[{"data":1,"prerenderedAt":106},["ShallowReactive",2],{"pattern-lambda-microvms-multi-tenant-ai-agents":3},{"id":4,"title":5,"architectureURL":6,"cleanup":7,"contributors":10,"deploy":12,"description":17,"extension":18,"framework":19,"gitHub":20,"highlight":6,"introBox":26,"language":34,"level":35,"meta":36,"patternArch":38,"resources":79,"s3URL":6,"services":93,"stem":99,"testing":100,"videoId":6,"__hash__":105},"patterns\u002Fpatterns\u002Flambda-microvms-multi-tenant-ai-agents.json","Multi-tenant AI agents on AWS Lambda MicroVMs",null,{"text":8},[9],".\u002Fteardown.sh \u003Cregion> \u003Cstack-name>",[11],"content\u002Fcontributors\u002Fshawn-zhang.json",{"headline":13,"text":14},"Deploy the pattern",[15,16],".\u002Fdeploy.sh \u003Cregion> \u003Cstack-name>",".\u002Fadd-tenant.sh \u003Cregion> \u003Cstack-name> tenant1","A self-hosted AI agent in one isolated Lambda MicroVM per tenant, with per-tenant state on Amazon EFS, Amazon Bedrock over a VPC endpoint; an orchestrator reaps idle VMs.","json","AWS CLI",{"template":21},{"repoURL":22,"templateURL":23,"projectFolder":24,"templateFile":25},"https:\u002F\u002Fgithub.com\u002Faws-samples\u002Fserverless-patterns\u002Ftree\u002Fmain\u002Flambda-microvms-multi-tenant-ai-agents","serverless-patterns\u002Flambda-microvms-multi-tenant-ai-agents","lambda-microvms-multi-tenant-ai-agents","template.yaml",{"headline":27,"text":28},"How it works",[29,30,31,32,33],"Each tenant gets a dedicated Firecracker micro-VM running their AI agent. Tenant isolation is a hard security boundary, not a shared runtime with guardrails bolted on.","A single CloudFormation template declares the full stack: VPC with EFS, Bedrock VPC endpoints, NAT egress, the MicroVM image (built server-side, no local Docker), a DynamoDB tenant registry, an orchestrator Lambda behind API Gateway, and an EventBridge sweeper. You upload two zip artifacts and run one deploy.","When a message arrives, the orchestrator checks the tenant registry. If the tenant's VM is suspended it resumes from snapshot in seconds with memory intact. If it's cold, a fresh VM launches, mounts the tenant's EFS subdirectory, and picks up where it left off. Warm turns complete in about two seconds.","The agent calls Bedrock through a VPC endpoint using temporary credentials from IMDSv2. Available models are discovered live at cold start so new models work without redeploying. All tenant state (config and conversation memory) lives on EFS and survives suspend, resume, and the 8-hour VM lifetime limit.","An EventBridge sweeper runs every 10 minutes, terminating idle VMs and reconciling the registry. Tenants flow from hot (running) to warm (suspended, barely billed) to cold (terminated, state parked on EFS at near-zero cost). You pay for conversations, not for waiting.","Python","300",{"patternType":37},"Serverless",{"icon1":39,"icon2":44,"icon3":49,"icon4":52,"icon5":56,"icon6":60,"icon7":63,"line1":66,"line2":69,"line3":71,"line4":73,"line5":75,"line6":77},{"x":40,"y":41,"service":42,"label":43},15,22,"apigw","Amazon API Gateway",{"x":45,"y":46,"service":47,"label":48},40,48,"lambda","Orchestrator Lambda",{"x":50,"y":41,"service":47,"label":51},64,"Tenant MicroVM",{"x":53,"y":41,"service":54,"label":55},88,"bedrock","Amazon Bedrock",{"x":53,"y":57,"service":58,"label":59},68,"efs","Amazon EFS",{"x":50,"y":57,"service":61,"label":62},"dynamodb","Tenant Registry",{"x":40,"y":57,"service":64,"label":65},"eventbridge","Sweeper",{"from":67,"to":68},"icon1","icon2",{"from":68,"to":70},"icon3",{"from":70,"to":72},"icon4",{"from":70,"to":74},"icon5",{"from":68,"to":76},"icon6",{"from":78,"to":68},"icon7",{"bullets":80},[81,84,87,90],{"text":82,"link":83},"AWS Lambda MicroVMs Documentation","https:\u002F\u002Fdocs.aws.amazon.com\u002Flambda\u002Flatest\u002Fdg\u002Flambda-microvms.html",{"text":85,"link":86},"Firecracker - Secure and fast microVMs for serverless computing","https:\u002F\u002Faws.amazon.com\u002Fblogs\u002Fopensource\u002Ffirecracker-open-source-secure-fast-microvm-serverless\u002F",{"text":88,"link":89},"Amazon Bedrock Documentation","https:\u002F\u002Fdocs.aws.amazon.com\u002Fbedrock\u002Flatest\u002Fuserguide\u002Fwhat-is-bedrock.html",{"text":91,"link":92},"Amazon EFS Documentation","https:\u002F\u002Fdocs.aws.amazon.com\u002Fefs\u002Flatest\u002Fug\u002Fwhatisefs.html",{"from":94,"to":96},{"serviceName":43,"serviceURL":95},"\u002Fapi-gateway\u002F",{"serviceName":97,"serviceURL":98},"AWS Lambda","\u002Flambda\u002F","patterns\u002Flambda-microvms-multi-tenant-ai-agents",{"text":101},[102,103,104],".\u002Fchat.sh \u003Cregion> \u003Cstack-name> tenant1 \"Remember my lucky number is 7777.\"",".\u002Fchat.sh \u003Cregion> \u003Cstack-name> tenant1 \"What's my lucky number?\"","See the README for cross-generation persistence and tenant-isolation tests.","DcUWpFAypNCQkHoUkC8XfGVkaWyzOKD3b4adsakD3j8",1785321313011]