Le traduzioni sono generate tramite traduzione automatica. In caso di conflitto tra il contenuto di una traduzione e la versione originale in Inglese, quest'ultima prevarrà.
Prerequisiti
La migrazione è ora aperta
AWS Agent Registry è stato lanciato con il nuovo agent-registry namespace. Il supporto per il bedrock-agentcore namespace di anteprima pubblico verrà interrotto il 17 settembre 2026. Per le istruzioni sulla migrazione, consulta la Guida completa alla migrazione del registro.
Prima di utilizzare AWS Agent Registry, completare i seguenti prerequisiti.
AWS account e credenziali
È necessario un AWS account con credenziali configurate. Per configurare le credenziali, installa e utilizza l'interfaccia a riga di AWS comando seguendo i passaggi in Guida introduttiva alla CLI AWS .
# Verify installation
aws --version # Should show version 2.
Python e AWS SDK
Per accedere alle tue AWS credenziali e configurarle per l'utilizzo con gli SDK, segui i passaggi indicati in Utilizzo di IAM Identity Center per autenticare AWS SDK e strumenti. Se prevedi di utilizzare AWS Python SDK (Boto3) per interagire con Agent Registry a livello di programmazione: AWS
-
Installa Python 3.10+.
-
Installa l'SDK: AWS pip install boto3
-
Verifica che le tue credenziali siano configurate: aws sts get-caller-identity
Fai riferimento a AWS Builder Tools per ulteriori informazioni su come configurare e utilizzare l' AWS SDK.
autorizzazioni IAM
Configura le autorizzazioni IAM in base alla persona che corrisponde al tuo ruolo. L'elenco completo delle autorizzazioni IAM per il registro è disponibile in Autorizzazioni IAM.
Autorizzazioni dell’amministratore
Per gli amministratori che gestiscono l'intero ciclo di vita di registri, record e record /deprecate: approve/reject
Esempio
- AWS Agent Registry namespace
-
{
"Version": "2012-10-17",
"Statement":
[
{
"Sid": "AllowCreatingAndListingRegistries",
"Effect": "Allow",
"Action":
[
"agent-registry:CreateRegistry",
"agent-registry:ListRegistries"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:*"
]
},
{
"Sid": "AllowGetUpdateDeleteRegistry",
"Effect": "Allow",
"Action":
[
"agent-registry:GetRegistry",
"agent-registry:UpdateRegistry",
"agent-registry:DeleteRegistry"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*"
]
},
{
"Sid": "AllowCreatingAndListingRecords",
"Effect": "Allow",
"Action":
[
"agent-registry:CreateRegistryRecord",
"agent-registry:ListRegistryRecords"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*"
]
},
{
"Sid": "AllowRecordLevelOperations",
"Effect": "Allow",
"Action":
[
"agent-registry:GetRegistryRecord",
"agent-registry:UpdateRegistryRecord",
"agent-registry:DeleteRegistryRecord",
"agent-registry:SubmitRegistryRecordForApproval"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*/record/*"
]
},
{
"Sid": "AllowApproveRejectDeprecateRecords",
"Effect": "Allow",
"Action":
[
"agent-registry:UpdateRegistryRecordStatus"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*/record/*"
]
},
{
"Sid": "AdditionalPermissionForRegistryManagedWorkloadIdentity",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:*WorkloadIdentity"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:workload-identity-directory/default/*"
]
},
{
"Sid": "AllowPermissionForCreatingServiceLinkedRole",
"Effect": "Allow",
"Action":
[
"iam:CreateServiceLinkedRole"
],
"Resource":
[
"arn:aws:iam::*:role/aws-service-role/agent-registry.amazonaws.com/AWSServiceRoleForAgentRegistry"
],
"Condition":
{
"StringLike": { "iam:AWSServiceName": "agent-registry.amazonaws.com" }
}
}
]
}
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
{
"Version": "2012-10-17",
"Statement":
[
{
"Sid": "AllowCreatingAndListingRegistries",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:CreateRegistry",
"bedrock-agentcore:ListRegistries"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:*"
]
},
{
"Sid": "AllowGetUpdateDeleteRegistry",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetRegistry",
"bedrock-agentcore:UpdateRegistry",
"bedrock-agentcore:DeleteRegistry"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*"
]
},
{
"Sid": "AllowCreatingAndListingRecords",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:CreateRegistryRecord",
"bedrock-agentcore:ListRegistryRecords"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*"
]
},
{
"Sid": "AllowRecordLevelOperations",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetRegistryRecord",
"bedrock-agentcore:UpdateRegistryRecord",
"bedrock-agentcore:DeleteRegistryRecord",
