Skip to content

AI-123 + AI-125: Bedrock Mantle and VPC endpoint docs for AI Gateway 2.3 - #7486

Draft
gperanich wants to merge 6 commits into
release/ai-gateway-2.3from
feature/ai-123-125-bedrock-mantle-vpc-docs
Draft

gperanich wants to merge 6 commits into
release/ai-gateway-2.3from
feature/ai-123-125-bedrock-mantle-vpc-docs

Conversation

@gperanich

@gperanich gperanich commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Resolves #7225

Summary

Docs proposal for two AI Gateway 2.3 GA features:

  • AI-123 Bedrock Mantle Parity: new endpoint_type (runtime | mantle, default runtime) on the Bedrock target config. mantle sends requests to https://bedrock-mantle.{region}.api.aws and forwards OpenAI Chat Completions / Responses and Anthropic Messages bodies without translation. A mantle target paired with a bedrock-format AI Model is rejected.
  • AI-125 Native Bedrock VPC Endpoint Support: vpc_endpoint on the shared Bedrock model config (chat/invoke targets and embeddings). Host-only override; Kong still builds Bedrock paths and streaming, and SigV4 signs for the real service and region. upstream_url wins if both are set. Plugin-level equivalent is model.options.bedrock.vpc_endpoint.

vpc_endpoint wasn't documented anywhere on main before this PR.

Changes

  • app/ai-gateway/ai-providers/bedrock.md (v2): new sections Choose a Bedrock endpoint {% new_in 2.3 %} (Runtime vs Mantle table, when to use each, the validation rule, and SigV4 or bearer auth) and Connect through a VPC endpoint {% new_in 2.3 %}, each with an entity_example.
  • app/_how-tos/ai-gateway/route-openai-traffic-to-bedrock-mantle.md (new, min_version: ai-gateway: '2.3')
  • app/_how-tos/ai-gateway/connect-to-bedrock-through-vpc-endpoint.md (new, min_version: ai-gateway: '2.3')
  • app/ai-gateway/v1/ai-providers/bedrock.md: short model.options.bedrock.vpc_endpoint section for AI Proxy / AI Proxy Advanced. The gateway version is still a TODO.

API proposal: https://github.com/Kong/platform-api/pull/3665 (endpoint_type). vpc_endpoint is already on platform-api main via #3543 (KOKO-4507).

Open questions (also left in the pages as {% comment %} TODO(reviewer) blocks)

AI-123:

  1. Which format and capability pairs map to Mantle (for example openai + generate for Chat Completions, openai + agentic for Responses)? Does Mantle support embeddings? Which Bedrock-specific APIs (Rerank, async invoke, batch) are Runtime-only?
  2. Which IAM actions does Mantle need? Which concrete model ID and region should the how-to use so validation can run in CI?
  3. Is a min-DP-version gate plus Koko enforcement enough to stop mantle from syncing to older DPs?

AI-125:

  1. If vpc_endpoint and upstream_url are both set, is that a hard validation error or does upstream_url win? The docs currently say upstream_url wins, matching the OAS description.
  2. Value format: bare hostname (the OAS says "Hostname") or a URL with a scheme (Aha says "same rules as aws_sts_endpoint_url")?
  3. Does vpc_endpoint apply to endpoint_type: mantle too, or only to Runtime?
  4. Which data plane deployments can use this: self-managed hybrid only, or Dedicated Cloud Gateways with private networking too?
  5. Which Kong Gateway version ships model.options.bedrock.vpc_endpoint in AI Proxy / AI Proxy Advanced? This decides the v1 page new_in tag. Drop that section if the plugin field ships later.

Notes for reviewers

  • This PR is based on main, and app/_data/products/ai-gateway.yml doesn't list 2.3 yet. Retarget it to the AI Gateway 2.3 release branch once that branch exists.
  • The generated schema reference picks up endpoint_type and vpc_endpoint when api-specs/ syncs from platform-api.
  • Frontmatter validator passes. I didn't run Vale or a full site build locally.

Links

🤖 Generated with Claude Code

…23, AI-125)

- Amazon Bedrock provider (v2): add "Choose a Bedrock endpoint" (runtime vs
  mantle, format and auth guidance, mantle + bedrock-format validation rule)
  and "Connect through a VPC endpoint" (vpc_endpoint, upstream_url precedence)
- New how-tos: route OpenAI traffic to Bedrock Mantle; connect to Bedrock
  through a VPC endpoint (min_version ai-gateway 2.3)
- Amazon Bedrock provider (v1): add model.options.bedrock.vpc_endpoint
  section for AI Proxy / AI Proxy Advanced, gateway version TODO

Open questions are left as {% comment %} TODO(reviewer) blocks.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@netlify

netlify Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for kongdeveloper ready!

Name Link
🔨 Latest commit 3d58ebf
🔍 Latest deploy log https://app.netlify.com/projects/kongdeveloper/deploys/6ac87716fe888b00083ff3e6
😎 Deploy Preview https://deploy-preview-7486--kongdeveloper.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@tomek-labuk
tomek-labuk changed the base branch from main to release/ai-gateway-2.3 October 8, 2026 04:53
tomek-labuk and others added 4 commits October 8, 2026 09:50
This reverts commit 6a11152.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…e requests on Bedrock

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@tomek-labuk tomek-labuk self-assigned this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Native Bedrock VPC Endpoint Support Bedrock Mantle parity

2 participants