Skip to main content
OpenHands Enterprise can use Amazon Bedrock through its bundled LiteLLM gateway. Configure the gateway according to how you installed OpenHands. The Helm IRSA example assigns the Bedrock role to the LiteLLM ServiceAccount. Replicated uses the credential behavior described in its tab below.

Configure the Gateway

  1. Open the Admin Console LLM configuration.
  2. Select AWS Bedrock and enter the AWS Region.
  3. Under AWS Authentication Method, choose one of the Admin Console options:
    • Access Key + Secret: enter the AWS Access Key ID and matching AWS Secret Access Key in their required fields.
    • EC2 Instance Profile: attach an IAM role to the EC2 instance. In a containerized installation, set the instance metadata service (IMDS) response hop limit to at least 2 so the LiteLLM pod can reach it.
    Grant the chosen IAM identity bedrock:InvokeModel and bedrock:InvokeModelWithResponseStream for every model you add.
  4. In Bedrock Model IDs, enter one Bedrock model ID or inference profile ID per line. Enter the IDs as AWS provides them, without the bedrock/ prefix. For example:
    The Admin Console creates a separate bundled-gateway model for each line. The first line becomes the installation default. Use IDs available to your account and selected Region; check each inference profile with aws bedrock get-inference-profile before adding it.
  5. Save the configuration and deploy the updated version.
If you add a cross-Region inference profile, keep its full ID, including the us. prefix in these examples. Your IAM policy must permit the profile and its destination models. A standard model ID is Region-specific. The Allow users to configure their own LLM providers (BYOK) checkbox controls whether users can add personal providers; it is not required for these administrator-managed Bedrock models.
In the Replicated static-key configuration, the installer also passes the AWS access key and secret into sandbox environments. With an EC2 instance profile, sandboxes may also reach IMDS unless your network controls prevent that access; a response hop limit of 2 does not isolate credentials to the gateway. Scope the IAM identity for this deployment behavior rather than assuming that only the LiteLLM pod can use it.

Select the Model in OpenHands

For a Replicated installation, select the Bedrock model configured in the Admin Console. For a Helm installation, create a profile in Settings → LLM for each gateway alias you want users to select. For the first Helm example above, use: Use your installation’s actual LiteLLM Service name and namespace. The profile points to the internal gateway, not to a Bedrock endpoint. For the second Helm route, create another profile with Model openhands/bedrock-sonnet-4-5 and the same Base URL.

Start Using the Model

  1. Select the Bedrock profile and start a new conversation.
  2. Ask the agent to run pwd.
  3. Confirm it starts a sandbox, runs the command, and replies with the output.

Troubleshooting

Check the IAM role annotation on the LiteLLM ServiceAccount, the role trust policy’s exact namespace and ServiceAccount subject, and the role’s model invocation policy. For a cross-Region inference profile, include its source profile ARN and all destination model ARNs; check organization service control policies for denied Regions.
Check the exact model or profile ID and aws_region_name. A model available in one Region may require an inference profile in another.
Check the internal LiteLLM Service DNS name, namespace, and profile base URL. Confirm the LiteLLM Deployment is ready and its logs show the Bedrock route.
Confirm the Bedrock model supports tool use and that its account quotas allow larger agent prompts. Test a full conversation with a sandbox command, not only a direct model completion.
For provider-specific model configuration, see LiteLLM’s Bedrock reference.