AWS cli high security documentation change
Summary
Added documentation for 'allowedWorkloadConfiguration' structure under authorizerConfiguration, defining restrictions for workloads allowed to invoke targets.
Security assessment
The change introduces explicit security controls restricting which workloads (hosting environments and identities) can invoke targets. This implements workload-based access controls (minimum length requirements, pattern validation) to prevent unauthorized access, directly addressing authorization security concerns.
Diff
diff --git a/cli/latest/reference/bedrock-agentcore-control/get-agent-runtime.md b/cli/latest/reference/bedrock-agentcore-control/get-agent-runtime.md index 90be15534..8f17af9de 100644 --- a//cli/latest/reference/bedrock-agentcore-control/get-agent-runtime.md +++ b//cli/latest/reference/bedrock-agentcore-control/get-agent-runtime.md @@ -15 +15 @@ - * [AWS CLI 2.35.5 Command Reference](../../index.html) » + * [AWS CLI 2.35.8 Command Reference](../../index.html) » @@ -1026,0 +1027,51 @@ authorizerConfiguration -> (tagged union structure) +>> +>> allowedWorkloadConfiguration -> (structure) +>> +>>> The configuration that restricts which workloads in the request’s identity chain are allowed to invoke the target, identified by their hosting environments and workload identities. At launch, this is supported only for AgentCore Runtime targets, and the allowed workloads are AgentCore Gateways. +>>> +>>> hostingEnvironments -> (list) +>>> +>>>> The list of hosting environments whose workloads are allowed to invoke the target. At launch, the only supported hosting environment is AgentCore Gateway. +>>>> +>>>> Constraints: +>>>> +>>>> * min: `1` +>>>> * max: `10` +>>>> + +>>>> +>>>> (structure) +>>>> +>>>>> A hosting environment whose workloads are allowed to invoke the target. At launch, the only supported hosting environment is AgentCore Gateway. +>>>>> +>>>>> arn -> (string) [required] +>>>>> +>>>>>> The Amazon Resource Name (ARN) of the hosting environment. +>>>>>> +>>>>>> Constraints: +>>>>>> +>>>>>> * min: `20` +>>>>>> * max: `1011` +>>>>>> + +>>> +>>> workloadIdentities -> (list) +>>> +>>>> The list of workload identities that are allowed to invoke the target. +>>>> +>>>> Constraints: +>>>> +>>>> * min: `1` +>>>> * max: `10` +>>>> + +>>>> +>>>> (string) +>>>> +>>>>> Constraints: +>>>>> +>>>>> * min: `3` +>>>>> * max: `255` +>>>>> * pattern: `[A-Za-z0-9_.-]+` +>>>>> + @@ -1166 +1217 @@ filesystemConfigurations -> (list) - * [AWS CLI 2.35.5 Command Reference](../../index.html) » + * [AWS CLI 2.35.8 Command Reference](../../index.html) »