View a markdown version of this page

建立和管理登錄檔 - Amazon Bedrock AgentCore

本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。

建立和管理登錄檔

遷移現已開啟

AWS 代理程式登錄檔已在新的agent-registry命名空間下啟動。公有預覽bedrock-agentcore命名空間的支援將於 2026 年 9 月 17 日停止。如需遷移說明,請參閱綜合登錄遷移指南。

建立登錄檔

主控台

範例
AWS Agent Registry namespace
  1. 開啟 AWS 代理程式登錄檔主控台。

  2. 在導覽窗格的探索下,選擇登錄檔。

  3. 在登錄檔區段中,選擇建立登錄檔。

  4. 在名稱中,輸入登錄檔的名稱。名稱必須以字母或數字開頭。有效字元為 a-z、A-Z、0-9、_ (底線)、- (連字號)、. (點) 和 / (正斜線)。名稱最多可有 64 個字元。

  5. (選用) 展開其他詳細資訊並輸入描述 (1–4,096 個字元)。

  6. (選用) 展開探索授權,以設定消費者在探索登錄檔中的記錄時如何授權 - 搜尋、瀏覽已核准的記錄目錄、批次取得已核准的記錄,以及叫用登錄檔的 MCP 端點 (傳入授權)。選擇 AWS IAM 以使用標準 AWS 登入資料,或選擇 JSON Web 字符 (JWT) 以使用您的公司身分提供者登入資料。如果您選擇 JWT,您可以使用 Cognito 快速建立,或提供探索 URL、對象、範圍、自訂宣告和用戶端來使用自己的 IdP。

  7. 在記錄核准下,選擇是否啟用自動核准。當自動核准關閉時,策展者必須先檢閱和核准每個記錄,才能搜尋。

  8. (選用) 展開標籤以將標籤新增至登錄檔。標籤是索引鍵/值組,可協助您分類、搜尋和管理登錄檔。每個標籤都包含必要的索引鍵和選用的值。

  9. (選用) 展開 KMS 金鑰以使用客戶受管金鑰設定靜態加密。根據預設,您的登錄檔會使用 AWS 擁有的金鑰加密。若要使用您自己的金鑰,請選取自訂加密設定 (進階),然後輸入 KMS 金鑰的 ARN,或選擇建立 AWS KMS 金鑰以建立新的金鑰。建立登錄檔後,就無法變更 KMS 金鑰。如需詳細資訊,請參閱AWS 客服人員登錄檔中的資料保護。

  10. 選擇建立登錄檔。

Amazon Bedrock AgentCore namespace (to be deprecated)
  1. 開啟 Amazon Bedrock AgentCore 主控台。

  2. 在導覽窗格的探索下,選擇登錄檔。

  3. 在登錄檔區段中,選擇建立登錄檔。

  4. 在名稱中,輸入登錄檔的名稱。名稱必須以字母或數字開頭。有效字元為 a-z、A-Z、0-9、_ (底線)、- (連字號)、. (點) 和 / (正斜線)。名稱最多可有 64 個字元。

  5. (選用) 展開其他詳細資訊並輸入描述 (1–4,096 個字元)。

  6. (選用) 展開搜尋 API 授權,以設定消費者在搜尋登錄檔時授權的方式 (傳入授權)。選擇 AWS IAM 以使用標準 AWS 登入資料,或選擇 JSON Web 字符 (JWT) 以使用您的公司身分提供者登入資料。如果您選擇 JWT,您可以使用 Cognito 快速建立,或提供探索 URL、對象、範圍、自訂宣告和用戶端來使用自己的 IdP。

  7. 在記錄核准下,選擇是否啟用自動核准。當自動核准關閉時,策展者必須先檢閱和核准每個記錄,才能搜尋。

  8. (選用) 展開 KMS 金鑰以使用客戶受管金鑰設定靜態加密。根據預設,您的登錄檔會使用 AWS 擁有的金鑰加密。若要使用您自己的金鑰,請選取自訂加密設定 (進階),然後輸入 KMS 金鑰的 ARN,或選擇建立 AWS KMS 金鑰以建立新的金鑰。建立登錄檔後,就無法變更 KMS 金鑰。如需詳細資訊,請參閱AWS 客服人員登錄檔中的資料保護。