"bedrock-agentcore:SubmitRegistryRecordForApproval"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*/record/*"
]
},
{
"Sid": "AllowApproveRejectDeprecateRecords",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:UpdateRegistryRecordStatus"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*/record/*"
]
},
{
"Sid": "AdditionalPermissionForRegistryManagedWorkloadIdentity",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:*WorkloadIdentity"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:workload-identity-directory/default/*"
]
},
{
"Sid": "AllowPermissionForCreatingServiceLinkedRole",
"Effect": "Allow",
"Action":
[
"iam:CreateServiceLinkedRole"
],
"Resource":
[
"arn:aws:iam::*:role/aws-service-role/agent-registry.amazonaws.com/AWSServiceRoleForAgentRegistry"
],
"Condition":
{
"StringLike": { "iam:AWSServiceName": "agent-registry.amazonaws.com" }
}
}
]
}
Autorizzazioni di curatore/approvatore
Per i curatori che effettuano revisioni e approve/reject registrazioni ma non eseguono operazioni amministrative:
Esempio
- AWS Agent Registry namespace
-
{
"Version": "2012-10-17",
"Statement":
[
{
"Effect": "Allow",
"Action":
[
"agent-registry:ListRegistries"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:*"
]
},
{
"Effect": "Allow",
"Action":
[
"agent-registry:GetRegistry"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*"
]
},
{
"Effect": "Allow",
"Action":
[
"agent-registry:ListRegistryRecords"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*"
]
},
{
"Effect": "Allow",
"Action":
[
"agent-registry:GetRegistryRecord"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*/record/*"
]
},
{
"Effect": "Allow",
"Action":
[
"agent-registry:UpdateRegistryRecordStatus"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*/record/*"
]
}
]
}
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
{
"Version": "2012-10-17",
"Statement":
[
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:ListRegistries"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:*"
]
},
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetRegistry"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*"
]
},
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:ListRegistryRecords"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*"
]
},
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetRegistryRecord"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*/record/*"
]
},
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:UpdateRegistryRecordStatus"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*/record/*"
]
}
]
}
Autorizzazioni dell'editore
Per gli editori che inviano server MCP, agenti o altre risorse al registro:
Le tre istruzioni relative alla sincronizzazione (AllowWorkloadIdentityForSynchronization,AllowGetResourceOauth2TokenForOauthBasedSynchronization,AllowPassRoleForIamBasedSynchronization) autorizzano l'identità del carico di lavoro e le risorse del provider di credenziali OAuth gestite da Identity. AgentCore Queste risorse rimangono intenzionalmente all'interno del bedrock-agentcore namespace, quindi le relative azioni, gli ARN e l'entità del servizio non cambiano.
Indirizza la AllowGetResourceOauth2TokenForOauthBasedSynchronization dichiarazione allo specifico provider di credenziali OAuth ARN di cui è necessario il token di accesso per questa identità. Evita i caratteri jolly nel segmento dei provider dell'ARN, ad esempio token-vault/default/oauth2credentialprovider/ concedendo l'accesso a tutti i provider di credenziali OAuth dell'account, in modo da consentire l'accesso alle credenziali tra team. token-vault/
Segui il principio del privilegio minimo nominando, ad esempio, il provider specifico nel campo. Resource arn:aws:bedrock-agentcore:<region>:<account>:token-vault/default/oauth2credentialprovider/<oauthProviderName>
Esempio
- AWS Agent Registry namespace
-
{
"Version": "2012-10-17",
"Statement":
[
{
"Effect": "Allow",
"Action":
[
"agent-registry:ListRegistries"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:*"
]
},
{
"Effect": "Allow",
"Action":
[
"agent-registry:GetRegistry"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*"
]
},
{
"Effect": "Allow",
"Action":
[
"agent-registry:CreateRegistryRecord",
"agent-registry:ListRegistryRecords"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*"
]
},
{
"Effect": "Allow",
"Action":
[
"agent-registry:GetRegistryRecord",
"agent-registry:UpdateRegistryRecord",
"agent-registry:DeleteRegistryRecord",
"agent-registry:SubmitRegistryRecordForApproval"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*/record/*"
