本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。
建立和管理登錄檔
遷移現已開啟
AWS 代理程式登錄檔已在新的agent-registry命名空間下啟動。公有預覽bedrock-agentcore命名空間的支援將於 2026 年 9 月 17 日停止。如需遷移說明,請參閱綜合登錄遷移指南。
建立登錄檔
主控台
範例
- AWS Agent Registry namespace
-
-
開啟 AWS 代理程式登錄檔主控台
。 -
在導覽窗格的探索下,選擇登錄檔。
-
在登錄檔區段中,選擇建立登錄檔。
-
在名稱中,輸入登錄檔的名稱。名稱必須以字母或數字開頭。有效字元為 a-z、A-Z、0-9、_ (底線)、- (連字號)、. (點) 和 / (正斜線)。名稱最多可有 64 個字元。
-
(選用) 展開其他詳細資訊並輸入描述 (1–4,096 個字元)。
-
(選用) 展開探索授權,以設定消費者在探索登錄檔中的記錄時如何授權 - 搜尋、瀏覽已核准的記錄目錄、批次取得已核准的記錄,以及叫用登錄檔的 MCP 端點 (傳入授權)。選擇 AWS IAM 以使用標準 AWS 登入資料,或選擇 JSON Web 字符 (JWT) 以使用您的公司身分提供者登入資料。如果您選擇 JWT,您可以使用 Cognito 快速建立,或提供探索 URL、對象、範圍、自訂宣告和用戶端來使用自己的 IdP。
-
在記錄核准下,選擇是否啟用自動核准。當自動核准關閉時,策展者必須先檢閱和核准每個記錄,才能搜尋。
-
(選用) 展開標籤以將標籤新增至登錄檔。標籤是索引鍵/值組,可協助您分類、搜尋和管理登錄檔。每個標籤都包含必要的索引鍵和選用的值。
-
(選用) 展開 KMS 金鑰以使用客戶受管金鑰設定靜態加密。根據預設,您的登錄檔會使用 AWS 擁有的金鑰加密。若要使用您自己的金鑰,請選取自訂加密設定 (進階),然後輸入 KMS 金鑰的 ARN,或選擇建立 AWS KMS 金鑰以建立新的金鑰。建立登錄檔後,就無法變更 KMS 金鑰。如需詳細資訊,請參閱AWS 客服人員登錄檔中的資料保護。
-
選擇建立登錄檔。
-
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
-
在導覽窗格的探索下,選擇登錄檔。
-
在登錄檔區段中,選擇建立登錄檔。
-
在名稱中,輸入登錄檔的名稱。名稱必須以字母或數字開頭。有效字元為 a-z、A-Z、0-9、_ (底線)、- (連字號)、. (點) 和 / (正斜線)。名稱最多可有 64 個字元。
-
(選用) 展開其他詳細資訊並輸入描述 (1–4,096 個字元)。
-
(選用) 展開搜尋 API 授權,以設定消費者在搜尋登錄檔時授權的方式 (傳入授權)。選擇 AWS IAM 以使用標準 AWS 登入資料,或選擇 JSON Web 字符 (JWT) 以使用您的公司身分提供者登入資料。如果您選擇 JWT,您可以使用 Cognito 快速建立,或提供探索 URL、對象、範圍、自訂宣告和用戶端來使用自己的 IdP。
-
在記錄核准下,選擇是否啟用自動核准。當自動核准關閉時,策展者必須先檢閱和核准每個記錄,才能搜尋。
-
(選用) 展開 KMS 金鑰以使用客戶受管金鑰設定靜態加密。根據預設,您的登錄檔會使用 AWS 擁有的金鑰加密。若要使用您自己的金鑰,請選取自訂加密設定 (進階),然後輸入 KMS 金鑰的 ARN,或選擇建立 AWS KMS 金鑰以建立新的金鑰。建立登錄檔後,就無法變更 KMS 金鑰。如需詳細資訊,請參閱AWS 客服人員登錄檔中的資料保護。
-
選擇建立登錄檔。
登錄檔狀態開始為建立,並在佈建完成時轉換為就緒。
注意
對於啟用 JWT 的登錄檔,至少需要一個 JWT 授權組態欄位:允許對象、允許用戶端、允許範圍或自訂宣告。如果您設定多個, AWS 客服人員登錄檔會驗證所有項目。
AWS CLI
IAM 型登錄:
範例
- AWS Agent Registry namespace
-
aws agent-registry-control create-registry \ --name "MyRegistry" \ --description "Production registry" \ --region us-east-1 - Amazon Bedrock AgentCore namespace (to be deprecated)
-
aws bedrock-agentcore-control create-registry \ --name "MyRegistry" \ --description "Production registry" \ --region us-east-1
以 JWT 為基礎的登錄檔:
範例
- AWS Agent Registry namespace
-
aws agent-registry-control create-registry \ --name "MyOAuthRegistry" \ --discovery-configuration '{"authorizerType": "CUSTOM_JWT", "authorizerConfiguration": {"customJWTAuthorizer": {"discoveryUrl": "https://cognito-idp.us-east-1.amazonaws.com/<poolId>/.well-known/openid-configuration", "allowedClients": ["<appClientId>"]}}}' \ --region us-east-1 - Amazon Bedrock AgentCore namespace (to be deprecated)
