Supercharge regulated workloads with Claude Code and Amazon Bedrock

The availability of Anthropic Claude Opus 5…5 and Claude Sonnet 5… Claude Sonnet 5 holds FedRAMP Class D (formerly High) certification and DoD Impact Level 4 and 5 (IL4/IL5) authorization, and Claude Opus 5…5 and Claude Sonnet 5… In this post, we explore how to use these models on Amazon Be…
Please note that the following post is intended for informational purposes only. The approach detailed below may not be suitable for all organizations or compliance programs. It is important to evaluate this potential solution against the compliance requirements of your organization and any applicable regulatory obligations you may have.
The availability of Anthropic Claude Opus 5.5 and Claude Sonnet 5.5 in the AWS GovCloud (US) Regions introduces an on-ramp for AI-assisted development for workloads with regulatory or compliance requirements, including International Traffic in Arms Regulations (ITAR). Claude Sonnet 5 holds FedRAMP Class D (formerly High) certification and DoD Impact Level 4 and 5 (IL4/IL5) authorization, and Claude Opus 5.5 and Claude Sonnet 5.5 hold FedRAMP Class D certification on Amazon Bedrock (verify current model certification status).
In this post, we explore how to use these models on Amazon Bedrock in AWS GovCloud (US) with Claude Code, Anthropic’s agentic coding tool. With this solution, you can run AI-assisted workflows that speed up everyday development tasks while maintaining compliance alignment.
Amazon Bedrock in AWS GovCloud (US)
AWS GovCloud (US) Regions are designed specifically for US customers with elevated compliance needs. You can deploy generative AI workloads to sensitive environments while maintaining compliance controls. Amazon Bedrock is built with security-focused features, including:
Built-in data protection where customer content isn’t stored, logged, or used to train AWS models or shared with third parties.
FedRAMP Class D (formerly High) certification and DoD Cloud Service Provider (CSP) SRG IL4/IL5 authorization pathways, supporting government agencies’ compliance requirements. See the Amazon Bedrock models compliance page for current model-level certification status.
Integration with existing security controls and compliance frameworks available in AWS GovCloud (US), maintaining the same high security standards as other AWS Regions while providing additional authorization pathways.
Amazon Bedrock in AWS GovCloud (US) supports two endpoint surfaces, bedrock-runtime and bedrock-mantle, both powered by the same underlying Mantle inference engine with Zero Operator Access (ZOA) architecture. The bedrock-runtime endpoint uses the AWS SDK (InvokeModel and Converse APIs) and supports Amazon Bedrock Guardrails, Amazon Bedrock Knowledge Bases, Agents, and invocation logging. This makes it the recommended choice for most new applications, particularly those requiring audit trails. The bedrock-mantle endpoint supports the Anthropic Messages API natively and provides access to capabilities currently available only on that surface, such as server-side tools, background inference, and Projects. Both endpoints are available for Claude Opus 5.5, Claude Sonnet 5.5, and Claude Sonnet 5, with bedrock-runtime available in both AWS GovCloud (US) Regions (US-West and US-East) and bedrock-mantle available in AWS GovCloud (US-West).
Claude Code
Claude Code is Anthropic’s agentic coding tool that reads your codebase, edits files, runs commands, and integrates with your development tools. Powered by models such as Claude Opus 5.5 and Claude Sonnet 5.5 on Amazon Bedrock in AWS GovCloud (US), it operates directly in your terminal, your preferred integrated development environments (IDEs) such as VS Code and JetBrains, and in the background with the Claude Agent SDK. Claude Code understands your entire codebase and can work across multiple files and tools to get things done. Claude Code can:
- Write code and fix bugs spanning multiple files across your codebase.
- Answer questions about your code’s architecture and logic.
- Execute and fix tests, linting, and other commands.
- Search through Git history, resolve merge conflicts, and create commits and pull requests.
- Connect to external tools and data sources with the Model Context Protocol (MCP), including the AWS Command Line Interface (AWS CLI), Terraform, and Kubernetes.
- Spawn sub-agents that work on different parts of a task simultaneously.
- Customize behavior with CLAUDE.md memory files, skills for repeatable workflows, and hooks for pre/post-action automation.
- Automate recurring tasks and integrate with continuous integration and continuous delivery (CI/CD) through GitHub Actions or GitLab CI/CD.
To learn more, see Anthropic’s articles: Claude Code tutorials and Claude Code: Best practices for agentic coding.
