Skip to content

Blog · Tag

#aws

21 posts tagged #aws.

The harness is one integer column

The fix for a poison-pill row re-billing a model every sixty seconds forever was not a rewrite. It was one INT column, capped at five, incremented atomically in the database. The fix itself shipped with a gap, and that gap is the actual lesson.

Introducing the AI Architect Roadmap

Eight rungs mapping what shipping production Agentic AI on AWS actually takes, marked honestly as covered, strong, flagship or gap rather than filled in to look finished.

Not a Python tutorial: the patterns that bite in production agents

The senior-lens Python patterns that actually bite in a production agent loop: why boto3 blocking the event loop is the first one, and four more that follow from it.

You probably don't need to fine-tune

A post framed fine-tuning as a 2026 interview trap. Here is the AWS version: the ladder before you touch weights, the four job types and three serving paths Bedrock forks 'fine-tune' into, and what each one costs, priced today.

Your quality alert needs 32 samples

Part 3 left me a label-free signal that responds to a real regression. It does not come with a threshold. Here is where the line actually goes, what a false page costs, and why the reflex answer computes to a negative number.

Your golden dataset is too easy

I could not detect a deleted guardrail with an LLM judge, a judge-free assertion, or six label-free signals. Three instruments, one null. The instrument was never the problem: shorten the source and the same gate goes from p = 1.000 to p = 0.0020.

Your regression gate needs a power calculation

I deliberately broke my summariser's prompt, then failed to detect it two ways: with an LLM judge over a golden dataset, and with a judge-free deterministic assertion. Removing the judge changed nothing. Here is the calculation that would have told me first.

A clean pass rate is not calibration

I built an LLM-as-judge eval on my own blog and got a suspiciously perfect 16/16. Here's the three-round test I ran before trusting that number: single-variable corruption, and a self-consistency check the research says most teams skip.

Field Notes: The AgentCore Memory write that returns success and reads back empty

AgentCore long-term memory has a read-after-write gotcha the docs skip: a direct BatchCreateMemoryRecords write returns 201 and stays unsearchable for 15 to 30 seconds. Measured, with the two-tier model that explains it.

Field Notes: Turning prompt caching on for a production Bedrock workload

Strands' BedrockModel ships with prompt caching off. Two kwargs turn it on, one per-model gotcha catches you, and a 10-turn driver measures 99.9% and 99.8% hit ratios against an 8,156-token production system prefix. The usage block proves it in seconds.

Field Notes: Three things I learned diagnosing a production Bedrock workload

Three findings from a real customer engagement on AWS Bedrock: what a load test was actually doing, why p95 latency was 45 seconds, and the prompt-caching default that costs every team money. Plus the three CloudWatch metrics that catch all three.

What a Year 10 study system taught me about production AI failure modes

A personal Bedrock-adjacent build that went through three iterations and an architecture pivot. Five lessons that map directly to production AWS AI work.

Part 2: The MCP Server: Turning ADRs and Incidents into a Queryable Org-Knowledge Surface

The agent doesn't read your wiki. It calls four tools that pull frontmatter-filtered chunks out of a Bedrock Knowledge Base. The contract, the code, and the small decisions between an agent that reads your docs and one that knows your org.

Part 3: Wiring It Into AWS DevOps Agent: AgentSpace, register-service, and the IAM Trust Policy That Ate My Afternoon

The MCP server is done. Now plug it into AWS DevOps Agent: three CDK stacks, the AgentSpace and register-service flow, the composite-principal trust policy you will get wrong first try, and an OIDC gotcha that broke my blog deploy for a month.

Part 1: Intent vs State. How AWS DevOps Agent Closes the Gap Between What Your System Is and What You Decided It Should Be

When something breaks at 3am, you look at logs, metrics, traces. You don't go and re-read the ADR your team wrote in January. AWS DevOps Agent does. Here's why that changes the first hour of an incident.

Part 6: Cost & Performance for Bedrock AgentCore: Prompt Caching, Model Selection, and CloudWatch Alarms

Real cost breakdown of running an AgentCore agent: prompt caching savings, when to use Nova Pro vs Claude Sonnet, PriceClass_100, idle timeouts, and how to set alarms before your bill surprises you.

Part 5: CI/CD for Bedrock AgentCore with GitHub Actions and AWS OIDC (No Stored Credentials)

How to build a complete CI/CD pipeline for AgentCore using GitHub Actions OIDC: no stored AWS keys, dual-tag ECR strategy, automated Runtime updates, and multi-environment promotion.

Part 4: Running Your AgentCore Agent Locally with Docker (The Right Way)

How to build and run your AgentCore container locally with real AWS credentials, the correct linux/amd64 platform flag, the .env.local pattern, and how to test with curl.

Part 3: Building the AI Agent with Strands Agents SDK, Prompt Caching, and AgentCore Memory

How to build the Python agent that runs inside AgentCore: Strands SDK setup, prompt caching that cuts costs by 90%, dual-model strategy, tool definitions, and AgentCore Memory integration.

Part 2: CDK Infrastructure for Amazon Bedrock AgentCore (And Every Gotcha You'll Hit)

A complete CDK v2 TypeScript stack for Bedrock AgentCore, with inline comments for every deployment trap: naming constraints, ECR bootstrap, missing L1 constructs, VPC endpoint conflicts, and more.

Part 1: Why I Chose Amazon Bedrock AgentCore (And What Lambda Gets Wrong for AI Agents)

Before writing a single line of agent code, I spent a week figuring out where to run it. Here's the architecture decision that changed everything, and the Lambda limitations that forced my hand.