-
aws bedrock-agentcore-control create-registry \ --name "MyOAuthRegistry" \ --authorizer-type CUSTOM_JWT \ --authorizer-configuration '{"customJWTAuthorizer": {"discoveryUrl": "https://cognito-idp.us-east-1.amazonaws.com/<poolId>/.well-known/openid-configuration", "allowedClients": ["<appClientId>"]}}' \ --region us-east-1
具有客戶受管金鑰的登錄檔
範例
- AWS Agent Registry namespace
-
aws agent-registry-control create-registry \ --name "MyEncryptedRegistry" \ --description "Registry with customer managed encryption" \ --encryption-configuration '{"kmsKeyArn":"arn:aws:kms:us-east-1:111122223333:key/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222"}' \ --region us-east-1 - Amazon Bedrock AgentCore namespace (to be deprecated)
-
aws bedrock-agentcore-control create-registry \ --name "MyEncryptedRegistry" \ --description "Registry with customer managed encryption" \ --encryption-configuration '{"kmsKeyArn":"arn:aws:kms:us-east-1:111122223333:key/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222"}' \ --region us-east-1
注意
您只能在建立登錄檔期間設定 --encryption-configuration 參數。您無法在建立登錄檔後變更 KMS 金鑰。如果您省略此參數,根據預設,登錄檔會使用 AWS 擁有的金鑰。
AWS 開發套件
IAM 型登錄:
範例
- AWS Agent Registry namespace
-
import boto3 client = boto3.client('agent-registry-control') response = client.create_registry( name='MyRegistry', description='Production registry' ) print(response['registryArn']) - Amazon Bedrock AgentCore namespace (to be deprecated)
-
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.create_registry( name='MyRegistry', description='Production registry' ) print(response['registryArn'])
以 JWT 為基礎的登錄檔:
範例
- AWS Agent Registry namespace
-
import boto3 client = boto3.client('agent-registry-control') response = client.create_registry( name='MyOAuthRegistry', discoveryConfiguration={ 'authorizerType': 'CUSTOM_JWT', 'authorizerConfiguration': { 'customJWTAuthorizer': { 'discoveryUrl': 'https://cognito-idp.us-east-1.amazonaws.com/<poolId>/.well-known/openid-configuration', 'allowedClients': ['<appClientId>'] } } } ) print(response['registryArn']) - Amazon Bedrock AgentCore namespace (to be deprecated)
-
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.create_registry( name='MyOAuthRegistry', authorizerType='CUSTOM_JWT', authorizerConfiguration={ 'customJWTAuthorizer': { 'discoveryUrl': 'https://cognito-idp.us-east-1.amazonaws.com/<poolId>/.well-known/openid-configuration', 'allowedClients': ['<appClientId>'] } } ) print(response['registryArn'])
具有客戶受管金鑰的登錄檔
範例
- AWS Agent Registry namespace
-
import boto3 client = boto3.client('agent-registry-control') response = client.create_registry( name='MyEncryptedRegistry', description='Registry with customer managed encryption', encryptionConfiguration={ 'kmsKeyArn': 'arn:aws:kms:us-east-1:111122223333:key/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222' } ) print(response['registryArn']) - Amazon Bedrock AgentCore namespace (to be deprecated)
-
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.create_registry( name='MyEncryptedRegistry', description='Registry with customer managed encryption', encryptionConfiguration={ 'kmsKeyArn': 'arn:aws:kms:us-east-1:111122223333:key/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222' } ) print(response['registryArn'])
列出登錄檔
主控台
範例
- AWS Agent Registry namespace
-
-
開啟 AWS 代理程式登錄檔主控台
。 -
在導覽窗格的探索下,選擇登錄檔。
-
註冊表會以下列資料欄顯示您帳戶中的所有註冊:
-
名稱 — 登錄檔名稱 (連結至詳細資訊頁面)。
-
描述 — 如果提供,則為登錄檔描述。
-
驗證類型 — 傳入授權方法 (AWS_IAM 或 CUSTOM_JWT)。
-
狀態 — 目前狀態 (建立、就緒、更新、刪除或失敗狀態)。
-
ARN — 登錄檔 Amazon Resource Name。
-
已建立 — 建立時間戳記。
-
上次更新 — 上次修改時間戳記。
-
-
使用尋找登錄檔搜尋列依名稱篩選。
-
使用分頁控制項瀏覽結果。
-
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
-
在導覽窗格的探索下,選擇登錄檔。
-
註冊表會以下列資料欄顯示您帳戶中的所有註冊:
-
名稱 — 登錄檔名稱 (連結至詳細資訊頁面)。
-
描述 — 如果提供,則為登錄檔描述。
-
授權類型 — 傳入授權方法 (AWS_IAM 或 CUSTOM_JWT)。
-
狀態 — 目前狀態 (建立、就緒、更新、刪除或失敗狀態)。
-
ARN — 登錄檔 Amazon Resource Name。
-
已建立 — 建立時間戳記。
-
上次更新 — 上次修改時間戳記。
-
-
使用尋找登錄檔搜尋列依名稱篩選。
-
使用分頁控制項瀏覽結果。
AWS CLI
範例
- AWS Agent Registry namespace
-
aws agent-registry-control list-registries \ --region us-east-1 - Amazon Bedrock AgentCore namespace (to be deprecated)
-
aws bedrock-agentcore-control list-registries \ --region us-east-1
AWS 開發套件
範例
- AWS Agent Registry namespace
-
import boto3 client = boto3.client('agent-registry-control') response = client.list_registries() for registry in response['registries']: print(f"{registry['name']} - {registry['status']} - {registry['registryArn']}") - Amazon Bedrock AgentCore namespace (to be deprecated)
-
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.list_registries() for registry in response['registries']: print(f"{registry['name']} - {registry['status']} - {registry['registryArn']}")
