Skip to content

Instantly share code, notes, and snippets.

@rvennam
Created February 12, 2026 16:45
Show Gist options
  • Select an option

  • Save rvennam/33e7f3c1dacac8f3c700394b0795d037 to your computer and use it in GitHub Desktop.

Select an option

Save rvennam/33e7f3c1dacac8f3c700394b0795d037 to your computer and use it in GitHub Desktop.
# Step 1: AgentgatewayBackend — omit policies.auth to use IRSA
apiVersion: agentgateway.dev/v1alpha1
kind: AgentgatewayBackend
metadata:
name: bedrock
namespace: enterprise-agentgateway
spec:
ai:
provider:
bedrock:
model: "amazon.nova-micro-v1:0"
region: "us-east-1"
# NOTE: No policies.auth section — this tells agentgateway to use IRSA/pod identity
---
# Step 2: EnterpriseAgentgatewayParameters — annotate the DATA PLANE service account with IRSA role
# Update your existing agentgateway-params
apiVersion: enterpriseagentgateway.solo.io/v1alpha1
kind: EnterpriseAgentgatewayParameters
metadata:
name: agentgateway-params
namespace: enterprise-agentgateway
spec:
serviceAccount:
metadata:
annotations:
eks.amazonaws.com/role-arn: "arn:aws:iam::<ACCOUNT_ID>:role/<BEDROCK_ROLE_NAME>"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment