AWS cli high security documentation change
Summary
Added 'allowedWorkloadConfiguration' parameter to define restrictions on which workloads can invoke AgentCore Runtime targets
Security assessment
The change introduces explicit access controls restricting invocations to specific hosting environments (AgentCore Gateways) and authorized workload identities. This directly addresses security by implementing workload-level authorization, preventing unauthorized access to AgentCore Runtime targets.
Diff
diff --git a/cli/latest/reference/bedrock-agentcore-control/update-agent-runtime.md b/cli/latest/reference/bedrock-agentcore-control/update-agent-runtime.md index 969e88e3f..6c7df5740 100644 --- a//cli/latest/reference/bedrock-agentcore-control/update-agent-runtime.md +++ b//cli/latest/reference/bedrock-agentcore-control/update-agent-runtime.md @@ -15 +15 @@ - * [AWS CLI 2.35.5 Command Reference](../../index.html) » + * [AWS CLI 2.35.8 Command Reference](../../index.html) » @@ -796,0 +797,51 @@ JSON Syntax: +>> +>> allowedWorkloadConfiguration -> (structure) +>> +>>> The configuration that restricts which workloads in the request’s identity chain are allowed to invoke the target, identified by their hosting environments and workload identities. At launch, this is supported only for AgentCore Runtime targets, and the allowed workloads are AgentCore Gateways. +>>> +>>> hostingEnvironments -> (list) +>>> +>>>> The list of hosting environments whose workloads are allowed to invoke the target. At launch, the only supported hosting environment is AgentCore Gateway. +>>>> +>>>> Constraints: +>>>> +>>>> * min: `1` +>>>> * max: `10` +>>>> + +>>>> +>>>> (structure) +>>>> +>>>>> A hosting environment whose workloads are allowed to invoke the target. At launch, the only supported hosting environment is AgentCore Gateway. +>>>>> +>>>>> arn -> (string) [required] +>>>>> +>>>>>> The Amazon Resource Name (ARN) of the hosting environment. +>>>>>> +>>>>>> Constraints: +>>>>>> +>>>>>> * min: `20` +>>>>>> * max: `1011` +>>>>>> + +>>> +>>> workloadIdentities -> (list) +>>> +>>>> The list of workload identities that are allowed to invoke the target. +>>>> +>>>> Constraints: +>>>> +>>>> * min: `1` +>>>> * max: `10` +>>>> + +>>>> +>>>> (string) +>>>> +>>>>> Constraints: +>>>>> +>>>>> * min: `3` +>>>>> * max: `255` +>>>>> * pattern: `[A-Za-z0-9_.-]+` +>>>>> + @@ -854 +905,10 @@ JSON Syntax: - ] + ], + "allowedWorkloadConfiguration": { + "hostingEnvironments": [ + { + "arn": "string" + } + ... + ], + "workloadIdentities": ["string", ...] + } @@ -1361 +1421 @@ status -> (string) - * [AWS CLI 2.35.5 Command Reference](../../index.html) » + * [AWS CLI 2.35.8 Command Reference](../../index.html) »