View a markdown version of this page

AgentCore Code Interpreter のファイルシステム設定 - Amazon Bedrock AgentCore

翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。

AgentCore Code Interpreter のファイルシステム設定

AgentCore Code Interpreter は、 filesystemConfigurationsパラメータを使用して独自のファイルシステムをコードインタープリタセッションにマウントすることをサポートしています。各設定は、指定したパスに Amazon S3 ファイルまたは Amazon EFS アクセスポイントをマウントします。カスタムマウントコード、特権コンテナ、またはダウンロードオーケストレーションは必要ありません — AgentCore はセッションサンドボックス内ですべてのマウントオペレーションを実行します。

Bring-your-own ファイルシステムは共有ストレージです。複数のセッション、複数のコードインタプリタ、または外部アプリケーションが同じアクセスポイントに同時にアクセスできます。データは自分の AWS アカウントで保持および管理されます。

CreateCodeInterpreter でコードインタープリタを作成するfilesystemConfigurations場合 (そのコードインタープリタから開始されるすべてのセッションがマウントを継承する場合)、または StartCodeInterpreterSession でセッションを開始する場合 (マウントはそのセッションに適用されます) に を指定できます。パラメータとシェイプはどちらの場所でも同じです。

注記

AgentCore ランタイムとは異なり、AgentCore コードインタープリタはマネージドセッションストレージオプションを提供しません。Code Interpreter はbring-your-ownAmazon S3 ファイルと Amazon EFS アクセスポイントのみをサポートします。

ストレージオプションの概要

次の表は、使用可能なファイルシステムタイプを比較したものです。

タイプ 分離 永続的 VPC が必要 適しているチーム

Amazon S3 Files

共有 – 複数のセッションとコードインタープリタが同じデータにアクセスする

カスタマー管理 (永続的、バッキング S3 バケットと同期)

はい

標準ファイルオペレーションと S3 APIs の両方からアクセスできるデータセットとアーティファクト

Amazon EFS

共有 – 複数のセッションとコードインタープリタが同じデータにアクセスする

カスタマー管理 (削除するまで永続的)

はい

セッション間でのリファレンスデータ、ダウンロード、読み取り/書き込みコラボレーションの共有

クイックスタート

次のチェックリストは、各ファイルシステムタイプを設定するための詳細な手順を示しています。

Amazon S3 Files アクセスポイント

  1. 、s3files:ClientWrite、 s3files:GetAccessPointを s3files:ClientMounts3files:AccessPointArn条件でコードインタプリタ実行ロールに追加します。

  2. コードインタープリタセキュリティグループから S3 Files マウントターゲットセキュリティグループへの TCP ポート 2049 アウトバウンドを許可します。

  3. S3 Files マウントターゲットがコードインタープリタサブネットと同じ VPC とアベイラビリティーゾーンにあることを確認します。

  4. CreateCodeInterpreter または StartCodeInterpreterSession呼び出しに s3FilesConfiguration エントリfilesystemConfigurationsで を追加します。

  5. セッションを開始します。マウントパスのファイル ( など/mnt/s3data) は、バッキング S3 バケットと双方向に同期します。

Amazon EFS アクセスポイント

  1. elasticfilesystem:AccessPointArn 条件でコードインタプリタ実行ロールelasticfilesystem:ClientWriteに elasticfilesystem:ClientMountと を追加します。

  2. コードインタープリタセキュリティグループから EFS マウントターゲットセキュリティグループへの TCP ポート 2049 アウトバウンドを許可します。

  3. EFS マウントターゲットが、コードインタープリタサブネットの少なくとも 1 つと同じアベイラビリティーゾーンにあることを確認します。

  4. CreateCodeInterpreter または StartCodeInterpreterSession呼び出しに efsConfiguration エントリfilesystemConfigurationsで を追加します。

  5. セッションを開始します。ファイルはマウントパス ( など/mnt/efs) で使用できます。

S3 ファイルと EFS の両方に、コードインタプリタでの VPC 接続が必要です。

仕組み

Bringbring-your-own ファイルシステムを設定すると、AgentCore Code Interpreter は、設定したパスのセッションサンドボックスに指定されたアクセスポイントをマウントします。データは共有されます。複数のセッション、複数のコードインタプリタ、または外部アプリケーションが同じファイルシステムに同時にアクセスできます。

AgentCore は、すべてのマウントオペレーションを自動的に処理します。マウントヘルパーをインストールしたり、TLS 証明書を管理したり、マウントコードを記述したりする必要はありません。

注記

アクセスポイント (S3 ファイルまたは EFS) を作成するときは、POSIX ユーザー ID (UID) とグループ ID (GID) を指定します。アクセスポイントを介したすべてのファイルオペレーションは、この ID として実行されます。

