import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages an AWS Bedrock AgentCore Agent Runtime. Agent Runtime provides a containerized execution environment for AI agents. * * ## Example Usage * * ### Basic Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const assumeRole = aws.iam.getPolicyDocument({ * statements: [{ * principals: [{ * type: "Service", * identifiers: ["bedrock-agentcore.amazonaws.com"], * }], * effect: "Allow", * actions: ["sts:AssumeRole"], * }], * }); * const ecrPermissions = aws.iam.getPolicyDocument({ * statements: [ * { * actions: ["ecr:GetAuthorizationToken"], * effect: "Allow", * resources: ["*"], * }, * { * actions: [ * "ecr:BatchGetImage", * "ecr:GetDownloadUrlForLayer", * ], * effect: "Allow", * resources: [exampleAwsEcrRepository.arn], * }, * ], * }); * const example = new aws.iam.Role("example", { * name: "bedrock-agentcore-runtime-role", * assumeRolePolicy: assumeRole.then(assumeRole => assumeRole.json), * }); * const exampleRolePolicy = new aws.iam.RolePolicy("example", { * role: example.id, * policy: ecrPermissions.then(ecrPermissions => ecrPermissions.json), * }); * const exampleAgentcoreAgentRuntime = new aws.bedrock.AgentcoreAgentRuntime("example", { * agentRuntimeArtifact: { * containerConfiguration: { * containerUri: `${exampleAwsEcrRepository.repositoryUrl}:latest`, * }, * }, * networkConfiguration: { * networkMode: "PUBLIC", * }, * agentRuntimeName: "example_agent_runtime", * roleArn: example.arn, * }); * ``` * * ### MCP Server With Custom JWT Authorizer * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.bedrock.AgentcoreAgentRuntime("example", { * agentRuntimeArtifact: { * containerConfiguration: { * containerUri: `${exampleAwsEcrRepository.repositoryUrl}:v1.0`, * }, * }, * authorizerConfiguration: { * customJwtAuthorizer: { * discoveryUrl: "https://accounts.google.com/.well-known/openid-configuration", * allowedAudiences: [ * "my-app", * "mobile-app", * ], * allowedClients: [ * "client-123", * "client-456", * ], * allowedScopes: [ * "openid", * "email", * ], * }, * }, * networkConfiguration: { * networkMode: "PUBLIC", * }, * protocolConfiguration: { * serverProtocol: "MCP", * }, * agentRuntimeName: "example_agent_runtime", * description: "Agent runtime with JWT authorization", * roleArn: exampleAwsIamRole.arn, * environmentVariables: { * LOG_LEVEL: "INFO", * ENV: "production", * }, * }); * ``` * * ### AG-UI Server * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.bedrock.AgentcoreAgentRuntime("example", { * agentRuntimeArtifact: { * containerConfiguration: { * containerUri: `${exampleAwsEcrRepository.repositoryUrl}:latest`, * }, * }, * networkConfiguration: { * networkMode: "PUBLIC", * }, * protocolConfiguration: { * serverProtocol: "AGUI", * }, * agentRuntimeName: "example_agui_runtime", * description: "Agent runtime with AG-UI protocol", * roleArn: exampleAwsIamRole.arn, * }); * ``` * * ### Agent runtime artifact from S3 with Code Configuration * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.bedrock.AgentcoreAgentRuntime("example", { * agentRuntimeArtifact: { * codeConfiguration: { * code: { * s3: { * bucket: "example-bucket", * prefix: "example-agent-runtime-code.zip", * }, * }, * entryPoints: ["main.py"], * runtime: "PYTHON_3_13", * }, * }, * networkConfiguration: { * networkMode: "PUBLIC", * }, * agentRuntimeName: "example_agent_runtime", * roleArn: exampleAwsIamRole.arn, * }); * ``` * * ## Import * * Using `pulumi import`, import Bedrock AgentCore Agent Runtime using `agentRuntimeId`. For example: * * ```sh * $ pulumi import aws:bedrock/agentcoreAgentRuntime:AgentcoreAgentRuntime example agent-runtime-12345 * ``` */ export declare class AgentcoreAgentRuntime extends pulumi.CustomResource { /** * Get an existing AgentcoreAgentRuntime resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: AgentcoreAgentRuntimeState, opts?: pulumi.CustomResourceOptions): AgentcoreAgentRuntime; /** * Returns true if the given object is an instance of AgentcoreAgentRuntime. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is AgentcoreAgentRuntime; /** * ARN of the Agent Runtime. */ readonly agentRuntimeArn: pulumi.Output; /** * Container artifact configuration. See `agentRuntimeArtifact` below. */ readonly agentRuntimeArtifact: pulumi.Output; /** * Unique identifier of the Agent Runtime. */ readonly agentRuntimeId: pulumi.Output; /** * Name of the agent runtime. */ readonly agentRuntimeName: pulumi.Output; /** * Version of the Agent Runtime. */ readonly agentRuntimeVersion: pulumi.Output; /** * Authorization configuration for authenticating incoming requests. See `authorizerConfiguration` below. */ readonly authorizerConfiguration: pulumi.Output; /** * Description of the agent runtime. */ readonly description: pulumi.Output; /** * Map of environment variables to pass to the container. */ readonly environmentVariables: pulumi.Output<{ [key: string]: string; } | undefined>; /** * List of filesystems to mount into the agent runtime. Up to 5 entries are supported. Each entry is one of session storage, Amazon S3 Files access point, or Amazon EFS access point. See `filesystemConfiguration` below. */ readonly filesystemConfigurations: pulumi.Output; /** * Runtime session and resource lifecycle configuration