Optional ReadonlyallowedTool allowlist controlling which tools (including the built-in shell / file_operations) the
agent may select during invocation. Supports the AgentCore allowedTools patterns (*, plain
names, @builtin, @server/tool, globs). Omit to allow all tools.
Note: allowedTools scopes LLM tool selection during InvokeHarness only - it does not gate
the separate InvokeAgentRuntimeCommand API (which executes commands directly, without the
LLM). To prevent direct command execution, do not grant bedrock-agentcore:InvokeAgentRuntimeCommand.
Use cases: restricting the default shell/file_operations tools, reducing tool-definition
token overhead
AWS: AllowedTools
Validation: Optional; String[]; 1-64 entries
Optional ReadonlyauthorizerInbound authorization configuration. Provide customJwt for JWT/OIDC inbound auth, or omit it
to use AWS IAM (SigV4) - the Harness's no-configuration fallback.
Use cases: inbound access control
AWS: AuthorizerConfiguration
Validation: Optional; valid customJwt when present
Optional ReadonlycontainerBring-your-own container image for the harness's underlying runtime environment (pre-built ECR image URI). Omit to use the AWS-managed harness container.
Use cases: custom runtime image
AWS: EnvironmentArtifact.ContainerConfiguration
Validation: Optional; HarnessContainerProperty
Optional ReadonlydataCloudWatch Data Protection configuration for the Harness's service-created log groups. PII masking and CMK encryption are always-on and cannot be disabled; this only tightens the posture by adding identifiers on top of the built-in floor.
Use cases: extending PII masking with additional identifiers
AWS: CloudWatch Logs Data Protection Policy
Validation: Optional; DataProtectionProperty; additive only
Optional ReadonlyendpointNamed, versioned invocation endpoint for the harness. Omit to invoke the harness's default (latest) version directly.
Use cases: pinning callers to a specific harness version, blue/green endpoint management
AWS: AWS::BedrockAgentCore::HarnessEndpoint
Validation: Optional; HarnessEndpointProperty
Optional ReadonlyenvironmentKey-value environment variables passed to the harness runtime environment.
Use cases: runtime configuration, environment customization
AWS: EnvironmentVariables
Validation: Optional; Record<string, string>
Optional ReadonlyguardrailGuardrail association for content filtering on the Harness's model calls. Rendered via a CDK property-override escape hatch (the pinned CDK L1 lags the CloudFormation spec for this field); see the class-level documentation.
Use cases: responsible-AI content filtering, safety controls
AWS: Model.BedrockModelConfig.AdditionalParams.guardrailConfig (escape hatch)
Validation: Optional; HarnessGuardrailAssociation
Optional ReadonlylifecycleIdle-session and runtime lifecycle settings for the underlying AgentCore Runtime environment.
Use cases: cost control, session cleanup
AWS: Environment.AgentCoreRuntimeEnvironment.LifecycleConfiguration
Validation: Optional; HarnessLifecycleProperty
Optional ReadonlylogCloudWatch Logs retention period for the Harness's service-created log groups, in days. Accepts
any CloudWatch Logs RetentionDays value; 9999 (RetentionDays.INFINITE) means never-expire
and can be set explicitly to lock indefinite retention into config. Omitting the field is
equivalent to 9999 - no retention policy is applied, leaving the log groups at CloudWatch's
never-expire default (logs are kept, and billed, forever) unless a finite value is set.
Use cases: log retention policy, cost management
AWS: CloudWatch Logs log group retention
Validation: Optional; Number; must be a valid RetentionDays value (9999 for never-expire) - validated at synth
Optional ReadonlymaxMaximum number of iterations the agent loop can execute per invocation.
Use cases: bounding tool-call loops, cost control
AWS: MaxIterations
Validation: Optional; Integer >= 1
Optional ReadonlymaxGlobal maximum tokens the harness may generate across the whole agent-loop invocation (distinct
from modelConfig.maxTokens, which bounds a single model call). A hard cost cap on total
generation per invocation.
Use cases: cost control, bounding total generation per invocation
AWS: MaxTokens
Validation: Optional; Number; >= 1
Optional ReadonlymodelModel sampling configuration (temperature, top-p, max tokens). Mirrors the CFN
HarnessBedrockModelConfig sampling fields.
Use cases: tuning response determinism, diversity, and length limits
AWS: Model.BedrockModelConfig
Validation: Optional; HarnessModelConfigProperty
ReadonlymodelFoundation model identifier for the agent loop. Accepts an on-demand model id, a cross-region
(system) inference profile id, or a full foundation-model / system inference-profile ARN
(resolved via resolveModelArn). Application inference profile ARNs
(application-inference-profile/...) are rejected at synth: their underlying foundation model is
not derivable, so the paired invoke grant an inference profile requires cannot be scoped.
Use cases: selecting the reasoning model for the agent loop
AWS: Model.BedrockModelConfig.ModelId
Validation: Required; String; not an application-inference-profile ARN
ReadonlynetworkVPC network configuration for the harness's runtime sessions, placing them behind your own
security groups and subnets for private access to internal resources. Required: MDAA enforces
VPC network isolation for the harness (NetworkMode: VPC), mirroring the AgentCore Runtime
construct - there is no public-network option.
Use cases: private access to internal resources, network isolation
AWS: Environment.AgentCoreRuntimeEnvironment.NetworkConfiguration (NetworkMode: VPC)
Validation: Required; HarnessNetworkProperty; 1-16 security groups and subnets
Optional ReadonlyroleExisting IAM role reference for the Harness execution role. If omitted, MDAA creates a role
trusting bedrock-agentcore.amazonaws.com, scoped to this account/harness.
Use cases: role reuse, centralized permission management
AWS: ExecutionRoleArn
Validation: Optional; MdaaRoleRef
Optional ReadonlyskillsSkills injected into the agent's context: filesystem paths to skill definitions baked into the
runtime image. Only the path skill source is exposed (the CDK L1 types only path); git / S3 /
awsSkills sources documented in the CloudFormation HarnessSkill schema are not yet supported.
Use cases: injecting curated instruction/script bundles into the agent
AWS: Skills
Validation: Optional; HarnessSkillProperty[]; each path non-empty
ReadonlysystemSystem prompt defining the agent's behavior and instructions.
Use cases: agent persona, task instructions, behavioral constraints
AWS: SystemPrompt (one text block)
Validation: Required; String
Optional ReadonlytimeoutMaximum duration in seconds for the agent loop execution per invocation.
Use cases: bounding total invocation latency
AWS: TimeoutSeconds
Validation: Optional; Integer >= 1
Optional ReadonlytoolsTools available to the agent loop, keyed by tool name. The key becomes HarnessTool.Name and is
what allowedTools entries refer to.
Use cases: giving the agent callable tools (client-executed or gateway-fronted)
AWS: Tools
Validation: Optional; NamedHarnessToolProps (map of tool name to config)
Optional ReadonlytruncationContext-truncation configuration controlling how the agent loop trims conversation context when it exceeds the model's context window. Omit to accept the service default.
Use cases: bounding long agent loops within the model context window
AWS: Truncation
Validation: Optional; HarnessTruncationProperty; tuning fields must match the selected strategy
Complete configuration for a Bedrock AgentCore Harness - a declarative agent loop (model + system prompt + tools).
Use cases: conversational AI agents, tool-using agents, RAG agents (via gateway tools)
AWS:
AWS::BedrockAgentCore::HarnessValidation: modelId, systemPrompt and networkConfiguration are required