]
},
{
"Sid": "AllowWorkloadIdentityForSynchronization",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetWorkloadAccessToken"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:workload-identity-directory/*"
]
},
{
"Sid": "AllowGetResourceOauth2TokenForOauthBasedSynchronization",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetResourceOauth2Token"
],
"Resource":
[
"arn:aws:bedrock-agentcore:<region>:<account>:token-vault/default/oauth2credentialprovider/<oauthProviderName>"
]
},
{
"Sid": "AllowPassRoleForIamBasedSynchronization",
"Effect": "Allow",
"Action":
[
"iam:PassRole"
],
"Resource":
[
"arn:aws:iam::<account>:role/<your-sync-role-name>"
],
"Condition":
{
"StringEquals":
{
"iam:PassedToService": "bedrock-agentcore.amazonaws.com"
},
"StringLike":
{
"iam:AssociatedResourceARN": "arn:aws:bedrock-agentcore:<region>:<account>:registry/*/record/*"
}
}
}
]
}
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
{
"Version": "2012-10-17",
"Statement":
[
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:ListRegistries"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:*"
]
},
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetRegistry"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*"
]
},
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:CreateRegistryRecord",
"bedrock-agentcore:ListRegistryRecords"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*"
]
},
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetRegistryRecord",
"bedrock-agentcore:UpdateRegistryRecord",
"bedrock-agentcore:DeleteRegistryRecord",
"bedrock-agentcore:SubmitRegistryRecordForApproval"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*/record/*"
]
},
{
"Sid": "AllowWorkloadIdentityForSynchronization",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetWorkloadAccessToken"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:workload-identity-directory/*"
]
},
{
"Sid": "AllowGetResourceOauth2TokenForOauthBasedSynchronization",
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetResourceOauth2Token"
],
"Resource":
[
"arn:aws:bedrock-agentcore:<region>:<account>:token-vault/default/oauth2credentialprovider/<oauthProviderName>"
]
},
{
"Sid": "AllowPassRoleForIamBasedSynchronization",
"Effect": "Allow",
"Action":
[
"iam:PassRole"
],
"Resource":
[
"arn:aws:iam::<account>:role/<your-sync-role-name>"
],
"Condition":
{
"StringEquals":
{
"iam:PassedToService": "bedrock-agentcore.amazonaws.com"
},
"StringLike":
{
"iam:AssociatedResourceARN": "arn:aws:bedrock-agentcore:<region>:<account>:registry/*/record/*"
}
}
}
]
}
Autorizzazioni per i consumatori
Per i consumatori che cercano e utilizzano risorse approvate:
Esempio
- AWS Agent Registry namespace
-
{
"Version": "2012-10-17",
"Statement":
[
{
"Effect": "Allow",
"Action":
[
"agent-registry:ListRegistries"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:*"
]
},
{
"Effect": "Allow",
"Action":
[
"agent-registry:GetRegistry"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*"
]
},
{
"Effect": "Allow",
"Action":
[
"agent-registry:SearchDiscoverableRegistryRecords",
"agent-registry:ListDiscoverableRegistryRecords",
"agent-registry:GetDiscoverableRegistryRecord",
"agent-registry:InvokeRegistryMcp"
],
"Resource":
[
"arn:aws:agent-registry:*:<account>:registry/*"
]
}
]
}
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
{
"Version": "2012-10-17",
"Statement":
[
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:ListRegistries"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:*"
]
},
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:GetRegistry"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*"
]
},
{
"Effect": "Allow",
"Action":
[
"bedrock-agentcore:SearchRegistryRecords",
"bedrock-agentcore:InvokeRegistryMcp"
],
"Resource":
[
"arn:aws:bedrock-agentcore:*:<account>:registry/*"
]
}
]
}
Ad esempio, le politiche IAM, vedi Gestione delle identità e degli accessi per Amazon Bedrock AgentCore.
(Facoltativo) Provider di identità per l'autorizzazione JWT
Se prevedi di utilizzare l'autorizzazione JWT per l'identità in entrata (per consentire ai consumatori di effettuare ricerche nel registro utilizzando Non-IAM le identità), configura Amazon Cognito o il tuo provider di identità prima di creare il registro:
-
Crea un pool di utenti Cognito (o usa il tuo provider di identità esistente)
-
Registra un App Client e annota l'ID del cliente
-
Crea un utente di prova con nome utente e password
Per istruzioni dettagliate, consulta Configurare l'autorizzatore JWT in entrata.