Skip to main content

What runs in your account (Studio)

A Studio deployment is five CloudFormation stacks in one of your AWS accounts, plus a handful of resources the engine and Studio itself create at runtime. This page walks the components from the front door inward and ends with a resource inventory derived from the templates.

Who this is for​

Security engineers reviewing the footprint, and cloud engineers who need to know what a deployment costs and why. The end-user view of the same features is in the Studio guide.

Before you start​

Stack names are alphaagent-<deployment id>-<suffix>. Resource names use the project prefix alphaagent and, for buckets, your account id and region. Everything below is created with CAPABILITY_NAMED_IAM, so the role names are fixed and predictable.

The network​

The core stack creates a dedicated VPC with two public and two private subnets across two availability zones, an internet gateway, and one NAT gateway with an Elastic IP. Tasks and sandboxes run in the private subnets. The NAT gateway is what gives them a path to the Console, to Docker Hub for two public images, to the public web for agent web search, and to your own data sources outside AWS. EnableNatGateway can be set to false in the stack; the private subnets then have no internet egress and the licence heartbeat cannot reach the Console.

Ten VPC endpoints keep AWS traffic inside the VPC: gateway endpoints for S3 and DynamoDB, and interface endpoints for Secrets Manager, STS, ECR (API and Docker registry), CloudWatch Logs, SQS, Systems Manager and Bedrock Runtime. Model calls never leave the VPC for the public internet.

Five security groups separate the load balancer, the tasks, the sandbox Lambda functions, Redis and the EFS mount targets. The sandbox security group allows outbound TCP 443 only.

The front door​

  • CloudFront fronts every deployment. The distribution's alias is your app domain, the viewer protocol policy redirects HTTP to HTTPS, and the minimum TLS version is TLSv1.2_2021. The certificate for the alias is requested in us-east-1 by the engine with DNS validation.
  • Lambda@Edge is one small nodejs20.x function in us-east-1, deployed by the edge stack and attached to the distribution as an origin-response function.
  • Origin lock. The engine mints a 24-byte random secret once per deployment and stores it as alphaagent-<deployment id>-edge-origin. CloudFront adds it to every request as the X-AlphaAgent-Edge header. Every load balancer listener rule requires that header, and the default action is a fixed 403, so a request that reaches the load balancer directly, bypassing CloudFront, is refused.
  • The load balancer listens on 443 with the certificate you supply in the deployment region (security policy ELBSecurityPolicy-TLS13-1-2-2021-06) and redirects 80 to 443. Every rule except one adds an authenticate-cognito action in front of the target: an unauthenticated browser is sent to sign in. The exception is /api/v1, the programmatic API, which the workflow service protects with API keys instead; see Programmatic access.
  • Optional WAF. When the deployment sets ApiWafIpSetCidrs, the stack creates a regional Web ACL with one rule that blocks /api/v1 from any source outside the allow-list. Every other path passes. Without CIDRs, no WAF resources are created.
  • Cognito. One user pool per deployment, with a SAML identity provider named AlphaAgentSSO that federates to your Entra ID tenant. Password sign-in is not offered to users; see Identity and access.

Services​

All services are ARM64 Fargate tasks in one ECS cluster, reached through the load balancer and, between themselves, through Service Connect.

ServiceRole in the deployment
agent-managementAgents, execution environments, active configurations, the Libraries browse and pull path, the Agent Store client, provisioning of sandbox Lambda functions
agent-runtimeRuns conversations and workflow runs, the licence activation and heartbeat, the usage outbox drainer, PII redaction
chatConversations, messages and summaries
data-connectorConnector definitions, credential storage, connection tests and connector guides
workflowWorkflow definitions, versions, runs and schedules; the programmatic API at /api/v1
knowledge-baseKnowledge graph document processing and version builds
knowledge-base-mcpKnowledge graph retrieval for agents
code-interpreterThe coder that writes and runs code, and the dispatch of each execution to a sandbox
web-browser-searchWeb search (a bundled SearXNG) and page browsing (headless Chromium)
notification-serviceInbox cards and banners
neo4jThe self-hosted graph store, single node, data on EFS

A twelfth task definition, kg-transfer, has no service: the Organisations engine starts it on demand to export or import a knowledge graph version during a Library transfer.

Sizing is one SizingProfile per deployment; the console offers xs, small, standard, large and xlarge (the template also accepts a reduced value the console does not offer). Services are grouped Heavy (agent-runtime, knowledge-base), Mid (knowledge-base-mcp, neo4j) and Light (everything else), and each group gets a vCPU and memory pair from the profile. At standard the Heavy pair is 16 vCPU and 64 GB, the Fargate per-task CPU ceiling; large and xlarge add memory only.

