更新防火墙和网关以允许访问 - Amazon Toolkit with Amazon Q
Amazon Web Services 文档中描述的 Amazon Web Services 服务或功能可能因区域而异。要查看适用于中国区域的差异,请参阅 中国的 Amazon Web Services 服务入门 (PDF)

更新防火墙和网关以允许访问

如果您使用 Web 内容筛选解决方案筛选对特定 Amazon 域或 URL 端点的访问,则必须将下列端点纳入允许列表中,这样才能通过 Amazon Toolkit for Visual Studio 和 Amazon Q 访问所有可用服务和功能。有关如何排除 Amazon Toolkit with Amazon Q 的防火墙和代理设置故障的详细步骤,请参阅本用户指南故障排除主题中的防火墙和代理设置一节。有关为 Amazon Q 配置公司代理的详细信息,请参阅《Amazon Q 开发者版用户指南》中的在 Amazon Q 中配置公司代理主题。

Amazon Toolkit for Visual Studio 端点

以下是需要纳入允许列表的特定于 Amazon Toolkit for Visual Studio 的端点和引用的列表。

端点

https://idetoolkits-hostedfiles.amazonaws.com/* https://idetoolkits.amazonwebservices.com/* http://vstoolkit.amazonwebservices.com/* https://aws-vs-toolkit.s3.amazonaws.com/* https://raw.githubusercontent.com/aws/aws-toolkit-visual-studio/main/version.json https://aws-toolkit-language-servers.amazonaws.com/*

Amazon Q 插件端点

以下是需要纳入允许列表的特定于 Amazon Q 插件的端点和引用的列表。

https://idetoolkits-hostedfiles.amazonaws.com/* (Plugin for configs) https://idetoolkits.amazonwebservices.com/* (Plugin for endpoints) https://aws-toolkit-language-servers.amazonaws.com/* (Language Server Process) https://client-telemetry.us-east-1.amazonaws.com/ (Telemetry) https://cognito-identity.us-east-1.amazonaws.com (Telemetry) https://aws-language-servers.us-east-1.amazonaws.com (Language Server Process)

Amazon Q 开发者版端点

以下是需要纳入允许列表的特定于 Amazon Q 开发者版的端点和引用的列表。

https://codewhisperer.us-east-1.amazonaws.com (Inline,Chat, QSDA,...) https://q.us-east-1.amazonaws.com (Inline,Chat, QSDA....) https://desktop-release.codewhisperer.us-east-1.amazonaws.com/ (Download URL for CLI.) https://specs.q.us-east-1.amazonaws.com (URL for auto-complete specs used by CLI) * aws-language-servers.us-east-1.amazonaws.com (Local Workspace context)

Amazon Q 代码转换端点

以下是需要纳入允许列表的特定于 Amazon Q 代码转换工具的端点和引用的列表。

https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/security_iam_manage-access-with-policies.html

身份验证端点

以下是需要纳入允许列表的身份验证端点和引用的列表。

[Directory ID or alias].awsapps.com * oidc.[Region].amazonaws.com *.sso.[Region].amazonaws.com *.sso-portal.[Region].amazonaws.com *.aws.dev *.awsstatic.com *.console.aws.a2z.com *.sso.amazonaws.com

身份端点

以下列表包含特定于身份的端点,例如 Amazon IAM Identity Center 和 Amazon 构建者 ID。

Amazon IAM Identity Center

有关 IAM Identity Center 所需端点的详细信息,请参阅《Amazon IAM Identity Center 用户指南》中的启用 IAM Identity Center 主题。

企业 IAM Identity Center

https://[Center director id].awsapps.com/start (should be permitted to initiate auth) https://us-east-1.signin.aws (for facilitating authentication, assuming IAM Identity Center is in IAD) https://oidc.(us-east-1).amazonaws.com https://log.sso-portal.eu-west-1.amazonaws.com https://portal.sso.eu-west-1.amazonaws.com

Amazon 构建者 ID

https://view.awsapps.com/start (must be blocked to disable individual tier) https://codewhisperer.us-east-1.amazonaws.com and q.us-east-1.amazonaws.com (should be permitted)

遥测

以下是需要纳入允许列表的特定于遥测的端点。

https://telemetry.aws-language-servers.us-east-1.amazonaws.com/ https://client-telemetry.us-east-1.amazonaws.com

引用

以下是端点引用的列表。

idetoolkits-hostedfiles.amazonaws.com cognito-identity.us-east-1.amazonaws.com amazonwebservices.gallery.vsassets.io eu-west-1.prod.pr.analytics.console.aws.a2z.com prod.pa.cdn.uis.awsstatic.com portal.sso.eu-west-1.amazonaws.com log.sso-portal.eu-west-1.amazonaws.com prod.assets.shortbread.aws.dev prod.tools.shortbread.aws.dev prod.log.shortbread.aws.dev a.b.cdn.console.awsstatic.com assets.sso-portal.eu-west-1.amazonaws.com oidc.eu-west-1.amazonaws.com aws-toolkit-language-servers.amazonaws.com aws-language-servers.us-east-1.amazonaws.com idetoolkits.amazonwebservices.com