Academy → Practical GuidesOfficial documentation · Arabic guidance

AWS Bedrock

التشغيل عبر AWS Bedrock

Intermediate5 min readLesson 204 questions✓ 2026-08-18
Before you read

What this page is, and what it holds.

This page covers AWS Bedrock. You will use hermes model and hermes chat here; about 5 minutes to read. The priciest model is not always best for your task. Compare on one task and set a spend cap.

9sections
7code examples
1tables
3commands
808source words
The official one-line description

Use Hermes Agent with Amazon Bedrock — native Converse API, IAM authentication, Guardrails, and cross-region inference

What you will be able to do

Outcomes taken from this page, not a template.

  • Understand what المزوّد والنموذج is and when you need it.
  • Run hermes model and hermes chat and understand what happens next.
  • Read the table and take only the row that applies to you.
  • Set AWS_ACCESS_KEY_ID in the right place.
Identifiers you will meet

Exactly as they appear in Hermes.

Commands
  • hermes model
  • hermes chat
  • hermes doctor
Environment variables
  • AWS_ACCESS_KEY_ID
  • AWS_SECRET_ACCESS_KEY
  • AWS_PROFILE
  • AWS_REGION
  • AWS_DEFAULT_REGION
  • AWS_BEARER_TOKEN_BEDROCK
Page map

Jump to the part you need.

  1. 01Prerequisites
  2. 02Quick Start
  3. 03Configuration
  4. 04Available Models
  5. 05Switching Models Mid-Session
  6. 06Diagnostics
  7. 07Gateway (Messaging Platforms)
  8. 08Troubleshooting
  9. 09One-Click AWS Deployment
The full official page

Nothing summarised away.

The documentation body below is reproduced from the official source so commands and identifiers stay exact. Each section carries a short note describing what it contains.

Hermes Agent supports Amazon Bedrock as a native provider using the Converse API — not the OpenAI-compatible endpoint. This gives you full access to the Bedrock ecosystem: IAM authentication, Guardrails, cross-region inference profiles, and all foundation models.

Prerequisites

Settings you configure once. Change one at a time so you can see what each does. Set AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY in your environment, not in the chat.

  • AWS credentials — any source supported by the boto3 credential chain ↗:
  • IAM instance role (EC2, ECS, Lambda — zero config)
  • AWS_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY environment variables
  • AWS_PROFILE for SSO or named profiles
  • aws configure for local development
  • boto3 — install with cd ~/.hermes/hermes-agent && uv pip install -e ".[bedrock]"
  • IAM permissions — at minimum:
  • bedrock:InvokeModel and bedrock:InvokeModelWithResponseStream (for inference)
  • bedrock:ListFoundationModels and bedrock:ListInferenceProfiles (for model discovery)

Quick Start

Ordered, practical steps. Run one and confirm it worked before moving on. Commands here: hermes chat, hermes model.

Shell10 lines
# Install with Bedrock support
cd ~/.hermes/hermes-agent && uv pip install -e ".[bedrock]"

# Select Bedrock as your provider
hermes model
# → Choose "More providers..." → "AWS Bedrock"
# → Select your region and model

# Start chatting
hermes chat

Configuration

Settings you configure once. Change one at a time so you can see what each does. Commands here: hermes model. Set AWS_REGION, AWS_DEFAULT_REGION in your environment, not in the chat.

After running hermes model, your ~/.hermes/config.yaml will contain:

YAML7 lines
model:
  default: us.anthropic.claude-sonnet-4-6
  provider: bedrock
  base_url: https://bedrock-runtime.us-east-2.amazonaws.com

bedrock:
  region: us-east-2

Region

Set the AWS region in any of these ways (highest priority first):

  1. bedrock.region in config.yaml
  2. AWS_REGION environment variable
  3. AWS_DEFAULT_REGION environment variable
  4. Default: us-east-1

Guardrails

To apply Amazon Bedrock Guardrails ↗ to all model invocations:

YAML7 lines
bedrock:
  region: us-east-2
  guardrail:
    guardrail_identifier: "abc123def456"  # From the Bedrock console
    guardrail_version: "1"                # Version number or "DRAFT"
    stream_processing_mode: "async"       # "sync" or "async"
    trace: "disabled"                     # "enabled", "disabled", or "enabled_full"

Model Discovery

Hermes auto-discovers available models via the Bedrock control plane. You can customize discovery:

YAML5 lines
bedrock:
  discovery:
    enabled: true
    provider_filter: ["anthropic", "amazon"]  # Only show these providers
    refresh_interval: 3600                     # Cache for 1 hour

Prompt caching (cachePoint)

Hermes automatically applies prompt caching on the Bedrock Converse API path by inserting cachePoint markers after the system prompt, tool definitions, and the latest message. Because sending a cachePoint block to a model that doesn't support it raises a ValidationException, markers are only added for models on a known-good allowlist (Anthropic Claude and Amazon Nova model IDs); unknown models default to no cache markers. Claude models normally use the AnthropicBedrock SDK path, which has its own prompt caching — the Converse cachePoint path covers Nova and the bearer-token Claude fallback. No configuration needed; cache reads/writes show up in usage accounting.

