PRAE for agent workloads on AWS ECS, EKS and Lambda.

In part

For agent workloads running in AWS containerized and serverless environments, PRAE provides runtime policy enforcement and execution evidence today through the Node / TypeScript SDK: a workload on ECS, EKS or Lambda imports prae-gate, judges each tool call in its own loop before the call runs, and appends each decision to a ledger it writes. Additional cloud deployment capabilities are on the roadmap.

Serves: Custom / homegrown agents →Deployed SaaS agents →

  1. 01 · Where the agent operates

    AWS ECS / EKS / Lambda

  2. 02 · What it can reach

    Whatever the workload’s IAM role and network allow: AWS services, internal APIs, databases, data stores and production systems.

  3. 03 · Where PRAE intervenes

    In the workload’s own tool loop, before each tool executes. Not at the network, the VPC or the AWS API.

04 · What PRAE does: Evaluate → Enforce → Steer → Prove

  1. Evaluate

    judge() checks each tool call your workload makes against your pack: tool, arguments, paths, hosts, commands, budgets.

  2. Enforce

    Your loop honours the verdict: a refused call never runs, a held call waits for the approval path your application provides.

  3. Steer

    Not in the SDK yet.

  4. Prove

    Each decision is appended to a hash-chained ledger file the workload writes, signed when you give it a key. Keeping that file is yours to run.

05 · What you get, and how it plugs in

  1. Add to the workload’s image or bundle npm install prae-gate
  2. Before each tool runs const { decision, record } = judge(pack, { name, arguments })
  3. Record the decision ledger.append(record)
  4. Honour the verdict deny → do not run · ask → hold for a person · allow → run

Any tool call your workload’s loop sends through judge(), with the same rules, verdicts and ledger rows as the SDK anywhere else.

Enforcement happens only where your workload’s code calls the gate: a call it does not check is not seen. PRAE does not intercept network traffic, egress or tool calls at the infrastructure level: there is no sidecar, VPC proxy or Lambda extension. Node and TypeScript only; Python is not supported. There is no AWS-specific integration, marketplace listing or managed service. On Lambda the ledger is a file in the function’s temporary storage unless your workload ships it elsewhere. Not yet validated end to end on ECS, EKS or Lambda.

Where PRAE sits

Agent runtime → PRAE enforcement → tool, service or production action. The agent runtime is your container on ECS or EKS, or your Lambda function. PRAE enforcement is prae-gate’s judge(), called from that runtime’s own tool loop. The action runs only if the verdict allows it. PRAE adds no AWS permission to the workload and makes no AWS call of its own.

Package the gate and the pack

Install prae-gate with the workload’s other dependencies and ship your policy pack with the image or the function bundle. The code is the same as anywhere else Node runs: see the Node / TypeScript SDK guide.

import { judge, Ledger, parsePack } from 'prae-gate'

The ledger on ECS, EKS and Lambda

The ledger is a file the workload appends to. On ECS and EKS, write it to a volume that outlives the task or pod. On Lambda, the writable path is the function’s temporary storage (/tmp): it is lost when the execution environment is recycled, and each concurrent environment keeps its own chain. Ship the file to storage you own if you need to keep it. PRAE does not provide a managed store and does not ship it for you.

const ledger = Ledger.open('/tmp/decisions.jsonl')

Held calls in an unattended workload

A workload no one is watching still receives ask verdicts. Your application decides what a hold means there: queue it for a person, or refuse it. PRAE does not provide a hosted approval service.