  9. 選擇建立登錄檔。

登錄檔狀態開始為建立,並在佈建完成時轉換為就緒。

注意

對於啟用 JWT 的登錄檔,至少需要一個 JWT 授權組態欄位:允許對象、允許用戶端、允許範圍或自訂宣告。如果您設定多個, AWS 客服人員登錄檔會驗證所有項目。

AWS CLI

IAM 型登錄:

範例
AWS Agent Registry namespace
aws agent-registry-control create-registry \ --name "MyRegistry" \ --description "Production registry" \ --region us-east-1
Amazon Bedrock AgentCore namespace (to be deprecated)
aws bedrock-agentcore-control create-registry \ --name "MyRegistry" \ --description "Production registry" \ --region us-east-1

以 JWT 為基礎的登錄檔:

範例
AWS Agent Registry namespace
aws agent-registry-control create-registry \ --name "MyOAuthRegistry" \ --discovery-configuration '{"authorizerType": "CUSTOM_JWT", "authorizerConfiguration": {"customJWTAuthorizer": {"discoveryUrl": "https://cognito-idp.us-east-1.amazonaws.com/<poolId>/.well-known/openid-configuration", "allowedClients": ["<appClientId>"]}}}' \ --region us-east-1
Amazon Bedrock AgentCore namespace (to be deprecated)
aws bedrock-agentcore-control create-registry \ --name "MyOAuthRegistry" \ --authorizer-type CUSTOM_JWT \ --authorizer-configuration '{"customJWTAuthorizer": {"discoveryUrl": "https://cognito-idp.us-east-1.amazonaws.com/<poolId>/.well-known/openid-configuration", "allowedClients": ["<appClientId>"]}}' \ --region us-east-1

具有客戶受管金鑰的登錄檔

範例
AWS Agent Registry namespace
aws agent-registry-control create-registry \ --name "MyEncryptedRegistry" \ --description "Registry with customer managed encryption" \ --encryption-configuration '{"kmsKeyArn":"arn:aws:kms:us-east-1:111122223333:key/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222"}' \ --region us-east-1
Amazon Bedrock AgentCore namespace (to be deprecated)
aws bedrock-agentcore-control create-registry \ --name "MyEncryptedRegistry" \ --description "Registry with customer managed encryption" \ --encryption-configuration '{"kmsKeyArn":"arn:aws:kms:us-east-1:111122223333:key/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222"}' \ --region us-east-1
注意

您只能在建立登錄檔期間設定 --encryption-configuration 參數。您無法在建立登錄檔後變更 KMS 金鑰。如果您省略此參數,根據預設,登錄檔會使用 AWS 擁有的金鑰。

AWS 開發套件

IAM 型登錄:

範例
AWS Agent Registry namespace
import boto3 client = boto3.client('agent-registry-control') response = client.create_registry( name='MyRegistry', description='Production registry' ) print(response['registryArn'])
Amazon Bedrock AgentCore namespace (to be deprecated)
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.create_registry( name='MyRegistry', description='Production registry' ) print(response['registryArn'])

以 JWT 為基礎的登錄檔:

範例
AWS Agent Registry namespace
import boto3 client = boto3.client('agent-registry-control') response = client.create_registry( name='MyOAuthRegistry', discoveryConfiguration={ 'authorizerType': 'CUSTOM_JWT', 'authorizerConfiguration': { 'customJWTAuthorizer': { 'discoveryUrl': 'https://cognito-idp.us-east-1.amazonaws.com/<poolId>/.well-known/openid-configuration', 'allowedClients': ['<appClientId>'] } } } ) print(response['registryArn'])
Amazon Bedrock AgentCore namespace (to be deprecated)
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.create_registry( name='MyOAuthRegistry', authorizerType='CUSTOM_JWT', authorizerConfiguration={ 'customJWTAuthorizer': { 'discoveryUrl': 'https://cognito-idp.us-east-1.amazonaws.com/<poolId>/.well-known/openid-configuration', 'allowedClients': ['<appClientId>'] } } ) print(response['registryArn'])

具有客戶受管金鑰的登錄檔

範例
AWS Agent Registry namespace
import boto3 client = boto3.client('agent-registry-control') response = client.create_registry( name='MyEncryptedRegistry', description='Registry with customer managed encryption', encryptionConfiguration={ 'kmsKeyArn': 'arn:aws:kms:us-east-1:111122223333:key/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222' } ) print(response['registryArn'])
Amazon Bedrock AgentCore namespace (to be deprecated)
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.create_registry( name='MyEncryptedRegistry', description='Registry with customer managed encryption', encryptionConfiguration={ 'kmsKeyArn': 'arn:aws:kms:us-east-1:111122223333:key/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222' } ) print(response['registryArn'])

列出登錄檔

主控台

範例
AWS Agent Registry namespace
  1. 開啟 AWS 代理程式登錄檔主控台。

  2. 在導覽窗格的探索下,選擇登錄檔。

  3. 註冊表會以下列資料欄顯示您帳戶中的所有註冊:

    1. 名稱 — 登錄檔名稱 (連結至詳細資訊頁面)。

    2. 描述 — 如果提供,則為登錄檔描述。

    3. 驗證類型 — 傳入授權方法 (AWS_IAM 或 CUSTOM_JWT)。

    4. 狀態 — 目前狀態 (建立、就緒、更新、刪除或失敗狀態)。

    5. ARN — 登錄檔 Amazon Resource Name。

    6. 已建立 — 建立時間戳記。

    7. 上次更新 — 上次修改時間戳記。

  4. 使用尋找登錄檔搜尋列依名稱篩選。

  5. 使用分頁控制項瀏覽結果。

Amazon Bedrock AgentCore namespace (to be deprecated)
  1. 開啟 Amazon Bedrock AgentCore 主控台。

  2. 在導覽窗格的探索下,選擇登錄檔。

  3. 註冊表會以下列資料欄顯示您帳戶中的所有註冊:

    1. 名稱 — 登錄檔名稱 (連結至詳細資訊頁面)。

    2. 描述 — 如果提供,則為登錄檔描述。

    3. 授權類型 — 傳入授權方法 (AWS_IAM 或 CUSTOM_JWT)。

    4. 狀態 — 目前狀態 (建立、就緒、更新、刪除或失敗狀態)。

    5. ARN — 登錄檔 Amazon Resource Name。

    6. 已建立 — 建立時間戳記。

    7. 上次更新 — 上次修改時間戳記。

  4. 使用尋找登錄檔搜尋列依名稱篩選。

  5. 使用分頁控制項瀏覽結果。

AWS CLI

範例
AWS Agent Registry namespace
aws agent-registry-control list-registries \ --region us-east-1
Amazon Bedrock AgentCore namespace (to be deprecated)
aws bedrock-agentcore-control list-registries \ --region us-east-1

AWS 開發套件

範例
AWS Agent Registry namespace
import boto3 client = boto3.client('agent-registry-control') response = client.list_registries() for registry in response['registries']: print(f"{registry['name']} - {registry['status']} - {registry['registryArn']}")
Amazon Bedrock AgentCore namespace (to be deprecated)
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.list_registries() for registry in response['registries']: print(f"{registry['name']} - {registry['status']} - {registry['registryArn']}")

檢視登錄檔詳細資訊

主控台

範例
AWS Agent Registry namespace
  1. 開啟 AWS 代理程式登錄檔主控台。

  2. 在導覽窗格的探索下,選擇登錄檔。

  3. 從註冊表選擇註冊表名稱。

  4. 登錄檔詳細資訊頁面會顯示下列可摺疊區段:

    1. 登錄檔詳細資訊 — 顯示名稱、狀態、描述、自動核准 (啟用或停用)、登錄檔 ARN、上次更新日期和建立日期。

    2. 登錄檔記錄 — 顯示提交至此登錄檔之記錄的狀態摘要計數器 (提交總數、待核准、已核准、已棄用、已拒絕) 和記錄表。您可以在這裡建立、檢視或管理記錄。

    3. 探索授權 (傳入授權) — 顯示目前的授權類型 (AWS_IAM 或 CUSTOM_JWT),以及 JWT 授權登錄檔的 JWT 授權方組態。

    4. 範例程式碼:提供您可以複製和調整的常見操作 (建立、核准、列出和探索記錄) 的範例程式碼。

    5. 標籤 — 將與登錄檔相關聯的標籤顯示為鍵值資料表。若要新增、移除或修改標籤,請在本節中選擇編輯以開啟編輯標籤頁面。

  5. 若要修改登錄檔,請選擇編輯。若要刪除登錄檔,請選擇刪除。

  6. 若要搜尋或瀏覽此登錄檔中已核准的記錄,請選擇頁面右上角的記錄目錄 (或在導覽窗格中)。如需探索演練,請參閱開始使用客服人員登錄檔。

Amazon Bedrock AgentCore namespace (to be deprecated)
  1. 開啟 Amazon Bedrock AgentCore 主控台。

  2. 在導覽窗格的探索下,選擇登錄檔。

  3. 從註冊表選擇註冊表名稱。

  4. 登錄檔詳細資訊頁面有兩個索引標籤:

    1. 管理記錄 — 檢視和管理登錄檔記錄。

    2. 搜尋記錄 — 在登錄檔中搜尋已核准的記錄。

  5. 登錄檔詳細資訊區段會顯示:名稱、狀態、描述、自動核准 (啟用或停用)、登錄檔 ARN、上次更新日期、建立日期。

  6. 登錄檔記錄區段會顯示狀態摘要計數器 (提交總數、待核准、已核准、已棄用、已拒絕) 和記錄表。

  7. 搜尋 API 授權 (傳入授權) 區段顯示目前的授權類型。

AWS CLI

範例
AWS Agent Registry namespace
aws agent-registry-control get-registry \ --registry-id "<registryId>" \ --region us-east-1
Amazon Bedrock AgentCore namespace (to be deprecated)
aws bedrock-agentcore-control get-registry \ --registry-id "<registryId>" \ --region us-east-1

AWS 開發套件

範例
AWS Agent Registry namespace
import boto3 client = boto3.client('agent-registry-control') response = client.get_registry( registryId='<registryId>' ) print(f"Name: {response['name']}") print(f"Status: {response['status']}") print(f"ARN: {response['registryArn']}")
Amazon Bedrock AgentCore namespace (to be deprecated)
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.get_registry( registryId='<registryId>' ) print(f"Name: {response['name']}") print(f"Status: {response['status']}") print(f"ARN: {response['registryArn']}")

更新登錄檔

主控台

範例
AWS Agent Registry namespace
  1. 開啟 AWS 代理程式登錄檔主控台。

  2. 在導覽窗格的探索下,選擇登錄檔。

  3. 選取您要編輯之登錄檔旁的選項按鈕,然後選擇編輯。或者,選擇登錄檔名稱,然後選擇編輯。

  4. 在編輯登錄頁面上,更新下列任何項目:

    1. 名稱 — 變更登錄檔名稱 (與建立相同的命名規則)。

    2. 描述 — 在其他詳細資訊下,更新或新增描述。

    3. 記錄核准 — 開啟或關閉自動核准。變更只會影響更新後提交的記錄。

    4. 探索授權 — 對於 JWT 授權的登錄檔,請更新 JWT 授權方組態 (允許用戶端、對象、範圍或自訂宣告)。建立登錄檔後,無法變更傳入授權類型本身 (IAM 或 JWT)。

  5. 選擇儲存變更。

Amazon Bedrock AgentCore namespace (to be deprecated)
  1. 開啟 Amazon Bedrock AgentCore 主控台。

  2. 在導覽窗格的探索下,選擇登錄檔。

  3. 選取您要編輯之登錄檔旁的選項按鈕,然後選擇編輯。或者,選擇登錄檔名稱,然後選擇編輯。

  4. 在編輯登錄頁面上,更新下列任何項目:

    1. 名稱 — 變更登錄檔名稱 (與建立相同的命名規則)。

    2. 描述 — 在其他詳細資訊下,更新或新增描述。

    3. 記錄核准 — 開啟或關閉自動核准。變更只會影響更新後提交的記錄。

  5. 選擇儲存變更。

注意

標籤不會從編輯登錄檔頁面編輯。若要修改標籤,請前往登錄檔詳細資訊頁面,在標籤區段中選擇編輯,在編輯標籤頁面上新增或移除標籤,然後選擇儲存變更。(只有在 AWS Agent Registry 主控台中才支援標籤。)

注意

將自動核准組態從 OFF 更新為 ON 只會影響變更後提交的記錄。已經「待核准」的現有記錄不受影響,但仍必須透過呼叫 UpdateRegistryRecordStatus API 來核准或拒絕。將組態從 ON 變更為 OFF 只會影響變更後發佈至「待核准」的記錄。

注意

建立登錄檔後,無法變更傳入授權類型 (IAM 或 JWT) 和 JWT 探索 URL。對於 JWT 授權的登錄檔,您只能更新授權方組態 (允許用戶端、對象、範圍、自訂宣告)。

AWS CLI

範例
AWS Agent Registry namespace
aws agent-registry-control update-registry \ --registry-id "<registryId>" \ --description '{"optionalValue": "Updated description"}' \ --region us-east-1
Amazon Bedrock AgentCore namespace (to be deprecated)
aws bedrock-agentcore-control update-registry \ --registry-id "<registryId>" \ --description '{"optionalValue": "Updated description"}' \ --region us-east-1

AWS 開發套件

範例
AWS Agent Registry namespace
import boto3 client = boto3.client('agent-registry-control') response = client.update_registry( registryId='<registryId>', description={'optionalValue': 'Updated description'} ) print(f"Updated: {response['name']} - Status: {response['status']}")
Amazon Bedrock AgentCore namespace (to be deprecated)
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.update_registry( registryId='<registryId>', description={'optionalValue': 'Updated description'} ) print(f"Updated: {response['name']} - Status: {response['status']}")

刪除登錄檔

主控台

範例
AWS Agent Registry namespace
  1. 開啟 AWS 代理程式登錄檔主控台。

  2. 在導覽窗格的探索下,選擇登錄檔。

  3. 選取您要刪除之登錄檔旁的選項按鈕,然後選擇刪除。

  4. 在確認對話方塊中,檢閱警告:您必須先刪除所有登錄檔記錄,然後再刪除登錄檔。

  5. 在確認欄位中輸入刪除。

  6. 選擇 刪除。

Amazon Bedrock AgentCore namespace (to be deprecated)
  1. 開啟 Amazon Bedrock AgentCore 主控台。

  2. 在導覽窗格的探索下,選擇登錄檔。

  3. 選取您要刪除之登錄檔旁的選項按鈕,然後選擇刪除。

  4. 在確認對話方塊中,檢閱警告:您必須先刪除所有登錄檔記錄,然後再刪除登錄檔。

  5. 在確認欄位中輸入刪除。

  6. 選擇 刪除。

登錄檔狀態會變更為刪除。成功橫幅會在刪除完成時確認。

AWS CLI

範例
AWS Agent Registry namespace
aws agent-registry-control delete-registry \ --registry-id "<registryId>" \ --region us-east-1
Amazon Bedrock AgentCore namespace (to be deprecated)
aws bedrock-agentcore-control delete-registry \ --registry-id "<registryId>" \ --region us-east-1

AWS 開發套件

範例
AWS Agent Registry namespace
import boto3 client = boto3.client('agent-registry-control') response = client.delete_registry( registryId='<registryId>' ) print(f"Status: {response['status']}") # DELETING
Amazon Bedrock AgentCore namespace (to be deprecated)
import boto3 client = boto3.client('bedrock-agentcore-control') response = client.delete_registry( registryId='<registryId>' ) print(f"Status: {response['status']}") # DELETING