Skip to content

Optional AgentCore Gateway interface endpoint for runtime → gateway traffic - #45

Merged
odinwang merged 1 commit into
mainfrom
feat/agentcore-gateway-vpce
Oct 1, 2026
Merged

odinwang merged 1 commit into
mainfrom
feat/agentcore-gateway-vpce

Conversation

@odinwang

@odinwang odinwang commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Runtimes run in VPC mode, but every call they make to an AgentCore Gateway (MCP tool gateways today, the agentcore_gateway model backend in #40) leaves through the NAT Gateway and reaches the gateway's public endpoint. This adds an opt-in interface VPC endpoint so that traffic stays inside the VPC.

  • enable_gateway_vpce (default false) creates a com.amazonaws.<region>.bedrock-agentcore.gateway interface endpoint in the platform's private subnets with private DNS on: *.gateway.bedrock-agentcore.<region>.amazonaws.com resolves to the endpoint ENIs, so no gateway URL changes anywhere.
  • Endpoint policy: bedrock-agentcore:InvokeGateway on arn:aws:bedrock-agentcore:<region>:<account>:gateway/* only. Principal is * because a gateway with a CUSTOM_JWT authorizer cannot be matched on an IAM principal in an endpoint policy (AgentCore docs, PrivateLink page).
  • Security group: 443 from the VPC CIDR.
  • Documented in docs/architecture.md §3 and terraform/terraform.tfvars.example.

Test plan

  • terraform validate; targeted plan shows exactly 2 to add, 0 to change, 0 to destroy
  • Applied in a live deployment (ap-northeast-1). From an instance in the platform's private subnets, both existing gateways' hostnames resolve to the endpoint's private IPs; an unauthenticated MCP call to the JWT-authorized gateway returns 401 via the endpoint IP (authorizer still enforced)

🤖 Generated with Claude Code

Runtimes in VPC mode reached every AgentCore Gateway (MCP tool gateways,
and the agentcore_gateway model backend) through the NAT. With
enable_gateway_vpce the platform VPC gets a
com.amazonaws.<region>.bedrock-agentcore.gateway interface endpoint with
private DNS, so *.gateway.bedrock-agentcore.<region> resolves to endpoint
ENIs and those calls stay inside the VPC with no URL change.

The endpoint policy allows only InvokeGateway on this account's gateways.
Principal stays "*": gateways with a CUSTOM_JWT authorizer cannot be
matched on an IAM principal in an endpoint policy. The security group
admits 443 from the VPC CIDR only. Off by default.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@odinwang
odinwang merged commit ca3a540 into main Oct 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant