View a markdown version of this page

为亚马逊 Bedrock 使用服务相关角色 AgentCore - 亚马逊基岩 AgentCore

本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。

为亚马逊 Bedrock 使用服务相关角色 AgentCore

亚马逊 Bedrock AgentCore 使用 AWS 身份和访问管理 (IAM) 服务相关角色。服务相关角色是一种独特的 IAM 角色类型,可直接关联到 AgentCore。 Service-linked 角色由预定义 AgentCore ,包括该服务代表您调用其他 AWS 服务所需的所有权限。

服务相关角色使使用变得 AgentCore 更加容易,因为您无需手动添加必要的权限。 AgentCore 定义其服务相关角色的权限,除非另有定义,否则 AgentCore 只能代入其角色。定义的权限包括信任策略和权限策略,而且权限策略不能附加到任何其他 IAM 实体。

只有在首先删除角色的相关资源后,才能删除角色。这可以保护您的 AgentCore 资源,因为您无法无意中删除访问资源的权限。

AgentCore 使用以下服务相关角色:

  • AWSServiceRoleForBedrockAgentCoreNetwork-管理您的 VPC 中的网络接口

  • AWSServiceRoleForBedrockAgentCoreRuntimeIdentity-管理代理运行时的工作负载身份访问令牌和 OAuth 凭证

  • AWSServiceRoleForBedrockAgentCoreGatewayNetwork-管理用于网关私有连接的 Amazon VPC L AgentCore attice 资源

  • AWSServiceRoleForBedrockAgentCoreIdentity-管理用于与私有身份提供商进行 AgentCore 身份连接的 Amazon VPC Lattice 资源

  • AWSServiceRoleForBedrockAgentCoreRuntimeInstances-清理容量提供商为实例计算类型创建的计算资源

AgentCore 与服务相关的角色权限

网络服务相关角色

AgentCore 使用名为的服务相关角色AWSServiceRoleForBedrockAgentCoreNetwork AgentCore 允许代表您在 VPC 中创建和管理网络接口。

AWSServiceRoleForBedrockAgentCoreNetwork 服务相关角色信任以下服务代入该角色:

  • network.bedrock-agentcore.amazonaws.com

角色权限策略 AgentCore 允许对指定资源完成以下操作:

您可以在以下位置查看完整的政策BedrockAgentCoreNetworkServiceRolePolicy。

{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowCreateEniInAnySubnet", "Effect": "Allow", "Action": "ec2:CreateNetworkInterface", "Resource": "arn:aws:ec2:*:*:subnet/*" }, { "Sid": "AllowCreateEniWithSecurityGroups", "Effect": "Allow", "Action": "ec2:CreateNetworkInterface", "Resource": "arn:aws:ec2:*:*:security-group/*" }, { "Sid": "AllowCreateEniWithBedrockManagedRequestTag", "Effect": "Allow", "Action": "ec2:CreateNetworkInterface", "Resource": "arn:aws:ec2:*:*:network-interface/*", "Condition": { "ForAllValues:StringEquals": { "aws:TagKeys": [ "AmazonBedrockAgentCoreManaged" ] }, "StringEquals": { "aws:RequestTag/AmazonBedrockAgentCoreManaged": "true" } } }, { "Sid": "AllowTagEniOnCreate", "Effect": "Allow", "Action": "ec2:CreateTags", "Resource": "arn:aws:ec2:*:*:network-interface/*", "Condition": { "StringEquals": { "ec2:CreateAction": "CreateNetworkInterface" } } }, { "Sid": "AllowManageEniWhenBedrockManaged", "Effect": "Allow", "Action": [ "ec2:DeleteNetworkInterface", "ec2:AssignPrivateIpAddresses", "ec2:UnassignPrivateIpAddresses", "ec2:CreateNetworkInterfacePermission" ], "Resource": "arn:aws:ec2:*:*:network-interface/*", "Condition": { "StringEquals": { "aws:ResourceTag/AmazonBedrockAgentCoreManaged": "true" } } }, { "Sid": "AllowGetSecurityGroupsForVpc", "Effect": "Allow", "Action": [ "ec2:GetSecurityGroupsForVPC" ], "Resource": "arn:aws:ec2:*:*:vpc/*" }, { "Sid": "AllowDescribeNetworkingResources", "Effect": "Allow", "Action": [ "ec2:DescribeNetworkInterfaces", "ec2:DescribeSecurityGroups", "ec2:DescribeSubnets", "ec2:DescribeVpcs" ], "Resource": "*" } ] }

