Skip to main content
Version: 0.0.42

AWS Bedrock

Lakehousecat supports AWS as a provider for Chat (Amazon Bedrock) and Speech-to-Text (Amazon Transcribe). This page covers the complete setup, common pitfalls, and best practices.


Prerequisites​

RequirementDetails
Lakehousecat roleAdministrator
AWS accountIAM user with Bedrock permissions (see below)
Regionus-east-1 recommended (largest model selection)
Model accessMust be enabled in the AWS Console under Bedrock → Model Access

Required IAM Permissions​

{
"Effect": "Allow",
"Action": [
"bedrock:InvokeModel",
"bedrock:InvokeModelWithResponseStream",
"bedrock:Converse",
"bedrock:ConverseStream",
"bedrock:ListInferenceProfiles",
"bedrock:GetInferenceProfile",
"transcribe:StartStreamTranscription",
"transcribe:StartTranscriptionJob"
],
"Resource": "*"
}

Foundation Model vs. Inference Profile — the most important distinction​

This is the most common configuration mistake. AWS Bedrock distinguishes between two ARN types:

Foundation Model ARN​

arn:aws:bedrock:us-east-1::foundation-model/amazon.nova-lite-v1:0

Direct model invocation without routing. Only available for models that support on-demand throughput (older / Amazon-native models).

Inference Profile ARN​

arn:aws:bedrock:us-east-1::inference-profile/us.anthropic.claude-sonnet-4-6

Cross-region load balancing across multiple AWS regions. Required for all newer models (Anthropic Claude 3.5+, Meta LLaMA 3.1+, DeepSeek, Writer, and others).

Wrong ARN → empty responses

If a model that only supports INFERENCE_PROFILE is called with a foundation-model ARN, Bedrock responds with a ValidationException. Lakehousecat will not display an error message in this case — the response is simply empty.

How to identify the correct ARN type​

Option 1 — AWS CLI:

# List available inference profiles
aws bedrock list-inference-profiles --region us-east-1

# Check whether a model uses on-demand or inference profile
aws bedrock get-foundation-model \
--model-identifier anthropic.claude-sonnet-4-6 \
--region us-east-1 \
--query "modelDetails.inferenceTypesSupported"

Option 2 — AWS Console: Bedrock → Model Catalog → select a model → API Details tab → copy the ARN.

ARN format overview​

Model typeARN formatExample
Amazon Nova (on-demand)foundation-model/amazon.nova-*arn:aws:bedrock:us-east-1::foundation-model/amazon.nova-lite-v1:0
Anthropic Claude 3.5+inference-profile/us.anthropic.*arn:aws:bedrock:us-east-1::inference-profile/us.anthropic.claude-sonnet-4-6
Meta LLaMA 3inference-profile/us.meta.llama3-*arn:aws:bedrock:us-east-1::inference-profile/us.meta.llama3-70b-instruct-v1:0
Mistralfoundation-model/mistral.*arn:aws:bedrock:us-east-1::foundation-model/mistral.mixtral-8x7b-instruct-v0:1
DeepSeekinference-profile/us.deepseek.*arn:aws:bedrock:us-east-1::inference-profile/us.deepseek.r1-v1:0

These examples illustrate the ARN patterns. The AWS Bedrock model catalog is updated frequently — use the AWS CLI or Console to find the current ARN for any model.


Region recommendation: us-east-1​

Lakehousecat recommends us-east-1 as the primary region for Bedrock workloads:

  • Largest selection of available models (catalog is updated regularly by AWS)
  • Inference profiles with us. prefix available
  • Many providers supported, including Anthropic, Amazon, Meta, Mistral, DeepSeek, and others

eu-west-1 is also supported but offers a smaller model catalog. Inference profile ARNs from eu-west-1 use the eu. prefix and typically require an account ID:

arn:aws:bedrock:eu-west-1:123456789012:inference-profile/eu.anthropic.claude-3-sonnet-20240229-v1:0

Configuration in Lakehousecat​

Navigate to Workspace → Models → Provider Models and click +.

Step 1: Provider Type​

Select AWS.

