OpsfleetAWS
AWS Partner, Advanced Tier ServicesAWS Partner, AI Services Competency

Opsfleet Agent Bootcamp · DataStream Corp

Prototype to production.

You build the agent. The platform handles the cloud. Two phases, sixteen tasks, one executive assistant for CEO Alice Chen, from a local script to a governed, observable service on Amazon Bedrock AgentCore.

Phase 1 · local

Build the agent

A Strands agent on your laptop: prompts, MCP tools, sessions, conversation windows, hooks, structured output and multi-agent routing.

8 tasks · about 3 hours
Phase 2 · AgentCore

Ship it

One command per stage provisions identity, runtimes, Gateway, Memory, observability, evaluations and policy. You focus on the code that runs on them.

8 tasks + optional pages · about 3.5 hours
The story

DataStream Corp needs an assistant, fast

DataStream Corp has 1,200+ employees, six departments and a CEO, Alice Chen, who is tired of waiting for reports. Every task starts with one of her problems: an agent that forgets her name, one that nearly deletes the database, one nobody can see inside. You solve each with one concept.

You're the developer, not the DevOps team. Infrastructure arrives with one command; your time goes into prompts, tools, memory, guardrails and testing.

How it fits together

Phase 1 runs on your laptop. Phase 2 moves the same agent into your own AgentCore stack. Every model call, in both phases, goes through the Opsfleet LiteLLM gateway.

Bootcamp architecture Your laptop gets tokens from Amazon Cognito: machine-to-machine tokens for the MCP server and the Gateway, and signed-in user tokens for the agent. It invokes your agent on AgentCore Runtime, optionally streaming the answer. The runtime accepts only user tokens and takes the actor from the verified token. All model calls, from the laptop in Phase 1 and from the agent in Phase 2, go keylessly through the Opsfleet LiteLLM gateway, which allows participants only the model routes, checks that a requested guardrail is their own and enforces per-person and per-company budgets, to Amazon Bedrock. The agent uses AgentCore Memory with three strategies and reaches tools through AgentCore Gateway, which searches its tools semantically, enforces a Cedar policy, uses AgentCore Identity for outbound OAuth to your MCP server runtime (which reads your own database copy from S3, read-only) and invokes your weather Lambda target. Runtimes and the gateway emit traces, logs and metrics to CloudWatch GenAI Observability. AgentCore Evaluations reads those traces: online evaluation scores sampled live traffic, offline evaluation runs your golden dataset as a batch evaluation with ground truth and prompt variants, and custom code evaluators such as exact_numbers or a rubric judge that calls its model through LiteLLM add your own scores. Code Interpreter, Browser and a Bedrock Guardrail are optional. MODEL ACCESS · SHARED BY THE CLASS AMAZON BEDROCK AGENTCORE · YOUR STACK Your laptop bootcamp.py · Phase 1 agent invoke --stream · eval · tools SQLite copy (Phase 1) Amazon Cognito M2M client: MCP server + Gateway user client: alice-chen, jordan-lee signed-in user tokens · task 0 LiteLLM gateway keyless STS identity · no API key model routes only · own guardrail only budgets per person + per company Amazon Bedrock gpt-6-luna · claude-sonnet-5-5 + your guardrail (optional) Agent runtime your orchestrator · task 4 JWT authorizer: user tokens only actor from the verified token SSE streaming · workload identity AgentCore Gateway inbound JWT · task 2 MCP + Lambda targets semantic tool search Cedar policy engine SELECT only · task 7 MCP runtime query_db · task 1 inbound OAuth (Cognito M2M) Your DB in S3 private SQLite copy · read-only Weather Lambda Lambda target · task 2 US forecast (weather.gov) AgentCore Memory UserFacts · UserPreferences SessionSummaries · task 3 AgentCore Identity OAuth2 credential provider token vault · workload tokens OPTIONAL Code Interpreter run_python Browser browse_web Bedrock Guardrail via LiteLLM · tool-output guard Observability · CloudWatch GenAI Observability traces, logs and metrics from runtimes and the gateway · Transaction Search · task 5 AgentCore Evaluations · task 6 Online evaluation Helpfulness · GoalSuccessRate · Correctness on live traces Offline: bootcamp.py eval golden dataset → batch evaluation ground truth · A/B prompt variants Custom evaluators code evaluators: exact_numbers (Lambda) · rubric judge via LiteLLM score offline runs, and live traffic when enabled Phase 1 calls invoke tokens models · keyless tools MCP Lambda outbound OAuth reads traces
Solid arrows are requests, dashed arrows lead to optional tools, dotted arrows are telemetry. On a phone, scroll the diagram sideways.

Quick start

Run these one line at a time. The full walkthrough, including Windows commands, is in the setup task.

terminal · macOS / Linux
git clone --branch bootcamp-participant --single-branch https://github.com/Opsfleet/agentic-workshop-aws.git datastream-bootcamp
cd datastream-bootcamp
aws configure sso
aws sso login --profile bootcamp
uv sync
cp .env.example .env
uv run bootcamp.py doctor
uv run bootcamp.py llm
uv run bootcamp.py phase1 t0

aws configure sso asks for the start URL and region from your instructor. Before doctor, set PARTICIPANT and AWS_PROFILE in .env. Before the workshop explains every doctor line.

Go to the setup task

Your own data

Phase 1 uses a local SQLite file; in Phase 2 your MCP server reads its own copy from your S3 bucket, read-only. Nobody else touches your data.

Your own budget

Keyless: the gateway knows you by your IAM role and bills your personal budget, $1 by default. No API key is ever handed out. gpt-6-luna is cheap; switch to claude-sonnet-5-5 when you need more reasoning.

Your own stack

Everything you create is named awsworkshop-<name>-*, tagged Participant=<name> and isolated by IAM. uv run bootcamp.py down removes it all.

Partnerships

Built with AWS

Opsfleet is an AWS Partner, recognised at the Advanced Tier for services and with the AI Services Competency. This bootcamp runs end to end on AWS: Amazon Bedrock models behind the Opsfleet LiteLLM gateway, and Amazon Bedrock AgentCore for runtime, gateway, memory, identity, observability, evaluations and policy.

AWS Partner, Advanced Tier Services

AWS Advanced Tier Services Partner

Opsfleet's partner tier in the AWS Partner Network.

AWS Partner, AI Services Competency

AWS AI Services Competency

Opsfleet holds the AWS AI Services Competency.