本文為英文版的機器翻譯版本,如內容有任何歧義或不一致之處,概以英文版為準。
使用介面 VPC 端點 (AWS PrivateLink) 在 VPC 和 Amazon Bedrock AgentCore 資源之間建立私有連線
您可以使用 AWS PrivateLink 在 VPC 和 Amazon Bedrock AgentCore 之間建立私有連線。您可以像在 VPC 中一樣存取 AgentCore,無需使用網際網路閘道、NAT 裝置、VPN 連接或 Direct Connect 連接。VPC 中的執行個體不需要公有 IP 地址即可存取 AgentCore。
您可以透過建立由 AWS PrivateLink 提供支援的介面端點 來建立此私有連線。我們會在您為介面端點啟用的每個子網中建立端點網路介面。這些是請求者管理的網路介面,可做為目的地為 AgentCore 之流量的進入點。
如需詳細資訊,請參閱《 AWS PrivateLink 指南》中的透過 PrivateLink 存取 AWS 服務。 AWS PrivateLink
AgentCore 的考量事項
在您設定 AgentCore 的介面端點之前,請檢閱 AWS PrivateLink 指南中的考量事項。
AgentCore 提供三個 AWS PrivateLink 端點:
-
資料平面端點 - com.amazonaws.region.bedrock-agentcore
-
控制平面端點 - com.amazonaws.region.bedrock-agentcore-control
-
閘道端點 - com.amazonaws.region.bedrock-agentcore.gateway
下表顯示每個 AgentCore 基本的 AWS PrivateLink 支援狀態:
| 基本 |
資料平面 |
控制平面 |
|
執行時期
|
支援
|
支援
|
|
記憶體
|
支援
|
支援
|
|
內建工具 (程式碼解譯器、瀏覽器工具)
|
支援
|
支援
|
|
Identity
|
支援
|
支援
|
|
閘道
|
支援
|
支援
|
|
評估和最佳化
|
支援
|
支援
|
|
政策
|
支援
|
支援
|
如需可使用 AgentCore 介面端點 AWS 的區域清單,請參閱支援 AWS 的區域。
資料平面 APIs 支援 AWS Signature 第 4 版 (SigV4) 標頭進行身分驗證和 Bearer Token (OAuth) 身分驗證。VPC 端點政策只能根據 IAM 主體而非 OAuth 使用者來限制發起人。若要讓以 OAuth 為基礎的請求透過 VPC 端點成功,委託人必須在端點政策中設定為 *。否則,只有 SigV4 允許清單的呼叫者可以透過 VPC 端點成功呼叫。
AWS 支援 IAM 全域條件內容索引鍵。根據預設,允許透過界面端點完整存取 AgentCore。您可以將端點政策連接至介面端點,或建立安全群組與端點網路介面的關聯,以控制存取。
建立 AgentCore 的介面端點
您可以使用 Amazon VPC 主控台或 AWS 命令列界面 (AWS CLI) 來建立 AgentCore 的界面端點。如需詳細資訊,請參閱 AWS PrivateLink 指南中的建立介面端點。
使用下列服務名稱格式建立 AgentCore 的介面端點:
-
所有資料平面基本概念 (執行期、內建工具、記憶體、身分): com.amazonaws.region.bedrock-agentcore
-
針對 AgentCore Gateway: com.amazonaws.region.bedrock-agentcore.gateway
-
對於控制平面操作 (執行期和記憶體管理): com.amazonaws.region.bedrock-agentcore-control
如果您為介面端點啟用私有 DNS,您可以使用其預設的區域 DNS 名稱向 AgentCore 提出 API 請求。例如 bedrock-agentcore.us-east-1.amazonaws.com。對於 Gateway,具體而言,它看起來會像是:*.gateway.bedrock-agentcore.us-east-1.amazonaws.com。
為您的介面端點建立端點政策
端點政策為 IAM 資源,您可將其連接至介面端點。預設端點政策允許透過介面端點完整存取 AgentCore。若要控制允許從您的 VPC 存取 AgentCore,請將自訂端點政策連接至介面端點。
端點政策會指定以下資訊:
如需詳細資訊,請參閱《 AWS PrivateLink 指南》中的使用端點政策控制對 服務的存取。
各種基本概念的端點政策
下列範例顯示不同 AgentCore 元件的端點政策:
範例
- Runtime
-
-
下列端點政策允許特定 IAM 主體叫用代理程式執行期資源。
{
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:user/USERNAME"
},
"Action": [
"bedrock-agentcore:InvokeAgentRuntime"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:runtime/RUNTIME_ID"
}
]
}
混合 IAM 和 OAuth 身分驗證
InvokeAgentRuntime API 支援兩種 VPC 端點授權模式。下列範例政策允許 IAM 主體和 OAuth 發起人存取不同的客服人員執行期資源。
{
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:InvokeAgentRuntime"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:runtime/customAgent1"
},
{
"Effect": "Allow",
"Principal": "*",
"Action": [
"bedrock-agentcore:InvokeAgentRuntime"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:runtime/customAgent2"
}
]
}
上述政策僅允許 IAM 主體InvokeAgentRuntime呼叫 customAgent1 。它還允許 IAM 主體和 OAuth 發起人對 進行InvokeAgentRuntime呼叫customAgent2。
受保護的資源中繼資料 (PRM) 端點政策
GetRuntimeProtectedResourceMetadata API 實作 OAuth 2.0 受保護的資源中繼資料 (RFC 9728)。用戶端會在擁有登入資料之前呼叫此端點,以探索哪個授權伺服器可保護指定的代理程式執行時間。此端點透過設計未經驗證,因此Principal必須在端點政策中將 設定為 *。
VPC 端點政策會強制執行於 PRM 請求。如果您的端點政策未明確允許 bedrock-agentcore:GetRuntimeProtectedResourceMetadata ,則 HTTP 403 會拒絕透過該端點提出的 PRM 請求。任何透過 VPC 端點存取的 OAuth 設定代理程式執行期,都需要對 FTP 存取以進行授權伺服器探索。
如果您有資料周邊強制執行的拒絕所有端點政策,且未使用 OAuth 或 JWT 身分驗證,則會自動拒絕 PRM 請求。不需要額外的組態。
下列端點政策允許任何發起人探索授權伺服器 (PRM),同時將執行時間調用限制為特定 IAM 主體:
{
"Statement": [
{
"Sid": "AllowPRMDiscovery",
"Effect": "Allow",
"Principal": "*",
"Action": [
"bedrock-agentcore:GetRuntimeProtectedResourceMetadata"
],
"Resource": "arn:aws:bedrock-agentcore:REGION:ACCOUNT_ID:runtime/*"
},
{
"Sid": "AllowInvoke",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:InvokeAgentRuntime"
],
"Resource": "arn:aws:bedrock-agentcore:REGION:ACCOUNT_ID:runtime/RUNTIME_ID"
}
]
}
若要封鎖透過 VPC 端點 (資料周邊強制執行) 的跨帳戶 DHCP 查詢,請將 MOST 允許陳述式範圍限定為您帳戶的執行時間:
{
"Statement": [
{
"Sid": "AllowPRMOwnAccountOnly",
"Effect": "Allow",
"Principal": "*",
"Action": [
"bedrock-agentcore:GetRuntimeProtectedResourceMetadata"
],
"Resource": "arn:aws:bedrock-agentcore:REGION:ACCOUNT_ID:runtime/*"
},
{
"Sid": "DenyCrossAccountPRM",
"Effect": "Deny",
"Principal": "*",
"Action": [
"bedrock-agentcore:GetRuntimeProtectedResourceMetadata"
],
"NotResource": "arn:aws:bedrock-agentcore:REGION:ACCOUNT_ID:runtime/*"
},
{
"Sid": "AllowInvoke",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:InvokeAgentRuntime"
],
"Resource": "arn:aws:bedrock-agentcore:REGION:ACCOUNT_ID:runtime/*"
}
]
}
- Code Interpreter Tool
-
-
下列端點政策允許特定 IAM 主體叫用 Code Interpreter 資源。
{
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:InvokeCodeInterpreter"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:code-interpreter/CODE_INTERPRETER_ID"
}
]
}
- Memory
-
-
======= 所有資料平面操作
下列端點政策允許特定 IAM 主體存取特定 AgentCore 記憶體的 us-east-1 資料平面操作。
{
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:CreateEvent",
"bedrock-agentcore:DeleteEvent",
"bedrock-agentcore:GetEvent",
"bedrock-agentcore:ListEvents",
"bedrock-agentcore:DeleteMemoryRecord",
"bedrock-agentcore:GetMemoryRecord",
"bedrock-agentcore:ListMemoryRecords",
"bedrock-agentcore:RetrieveMemoryRecords",
"bedrock-agentcore:ListActors",
"bedrock-agentcore:ListSessions",
"bedrock-agentcore:BatchCreateMemoryRecords",
"bedrock-agentcore:BatchDeleteMemoryRecords",
"bedrock-agentcore:BatchUpdateMemoryRecords"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:memory/MEMORY_ID"
}
]
}
存取所有記憶體
下列端點政策允許特定 IAM 主體存取所有記憶體。
{
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:CreateEvent",
"bedrock-agentcore:DeleteEvent",
"bedrock-agentcore:GetEvent",
"bedrock-agentcore:ListEvents",
"bedrock-agentcore:DeleteMemoryRecord",
"bedrock-agentcore:GetMemoryRecord",
"bedrock-agentcore:ListMemoryRecords",
"bedrock-agentcore:RetrieveMemoryRecords",
"bedrock-agentcore:ListActors",
"bedrock-agentcore:ListSessions",
"bedrock-agentcore:BatchCreateMemoryRecords",
"bedrock-agentcore:BatchDeleteMemoryRecords",
"bedrock-agentcore:BatchUpdateMemoryRecords"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:memory/*"
}
]
}
APIs存取限制
下列端點政策授予特定 IAM 主體在特定 AgentCore 記憶體資源中建立事件的許可。
{
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:CreateEvent"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:memory/MEMORY_ID"
