llm-catalog-archive

Change

42e9060

42e9060559c03996a3a8ed9bcd55421351a8f1a7 · commit on GitHub

aws-blog-feed: changed (572316 bytes, HTTP 200)

raw/aws-blog-feed/response.xml modified

Lines added
+4,798
Lines removed
-4,210
Stored bytes at this commit
572,316
Timestamp
observed
Raw artifact at this commit
raw/aws-blog-feed/response.xml
Recorded headers
observed_at2026-10-02T05:37:33.339Z
origin_datenull
status200
final URLhttps://aws.amazon.com/blogs/machine-learning/feed/
etagnull
last-modifiedThu, 01 Oct 2026 22:20:57 GMT
dateFri, 02 Oct 2026 05:37:33 GMT
agenull
cache-controlnull
cf-cache-statusnull
content-encodingnull
content-lengthnull
@@@ -5,7 +5,7 @@
<atom:link href="https://aws.amazon.com/blogs/machine-learning/feed/" rel="self" type="application/rss+xml"/>
<link>https://aws.amazon.com/blogs/machine-learning/</link>
<description>Official Machine Learning Blog of Amazon Web Services</description>
- <lastBuildDate>Wed, 30 Sep 2026 15:37:15 +0000</lastBuildDate>
+ <lastBuildDate>Thu, 01 Oct 2026 22:13:49 +0000</lastBuildDate>
<language>en-US</language>
<sy:updatePeriod>
hourly </sy:updatePeriod>
@@@ -13,555 +13,2451 @@
1 </sy:updateFrequency>
<item>
- <title>Query claims in natural language with Amazon Bedrock Knowledge Bases</title>
- <link>https://aws.amazon.com/blogs/machine-learning/query-claims-in-natural-language-with-amazon-bedrock-knowledge-bases/</link>
+ <title>Scaling cloud migrations with agentic AI on Amazon Bedrock AgentCore</title>
+ <link>https://aws.amazon.com/blogs/machine-learning/scaling-cloud-migrations-with-agentic-ai-on-amazon-bedrock-agentcore/</link>
- <dc:creator><![CDATA[Shreya Pawaskar]]></dc:creator>
- <pubDate>Wed, 30 Sep 2026 15:37:15 +0000</pubDate>
+ <dc:creator><![CDATA[Nikhil Jha]]></dc:creator>
+ <pubDate>Thu, 01 Oct 2026 22:06:14 +0000</pubDate>
<category><![CDATA[Advanced (300)]]></category>
- <category><![CDATA[Amazon Bedrock]]></category>
- <category><![CDATA[Amazon Bedrock Knowledge Bases]]></category>
+ <category><![CDATA[Amazon Bedrock AgentCore]]></category>
<category><![CDATA[Technical How-to]]></category>
- <guid isPermaLink="false">6f62e0665479ef5d4ffddb480328d07ce719281b</guid>
+ <guid isPermaLink="false">d0376fa78aeb5acfd7edb22f7e3658ad0679a620</guid>
- <description>This technical how-to builds a conversational claims assistant on Amazon Bedrock Knowledge Bases that answers natural-language questions with citations. It covers ingesting claim documents from Amazon S3, querying with the AgenticRetrieveStream API, multi-turn follow-ups, metadata …
- <content:encoded>&lt;p&gt;Claim answers are scattered across adjuster diary entries, repair estimates, police reports, payment ledgers, and scanned attachments rather than one searchable field. A policyholder might ask whether a claim was approved, while an adjuster might need every open a…
-&lt;p&gt;Retrieval Augmented Generation (RAG) uses retrieved documents to ground model responses. &lt;a href="https://docs.aws.amazon.com/bedrock/latest/userguide/knowledge-base.html" target="_blank" rel="noopener"&gt;Amazon Bedrock Knowledge Bases&lt;/a&gt; is the fully managed RAG capability for d…
-&lt;p&gt;This technical how-to uses synthetic claim records and doesn’t describe a production customer deployment. You build a claims assistant that answers natural-language questions with citations by completing these steps:&lt;/p&gt;
+ <description>Learn how AWS Professional Services uses a multi-agent framework built on Amazon Bedrock AgentCore to automate enterprise cloud migrations end to end. Purpose-built AI agents handle discovery, infrastructure as code generation, portfolio governance, and post-migration operations, r…
+ <content:encoded>&lt;p&gt;&lt;em&gt;&lt;strong&gt;October 2026: This post was reviewed and updated for accuracy.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
+&lt;p&gt;Scaling cloud migrations with agentic AI on &lt;a href="https://aws.amazon.com/bedrock/agentcore/" target="_blank" rel="noopener"&gt;Amazon Bedrock AgentCore&lt;/a&gt; raises a practical question. Which parts of a large migration program belong to a managed service, and which parts need cus…
+&lt;p&gt;This pattern runs alongside &lt;a href="https://docs.aws.amazon.com/transform/" target="_blank" rel="noopener"&gt;AWS Transform&lt;/a&gt; rather than in place of it, as a hybrid that adds custom agents where your program requires them. AWS Transform covers the migration and modernization wo…
+&lt;p&gt;AWS Professional Services builds a suite of purpose-built AI agents for programs with that requirement. The agents use the &lt;a href="https://strandsagents.com/" target="_blank" rel="noopener"&gt;Strands Agents SDK&lt;/a&gt; and run on Amazon Bedrock AgentCore, a platform to build, connect…
+&lt;p&gt;In this post, you explore the architecture of a four-agent pattern for MCP-connected environments. You also see the code that defines an agent, connects it to its tools, and applies responsible AI controls. The pattern includes four agents:&lt;/p&gt;
