The all-powerful, all-encompassing agentic system
Self-evolutionary. Self-optimizing. Self-expanding. A self-evolving, multi-tenant, AWS-native agent platform. Built on Bedrock AgentCore, Strands Agents, and AI SDK v5 Data Stream Protocol.
Chimera β the multi-formed creature of Greek mythology. Like its namesake, this platform is many things at once: multi-tenant, multi-agent, multi-platform, and self-evolving. It shape-shifts to serve each tenant's needs while maintaining a unified architecture.
π Read the Complete Vision β β The authoritative vision document covering identity, heritage, AWS account intelligence, infrastructure-as-capability, autonomous problem-solving, self-evolution, and more.
Chimera is a production-ready Agent-as-a-Service platform where:
- Tenants deploy AI agents with first-class AWS account access across multiple channels
- Agents use 40 AWS tools, multi-modal processing, memory, and orchestration to build, deploy, and operate infrastructure autonomously
- The platform self-evolves: auto-generates skills, optimizes model routing, A/B tests prompts, modifies its own infrastructure
- Everything runs on AWS managed services with AgentCore MicroVM isolation and 14 production-grade CDK stacks
Chimera is an AWS-native rebuild inspired by:
| Project | Inspiration |
|---|---|
| OpenClaw | 4-tool minimalism, SKILL.md format, ClawHub marketplace, 23+ chat channels |
| NemoClaw | Enterprise security (Landlock LSM, seccomp), deny-by-default policies |
| OpenFang | Rust Agent OS, 16-layer security, WASM sandbox, 180ms cold start |
| Capability | Implementation Status |
|---|---|
| AWS Account Intelligence | β BUILT β 40 AWS tools (19 TypeScript + 21 Python: EC2, S3, Lambda, CloudWatch, RDS, SageMaker, Athena, Step Functions, CodePipeline, etc.) β’ Discovery modules (Config, Resource Explorer, Cost analyzer, Stack inventory) β’ Well-Architected Framework tool for architecture review |
| Infrastructure as Capability | β BUILT β Infra-builder module generates CDK from requirements β’ CodeCommit/CodePipeline tools for git-based deployment β’ Self-modifying IaC with safety harness |
| Multi-Modal Processing | β BUILT β Auto-detection and routing for images, audio, video, documents β’ Rekognition, Transcribe, Textract tools integrated |
| Agent Runtime | β BUILT β Python agent with Strands SDK + AgentCore Runtime β’ ReAct loop with streaming β’ MicroVM isolation β’ AgentCore Memory integration (STM + LTM) |
| Autonomous Problem Solving | β BUILT β Swarm orchestration (task decomposer, role assigner, progressive refiner, blocker resolver, HITL gateway) β’ Multi-agent workflows via Step Functions |
| Self-Evolution | β BUILT β 7 evolution modules (auto-skill generator, experiment runner, IaC modifier, model router, prompt optimizer, safety harness) β’ A/B testing framework β’ Evolution stack (577 LOC) |
| Multi-Tenant Isolation | β BUILT β Tenant router, Cedar authorization engine, quota manager, rate limiter (token bucket) β’ Per-tenant KMS encryption β’ DynamoDB partition isolation with GSI FilterExpression enforcement |
| Enterprise Security | β BUILT β 7-stage skill security pipeline β’ Trust engine with 5-tier model β’ Cross-tenant isolation tests β’ Audit trail with CMK encryption |
| Observability | β BUILT β Activity logging with ADR/runbook generators β’ CloudWatch alarms with runbooks β’ X-Ray distributed tracing β’ Real-time cost tracking |
