What runs in your account (Studio)
A Studio deployment is five CloudFormation stacks in one of your AWS accounts, plus a handful of resources the engine and Studio itself create at runtime. This page walks the components from the front door inward and ends with a resource inventory derived from the templates.
Who this is for
Security engineers reviewing the footprint, and cloud engineers who need to know what a deployment costs and why. The end-user view of the same features is in the Studio guide.
Before you start
Stack names are alphaagent-<deployment id>-<suffix>. Resource names use the project prefix alphaagent and, for buckets, your account id and region. Everything below is created with CAPABILITY_NAMED_IAM, so the role names are fixed and predictable.
The network
The core stack creates a dedicated VPC with two public and two private subnets across two availability zones, an internet gateway, and one NAT gateway with an Elastic IP. Tasks and sandboxes run in the private subnets. The NAT gateway is what gives them a path to the Console, to Docker Hub for two public images, to the public web for agent web search, and to your own data sources outside AWS. EnableNatGateway can be set to false in the stack; the private subnets then have no internet egress and the licence heartbeat cannot reach the Console.
Ten VPC endpoints keep AWS traffic inside the VPC: gateway endpoints for S3 and DynamoDB, and interface endpoints for Secrets Manager, STS, ECR (API and Docker registry), CloudWatch Logs, SQS, Systems Manager and Bedrock Runtime. Model calls never leave the VPC for the public internet.
Five security groups separate the load balancer, the tasks, the sandbox Lambda functions, Redis and the EFS mount targets. The sandbox security group allows outbound TCP 443 only.
The front door
- CloudFront fronts every deployment. The distribution's alias is your app domain, the viewer protocol policy redirects HTTP to HTTPS, and the minimum TLS version is
TLSv1.2_2021. The certificate for the alias is requested inus-east-1by the engine with DNS validation. - Lambda@Edge is one small
nodejs20.xfunction inus-east-1, deployed by the edge stack and attached to the distribution as an origin-response function. - Origin lock. The engine mints a 24-byte random secret once per deployment and stores it as
alphaagent-<deployment id>-edge-origin. CloudFront adds it to every request as theX-AlphaAgent-Edgeheader. Every load balancer listener rule requires that header, and the default action is a fixed 403, so a request that reaches the load balancer directly, bypassing CloudFront, is refused. - The load balancer listens on 443 with the certificate you supply in the deployment region (security policy
ELBSecurityPolicy-TLS13-1-2-2021-06) and redirects 80 to 443. Every rule except one adds anauthenticate-cognitoaction in front of the target: an unauthenticated browser is sent to sign in. The exception is/api/v1, the programmatic API, which the workflow service protects with API keys instead; see Programmatic access. - Optional WAF. When the deployment sets
ApiWafIpSetCidrs, the stack creates a regional Web ACL with one rule that blocks/api/v1from any source outside the allow-list. Every other path passes. Without CIDRs, no WAF resources are created. - Cognito. One user pool per deployment, with a SAML identity provider named
AlphaAgentSSOthat federates to your Entra ID tenant. Password sign-in is not offered to users; see Identity and access.
Services
All services are ARM64 Fargate tasks in one ECS cluster, reached through the load balancer and, between themselves, through Service Connect.
| Service | Role in the deployment |
|---|---|
agent-management | Agents, execution environments, active configurations, the Libraries browse and pull path, the Agent Store client, provisioning of sandbox Lambda functions |
agent-runtime | Runs conversations and workflow runs, the licence activation and heartbeat, the usage outbox drainer, PII redaction |
chat | Conversations, messages and summaries |
data-connector | Connector definitions, credential storage, connection tests and connector guides |
workflow | Workflow definitions, versions, runs and schedules; the programmatic API at /api/v1 |
knowledge-base | Knowledge graph document processing and version builds |
knowledge-base-mcp | Knowledge graph retrieval for agents |
code-interpreter | The coder that writes and runs code, and the dispatch of each execution to a sandbox |
web-browser-search | Web search (a bundled SearXNG) and page browsing (headless Chromium) |
notification-service | Inbox cards and banners |
neo4j | The self-hosted graph store, single node, data on EFS |
A twelfth task definition, kg-transfer, has no service: the Organisations engine starts it on demand to export or import a knowledge graph version during a Library transfer.
Sizing is one SizingProfile per deployment; the console offers xs, small, standard, large and xlarge (the template also accepts a reduced value the console does not offer). Services are grouped Heavy (agent-runtime, knowledge-base), Mid (knowledge-base-mcp, neo4j) and Light (everything else), and each group gets a vCPU and memory pair from the profile. At standard the Heavy pair is 16 vCPU and 64 GB, the Fargate per-task CPU ceiling; large and xlarge add memory only.
