View a markdown version of this page

AgentCore 支付的 IAM 角色 - 亚马逊基岩 AgentCore

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

AgentCore 支付的 IAM 角色

角色摘要

AgentCore 支付使用五种角色的 IAM 模型,将管理、管理、代理执行、服务运营和 AWS 市场订阅分开(仅限 Coinbase)。根据与您的角色匹配的角色设置 IAM 权限。

角色 用途

管理员 (ControlPlaneRole)

管理支付管理器、连接器和凭证提供商。对于Coinbase来说,这个角色还需要 AWS 托管政策AWSMarketplaceManageSubscriptions才能在市场中 AWS 订阅

代理开发者 (ManagementRole)

管理支付工具和会话,无法执行付款

付款执行 (ProcessPaymentRole)

代表代理执行付款交易

服务角色 (ResourceRetrievalRole)

假设在运行时 AgentCore 付款可以检索凭证

商城订阅(AWSMarketplaceManageSubscriptions在管理员上)

对于Coinbase,将该账户订阅市场中的 Coinbase AgentCore 付款钱包列表。 AWS 这是附加到管理员身份的 AWS 托管策略,而不是单独的假定角色。

提示

您可以使用 AWS 代理工具包中的 AgentCore 付款技能自动执行此页面上的步骤。该技能是 aws-agents 插件的一部分,它允许 AI 编码代理使用 agentcore CLI 创建您的支付管理器、连接器、凭证提供商、支付工具和会话,并为您的代理添加流程付款工具。有关详细信息,请参阅上的 GitHub快速入门和AWS 代理工具包。

为什么角色分离很重要

将支付管理与支付执行分开,可以防止单一被泄露的身份既无法创建预算无限的会话,又可以针对这些会话执行付款。管理角色的明确规定Deny了这一界限。ProcessPayment这也确保了审计记录可以清楚地区分谁配置了支付资源和谁执行了交易。

管理员权限 (ControlPlaneRole)

对于管理支付管理器、连接器和凭证提供商的管理员:

注意

要使用Coinbase作为支付提供商,管理员还必须将该账户订阅市场上列出的 Coinbase AgentCore 付款钱包。 AWS 这需要 AWS 托管策略AWSMarketplaceManageSubscriptions。通过此订阅,您的Coinbase钱包使用费将根据Coinbase在Coinbase网站上的定价合并到您的月度 AWS 账单中。订阅没有额外费用或义务。有关更多信息,请参阅订阅Coinbase钱包以在 AWS 市场上 AgentCore 付款。

{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowPaymentManagerOperations", "Effect": "Allow", "Action": [ "bedrock-agentcore:CreatePaymentManager", "bedrock-agentcore:GetPaymentManager", "bedrock-agentcore:ListPaymentManagers", "bedrock-agentcore:DeletePaymentManager", "bedrock-agentcore:UpdatePaymentManager" ], "Resource": [ "arn:aws:bedrock-agentcore:*:111122223333:payment-manager/*" ] }, { "Sid": "AllowPaymentConnectorOperations", "Effect": "Allow", "Action": [ "bedrock-agentcore:CreatePaymentConnector", "bedrock-agentcore:GetPaymentConnector", "bedrock-agentcore:ListPaymentConnectors", "bedrock-agentcore:DeletePaymentConnector", "bedrock-agentcore:UpdatePaymentConnector" ], "Resource": [ "arn:aws:bedrock-agentcore:*:111122223333:payment-manager/*/connector/*" ] }, { "Sid": "AllowCredentialProviderOperations", "Effect": "Allow", "Action": [ "bedrock-agentcore:CreatePaymentCredentialProvider", "bedrock-agentcore:GetPaymentCredentialProvider", "bedrock-agentcore:ListPaymentCredentialProviders", "bedrock-agentcore:DeletePaymentCredentialProvider", "bedrock-agentcore:UpdatePaymentCredentialProvider" ], "Resource": [ "arn:aws:bedrock-agentcore:*:111122223333:token-vault/*/paymentcredentialprovider/*" ] }, { "Sid": "AllowVendedLogDelivery", "Effect": "Allow", "Action": [ "bedrock-agentcore:AllowVendedLogDeliveryForResource" ], "Resource": [ "arn:aws:bedrock-agentcore:*:111122223333:payment-manager/*" ] }, { "Sid": "AllowPassResourceRetrievalRole", "Effect": "Allow", "Action": "iam:PassRole", "Resource": "arn:aws:iam::111122223333:role/AgentCorePaymentsResourceRetrievalRole", "Condition": { "StringEquals": { "iam:PassedToService": "bedrock-agentcore.amazonaws.com" } } } ] }

要订阅 AWS 市场中的 Coinbase AgentCore 支付钱包列表,管理员身份还需要 AWS 托管策略AWSMarketplaceManageSubscriptions。将其附加到管理员的 IAM 角色(或用户)。例如,使用 AWS CLI:

aws iam attach-role-policy \ --role-name <administrator-role-name> \ --policy-arn <AWSMarketplaceManageSubscriptions-policy-arn>

代理开发者权限 (ManagementRole)

对于管理支付工具和会话但不直接执行付款的在 deterministic/human环(HITL)代码:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowPaymentManagement", "Effect": "Allow", "Action": [ "bedrock-agentcore:CreatePaymentInstrument", "bedrock-agentcore:GetPaymentInstrument", "bedrock-agentcore:ListPaymentInstruments", "bedrock-agentcore:DeletePaymentInstrument", "bedrock-agentcore:CreatePaymentSession", "bedrock-agentcore:GetPaymentSession", "bedrock-agentcore:ListPaymentSessions", "bedrock-agentcore:DeletePaymentSession" ], "Resource": [ "arn:aws:bedrock-agentcore:*:111122223333:payment-manager/*" ] }, { "Sid": "DenyProcessPayment", "Effect": "Deny", "Action": "bedrock-agentcore:ProcessPayment", "Resource": "*" } ] }
注意

