How do I run AI agents on AWS?
Pick a compute option
For a simple scheduled agent, Lambda is often the easiest start, but it has run-time limits. For longer or always-on agents, ECS or a small EC2 instance usually fits better. Choose the option that matches how long each run takes and how often it runs.
Package the code in a container image or a Lambda deployment package. Keep model API calls in the same region as your data when possible to reduce latency.
- Lambda suits short, scheduled runs
- ECS or EC2 suits long-running agents
- Use EventBridge for schedules
- Send logs to CloudWatch
Keep it secure and running
Store API keys in AWS Secrets Manager or Parameter Store, and give the agent's IAM role only the permissions it needs. Avoid putting keys in the image or the code repository.
Set billing alerts and watch model API usage closely. Agents can loop and spend money quickly if no limit is set. Add a maximum step count so each run stops on its own. A simple dashboard that shows daily spend makes unusual activity easy to spot.
- Use a separate IAM role for each agent
- Set AWS Budgets alerts
- Cap steps and retries
- Review logs after the first few runs
Common mistakes
- Hardcoding API keys into the container image.
- Running a long agent job on Lambda and hitting its time limit mid-task.
- Skipping a dry run, so a bug in the schedule triggers many paid model calls before anyone notices.