Amazon S3 Files マウントフロー

  1. S3 ファイルファイルシステム (S3 バケットにバックアップ) を作成し、VPC にターゲットをマウントします。

  2. POSIX UID/GID とルートディレクトリを指定する S3 Files アクセスポイントを作成します。

  3. アクセスポイント ARN、ファイルシステム ARN、マウントパスを使用してコードインタープリタ (またはセッション) を設定します。

  4. セッションの開始時に、AgentCore は VPC へのネットワークアクセスを持つサンドボックスをプロビジョニングします。

  5. サンドボックスは、VPC 経由で IAM 認証 (ポート 2049) を使用して TLS 経由で NFSv4.2 を介してファイルシステムをマウントします。

  6. エージェントは、マウントパスでファイルの読み取りと書き込みを行います。変更はバッキング S3 バケットに自動的に同期されます。

Amazon EFS マウントフロー

  1. EFS ファイルシステムを作成し、VPC にターゲットをマウントします (アベイラビリティーゾーンごとに 1 つ)。

  2. POSIX UID/GID とルートディレクトリを指定する EFS アクセスポイントを作成します。

  3. アクセスポイント ARN、ファイルシステム ARN、マウントパスを使用してコードインタープリタ (またはセッション) を設定します。

  4. セッションの開始時に、AgentCore は VPC へのネットワークアクセスを持つサンドボックスをプロビジョニングします。

  5. サンドボックスは、同じアベイラビリティーゾーンのマウントターゲットを介して TLS (ポート 2049) 経由で NFSv4.1 を介してファイルシステムをマウントします。

  6. エージェントは、標準のファイルオペレーションを使用して、マウントパスでファイルの読み取りと書き込みを行います。

前提条件

bring-your-own ファイルシステムを設定する前に、次の前提条件を完了してください。

VPC 設定

コードインタープリタはVPCネットワークモードを使用する必要があります。指定するサブネットは、ファイルシステムのマウントターゲットアベイラビリティーゾーンと重複する必要があります。

IAM アクセス許可

コードインタプリタ実行ロールには、ファイルシステムをマウントするためのアクセス許可が含まれている必要があります。

S3 ファイルの IAM アクセス許可

{ "Effect": "Allow", "Action": [ "s3files:ClientMount", "s3files:ClientWrite", "s3files:GetAccessPoint" ], "Resource": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>", "Condition": { "ArnEquals": { "s3files:AccessPointArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>/access-point/<access-point-id>" } } }

EFS の IAM アクセス許可

{ "Effect": "Allow", "Action": [ "elasticfilesystem:ClientMount", "elasticfilesystem:ClientWrite" ], "Resource": "arn:aws:elasticfilesystem:<region>:<account-id>:file-system/<file-system-id>", "Condition": { "ArnEquals": { "elasticfilesystem:AccessPointArn": "arn:aws:elasticfilesystem:<region>:<account-id>:access-point/<access-point-id>" } } }

エージェントが読み取りアクセスのみを必要とするClientWrite場合は、 を省略します。

セキュリティグループ

ポート 2049 でコードインタープリタセキュリティグループからマウントターゲットセキュリティグループへのアウトバウンド TCP を許可します。コードインタープリタセキュリティグループからマウントターゲットセキュリティグループのポート 2049 でインバウンド TCP を許可します。

ファイルシステムを設定する

の各ファイルシステムを s3FilesConfigurationまたは filesystemConfigurationsとして指定しますefsConfiguration。どちらも 3 つのフィールドが必要です。

  • accessPointArn – マウントする S3 ファイルまたは EFS アクセスポイントの ARN。

  • fileSystemArn – アクセスポイントを所有するファイルシステムの ARN。このフィールドは必須です。

  • mountPath – アクセスポイントがマウントされているセッション内の絶対パス (例: /mnt/s3data)。

同じシェイプを使用して、2 filesystemConfigurationsつの場所で を指定できます。

  • コントロールプレーン – CreateCodeInterpreter – マウントは、コードインタプリタから開始されたすべてのセッションによって継承されます。コードインタープリタは VPC ネットワークモードを使用する必要があります。

  • データプレーン – StartCodeInterpreterSession – マウントはその特定のセッションに適用されます。

注記

コードインタープリタが VPC ネットワークモードを使用し、S3 ファイルまたは EFS アクセスポイントが正しく設定されている (マウントターゲット、IAM アクセス許可、およびセキュリティグループ) 限り、コントロールプレーン (StartCodeInterpreterSession)、CreateCodeInterpreterデータプレーン ()、またはその両方でファイルシステム設定を指定できます。からの設定CreateCodeInterpreterはすべてのセッションに継承されます。 からの設定はそのセッションStartCodeInterpreterSessionに適用されます。両方を指定すると、セッションに対して結合され、各マウントパスは結合されたセット全体で一意である必要があります。

