- Introduce the AWS CLI as the primary tool for Bedrock interaction.
- Explain the difference between control-plane and inference/runtime Bedrock commands.
- Cover common authentication options for securely using the CLI.
- Summarize best practices and next steps.

- Faster iterative testing without switching to a browser.
- Automation via Bash, PowerShell, or CI/CD pipelines that call the AWS CLI.
- Secure access patterns using AWS credential mechanisms such as named profiles, environment variables, IAM roles, or SSO.

- aws <service> <operation> [parameters]
aws selects the service (for example, s3, ec2), the second token is the operation (for example, ls, describe-instances), and flags such as --region scope the command.

-
Control plane (management):
aws bedrock <operation> ...
Use this for listing available foundation models, managing access, or configuring guardrails and knowledge bases. -
Inference/runtime:
aws bedrock-runtime <operation> ...
Use this for sending prompts to models and receiving outputs, embeddings, or multi-turn conversation messages.
invoke-model— lower-level call for sending a payload to a specific model and receiving the response.converse— higher-level method designed for managing multi-turn conversations and consistent message structure across models.conversecan simplify conversation flow handling and help with token accounting for context windows.
- Use
aws bedrockfor administrative actions: listing models, configuring guardrails, or managing knowledge bases. - Use
aws bedrock-runtimefor inference: sending prompts, receiving outputs, or managing multi-turn conversations.
Example: configure the CLI with a named profile
When running inference, be mindful of token usage. Tokens are consumed both for prompt/context tokens and for tokens produced in model responses. Tokenization affects context window limits and cost for on-demand model invocations. Consider smaller prompts, batching, or model selection to control costs.
Avoid committing credentials to source control. Use IAM roles, SSO, or environment variables for short-lived credentials. Rotate keys regularly and apply least-privilege IAM policies for Bedrock operations.
- The AWS CLI is a fast, scriptable way to interact with Amazon Bedrock from a developer workstation.
- Use
aws bedrockfor control-plane management andaws bedrock-runtimefor inference and multi-turn conversations. - Authenticate securely using named profiles, environment variables, IAM roles, or AWS SSO, and monitor token usage (context windows and cost).
converse to manage a multi-turn conversation and token accounting.
Links and references
- Amazon Bedrock overview — https://docs.aws.amazon.com/bedrock/latest/ug/overview.html
- AWS CLI User Guide — https://docs.aws.amazon.com/cli/latest/userguide/
- AWS Single Sign-On / IAM Identity Center — https://docs.aws.amazon.com/singlesignon/latest/userguide/