import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages an AWS Bedrock AgentCore Gateway Target. Gateway targets define the endpoints and configurations that a gateway can invoke, such as Lambda functions, APIs, or AgentCore Runtime agents, allowing agents to interact with external services through the Model Context Protocol (MCP) or by routing HTTP traffic directly to a runtime. * * ## Example Usage * * ### Lambda Target with Gateway IAM Role * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const gatewayAssume = aws.iam.getPolicyDocument({ * statements: [{ * principals: [{ * type: "Service", * identifiers: ["bedrock-agentcore.amazonaws.com"], * }], * effect: "Allow", * actions: ["sts:AssumeRole"], * }], * }); * const gatewayRole = new aws.iam.Role("gateway_role", { * name: "bedrock-gateway-role", * assumeRolePolicy: gatewayAssume.then(gatewayAssume => gatewayAssume.json), * }); * const lambdaAssume = aws.iam.getPolicyDocument({ * statements: [{ * principals: [{ * type: "Service", * identifiers: ["lambda.amazonaws.com"], * }], * effect: "Allow", * actions: ["sts:AssumeRole"], * }], * }); * const lambdaRole = new aws.iam.Role("lambda_role", { * name: "example-lambda-role", * assumeRolePolicy: lambdaAssume.then(lambdaAssume => lambdaAssume.json), * }); * const example = new aws.lambda.Function("example", { * code: new pulumi.asset.FileArchive("example.zip"), * name: "example-function", * role: lambdaRole.arn, * handler: "index.handler", * runtime: aws.lambda.Runtime.NodeJS24dX, * }); * const exampleAgentcoreGateway = new aws.bedrock.AgentcoreGateway("example", { * authorizerConfiguration: { * customJwtAuthorizer: { * discoveryUrl: "https://accounts.google.com/.well-known/openid-configuration", * }, * }, * name: "example-gateway", * roleArn: gatewayRole.arn, * }); * const exampleAgentcoreGatewayTarget = new aws.bedrock.AgentcoreGatewayTarget("example", { * credentialProviderConfiguration: { * gatewayIamRole: {}, * }, * targetConfiguration: { * mcp: { * lambda: { * toolSchema: { * inlinePayloads: [{ * inputSchema: { * properties: [ * { * name: "message", * type: "string", * description: "Message to process", * required: true, * }, * { * properties: [ * { * name: "priority", * type: "string", * }, * { * items: [{ * type: "string", * }], * name: "tags", * type: "array", * }, * ], * name: "options", * type: "object", * }, * ], * type: "object", * description: "Request processing schema", * }, * outputSchema: { * properties: [ * { * name: "status", * type: "string", * required: true, * }, * { * name: "result", * type: "string", * }, * ], * type: "object", * }, * name: "process_request", * description: "Process incoming requests", * }], * }, * lambdaArn: example.arn, * }, * }, * }, * name: "example-target", * gatewayIdentifier: exampleAgentcoreGateway.gatewayId, * description: "Lambda function target for processing requests", * }); * ``` * * ### Target with API Key Authentication * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const apiKeyExample = new aws.bedrock.AgentcoreGatewayTarget("api_key_example", { * credentialProviderConfiguration: { * apiKey: { * providerArn: "arn:aws:iam::123456789012:oidc-provider/example.com", * credentialLocation: "HEADER", * credentialParameterName: "X-API-Key", * credentialPrefix: "Bearer", * }, * }, * targetConfiguration: { * mcp: { * lambda: { * toolSchema: { * inlinePayloads: [{ * inputSchema: { * type: "string", * description: "Simple string input for API calls", * }, * name: "api_tool", * description: "External API integration tool", * }], * }, * lambdaArn: example.arn, * }, * }, * }, * name: "api-target", * gatewayIdentifier: exampleAwsBedrockagentcoreGateway.gatewayId, * description: "External API target with API key authentication", * }); * ``` * * ### Target with OAuth Authentication * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const oauthExample = new aws.bedrock.AgentcoreGatewayTarget("oauth_example", { * credentialProviderConfiguration: { * oauth: { * providerArn: "arn:aws:iam::123456789012:oidc-provider/oauth.example.com", * scopes: [ * "read", * "write", * ], * grantType: "authorization_code", * defaultReturnUrl: "https://myapp.example.com/callback", * customParameters: { * client_type: "confidential", * }, * }, * }, * targetConfiguration: { * mcp: { * lambda: { * toolSchema: { * inlinePayloads: [{ * inputSchema: { * items: { * properties: [ * { * name: "id", * type: "string", * required: true, * }, * { * name: "value", * type: "number", * }, * ], * type: "object", * }, * type: "array", * }, * name: "oauth_tool", * description: "OAuth-authenticated service", * }], * }, * lambdaArn: example.arn, * }, * }, * }, * name: "oauth-target", * gatewayIdentifier: exampleAwsBedrockagentcoreGateway.gatewayId, * }); * ``` * * ### Target with IAM SigV4 Authentication (MCP Server) * * Use this for `mcpServer` targets pointing at AWS-hosted SigV4-protected endpoints (e.g. another Bedrock AgentCore Runtime). The gateway signs upstream requests using its own IAM role. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const sigv4Example = new aws.bedrock.AgentcoreGatewayTarget("sigv4_example", { * credentialProviderConfiguration: { * gatewayIamRole: { * service: "bedrock-agentcore", * }, * }, * targetConfiguration: { * mcp: { * mcpServer: { * endpoint: "https://example-runtime.bedrock-agentcore.us-east-1.amazonaws.com/runtimes/example/invocations?qualifier=DEFAULT", * }, * }, * }, * name: "sigv4-target", * gatewayIdentifier: example.gatewayId, * }); * ``` * * ### Complex Schema with JSON Serialization * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const complexSchema = new aws.bedrock.AgentcoreGatewayTarget("complex_schema", { * credentialProviderConfiguration: { * gatewayIamRole: {}, * }, * targetConfiguration: { * mcp: { * lambda: { * toolSchema: { * inlinePayloads: [{ * inputSchema: { * properties: [{ * properties: [ * { * name: "nested_tags", * type: "array", * itemsJson: JSON.stringify({ * type: "string", * }), * }, * { * name: "metadata", * type: "object", * propertiesJson: JSON.stringify({ * properties: { * created_at: { * type: "string", * }, * version: { * type: "number", * }, * }, * required: ["created_at"], * }), * }, * ], * name: "profile", * type: "object", * }], * type: "object", * }, * name: "complex_tool", * description: "Tool with complex nested schema", * }], * }, * lambdaArn: example.arn, * }, * }, * }, * name: "complex-target", * gatewayIdentifier: exampleAwsBedrockagentcoreGateway.gatewayId, * }); * ``` * * ### MCP Server Target with Header Propagation * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const mcpWithHeaders = new aws.bedrock.AgentcoreGatewayTarget("mcp_with_headers", { * targetConfiguration: { * mcp: { * mcpServer: { * endpoint: "https://example.com/mcp", * }, * }, * }, * metadataConfiguration: { * allowedRequestHeaders: [ * "x-correlation-id", * "x-tenant-id", * ], * allowedResponseHeaders: ["x-rate-limit-remaining"], * allowedQueryParameters: ["version"], * }, * name: "mcp-target-with-headers", * gatewayIdentifier: example.gatewayId, * description: "MCP server target with header propagation", * }); * ``` * * ### Self-hosted MCP server in a VPC (managed Lattice) * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.bedrock.AgentcoreGatewayTarget("example", { * targetConfiguration: { * mcp: { * mcpServer: { * endpoint: "https://mcp.internal.example.com/mcp", * }, * }, * }, * privateEndpoint: { * managedVpcResource: { * vpcIdentifier: exampleAwsVpc.id, * subnetIds: exampleAwsSubnet.map(__item => __item.id), * endpointIpAddressType: "IPV4", * securityGroupIds: [mcpLattice.id], * }, * }, * gatewayIdentifier: exampleAwsBedrockagentcoreGateway.gatewayId, * name: "my-private-mcp-target", * }); * ``` * * ### Self-hosted MCP server with routing through an internal ALB * * Use `routingDomain` when the MCP server has a private TLS certificate. Place an internal ALB with a public ACM certificate in front of the server and set `routingDomain` to the ALB DNS name. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.bedrock.AgentcoreGatewayTarget("example", { * targetConfiguration: { * mcp: { * mcpServer: { * endpoint: "https://mcp.example.com/mcp", * }, * }, * }, * privateEndpoint: { * managedVpcResource: { * vpcIdentifier: exampleAwsVpc.id, * subnetIds: exampleAwsSubnet.map(__item => __item.id), * endpointIpAddressType: "IPV4", * routingDomain: mcpAlb.dnsName, * }, * }, * gatewayIdentifier: exampleAwsBedrockagentcoreGateway.gatewayId, * name: "my-private-mcp-via-alb", * }); * ``` * * ### Self-managed VPC Lattice resource configuration * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.bedrock.AgentcoreGatewayTarget("example", { * targetConfiguration: { * mcp: { * mcpServer: { * endpoint: "https://mcp.internal.example.com/mcp", * }, * }, * }, * privateEndpoint: { * selfManagedLatticeResource: { * resourceConfigurationIdentifier: mcp.arn, * }, * }, * gatewayIdentifier: exampleAwsBedrockagentcoreGateway.gatewayId, * name: "my-private-mcp-self-managed", * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * * `gatewayIdentifier` (String) Gateway identifier. * * `targetId` (String) Gateway target ID. * * #### Optional * * * `accountId` (String) Account ID where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import gateway targets using `gatewayIdentifier` and `targetId` separated by a comma (`,`). For example: * * ```sh * $ pulumi import aws:bedrock/agentcoreGatewayTarget:AgentcoreGatewayTarget example GATEWAY1234567890,TARGET0987654321 * ``` */ export declare class AgentcoreGatewayTarget extends pulumi.CustomResource { /** * Get an existing AgentcoreGatewayTarget resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: AgentcoreGatewayTargetState, opts?: pulumi.CustomResourceOptions): AgentcoreGatewayTarget; /** * Returns true if the given object is an instance of AgentcoreGatewayTarget. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is AgentcoreGatewayTarget; /** * Configuration for authenticating requests to the target. Required when using `lambda`, `openApiSchema` and `smithyModel` in `mcp` block. If using `mcpServer` in `mcp` block with no authorization, it should not be specified. See `credentialProviderConfiguration` Block below. */ readonly credentialProviderConfiguration: pulumi.Output; /** * Description of the gateway target. */ readonly description: pulumi.Output; /** * Identifier of the gateway that this target belongs to. */ readonly gatewayIdentifier: pulumi.Output; /** * Configuration for HTTP header and query parameter propagation between the gateway and target servers. See `metadataConfiguration` Block below. */ readonly metadataConfiguration: pulumi.Output; /** * Name of the gateway target. */ readonly name: pulumi.Output; /** * Configuration for private connectivity from AgentCore Gateway to a resource inside your VPC. Traffic is routed through Amazon VPC Lattice and never traverses the public internet. See `privateEndpoint` Block below. */ readonly privateEndpoint: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * Configuration for the target endpoint. See `targetConfiguration` Block below. * * The following arguments are optional: */ readonly targetConfiguration: pulumi.Output; /** * Unique identifier of the gateway target. */ readonly targetId: pulumi.Output; readonly timeouts: pulumi.Output; /** * Create a AgentcoreGatewayTarget resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: AgentcoreGatewayTargetArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering AgentcoreGatewayTarget resources. */ export interface AgentcoreGatewayTargetState { /** * Configuration for authenticating requests to the target. Required when using `lambda`, `openApiSchema` and `smithyModel` in `mcp` block. If using `mcpServer` in `mcp` block with no authorization, it should not be specified. See `credentialProviderConfiguration` Block below. */ credentialProviderConfiguration?: pulumi.Input; /** * Description of the gateway target. */ description?: pulumi.Input; /** * Identifier of the gateway that this target belongs to. */ gatewayIdentifier?: pulumi.Input; /** * Configuration for HTTP header and query parameter propagation between the gateway and target servers. See `metadataConfiguration` Block below. */ metadataConfiguration?: pulumi.Input; /** * Name of the gateway target. */ name?: pulumi.Input; /** * Configuration for private connectivity from AgentCore Gateway to a resource inside your VPC. Traffic is routed through Amazon VPC Lattice and never traverses the public internet. See `privateEndpoint` Block below. */ privateEndpoint?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Configuration for the target endpoint. See `targetConfiguration` Block below. * * The following arguments are optional: */ targetConfiguration?: pulumi.Input; /** * Unique identifier of the gateway target. */ targetId?: pulumi.Input; timeouts?: pulumi.Input; } /** * The set of arguments for constructing a AgentcoreGatewayTarget resource. */ export interface AgentcoreGatewayTargetArgs { /** * Configuration for authenticating requests to the target. Required when using `lambda`, `openApiSchema` and `smithyModel` in `mcp` block. If using `mcpServer` in `mcp` block with no authorization, it should not be specified. See `credentialProviderConfiguration` Block below. */ credentialProviderConfiguration?: pulumi.Input; /** * Description of the gateway target. */ description?: pulumi.Input; /** * Identifier of the gateway that this target belongs to. */ gatewayIdentifier: pulumi.Input; /** * Configuration for HTTP header and query parameter propagation between the gateway and target servers. See `metadataConfiguration` Block below. */ metadataConfiguration?: pulumi.Input; /** * Name of the gateway target. */ name?: pulumi.Input; /** * Configuration for private connectivity from AgentCore Gateway to a resource inside your VPC. Traffic is routed through Amazon VPC Lattice and never traverses the public internet. See `privateEndpoint` Block below. */ privateEndpoint?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Configuration for the target endpoint. See `targetConfiguration` Block below. * * The following arguments are optional: */ targetConfiguration: pulumi.Input; timeouts?: pulumi.Input; } //# sourceMappingURL=agentcoreGatewayTarget.d.ts.map