View a markdown version of this page

Conditions préalables - Base rocheuse de l'Amazonie AgentCore

Les traductions sont fournies par des outils de traduction automatique. En cas de conflit entre le contenu d'une traduction et celui de la version originale en anglais, la version anglaise prévaudra.

Conditions préalables

La migration est désormais ouverte

AWS Le registre des agents a été lancé sous le nouvel agent-registry espace de noms. La prise en charge de l'bedrock-agentcoreespace de noms de version préliminaire publique sera interrompue le 17 septembre 2026. Pour obtenir des instructions de migration, consultez le guide complet de migration du registre.

Avant d'utiliser le registre des AWS agents, remplissez les conditions préalables suivantes.

AWS compte et informations d'identification

Vous avez besoin d'un AWS compte avec des informations d'identification configurées. Pour configurer les informations d'identification, installez et utilisez l'interface de ligne de AWS commande en suivant les étapes de la section Démarrage avec l' AWS interface de ligne de commande.

# Verify installation aws --version # Should show version 2.

Python et AWS Kit SDK

Pour accéder à vos AWS informations d'identification et les configurer pour les utiliser avec les kits de développement logiciel, suivez les étapes décrites dans la section Utiliser IAM Identity Center pour authentifier le AWS SDK et les outils. Si vous envisagez d'utiliser le SDK AWS Python (Boto3) pour interagir avec le registre des AWS agents par programmation :

  1. Installez Python 3.10+.

  2. Installez le AWS SDK : pip install boto3

  3. Vérifiez que vos informations d'identification sont configurées : aws sts get-caller-identity

Reportez-vous à AWS Builder Tools pour plus d'informations sur la configuration et l'utilisation du AWS SDK.

Autorisations IAM

Configurez les autorisations IAM en fonction du personnage correspondant à votre rôle. La liste complète des autorisations IAM pour le registre se trouve dans Permissions IAM.

Autorisations d’administrateur

Pour les administrateurs qui gèrent le cycle de vie complet des registres, des enregistrements et des enregistrements approve/reject /deprecate :

Exemple
AWS Agent Registry namespace
{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowCreatingAndListingRegistries", "Effect": "Allow", "Action": [ "agent-registry:CreateRegistry", "agent-registry:ListRegistries" ], "Resource": [ "arn:aws:agent-registry:*:<account>:*" ] }, { "Sid": "AllowGetUpdateDeleteRegistry", "Effect": "Allow", "Action": [ "agent-registry:GetRegistry", "agent-registry:UpdateRegistry", "agent-registry:DeleteRegistry" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*" ] }, { "Sid": "AllowCreatingAndListingRecords", "Effect": "Allow", "Action": [ "agent-registry:CreateRegistryRecord", "agent-registry:ListRegistryRecords" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*" ] }, { "Sid": "AllowRecordLevelOperations", "Effect": "Allow", "Action": [ "agent-registry:GetRegistryRecord", "agent-registry:UpdateRegistryRecord", "agent-registry:DeleteRegistryRecord", "agent-registry:SubmitRegistryRecordForApproval" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*/record/*" ] }, { "Sid": "AllowApproveRejectDeprecateRecords", "Effect": "Allow", "Action": [ "agent-registry:UpdateRegistryRecordStatus" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*/record/*" ] }, { "Sid": "AdditionalPermissionForRegistryManagedWorkloadIdentity", "Effect": "Allow", "Action": [ "bedrock-agentcore:*WorkloadIdentity" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:workload-identity-directory/default/*" ] }, { "Sid": "AllowPermissionForCreatingServiceLinkedRole", "Effect": "Allow", "Action": [ "iam:CreateServiceLinkedRole" ], "Resource": [ "arn:aws:iam::*:role/aws-service-role/agent-registry.amazonaws.com/AWSServiceRoleForAgentRegistry" ], "Condition": { "StringLike": { "iam:AWSServiceName": "agent-registry.amazonaws.com" } } } ] }
Amazon Bedrock AgentCore namespace (to be deprecated)
{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowCreatingAndListingRegistries", "Effect": "Allow", "Action": [ "bedrock-agentcore:CreateRegistry", "bedrock-agentcore:ListRegistries" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:*" ] }, { "Sid": "AllowGetUpdateDeleteRegistry", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetRegistry", "bedrock-agentcore:UpdateRegistry", "bedrock-agentcore:DeleteRegistry" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*" ] }, { "Sid": "AllowCreatingAndListingRecords", "Effect": "Allow", "Action": [ "bedrock-agentcore:CreateRegistryRecord", "bedrock-agentcore:ListRegistryRecords" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*" ] }, { "Sid": "AllowRecordLevelOperations", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetRegistryRecord", "bedrock-agentcore:UpdateRegistryRecord", "bedrock-agentcore:DeleteRegistryRecord", "bedrock-agentcore:SubmitRegistryRecordForApproval" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*/record/*" ] }, { "Sid": "AllowApproveRejectDeprecateRecords", "Effect": "Allow", "Action": [ "bedrock-agentcore:UpdateRegistryRecordStatus" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*/record/*" ] }, { "Sid": "AdditionalPermissionForRegistryManagedWorkloadIdentity", "Effect": "Allow", "Action": [ "bedrock-agentcore:*WorkloadIdentity" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:workload-identity-directory/default/*" ] }, { "Sid": "AllowPermissionForCreatingServiceLinkedRole", "Effect": "Allow", "Action": [ "iam:CreateServiceLinkedRole" ], "Resource": [ "arn:aws:iam::*:role/aws-service-role/agent-registry.amazonaws.com/AWSServiceRoleForAgentRegistry" ], "Condition": { "StringLike": { "iam:AWSServiceName": "agent-registry.amazonaws.com" } } } ] }

