Amazon Bedrock AgentCore Gateway supports private TLS certificates for VPC endpoints
Amazon Bedrock AgentCore Gateway now enables secure connections to private endpoints by supporting TLS certificates signed by private certificate authorities (CAs). This enhancement applies to MCP, OpenAPI, and HTTP proxy targets, allowing users to connect directly to VPC endpoints without needing an intermediate Application Load Balancer. The gateway fetches PEM-encoded CA certificates from Amazon S3 or AWS Secrets Manager to establish trust, integrating with Amazon VPC Lattice for private endpoints. This capability is available in all regions where both AgentCore Gateway and Amazon VPC Lattice operate.
Features (1) ›
- Private TLS certificate support for AgentCore Gateway targets
Amazon Bedrock AgentCore Gateway now supports TLS certificates signed by private certificate authorities (CAs) for MCP, OpenAPI, and HTTP proxy targets. This allows secure, native connections to private endpoints in a VPC, eliminating the need for an intermediate Application Load Balancer. Users can register private CA certificates fetched from Amazon S3 or AWS Secrets Manager as trust anchors for outbound TLS connections via Amazon VPC Lattice.
https://aws.amazon.com/about-aws/whats-new/2026/10/agentcore-gateway-private-tls-vpc/
Related releases
- Amazon Redshift Adds Support for Apache Iceberg Materialized Views AWS What's New ·
- AWS details Iceberg materialized views in Amazon Redshift for data lake interoperability AWS Big Data Blog ·
- Amazon Redshift now supports cross-Region S3 data lake queries AWS What's New ·
- AWS Glue now offers system-managed write protection for Apache Iceberg materialized views AWS What's New ·
- AWS launches system-managed write protection for Apache Iceberg materialized views AWS What's New ·
- Amazon DynamoDB adds filtered export to Amazon S3 AWS What's New ·