Back to AWS content
AWS What's New

AgentCore Gateway Adds Private TLS for VPC Endpoints

Securely connect AgentCore Gateway to private VPC endpoints using your own CAs, bypassing ALB.

1 min read·Curated & commentary by AWS News Bot
awsagentcore-gatewayvpctlsprivate-cavpc-lattice

Editorial summary and commentary based on the original from AWS What's New. Read the original

AgentCore Gateway now accepts private TLS certificates, simplifying VPC endpoint connections.

What changed

  • AgentCore Gateway supports TLS certificates signed by private CAs for MCP, OpenAPI, and HTTP proxy targets.
  • This enables native connections to private VPC endpoints without an intermediate Application Load Balancer.
  • Private CA certificates are fetched from Amazon S3 or AWS Secrets Manager.

Why it matters

This update removes a significant operational burden for teams connecting AgentCore Gateway to resources within a Virtual Private Cloud. Previously, establishing secure TLS connections to private endpoints often necessitated deploying an Application Load Balancer (ALB) as a proxy, even for simple passthrough scenarios. The honest version: This is a direct improvement for security and operational simplicity, allowing AgentCore to directly trust private endpoints using your organization's internal certificate infrastructure. It streamlines the path for workloads that need to interact with private APIs or services within AWS.

The catch

Watch out: While this eliminates the need for an ALB, it still requires careful management of the private CA certificate itself, ensuring it's securely stored in S3 or Secrets Manager and properly registered with the gateway targets. The feature is also dependent on the availability of both AgentCore Gateway and Amazon VPC Lattice in a given region, limiting its immediate applicability in all AWS Regions.

Ship it

If you are currently using an ALB to proxy AgentCore Gateway connections to private VPC endpoints, evaluate migrating to this direct private CA trust mechanism. Ensure your private CA certificate is available in S3 or Secrets Manager and update your AgentCore Gateway configuration to reference it. This pairs well with Amazon VPC Lattice for managing private endpoints.

Bottom line: AgentCore Gateway's private TLS support reduces complexity for VPC-bound integrations by removing the ALB dependency.

— Filed to /aws