Bedrock AgentCore Gateway adds private CA TLS for direct VPC agent connections

This update is narrow but useful for enterprise agent deployments. AgentCore Gateway targets can now trust certificates signed by private CAs, which is how most enterprises secure internal services. Previously, reaching an internal MCP server or API from AgentCore often required a public-CA workaround or an Application Load Balancer in front of the service. Now gateway targets route through Amazon VPC Lattice directly.
Setup is straightforward. Each MCP, OpenAPI or HTTP proxy target can load a PEM-encoded CA certificate from Amazon S3 or AWS Secrets Manager and use it as the trust anchor. That fits existing PKI workflows and removes a network hop. In the same release cycle, the managed AWS MCP Server, part of the Agent Toolkit for AWS, became available in Singapore, Sydney, Tokyo, Ireland, London and Oregon. AWS also published guides on connecting Claude Desktop to secure web search through AgentCore, and on linking its DevOps Agent to OpenSearch through MCP for closed-loop incident response.
AWS is building out the infrastructure around models, what Swami Sivasubramanian described as 'runtime, memory, identity, and governance'. Its competitors are Microsoft's Copilot and Foundry stack and Google's agent platform. Private connectivity to agent endpoints carries extra weight this week: OpenAI's rogue-agent disclosures make keeping agent traffic inside private networks a stronger selling point.
The caveat is that private connectivity does not provide containment. An agent with valid credentials inside the VPC can still misuse them. Teams should pair this feature with least-privilege tool scopes.