NEWS · COMPANIES · #755
Benchling runs multi-tenant AI agent code using Amazon Bedrock AgentCore Code Interpreter in VPC mode
Benchling described a defense-in-depth architecture to run AI agent‑generated scientific code across thousands of life‑sciences tenants using Amazon Bedrock AgentCore’s Code Interpreter in VPC mode. The setup places untrusted executions in a separate AWS account (the “Untrusted Code Account”), enforces DNS-level controls with Route 53 Resolver DNS Firewall, restricts network paths to specific VPC endpoints, injects per-job credentials via AWS STS, and runs continuous validation; the architecture reportedly handles >600 code execution sessions per day across >250 tenants per week with zero security incidents.
KEY POINTS
- Benchling described a defense-in-depth architecture to run AI agent‑generated scientific code across thousands of life‑sciences tenants using Amazon Bedrock AgentCore’s Code Interpreter in VPC mode.
- The setup places untrusted executions in a separate AWS account (the “Untrusted Code Account”), enforces DNS-level controls with Route 53 Resolver DNS Firewall, restricts network paths to specific VPC endpoints, injects per-job credentials via AWS STS, and runs continuous validation; the architecture reportedly handles >600 code execution sessions per day across >250 tenants per week with zero security incidents.
- Provides a concrete, production‑scale pattern for isolating and validating untrusted AI agent code (including DNS controls and per‑job credentials) that other regulated enterprises can adopt when running agentic workloads.
WHY IT MATTERS
Provides a concrete, production‑scale pattern for isolating and validating untrusted AI agent code (including DNS controls and per‑job credentials) that other regulated enterprises can adopt when running agentic workloads.