ZDX AgentCore Team // AWS Marketplace

Documentation

AWS MARKETPLACE EDITION

ZeroDriveX AgentCore Team deployment guide

This guide covers the AWS Marketplace container edition of ZeroDriveX AgentCore Team for Amazon Bedrock AgentCore Runtime. It describes launch requirements, runtime endpoints, model-provider configuration, invocation examples, persistent state, execution controls, and support.

RUNTIME CONTRACT

AgentCore-compatible HTTP interface

  • • Architecture: Linux ARM64
  • • Listen address: 0.0.0.0
  • • Port: 8080
  • • Health check: GET /ping
  • • Agent invocation: POST /invocations
  • • Operator console: /console when exposed through a trusted administrative boundary

AGENT TEAM

Five coordinated roles

Manager / Orchestrator coordinates the job. Researcher gathers technical evidence. Architect produces implementation-ready designs. Developer performs authorized repository, build, test, and implementation operations. Reviewer independently checks the result and supporting evidence.

LAUNCH

Configure the Marketplace delivery option in AgentCore Runtime

  1. 1. Subscribe to the ZeroDriveX AgentCore Team offer in AWS Marketplace.
  2. 2. Launch the Marketplace container delivery option with Amazon Bedrock AgentCore Runtime.
  3. 3. Configure at least one supported model provider through environment variables.
  4. 4. Persist /data when approvals, operations history, and report-signing identity must survive container replacement.
  5. 5. Keep AGENT_ALLOWED_COMMANDS limited to commands required for the intended workload.
  6. 6. Verify GET /ping reports a healthy runtime before sending agent work.

INVOCATION EXAMPLE

Send a JSON request to /invocations

{
  "prompt": "Inspect the configured repository, identify the highest-risk correctness issue, implement the smallest safe fix, run relevant tests, and independently review the result."
}

The runtime coordinates specialist work and applies configured capability, approval, budget, command-allowlist, and evidence controls before authorized tool execution.

CONFIGURATION

Environment variables

OPENAI_API_KEY

Optional OpenAI API key. Do not place provider credentials in prompts or logs.

OPENAI_MODEL

OpenAI model identifier. Default: gpt-5-mini.

GROQ_API_KEY

Optional Groq API key.

GROQ_MODEL

Groq model identifier. Default: openai/gpt-oss-20b.

GEMINI_API_KEY

Optional Google Gemini API key.

GEMINI_MODEL

Gemini model identifier. Default: gemini-2.5-flash.

OLLAMA_BASE_URL

Optional network-reachable Ollama base URL. localhost only works when Ollama is in the same container.

OLLAMA_MODEL

Ollama model identifier. Default: qwen2.5:3b.

MODEL_PROVIDER_ORDER

Comma-separated provider failover order. Default: openai,groq,gemini,ollama.

AGENT_ALLOWED_COMMANDS

Comma-separated command allowlist for bounded developer tooling. Keep this limited to the workload.

CHAT_MAX_ORCHESTRATION_STEPS

Maximum orchestration steps per request. Default: 8.

ZDX_OPERATIONS_HISTORY_PERSIST

Set to 1 to persist local operations history; set to 0 to disable.

ZDX_OPERATIONS_HISTORY_PATH

Operations-history path. Default: /data/agent-operations.json.

AGENT_APPROVAL_STATE_PATH

Durable exact-action approval state. Default: /data/pending-approvals.json.

ZDX_REPORT_SIGNING_KEY_PATH

Per-installation Ed25519 report-signing private key. Default: /data/report-signing-key.pem.

ZDX_REPORT_SIGNING_PUBLIC_KEY_PATH

Report-signing public key. Default: /data/report-signing-key.pub.pem.

SECURITY

Operational boundaries

  • • Store provider credentials in environment configuration, not prompts or logs.
  • • Expose the operator console only through authenticated HTTPS, a private load balancer, VPN, or equivalent trusted administrative boundary.
  • • Scope command access to the minimum required workload.
  • • Exact-action approvals bind authorization to the frozen action before execution.
  • • Signed reports use a per-installation Ed25519 identity stored under /data.

PERSISTENCE

Persist /data for durable operational state

Back the /data path with persistent storage when approval state, operations history, or signing identity must survive replacement or restart. If the runtime cannot prove whether an approved side effect completed before an interruption, automatic replay is blocked rather than guessing.

MODEL PROVIDERS AND EXTERNAL SERVICES

Customer-controlled provider configuration

The container supports configurable OpenAI, Groq, Gemini, and Ollama model providers. Provider accounts, API usage, network connectivity, and any associated third-party costs are controlled by the customer and are separate from the AWS Marketplace software offer. A remote Ollama deployment must be reachable from the AgentCore runtime network.

SUPPORT

ZeroDriveX deployment and product support

For AWS Marketplace support, include the product version, AWS Region, AgentCore deployment identifier, configured provider/model, and redacted runtime error details. Never send API keys, tokens, credentials, or proprietary source code unless explicitly requested for a support case.