Dome Systems

Amazon Bedrock and Dome

Amazon Bedrock behind one Gateway, with every call governed.

Connect Bedrock to Dome with your AWS credentials and a region. Dome signs each call and sends it through the Converse API. Pool Bedrock behind Anthropic and agents keep working when one provider fails.

PeopleAgentsDomeBedrock modelsCallersPeopleAgentsresearch-agentAgentsdev-agentAgentssupport-agentGatewaysprod-gatewayClaude Opus 5.5us.anthropic.claude-opus-5-5Claude Sonnet 5.5us.anthropic.claude-sonnet-5-5Claude Haiku 4.5AWS account: prodRulesGuardsAuditsaudit-trail
research-agent→claude-opus-5-5· as p.nakamuraAllowed

How Dome helps

Dome provides model brokering and routing for Amazon Bedrock

AWS credentials stay in Dome

Access keys sit in Dome's vault and sign each request with SigV4. Agents never hold an AWS credential.

Bedrock as the second provider

Pool Claude on Bedrock behind Anthropic under one name. When Anthropic fails, the call goes to Bedrock.

Accounts kept apart

Tag each connection with the AWS account it bills to. A rule keeps development agents off production.

Get started

Connect Bedrock in three steps

Add the connection with your AWS keys, pool it, and point agents at the Gateway.

  1. 01

    Add it in the dashboard

    Choose Amazon Bedrock, then enter the AWS access key ID, secret access key, an optional session token, the region and the model id. Static AWS keys can only be set in the dashboard; the CLI has no flag for them.

  2. 02

    Pool it behind Anthropic

    Members are tried in priority order. Agents send the pool's name, and any OpenAI- or Anthropic-compatible client works.

    $ dome models pool create claude-sonnet-5-5 \
    --failover-max all --gateway prod-gateway
     
    $ dome models pool member add claude-sonnet-5-5 sonnet-55-anthropic --priority 0
    $ dome models pool member add claude-sonnet-5-5 sonnet-55-bedrock --priority 1

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Amazon Bedrock itself, see AWS's documentation.

Rules

Development agents stay off the production account

Tag each Bedrock connection with the AWS account it uses. Applied to a development agent with --agent, this refuses every connection tagged prod.

forbid (principal, action == Dome::Action::"llm:invoke", resource is Dome::LLMModel)
when { resource has aws_account && resource.aws_account == "prod" };

Agent workflow

Bringing it together

Connecting Amazon Bedrock to registered agents, tools, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

FAQ

Common questions

How does Dome authenticate to Amazon Bedrock?

With AWS access keys stored in Dome's vault, signed per request with SigV4.

Can I add AWS keys from the CLI?

No. Static AWS keys are set in the dashboard.

Which model id do I use?

The Bedrock model or inference profile id, such as us.anthropic.claude-sonnet-5-5. Dome sends it to the Converse API as given.

Do embeddings work on Bedrock connections?

No. Dome serves Bedrock chat through the Converse API; use another provider for embeddings.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.