Step 2: Model Type​

  • Chat → Amazon Bedrock
  • STT → Amazon Transcribe

Step 3: Fill in the fields​

All model types​

FieldDescription
Configuration NameA unique internal name, e.g. aws-claude-sonnet-4-6
AWS Access Key IDIAM access key, starts with AKIA…
AWS Secret Access KeyCorresponding secret key
AWS Region Nameus-east-1 (recommended)

Chat (Amazon Bedrock)​

FieldDescription
Inference Profile ARNFull ARN — foundation model or inference profile (see above)
Finding the ARN

The quickest way to find the correct ARN:

aws bedrock list-inference-profiles --region us-east-1 \
--query "inferenceProfileSummaries[?contains(inferenceProfileName, 'Claude')].inferenceProfileArn"

STT (Amazon Transcribe)​

FieldDescription
STT Model ID / ARN (optional)Leave empty for standard Amazon Transcribe. Provide a Bedrock ARN only for Bedrock-based STT.

Step 4: Save​

Click Save. Optionally set the model as Default UI Model or Default Backend Model afterwards.


Activating model access​

New models in AWS Bedrock are not active by default. Before use:

  1. AWS Console → Amazon Bedrock → Model Access
  2. Enable the desired models (Anthropic, Meta, Mistral, etc.)
  3. For Anthropic models: accept the terms of use
  4. Activation typically takes 1–2 minutes

Geographic restrictions​

Some models have geographic usage restrictions:

Model familyRestriction
Meta LLaMA 4 (Maverick, Scout)EU / Germany not supported (Meta EULA)
Meta LLaMA 3.xAvailable in us-east-1
All other providersNo known EU restrictions
LLaMA 4 from the EU

Calling meta.llama4-* models from Germany or the EU results in:

ValidationException: Access to Meta Llama models is not allowed from
unsupported countries, regions, or territories.

Alternative: LLaMA 3.3 70B or Meta LLaMA 4 via another provider.


Common errors​

Empty responses (no error message visible)​

Symptom: Chat does not respond, no error shown. Cause A: Wrong ARN type — foundation-model ARN for a model that requires INFERENCE_PROFILE. Fix: Switch the ARN to inference-profile/us.{model-id} (see above).

Cause B: Model access not activated. Fix: AWS Console → Bedrock → Model Access → enable the model.


ValidationException — On-Demand not supported​

Invocation of model ID X with on-demand throughput isn't supported.
Retry your request with the ID or ARN of an inference profile that contains this model.

Fix: Replace the foundation model ARN with an inference profile ARN:

# Before (wrong for newer models):
arn:aws:bedrock:us-east-1::foundation-model/anthropic.claude-haiku-4-5-20251001-v1:0

# After (correct):
arn:aws:bedrock:us-east-1::inference-profile/us.anthropic.claude-haiku-4-5-20251001-v1:0

AccessDeniedException​

User is not authorized to perform: bedrock:InvokeModel

Fix: Review the IAM policy — bedrock:ConverseStream and bedrock:InvokeModelWithResponseStream must be allowed.


Credential errors​

The security token included in the request is invalid

Fix: Update the Access Key ID and Secret Access Key in the Lakehousecat model configuration. Keys rotate regularly — check expiry dates for managed keys.


Region mismatch​

Could not connect to the endpoint URL: "https://bedrock-runtime.eu-central-1.amazonaws.com"

Fix: Make sure the configured region matches the region where Model Access was activated.


Best practices​

  • Region: us-east-1 as the default for all Bedrock workloads (largest model selection).
  • Naming convention: aws-{provider}-{model-slug}, e.g. aws-anthropic-claude-sonnet-4-6.
  • IAM least privilege: Dedicated IAM user for Lakehousecat with only Bedrock / Transcribe permissions.
  • Key rotation: Rotate AWS access keys regularly and update them in Lakehousecat.
  • Prefer inference profiles: Even when a model supports on-demand, inference profiles offer better availability through cross-region routing.
  • Check model access in advance: Enable all required models in Bedrock before deployment.