Sandboxes​

Agent code runs in AWS Lambda, not in the ECS tasks. agent-management creates one Lambda function per execution environment, named alphaagent-env-<environment id>, from the environment's container image in the alphaagent-envs ECR repository, inside the VPC on the sandbox security group. Each execution is one invocation. Per-invocation credentials are narrowed to the invoking user's workspace prefix and the invoking agent's connector secret; the mechanics are on Sandbox isolation.

Data stores​

  • DynamoDB: 38 tables, all on-demand capacity, grouped by service: agents, environments and active configurations; chat conversations, messages and summaries; workflow definitions, versions, executions and schedules; execution runs, run events and run boards; connectors and agent-connector links; knowledge graphs, documents, jobs and build state; notifications and activity; API keys; share requests; the metering outbox. Stateful tables carry DeletionPolicy: Retain.
  • S3: seven buckets from the core stack, each with SSE-S3 (AES-256) default encryption, versioning and all public access blocked: workspaces (every user's files, run inputs and outputs), kb-artifacts (uploaded documents), kb-processing and kb-dgl-training (knowledge graph build state), chat-overflow (large payloads and the staged sandbox handler), code-scripts, and frontend (the Studio web app). The engine also creates alphaagent-deploy-<account>-<region> on first use to hold CloudFormation templates.
  • Neo4j on EFS: one encrypted EFS file system with elastic throughput and AWS Backup enabled, two mount targets, and two access points (/data and /logs) for the Neo4j task.
  • Redis: one ElastiCache replication group (default node type cache.t4g.medium) with at-rest and in-transit encryption, used for sessions and runtime cache.
  • Secrets Manager: 18 secret shells from the core stack (one -config secret per service plus common configuration, the licence bootstrap and persisted licence secret, Neo4j credentials, and the PII hash key), populated at install. Studio adds the data-connector credential secret, one connector-credential secret per agent, and the prompt key after activation.
  • SQS: three queue pairs (main plus dead-letter) for knowledge graph processing, notification events and workflow schedules. EventBridge rules are created per workflow schedule at runtime.
  • CloudWatch: one log group per service (/alphaagent/services/<service>), retention LogRetentionInDays (default 30), plus alarms on the task-definition stack.

Steps: read the inventory from your own account​

  1. Open CloudFormation in the deployment region, select the -core stack and open Resources. Compare the list with the table below.
  2. Repeat for -stateless, -compute and -taskdef.
  3. Switch to us-east-1 and open the -edge stack. Three resources: an IAM role, a Lambda function and a published version.
  4. In Lambda (deployment region), filter functions by alphaagent-env-. One per execution environment your users have created.
  5. In S3, filter buckets by alphaagent-. Seven from the stack plus the deploy bucket, and the optional staging bucket from the account template.

What you should see​

The table below is generated from the templates and the deployment inventory; a build check regenerates it so it cannot drift from the fixture. Counts are per deployment.

