[{"data":1,"prerenderedAt":70},["ShallowReactive",2],{"pattern-waf-agentcore-gateway-bedrock-cdk":3},{"id":4,"title":5,"architectureURL":6,"cleanup":7,"contributors":10,"deploy":12,"description":17,"extension":18,"framework":19,"gitHub":20,"highlight":6,"introBox":26,"language":33,"level":34,"meta":35,"patternArch":36,"resources":54,"s3URL":6,"services":6,"stem":65,"testing":66,"videoId":6,"__hash__":69},"patterns\u002Fpatterns\u002Fwaf-agentcore-gateway-bedrock-cdk.json","AWS WAF Protection for Amazon Bedrock AgentCore Gateway",null,{"text":8},[9],"\u003Ccode>cdk destroy\u003C\u002Fcode>",[11],"content\u002Fcontributors\u002Fnithin-chandran-r.json",{"text":13},[14,15,16],"\u003Ccode>cd waf-agentcore-gateway-bedrock-cdk\u002Fcdk\u003C\u002Fcode>","\u003Ccode>npm install\u003C\u002Fcode>","\u003Ccode>cdk deploy\u003C\u002Fcode>","Deploy AWS WAF with rate limiting, managed rules, and bot control to protect an Amazon Bedrock AgentCore Gateway routing tool calls to AWS Lambda and Amazon Bedrock","json","AWS CDK",{"template":21},{"repoURL":22,"templateURL":23,"projectFolder":24,"templateFile":25},"https:\u002F\u002Fgithub.com\u002Faws-samples\u002Fserverless-patterns\u002Ftree\u002Fmain\u002Fwaf-agentcore-gateway-bedrock-cdk","serverless-patterns\u002Fwaf-agentcore-gateway-bedrock-cdk","waf-agentcore-gateway-bedrock-cdk","cdk\u002Flib\u002Fwaf-agentcore-gateway-bedrock-stack.ts",{"headline":27,"text":28},"How it works",[29,30,31,32],"This pattern deploys an AWS WAF WebACL that protects an Amazon Bedrock AgentCore Gateway from common web exploits and abuse.","The WebACL includes rate-based rules (100 requests per 5 minutes per IP), AWS Managed Rules for common threats and known bad inputs, Bot Control for detecting automated traffic, and an IP allowlist for trusted agents.","The AgentCore Gateway uses the MCP protocol to route tool invocations to an AWS Lambda function that invokes Amazon Bedrock Claude Sonnet 4.6 for AI inference.","All AWS WAF decisions are logged to Amazon CloudWatch Logs for security monitoring and incident response.","TypeScript","300",{},{"icon1":37,"icon2":42,"icon3":45,"line1":49,"line2":52},{"x":38,"y":39,"service":40,"label":41},20,50,"waf","AWS WAF",{"x":39,"y":39,"service":43,"label":44},"bedrock-agentcore","AgentCore Gateway",{"x":46,"y":39,"service":47,"label":48},80,"lambda","AWS Lambda",{"from":50,"to":51},"icon1","icon2",{"from":51,"to":53},"icon3",{"bullets":55},[56,59,62],{"text":57,"link":58},"AWS WAF Developer Guide - Protecting resources","https:\u002F\u002Fdocs.aws.amazon.com\u002Fwaf\u002Flatest\u002Fdeveloperguide\u002Fhow-aws-waf-works-resources.html",{"text":60,"link":61},"Amazon Bedrock AgentCore Gateway documentation","https:\u002F\u002Fdocs.aws.amazon.com\u002Fbedrock-agentcore\u002Flatest\u002Fdevguide\u002Fgateway.html",{"text":63,"link":64},"AWS WAF rate-based rules","https:\u002F\u002Fdocs.aws.amazon.com\u002Fwaf\u002Flatest\u002Fdeveloperguide\u002Fwaf-rule-statement-type-rate-based.html","patterns\u002Fwaf-agentcore-gateway-bedrock-cdk",{"text":67},[68],"Invoke the AWS Lambda tool to verify Amazon Bedrock connectivity and check AWS WAF metrics in Amazon CloudWatch.","zTKAjVO8iDsnDzpK0UiqyZhuKno5sRAotSmZ1WysUj0",1785321315465]