AWS Bedrock
Lakehousecat supports AWS as a provider for Chat (Amazon Bedrock) and Speech-to-Text (Amazon Transcribe). This page covers the complete setup, common pitfalls, and best practices.
Prerequisites
| Requirement | Details |
|---|---|
| Lakehousecat role | Administrator |
| AWS account | IAM user with Bedrock permissions (see below) |
| Region | us-east-1 recommended (largest model selection) |
| Model access | Must be enabled in the AWS Console under Bedrock → Model Access |
Required IAM Permissions
{
"Effect": "Allow",
"Action": [
"bedrock:InvokeModel",
"bedrock:InvokeModelWithResponseStream",
"bedrock:Converse",
"bedrock:ConverseStream",
"bedrock:ListInferenceProfiles",
"bedrock:GetInferenceProfile",
"transcribe:StartStreamTranscription",
"transcribe:StartTranscriptionJob"
],
"Resource": "*"
}
If this account is used only for Speech-to-Text (not Bedrock chat), create a dedicated IAM user with programmatic access only and attach a policy limited to the single streaming action. Lakehousecat uses Amazon Transcribe's streaming API, so this is the only permission required (no batch, no S3):
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "LakehousecatTranscribeStreamingOnly",
"Effect": "Allow",
"Action": "transcribe:StartStreamTranscription",
"Resource": "*",
"Condition": {
"StringEquals": {
"aws:RequestedRegion": ["eu-central-1", "eu-west-1"]
}
}
}
]
}
Resource: "*" is not over-permissive here — Transcribe streaming actions do not support resource-scoped ARNs (there is no persistent job object as with the batch API). The optional aws:RequestedRegion condition is an extra least-privilege guard: restrict it to the region(s) you actually use so the key is only valid there.
Foundation Model vs. Inference Profile — the most important distinction
This is the most common configuration mistake. AWS Bedrock distinguishes between two ARN types:
Foundation Model ARN
arn:aws:bedrock:us-east-1::foundation-model/amazon.nova-lite-v1:0
Direct model invocation without routing. Only available for models that support on-demand throughput (older / Amazon-native models).
Inference Profile ARN
arn:aws:bedrock:us-east-1::inference-profile/us.anthropic.claude-sonnet-4-6
Cross-region load balancing across multiple AWS regions. Required for all newer models (Anthropic Claude 3.5+, Meta LLaMA 3.1+, DeepSeek, Writer, and others).
If a model that only supports INFERENCE_PROFILE is called with a foundation-model ARN, Bedrock responds with a ValidationException. Lakehousecat will not display an error message in this case — the response is simply empty.
How to identify the correct ARN type
Option 1 — AWS CLI:
# List available inference profiles
aws bedrock list-inference-profiles --region us-east-1
# Check whether a model uses on-demand or inference profile
aws bedrock get-foundation-model \
--model-identifier anthropic.claude-sonnet-4-6 \
--region us-east-1 \
--query "modelDetails.inferenceTypesSupported"
Option 2 — AWS Console: Bedrock → Model Catalog → select a model → API Details tab → copy the ARN.
ARN format overview
| Model type | ARN format | Example |
|---|---|---|
| Amazon Nova (on-demand) | foundation-model/amazon.nova-* | arn:aws:bedrock:us-east-1::foundation-model/amazon.nova-lite-v1:0 |
| Anthropic Claude 3.5+ | inference-profile/us.anthropic.* | arn:aws:bedrock:us-east-1::inference-profile/us.anthropic.claude-sonnet-4-6 |
| Meta LLaMA 3 | inference-profile/us.meta.llama3-* | arn:aws:bedrock:us-east-1::inference-profile/us.meta.llama3-70b-instruct-v1:0 |
| Mistral | foundation-model/mistral.* | arn:aws:bedrock:us-east-1::foundation-model/mistral.mixtral-8x7b-instruct-v0:1 |
| DeepSeek | inference-profile/us.deepseek.* | arn:aws:bedrock:us-east-1::inference-profile/us.deepseek.r1-v1:0 |
These examples illustrate the ARN patterns. The AWS Bedrock model catalog is updated frequently — use the AWS CLI or Console to find the current ARN for any model.
Region recommendation: us-east-1
Lakehousecat recommends us-east-1 as the primary region for Bedrock workloads:
- Largest selection of available models (catalog is updated regularly by AWS)
- Inference profiles with
us.prefix available - Many providers supported, including Anthropic, Amazon, Meta, Mistral, DeepSeek, and others
eu-west-1 is also supported but offers a smaller model catalog. Inference profile ARNs from eu-west-1 use the eu. prefix and typically require an account ID:
arn:aws:bedrock:eu-west-1:123456789012:inference-profile/eu.anthropic.claude-3-sonnet-20240229-v1:0
Configuration in Lakehousecat
Navigate to Workspace → Models → Provider Models and click +.
Step 1: Provider Type
Select AWS.
Step 2: Model Type
- Chat → Amazon Bedrock
- STT → Amazon Transcribe
Step 3: Fill in the fields
All model types
| Field | Description |
|---|---|
| Configuration Name | A unique internal name, e.g. aws-claude-sonnet-4-6 |
| AWS Access Key ID | IAM access key, starts with AKIA… |
| AWS Secret Access Key | Corresponding secret key |
| AWS Region Name | us-east-1 (recommended) |
Chat (Amazon Bedrock)
| Field | Description |
|---|---|
| Inference Profile ARN | Full ARN — foundation model or inference profile (see above) |
The quickest way to find the correct ARN:
aws bedrock list-inference-profiles --region us-east-1 \
--query "inferenceProfileSummaries[?contains(inferenceProfileName, 'Claude')].inferenceProfileArn"
STT (Amazon Transcribe)
| Field | Description |
|---|---|
| STT Model ID / ARN (optional) | Leave empty for standard Amazon Transcribe. Provide a Bedrock ARN only for Bedrock-based STT. |
In addition, set the AWS Region Name and the STT language code (e.g. en-US, de-DE) for the audio you expect.
Unlike Bedrock — where each foundation model must be enabled under Model Access — Amazon Transcribe is a regular, always-available service. Once the IAM permissions are in place, transcription works immediately: there is no model-access request and no separate console activation step.
The STT Model ID field stays empty for normal use. Only fill it in if you have trained your own Amazon Transcribe custom language model — it is not required for standard operation.
Step 4: Save
Click Save. Optionally set the model as Default UI Model or Default Backend Model afterwards.
Activating model access
New models in AWS Bedrock are not active by default. Before use:
- AWS Console → Amazon Bedrock → Model Access
- Enable the desired models (Anthropic, Meta, Mistral, etc.)
- For Anthropic models: accept the terms of use
- Activation typically takes 1–2 minutes
Geographic restrictions
Some models have geographic usage restrictions:
| Model family | Restriction |
|---|---|
| Meta LLaMA 4 (Maverick, Scout) | EU / Germany not supported (Meta EULA) |
| Meta LLaMA 3.x | Available in us-east-1 |
| All other providers | No known EU restrictions |
Calling meta.llama4-* models from Germany or the EU results in:
ValidationException: Access to Meta Llama models is not allowed from
unsupported countries, regions, or territories.
Alternative: LLaMA 3.3 70B or Meta LLaMA 4 via another provider.
Common errors
Empty responses (no error message visible)
Symptom: Chat does not respond, no error shown.
Cause A: Wrong ARN type — foundation-model ARN for a model that requires INFERENCE_PROFILE.
Fix: Switch the ARN to inference-profile/us.{model-id} (see above).
Cause B: Model access not activated. Fix: AWS Console → Bedrock → Model Access → enable the model.
ValidationException — On-Demand not supported
Invocation of model ID X with on-demand throughput isn't supported.
Retry your request with the ID or ARN of an inference profile that contains this model.
Fix: Replace the foundation model ARN with an inference profile ARN:
# Before (wrong for newer models):
arn:aws:bedrock:us-east-1::foundation-model/anthropic.claude-haiku-4-5-20251001-v1:0
# After (correct):
arn:aws:bedrock:us-east-1::inference-profile/us.anthropic.claude-haiku-4-5-20251001-v1:0
AccessDeniedException
User is not authorized to perform: bedrock:InvokeModel
Fix: Review the IAM policy — bedrock:ConverseStream and bedrock:InvokeModelWithResponseStream must be allowed.
Credential errors
The security token included in the request is invalid
Fix: Update the Access Key ID and Secret Access Key in the Lakehousecat model configuration. Keys rotate regularly — check expiry dates for managed keys.
Region mismatch
Could not connect to the endpoint URL: "https://bedrock-runtime.eu-central-1.amazonaws.com"
Fix: Make sure the configured region matches the region where Model Access was activated.
Tested Configurations
Stand: 2026-07-22. This reflects what Lakehousecat has actually run and observed, not a benchmark or performance ranking — see There is no single "right" provider for why we don't publish comparative scores.
Bedrock exposes a large and constantly changing model catalog; Lakehousecat has broadly validated connectivity across it (56 models in us-east-1, 50 working without issues), plus targeted chart-generation runs for representative models per provider family:
| Provider family (via Bedrock) | Chat connectivity | Notes |
|---|---|---|
| Anthropic, Amazon Nova, Mistral AI, Meta LLaMA, Google Gemma, DeepSeek, Qwen | ✅ Broadly working | Established foundation models — no known issues |
| MiniMax, Moonshot AI, NVIDIA Nemotron, Z.AI (open-weight) | ✅ Working, with a caveat | Model IDs using an "exotic" provider prefix (e.g. zai.*) initially failed once tools were bound (chart generation requires this) — fixed in Lakehousecat's Bedrock integration; zai.glm-5 chart generation validated afterward |
| Writer, OpenAI (via Bedrock), TwelveLabs | ⚠️ Partial / not chat-capable | A few individual models in these families are not usable as chat models on Bedrock — see the AWS Bedrock model catalog for current details |
Chart generation cost (open-weight models via Bedrock): roughly $0.06/chart on average (daily-aggregate billing, not per-call), placing Bedrock open-weight models between xAI's fast variant ($0.04/chart) and Anthropic Haiku ($0.068/chart) — cost is mid-field, the main trade-off for open-weight models is latency, not price.
Best practices
- Region:
us-east-1as the default for all Bedrock workloads (largest model selection). - Naming convention:
aws-{provider}-{model-slug}, e.g.aws-anthropic-claude-sonnet-4-6. - IAM least privilege: Dedicated IAM user for Lakehousecat with only Bedrock / Transcribe permissions. If you use AWS for Speech-to-Text only, restrict it to
transcribe:StartStreamTranscription(see the tip under Required IAM Permissions). - Key rotation: Rotate AWS access keys regularly and update them in Lakehousecat.
- Prefer inference profiles: Even when a model supports on-demand, inference profiles offer better availability through cross-region routing.
- Check model access in advance: Enable all required models in Bedrock before deployment.
- For chart generation, prefer an established foundation model in a lightweight tier (e.g. Claude Haiku via Bedrock) — heavy reasoning models cost more without improving the result for this structured task. See Choosing a Model for Chart Generation. Note that Bedrock cost visibility in the AWS dashboard is typically delayed.