Skip to main content
FluffBuzz can use Amazon Bedrock models via pi-ai’s Bedrock Converse streaming provider. Bedrock auth uses the AWS SDK default credential chain, not an API key.

Getting started

Choose your preferred auth method and follow the setup steps.
Best for: developer machines, CI, or hosts where you manage AWS credentials directly.
1

Set AWS credentials on the gateway host

2

Add a Bedrock provider and model to your config

No apiKey is required. Configure the provider with auth: "aws-sdk":
3

Verify models are available

With env-marker auth (AWS_ACCESS_KEY_ID, AWS_PROFILE, or AWS_BEARER_TOKEN_BEDROCK), FluffBuzz auto-enables the implicit Bedrock provider for model discovery without extra config.

Automatic model discovery

FluffBuzz can automatically discover Bedrock models that support streaming and text output. Discovery uses bedrock:ListFoundationModels and bedrock:ListInferenceProfiles, and results are cached (default: 1 hour). How the implicit provider is enabled:
  • If plugins.entries.amazon-bedrock.config.discovery.enabled is true, FluffBuzz will try discovery even when no AWS env marker is present.
  • If plugins.entries.amazon-bedrock.config.discovery.enabled is unset, FluffBuzz only auto-adds the implicit Bedrock provider when it sees one of these AWS auth markers: AWS_BEARER_TOKEN_BEDROCK, AWS_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY, or AWS_PROFILE.
  • The actual Bedrock runtime auth path still uses the AWS SDK default chain, so shared config, SSO, and IMDS instance-role auth can work even when discovery needed enabled: true to opt in.
For explicit models.providers["amazon-bedrock"] entries, FluffBuzz can still resolve Bedrock env-marker auth early from AWS env markers such as AWS_BEARER_TOKEN_BEDROCK without forcing full runtime auth loading. The actual model-call auth path still uses the AWS SDK default chain.
Config options live under plugins.entries.amazon-bedrock.config.discovery:

Quick setup (AWS path)

This walkthrough creates an IAM role, attaches Bedrock permissions, associates the instance profile, and enables FluffBuzz discovery on the EC2 host.

Advanced configuration

FluffBuzz discovers regional and global inference profiles alongside foundation models. When a profile maps to a known foundation model, the profile inherits that model’s capabilities (context window, max tokens, reasoning, vision) and the correct Bedrock request region is injected automatically. This means cross-region Claude profiles work without manual provider overrides.Inference profile IDs look like us.anthropic.claude-opus-4-6-v1:0 (regional) or anthropic.claude-opus-4-6-v1:0 (global). If the backing model is already in the discovery results, the profile inherits its full capability set; otherwise safe defaults apply.No extra configuration is needed. As long as discovery is enabled and the IAM principal has bedrock:ListInferenceProfiles, profiles appear alongside foundation models in fluffbuzz models list.
You can apply Amazon Bedrock Guardrails to all Bedrock model invocations by adding a guardrail object to the amazon-bedrock plugin config. Guardrails let you enforce content filtering, topic denial, word filters, sensitive information filters, and contextual grounding checks.
The IAM principal used by the gateway must have the bedrock:ApplyGuardrail permission in addition to the standard invoke permissions.
Bedrock can also serve as the embedding provider for memory search. This is configured separately from the inference provider — set agents.defaults.memorySearch.provider to "bedrock":
Bedrock embeddings use the same AWS SDK credential chain as inference (instance roles, SSO, access keys, shared config, and web identity). No API key is needed. When provider is "auto", Bedrock is auto-detected if that credential chain resolves successfully.Supported embedding models include Amazon Titan Embed (v1, v2), Amazon Nova Embed, Cohere Embed (v3, v4), and TwelveLabs Marengo. See Memory configuration reference — Bedrock for the full model list and dimension options.
  • Bedrock requires model access enabled in your AWS account/region.
  • Automatic discovery needs the bedrock:ListFoundationModels and bedrock:ListInferenceProfiles permissions.
  • If you rely on auto mode, set one of the supported AWS auth env markers on the gateway host. If you prefer IMDS/shared-config auth without env markers, set plugins.entries.amazon-bedrock.config.discovery.enabled: true.
  • FluffBuzz surfaces the credential source in this order: AWS_BEARER_TOKEN_BEDROCK, then AWS_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY, then AWS_PROFILE, then the default AWS SDK chain.
  • Reasoning support depends on the model; check the Bedrock model card for current capabilities.
  • If you prefer a managed key flow, you can also place an OpenAI-compatible proxy in front of Bedrock and configure it as an OpenAI provider instead.

Model selection

Choosing providers, model refs, and failover behavior.

Memory search

Bedrock embeddings for memory search configuration.

Memory config reference

Full Bedrock embedding model list and dimension options.

Troubleshooting

General troubleshooting and FAQ.