Sandboxes
Agent code runs in AWS Lambda, not in the ECS tasks. agent-management creates one Lambda function per execution environment, named alphaagent-env-<environment id>, from the environment's container image in the alphaagent-envs ECR repository, inside the VPC on the sandbox security group. Each execution is one invocation. Per-invocation credentials are narrowed to the invoking user's workspace prefix and the invoking agent's connector secret; the mechanics are on Sandbox isolation.
Data stores
- DynamoDB: 38 tables, all on-demand capacity, grouped by service: agents, environments and active configurations; chat conversations, messages and summaries; workflow definitions, versions, executions and schedules; execution runs, run events and run boards; connectors and agent-connector links; knowledge graphs, documents, jobs and build state; notifications and activity; API keys; share requests; the metering outbox. Stateful tables carry
DeletionPolicy: Retain. - S3: seven buckets from the core stack, each with SSE-S3 (AES-256) default encryption, versioning and all public access blocked:
workspaces(every user's files, run inputs and outputs),kb-artifacts(uploaded documents),kb-processingandkb-dgl-training(knowledge graph build state),chat-overflow(large payloads and the staged sandbox handler),code-scripts, andfrontend(the Studio web app). The engine also createsalphaagent-deploy-<account>-<region>on first use to hold CloudFormation templates. - Neo4j on EFS: one encrypted EFS file system with elastic throughput and AWS Backup enabled, two mount targets, and two access points (
/dataand/logs) for the Neo4j task. - Redis: one ElastiCache replication group (default node type
cache.t4g.medium) with at-rest and in-transit encryption, used for sessions and runtime cache. - Secrets Manager: 18 secret shells from the core stack (one
-configsecret per service plus common configuration, the licence bootstrap and persisted licence secret, Neo4j credentials, and the PII hash key), populated at install. Studio adds the data-connector credential secret, one connector-credential secret per agent, and the prompt key after activation. - SQS: three queue pairs (main plus dead-letter) for knowledge graph processing, notification events and workflow schedules. EventBridge rules are created per workflow schedule at runtime.
- CloudWatch: one log group per service (
/alphaagent/services/<service>), retentionLogRetentionInDays(default 30), plus alarms on the task-definition stack.
Steps: read the inventory from your own account
- Open CloudFormation in the deployment region, select the
-corestack and open Resources. Compare the list with the table below. - Repeat for
-stateless,-computeand-taskdef. - Switch to
us-east-1and open the-edgestack. Three resources: an IAM role, a Lambda function and a published version. - In Lambda (deployment region), filter functions by
alphaagent-env-. One per execution environment your users have created. - In S3, filter buckets by
alphaagent-. Seven from the stack plus the deploy bucket, and the optional staging bucket from the account template.
What you should see
The table below is generated from the templates and the deployment inventory; a build check regenerates it so it cannot drift from the fixture. Counts are per deployment.
| Stack | Resource type | Count | Purpose | Cost driver |
|---|---|---|---|---|
| core | AWS::EC2::VPC | 1 | Dedicated network for the deployment | No charge |
| core | AWS::EC2::Subnet | 4 | Two public, two private, across two availability zones | No charge |
| core | AWS::EC2::RouteTable / Route / SubnetRouteTableAssociation / InternetGateway / VPCGatewayAttachment | 10 | Public and private routing | No charge |
| core | AWS::EC2::NatGateway | 1 | Outbound internet for the private subnets; can be disabled with EnableNatGateway | Hourly plus per GB processed |
| core | AWS::EC2::EIP | 1 | Address of the NAT gateway | Hourly while the NAT gateway exists |
| core | AWS::EC2::SecurityGroup | 5 | Load balancer, tasks, sandboxes, Redis, EFS | No charge |
| core | AWS::EC2::VPCEndpoint | 10 | Gateway: S3, DynamoDB. Interface: Secrets Manager, STS, ECR API, ECR registry, CloudWatch Logs, SQS, Systems Manager, Bedrock Runtime | Interface endpoints hourly per availability zone plus per GB; gateway endpoints no charge |
| core | AWS::DynamoDB::Table | 38 | Agents, environments, chat, workflows, runs and events, connectors, knowledge graphs, notifications, API keys, share requests, the metering outbox | On-demand reads and writes, storage; point-in-time recovery on 14 tables |
| core | AWS::S3::Bucket | 7 | workspaces, kb-artifacts, kb-processing, kb-dgl-training, chat-overflow, code-scripts, frontend | Storage per GB-month and requests; versioning keeps prior versions until a lifecycle rule expires them |
| core | AWS::SQS::Queue | 6 | Knowledge graph processing, notification events, workflow schedules, each with a dead-letter queue | Per million requests |
