Building on the Clouds
AWS AgentCore, Microsoft Foundry, and Vertex AI — deploy, secure, and pay for agents
- The Cloud Agent Landscape: Three Managed Platforms, One Map — AWS Bedrock AgentCore, Microsoft Foundry Agent Service, and Google’s Agent Platform side by side — what a managed agent platform actually gives you, what you trade away, the seven concepts all three implement under different names, the shape of their meters, and how to pick one without a feature bake-off. (5 lessons, 40 min)
- Amazon Bedrock AgentCore, Service by Service — AWS unbundled the managed agent. AgentCore is nine independently usable services — Runtime, Memory, Gateway, Identity, Policy, Code Interpreter, Browser, Observability, Evaluations, plus the Agent Registry — that work with any framework and any model. Learn what each one actually does, how Bedrock Agents Classic maps onto them, and where Strands fits. (6 lessons, 50 min)
- AWS Agents in Practice: Deploy, Authorize, Guard, Observe, Pay — The day-two module. How an agent actually gets onto AgentCore Runtime and when plain Lambda or ECS is still the right answer; IAM roles versus AgentCore Identity and how an agent acts on behalf of a user; where guardrail checks attach so the model cannot argue with them; how traces reach CloudWatch; and which consumption dimensions dominate an agent bill on AWS. (5 lessons, 45 min)
- Microsoft Foundry Agent Service, Three Ways to Run an Agent — Microsoft renamed the platform twice and rebuilt the agent primitive once. Learn the current shape: prompt agents (no infrastructure), hosted agents (your container, their endpoint and Entra identity), and ephemeral agents via the Responses API — plus Toolboxes as one governed MCP endpoint, where Microsoft Agent Framework fits, and how publishing and agent identity actually work. (5 lessons, 50 min)
- Microsoft Foundry Agents in Practice: Identity, Boundaries, Guardrails, Traces, Bills — Day two on Microsoft Foundry. Every agent gets an Entra identity and can act on behalf of a user — decide when it should. Standard setup pulls conversation state into your own storage, search and Cosmos DB, and network injection is a one-way door. Guardrails scan four intervention points including tool responses for cross-prompt injection, and they are one layer, not the defence. Then traces into Application Insights, version rollback, and the two shapes of a Foundry agent bill. (5 lessons, 45 min)
- Google’s Agent Stack: ADK, Agent Runtime, and the Names That Keep Moving — Google ships the agent stack in two halves: ADK, an open-source, five-language framework you can run on your laptop, and a managed platform — Agent Runtime, Sessions, Memory Bank, Agent Gateway — that runs it for you. Learn the pieces, the ADK vocabulary, the runtime’s operational and billing shape, Google’s A2A posture, and the guardrails that actually bind — with the branding churn labelled honestly. (5 lessons, 45 min)
- Choosing a Cloud for Agents: A Decision You Can Defend — The synthesis module. Not what the three platforms are — you already know that — but how to decide between them: the axes that actually carry weight (data gravity, identity provider, delivery surface, boundary constraints, commitments, team skills), what travels when you change your mind, the security invariants that must hold on any cloud, how to run an honest bake-off, and a decision tree that ends in a recommendation you can put in writing. (5 lessons, 40 min)
- The Well-Architected Agentic AI Lens: 41 Questions Worth Borrowing — AWS published a Well-Architected lens for agents on 10 June 2026 — 6 pillars, 41 focus-area questions, 150 best practices, 90 of them rated High risk. This module gets you all 41 questions without reading 150 pages of vendor documentation, then draws the line that matters: the questions travel to any platform, the answers are AWS services, and a completed review is a conversation record rather than a certificate. (5 lessons, 40 min)