How AxonLLM is built

Start with four executable request stories, then inspect the AWS infrastructure, ordered gateway pipeline, and component graph behind them. The engineering diagrams are generated from the source and include narrated walkthroughs.

See where every decision is made

Play each scenario step by step. The highlighted path separates caller identity, governance, routing, provider or data execution, and durable evidence.

Production Topology — AgentCore data plane + private Fargate control plane + canonical DynamoDB authority

100%

Drag to pan · use − and + to zoom

What happens to a request

The normal non-streaming path through GatewayAgent.handle_chat_completion is ordered so authority and admission run before provider spend, accounting runs immediately after the provider result, and output policy runs before release. Streaming uses the same controls with the lifecycle differences called out below.

  1. Parse the request and extract context — project, user, and model resolved from the token or API key
  2. Validate — skipped for smart and ensemble routing, where the model is not yet chosen
  3. Enforce quotas and cap max_tokens — the policy hierarchy resolves org → business unit → project → env
  4. Detect prompt injection — NFKD normalization and homoglyph-resistant patterns; audited and dispatched even when allowed
  5. Redact PII — replaced with tokens, and the mapping held for step 11.5
  6. Rate limit — sliding window per project and user
  7. Check model access — project allow-list intersected with the user's
  8. Check budgets — project and user, tightest limit wins
  9. Apply request guardrails
  10. Look up the cache — exact key first, then a semantic match on the reworded question; a hit returns here and never reaches a provider
  11. Route by region — hub to spoke, honouring data-residency zones; skipped in single-region deploys
  12. Route and execute — direct with a fallback chain, smart (classify → leaderboard → cost/quality), or ensemble (panel → quorum → synthesis)
  13. Finalize usage, cost, and reserved spend — provider usage is durable before output policy can withhold a response
  14. Apply response guardrails — only block changes execution today; warn/redact rules record matches
  15. Re-inject PII — the original values restored into the response, per chunk when streaming
  16. Append audit metadata — tenant SHA-256 hash chain without prompt or response bodies
  17. Budget status and session storage — recorded after the response is complete
  18. Stream, if asked — eligible routes relay native chunks; output inspection buffers, and other routes can emit simulated chunks
  19. Write the cache — only eligible non-streaming, post-policy responses are stored
  20. Return — JSON, with routing and cache metadata attached

AWS services it deploys onto

The production topology separates the AgentCore data plane from a private Fargate web control plane. They share canonical DynamoDB authority but have different routes and IAM permissions.

Amazon CloudFront

Provides the generated-domain browser option with WAF, a VPC origin, Cognito authorization-code PKCE, and opaque DynamoDB-backed sessions.

Application Load Balancer

Provides the custom-domain option. ALB Cognito authentication produces signed OIDC headers that AxonLLM verifies before canonical authorization.

Amazon Bedrock AgentCore

Runs the OIDC-authenticated data plane for chat, model listing, governed query, bounded project configuration, health, and readiness.

Amazon DynamoDB

One tenant-qualified authority table for principals, projects, key hashes, sessions, SCIM, policy, budgets, usage, audit, events, and query lifecycle.

AWS Secrets Manager

Production provider settings load from one exact secret ARN and version, with only allowlisted fields accepted by the runtime.

Amazon Bedrock

Bedrock and Bedrock Mantle use scoped runtime IAM instead of a stored provider API key.

CloudWatch Logs

Collects logs, metrics, alarms, and readiness signals. Optional OTLP export carries completed usage telemetry.

Amazon ECR

Stores separately built, immutable ARM64 AgentCore and AMD64 control-plane images identified by digest.

What's inside the gateway

Wired in one place — build_gateway_components() in src/gateway/bootstrap.py. Every component takes its collaborators as constructor arguments, which is what makes the persistence layer optional rather than assumed.

GatewayAgent

The orchestrator for validation, governance, safety, routing, accounting, output policy, and native or policy-buffered streaming.

Router

Provider fallback chain with exponential backoff, plus the entry points for smart and ensemble routing.

SmartRoutingStrategy

Classifies the task, consults the model leaderboard, and picks on a cost/quality tradeoff read from the live pricing table.

EnsembleStrategy

Dispatches a panel, takes a quorum, ranks the answers, and synthesizes. Budget is pre-checked at (N+1)×cost before any of it runs.

RegionRouter + SpokeHealthMonitor

Hub-and-spoke topology with data-residency zones, active-passive and active-active weighted failover, and a background health task.

MultiProviderFactory

Thirteen adapters behind AWS SDK and HTTP transports, with provider route pools for credentials, endpoints, health, and capacity.

PolicyHierarchyResolver

Resolves inherited limits: budget and rate take the minimum, allowed models intersect, PII types union, and PII redaction cannot be switched off downstream.

QuotaEnforcer + CostTracker

Rate, token, and spend limits with budget-threshold alerts, priced per request against the pricing table.

PIIRedactor

Redacts shaped and optional named-entity PII, restores eligible caller values, and fails closed when configured output inspection cannot complete.

AuditTrail

Tenant-qualified SHA-256 hash chains over operation metadata and security events; prompt and response bodies are not stored.

EventDispatcher

Fans security and budget events out to webhook, SNS, and CloudWatch destinations with per-destination event filters.

DynamoPersistence

Optional for local development, but required for canonical production authority, shared admission, sessions, durable audit, and AgentCore readiness.