Solution overview: Try Claude Code with Amazon Bedrock in AWS GovCloud (US)
This section provides step-by-step instructions for setting up and configuring Claude Code to work with Amazon Bedrock in AWS GovCloud (US), including prerequisites, installation commands, environment configuration, and verification steps.
Prerequisites
Before you get started, make sure that you have the following in place:
- An AWS GovCloud (US) account with access to Amazon Bedrock.
- Appropriate AWS Identity and Access Management (IAM) roles and permissions for Amazon Bedrock. At minimum, your IAM policy should include:
- For bedrock-runtime:
bedrock:InvokeModel,bedrock:InvokeModelWithResponseStream,bedrock:ListInferenceProfiles, andbedrock:GetInferenceProfile. - For bedrock-mantle (if using the Mantle endpoint):
bedrock-mantle:CreateInference,bedrock-mantle:GetProject,bedrock-mantle:ListProjects, andbedrock-mantle:ListModels. - Alternatively, attach the
AmazonBedrockMantleInferenceAccessmanaged policy.
- For bedrock-runtime:
- Amazon Bedrock model access to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Sonnet 5 enabled in your AWS GovCloud (US) account.
- AWS CLI configured with valid AWS session credentials using short-term API keys or AWS SSO login.
Set up Claude Code with Amazon Bedrock in AWS GovCloud (US)
After configuring AWS CLI with your credentials, install Claude Code using one of the following methods:
macOS, Linux, WSL:
Windows PowerShell:
Windows CMD:
Homebrew (macOS/Linux):
For additional installation methods, see Claude Code installation docs.
Option A: Interactive setup wizard (recommended)
- Navigate to your project:
- Launch Claude Code:
- Run through the login wizard:
At the login prompt, select 3rd-party platform, then Amazon Bedrock. Follow the wizard prompts to choose your authentication method, region (us-gov-west-1), and pin your models. The wizard saves configuration to your settings file automatically.
If you have previously configured Claude Code, run /setup-bedrock to reopen the wizard and update your credentials, region, or model pins.
Option B: Manual environment variable configuration
For scripted or enterprise deployments, set the following environment variables:
To use Claude Opus 5.5 as the primary model instead:
To pin specific model versions for consistent team deployments:
Then navigate to your project and launch Claude Code:
Option C: Using the Bedrock Mantle endpoint
Bedrock Mantle supports the Anthropic Messages API natively and is available in AWS GovCloud (US-West). To route Claude Code through Mantle:
When both bedrock-runtime and bedrock-mantle are needed in the same session:
Note: Guardrails and invocation logging are available exclusively through the bedrock-runtime endpoint. For deployments requiring these compliance features, use the bedrock-runtime endpoint (Option A or B).
Verify your configuration
Verify that Claude Code is running by checking for the Welcome to Claude Code! message in your terminal. Run the /status command to confirm your model and provider. The provider line should show Amazon Bedrock or Amazon Bedrock (Mantle) depending on your configuration.
To learn more about configuring Claude Code for Amazon Bedrock, see Claude Code on Amazon Bedrock.
Considerations when deploying Claude Code to your organization
With Claude Code now generally available, the next step is deciding how to deploy it across your organization. Consider your foundational architecture for security, governance, and compliance:
Use AWS IAM Identity Center to centrally govern identity and access to Claude Code. This verifies that only authorized developers have access. Additionally, using IAM Identity Center, developers can access resources with temporary, role-based credentials, alleviating the need for static access keys and helping enhance security. Prior to opening Claude Code, make sure that you configure AWS CLI to use an IAM Identity Center profile by using aws configure sso --profile <PROFILE_NAME>. Then log in using the profile you created: aws sso login --profile <PROFILE_NAME>.
Consider automated configuration of default environment variables. This includes the environment variables outlined in this post, such as AWS_REGION, CLAUDE_CODE_USE_BEDROCK, ANTHROPIC_MODEL, ANTHROPIC_DEFAULT_OPUS_MODEL, and ANTHROPIC_DEFAULT_SONNET_MODEL. This will configure Claude Code to automatically connect to Amazon Bedrock, providing a consistent baseline for development across teams. Organizations can start by providing developers with self-service instructions, or use settings files to manage configuration centrally.
Consider implementing Guidance for Claude Code with Amazon Bedrock for large enterprise deployments. The guidance helps organizations deploy Claude Code while maintaining strict control over AI resource access, connecting to existing identity infrastructure and providing observability for developer productivity and usage patterns.
Review service quotas and set appropriate tokens per minute (TPM) and requests per minute (RPM) based on the number of active developers. Make sure that you have enough TPM and RPM quotas to support your team’s usage. For guidance, follow the rate limit recommendations.
