# Deploying to AWS GovCloud Regions: A Complete Guide for the GenAI IDP Accelerator

> Deploy GenAI IDP Accelerator to AWS GovCloud. Learn specific considerations, partition-aware ARNs, and compatible service endpoints for a secure deployment.

- Repository: [aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws)
- Tags: how-to-guide
- Published: 2026-02-25

---

**Deploying the GenAI IDP Accelerator to AWS GovCloud requires using partition-aware ARNs with `${AWS::Partition}`, substituting `${AWS::URLSuffix}` for service endpoints, removing unsupported services like AppSync and CloudFront, and specifying GovCloud-compatible Bedrock model IDs.**

The aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws repository provides full support for AWS GovCloud (US) regions, but deploying to these isolated partitions requires specific architectural adjustments. Unlike commercial regions that use the standard `aws` partition, GovCloud operates under the `aws-us-gov` partition, affecting every ARN, service principal, and endpoint URL throughout the infrastructure.

## Architecture Adjustments for AWS GovCloud Deployment

### ARN Partition Compatibility

All resource identifiers must use the `${AWS::Partition}` intrinsic function instead of hard-coded `arn:aws:` prefixes. In [`template.yaml`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/template.yaml), the KMS key policy demonstrates this pattern at lines 1518-1522:

```yaml
Principal:
  AWS: !Sub "arn:${AWS::Partition}:iam::${AWS::AccountId}:root"

```

This substitution ensures the template resolves to `arn:aws-us-gov:` in GovCloud regions while maintaining compatibility with commercial partitions.

### Service Principal URL Suffixes

GovCloud uses the `amazonaws.com.gov` domain suffix instead of `amazonaws.com`. The template must reference `${AWS::URLSuffix}` for service principals affecting DynamoDB, CloudWatch Logs, and the S3 Vectors indexing service. The KMS key policy at [`template.yaml`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/template.yaml) lines 1519-1565 implements this for the S3 Vectors indexing principal:

```yaml
- Sid: Allow S3 Vectors indexing service
  Effect: Allow
  Principal:
    Service: !Sub "indexing.s3vectors.${AWS::URLSuffix}"

```

### Removed Services and Features

The GovCloud deployment automatically excludes services unavailable in isolated partitions. According to [`docs/govcloud-deployment.md`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/docs/govcloud-deployment.md), the following components are stripped from the GovCloud-specific template:

- **AppSync** (GraphQL API layer)
- **CloudFront** (CDN distribution)
- **WAF** (Web Application Firewall)
- **Cognito UI** (Managed login interface)

This creates a "headless" deployment architecture suitable for GovCloud compliance requirements.

### Bedrock Model ID Constraints

GovCloud supports only specific Amazon Bedrock foundation models. The accelerator ships GovCloud-specific configuration libraries that pin supported IDs such as:

- `amazon.nova-pro-v1:0`
- `anthropic.claude-3-7-sonnet-20250219-v1:0`

Reference these configurations in [`config_library/pattern-2/lending-package-sample-govcloud/config.yaml`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/config_library/pattern-2/lending-package-sample-govcloud/config.yaml) or the Pattern-1 equivalent when deploying to GovCloud regions.

## Required ARN Formats for GovCloud Parameters

The main CloudFormation template enforces ARN patterns through `AllowedPattern` constraints. When deploying to GovCloud, ensure your parameter values conform to these partition-aware formats:

| Parameter | Expected Pattern | GovCloud Example |
|-----------|------------------|------------------|
| **Lambda Layer ARN** | `arn:aws[a-z-]*:lambda:…` | `arn:${AWS::Partition}:lambda:us-gov-west-1:123456789012:layer:my-layer:1` |
| **IAM Policy ARN** | `arn:aws[a-z-]*:iam::[0-9]{12}:policy/.+` | `arn:${AWS::Partition}:iam::123456789012:policy/MyGovCloudPolicy` |
| **KMS Key ARN** | `arn:aws[a-z-]*:kms:…` | `arn:${AWS::Partition}:kms:us-gov-west-1:123456789012:key/abcd-ef12-3456-7890-abcd` |
| **Bedrock Model ARN** | `arn:aws[a-z-]*:bedrock:…` | `arn:${AWS::Partition}:bedrock:us-gov-west-1::model/amazon.nova-pro-v1:0` |

The `AllowedPattern` for IAM policy ARNs appears at line 122 of [`template.yaml`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/template.yaml) in the nested `bedrockkb` template, ensuring strict validation of partition formats.

## Step-by-Step Deployment Process

Follow this sequence to deploy the accelerator in AWS GovCloud regions:

1. **Generate the GovCloud-compatible template** using the provided script:

   ```bash
   python scripts/generate_govcloud_template.py my-govcloud-bucket my-prefix us-gov-west-1
   ```

   This script builds SAM artifacts, strips unavailable services, and rewrites ARNs to use `${AWS::Partition}`.