身份服务相关角色

AgentCore 使用名为的服务相关角色AWSServiceRoleForBedrockAgentCoreRuntimeIdentity AgentCore 允许代表您管理工作负载身份访问令牌和 OAuth 证书。

AWSServiceRoleForBedrockAgentCoreRuntimeIdentity 服务相关角色信任以下服务代入该角色:

  • runtime-identity.bedrock-agentcore.amazonaws.com

角色权限策略 AgentCore 允许在指定资源上完成这些操作。

您可以在以下位置查看完整的政策BedrockAgentCoreRuntimeIdentityServiceRolePolicy。

{ "Version": "2012-10-17", "Statement": { "Sid": "AllowWorkloadIdentityAccess", "Effect": "Allow", "Action": [ "bedrock-agentcore:GetWorkloadAccessToken", "bedrock-agentcore:GetWorkloadAccessTokenForJWT", "bedrock-agentcore:GetWorkloadAccessTokenForUserId" ], "Resource": [ "arn:aws:bedrock-agentcore:*:*:workload-identity-directory/default", "arn:aws:bedrock-agentcore:*:*:workload-identity-directory/default/workload-identity/*" ] } }

有关此策略更改的信息,请参阅 AWS 托管策略的AgentCore 更新。

了解身份特征

服务相关角色用于支持运行时资源的 OAuth 身份验证和 JWT 持有者令牌功能。 AgentCore 此功能允许代理运行时安全地管理工作负载身份并代表用户访问外部 OAuth 提供商。

身份管理的主要好处

  • 简化的权限管理:无需为工作负载身份访问手动配置 IAM 策略

  • 安全令牌管理:为 OAuth 流程提供对工作负载访问令牌的安全访问

  • 用户联盟:启用三段 OAuth 流程来访问外部服务,例如谷歌云端硬盘、微软 Graph 等。

  • 自动配置:需要时自动创建 Service-linked 角色

身份管理的工作原理

当您使用 OAuth 身份验证或 JWT 持有者令牌调用 AgentCore 运行时时:

  1. 您可以在运行时创建期间配置 JWT 授权方设置(发现 URL、允许的客户端、允许的受众)

  2. AgentCore 自动创建服务相关角色以管理工作负载身份权限

  3. 运行时使用服务相关角色将 JWT 令牌交换为工作负载访问令牌

  4. 您的代理代码可以使用这些令牌来访问外部 OAuth 提供商和服务

  5. 所有令牌管理均通过 AgentCore 身份服务安全处理

从传统方法迁移

适用于现有代理(在 2025 年 10 月 13 日之前创建)
  • 继续使用附加到代理执行角色的手动 IAM 策略

  • 不自动迁移-保留现有行为

适用于新代理(在 2025 年 10 月 13 日当天或之后创建)
  • 自动使用服务相关角色方法

  • 无需手动配置 IAM 策略

  • 简化了设置和管理

服务相关角色确保 AgentCore 只能访问与您的代理运行时明确关联的工作负载身份资源,同时保持安全隔离和明确的资源归因。

有关实施的详细信息,请参阅使用入站身份验证和出站身份验证进行身份验证和授权。

网关服务相关角色

AgentCore 使用名为AWSServiceRoleForBedrockAgentCoreGatewayNetwork的服务相关角色允许 AgentCore Gateway 代表您在您的账户中创建和管理 Amazon VPC Lattice 资源。当您使用托管私有终端节点配置网关目标时,将使用此角色,使 AgentCore 网关能够设置必要的 VPC Lattice 资源网关,以便与您的 VPC 中的资源进行私有连接。

AWSServiceRoleForBedrockAgentCoreGatewayNetwork 服务相关角色信任以下服务代入该角色:

  • bedrock-agentcore.amazonaws.com

角色权限策略 AgentCore 允许对指定资源完成以下操作:

您可以在以下位置查看完整的政策AWSBedrockAgentCoreGatewayNetworkServiceRolePolicy。

{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowSLRActionsForLattice", "Effect": "Allow", "Action": [ "iam:CreateServiceLinkedRole" ], "Resource": [ "arn:aws:iam::*:role/aws-service-role/vpc-lattice.amazonaws.com/AWSServiceRoleForVpcLattice" ], "Condition": { "StringEquals": { "iam:AWSServiceName": "vpc-lattice.amazonaws.com" } } }, { "Sid": "AllowResourceGatewayCreate", "Effect": "Allow", "Action": [ "vpc-lattice:CreateResourceGateway", "vpc-lattice:TagResource" ], "Resource": [ "arn:aws:vpc-lattice:*:*:resourcegateway/*" ], "Condition": { "StringEquals": { "aws:RequestTag/BedrockAgentCoreGatewayManaged": "true", "aws:ResourceTag/BedrockAgentCoreGatewayManaged": "true" } } }, { "Sid": "AllowEC2PermissionsForResourceGatewayCreate", "Effect": "Allow", "Action": [ "ec2:DescribeSubnets", "ec2:DescribeVpcs", "ec2:DescribeSecurityGroups" ], "Resource": [ "*" ] }, { "Sid": "AllowResourceGatewayDelete", "Effect": "Allow", "Action": [ "vpc-lattice:DeleteResourceGateway", "vpc-lattice:GetResourceGateway" ], "Resource": [ "*" ], "Condition": { "StringEquals": { "aws:ResourceTag/BedrockAgentCoreGatewayManaged": "true" } } } ] }

了解网关管理的莱迪思功能

服务相关角色用于支持 AgentCore 网关目标的托管私有终端节点功能。当您使用托管私有终端节点创建网关目标时, AgentCore 使用此角色代表您在账户中创建和管理 VPC Lattice 资源网关。这些托管资源网关支持网 AgentCore 关与您的 VPC 中的资源之间的私有连接,无需您手动设置 VPC Lattice 资源。

管理莱迪思资源的主要优点

  • 简化设置:无需手动创建和配置 VPC 莱迪思资源网关

  • Scoped-down 联网权限:应用程序开发人员在自己的 IAM 策略中不需要 VPC Lattice 网络权限

  • 管理生命周期: AgentCore 管理莱迪思资源的整个生命周期,包括创建、重复使用和清理

  • 自动配置:当您使用托管私有终端节点创建网关目标时,会自动创建服务相关角色

受管理的莱迪思资源的工作原理

当您使用托管私有终端节点创建网关目标时:

  1. 您在配置中为私有终端节点指定 VPC、子网和可选安全组 managedVpcResource

  2. AgentCore 如果服务相关角色尚不存在,则自动创建该角色

  3. AgentCore 使用角色在您的账户中创建托管 VPC 莱迪思资源网关,标签为 BedrockAgentCoreGatewayManaged

  4. AgentCore 设置必要的 VPC Lattice 资源以启用私有连接

  5. 当您删除网关目标时,将 AgentCore 清理不再使用的托管莱迪思资源

注意

服务相关角色只能管理带有标签的 VPC Lattice 资源网关。BedrockAgentCoreGatewayManaged它无法修改或删除您自己创建和管理的资源网关。如果您为网关目标使用自我管理的莱迪思资源选项,则不需要此服务相关角色。

身份网络服务相关角色

AgentCore 使用名为AWSServiceRoleForBedrockAgentCoreIdentity的服务相关角色允许 AgentCore Identity 代表您在账户中创建和管理 Amazon VPC Lattice 资源。此角色用于为私有身份提供商配置私有终端节点,从而使 Identity 能够 AgentCore 设置必要的 VPC Lattice 资源网关,以便与您的 VPC 中的身份提供商建立私有连接。

AWSServiceRoleForBedrockAgentCoreIdentity 服务相关角色信任以下服务代入该角色:

  • identity-network.bedrock-agentcore.amazonaws.com

角色权限策略 AgentCore 允许对指定资源完成以下操作:

您可以在以下位置查看完整的政策AWSBedrockAgentCoreIdentityNetworkServiceRolePolicy。

{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "AllowSLRActionsForLattice", "Effect" : "Allow", "Action" : [ "iam:CreateServiceLinkedRole" ], "Resource" : [ "arn:aws:iam::*:role/aws-service-role/vpc-lattice.amazonaws.com/AWSServiceRoleForVpcLattice" ], "Condition" : { "StringEquals" : { "iam:AWSServiceName" : "vpc-lattice.amazonaws.com" } } }, { "Sid" : "AllowResourceGatewayCreate", "Effect" : "Allow", "Action" : [ "vpc-lattice:CreateResourceGateway", "vpc-lattice:TagResource" ], "Resource" : [ "arn:aws:vpc-lattice:*:*:resourcegateway/*" ], "Condition" : { "StringEquals" : { "aws:RequestTag/BedrockAgentCoreIdentityManaged" : "true", "aws:ResourceTag/BedrockAgentCoreIdentityManaged" : "true" } } }, { "Sid" : "AllowEC2PermissionsForResourceGatewayCreate", "Effect" : "Allow", "Action" : [ "ec2:DescribeSubnets", "ec2:DescribeVpcs", "ec2:DescribeSecurityGroups" ], "Resource" : [ "*" ] }, { "Sid" : "AllowResourceGatewayDelete", "Effect" : "Allow", "Action" : [ "vpc-lattice:DeleteResourceGateway", "vpc-lattice:GetResourceGateway" ], "Resource" : [ "*" ], "Condition" : { "StringEquals" : { "aws:ResourceTag/BedrockAgentCoreIdentityManaged" : "true" } } } ] }