以下のセクションでは、各ファイルシステムタイプの両方の API コールを示します。

Amazon S3 Files アクセスポイントを設定する

コントロールプレーン: CreateCodeInterpreter

例
AWS CLI
  1. aws bedrock-agentcore-control create-code-interpreter \ --name "data-code-interpreter" \ --execution-role-arn "arn:aws:iam::<account-id>:role/CodeInterpreterExecutionRole" \ --network-configuration '{ "networkMode": "VPC", "vpcConfig": { "subnets": ["<subnet-id-1>", "<subnet-id-2>"], "securityGroups": ["<security-group-id>"] } }' \ --filesystem-configurations '[{ "s3FilesConfiguration": { "accessPointArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>/access-point/<access-point-id>", "fileSystemArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>", "mountPath": "/mnt/s3data" } }]'
AWS SDK
  1. boto3 を使用して S3 Files アクセスポイントを持つコードインタプリタを作成する Python の例。

    import boto3 cp = boto3.client("bedrock-agentcore-control", region_name="us-west-2") response = cp.create_code_interpreter( name="data-code-interpreter", executionRoleArn="arn:aws:iam::<account-id>:role/CodeInterpreterExecutionRole", networkConfiguration={ "networkMode": "VPC", "vpcConfig": { "subnets": ["<subnet-id-1>", "<subnet-id-2>"], "securityGroups": ["<security-group-id>"] } }, filesystemConfigurations=[ { "s3FilesConfiguration": { "accessPointArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>/access-point/<access-point-id>", "fileSystemArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>", "mountPath": "/mnt/s3data" } } ] )

データプレーン: StartCodeInterpreterSession

例
AWS CLI
  1. aws bedrock-agentcore start-code-interpreter-session \ --code-interpreter-identifier "<code-interpreter-id>" \ --name "byos-session" \ --session-timeout-seconds 3600 \ --filesystem-configurations '[{ "s3FilesConfiguration": { "accessPointArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>/access-point/<access-point-id>", "fileSystemArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>", "mountPath": "/mnt/s3data" } }]'
AWS SDK
  1. boto3 を使用して S3 Files アクセスポイントでコードインタープリタセッションを開始する Python の例。

    import boto3 dp = boto3.client("bedrock-agentcore", region_name="us-west-2") response = dp.start_code_interpreter_session( codeInterpreterIdentifier="<code-interpreter-id>", name="byos-session", sessionTimeoutSeconds=3600, filesystemConfigurations=[ { "s3FilesConfiguration": { "accessPointArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>/access-point/<access-point-id>", "fileSystemArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>", "mountPath": "/mnt/s3data" } } ] ) session_id = response["sessionId"]

Amazon EFS アクセスポイントを設定する

コントロールプレーン: CreateCodeInterpreter

例
AWS CLI
  1. aws bedrock-agentcore-control create-code-interpreter \ --name "shared-tools-code-interpreter" \ --execution-role-arn "arn:aws:iam::<account-id>:role/CodeInterpreterExecutionRole" \ --network-configuration '{ "networkMode": "VPC", "vpcConfig": { "subnets": ["<subnet-id-1>", "<subnet-id-2>"], "securityGroups": ["<security-group-id>"] } }' \ --filesystem-configurations '[{ "efsConfiguration": { "accessPointArn": "arn:aws:elasticfilesystem:<region>:<account-id>:access-point/<access-point-id>", "fileSystemArn": "arn:aws:elasticfilesystem:<region>:<account-id>:file-system/<file-system-id>", "mountPath": "/mnt/efs" } }]'
AWS SDK
  1. boto3 を使用して EFS アクセスポイントを持つコードインタプリタを作成する Python の例。

    import boto3 cp = boto3.client("bedrock-agentcore-control", region_name="us-west-2") response = cp.create_code_interpreter( name="shared-tools-code-interpreter", executionRoleArn="arn:aws:iam::<account-id>:role/CodeInterpreterExecutionRole", networkConfiguration={ "networkMode": "VPC", "vpcConfig": { "subnets": ["<subnet-id-1>", "<subnet-id-2>"], "securityGroups": ["<security-group-id>"] } }, filesystemConfigurations=[ { "efsConfiguration": { "accessPointArn": "arn:aws:elasticfilesystem:<region>:<account-id>:access-point/<access-point-id>", "fileSystemArn": "arn:aws:elasticfilesystem:<region>:<account-id>:file-system/<file-system-id>", "mountPath": "/mnt/efs" } } ] )