2. **Verify the generated template** exists in your S3 bucket at the location output by the script.

3. **Deploy via CloudFormation** with partition-aware parameter values:

   ```bash
   aws cloudformation deploy \
     --template-file .aws-sam/idp-govcloud.yaml \
     --s3-bucket my-govcloud-bucket \
     --stack-name my-idp-govcloud \
     --region us-gov-west-1 \
     --parameter-overrides \
         IDPPattern="Pattern2 - Packet processing with Textract and Bedrock" \
         ExistingKMSKeyArn="arn:${AWS::Partition}:kms:us-gov-west-1:123456789012:key/abcd-ef12-3456-7890-abcd"
   ```

4. **Confirm model ID compatibility** by referencing the GovCloud configuration files in [`config_library/pattern-2/lending-package-sample-govcloud/config.yaml`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/config_library/pattern-2/lending-package-sample-govcloud/config.yaml).

5. **Validate stack creation** ensures core resources (S3 buckets, DynamoDB tables, Step Functions, Lambda functions) deploy without errors related to partition mismatches.

6. **Test document processing** using the direct S3 upload method described in [`docs/govcloud-deployment.md`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/docs/govcloud-deployment.md), as the web UI components are unavailable in GovCloud.

## Key Configuration Files and Code References

| File Path | Significance for GovCloud |
|-----------|---------------------------|
| [`docs/govcloud-deployment.md`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/docs/govcloud-deployment.md) | Comprehensive guide covering removed services and deployment prerequisites. |
| [`template.yaml`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/template.yaml) | Contains KMS key policies with `${AWS::Partition}` and `${AWS::URLSuffix}` substitutions (lines 1518-1565). |
| [`scripts/generate_govcloud_template.py`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/scripts/generate_govcloud_template.py) | Automation script that creates GovCloud-compatible templates by rewriting ARNs and removing unsupported services. |
| [`config_library/pattern-2/lending-package-sample-govcloud/config.yaml`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/config_library/pattern-2/lending-package-sample-govcloud/config.yaml) | GovCloud-specific Bedrock model configurations. |
| [`config_library/pattern-1/lending-package-sample-govcloud/config.yaml`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/config_library/pattern-1/lending-package-sample-govcloud/config.yaml) | Pattern-1 GovCloud configuration reference. |
| [`nested/bedrockkb/template.yaml`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/nested/bedrockkb/template.yaml) | Shows `AllowedPattern` constraints for IAM policy ARNs (line 122). |

## Summary

Deploying to AWS GovCloud regions requires careful attention to partition-specific formatting:

- **Use `${AWS::Partition}`** in all ARN references to ensure compatibility with the `aws-us-gov` partition.
- **Reference `${AWS::URLSuffix}`** for service principals to resolve the correct `amazonaws.com.gov` endpoints.
- **Remove unsupported services** including AppSync, CloudFront, WAF, and Cognito UI via the [`generate_govcloud_template.py`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/generate_govcloud_template.py) script.
- **Specify GovCloud-compatible Bedrock models** such as `amazon.nova-pro-v1:0` using the provided configuration libraries.
- **Validate ARN patterns** against the `AllowedPattern` constraints in the CloudFormation templates.

## Frequently Asked Questions

### What is the difference between the commercial and GovCloud ARN formats?

The primary difference is the partition identifier. Commercial AWS regions use `arn:aws:` while AWS GovCloud (US) regions use `arn:aws-us-gov:`. The CloudFormation templates in this accelerator use the intrinsic function `${AWS::Partition}` to automatically resolve to the correct partition based on the deployment region, ensuring templates work in both environments without modification.

### Which services are removed when deploying to GovCloud?

The GovCloud deployment automatically excludes services that are either unavailable in isolated partitions or require additional compliance steps. According to [`docs/govcloud-deployment.md`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/docs/govcloud-deployment.md), these include **AppSync** (GraphQL APIs), **CloudFront** (CDN distributions), **WAF** (Web Application Firewall), and **Cognito UI** (managed login interfaces). The [`generate_govcloud_template.py`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/generate_govcloud_template.py) script handles this removal automatically.

### How do I specify Bedrock model IDs for GovCloud deployments?

GovCloud supports only a subset of Amazon Bedrock foundation models. You must use GovCloud-compatible model IDs such as `amazon.nova-pro-v1:0` or `anthropic.claude-3-7-sonnet-20250219-v1:0`. The accelerator provides GovCloud-specific configuration files in [`config_library/pattern-2/lending-package-sample-govcloud/config.yaml`](https://github.com/aws-solutions-library-samples/accelerated-intelligent-document-processing-on-aws/blob/main/config_library/pattern-2/lending-package-sample-govcloud/config.yaml) and the Pattern-1 equivalent, which pre-configure these supported model IDs for your deployment.