| Multi-Account Management | β BUILT β Multi-account orchestration module β’ AWS Organizations integration β’ Cross-account role assumption β’ SCP enforcement |
| Universal Skills | β BUILT β Skill registry, discovery, installer, validator, MCP gateway client β’ SKILL.md v2 parser β’ 5-tier trust model (Platform, Verified, Community, Private, Experimental) |
| Multi-Platform Chat | β BUILT β 5 platform adapters (Web, Slack, Discord, Teams, Telegram) β’ AI SDK v5 Data Stream Protocol β’ SSE bridge (760+ LOC) β’ Chimera identity + system prompt wired β’ Real Bedrock streaming via BedrockModel (ConverseStream) + MantleModel (OpenAI-compat) |
| CLI Deploy Flow | β BUILT β 21 commands: deploy, monitor, chat, doctor, login (terminal + browser), session, skill, tenant, status, sync, init, setup, destroy, upgrade, connect, completion, endpoints, config, logs, version, help |
Platform Adapters (Web, Slack, Discord, Teams, Telegram)
β
Hono on ECS Fargate (chat-gateway)
β AI SDK v5 Data Stream Protocol
βββββββ΄βββββββββββββββββββββββββββ
β BedrockModel (ConverseStream) β
β MantleModel (OpenAI-compat) β
βββββββ¬βββββββββββββββββββββββββββ
API Gateway (HTTP API, WebSocket)
β
Tenant Router (Cognito JWT β DynamoDB)
β
ββββββ΄βββββββββββββββββββββββββββββ
β AgentCore Runtime β
β βββββββββββ βββββββββββ βββββββββ β
β βTenant A β βTenant B β β Cron β β
β βMicroVM β βMicroVM β βMicroVMβ β
β β(Strands)β β(Strands)β β β β
β ββββββ¬βββββ ββββββ¬βββββ βββββ¬ββββ β
βββββββββΌβββββββββββββΌββββββββββΌββββββ
β β β
ββββββββ΄βββββββ¬ββββββ΄ββββ¬ββββββ΄βββββββ
β β β β
AgentCore AgentCore AgentCore AgentCore
Memory Gateway Code Interp Browser
(STM+LTM) (MCP) (Sandbox) (CDP)
| Service | Role |
|---|---|
| AgentCore Runtime | Agent execution (MicroVM isolation) |
| AgentCore Memory | Session + long-term memory |
| AgentCore Gateway | MCP tool routing |
| AgentCore Identity | Auth (inbound + outbound) |
| AgentCore Code Interpreter | Safe code execution (OpenSandbox) |
| AgentCore Browser | Web browsing (Playwright CDP) |
| DynamoDB | State (6 tables: tenants, sessions, skills, rate-limits, cost-tracking, audit) |
| S3 | Storage (skills, tenant data, artifacts, workspace archives) |
| EFS | Agent workspaces (POSIX filesystem, ephemeral) |
| CodeCommit | Git-backed workspaces (version control for agent sessions) |
| CodePipeline | CI/CD for agent-generated infrastructure |
| Cognito | Tenant authentication |
| API Gateway | API layer (HTTP + WebSocket) |
| ECS Fargate | Chat gateway + SSE bridge |
| EventBridge | Cron scheduling |
| Step Functions | Workflow orchestration |
| Cedar | Policy engine (IAM-style authorization) |
| KMS | Per-tenant encryption keys |
| AWS Organizations | Multi-account management + consolidated billing |
| CloudWatch + X-Ray | Observability + distributed tracing |
| AWS Config | Resource discovery + compliance tracking |
| Resource Explorer | Fast cross-region search |
# Install the CLI (download from GitHub releases)
curl -L https://github.com/Codeseys-Labs/chimera/releases/latest/download/chimera-darwin-arm64.tar.gz | tar xz
chmod +x chimera-darwin-arm64
sudo mv chimera-darwin-arm64 /usr/local/bin/chimera
chimera --version # should print v0.6.3
# Or build from source
git clone https://github.com/Codeseys-Labs/chimera.git
cd chimera
bun install
bun run compile:cli # produces packages/cli/chimera-<platform>
sudo mv packages/cli/chimera-* /usr/local/bin/chimera
# Deploy to your AWS account
chimera init # Configure AWS profile + region
chimera deploy --source git \ # Deploy from GitHub
--remote https://github.com/Codeseys-Labs/chimera.git
chimera setup # Create admin Cognito user
chimera endpoints # Fetch and save all URLs
# Verify
chimera status # Check all 14 stack statuses
chimera doctor # Run health checks
# Chat with the agent
chimera chat # Terminal chat
# Or open the web UI at the Frontend URL from chimera.toml
# Tear down everything
chimera destroy --forcechimera/
βββ packages/
β βββ core/ # Strands agent definitions + runtime
β βββ agents/ # Python agent runtime
β βββ sse-bridge/ # Strands to Vercel DSP bridge
β βββ chat-gateway/ # Vercel Chat SDK + SSE bridge
β βββ cli/ # chimera CLI
β βββ shared/ # Types, utils, schemas
βββ infra/ # CDK infrastructure
β βββ bin/ # App entry point
β βββ lib/ # Stack definitions
β βββ constructs/ # L3 constructs
βββ docs/ # Documentation
β βββ architecture/ # ADRs and architecture docs
β β βββ decisions/ # 32 Architecture Decision Records
β βββ guide/ # Core guides
β βββ guides/ # Operational guides
β βββ research/ # Research documents
β βββ runbooks/ # Operational runbooks
βββ tests/ # Integration + E2E tests
Platform: Production β v0.6.3 β All 14 CDK stacks deploy and destroy cleanly. Full lifecycle verified with the released CLI binary. Live in baladita+Bedrock-Admin (us-west-2). v0.6.3 bundles Waves 15-19 β a 90+ commit post-deploy hardening pass across security-ops, observability, DR tooling, 39 ADRs, and architecture documentation.
First-time deploy? See
docs/runbooks/first-deploy-baladita.mdfor a pre-flight checklist including Bedrock model approvals, service quota requirements, and the 7 risk items a Wave-10 code review flagged inchimera deploy.
| Phase | Status | Key Deliverables |
|---|---|---|
| 0. Foundation | β COMPLETE | 14 CDK stacks (8,700+ LOC), 6-table DynamoDB design, VPC + networking, 34 ADRs, L3 constructs |
| 1. Agent Runtime | β COMPLETE | Python agent with Strands SDK + AgentCore β’ 40 AWS tools β’ Multi-modal processing β’ Discovery modules β’ Gateway-based tool discovery |
| 2. Chat Gateway | β COMPLETE | SSE bridge ship-ready β’ Chimera identity + system prompt wired β’ Bedrock model corrected β’ DSP parser fixed β’ React frontend with Amplify auth β’ Deployed |
| 3. Skill Ecosystem | β COMPLETE | Registry, discovery, installer, validator, MCP gateway β’ Trust engine β’ 7-stage security pipeline β’ SKILL.md v2 parser β’ MCP/instruction/hybrid providers |
| 4. Multi-Tenant | β COMPLETE | Tenant router β’ Cedar authorization β’ Rate limiting β’ Quota management β’ Cost tracking β’ Per-tenant KMS |
| 5. Orchestration | β COMPLETE | Swarm modules (5 components) β’ HITL DDB persistence β’ Multi-agent workflows β’ SQS/DDB/EventBridge stubs wired |
| 6. Self-Evolution | β COMPLETE | 7 evolution modules β’ Prompt A/B testing β’ Auto-skill generation β’ Model routing β’ Self-modifying IaC with safety harness |
| 7. Production | β COMPLETE | Verified: deploy from public repo β 14 stacks β E2E pass β destroy β clean account |
Test Coverage: ~2,500 tests across 150+ test files (1,285 core, 60 web, 43 SSE bridge, 196 orchestration, 178 chat-gateway, 11 Playwright E2E specs).
- VISION.md β The authoritative Chimera vision (identity, capabilities, self-evolution)
- ROADMAP.md β Implementation roadmap and phasing
- CLAUDE.md β Development workflow and Overstory conventions
- AGENTS.md β Mulch, Seeds, Canopy quick reference
- System Architecture β 9 mermaid diagrams covering CDK stacks, request flows, auth, self-evolution, multi-tenant isolation, skill lifecycle, deploy pipeline, and session state
- CLI Lifecycle β Command registry, 7-stage operator workflow, deploy internals, Cognito challenge loop, doctor health checks
- Deployment Architecture β 15-stack CDK topology, deployment order, CDK Nag compliance, custom aspects
- Agent Architecture β Strands ReAct loop, AWS tool tiers, skill runtime, evolution engine, memory architecture
- Canonical Data Model β 6-table DynamoDB schema, GSI design, multi-tenant isolation patterns
Production Implementation:
| Metric | Count |
|---|---|
| Packages | 7 (core, agents, shared, sse-bridge, chat-gateway, cli, web) |
| CDK Infrastructure Stacks | 14 stacks (8,700+ LOC) |
| TypeScript LOC | ~91,300 lines |
| Python Agent Runtime | 252 lines (chimera_agent.py) + ~9,200 total Python LOC |
| AWS Tool Implementations | 40 tools (19 TypeScript + 21 Python) + 5 Cloud Map discovery tools |
| CLI Commands | 21 (chat, completion, config, connect, deploy, destroy, doctor, endpoints, help, init, login, logs, monitor, session, setup, skill, status, sync, tenant, upgrade, version) |
| Core Modules | 22 (activity, agent, auth, aws-tools, billing, discovery, events, evolution, gateway, infra-builder, media, memory, multi-account, orchestration, runtime, skills, stream, swarm, tenant, tools, well-architected) |
| Test Coverage | ~2,500 tests across 150+ test files |
| Test Assertions | 4,084 expect() calls |
| Architecture Decision Records | 34 ADRs |
| Research Documentation | 123 docs, 118,000+ lines |
Key Components Built:
- β Agent runtime (Strands + AgentCore in Python, 252 LOC + ~9,200 total)
- β 40 AWS service tools (19 TypeScript + 21 Python: EC2, S3, Lambda, RDS, SageMaker, Athena, Glue, Redshift, OpenSearch, Step Functions, CodePipeline, CodeCommit, CodeBuild, CloudWatch, Rekognition, Transcribe, Textract, SQS, Bedrock, etc.)
- β Discovery triad (AWS Config, Resource Explorer, Cost Explorer)
- β Multi-modal media processing (auto-detection, routing)
- β Swarm orchestration (5 components: task decomposer, role assigner, progressive refiner, blocker resolver, HITL gateway)
- β Self-evolution engine (7 modules: auto-skill gen, experiments, IaC modifier, model router, prompt optimizer, safety harness)
- β Multi-tenant isolation (tenant router, Cedar auth, rate limiter, quota manager, cost tracker)
- β Universal skill system (registry, discovery, installer, validator, MCP gateway, trust engine)
- β Well-Architected Framework integration (6-pillar review tool)
- β Infrastructure-as-code builder (CDK generation from requirements)
- β Activity logging with ADR/runbook auto-generation
- β 14 production CDK stacks (8,700+ LOC) (Network, Data, Security, Observability, API, Chat, Tenant Onboarding, Pipeline, Skill Pipeline, Evolution, Orchestration, Email, Frontend, GatewayRegistration, Destroy)
chimera destroy --force runs a 3-phase CodeBuild-delegated teardown that removes all 14 stacks and leaves the AWS account clean. Phase 1 destroys application stacks (Chat, API, Frontend, etc.), Phase 2 removes data and security stacks (with S3 bucket auto-emptying and Cognito cleanup), and Phase 3 tears down the network foundation. See ADR-032 for design details.
Apache-2.0
Chimera β where agents are forged.