檢視登錄檔詳細資訊
主控台
範例
- AWS Agent Registry namespace
-
-
開啟 AWS 代理程式登錄檔主控台
。 -
在導覽窗格的探索下,選擇登錄檔。
-
從註冊表選擇註冊表名稱。
-
登錄檔詳細資訊頁面會顯示下列可摺疊區段:
-
登錄檔詳細資訊 — 顯示名稱、狀態、描述、自動核准 (啟用或停用)、登錄檔 ARN、上次更新日期和建立日期。
-
登錄檔記錄 — 顯示提交至此登錄檔之記錄的狀態摘要計數器 (提交總數、待核准、已核准、已棄用、已拒絕) 和記錄表。您可以在這裡建立、檢視或管理記錄。
-
探索授權 (傳入授權) — 顯示目前的授權類型 (AWS_IAM 或 CUSTOM_JWT),以及 JWT 授權登錄檔的 JWT 授權方組態。
-
範例程式碼:提供您可以複製和調整的常見操作 (建立、核准、列出和探索記錄) 的範例程式碼。
-
標籤 — 將與登錄檔相關聯的標籤顯示為鍵值資料表。若要新增、移除或修改標籤,請在本節中選擇編輯以開啟編輯標籤頁面。
-
-
若要修改登錄檔,請選擇編輯。若要刪除登錄檔,請選擇刪除。
-
若要搜尋或瀏覽此登錄檔中已核准的記錄,請選擇頁面右上角的記錄目錄 (或在導覽窗格中)。如需探索演練,請參閱開始使用客服人員登錄檔。
-
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
-
在導覽窗格的探索下,選擇登錄檔。
-
從註冊表選擇註冊表名稱。
-
登錄檔詳細資訊頁面有兩個索引標籤:
-
管理記錄 — 檢視和管理登錄檔記錄。
-
搜尋記錄 — 在登錄檔中搜尋已核准的記錄。
-
-
登錄檔詳細資訊區段會顯示:名稱、狀態、描述、自動核准 (啟用或停用)、登錄檔 ARN、上次更新日期、建立日期。
-
登錄檔記錄區段會顯示狀態摘要計數器 (提交總數、待核准、已核准、已棄用、已拒絕) 和記錄表。
-
搜尋 API 授權 (傳入授權) 區段顯示目前的授權類型。
AWS CLI
範例
- AWS Agent Registry namespace
-
aws agent-registry-control get-registry \ --registry-id "<registryId>" \ --region us-east-1 - Amazon Bedrock AgentCore namespace (to be deprecated)
-
aws bedrock-agentcore-control get-registry \ --registry-id "<registryId>" \ --region us-east-1
AWS 開發套件
範例
- AWS Agent Registry namespace
-
import boto3 client = boto3.client('agent-registry-control') response = client.get_registry( registryId='<registryId>' ) print(f"Name: {response['name']}") print(f"Status: {response['status']}") print(f"ARN: {response['registryArn']}") - Amazon Bedrock AgentCore namespace (to be deprecated)
-
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.get_registry( registryId='<registryId>' ) print(f"Name: {response['name']}") print(f"Status: {response['status']}") print(f"ARN: {response['registryArn']}")
更新登錄檔
主控台
範例
- AWS Agent Registry namespace
-
-
開啟 AWS 代理程式登錄檔主控台
。 -
在導覽窗格的探索下,選擇登錄檔。
-
選取您要編輯之登錄檔旁的選項按鈕,然後選擇編輯。或者,選擇登錄檔名稱,然後選擇編輯。
-
在編輯登錄頁面上,更新下列任何項目:
-
名稱 — 變更登錄檔名稱 (與建立相同的命名規則)。
-
描述 — 在其他詳細資訊下,更新或新增描述。
-
記錄核准 — 開啟或關閉自動核准。變更只會影響更新後提交的記錄。
-
探索授權 — 對於 JWT 授權的登錄檔,請更新 JWT 授權方組態 (允許用戶端、對象、範圍或自訂宣告)。建立登錄檔後,無法變更傳入授權類型本身 (IAM 或 JWT)。
-
-
選擇儲存變更。
-
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
-
在導覽窗格的探索下,選擇登錄檔。
-
選取您要編輯之登錄檔旁的選項按鈕,然後選擇編輯。或者,選擇登錄檔名稱,然後選擇編輯。
-
在編輯登錄頁面上,更新下列任何項目:
-
名稱 — 變更登錄檔名稱 (與建立相同的命名規則)。
-
描述 — 在其他詳細資訊下,更新或新增描述。
-
記錄核准 — 開啟或關閉自動核准。變更只會影響更新後提交的記錄。
-
-
選擇儲存變更。
注意
