ProcessAWS Bedrock & AgentCore
From notebook to AgentCore Runtime: deploying a LangGraph or CrewAI agent
A LangGraph or CrewAI agent that works in a notebook still needs a runtime contract, authentication, governed tools, memory, tracing and rehearsed failure handling before anyone depends on it. This process walks through deploying such an agent to Amazon Bedrock AgentCore Runtime in nine steps, using a hypothetical research assistant, and flags what usually breaks on the way.
On this page
One authenticated request through the deployed agent
- Client application
The user-facing app that signs the user in and calls the agent with a bearer token.
- AgentCore Runtime
Validates the token, starts or resumes an isolated session and passes the request to your code.
- Agent code (LangGraph)
Your graph or crew, wrapped in the AgentCore entrypoint, deciding which steps and tools to run.
- AgentCore Memory
Holds session events and long-term records the agent reads and writes.
- Gateway with Policy
Checks each tool call against policy and injects the right outbound credential.
- Enterprise API
The internal or third-party system behind the tool.
Nine steps from notebook to production runtime
Write the runtime contract
Document what the agent accepts and returns, every tool it calls and whether each reads or writes, what state must survive between turns, the longest acceptable run and who may call it. Every later step, and every reviewer, works from this document.
Package the agent for Runtime
Wrap the graph or crew with the AgentCore SDK's BedrockAgentCoreApp entrypoint and build an ARM64 container image pushed to Amazon ECR, or let the AgentCore CLI scaffold and deploy it9. Under the HTTP contract the container serves requests on port 8080 at the invocations path1.
Configure inbound authentication
Choose IAM SigV4 for service-to-service callers, or a JWT authorizer with your identity provider's discovery URL and allowed audiences, clients and scopes for user-facing apps. A runtime supports one of the two, not both2.
Set up outbound credentials
Create a credential provider in AgentCore Identity for each third-party system, decide whether each call acts for the user or for the agent, and let the token vault hold OAuth tokens and API keys instead of environment variables2.
Register tools through Gateway
Expose APIs, Lambda functions and existing MCP servers as MCP tools behind one gateway endpoint, using OpenAPI, Smithy or Lambda definitions as inputs3. Point the agent's tool client at the gateway rather than at each system.
Add memory deliberately
Use short-term memory for turn-by-turn context within a session, and long-term memory only for facts worth keeping across sessions4. Scope records per user and write down what must never be stored.
Turn on tracing and dashboards
AgentCore emits built-in metrics; add OpenTelemetry spans in your code for graph nodes, decisions and tool calls so that traces in CloudWatch explain a failure rather than merely record it5.
Enforce tool boundaries with Policy
Associate a policy engine with the gateway and write Cedar rules, or natural-language drafts validated into Cedar, stating which principals may call which tools with which arguments6. Then restrict the runtime so that callers cannot bypass the gateway.
Rehearse failure, evaluate and release
Set idle timeout and maximum lifetime, test cancellation and recovery in the middle of a tool call, and run an on-demand evaluation set from the pipeline8. Release a version to a named endpoint so that rollback is a pointer change.
A hypothetical research assistant leaves the notebook
What usually breaks between notebook and production
State held in process memory
Early signalAnswers lose context when a new session starts or a microVM is replaced.
MitigationKeep conversation state in AgentCore Memory or a persistent filesystem, never in module-level variables.
Tool calls that outlive the session
Early signalLong reports or slow APIs end in timeouts and half-finished side effects.
MitigationMake writes idempotent, move long work to asynchronous patterns and size lifetime settings from measured runs.
Secrets baked into the container
Early signalAPI keys turn up in environment variables, image layers or logs.
MitigationFetch credentials through Identity at call time and scan images before every release.
Framework internals invisible in traces
Early signalA trace shows one long span for the whole graph run.
MitigationAdd a span per node and per tool call, redacting inputs where needed.
Direct invocations that skip Policy
Early signalSome clients call the runtime endpoint instead of going through the gateway.
MitigationLock runtime invocation to the gateway and alert on any direct call.
Questions and answers
Can I test an AgentCore agent locally before deploying it?
Yes. Runtime hosts a container that implements a documented HTTP contract, so you can run the same image locally and send requests to its invocations path before deploying1. The AgentCore CLI also scaffolds projects and invokes deployed agents. Local runs will not reproduce gateway policies or identity flows, so keep a cloud test environment for those.
How does a Runtime-hosted agent reach systems inside our VPC?
Runtime supports VPC networking, so sessions can reach private endpoints such as internal APIs or databases9. Agree subnets, security groups, VPC endpoints for AWS services and DNS with your platform team before deployment, and keep tool traffic going through Gateway wherever Policy should apply.
What if a task runs longer than an AgentCore session allows?
On the default microVM compute a session can run for up to eight hours, and the Instances compute type supports sessions of up to fourteen days on AWS-managed EC2 capacity7. For work that is merely slow, an asynchronous pattern that returns a job reference and stores progress is usually cleaner than holding a session open.
Does a CrewAI agent need anything different from a LangGraph agent?
Not from Runtime's point of view: both are framework code behind the same entrypoint, and AWS lists both as supported7. The differences are inside the agent: where each framework keeps state, how it calls tools and where you add tracing spans. Map those three points explicitly when moving either framework onto AgentCore Memory, Gateway and Observability.
Sources
- Understand the AgentCore Runtime service contract — Amazon Web Services · checked 10 October 2026
- Authenticate and authorize with Inbound Auth and Outbound Auth — Amazon Web Services · checked 10 October 2026
- Amazon Bedrock AgentCore Gateway — Amazon Web Services · checked 10 October 2026
- Add memory to your Amazon Bedrock AgentCore agent — Amazon Web Services · checked 10 October 2026
- Observe your agent applications on Amazon Bedrock AgentCore Observability — Amazon Web Services · checked 10 October 2026
- Policy in Amazon Bedrock AgentCore: Control Agent Interactions — Amazon Web Services · checked 10 October 2026
- Host agent or tools with Amazon Bedrock AgentCore Runtime — Amazon Web Services · checked 10 October 2026
- Amazon Bedrock AgentCore Evaluations is now generally available — Amazon Web Services · checked 10 October 2026
- AgentCore harness vs. Runtime — Amazon Web Services · checked 10 October 2026