AWS Details on Claude Code Deployment on Amazon Bedrock in GovCloud (US) – Unite.AI
Amazon Web Services published a guide on its machine learning blog on October 5, 2026, detailing how organizations with regulatory or compliance requirements, including International Traffic in Arms (ITAR) regulations, can run Anthropic’s Claude code with Claude Opus 5.5 and Claude Sonnet 5.5 on Amazon Bedrock in AWS GovCloud (US) Regions.
According to the post, Claude Opus 5.5 and Claude Sonnet 5.5 are FedRAMP Class D (formerly High) certified on Amazon Bedrock, while Claude Sonnet 5 is FedRAMP Class D certified and DoD Impact Level 4 and 5 (IL4/IL5) authorized. Bedrock in GovCloud (US) offers FedRAMP Class D and DoD Cloud Service Provider SRG IL4/IL5 authorization paths, and its built-in data protection ensures that customer content is not stored, logged, used to train AWS models, or shared with third parties.
Claude Opus 5.5 became available on AWS GovCloud (US) on September 22, 2026, according to an AWS announcement, followed by Claude Sonnet 5.5 on September 28, 2026. In the Opus announcement, AWS said the model is offered on Amazon Bedrock with zero data retention support by default and regional data residency.
Two Bedrock endpoint surfaces
Amazon Bedrock on AWS GovCloud (US) supports two endpoint surfaces, bedrock-runtime and bedrock-mantle, both powered by the same Mantle inference engine with a Zero Operator Access architecture. The bedrock runtime endpoint uses the AWS SDK via the InvokeModel and Converse APIs and supports Amazon Bedrock Guardrails, Knowledge Base, Agents, and Call Recording; AWS recommends it for most new applications, especially those that require audit trails.
The bedrock-mantle endpoint supports the Anthropic Messages API natively, with features unique to that surface, such as server-side tools, background inference, and projects. The bedrock-runtime endpoint is available in both GovCloud (US West and US East) regions, while bedrock-mantle is only available in AWS GovCloud (US West). Guardrails and call logging are unique to bedrock-runtime, so the post directs deployments that require full audit trails and content filtering to that endpoint.
What Claude Code does
Claude Code is Anthropic’s agent-based coding tool that reads a code base, edits files, executes commands, and integrates with development tools. It runs in the terminal, in integrated development environments like VS Code and JetBrains, and in the background via the Claude Agent SDK.
AWS lists features that include writing code and fixing bugs across multiple files, running and fixing tests and linting, searching Git history, resolving merge conflicts, and creating commits and pull requests. The tool connects to external tools and data sources via the Model Context Protocol, including AWS Command Line Interface, Terraform, and Kubernetes, and can spawn sub-agents that work on different parts of a task simultaneously. Behavior can be customized with memory files, skills, and CLAUDE.md hooks, while recurring tasks can be automated via CI/CD integration with GitHub Actions or GitLab CI/CD.
Setup and configuration
Prerequisites include an AWS GovCloud (US) account with access to Amazon Bedrock; IAM permissions that include at least bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream, bedrock:ListInferenceProfiles, and bedrock:GetInferenceProfile for bedrock-runtime, as well as bedrock-mantle operations or the AmazonBedrockMantleInferenceAccess managed policy for the Mantle endpoint; Claude Opus 5.5, Claude Sonnet 5.5 and Claude Sonnet 5 model access enabled in your account; and the AWS CLI configured with short-term credentials or AWS SSO.
The post documents three configuration paths, labeled A to C. Option A uses Claude Code’s interactive login wizard: select the third-party platform, then Amazon Bedrock, choose the us-gov-west-1 region, and add the templates; Previously configured installations can reopen the wizard with /setup-bedrock. Option B sets the environment variables: CLAUDECODEUSEBEDROCK=1, AWSREGION set to us-gov-west-1 and ANTHROPICMODEL pointing to model ID prefixed with us-gov. such as us-gov.anthropic.claude-sonnet-5-5 or us-gov.anthropic.claude-opus-5-5. Option C routes Claude Code through Mantle with CLAUDECODEUSEMANTLE=1 and the Bedrock and Mantle flags can be combined in a single session. Running /status checks the configuration; the vendor row shows Amazon Bedrock or Amazon Bedrock (Mantle).
Enterprise distribution and cost control
With Claude Code now generally available, AWS recommends governing identity and access through AWS IAM Identity Center with temporary role-based credentials rather than static access keys, automating default environment variables or managing settings files centrally, and implementing Guidance for Claude Code with Amazon Bedrock for large enterprise deployments. AWS also recommends reviewing your Bedrock service quotas for tokens per minute and requests per minute against the number of active developers.
AWS recommends locking template versions because unlocked aliases such as sonnet and opus resolve with Claude Code’s built-in defaults, which can change between releases. Claude Code defaults to Claude Opus 5.5 as its primary model, so an unblocked deployment is billed at the Opus rate per token, which the post says is higher than Claude Sonnet 5.5. For cost governance, AWS targets per-user token guardrails that enforce daily limits with alerts at the 80% and 100% thresholds, based on CloudWatch, Lambda, and DynamoDB call logging, and to require caching with 5-minute and 1-hour TTL options for supported models.
AWS suggests setting up Teams on Claude Sonnet 5.5 and reserving Claude Opus 5.5 for tasks requiring deeper reasoning or longer autonomous executions, while workloads requiring IL4/IL5 authorization should use Claude Sonnet 5, which the post describes as offering the strongest compliance coverage for sensitive environments. He characterizes Claude Sonnet 5.5 as a step up from Claude Sonnet 5 on coding and knowledge work at a lower cost per task. According to Anthropic, as cited in AWS records, Claude Opus 5.5 completes tasks using fewer tokens than Claude Opus 5 at a lower price per token.
Regarding security, AWS recommends conducting a thorough assessment before deployment: Amazon Bedrock secures the inference layer, but Claude Code runs on local development machines and requires separate risk assessment and management. The post recommends applying controls such as managed permissions, call recording, and per-user token limits, as it would for other third-party software in its environment.



Post Comment