標籤不會從編輯登錄檔頁面編輯。若要修改標籤,請前往登錄檔詳細資訊頁面,在標籤區段中選擇編輯,在編輯標籤頁面上新增或移除標籤,然後選擇儲存變更。(只有在 AWS Agent Registry 主控台中才支援標籤。)
注意
將自動核准組態從 OFF 更新為 ON 只會影響變更後提交的記錄。已經「待核准」的現有記錄不受影響,但仍必須透過呼叫 UpdateRegistryRecordStatus API 來核准或拒絕。將組態從 ON 變更為 OFF 只會影響變更後發佈至「待核准」的記錄。
注意
建立登錄檔後,無法變更傳入授權類型 (IAM 或 JWT) 和 JWT 探索 URL。對於 JWT 授權的登錄檔,您只能更新授權方組態 (允許用戶端、對象、範圍、自訂宣告)。
AWS CLI
範例
- AWS Agent Registry namespace
-
aws agent-registry-control update-registry \ --registry-id "<registryId>" \ --description '{"optionalValue": "Updated description"}' \ --region us-east-1 - Amazon Bedrock AgentCore namespace (to be deprecated)
-
aws bedrock-agentcore-control update-registry \ --registry-id "<registryId>" \ --description '{"optionalValue": "Updated description"}' \ --region us-east-1
AWS 開發套件
範例
- AWS Agent Registry namespace
-
import boto3 client = boto3.client('agent-registry-control') response = client.update_registry( registryId='<registryId>', description={'optionalValue': 'Updated description'} ) print(f"Updated: {response['name']} - Status: {response['status']}") - Amazon Bedrock AgentCore namespace (to be deprecated)
-
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.update_registry( registryId='<registryId>', description={'optionalValue': 'Updated description'} ) print(f"Updated: {response['name']} - Status: {response['status']}")
刪除登錄檔
主控台
範例
- AWS Agent Registry namespace
-
-
開啟 AWS 代理程式登錄檔主控台
。 -
在導覽窗格的探索下,選擇登錄檔。
-
選取您要刪除之登錄檔旁的選項按鈕,然後選擇刪除。
-
在確認對話方塊中,檢閱警告:您必須先刪除所有登錄檔記錄,然後再刪除登錄檔。
-
在確認欄位中輸入刪除。
-
選擇 刪除。
-
- Amazon Bedrock AgentCore namespace (to be deprecated)
-
-
在導覽窗格的探索下,選擇登錄檔。
-
選取您要刪除之登錄檔旁的選項按鈕,然後選擇刪除。
-
在確認對話方塊中,檢閱警告:您必須先刪除所有登錄檔記錄,然後再刪除登錄檔。
-
在確認欄位中輸入刪除。
-
選擇 刪除。
登錄檔狀態會變更為刪除。成功橫幅會在刪除完成時確認。
AWS CLI
範例
- AWS Agent Registry namespace
-
aws agent-registry-control delete-registry \ --registry-id "<registryId>" \ --region us-east-1 - Amazon Bedrock AgentCore namespace (to be deprecated)
-
aws bedrock-agentcore-control delete-registry \ --registry-id "<registryId>" \ --region us-east-1
AWS 開發套件
範例
- AWS Agent Registry namespace
-
import boto3 client = boto3.client('agent-registry-control') response = client.delete_registry( registryId='<registryId>' ) print(f"Status: {response['status']}") # DELETING - Amazon Bedrock AgentCore namespace (to be deprecated)
-
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.delete_registry( registryId='<registryId>' ) print(f"Status: {response['status']}") # DELETING