS region to the Lambda.
2. Set `AKTO_DATA_INGESTION_URL` and `AKTO_API_TOKEN`.
3. Wrap the handler after defining it:

Current public `us-east-1` layer:

`arn:aws:lambda:us-east-1:041877753357:layer:akto-agentcore:3`

```python
from akto_agentcore import wrap_interceptor


def lambda_handler(event, context):
    # Your existing interceptor logic stays unchanged.
    ...


lambda_handler = wrap_interceptor(lambda_handler)
```

Your interceptor runs first. Akto scans the effective payload after your
transformations, so an Akto block or redaction cannot be bypassed by later
handler code. Existing headers, status codes, and unrelated transformations
are retained.

## No existing interceptor

Use this complete Lambda handler:

```python
from akto_agentcore import lambda_handler
```

Attach that Lambda to the Gateway's `REQUEST` and `RESPONSE` interception
points.

## Configuration

Required Lambda environment variables:

- `AKTO_DATA_INGESTION_URL`
- `AKTO_API_TOKEN`

Optional:

- `AKTO_FAIL_OPEN=false` — errors and unresolved approvals block by default.
- `AKTO_TIMEOUT_SECONDS=30` — timeout for each Akto API call.
- `AKTO_APPROVAL_WAIT_SECONDS=840`
- `AKTO_APPROVAL_POLL_SECONDS=2`

The Lambda timeout should be 900 seconds when human approval is enabled.

## Supported traffic

- MCP `tools/call` requests and tool results
- Buffered HTTP request/response envelopes used by AgentCore Runtime,
  inference, and custom targets
- Allow, block, payload modification/redaction, and human approval

AWS does not invoke HTTP interceptors for streaming targets. If the Gateway
excludes `RESPONSE_BODY`, Akto cannot scan that response body.

## Publish the layer

Akto publishes immutable, versioned layer ARNs per AWS region. To build and
publish from this repository:

```bash
AWS_REGION=us-east-1 deploy/publish-layer.sh
```

The command prints the versioned layer ARN and makes that exact version
attachable by other AWS accounts. `deploy/build-layer.sh` creates the same
byte-for-byte ZIP for identical source.

To deploy Akto's standalone interceptor Lambda, copy `deploy/.env.example`,
pin `AKTO_LAYER_ARN` to the printed version, and run:

```bash
deploy/deploy.sh
```

For the same deployment in the AWS Management Console (no scripts), follow
[docs/manual-deployment.md](docs/manual-deployment.md).

AWS interceptor contracts:

- https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-interceptors-types.html
- https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-interceptors-configuration.html

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages