AWS Bedrock
التشغيل عبر AWS Bedrock
What this page is, and what it holds.
This page covers AWS Bedrock. You will use hermes model and hermes chat here; about 5 minutes to read. The priciest model is not always best for your task. Compare on one task and set a spend cap.
Use Hermes Agent with Amazon Bedrock — native Converse API, IAM authentication, Guardrails, and cross-region inference
Outcomes taken from this page, not a template.
- Understand what المزوّد والنموذج is and when you need it.
- Run
hermes modelandhermes chatand understand what happens next. - Read the table and take only the row that applies to you.
- Set
AWS_ACCESS_KEY_IDin the right place.
Exactly as they appear in Hermes.
hermes modelhermes chathermes doctor
AWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYAWS_PROFILEAWS_REGIONAWS_DEFAULT_REGIONAWS_BEARER_TOKEN_BEDROCK
Jump to the part you need.
Nothing summarised away.
The documentation body below is reproduced from the official source so commands and identifiers stay exact. Each section carries a short note describing what it contains.
Hermes Agent supports Amazon Bedrock as a native provider using the Converse API — not the OpenAI-compatible endpoint. This gives you full access to the Bedrock ecosystem: IAM authentication, Guardrails, cross-region inference profiles, and all foundation models.
Prerequisites
Settings you configure once. Change one at a time so you can see what each does. Set AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY in your environment, not in the chat.
- AWS credentials — any source supported by the boto3 credential chain ↗:
- IAM instance role (EC2, ECS, Lambda — zero config)
AWS_ACCESS_KEY_ID+AWS_SECRET_ACCESS_KEYenvironment variablesAWS_PROFILEfor SSO or named profilesaws configurefor local development- boto3 — install with
cd ~/.hermes/hermes-agent && uv pip install -e ".[bedrock]" - IAM permissions — at minimum:
bedrock:InvokeModelandbedrock:InvokeModelWithResponseStream(for inference)bedrock:ListFoundationModelsandbedrock:ListInferenceProfiles(for model discovery)
Quick Start
Ordered, practical steps. Run one and confirm it worked before moving on. Commands here: hermes chat, hermes model.
# Install with Bedrock support
cd ~/.hermes/hermes-agent && uv pip install -e ".[bedrock]"
# Select Bedrock as your provider
hermes model
# → Choose "More providers..." → "AWS Bedrock"
# → Select your region and model
# Start chatting
hermes chatConfiguration
Settings you configure once. Change one at a time so you can see what each does. Commands here: hermes model. Set AWS_REGION, AWS_DEFAULT_REGION in your environment, not in the chat.
After running hermes model, your ~/.hermes/config.yaml will contain:
model:
default: us.anthropic.claude-sonnet-4-6
provider: bedrock
base_url: https://bedrock-runtime.us-east-2.amazonaws.com
bedrock:
region: us-east-2Region
Set the AWS region in any of these ways (highest priority first):
bedrock.regioninconfig.yamlAWS_REGIONenvironment variableAWS_DEFAULT_REGIONenvironment variable- Default:
us-east-1
Guardrails
To apply Amazon Bedrock Guardrails ↗ to all model invocations:
bedrock:
region: us-east-2
guardrail:
guardrail_identifier: "abc123def456" # From the Bedrock console
guardrail_version: "1" # Version number or "DRAFT"
stream_processing_mode: "async" # "sync" or "async"
trace: "disabled" # "enabled", "disabled", or "enabled_full"Model Discovery
Hermes auto-discovers available models via the Bedrock control plane. You can customize discovery:
bedrock:
discovery:
enabled: true
provider_filter: ["anthropic", "amazon"] # Only show these providers
refresh_interval: 3600 # Cache for 1 hourPrompt caching (cachePoint)
Hermes automatically applies prompt caching on the Bedrock Converse API path by inserting cachePoint markers after the system prompt, tool definitions, and the latest message. Because sending a cachePoint block to a model that doesn't support it raises a ValidationException, markers are only added for models on a known-good allowlist (Anthropic Claude and Amazon Nova model IDs); unknown models default to no cache markers. Claude models normally use the AnthropicBedrock SDK path, which has its own prompt caching — the Converse cachePoint path covers Nova and the bearer-token Claude fallback. No configuration needed; cache reads/writes show up in usage accounting.