}
]
}
- Browser Tool
-
-
下列端點政策允許特定 IAM 主體連線到瀏覽器工具資源。
{
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:ConnectBrowserAutomationStream"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:browser/BROWSER_ID"
}
]
}
- Gateway
-
-
以下是自訂端點政策的範例。當您將此政策連接到介面端點時,它允許所有主體叫用 Resource 欄位中指定的閘道。
{
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": [
"bedrock-agentcore:InvokeGateway"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:gateway/my-gateway"
}
]
}
- Identity
-
-
下列端點政策允許存取 Identity 資源。
{
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": [
"*"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:workload-identity-directory/default/workload-identity/WORKLOAD_IDENTITY_ID"
}
]
}
- Evaluations and Optimizations
-
-
下列端點政策允許特定 IAM 主體存取評估和最佳化操作。
{
"Statement": [
{
"Sid": "AllowBatchEvaluations",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:StartBatchEvaluation",
"bedrock-agentcore:GetBatchEvaluation",
"bedrock-agentcore:ListBatchEvaluations",
"bedrock-agentcore:StopBatchEvaluation",
"bedrock-agentcore:DeleteBatchEvaluation"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:batch-evaluate/*"
},
{
"Sid": "AllowRecommendations",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:StartRecommendation",
"bedrock-agentcore:GetRecommendation",
"bedrock-agentcore:ListRecommendations",
"bedrock-agentcore:DeleteRecommendation"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:recommendation/*"
},
{
"Sid": "AllowEvaluators",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:CreateEvaluator",
"bedrock-agentcore:GetEvaluator",
"bedrock-agentcore:ListEvaluators",
"bedrock-agentcore:UpdateEvaluator",
"bedrock-agentcore:DeleteEvaluator"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:evaluator/*"
},
{
"Sid": "AllowOnlineEvaluationConfigs",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:CreateOnlineEvaluationConfig",
"bedrock-agentcore:GetOnlineEvaluationConfig",
"bedrock-agentcore:ListOnlineEvaluationConfigs",
"bedrock-agentcore:UpdateOnlineEvaluationConfig",
"bedrock-agentcore:DeleteOnlineEvaluationConfig"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:online-evaluation-config/*"
},
{
"Sid": "AllowABTests",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:CreateABTest",
"bedrock-agentcore:GetABTest",
"bedrock-agentcore:ListABTests",
"bedrock-agentcore:UpdateABTest",
"bedrock-agentcore:DeleteABTest"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:ab-test/*"
},
{
"Sid": "AllowConfigurationBundles",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_ID:root"
},
"Action": [
"bedrock-agentcore:CreateConfigurationBundle",
"bedrock-agentcore:GetConfigurationBundle",
"bedrock-agentcore:GetConfigurationBundleVersion",
"bedrock-agentcore:ListConfigurationBundles",
"bedrock-agentcore:ListConfigurationBundleVersions",
"bedrock-agentcore:UpdateConfigurationBundle",
"bedrock-agentcore:DeleteConfigurationBundle"
],
"Resource": "arn:aws:bedrock-agentcore:us-east-1:ACCOUNT_ID:configuration-bundle/*"
}
]
}