Live
AI‑Driven Dependency Selection Needs Point‑of‑Choice Security GuardrailsEmbedding Human Judgment in AI‑Driven Code Review PipelinesStudio UI now manages SageMaker HyperPod Spaces, streamlining AI development workflowsOpen AI Models Shift Telecom Engineering: New Architecture, Ops, and Security PracticesCloudflare WAF upgrades to block new F5 BIG‑IP heap overflow and command‑injection ruleAWS scaling metrics from Prime Day 2026: what engineers need to knowBuilding a Scalable Voice Travel Concierge on Amazon Bedrock AgentCore and Nova SonicImplementing Trusted Identity Propagation for AI Data Agents on AWSAI‑Driven Dependency Selection Needs Point‑of‑Choice Security GuardrailsEmbedding Human Judgment in AI‑Driven Code Review PipelinesStudio UI now manages SageMaker HyperPod Spaces, streamlining AI development workflowsOpen AI Models Shift Telecom Engineering: New Architecture, Ops, and Security PracticesCloudflare WAF upgrades to block new F5 BIG‑IP heap overflow and command‑injection ruleAWS scaling metrics from Prime Day 2026: what engineers need to knowBuilding a Scalable Voice Travel Concierge on Amazon Bedrock AgentCore and Nova SonicImplementing Trusted Identity Propagation for AI Data Agents on AWS
AWS

Building a Scalable Voice Travel Concierge on Amazon Bedrock AgentCore and Nova Sonic

AI SummaryPowered by AI

Amazon now offers a managed stack—Bedrock AgentCore, Nova Sonic, and Knowledge Bases—to add a voice travel concierge to airline apps. This gives engineers a scalable, decoupled way to embed real‑time speech AI while leveraging existing AWS services for authentication, data storage, and operations.

Amazon has introduced a managed stack that lets you add a real‑time voice layer to an airline’s existing app using Bedrock AgentCore, Nova Sonic, and a Bedrock Knowledge Base. For engineers, this means a pre‑built, scalable path to speech‑to‑speech AI without wiring custom media pipelines or tightly coupling the agent to legacy booking services.

Solution Overview

The architecture isolates three concerns: the front‑end UI, the AI agent runtime, and the airline backend. User identity is handled by Amazon Cognito, which issues temporary AWS credentials for signed API calls. The agent runs in Bedrock AgentCore runtime, where each session is isolated in a microVM. AgentCore Gateway exposes backend endpoints as Model Context Protocol (MCP) tools, keeping the agent loosely coupled to the services it invokes.

Implementation Highlights

Deployment is driven by the AWS Cloud Development Kit (CDK), allowing the entire stack to be provisioned as code. The agent itself is built with the Strands Agents framework and leverages Amazon Nova 2.5 Sonic for bidirectional speech conversion. Business logic—such as itinerary lookup, seat‑map updates, meal preferences, and flight‑status queries—is implemented in AWS Lambda functions behind an Amazon API Gateway that enforces IAM‑based authorization. Data persistence uses Amazon DynamoDB for profiles, bookings, and conversation state. Policy‑related questions are answered by a Bedrock Knowledge Base that grounds responses in airline‑specific documents. Email notifications are sent via Amazon SES, and the React front end is hosted on AWS Amplify.

Operational and Security Considerations

Because each agent session runs in its own microVM, scaling spikes—such as holiday travel surges—are handled by the managed Bedrock service without additional capacity planning. Cognito isolates user authentication from the AI layer, and IAM policies on API Gateway restrict Lambda access to the principle of least privilege. DynamoDB provides serverless durability for both transactional data and conversational logs, simplifying backup and retention. The Knowledge Base runs as a managed retrieval‑augmented generation service, reducing the operational burden of maintaining a separate search index.

Related CloudNinjas coverage: AWS.

What This Means For Practitioners

Adopting this pattern lets you prototype a voice‑first travel assistant quickly while keeping the underlying services modular. Evaluate the MCP tool definitions to ensure they map cleanly to existing Lambda APIs. Verify that Cognito identity pools and IAM roles are scoped correctly for the least‑privilege access required by the agent. Monitor Bedrock AgentCore runtime metrics to size microVM capacity for peak traffic. Finally, treat the Knowledge Base as a separate trust boundary for policy content and apply appropriate data‑handling controls.

Originally published atAWS Machine Learning Blog