for the agent runtime. See `lifecycleConfiguration` below. */ readonly lifecycleConfigurations: pulumi.Output; /** * Network configuration for the agent runtime. See `networkConfiguration` below. */ readonly networkConfiguration: pulumi.Output; /** * Protocol configuration for the agent runtime. See `protocolConfiguration` below. */ readonly protocolConfiguration: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * Configuration for HTTP request headers that will be passed through to the runtime. See `requestHeaderConfiguration` below. */ readonly requestHeaderConfiguration: pulumi.Output; /** * ARN of the IAM role that the agent runtime assumes to access AWS services. * * The following arguments are optional: */ readonly roleArn: pulumi.Output; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ readonly tags: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ readonly tagsAll: pulumi.Output<{ [key: string]: string; }>; readonly timeouts: pulumi.Output; /** * Workload identity details for the agent runtime. See `workloadIdentityDetails` below. */ readonly workloadIdentityDetails: pulumi.Output; /** * Create a AgentcoreAgentRuntime resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: AgentcoreAgentRuntimeArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering AgentcoreAgentRuntime resources. */ export interface AgentcoreAgentRuntimeState { /** * ARN of the Agent Runtime. */ agentRuntimeArn?: pulumi.Input; /** * Container artifact configuration. See `agentRuntimeArtifact` below. */ agentRuntimeArtifact?: pulumi.Input; /** * Unique identifier of the Agent Runtime. */ agentRuntimeId?: pulumi.Input; /** * Name of the agent runtime. */ agentRuntimeName?: pulumi.Input; /** * Version of the Agent Runtime. */ agentRuntimeVersion?: pulumi.Input; /** * Authorization configuration for authenticating incoming requests. See `authorizerConfiguration` below. */ authorizerConfiguration?: pulumi.Input; /** * Description of the agent runtime. */ description?: pulumi.Input; /** * Map of environment variables to pass to the container. */ environmentVariables?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * List of filesystems to mount into the agent runtime. Up to 5 entries are supported. Each entry is one of session storage, Amazon S3 Files access point, or Amazon EFS access point. See `filesystemConfiguration` below. */ filesystemConfigurations?: pulumi.Input[] | undefined>; /** * Runtime session and resource lifecycle configuration for the agent runtime. See `lifecycleConfiguration` below. */ lifecycleConfigurations?: pulumi.Input[] | undefined>; /** * Network configuration for the agent runtime. See `networkConfiguration` below. */ networkConfiguration?: pulumi.Input; /** * Protocol configuration for the agent runtime. See `protocolConfiguration` below. */ protocolConfiguration?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Configuration for HTTP request headers that will be passed through to the runtime. See `requestHeaderConfiguration` below. */ requestHeaderConfiguration?: pulumi.Input; /** * ARN of the IAM role that the agent runtime assumes to access AWS services. * * The following arguments are optional: */ roleArn?: pulumi.Input; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; /** * Workload identity details for the agent runtime. See `workloadIdentityDetails` below. */ workloadIdentityDetails?: pulumi.Input[] | undefined>; } /** * The set of arguments for constructing a AgentcoreAgentRuntime resource. */ export interface AgentcoreAgentRuntimeArgs { /** * Container artifact configuration. See `agentRuntimeArtifact` below. */ agentRuntimeArtifact: pulumi.Input; /** * Name of the agent runtime. */ agentRuntimeName: pulumi.Input; /** * Authorization configuration for authenticating incoming requests. See `authorizerConfiguration` below. */ authorizerConfiguration?: pulumi.Input; /** * Description of the agent runtime. */ description?: pulumi.Input; /** * Map of environment variables to pass to the container. */ environmentVariables?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * List of filesystems to mount into the agent runtime. Up to 5 entries are supported. Each entry is one of session storage, Amazon S3 Files access point, or Amazon EFS access point. See `filesystemConfiguration` below. */ filesystemConfigurations?: pulumi.Input[] | undefined>; /** * Runtime session and resource lifecycle configuration for the agent runtime. See `lifecycleConfiguration` below. */ lifecycleConfigurations?: pulumi.Input[] | undefined>; /** * Network configuration for the agent runtime. See `networkConfiguration` below. */ networkConfiguration: pulumi.Input; /** * Protocol configuration for the agent runtime. See `protocolConfiguration` below. */ protocolConfiguration?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Configuration for HTTP request headers that will be passed through to the runtime. See `requestHeaderConfiguration` below. */ requestHeaderConfiguration?: pulumi.Input; /** * ARN of the IAM role that the agent runtime assumes to access AWS services. * * The following arguments are optional: */ roleArn: pulumi.Input; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } //# sourceMappingURL=agentcoreAgentRuntime.d.ts.map