How to Configure Amazon Bedrock Models in OpenMAIC
Set BEDROCK_REGION and BEDROCK_MODELS as environment variables (or define a bedrock block in server-providers.yml) to enable the Bedrock provider; OpenMAIC then automatically activates it via applyBedrockProviderConfig in lib/server/provider-config.ts.
Configuring Amazon Bedrock models in OpenMAIC requires understanding that the platform treats providers as server-managed services with explicit opt-in. Unlike other providers that may auto-register, Bedrock is only activated when you supply configuration through environment variables or YAML. This guide walks through the exact mechanism, configuration options, and runnable examples drawn directly from the THU-MAIC/OpenMAIC source code.
Activation Mechanism: How Bedrock Gets Enabled
OpenMAIC's provider system gates Bedrock behind a deliberate activation check. The function applyBedrockProviderConfig in lib/server/provider-config.ts (lines 69–94) implements this logic:
const yamlBedrock = yamlProviders?.[BEDROCK_PROVIDER_ID]; // line 69
const envRegion = process.env.BEDROCK_REGION?.trim() || undefined; // line 72
const envModels = splitModels(process.env.BEDROCK_MODELS); // line 73
const hasExplicitBedrockEnv = !!envRegion || !!envModels || …; // lines 74-79
If no configuration source provides Bedrock details and BEDROCK_REGION is absent, the function returns early (lines 85–87), completely omitting the provider. This prevents accidental Bedrock usage.
When activated, the merged configuration lands in config.providers[BEDROCK_PROVIDER_ID] (lines 89–94), which the LLM factory in lib/ai/providers.ts consumes:
const bedrock = createAmazonBedrock({
region: resolveBedrockRegion(),
credentialProvider: createBedrockCredentialProvider(),
});
Configuration Methods
You can configure Bedrock models through environment variables (recommended for deployment) or YAML configuration (preferred for version-controlled setups).
Environment Variable Configuration
Set these variables in .env.local or your deployment environment:
| Variable | Purpose | Required? |
|---|---|---|
BEDROCK_REGION |
AWS region (e.g., us-east-1) |
Yes — enables provider |
BEDROCK_MODELS |
Comma-separated model IDs | Yes — defines available models |
BEDROCK_API_KEY |
Custom endpoint API key | Optional |
BEDROCK_BASE_URL |
Non-AWS endpoint URL | Optional |
AWS_BEARER_TOKEN_BEDROCK |
Bearer token credential | Optional |
# .env.local
BEDROCK_REGION=us-east-1
BEDROCK_MODELS=us.anthropic.claude-sonnet-5,us.anthropic.claude-opus-4-8
DEFAULT_MODEL=bedrock:us.anthropic.claude-sonnet-5
The splitModels function parses BEDROCK_MODELS into an array. Environment variables take precedence over YAML values when both are present.
YAML Configuration Alternative
Create or edit server-providers.yml for infrastructure-as-code setups:
# server-providers.yml
providers:
bedrock:
models:
- us.anthropic.claude-sonnet-5
- us.anthropic.claude-opus-4-8
# apiKey: your-key # optional
# baseUrl: https://... # optional
Note that BEDROCK_REGION in environment variables still activates the provider—YAML alone without any env var won't trigger hasExplicitBedrockEnv to true unless region is also specified in YAML.
Setting the Default Bedrock Model Client-Side
After server-side configuration, users can select Bedrock models. Set DEFAULT_MODEL with the bedrock: prefix:
DEFAULT_MODEL=bedrock:us.anthropic.claude-opus-4-8
Or programmatically in client components:
import { useModelStore } from '@/stores/model';
useModelStore.setState({ modelId: 'bedrock:us.anthropic.claude-opus-4-8' });
The model ID string follows the pattern bedrock:<model-id> where <model-id> matches an entry in your BEDROCK_MODELS list.
AWS Credential Handling
The createBedrockCredentialProvider function in lib/ai/providers.ts resolves credentials through:
- Standard AWS SDK credential chain (IAM roles,
~/.aws/credentials, etc.) - Optional
AWS_BEARER_TOKEN_BEDROCKenvironment variable for token-based auth
No additional configuration is required if your server runs with standard AWS credentials.
Complete Configuration Example
Here's a production-ready .env.local for OpenMAIC with Amazon Bedrock:
# Core Bedrock activation
BEDROCK_REGION=us-west-2
BEDROCK_MODELS=us.anthropic.claude-3-5-sonnet-20241022-v2:0,us.anthropic.claude-3-opus-20240229-v1:0
# Default model for new conversations
DEFAULT_MODEL=bedrock:us.anthropic.claude-3-5-sonnet-20241022-v2:0
# Optional: proxy configuration for VPC endpoint
# BEDROCK_BASE_URL=https://vpce-xxx.bedrock-runtime.us-west-2.vpce.amazonaws.com
# Optional: bearer token if not using standard AWS credentials
# AWS_BEARER_TOKEN_BEARROCK=eyJhbGc...
Key Source Files Reference
| File | Purpose |
|---|---|
lib/server/provider-config.ts |
applyBedrockProviderConfig — merges env/YAML and conditionally activates Bedrock |
lib/ai/providers.ts |
createAmazonBedrock — instantiates the Bedrock client with resolved config |
.env.example |
Template with Bedrock placeholders |
README.md |
AWS credential handling documentation |
Summary
- Enable first: Set
BEDROCK_REGIONto activate the provider viaapplyBedrockProviderConfig - Define models: Use
BEDROCK_MODELS(comma-separated) or YAMLproviders.bedrock.models - Precedence rules: Environment variables override YAML values
- Client selection: Prefix model IDs with
bedrock:inDEFAULT_MODELoruseModelStore - Credentials: Standard AWS SDK chain or
AWS_BEARER_TOKEN_BEDROCKfor custom auth
Frequently Asked Questions
What happens if I only set BEDROCK_MODELS without BEDROCK_REGION?
The Bedrock provider will not activate. The hasExplicitBedrockEnv check in lib/server/provider-config.ts (lines 74–79) requires envRegion to be truthy, or the function returns early at lines 85–87. You must set BEDROCK_REGION to enable Bedrock.
Can I use Bedrock with a custom endpoint or proxy?
Yes. Set BEDROCK_BASE_URL to your proxy URL and optionally BEDROCK_API_KEY for authentication. These merge into the provider configuration's baseUrl and apiKey fields, respectively, as handled in applyBedrockProviderConfig.
How do I switch between multiple Bedrock models in the UI?
Ensure all desired models are listed in BEDROCK_MODELS, then toggle via useModelStore.setState({ modelId: 'bedrock:<model-id>' }) or configure DEFAULT_MODEL for the initial selection. The UI populates available models from the server-managed provider list.
Does OpenMAIC support AWS SSO or temporary credentials?
Yes. The createBedrockCredentialProvider function uses the standard AWS SDK credential provider chain, which automatically handles SSO profiles, IAM roles, and temporary credentials from ~/.aws/credentials or environment variables.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →