Write full README: overview, component map, deploy, demo script, caveats

This commit is contained in:
2026-07-01 05:02:08 +00:00
parent 5707ff7610
commit 293fa3d516

View File

@@ -1,3 +1,85 @@
# hncb-fusion-deid-demo # hncb-fusion-deid-demo
All-AWS demo: reversible PII de-identification round trip through Axway Amplify AI Gateway (Fusion) with an Amazon Bedrock AgentCore agent. HNCB use case. All-AWS demo of the HNCB use case: a **reversible PII de-identification round trip**
through **Axway Amplify AI Gateway (Fusion)**, with the reasoning done by an
**Amazon Bedrock AgentCore** agent. The advisor types a query containing a real
name; the cloud only ever sees a token; the real identity is restored on-prem
before the answer is shown.
> **Status: unrun scaffold.** This was authored, not executed. Review everything,
> pin dependency versions, and expect to adjust AgentCore/Fusion specifics to the
> current CLI/console. Demo-grade, not production-grade.
## What it demonstrates
Raw PII (a Chinese name + a Taiwan ROC ID) is detected on ingress, replaced with a
**random, format-safe token**, and only the tokenized prompt goes to the cloud
agent. The agent calls a tool back "on-prem" with the token, gets a de-identified
evidence package, and writes talking points. Fusion restores the identity on the
way out. **The money shot:** show the Bedrock request / AgentCore trace live — the
cloud only ever saw `CUST_000123`, never `王小明`.
## Trust zones are logical
Everything is one AWS account. The "on-prem" zone is a set of tag-labelled
resources (`Zone = on-prem-VPC-A`) standing in for HNCB's branch data centre. This
demo proves **behaviour and data-flow**, not physical data residency — say so on
camera: *"in production this zone is the branch DC; here a VPC stands in for it."*
## Component → service map (their 8 steps)
| Step | Component | Service in this repo |
|---|---|---|
| 1, 8 | Advisor UI | `ui/index.html` on S3+CloudFront (or local) |
| 2, 3-route, 8 | **Fusion AI Gateway** (the product) | ECS Fargate — `terraform/ecs.tf`, config in `fusion/POLICY_SETUP.md` |
| 2 | PII **detector** (typed findings, not redaction) | Presidio on Fargate — `presidio/` |
| 2, 4, 8 | Token **vault** (reversible map) | DynamoDB — `terraform/main.tf` |
| 3, 7 | Cloud **agent** + model | AgentCore Runtime + Bedrock — `agent/` |
| 4 | Tool bridge (Lambda → MCP tool) | AgentCore Gateway — `scripts/agentcore_setup.sh` |
| 4-6 | On-prem **RAG tool** + data | Lambda + DynamoDB — `lambda_rag/`, `seed/` |
| all | Observability | AgentCore Observability + CloudWatch |
## Repo layout
```
terraform/ core infra (DynamoDB, RAG Lambda, IAM) + ECS hosting
lambda_rag/ RAG tool: token resolve -> de-identified evidence package
agent/ Strands agent for AgentCore Runtime + tool schema
presidio/ PII detector service (returns typed findings) + Dockerfile
seed/ fake customer (Wang Xiaoming) + seed script
ui/ advisor UI with restored-vs-tokenized split view
scripts/ deploy.sh, agentcore_setup.sh, teardown.sh
fusion/ POLICY_SETUP.md (the console/flow config — the manual part)
```
## Prerequisites
`aws-cli` configured (creds + region), `terraform >= 1.5`, `docker`, `python3`,
the AgentCore CLI (`npm i -g @aws/agentcore`), Bedrock model access enabled for
`bedrock_model_id`, and an Axway Amplify AI Gateway (Fusion) container image you
supply (`fusion_image_uri`).
## Deploy
```bash
bash scripts/deploy.sh # infra -> presidio image -> ECS -> seed -> AgentCore
# then: configure Fusion policy (fusion/POLICY_SETUP.md)
# then: point ui/index.html GATEWAY_URL at the Fusion host and open it
```
## Demo script (maps to the 8 steps)
1. Advisor UI: submit *"請幫我整理王小明最近三個月的理財往來,並給我下次拜訪話術。"*
2. Fusion detects `王小明` + `A123456789`, tokenizes, logs tokens only.
3. Show the Bedrock/AgentCore trace — the prompt the cloud saw contains `CUST_000123`.
4-6. Agent tool-calls back on-prem; RAG resolves the token, returns a summary.
7. Agent writes talking points (no PII).
8. Fusion restores `王小明`; the UI shows the restored answer beside the tokenized view.
## Teardown
```bash
bash scripts/teardown.sh # stop paying for Fargate / AgentCore
```
## Honest caveats
- **zh-TW detection is demo-narrow.** Presidio here is tuned to the scripted
entities; a smooth run is **not** evidence of production zh-TW recall — that
remains the real-engagement risk.
- **Per-request randomization** ("different each time") lives in the Fusion mint
step (`fusion/POLICY_SETUP.md`); confirm it satisfies HNCB's requirement.
- **The agentic token-resolution loop** (agent tool call → on-prem RAG resolves the
token) is custom orchestration — it is not turnkey on any gateway, which is
exactly where Fusion's orchestration depth is the argument.