Pin model versions for consistent team deployments. Without pinning, model aliases such as sonnet and opus resolve to Claude Code’s built-in defaults, which may change between releases. Claude Code defaults to Claude Opus 5.5 as its primary model, so an unpinned deployment is billed at the Opus per-token rate. To keep teams on Claude Sonnet 5.5, set ANTHROPIC_MODEL to its full model ID. Use ANTHROPIC_DEFAULT_OPUS_MODEL and ANTHROPIC_DEFAULT_SONNET_MODEL to control when your team moves to a new model. In AWS GovCloud (US), use the us-gov. prefix for cross-region inference profile IDs.
Implement cost monitoring and per-user token guardrails. Claude Code sessions can be token-intensive, particularly with Claude Opus 5.5, which carries a higher per-token cost than Claude Sonnet 5.5. According to Anthropic, Claude Opus 5.5 completes tasks using fewer tokens than Claude Opus 5, at a lower price per token. Consider the following:
- Implement per-user token guardrails to enforce daily token limits per developer, with alerting at 80% and 100% thresholds. This pattern uses Amazon CloudWatch invocation logging, AWS Lambda, and Amazon DynamoDB to track and enforce limits in near real time.
- Use prompt caching to reduce costs and improve response times. Both 5-minute and 1-hour TTL options are available for supported models.
- Consider defaulting teams to Claude Sonnet 5.5 (lower cost than Claude Opus 5.5) and reserving Claude Opus 5.5 for tasks requiring deeper reasoning or longer autonomous runs. For workloads that require IL4/IL5 authorization, default to Claude Sonnet 5.
See the Claude Code Monitoring Implementation guide for additional observability patterns.
Consider permissions, memory, and MCP servers for your organization. Security teams can configure managed permissions for what Claude Code is and is not allowed to do, which cannot be overwritten by local configuration. In addition, you can configure CLAUDE.md memory files across projects to auto-add common workflows, style conventions, and coding standards to align with your organization’s preferences. Deploy your CLAUDE.md file into an enterprise directory so all developers inherit the same baseline. Use hooks to enforce pre/post-action automation such as auto-formatting or lint checks.
Choose the appropriate endpoint for your compliance requirements. The bedrock-runtime endpoint supports Guardrails, invocation logging, and cross-region inference within both AWS GovCloud (US) Regions (US-West and US-East). The bedrock-mantle endpoint supports the Anthropic Messages API natively and is available in AWS GovCloud (US-West). Guardrails and invocation logging are exclusive to bedrock-runtime today, so for deployments requiring comprehensive audit trails and content filtering, bedrock-runtime is recommended.
Conduct a thorough security assessment before deployment. Evaluate Claude Code’s capabilities against your organization’s security policies. Amazon Bedrock secures the inference layer, but Claude Code runs on local developer machines and requires separate evaluation and risk management. Apply controls such as managed permissions, invocation logging, and per-user token limits, as you would for other third-party software running in your environment.
Conclusion
The availability of Claude Opus 5.5 and Claude Sonnet 5.5 on Amazon Bedrock in AWS GovCloud (US) provides organizations with a compliance-aligned path to AI-assisted development for regulated workloads. Claude Sonnet 5, with FedRAMP Class D (formerly High) certification and DoD IL4/IL5 authorization, offers the strongest compliance coverage for sensitive environments. Claude Sonnet 5.5, with FedRAMP Class D certification, is a step up from Claude Sonnet 5 on coding and knowledge work at a lower cost per task. Claude Opus 5.5, with FedRAMP Class D certification, brings deeper reasoning and longer autonomous task capabilities for workloads where that certification level is sufficient.
Combined with Claude Code, teams can adopt agentic coding workflows directly in their terminal, IDE, or CI/CD pipelines while data remains within AWS GovCloud (US) infrastructure. Whether you choose the bedrock-runtime endpoint for full Guardrails and logging support, or the bedrock-mantle endpoint for native Anthropic Messages API access, you can tailor the deployment to your organization’s compliance and operational requirements.
For more information
- Amazon Bedrock in AWS GovCloud (US)
- Claude Code on Amazon Bedrock
- Guidance for Claude Code with Amazon Bedrock
- Amazon Bedrock model FedRAMP certification and DoD authorization status
- Per-user token guardrails for Amazon Bedrock in government agencies
- Claude Sonnet 5.5 in AWS GovCloud (US)
- Claude Opus 5.5 in AWS GovCloud (US)
About the authors
Author: Bradley Wyman