AWS Configuration
Runtime Security can be configured to route traffic to a single AWS account or multiple AWS accounts.- If there is only one AWS account configured, this account is used as the default for routing all traffic.
-
If multiple AWS accounts are registered, while there is a default account, it is not used for routing all traffic. Requests with incorrect AWS account information will result in an error message.
- There must be a default registered account. A single account configuration will be set as the default account.
- For any additional named credential sets, the suffix X in the environment variables should be the actual AWS Access Key ID. See the Single AWS Account and Multiple AWS Accounts examples below.
Default AWS Account
If only one AWS account is registered with Runtime Security, this account is used by default to route traffic. Example - Default AWS Account This will create a default credential set. The application can then use this credential set to configure AWS clients.Additional AWS Accounts
Runtime Security can be configured to route traffic to multiple AWS accounts. If there are multiple keys registered, there is no default account for routing traffic. Requests with incorrect AWS account information will result in an error message. When configuring multiple AWS accounts, you must create a default account and additional accounts. Example - Default AWS Account This will create a default credential set.AKIAXXXXXXXXFOO, this will create a credential set named AKIAXXXXXXXXFOO.
AWS Credential Sets Environment Variables
There must be a default AWS account, for either a single registered account or multiple registered accounts. For any additional named credential sets, the suffixX in the environment variables should be the actual AWS Access Key ID. For example, if your AWS Access Key ID is AKIAXXXXXXXXFOO, set HL_LLM_PROXY_AWS_ACCESS_KEY_ID_AKIAXXXXXXXXFOO and corresponding variables using that exact key ID. This creates a credential set named after that AWS Access Key ID.
AWS Secrets Manager
Arbitrary settings can be sourced from the AWS Secrets Manager. This is intended for Instance Profile authentication use only. The environment variable isHL_LLM_PROXY_SECRETS_<MANAGER NAME>_SECRET_<PROXY SETTING NAME>.
- For
<MANAGER NAME>, use AWS. - For
<PROXY SETTING NAME>, use any of the environment variable names for a setting.
HL_LICENSE and HL_LLM_PROXY_CLIENT_ID from a secret named HiddenLayer_Runtime in the AWS Secrets Manager.
'{"HL_LLM_PROXY_CLIENT_ID": "xxxx-xxxx-xxxx-xxxx"}'.
- This implementation requires the keys in this JSON blob to match the Proxy env var setting name.
- Alternatively, you can store a plaintext value for the secret.

