Configure the Gateway
- Replicated
- Helm
- Open the Admin Console LLM configuration.
-
Select
AWS Bedrockand enter the AWS Region. -
Under
AWS Authentication Method, choose one of the Admin Console options:Access Key + Secret: enter theAWS Access Key IDand matchingAWS Secret Access Keyin their required fields.EC2 Instance Profile: attach an IAM role to the EC2 instance. In a containerized installation, set the instance metadata service (IMDS) response hop limit to at least 2 so the LiteLLM pod can reach it.
bedrock:InvokeModelandbedrock:InvokeModelWithResponseStreamfor every model you add. -
In
Bedrock Model IDs, enter one Bedrock model ID or inference profile ID per line. Enter the IDs as AWS provides them, without thebedrock/prefix. For example:The Admin Console creates a separate bundled-gateway model for each line. The first line becomes the installation default. Use IDs available to your account and selected Region; check each inference profile withaws bedrock get-inference-profilebefore adding it. - Save the configuration and deploy the updated version.
us. prefix in these examples. Your IAM policy must permit the profile and
its destination models. A standard model ID is Region-specific. The
Allow users to configure their own LLM providers (BYOK) checkbox controls
whether users can add personal providers; it is not required for these
administrator-managed Bedrock models.In the Replicated static-key configuration, the installer also passes the AWS
access key and secret into sandbox environments. With an EC2 instance profile,
sandboxes may also reach IMDS unless your network controls prevent that access;
a response hop limit of 2 does not isolate credentials to the gateway.
Scope the IAM identity for this deployment behavior rather than assuming that
only the LiteLLM pod can use it.
Select the Model in OpenHands
For a Replicated installation, select the Bedrock model configured in the Admin Console. For a Helm installation, create a profile inSettings → LLM
for each gateway alias you want users to select. For the first Helm example
above, use:
Use your installation’s actual LiteLLM Service name and namespace. The profile
points to the internal gateway, not to a Bedrock endpoint.
For the second Helm route, create another profile with Model
openhands/bedrock-sonnet-4-5 and the same Base URL.
Start Using the Model
- Select the Bedrock profile and start a new conversation.
- Ask the agent to run
pwd. - Confirm it starts a sandbox, runs the command, and replies with the output.
Troubleshooting
Bedrock AccessDeniedException
Bedrock AccessDeniedException
Check the IAM role annotation on the LiteLLM ServiceAccount, the role trust
policy’s exact namespace and ServiceAccount subject, and the role’s model
invocation policy. For a cross-Region inference profile, include its source
profile ARN and all destination model ARNs; check organization service control
policies for denied Regions.
Model or inference profile not found
Model or inference profile not found
Check the exact model or profile ID and
aws_region_name. A model available in
one Region may require an inference profile in another.The profile cannot reach the gateway
The profile cannot reach the gateway
Check the internal LiteLLM Service DNS name, namespace, and profile base URL.
Confirm the LiteLLM Deployment is ready and its logs show the Bedrock route.
The model answers a short prompt but the agent cannot work
The model answers a short prompt but the agent cannot work
Confirm the Bedrock model supports tool use and that its account quotas allow
larger agent prompts. Test a full conversation with a sandbox command, not
only a direct model completion.