StackResource typeCountPurposeCost driver
coreAWS::EC2::VPC1Dedicated network for the deploymentNo charge
coreAWS::EC2::Subnet4Two public, two private, across two availability zonesNo charge
coreAWS::EC2::RouteTable / Route / SubnetRouteTableAssociation / InternetGateway / VPCGatewayAttachment10Public and private routingNo charge
coreAWS::EC2::NatGateway1Outbound internet for the private subnets; can be disabled with EnableNatGatewayHourly plus per GB processed
coreAWS::EC2::EIP1Address of the NAT gatewayHourly while the NAT gateway exists
coreAWS::EC2::SecurityGroup5Load balancer, tasks, sandboxes, Redis, EFSNo charge
coreAWS::EC2::VPCEndpoint10Gateway: S3, DynamoDB. Interface: Secrets Manager, STS, ECR API, ECR registry, CloudWatch Logs, SQS, Systems Manager, Bedrock RuntimeInterface endpoints hourly per availability zone plus per GB; gateway endpoints no charge
coreAWS::DynamoDB::Table38Agents, environments, chat, workflows, runs and events, connectors, knowledge graphs, notifications, API keys, share requests, the metering outboxOn-demand reads and writes, storage; point-in-time recovery on 14 tables
coreAWS::S3::Bucket7workspaces, kb-artifacts, kb-processing, kb-dgl-training, chat-overflow, code-scripts, frontendStorage per GB-month and requests; versioning keeps prior versions until a lifecycle rule expires them
coreAWS::SQS::Queue6Knowledge graph processing, notification events, workflow schedules, each with a dead-letter queuePer million requests
coreAWS::SecretsManager::Secret18Per-service and common configuration, licence bootstrap and persisted secret, Neo4j credentials, PII hash keyPer secret per month plus API calls
coreAWS::ECR::Repository3alphaagent/studio, alphaagent-envs, alphaagent/web-browser-searchStorage per GB-month
coreAWS::ElastiCache::ReplicationGroup1Sessions and runtime cache; at-rest and in-transit encryptionNode hours (default cache.t4g.medium)
coreAWS::EFS::FileSystem / MountTarget / AccessPoint5Neo4j data and logs, encrypted, elastic throughput, AWS Backup enabledStorage per GB-month, throughput per GB, backup storage
coreAWS::Cognito::UserPool / UserPoolClient / UserPoolDomain3Studio sign-in, federated to your identity providerMonthly active users above the free tier
coreAWS::IAM::Role2Sandbox Lambda execution role and sandbox scoped roleNo charge
coreAWS::Events::Rule1kb-artifacts object-created to the processing queuePer million events
coreAWS::SNS::Topic / Subscription2Notification eventsPer million requests
coreAWS::SSM::Parameter2Deployment parametersNo charge
coreAWS::Logs::LogGroup10One per service; retention LogRetentionInDays, default 30Ingestion per GB, storage per GB-month
statelessAWS::ElasticLoadBalancingV2::LoadBalancer1HTTPS 443 with your certificate; 80 redirects to 443Hourly plus LCU hours
statelessAWS::ElasticLoadBalancingV2::Listener / ListenerRule / TargetGroup28Routing to the eleven services; authenticate-cognito on every rule except /api/v1; origin-lock header requiredNo charge
statelessAWS::EC2::SecurityGroup1Load balancerNo charge
statelessAWS::Lambda::Function1Serves the Studio web app (python3.12), with its role and permissionPer request and GB-second
statelessAWS::CloudFront::Distribution1The front door; alias is your app domain; TLS 1.2 minimum; adds the origin-lock headerPer request and per GB transferred
statelessAWS::WAFv2::IPSet / WebACL / WebACLAssociation3Blocks /api/v1 from sources outside your allow-list; created only when ApiWafIpSetCidrs is setWeb ACL and rule per month plus per million requests, only when created
statelessAWS::Logs::LogGroup1SPA server, 30 daysIngestion and storage
computeAWS::ServiceDiscovery::HttpNamespace1Service Connect between tasksNo charge
computeAWS::ECS::Cluster / ClusterCapacityProviderAssociations2The Fargate clusterNo charge for the cluster itself
computeAWS::IAM::Role2Task execution role; task role with Bedrock invoke and Marketplace subscribeNo charge
taskdefAWS::ECS::TaskDefinition12Eleven services plus the on-demand kg-transfer task; all ARM64 FargateNo charge
taskdefAWS::ECS::Service11The running servicesFargate vCPU-hours and GB-hours per the sizing profile
taskdefAWS::CloudWatch::Alarm6Service health and metering alarmsPer alarm per month
taskdefAWS::Logs::MetricFilter2Bedrock invocation countsNo charge
taskdefAWS::Logs::LogGroup3kg-transfer, SearXNG, Neo4j; 30 daysIngestion and storage
edgeAWS::IAM::Role1Lambda@Edge execution roleNo charge
edgeAWS::Lambda::Function1Origin-response function attached to the distribution (nodejs20.x)Per Lambda@Edge request and GB-second
edgeAWS::Lambda::Version1Published version the distribution referencesNo charge
account templateAWS::IAM::Role1AlphaAgentOrgTarget-<suffix>, assumable only by your Organisations account with the External IDNo charge
account templateAWS::IAM::ManagedPolicy4Guardrails, stacks and compute, data and storage, application and probe (plus WAF when enabled)No charge
account templateAWS::S3::Bucket1alphaagent-org-staging-<account>-<region> for Library transfers; objects expire after 7 daysStorage per GB-month while a transfer is staged

For what these cost at each sizing profile, see Infrastructure sizing and costs.

Limits​

  • The edge stack is always in us-east-1. A service control policy that denies that region, CloudFront or Lambda@Edge blocks the front door and the deploy fails with a permission error naming the stack; see SCPs and guardrails.
  • One NAT gateway, one Elastic IP and one VPC per deployment count against the account's quotas; the Organisations preflight checks the headroom.
  • The Heavy tier tops out at 16 vCPU per task; larger profiles add memory only.
  • Two images are pulled from Docker Hub at task start (neo4j:5.26-community and searxng/searxng:latest) rather than from your ECR.

If something goes wrong​

  • A -core stack resource is missing from your account: the deployment's job in the Organisations console names the failed step and the CloudFormation failure reason. See Jobs, progress and failures.
  • The load balancer answers 403 to every request: you are reaching it directly rather than through CloudFront. Point your DNS at the distribution.