Context-window probing

For models whose context window isn't in Hermes' static table, Hermes can probe the real limit by sending oversized requests at fixed tiers (~1.3M and ~2.2M tokens) and parsing the maximum reported in Bedrock's length-validation error. Probed values feed the same metadata cache as the static table; stale cached entries that under-report a model's window (e.g. entries seeded before a model's 1M window went GA) are dropped automatically in favor of the larger known value.

Available Models

A lookup table. Do not read it all; find the row that applies to you. Commands here: hermes model.

Bedrock models use inference profile IDs for on-demand invocation. The hermes model picker shows these automatically, with recommended models at the top:

ModelIDNotes
Claude Sonnet 4.6us.anthropic.claude-sonnet-4-6Recommended — best balance of speed and capability
Claude Opus 4.6us.anthropic.claude-opus-4-6-v1Most capable
Claude Haiku 4.5us.anthropic.claude-haiku-4-5-20251001-v1:0Fastest Claude
Amazon Nova Prous.amazon.nova-pro-v1:0Amazon's flagship
Amazon Nova Microus.amazon.nova-micro-v1:0Fastest, cheapest
DeepSeek V3.2deepseek.v3.2Strong open model
Llama 4 Scout 17Bus.meta.llama4-scout-17b-instruct-v1:0Meta's latest

Switching Models Mid-Session

Explains the idea itself. Read it slowly; the later sections build on it.

Use the /model command during a conversation:

Text3 lines
/model us.amazon.nova-pro-v1:0
/model deepseek.v3.2
/model us.anthropic.claude-opus-4-6-v1

Diagnostics

Commands you type in a terminal. Understand what one does before copying it. Commands here: hermes doctor.

Shell1 line
hermes doctor

The doctor checks:

  • Whether AWS credentials are available (env vars, IAM role, SSO)
  • Whether boto3 is installed
  • Whether the Bedrock API is reachable (ListFoundationModels)
  • Number of available models in your region

Gateway (Messaging Platforms)

Explains the idea itself. Read it slowly; the later sections build on it.

Bedrock works with all Hermes gateway platforms (Telegram, Discord, Slack, Feishu, etc.). Configure Bedrock as your provider, then start the gateway normally:

Shell2 lines
hermes gateway setup
hermes gateway start

The gateway reads config.yaml and uses the same Bedrock provider configuration.

Troubleshooting

A troubleshooting section. Find the symptom that matches yours rather than reading it end to end.

"No API key found" / "No AWS credentials"

Hermes checks for credentials in this order:

  1. AWS_BEARER_TOKEN_BEDROCK
  2. AWS_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY
  3. AWS_PROFILE
  4. EC2 instance metadata (IMDS)
  5. ECS container credentials
  6. Lambda execution role

If none are found, run aws configure or attach an IAM role to your compute instance.

"Invocation of model ID ... with on-demand throughput isn't supported"

Use an inference profile ID (prefixed with us. or global.) instead of the bare foundation model ID. For example:

  • ❌ anthropic.claude-sonnet-4-6
  • ✅ us.anthropic.claude-sonnet-4-6

"ThrottlingException"

You've hit the Bedrock per-model rate limit. Hermes automatically retries with backoff. To increase limits, request a quota increase in the AWS Service Quotas console ↗.

One-Click AWS Deployment

Explains the idea itself. Read it slowly; the later sections build on it.

For a fully automated deployment on EC2 with CloudFormation:

sample-hermes-agent-on-aws-with-bedrock ↗ — creates VPC, IAM role, EC2 instance, and configures Bedrock automatically. Deploy in any region with one click.

Knowledge check

4 questions answered by this page alone.

Every option is a real identifier from the Hermes documentation. The wrong ones are real too, just from other pages.

1. In this lesson's table, what is the “ID” for “Amazon Nova Pro”?
2. Which of these environment variables actually appears in this lesson?
3. Which of these headings does not appear in this lesson?
4. Which configuration key appears in this lesson's examples?