| core | AWS::SecretsManager::Secret | 18 | Per-service and common configuration, licence bootstrap and persisted secret, Neo4j credentials, PII hash key | Per secret per month plus API calls |
| core | AWS::ECR::Repository | 3 | alphaagent/studio, alphaagent-envs, alphaagent/web-browser-search | Storage per GB-month |
| core | AWS::ElastiCache::ReplicationGroup | 1 | Sessions and runtime cache; at-rest and in-transit encryption | Node hours (default cache.t4g.medium) |
| core | AWS::EFS::FileSystem / MountTarget / AccessPoint | 5 | Neo4j data and logs, encrypted, elastic throughput, AWS Backup enabled | Storage per GB-month, throughput per GB, backup storage |
| core | AWS::Cognito::UserPool / UserPoolClient / UserPoolDomain | 3 | Studio sign-in, federated to your identity provider | Monthly active users above the free tier |
| core | AWS::IAM::Role | 2 | Sandbox Lambda execution role and sandbox scoped role | No charge |
| core | AWS::Events::Rule | 1 | kb-artifacts object-created to the processing queue | Per million events |
| core | AWS::SNS::Topic / Subscription | 2 | Notification events | Per million requests |
| core | AWS::SSM::Parameter | 2 | Deployment parameters | No charge |
| core | AWS::Logs::LogGroup | 10 | One per service; retention LogRetentionInDays, default 30 | Ingestion per GB, storage per GB-month |
| stateless | AWS::ElasticLoadBalancingV2::LoadBalancer | 1 | HTTPS 443 with your certificate; 80 redirects to 443 | Hourly plus LCU hours |
| stateless | AWS::ElasticLoadBalancingV2::Listener / ListenerRule / TargetGroup | 28 | Routing to the eleven services; authenticate-cognito on every rule except /api/v1; origin-lock header required | No charge |
| stateless | AWS::EC2::SecurityGroup | 1 | Load balancer | No charge |
| stateless | AWS::Lambda::Function | 1 | Serves the Studio web app (python3.12), with its role and permission | Per request and GB-second |
| stateless | AWS::CloudFront::Distribution | 1 | The front door; alias is your app domain; TLS 1.2 minimum; adds the origin-lock header | Per request and per GB transferred |
| stateless | AWS::WAFv2::IPSet / WebACL / WebACLAssociation | 3 | Blocks /api/v1 from sources outside your allow-list; created only when ApiWafIpSetCidrs is set | Web ACL and rule per month plus per million requests, only when created |
| stateless | AWS::Logs::LogGroup | 1 | SPA server, 30 days | Ingestion and storage |
| compute | AWS::ServiceDiscovery::HttpNamespace | 1 | Service Connect between tasks | No charge |
| compute | AWS::ECS::Cluster / ClusterCapacityProviderAssociations | 2 | The Fargate cluster | No charge for the cluster itself |
| compute | AWS::IAM::Role | 2 | Task execution role; task role with Bedrock invoke and Marketplace subscribe | No charge |
| taskdef | AWS::ECS::TaskDefinition | 12 | Eleven services plus the on-demand kg-transfer task; all ARM64 Fargate | No charge |
| taskdef | AWS::ECS::Service | 11 | The running services | Fargate vCPU-hours and GB-hours per the sizing profile |
| taskdef | AWS::CloudWatch::Alarm | 6 | Service health and metering alarms | Per alarm per month |
| taskdef | AWS::Logs::MetricFilter | 2 | Bedrock invocation counts | No charge |
| taskdef | AWS::Logs::LogGroup | 3 | kg-transfer, SearXNG, Neo4j; 30 days | Ingestion and storage |
| edge | AWS::IAM::Role | 1 | Lambda@Edge execution role | No charge |
| edge | AWS::Lambda::Function | 1 | Origin-response function attached to the distribution (nodejs20.x) | Per Lambda@Edge request and GB-second |
| edge | AWS::Lambda::Version | 1 | Published version the distribution references | No charge |
| account template | AWS::IAM::Role | 1 | AlphaAgentOrgTarget-<suffix>, assumable only by your Organisations account with the External ID | No charge |
| account template | AWS::IAM::ManagedPolicy | 4 | Guardrails, stacks and compute, data and storage, application and probe (plus WAF when enabled) | No charge |
| account template | AWS::S3::Bucket | 1 | alphaagent-org-staging-<account>-<region> for Library transfers; objects expire after 7 days | Storage per GB-month while a transfer is staged |
For what these cost at each sizing profile, see Infrastructure sizing and costs.
Limits
- The edge stack is always in
us-east-1. A service control policy that denies that region, CloudFront or Lambda@Edge blocks the front door and the deploy fails with a permission error naming the stack; see SCPs and guardrails. - One NAT gateway, one Elastic IP and one VPC per deployment count against the account's quotas; the Organisations preflight checks the headroom.
- The Heavy tier tops out at 16 vCPU per task; larger profiles add memory only.
- Two images are pulled from Docker Hub at task start (
neo4j:5.26-communityandsearxng/searxng:latest) rather than from your ECR.
If something goes wrong
- A
-corestack resource is missing from your account: the deployment's job in the Organisations console names the failed step and the CloudFormation failure reason. See Jobs, progress and failures. - The load balancer answers 403 to every request: you are reaching it directly rather than through CloudFront. Point your DNS at the distribution.