09:15–09:45
0. Setup and access
You'll spend the next 30 minutes getting an AWS account, a browser-based code editor and the workshop code ready. Everyone does this, console path included, since each scenario has a terminal step or two. Work through it in order, and flag us early if something doesn't look right.
Join the workshop event
- Open the join link shown on the screen at the front, in a new tab.
- Sign in with your work email. You'll get a one-time code by email.
- Enter the event access code from the screen at the front.
- Read and accept the terms.
You'll land on the event dashboard. Keep this tab open all morning, because it's where your console link and outputs live.
Open the AWS console and check the region
On the event dashboard, choose Open AWS console. In the top-right corner of the console, check the region is Asia Pacific (Singapore) ap-southeast-1. If it isn't, change it, because every scenario today runs in this region.
Open your code editor
Back on the event dashboard, find the output called CodeEditorURL and open it in a new tab. Then open a terminal: Menu → Terminal → New Terminal.
You'll run all the commands in this guide in that terminal.
Check your tools
aws sts get-caller-identity; node --version; uv --version; agentcore --version
You should see your workshop account ID, Node v20 or later, a uv version and an agentcore version.
If agentcore isn't found, install it:
npm install -g @aws/agentcore
If you see a warning about the old Bedrock AgentCore Starter Toolkit, remove it. Both tools use the agentcore command name and will confuse each other.
pip uninstall -y bedrock-agentcore-starter-toolkit
Get the workshop code
cd ~ &&
git clone https://github.com/jamadmin/agentcore-workshop.git agentcore-workshop &&
cd agentcore-workshop &&
source scripts/env.sh
env.sh sets a few variables you'll use all morning: WORKSHOP (the repo folder), AWS_REGION, and the ARNs of three small backend APIs that are already deployed in your account, one per scenario. It also gives you a newsession command that prints a fresh session ID. It only lasts for this terminal, so if you open a new one, run source ~/agentcore-workshop/scripts/env.sh there too. The workshop scripts load it themselves, so they work either way.
env | grep -E '^(WORKSHOP|AWS_REGION|.*_API_ARN)='
You should see all three _API_ARN lines with a value. If env.sh says it couldn't find the sample APIs, carry on to the setup check, which tells you which one is missing.
Source env.sh, run everything else
env.sh is the only file you source. Everything else in scripts/ is a script you run, like $WORKSHOP/scripts/check-setup.sh. If you source a script by mistake, it stops and tells you the command to run instead.
Paste a whole box at once
Commands that belong together are joined with &&, so you can copy a box and paste it in one go. They run one after another, and if one fails, the rest stop there. Read the error, fix it, and paste the box again.
Run the setup check
$WORKSHOP/scripts/check-setup.sh
It checks your tools, credentials and region, makes one tiny Bedrock model call, calls each backend API once, and reports whether CloudWatch Transaction Search is on. Each line says PASS or FAIL with a hint.
Using your own AWS account instead of a workshop account?
Workshop accounts come with the three sample APIs already deployed. Your own account won't have them, so the three API checks fail. Deploy them once, then load the environment again:
$WORKSHOP/scripts/deploy-backends.sh &&
source $WORKSHOP/scripts/env.sh &&
$WORKSHOP/scripts/check-setup.sh
This creates a CloudFormation stack called AgentCoreWorkshopBackends: three small Lambda functions and two DynamoDB tables with made-up data. If CDK isn't bootstrapped in the region yet, the script offers to do it. Turning on Transaction Search changes a setting for the whole account, so check that's fine before you run the next step. When you're done, the wrap-up page shows how to remove everything.
The scripts run in bash. You can use zsh or another shell for your own terminal, because each script starts its own bash.
Turn on CloudWatch Transaction Search
Every trace you look at today depends on this. It's a one-time switch per account and takes around ten minutes to start indexing, which is why we do it now. If the setup check already said PASS for Transaction Search, skip this step.
$WORKSHOP/scripts/enable-transaction-search.sh
If you'd rather use the console: open CloudWatch, expand Application Signals (APM) in the navigation pane, choose Transaction Search, choose Enable Transaction Search, tick the box to ingest spans as structured logs, and save. Until it's on, the AgentCore pages in CloudWatch show a banner saying span ingestion is required.
Choose your path
You can build the agents in two ways. Both get you to the same result, and we'll help you just as much on either.
| Console | Terminal | |
|---|---|---|
| How you build | Forms in the AgentCore console, and you chat with the agent in the console's Playground | AgentCore CLI commands, with the agent defined in files you could keep in Git |
| Good if | You're new to AgentCore or want to see each piece as it's created | You're comfortable on a command line, or want the version you'd automate |
| Terminal still needed for | The rush of orders in Kopi Run, running Tally's own agent, and the catch-up commands | Everything |
Pick one now. You can switch at any time with Your path at the top of the sidebar, and each step that differs has Console and Terminal tabs.
Done when
check-setup.sh shows PASS on every line, and you've picked a path. Transaction Search can show PENDING for a few minutes, which is fine.
Stuck?
AccessDeniedon the Bedrock check. This means model access isn't enabled in your account. Put your hand up, as a facilitator needs to sort this one out.- A backend API check fails. Run
source $WORKSHOP/scripts/env.shagain, then re-run the check. If it still fails, the sandbox stack may not have finished yet, so let a facilitator know. - Wrong account or region. You probably have two console tabs open. Close the extras and start again from the event dashboard.
- For anything else, the setup desk can swap you onto a spare account in a couple of minutes.
Kiro corner (optional)
If you want an AI assistant beside you for the morning, install Kiro on your laptop from kiro.dev/downloads and sign in. The free plan's 50 monthly credits are more than enough for the Kiro corner prompts. Nothing in the workshop depends on it. Don't paste AWS credentials or account details into any assistant.