OpsfleetAWS
AWS Partner, Advanced Tier ServicesAWS Partner, AI Services Competency

Opsfleet Agent Bootcamp · DataStream Corp

Prototype to production.

You build the agent. The platform handles the cloud. Two phases, sixteen tasks, one executive assistant for CEO Alice Chen, from a local script to a governed, observable service on Amazon Bedrock AgentCore.

Phase 1 · local

Build the agent

A Strands agent on your laptop: prompts, MCP tools, sessions, conversation windows, hooks, structured output and multi-agent routing.

8 tasks · about 2 hours
Phase 2 · AgentCore

Ship it

One command per stage provisions identity, runtimes, Gateway, Memory, observability, evaluations and policy. You focus on the code that runs on them.

8 tasks + 2 optional · about 3 hours
The story

DataStream Corp needs an assistant, fast

DataStream Corp has 1,200+ employees, six departments and a CEO, Alice Chen, who is tired of waiting for reports. Every task starts with one of her problems: an agent that forgets her name, one that nearly deletes the database, one nobody can see inside. You solve each with one concept.

You're the developer, not the DevOps team. Infrastructure arrives with one command; your time goes into prompts, tools, memory, guardrails and testing.

How it fits together

Phase 1 runs on your laptop. Phase 2 moves the same agent into your own AgentCore stack. Every model call, in both phases, goes through the Opsfleet LiteLLM gateway.

Bootcamp architecture Your laptop gets a token from Amazon Cognito and invokes your agent on AgentCore Runtime. All model calls, from the laptop in Phase 1 and from the agent in Phase 2, go keylessly through the Opsfleet LiteLLM gateway, with per-person and team budgets, to Amazon Bedrock. The agent uses AgentCore Memory and reaches tools through AgentCore Gateway, which enforces a Cedar policy and uses AgentCore Identity for outbound OAuth to your MCP server runtime, which reads your own database copy in S3. Runtimes and the gateway emit traces, logs and metrics to CloudWatch GenAI Observability, which online evaluations read. Code Interpreter and Browser are optional tools for the agent. MODEL ACCESS · SHARED BY THE CLASS AMAZON BEDROCK AGENTCORE · YOUR STACK Your laptop bootcamp.py · Phase 1 agent SQLite copy (Phase 1) Amazon Cognito inbound JWT for runtimes + gateway M2M tokens · task 0 LiteLLM gateway keyless STS identity · no API key per-person + team budgets Amazon Bedrock gpt-6-luna · claude-sonnet-5-5 Agent runtime your orchestrator · task 4 inbound JWT (Cognito) workload identity AgentCore Gateway inbound JWT · tool search · task 2 Cedar policy engine SELECT only · task 7 MCP runtime query_db · task 1 inbound OAuth (Cognito) AgentCore Memory UserFacts per actor · task 3 AgentCore Identity OAuth2 credential provider token vault · workload tokens Your DB in S3 private SQLite copy OPTIONAL TOOLS Code Interpreter (optional) Browser (optional) Observability · CloudWatch GenAI Observability traces, logs and metrics from every runtime and the gateway · Transaction Search · task 5 Online evaluations Helpfulness · GoalSuccessRate · Correctness, judged from the traces · task 6 Phase 1 calls invoke token models · keyless tools MCP outbound OAuth reads traces
Solid arrows are requests, dashed arrows lead to optional tools, dotted arrows are telemetry. On a phone, scroll the diagram sideways.

Quick start

Run these one line at a time. The full walkthrough, including Windows commands, is in the setup task.

terminal · macOS / Linux
git clone https://github.com/Opsfleet/agentic-workshop-aws.git
cd agentic-workshop-aws
git checkout genai-bootcamp
cd bootcamp
aws configure sso
aws sso login --profile bootcamp
uv sync
cp .env.example .env
uv run bootcamp.py llm
uv run bootcamp.py phase1 t0

aws configure sso asks for the start URL and region from your instructor. Before llm, set PARTICIPANT and AWS_PROFILE in .env.

Go to the setup task

Your own data

Phase 1 uses a local SQLite file; in Phase 2 your MCP server keeps your copy in your own S3 bucket. Destructive experiments only hurt you.

Your own budget

Keyless: the gateway knows you by your IAM role and bills your personal budget, $1 by default. No API key is ever handed out. gpt-6-luna is cheap; switch to claude-sonnet-5-5 when you need more reasoning.

Your own stack

Everything you create is named awsworkshop-<name>-*, tagged Participant=<name> and isolated by IAM. uv run bootcamp.py down removes it all.

Partnerships

Built with AWS

Opsfleet is an AWS Partner, recognised at the Advanced Tier for services and with the AI Services Competency. This bootcamp runs end to end on AWS: Amazon Bedrock models behind the Opsfleet LiteLLM gateway, and Amazon Bedrock AgentCore for runtime, gateway, memory, identity, observability, evaluations and policy.

AWS Partner, Advanced Tier Services

AWS Advanced Tier Services Partner

Opsfleet's partner tier in the AWS Partner Network.

AWS Partner, AI Services Competency

AWS AI Services Competency

Opsfleet holds the AWS AI Services Competency.