Optional ReadonlyagentAgentCore Gateway - the gateway's MCP host, a distinct service from the AgentCore data plane. Needed
only by a consumer declaring an agentCoreGateway tool; without it the tool load fails with a DNS
"Name or service not known" error.
Validation: Optional; VpcEndpointProps; only valid when a referencing consumer declares a gateway tool; omit to have it created
Optional ReadonlybedrockAmazon Bedrock runtime, for model inference over the Converse API. Every AgentCore Harness needs it; without a path it reaches READY and every invoke hangs.
Validation: Optional; VpcEndpointProps; omit to have it created
Optional ReadonlyecrAmazon ECR API, for the registry calls a session's container image pull makes.
Validation: Optional; VpcEndpointProps; omit to have it created
Optional ReadonlyecrAmazon ECR Docker Registry, for the registry protocol of the image pull.
Validation: Optional; VpcEndpointProps; omit to have it created
Optional ReadonlylogsAmazon CloudWatch Logs, for log delivery from a session.
Validation: Optional; VpcEndpointProps; omit to have it created
Optional ReadonlyrouteRoute tables that receive the S3 gateway endpoint's prefix-list route, enabling container image-layer downloads: image layers are served from the ECR layer bucket over S3, so the ECR interface endpoints alone cannot complete a pull in a VPC with no NAT.
IMPORTANT - blast radius: the endpoint intercepts all S3 traffic from every subnet associated
with these route tables, and its derived policy allows only the ECR image-layer read. If other
workloads share these route tables and need broader S3 access, provision the S3 gateway endpoint out
of band and set s3ImageLayers.external instead.
Use cases: no-NAT container image-layer pulls
AWS: RouteTableIds
Validation: Required unless s3ImageLayers.external is set, and mutually exclusive with it; String[]
Optional Readonlys3Amazon S3, reached through a gateway endpoint, for container image layers. Created from the set's
routeTableIds; set external here when S3 is already reachable.
Validation: Optional; S3ImageLayerEndpointProps
Optional ReadonlystsAWS STS, for credential vending inside a session.
Validation: Optional; VpcEndpointProps; omit to have it created
ReadonlysubnetSubnets for the ENIs of every interface endpoint created by this set, unless an endpoint overrides it. An interface endpoint takes at most one subnet per availability zone, and is reachable from any zone - so covering fewer zones costs less in endpoint ENI hours and more in cross-zone data.
Use cases: multi-AZ endpoint placement, endpoint ENI cost control
AWS: SubnetIds
Validation: Required; String[]; at least one, at most one per availability zone
ReadonlyvpcVPC the endpoints are created in, and in which each referencing consumer's endpoint client security group is created.
Use cases: private workload connectivity in a specific VPC
AWS: VpcId
Validation: Required; String; each set must name a distinct VPC
One VPC's endpoint set: which VPC it serves, where created endpoints go, and how each endpoint the referencing consumers need is provided. A consumer references a set by name from its own configuration, and the endpoints belong to the VPC rather than to any one consumer - AWS allows a single Private DNS interface endpoint per service per VPC, so one set owns them and every consumer referencing it shares them.
Which endpoints exist is derived from the consumers, never added here: a set can only say how each derived endpoint is reached. Omitting an endpoint property means it is created; see VpcEndpointProps for the other two states.
Endpoint policies are derived too, and are not configurable: the AgentCore Gateway endpoint is scoped to gateway invocation and the S3 gateway endpoint to the ECR image-layer bucket, while the multi-action supporting services keep the AWS default - Private DNS makes an interface endpoint VPC-wide, so restricting those would deny unrelated workloads in the same VPC. That default permits every action on those services in any account, so a set is a private network path and not an authorization boundary: what a session may reach through it stays governed by its execution role.
Use cases: private (no-NAT) AgentCore Harness sessions, reusing centrally provisioned endpoints, keeping selected services on the VPC's existing egress path
Validation:
vpcIdandsubnetIdsrequired; exactly one ofrouteTableIdsands3ImageLayers.external; each set must name a distinct VPC and be referenced by at least one consumer