Autorisations du curateur ou de l'approbateur

Pour les conservateurs qui révisent et approve/reject enregistrent mais n'effectuent pas d'opérations administratives :

Exemple
AWS Agent Registry namespace
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "agent-registry:ListRegistries" ], "Resource": [ "arn:aws:agent-registry:*:<account>:*" ] }, { "Effect": "Allow", "Action": [ "agent-registry:GetRegistry" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*" ] }, { "Effect": "Allow", "Action": [ "agent-registry:ListRegistryRecords" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*" ] }, { "Effect": "Allow", "Action": [ "agent-registry:GetRegistryRecord" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*/record/*" ] }, { "Effect": "Allow", "Action": [ "agent-registry:UpdateRegistryRecordStatus" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*/record/*" ] } ] }
Amazon Bedrock AgentCore namespace (to be deprecated)
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "bedrock-agentcore:ListRegistries" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:*" ] }, { "Effect": "Allow", "Action": [ "bedrock-agentcore:GetRegistry" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*" ] }, { "Effect": "Allow", "Action": [ "bedrock-agentcore:ListRegistryRecords" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*" ] }, { "Effect": "Allow", "Action": [ "bedrock-agentcore:GetRegistryRecord" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*/record/*" ] }, { "Effect": "Allow", "Action": [ "bedrock-agentcore:UpdateRegistryRecordStatus" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*/record/*" ] } ] }

Autorisations de l'éditeur

Pour les éditeurs qui soumettent des serveurs MCP, des agents ou d'autres ressources au registre :

Note

Les trois instructions liées à la synchronisation (AllowWorkloadIdentityForSynchronization,AllowGetResourceOauth2TokenForOauthBasedSynchronization,AllowPassRoleForIamBasedSynchronization) autorisent l'identité de la charge de travail et les ressources du fournisseur d'informations d'identification OAuth gérées par Identity. AgentCore Ces ressources restent intentionnellement dans l'bedrock-agentcoreespace de noms, de sorte que leurs actions, leurs ARN et leur principal de service ne changent pas.

Note

Étendez la AllowGetResourceOauth2TokenForOauthBasedSynchronization déclaration à l'ARN du fournisseur d'informations d'identification OAuth spécifique dont le jeton d'accès a besoin pour cette identité. Évitez les caractères génériques dans le segment fournisseur de l'ARN, par exemple en accordant l'accès à tous les fournisseurs token-vault/ d'token-vault/default/oauth2credentialprovider/informations d'identification OAuth du compte, ce qui peut permettre l'accès aux informations d'identification entre les équipes. Suivez le principe du moindre privilège en nommant le fournisseur spécifique dans le Resource champ, par exemplearn:aws:bedrock-agentcore:<region>:<account>:token-vault/default/oauth2credentialprovider/<oauthProviderName>.

Exemple
AWS Agent Registry namespace
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "agent-registry:ListRegistries" ], "Resource": [ "arn:aws:agent-registry:*:<account>:*" ] }, { "Effect": "Allow", "Action": [ "agent-registry:GetRegistry" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*" ] }, { "Effect": "Allow", "Action": [ "agent-registry:CreateRegistryRecord", "agent-registry:ListRegistryRecords" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*" ] }, { "Effect": "Allow", "Action": [ "agent-registry:GetRegistryRecord", "agent-registry:UpdateRegistryRecord", "agent-registry:DeleteRegistryRecord", "agent-registry:SubmitRegistryRecordForApproval" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*/record/*" ] }, { "Sid": "AllowWorkloadIdentityForSynchronization", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetWorkloadAccessToken" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:workload-identity-directory/*" ] }, { "Sid": "AllowGetResourceOauth2TokenForOauthBasedSynchronization", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetResourceOauth2Token" ], "Resource": [ "arn:aws:bedrock-agentcore:<region>:<account>:token-vault/default/oauth2credentialprovider/<oauthProviderName>" ] }, { "Sid": "AllowPassRoleForIamBasedSynchronization", "Effect": "Allow", "Action": [ "iam:PassRole" ], "Resource": [ "arn:aws:iam::<account>:role/<your-sync-role-name>" ], "Condition": { "StringEquals": { "iam:PassedToService": "bedrock-agentcore.amazonaws.com" }, "StringLike": { "iam:AssociatedResourceARN": "arn:aws:bedrock-agentcore:<region>:<account>:registry/*/record/*" } } } ] }
Amazon Bedrock AgentCore namespace (to be deprecated)
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "bedrock-agentcore:ListRegistries" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:*" ] }, { "Effect": "Allow", "Action": [ "bedrock-agentcore:GetRegistry" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*" ] }, { "Effect": "Allow", "Action": [ "bedrock-agentcore:CreateRegistryRecord", "bedrock-agentcore:ListRegistryRecords" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*" ] }, { "Effect": "Allow", "Action": [ "bedrock-agentcore:GetRegistryRecord", "bedrock-agentcore:UpdateRegistryRecord", "bedrock-agentcore:DeleteRegistryRecord", "bedrock-agentcore:SubmitRegistryRecordForApproval" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*/record/*" ] }, { "Sid": "AllowWorkloadIdentityForSynchronization", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetWorkloadAccessToken" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:workload-identity-directory/*" ] }, { "Sid": "AllowGetResourceOauth2TokenForOauthBasedSynchronization", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetResourceOauth2Token" ], "Resource": [ "arn:aws:bedrock-agentcore:<region>:<account>:token-vault/default/oauth2credentialprovider/<oauthProviderName>" ] }, { "Sid": "AllowPassRoleForIamBasedSynchronization", "Effect": "Allow", "Action": [ "iam:PassRole" ], "Resource": [ "arn:aws:iam::<account>:role/<your-sync-role-name>" ], "Condition": { "StringEquals": { "iam:PassedToService": "bedrock-agentcore.amazonaws.com" }, "StringLike": { "iam:AssociatedResourceARN": "arn:aws:bedrock-agentcore:<region>:<account>:registry/*/record/*" } } } ] }

Autorisations pour les consommateurs

Pour les consommateurs qui recherchent et utilisent des ressources approuvées :

Exemple
AWS Agent Registry namespace
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "agent-registry:ListRegistries" ], "Resource": [ "arn:aws:agent-registry:*:<account>:*" ] }, { "Effect": "Allow", "Action": [ "agent-registry:GetRegistry" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*" ] }, { "Effect": "Allow", "Action": [ "agent-registry:SearchDiscoverableRegistryRecords", "agent-registry:ListDiscoverableRegistryRecords", "agent-registry:GetDiscoverableRegistryRecord", "agent-registry:InvokeRegistryMcp" ], "Resource": [ "arn:aws:agent-registry:*:<account>:registry/*" ] } ] }
Amazon Bedrock AgentCore namespace (to be deprecated)
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "bedrock-agentcore:ListRegistries" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:*" ] }, { "Effect": "Allow", "Action": [ "bedrock-agentcore:GetRegistry" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*" ] }, { "Effect": "Allow", "Action": [ "bedrock-agentcore:SearchRegistryRecords", "bedrock-agentcore:InvokeRegistryMcp" ], "Resource": [ "arn:aws:bedrock-agentcore:*:<account>:registry/*" ] } ] }

Pour des exemples de politiques IAM, consultez la section Gestion des identités et des accès pour Amazon AgentCore Bedrock.

(Facultatif) Fournisseur d'identité pour l'autorisation JWT

Si vous envisagez d'utiliser l'autorisation JWT pour l'identité entrante (afin de permettre aux consommateurs d'effectuer des recherches dans le registre à l'aide d' Non-IAM identités), configurez Amazon Cognito ou votre propre fournisseur d'identité avant de créer le registre :

  1. Créez un groupe d'utilisateurs Cognito (ou utilisez votre fournisseur d'identité existant)

  2. Enregistrez un client d'application et notez l'ID client

  3. Création d'un utilisateur de test avec un nom d'utilisateur et un mot de passe

Pour obtenir des instructions détaillées, voir Configurer l'autorisateur JWT entrant.