该政策明确ProcessPayment拒绝在管理运营和付款执行之间实行职责分离。这确保了只有确定性代码路径才能设置控制平面操作,而代理执行只能在不覆盖预算或创建支付工具来解决这个问题的情况下处理付款。

付款执行权限 (ProcessPaymentRole)

对于代表代理执行付款交易的确定性代码路径:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowProcessPayment", "Effect": "Allow", "Action": "bedrock-agentcore:ProcessPayment", "Resource": [ "arn:aws:bedrock-agentcore:*:111122223333:payment-manager/*" ] }, { "Sid": "AllowPaymentReadOperations", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetPaymentInstrument", "bedrock-agentcore:GetPaymentInstrumentBalance", "bedrock-agentcore:GetPaymentSession" ], "Resource": [ "arn:aws:bedrock-agentcore:*:111122223333:payment-manager/*" ] } ] }
重要

不要包括 PaymentSession 写入权限(例如,CreatePaymentSession)和担任相同角色,否则呼叫者可以通过ProcessPayment在预算增加的情况下创建新会话来绕过付款限制。

服务角色权限 (ResourceRetrievalRole)

以下服务角色由运行时 AgentCore 付款代替,以检索凭证和管理工作负载身份。它未分配给人类用户。

信任策略

服务角色必须信任bedrock-agentcore.amazonaws.com服务主体。以下信任政策限制了对特定账户和付款管理器的访问权限:

{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "bedrock-agentcore.amazonaws.com" }, "Action": "sts:AssumeRole", "Condition": { "StringEquals": { "aws:SourceAccount": "<account>" }, "ArnLike": { "aws:SourceArn": "arn:aws:bedrock-agentcore:<region>:<account>:payment-manager/<payment-manager-name>-*" } } } ] }

基本权限(创建付款管理器时附加)

创建付款管理器时,以下权限将附加到该服务角色。它们授予支付经理访问工作负载身份和支付令牌操作的权限:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "WorkloadIdentityManagement", "Effect": "Allow", "Action": [ "bedrock-agentcore:CreateWorkloadIdentity", "bedrock-agentcore:DeleteWorkloadIdentity" ], "Resource": [ "arn:aws:bedrock-agentcore:<region>:<account>:workload-identity-directory/default", "arn:aws:bedrock-agentcore:<region>:<account>:workload-identity-directory/default/workload-identity/*" ] }, { "Sid": "WorkloadIdentityAccess", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetWorkloadAccessToken" ], "Resource": [ "arn:aws:bedrock-agentcore:<region>:<account>:workload-identity-directory/default", "arn:aws:bedrock-agentcore:<region>:<account>:workload-identity-directory/default/workload-identity/<payment-manager-name>-*" ] }, { "Sid": "PaymentTokenBaseAccess", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetResourcePaymentToken" ], "Resource": [ "arn:aws:bedrock-agentcore:<region>:<account>:token-vault/default", "arn:aws:bedrock-agentcore:<region>:<account>:workload-identity-directory/default", "arn:aws:bedrock-agentcore:<region>:<account>:workload-identity-directory/default/workload-identity/<payment-manager-name>-*" ] }, { "Sid": "PaymentCredentialProviderProvisioning", "Effect": "Allow", "Action": [ "bedrock-agentcore:CreatePaymentCredentialProvider", "bedrock-agentcore:GetPaymentCredentialProvider", "bedrock-agentcore:TagResource" ], "Resource": [ "arn:aws:bedrock-agentcore:<region>:<account>:token-vault/<token-vault-id>", "arn:aws:bedrock-agentcore:<region>:<account>:token-vault/<token-vault-id>/paymentcredentialprovider/*" ] } ] }

KMS 权限

如果您在付款管理器上配置客户管理的 AWS KMS 密钥,请向该服务角色添加以下权限:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "KMSPermissions", "Effect": "Allow", "Action": [ "kms:Decrypt", "kms:GenerateDataKey" ], "Resource": [ "arn:aws:kms:<region>:<account>:key/<key-id>" ], "Condition": { "StringEquals": { "aws:ResourceAccount": "<account>" }, "StringLike": { "kms:EncryptionContext:aws:payments-manager:arn": "arn:aws:bedrock-agentcore:<region>:<account>:payment-manager/*" } } } ] }

Per-connector 权限

每次向支付管理器添加支付连接器时,都会向该服务角色附加以下权限。它们授予对特定支付凭证提供商及其支持机密的访问权限:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "PaymentTokenAccess", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetResourcePaymentToken" ], "Resource": [ "<payment-credential-provider-arn>" ] }, { "Sid": "SecretsManagerAccess", "Effect": "Allow", "Action": [ "secretsmanager:GetSecretValue" ], "Resource": [ "<secret-arns>" ], "Condition": { "StringEquals": { "aws:ResourceAccount": "<account>" } } } ] }

使用现有角色

如果您选择使用现有服务角色而不是创建新服务角色,请确保该角色具有:

  1. 上面显示的信任策略,以可信委托人bedrock-agentcore.amazonaws.com为准。

  2. 工作负载身份和支付令牌访问的基本权限。

  3. Per-connector 支付管理器连接器引用的每个支付凭证提供商的权限。

注意

管理员、代理开发者和付款执行角色使用标准账户信任政策,arn:aws:iam::111122223333:root允许他们代入。

例如 IAM 政策,请参阅亚马逊 Bedrock AgentCore 的身份和访问管理。