

本文為英文版的機器翻譯版本，如內容有任何歧義或不一致之處，概以英文版為準。

# IAM 許可
<a name="registry-iam-permissions"></a>

**遷移現已開啟**  
 AWS 代理程式登錄檔已在新的`agent-registry`命名空間下啟動。公有預覽`bedrock-agentcore`命名空間的支援將於 2026 年 9 月 17 日停止。如需遷移說明，請參閱[綜合登錄遷移指南](registry-faq.md)。

## 登錄檔動作
<a name="registry-iam-actions"></a>

若要建立、管理或使用登錄檔，請將身分型政策連接至您的 IAM 身分，以允許其執行[AWS 客服人員登錄檔相關的動作](https://docs.aws.amazon.com/service-authorization/latest/reference/list_amazonagentregistry.html)。如需完整許可，您可以使用 [AgentRegistryFullAccess](https://docs.aws.amazon.com/aws-managed-policy/latest/reference/AgentRegistryFullAccess.html) 受管政策。

為了提高安全性和控制，您可以透過減少完整存取政策中的許可來建立自己的自訂政策。

**注意**  
在 `bedrock-agentcore` 命名空間中，`BedrockAgentCoreFullAccess`受管政策會涵蓋下列動作。在 `agent-registry` 命名空間中，新`AgentRegistryFullAccess`受管政策會涵蓋這些政策。下表顯示遷移時段期間的兩個命名空間。如需完整的遷移映射，請參閱[綜合登錄遷移指南](registry-faq.md)。

## 登錄控制平面動作
<a name="registry-iam-control-plane"></a>

**Example**  


| Action | 說明 | 存取層級 | 
| --- | --- | --- | 
|  `agent-registry:CreateRegistry`  | 准許建立登錄檔 | 寫入 | 
|  `agent-registry:GetRegistry`  | 准許取得登錄檔 | 讀取 | 
|  `agent-registry:UpdateRegistry`  | 准許更新登錄檔 | 寫入 | 
|  `agent-registry:DeleteRegistry`  | 准許刪除登錄檔 | 寫入 | 
|  `agent-registry:ListRegistries`  | 准許列出登錄檔 | 清單 | 


| Action | 說明 | 存取層級 | 
| --- | --- | --- | 
|  `bedrock-agentcore:CreateRegistry`  | 准許建立登錄檔 | 寫入 | 
|  `bedrock-agentcore:GetRegistry`  | 准許取得登錄檔 | 讀取 | 
|  `bedrock-agentcore:UpdateRegistry`  | 准許更新登錄檔 | 寫入 | 
|  `bedrock-agentcore:DeleteRegistry`  | 准許刪除登錄檔 | 寫入 | 
|  `bedrock-agentcore:ListRegistries`  | 准許列出登錄檔 | 清單 | 

## 登錄檔記錄控制平面動作
<a name="registry-iam-record-control-plane"></a>

**Example**  


| Action | 說明 | 存取層級 | 
| --- | --- | --- | 
|  `agent-registry:CreateRegistryRecord`  | 准許建立登錄檔記錄 | 寫入 | 
|  `agent-registry:GetRegistryRecord`  | 准許取得登錄檔記錄 | 讀取 | 
|  `agent-registry:UpdateRegistryRecord`  | 准許更新登錄檔記錄 | 寫入 | 
|  `agent-registry:DeleteRegistryRecord`  | 准許刪除登錄檔記錄 | 寫入 | 
|  `agent-registry:ListRegistryRecords`  | 准許列出登錄檔記錄 | 清單 | 
|  `agent-registry:SubmitRegistryRecordForApproval`  | 准許提交登錄檔記錄以供核准 | 寫入 | 
|  `agent-registry:UpdateRegistryRecordStatus`  | 准許核准、拒絕或棄用登錄檔記錄 | 寫入 | 


| Action | 說明 | 存取層級 | 
| --- | --- | --- | 
|  `bedrock-agentcore:CreateRegistryRecord`  | 准許建立登錄檔記錄 | 寫入 | 
|  `bedrock-agentcore:GetRegistryRecord`  | 准許取得登錄檔記錄 | 讀取 | 
|  `bedrock-agentcore:UpdateRegistryRecord`  | 准許更新登錄檔記錄 | 寫入 | 
|  `bedrock-agentcore:DeleteRegistryRecord`  | 准許刪除登錄檔記錄 | 寫入 | 
|  `bedrock-agentcore:ListRegistryRecords`  | 准許列出登錄檔記錄 | 清單 | 
|  `bedrock-agentcore:SubmitRegistryRecordForApproval`  | 准許提交登錄檔記錄以供核准 | 寫入 | 
|  `bedrock-agentcore:UpdateRegistryRecordStatus`  | 准許核准、拒絕或棄用登錄檔記錄 | 寫入 | 