データプレーン: StartCodeInterpreterSession

例
AWS CLI
  1. aws bedrock-agentcore start-code-interpreter-session \ --code-interpreter-identifier "<code-interpreter-id>" \ --name "byos-session" \ --session-timeout-seconds 3600 \ --filesystem-configurations '[{ "efsConfiguration": { "accessPointArn": "arn:aws:elasticfilesystem:<region>:<account-id>:access-point/<access-point-id>", "fileSystemArn": "arn:aws:elasticfilesystem:<region>:<account-id>:file-system/<file-system-id>", "mountPath": "/mnt/efs" } }]'
AWS SDK
  1. boto3 を使用して EFS アクセスポイントでコードインタープリタセッションを開始する Python の例。

    import boto3 dp = boto3.client("bedrock-agentcore", region_name="us-west-2") response = dp.start_code_interpreter_session( codeInterpreterIdentifier="<code-interpreter-id>", name="byos-session", sessionTimeoutSeconds=3600, filesystemConfigurations=[ { "efsConfiguration": { "accessPointArn": "arn:aws:elasticfilesystem:<region>:<account-id>:access-point/<access-point-id>", "fileSystemArn": "arn:aws:elasticfilesystem:<region>:<account-id>:file-system/<file-system-id>", "mountPath": "/mnt/efs" } } ] ) session_id = response["sessionId"]

ファイルシステムを組み合わせる

にエントリを追加することで、1 回の呼び出しで複数のアクセスポイント (以下の制限まで) をアタッチできますfilesystemConfigurations。各エントリは、一意のマウントパスを使用する必要があります。

filesystemConfigurations=[ { "s3FilesConfiguration": { "accessPointArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>/access-point/<access-point-id>", "fileSystemArn": "arn:aws:s3files:<region>:<account-id>:file-system/<file-system-id>", "mountPath": "/mnt/s3data" } }, { "efsConfiguration": { "accessPointArn": "arn:aws:elasticfilesystem:<region>:<account-id>:access-point/<access-point-id>", "fileSystemArn": "arn:aws:elasticfilesystem:<region>:<account-id>:file-system/<file-system-id>", "mountPath": "/mnt/efs" } } ]

マウントされたファイルシステムを確認する

GetCodeInterpreter を使用してコードインタプリタfilesystemConfigurationsの を確認し、GetCodeInterpreterSession を使用して実行中のセッションで有効な設定を確認します。コードインタープリタの作成時とセッション開始時に設定された設定は、どちらもセッションレスポンスに表示されます。

制限

ファイルシステム設定の制限はリクエストごとに適用されます。 CreateCodeInterpreter設定はすべてのセッションに継承され、StartCodeInterpreterSession設定はそのセッションに適用されます。セッションの有効なマウントは、両方の組み合わせです。

設定タイプ CreateCodeInterpreter ごと StartCodeInterpreterSession ごと セッションあたりの合計

Amazon S3 Files アクセスポイント

2

2

4

Amazon EFS アクセスポイント

2

2

4

ファイルシステム設定の合計

4

4

8

たとえば、1 つの S3 Files アクセスポイントと 1 つの EFS アクセスポイントを に設定しCreateCodeInterpreter、1 つの S3 Files アクセスポイントと 1 つの EFS アクセスポイントを に追加してStartCodeInterpreterSession、セッションの合計 4 つのマウントを設定できます。各マウントパスは、結合されたセット全体で一意である必要があります。

マウントパスの制約

すべてのファイルシステム設定は、次のマウントパスルールに従う必要があります。

  • 1 つのサブディレクトリレベル (例: 、) /mnt/data/mnt/で 未満である必要があります/mnt/s3data。

  • パターン: /mnt/[a-zA-Z0-9._-]+/?

  • 各マウントパスは、すべての設定で一意である必要があります。

  • マウントパスは相互にサブディレクトリにすることはできません。

ファイルシステムのマウントのトラブルシューティング

Bringbring-your-own ファイルシステムのマウントが失敗した場合、 はエラーStartCodeInterpreterSessionを返し、セッションは になりませんREADY。

症状 考えられる原因 クイック修正

「アクセス拒否」

実行ロールが見つからないClientMount、または ClientWrite

AccessPointArn 条件で IAM アクセス許可を追加する

ResourceNotFound」または「Failed to resolve」

アクセスポイントまたはマウントターゲットの削除または使用不可

ARN が存在し、マウントターゲットが使用可能であることを確認する

マウントがハングしてから失敗する

セキュリティグループがポート 2049 をブロックしているか、セッションのアベイラビリティーゾーンにマウントターゲットがない

TCP 2049 を許可し、アベイラビリティーゾーンの重複を検証する

書き込みの「アクセス許可が拒否されました」

欠落ClientWriteまたは POSIX UID/GID の不一致

書き込みアクセス許可を追加するか、アクセスポイント POSIX ユーザーを調整する

設定されたすべてのファイルシステムは、セッションの開始時に並列にマウントされます。1 回のマウントに失敗すると、セッションの開始が失敗します。