了解身份网络功能

服务相关角色用于支持 Id AgentCore entity 的托管私有端点功能。当您为私有身份提供商配置私有终端节点时, AgentCore 使用此角色代表您在账户中创建和管理 VPC Lattice 资源网关。这些托管资源网关支持您的 VPC 中的 AgentCore 身份和身份提供商(例如自托管的 Keycloak 或其他 OIDC-compliant 授权服务器)之间的私有连接 PingFederate,无需您手动设置 VPC Lattice 资源。

管理的莱迪思资源如何实现身份

当您为私有身份提供商配置私有终端节点时:

  1. 您在配置中为私有终端节点指定 VPC、子网和可选安全组 managedVpcResource

  2. AgentCore 如果服务相关角色尚不存在,则自动创建该角色

  3. AgentCore 使用角色在您的账户中创建托管 VPC 莱迪思资源网关,标签为 BedrockAgentCoreIdentityManaged

  4. AgentCore 设置必要的 VPC Lattice 资源以启用与身份提供商的私有连接

  5. 删除私有终端节点配置后,将 AgentCore 清理不再使用的托管莱迪思资源

注意

服务相关角色只能管理带有标签的 VPC Lattice 资源网关。BedrockAgentCoreIdentityManaged它无法修改或删除您自己创建和管理的资源网关。如果您为私人身份提供商使用自我管理的莱迪思资源选项,则不需要此服务相关角色。

有关配置私有身份提供商的更多信息,请参阅连接您的 VPC 中的私有身份提供商。

运行时实例服务相关角色

AgentCore 使用名AWSServiceRoleForBedrockAgentCoreRuntimeInstances为的服务相关角色清理容量提供商为实例计算类型创建的计算资源。 AgentCore 使用此角色在会话结束或容量提供商被删除时释放 EC2 实例、Amazon EBS 卷、启动模板、Auto Scaling 组和亚马逊 EventBridge 规则等资源。Cleanup 通过服务相关角色运行,因此即使容量提供商操作员角色后来被修改或删除,该角色 AgentCore 也可以释放这些资源。

AWSServiceRoleForBedrockAgentCoreRuntimeInstances 服务相关角色信任以下服务代入该角色:

  • runtime-instances.bedrock-agentcore.amazonaws.com

角色权限策略 AgentCore 允许对指定资源完成以下操作。权限范围限于使用条件密钥、bedrock-agentcore:capacity-provider-id资源标签和ec2:ManagedResourceOperator条件密钥进行 AgentCore 管理的events:ManagedBy资源。