## 登錄檔資料平面動作
<a name="registry-iam-data-plane"></a>

**Example**  


| Action | 說明 | 存取層級 | 
| --- | --- | --- | 
|  `agent-registry:SearchDiscoverableRegistryRecords`  | 准許搜尋核准的登錄檔記錄 | 讀取 | 
|  `agent-registry:ListDiscoverableRegistryRecords`  | 准許列出核准的登錄檔記錄 | 清單 | 
|  `agent-registry:GetDiscoverableRegistryRecord`  | 准許擷取核准的登錄檔記錄。也授權 `BatchGetDiscoverableRegistryRecord`。 | 讀取 | 
|  `agent-registry:InvokeRegistryMcp`  | 准許叫用登錄檔 MCP 端點 | 讀取 | 


| Action | 說明 | 存取層級 | 
| --- | --- | --- | 
|  `bedrock-agentcore:SearchRegistryRecords`  | 准許搜尋登錄檔記錄 | 讀取 | 
|  `bedrock-agentcore:InvokeRegistryMcp`  | 准許叫用登錄檔 MCP 端點 | 讀取 | 

**注意**  
若要叫用登錄檔 MCP 端點，您需要同時執行搜尋動作和 `InvokeRegistryMcp`動作。在`agent-registry`命名空間中，搜尋動作為 `agent-registry:SearchDiscoverableRegistryRecords`；在`bedrock-agentcore`命名空間中則為 `bedrock-agentcore:SearchRegistryRecords`。

**注意**  
 `BatchGetDiscoverableRegistryRecord` 沒有自己的 IAM 動作。每個請求的記錄都會針對 進行授權`agent-registry:GetDiscoverableRegistryRecord`。授予 `GetDiscoverableRegistryRecord` 以使用 `BatchGetDiscoverableRegistryRecord`。

## 工作負載身分動作 （登錄生命週期需要）
<a name="registry-iam-workload-identity"></a>

登錄受管工作負載身分操作需要下列動作。這些動作會使用 `bedrock-agentcore` 命名空間，並在 `CreateRegistry`和 `DeleteRegistry`工作流程期間由 服務代您呼叫。


| Action | 說明 | 存取層級 | 
| --- | --- | --- | 
|  `bedrock-agentcore:CreateWorkloadIdentity`  | 准許為登錄檔建立工作負載身分 | 寫入 | 
|  `bedrock-agentcore:GetWorkloadIdentity`  | 准許擷取工作負載身分詳細資訊 （用於重試時的冪等性） | 讀取 | 
|  `bedrock-agentcore:DeleteWorkloadIdentity`  | 准許在刪除登錄檔時刪除工作負載身分 | 寫入 | 

**注意**  
需要 `GetWorkloadIdentity`許可才能支援`CreateRegistry`工作流程的等冪重試。如果沒有此許可，如果重試登錄檔建立 （例如，暫時性失敗之後），工作流程無法驗證現有的工作負載身分，且 將會失敗。

## IAM 服務連結角色動作 （登錄生命週期需要）
<a name="registry-iam-create-service-linked-role"></a>

在登錄生命週期管理期間，需要下列動作。此動作會使用 `iam` 命名空間，並在`CreateRegistry`工作流程期間由 服務代您呼叫。


| Action | 說明 | 存取層級 | 
| --- | --- | --- | 
|  `iam:CreateServiceLinkedRole`  | 准許為 AWS 代理程式登錄檔建立服務連結角色 | 寫入 | 

**注意**  
在建立登錄檔期間需要 `CreateServiceLinkedRole`許可，才能讓服務在建立登錄檔之後，在您的帳戶中發佈 CloudWatch 指標。如果沒有此許可，註冊表建立將會失敗。

## 登錄檔資源類型
<a name="registry-iam-resource-types"></a>

 AWS 代理程式登錄檔會定義下列資源類型：

**Example**  


| Resource Type (資源類型) | ARN 格式 | 
| --- | --- | 
| 登錄檔 |  `arn:aws:agent-registry:{region}:{account}:registry/{registryId}`  | 
| 登錄檔記錄 |  `arn:aws:agent-registry:{region}:{account}:registry/{registryId}/record/{recordId}`  | 


| Resource Type (資源類型) | ARN 格式 | 
| --- | --- | 
| 登錄檔 |  `arn:aws:bedrock-agentcore:{region}:{account}:registry/{registryId}`  | 
| 登錄檔記錄 |  `arn:aws:bedrock-agentcore:{region}:{account}:registry/{registryId}/record/{recordId}`  | 