High
BedrockAgentCore
Regional
Bedrock AgentCore runtimes should be configured with VPC network mode
Description
Flags Amazon Bedrock AgentCore runtimes whose network mode is set to PUBLIC. PUBLIC runtimes communicate over the internet and bypass VPC controls; production agents that handle sensitive data should run in VPC network mode.
Remediation
Configure every AgentCore runtime to use VPC network mode with subnets and security groups that match your isolation requirements.
Steps
- Open the Amazon Bedrock AgentCore console and select the runtime.
- Choose Edit network configuration.
- Set the network mode to VPC.
- Select the subnets and security groups for the runtime.
- Save the changes and redeploy the runtime.