{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowDescribeResources", "Effect": "Allow", "Action": [ "ec2:DescribeInstanceStatus", "ec2:DescribeInstances", "ec2:DescribeNetworkInterfaces", "ec2:DescribeVolumes", "ec2:DescribeLaunchTemplates", "ec2:DescribeLaunchTemplateVersions", "autoscaling:DescribeAutoScalingGroups" ], "Resource": [ "*" ] }, { "Sid": "AllowCleanupManagedLaunchTemplate", "Effect": "Allow", "Action": [ "ec2:DeleteLaunchTemplate", "ec2:DeleteLaunchTemplateVersions" ], "Resource": "arn:aws:ec2:*:*:launch-template/*", "Condition": { "StringEquals": { "ec2:ManagedResourceOperator": "bedrock-agentcore.amazonaws.com" } } }, { "Sid": "AllowCleanupAutoScalingGroup", "Effect": "Allow", "Action": [ "autoscaling:DeleteAutoScalingGroup", "autoscaling:CompleteLifecycleAction" ], "Resource": "arn:aws:autoscaling:*:*:autoScalingGroup:*", "Condition": { "Null": { "aws:ResourceTag/bedrock-agentcore:capacity-provider-id": "false" } } }, { "Sid": "AllowCleanupEventBridge", "Effect": "Allow", "Action": [ "events:RemoveTargets", "events:DeleteRule" ], "Resource": "arn:aws:events:*:*:rule/*", "Condition": { "StringEquals": { "events:ManagedBy": "bedrock-agentcore.amazonaws.com" } } }, { "Sid": "AllowCleanupEBSVolumes", "Effect": "Allow", "Action": [ "ec2:DeleteVolume" ], "Resource": [ "arn:aws:ec2:*:*:volume/*" ], "Condition": { "StringEquals": { "ec2:ManagedResourceOperator": "bedrock-agentcore.amazonaws.com" } } }, { "Sid": "AllowDetachEBSVolumes", "Effect": "Allow", "Action": [ "ec2:DetachVolume" ], "Resource": [ "arn:aws:ec2:*:*:volume/*", "arn:aws:ec2:*:*:instance/*" ], "Condition": { "StringEquals": { "ec2:ManagedResourceOperator": "bedrock-agentcore.amazonaws.com" } } }, { "Sid": "AllowTerminateManagedInstances", "Effect": "Allow", "Action": [ "ec2:TerminateInstances" ], "Resource": [ "arn:aws:ec2:*:*:instance/*" ], "Condition": { "StringEquals": { "ec2:ManagedResourceOperator": "bedrock-agentcore.amazonaws.com" } } } ] }

为创建服务相关角色 AgentCore

您无需手动创建服务相关角色。 AgentCore 需要时自动创建它们:

  • 网络服务相关角色:在使用 VPC 配置创建 AgentCore 运行时、代码解释器或浏览器资源时创建

  • 身份服务相关角色:在 2025 年 10 月 13 日当天或之后创建或更新 AgentCore Runtime 时创建

  • 网关服务相关角色:使用托管私有终端节点 (managedVpcResource) 配置创建 AgentCore 网关目标时创建

  • 身份网络服务相关角色:当您为 VPC 托管身份提供商 (managedVpcResource) 配置配置私有终端节点时创建

  • 运行时实例服务相关角色:在为实例计算类型创建容量提供商时创建

如果您删除服务相关角色然后需要重新创建,则可以使用相同的流程在账户中重新创建该角色。当您创建相应的 AgentCore 资源时, AgentCore 会再次为您创建服务相关角色。

创建服务相关角色所需的权限

您必须配置权限,允许 IAM 实体(如用户、组或角色)创建、编辑或删除服务关联角色。IAM 实体需要具有以下权限:

对于网络服务相关角色

{ "Action": "iam:CreateServiceLinkedRole", "Effect": "Allow", "Resource": "arn:aws:iam::*:role/aws-service-role/network.bedrock-agentcore.amazonaws.com/AWSServiceRoleForBedrockAgentCoreNetwork", "Condition": { "StringLike": { "iam:AWSServiceName": "network.bedrock-agentcore.amazonaws.com" } } }

对于身份服务相关角色

{ "Sid": "CreateBedrockAgentCoreRuntimeIdentityServiceLinkedRolePermissions", "Effect": "Allow", "Action": "iam:CreateServiceLinkedRole", "Resource": "arn:aws:iam::*:role/aws-service-role/runtime-identity.bedrock-agentcore.amazonaws.com/AWSServiceRoleForBedrockAgentCoreRuntimeIdentity", "Condition": { "StringEquals": { "iam:AWSServiceName": "runtime-identity.bedrock-agentcore.amazonaws.com" } } }

对于网关服务相关角色

{ "Effect": "Allow", "Action": "iam:CreateServiceLinkedRole", "Resource": "arn:aws:iam::*:role/aws-service-role/bedrock-agentcore.amazonaws.com/AWSServiceRoleForBedrockAgentCoreGatewayNetwork", "Condition": { "StringEquals": { "iam:AWSServiceName": "bedrock-agentcore.amazonaws.com" } } }

对于身份网络服务相关角色

{ "Effect": "Allow", "Action": "iam:CreateServiceLinkedRole", "Resource": "arn:aws:iam::*:role/aws-service-role/identity-network.bedrock-agentcore.amazonaws.com/AWSServiceRoleForBedrockAgentCoreIdentity", "Condition": { "StringEquals": { "iam:AWSServiceName": "identity-network.bedrock-agentcore.amazonaws.com" } } }

对于运行时实例服务相关角色

{ "Effect": "Allow", "Action": "iam:CreateServiceLinkedRole", "Resource": "arn:aws:iam::*:role/aws-service-role/runtime-instances.bedrock-agentcore.amazonaws.com/AWSServiceRoleForBedrockAgentCoreRuntimeInstances", "Condition": { "StringEquals": { "iam:AWSServiceName": "runtime-instances.bedrock-agentcore.amazonaws.com" } } }

这些权限已包含在 AWS 托管策略中BedrockAgentCoreFullAccess。

编辑的服务相关角色 AgentCore

AgentCore 不允许您编辑AWSServiceRoleForBedrockAgentCoreNetwork、、AWSServiceRoleForBedrockAgentCoreRuntimeIdentityAWSServiceRoleForBedrockAgentCoreGatewayNetworkAWSServiceRoleForBedrockAgentCoreIdentity、或AWSServiceRoleForBedrockAgentCoreRuntimeInstances服务相关角色。创建服务关联角色后,您将无法更改角色的名称,因为可能有多种实体引用该角色。但是可以使用 IAM 编辑角色描述。有关更多信息,请参阅编辑服务相关角色。

删除的服务相关角色 AgentCore

如果不再需要使用某个需要服务关联角色的功能或服务,我们建议您删除该角色。这样就没有未被主动监控或维护的未使用实体。但是,必须先删除所有使用服务相关角色的 AgentCore 资源,然后才能删除该角色:

  • 网络服务相关角色:使用 VPC 配置删除所有 AgentCore 运行时、代码解释器和浏览器资源

  • 身份服务相关角色:删除所有 AgentCore 运行时资源

  • 网关服务相关角色:删除所有使用托管私有端点的 AgentCore 网关目标(managedVpcResource配置)

  • 身份网络服务相关角色:删除使用 VPC 托管 AgentCore 身份提供商的托管私有终端节点的所有身份资源(managedVpcResource配置)。这包括出站 OAuth 凭证提供商和入站 JWT 授权方配置(在运行时或网关上 AgentCore )。

  • 运行时实例服务相关角色:删除所有容量提供者。

清除服务相关角色

必须先确认服务相关角色没有活动会话并删除该角色使用的任何资源,然后才能使用 IAM 删除服务相关角色。

检查服务相关角色在 IAM 控制台中是否有活跃的会话

  1. 登录 AWS 管理控制台并在上打开 IAM 控制台https://console.aws.amazon.com/iam/。

  2. 在 IAM 控制台的导航窗格中,选择角色,然后选择角色的名称(不是复选框)。AWSServiceRoleForBedrockAgentCoreNetwork

  3. 在所选角色的 Summary 页面上,选择 Access Advisor 选项卡。

  4. 在 Access Advisor (访问顾问) 选项卡上,查看服务相关角色的近期活动。

注意

如果您不确定 AgentCore 是否在使用服务相关角色,则可以尝试删除该角色。如果服务正在使用该角色,则删除操作会失败,并且您可以查看正在使用该角色的 区域。如果该角色已被使用,则您必须等待会话结束,然后才能删除该角色。您无法撤销服务相关角色对会话的权限。

如果要删除服务相关角色,则必须先删除相应的 AgentCore 资源:

  • AWSServiceRoleForBedrockAgentCoreNetwork: 使用 VPC 配置删除所有 AgentCore 运行时、代码解释器和浏览器资源

  • AWSServiceRoleForBedrockAgentCoreRuntimeIdentity: 删除所有 AgentCore 运行时资源

  • AWSServiceRoleForBedrockAgentCoreGatewayNetwork:删除所有使用托管私有端点的 AgentCore 网关目标。删除所有托管目标后, AgentCore 释放不再使用的托管 VPC Lattice 资源网关。

  • AWSServiceRoleForBedrockAgentCoreIdentity:删除使用 VPC 托管 AgentCore 身份提供商的托管私有终端节点的所有身份资源。这包括出站 OAuth 凭证提供商和具有私有端点的入站 JWT 授权方配置(在 AgentCore 运行时或网关上)。managedVpcResource移除所有托管私有终端节点配置后, AgentCore 释放不再使用的托管 VPC Lattice 资源网关。

  • AWSServiceRoleForBedrockAgentCoreRuntimeInstances:删除所有容量提供者。删除容量提供者会停止和删除其会话并释放相关的计算资源。

手动删除服务相关角色

使用 IAM 控制台、 AWS CLI 或 IAM API 删除服务相关角色。有关更多信息,请参阅删除服务相关角色。