Context-window probing
For models whose context window isn't in Hermes' static table, Hermes can probe the real limit by sending oversized requests at fixed tiers (~1.3M and ~2.2M tokens) and parsing the maximum reported in Bedrock's length-validation error. Probed values feed the same metadata cache as the static table; stale cached entries that under-report a model's window (e.g. entries seeded before a model's 1M window went GA) are dropped automatically in favor of the larger known value.
Available Models
A lookup table. Do not read it all; find the row that applies to you. Commands here: hermes model.
Bedrock models use inference profile IDs for on-demand invocation. The hermes model picker shows these automatically, with recommended models at the top:
| Model | ID | Notes |
|---|---|---|
| Claude Sonnet 4.6 | us.anthropic.claude-sonnet-4-6 | Recommended — best balance of speed and capability |
| Claude Opus 4.6 | us.anthropic.claude-opus-4-6-v1 | Most capable |
| Claude Haiku 4.5 | us.anthropic.claude-haiku-4-5-20251001-v1:0 | Fastest Claude |
| Amazon Nova Pro | us.amazon.nova-pro-v1:0 | Amazon's flagship |
| Amazon Nova Micro | us.amazon.nova-micro-v1:0 | Fastest, cheapest |
| DeepSeek V3.2 | deepseek.v3.2 | Strong open model |
| Llama 4 Scout 17B | us.meta.llama4-scout-17b-instruct-v1:0 | Meta's latest |
Switching Models Mid-Session
Explains the idea itself. Read it slowly; the later sections build on it.
Use the /model command during a conversation:
/model us.amazon.nova-pro-v1:0
/model deepseek.v3.2
/model us.anthropic.claude-opus-4-6-v1Diagnostics
Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes doctor.
hermes doctorThe doctor checks:
- Whether AWS credentials are available (env vars, IAM role, SSO)
- Whether
boto3is installed - Whether the Bedrock API is reachable (ListFoundationModels)
- Number of available models in your region
Gateway (Messaging Platforms)
Explains the idea itself. Read it slowly; the later sections build on it.
Bedrock works with all Hermes gateway platforms (Telegram, Discord, Slack, Feishu, etc.). Configure Bedrock as your provider, then start the gateway normally:
hermes gateway setup
hermes gateway startThe gateway reads config.yaml and uses the same Bedrock provider configuration.
Troubleshooting
A troubleshooting section. Find the symptom that matches yours rather than reading it end to end.
"No API key found" / "No AWS credentials"
Hermes checks for credentials in this order:
AWS_BEARER_TOKEN_BEDROCKAWS_ACCESS_KEY_ID+AWS_SECRET_ACCESS_KEYAWS_PROFILE- EC2 instance metadata (IMDS)
- ECS container credentials
- Lambda execution role
If none are found, run aws configure or attach an IAM role to your compute instance.
"Invocation of model ID ... with on-demand throughput isn't supported"
Use an inference profile ID (prefixed with us. or global.) instead of the bare foundation model ID. For example:
- ❌
anthropic.claude-sonnet-4-6 - ✅
us.anthropic.claude-sonnet-4-6
"ThrottlingException"
You've hit the Bedrock per-model rate limit. Hermes automatically retries with backoff. To increase limits, request a quota increase in the AWS Service Quotas console ↗.
One-Click AWS Deployment
Explains the idea itself. Read it slowly; the later sections build on it.
For a fully automated deployment on EC2 with CloudFormation:
sample-hermes-agent-on-aws-with-bedrock ↗ — creates VPC, IAM role, EC2 instance, and configures Bedrock automatically. Deploy in any region with one click.
4 questions answered by this page alone.
Every option is a real identifier from the Hermes documentation. The wrong ones are real too, just from other pages.