Architecture
Start with four executable request stories, then inspect the AWS infrastructure, ordered gateway pipeline, and component graph behind them. The engineering diagrams are generated from the source and include narrated walkthroughs.
Interactive Request Journeys
Play each scenario step by step. The highlighted path separates caller identity, governance, routing, provider or data execution, and durable evidence.
Drag to pan · use − and + to zoom
Request Pipeline
The normal non-streaming path through
GatewayAgent.handle_chat_completion is ordered so authority and
admission run before provider spend, accounting runs immediately after the
provider result, and output policy runs before release. Streaming uses the
same controls with the lifecycle differences called out below.
max_tokens — the policy hierarchy resolves org → business unit → project → envblock changes execution today; warn/redact rules record matchesInfrastructure
The production topology separates the AgentCore data plane from a private Fargate web control plane. They share canonical DynamoDB authority but have different routes and IAM permissions.
Provides the generated-domain browser option with WAF, a VPC origin, Cognito authorization-code PKCE, and opaque DynamoDB-backed sessions.
Provides the custom-domain option. ALB Cognito authentication produces signed OIDC headers that AxonLLM verifies before canonical authorization.
Runs the OIDC-authenticated data plane for chat, model listing, governed query, bounded project configuration, health, and readiness.
One tenant-qualified authority table for principals, projects, key hashes, sessions, SCIM, policy, budgets, usage, audit, events, and query lifecycle.
Production provider settings load from one exact secret ARN and version, with only allowlisted fields accepted by the runtime.
Bedrock and Bedrock Mantle use scoped runtime IAM instead of a stored provider API key.
Collects logs, metrics, alarms, and readiness signals. Optional OTLP export carries completed usage telemetry.
Stores separately built, immutable ARM64 AgentCore and AMD64 control-plane images identified by digest.
Components
Wired in one place — build_gateway_components() in
src/gateway/bootstrap.py. Every component takes its
collaborators as constructor arguments, which is what makes the
persistence layer optional rather than assumed.
The orchestrator for validation, governance, safety, routing, accounting, output policy, and native or policy-buffered streaming.
Provider fallback chain with exponential backoff, plus the entry points for smart and ensemble routing.
Classifies the task, consults the model leaderboard, and picks on a cost/quality tradeoff read from the live pricing table.
Dispatches a panel, takes a quorum, ranks the answers, and synthesizes. Budget is pre-checked at (N+1)×cost before any of it runs.
Hub-and-spoke topology with data-residency zones, active-passive and active-active weighted failover, and a background health task.
Thirteen adapters behind AWS SDK and HTTP transports, with provider route pools for credentials, endpoints, health, and capacity.
Resolves inherited limits: budget and rate take the minimum, allowed models intersect, PII types union, and PII redaction cannot be switched off downstream.
Rate, token, and spend limits with budget-threshold alerts, priced per request against the pricing table.
Redacts shaped and optional named-entity PII, restores eligible caller values, and fails closed when configured output inspection cannot complete.
Tenant-qualified SHA-256 hash chains over operation metadata and security events; prompt and response bodies are not stored.
Fans security and budget events out to webhook, SNS, and CloudWatch destinations with per-destination event filters.
Optional for local development, but required for canonical production authority, shared admission, sessions, durable audit, and AgentCore readiness.