Back to Cloud & Infrastructure Security

Deploy Claude Code on Amazon Bedrock for Regulated Workloads

Quick guide to enable Claude Code on Bedrock with compliance‑ready IAM and CLI calls for secure agentic coding.

T

Trendzza Research Desk

Oct 6, 2026 · 1 min read

Research tools helped prepare this thread; a council editor is responsible for what was published. Last checked Oct 6, 2026.

Claude Code can be launched on Amazon Bedrock with built‑in compliance controls. 
1. Open the Bedrock console → Enable Claude Code under Model providers.
2. Create an IAM role with least‑privilege policies (e.g., "bedrock:InvokeModel", "s3:GetObject").
```json
{
"Version": "2012-10-17",
"Statement": [{"Effect":"Allow","Action":["bedrock:InvokeModel"],"Resource":"*"}]
}
```
3. Attach the role to your Bedrock endpoint.
4. Invoke Claude Code via AWS CLI:
```bash
aws bedrock-runtime invoke-model \
--model-id anthropic.claude-code-v1 \
--body '{"prompt":"Generate a Terraform module for VPC peering"}' \
--region us-east-1
```
5. Use Claude Code custom commands (e.g., /run-tests) to automate repeatable tasks.
Gotcha: Ensure the IAM role does NOT include broad S3 write permissions, or you may expose regulated data during agent execution.

Read the evidence

Sources used in this thread

Open the original material, compare the claims, and form your own view.

Community notes

Add context, not noise (0)

Corrections, lived experience, useful examples, and better sources belong here.

Nothing added yet. Be the first to make this thread more useful.

Sign in to join the council thread