&lt;ul&gt;
- &lt;li&gt;Ingest claim documents and their metadata from Amazon Simple Storage Service (Amazon S3).&lt;/li&gt;
- &lt;li&gt;Query them in plain language with the &lt;code&gt;AgenticRetrieveStream&lt;/code&gt; API.&lt;/li&gt;
- &lt;li&gt;Ask multi-turn follow-up questions.&lt;/li&gt;
- &lt;li&gt;Scope retrieval with metadata filters on attributes such as claim ID and claim type.&lt;/li&gt;
- &lt;li&gt;Add a contextual grounding guardrail to keep answers tied to the records.&lt;/li&gt;
+ &lt;li&gt;The Intake Agent, which reads migration inputs from document and collaboration systems through MCP tools.&lt;/li&gt;
+ &lt;li&gt;The IaC Agent, which generates IaC that composes your approved internal modules.&lt;/li&gt;
+ &lt;li&gt;The Migration Intelligence and Governance Agent, which reports and governs inside your own program tools.&lt;/li&gt;
+ &lt;li&gt;The Site Reliability Engineering (SRE) Agent for operations after cutover.&lt;/li&gt;
&lt;/ul&gt;
-&lt;h2 id="the-claims-lookup-challenge"&gt;The claims lookup challenge&lt;/h2&gt;
-&lt;p&gt;Policyholders, contact center agents, and adjusters ask different questions:&lt;/p&gt;
+&lt;p&gt;To follow along, you need an AWS account with access to Amazon Bedrock AgentCore and to Amazon Bedrock foundation models. You also need familiarity with the Strands Agents SDK and MCP server patterns, plus the IaC tooling used by your organization. Confirm first that an AWS managed service …
+&lt;h2 id="when-this-pattern-applies"&gt;When this pattern applies&lt;/h2&gt;
+&lt;p&gt;AWS Transform covers migration and modernization for server, network, mainframe, .NET, and application code workloads as a managed service, and AWS DMS covers databases. This pattern adds agents for the requirements that stay specific to your organization.&lt;/p&gt;
+&lt;p&gt;On the program described here, three conditions held together.&lt;/p&gt;
&lt;ul&gt;
- &lt;li&gt;Policyholders ask for a plain-language status update: “Has the estimate for claim CLM-100482 been approved, and when will the check be issued?”&lt;/li&gt;
- &lt;li&gt;Contact center agents need a fast, accurate answer while the customer waits, without transferring the call.&lt;/li&gt;
- &lt;li&gt;Adjusters ask multi-part questions across claims, such as which open auto claims over $10,000 were filed last month and what work remains on each.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;MCP-connected sources and destinations:&lt;/strong&gt; The systems holding the migration inputs, and the systems receiving the outputs, were reached through MCP tools that the delivery team built and maintained. They included an internal wiki holding security standards, a ti…
+ &lt;li&gt;&lt;strong&gt;Organization-specific IaC composition:&lt;/strong&gt; Generated infrastructure code had to compose an internal module library that the security office reviews and approves. Writing that composition by hand took 3 to 4 weeks per application, which across a 300+ application po…
+ &lt;li&gt;&lt;strong&gt;Work continuing past cutover:&lt;/strong&gt; Program scope included operations after handover, which sits outside the migration services.&lt;/li&gt;
&lt;/ul&gt;
-&lt;p&gt;Answers are stored in PDF adjuster reports, Word correspondence, and text notes rather than consistent database fields.&lt;/p&gt;
-&lt;p&gt;Records can conflict or supersede earlier versions. A revised estimate can replace an earlier one, or a provisional payment can be reversed later. The assistant must identify which estimate, payment, or status controls.&lt;/p&gt;
-&lt;p&gt;Because claims are regulated, every answer must be grounded in source documents and include citations. Contact center agents can verify a source before repeating an answer, and supervisors can audit how the assistant reached it.&lt;/p&gt;
-&lt;h2 id="solution-overview"&gt;Solution overview&lt;/h2&gt;
-&lt;p&gt;The solution uses &lt;a href="https://docs.aws.amazon.com/bedrock/latest/userguide/knowledge-base.html" target="_blank" rel="noopener"&gt;Amazon Bedrock Knowledge Bases&lt;/a&gt; to index claim documents from Amazon S3 for retrieval.&lt;/p&gt;
-&lt;p&gt;&lt;a href="https://docs.aws.amazon.com/bedrock/latest/userguide/kb-test-agentic-retrieve.html" target="_blank" rel="noopener"&gt;Agentic retrieval&lt;/a&gt; through &lt;code&gt;AgenticRetrieveStream&lt;/code&gt; plans an answer, breaks a multi-part question into sub-queries, and runs one o…
-&lt;p&gt;The API streams trace events, answer text, and citations. Trace events expose the retrieval plan, and each citation maps part of the answer to a source claim document.&lt;/p&gt;
-&lt;p&gt;The following diagram shows both paths. The ingestion lane loads claim documents and metadata into a knowledge base. The retrieval lane sends each question through &lt;code&gt;AgenticRetrieveStream&lt;/code&gt; and an Amazon Bedrock Guardrails grounding check before returning a cited answer…
+&lt;h2 id="architecture-overview"&gt;Architecture overview&lt;/h2&gt;
+&lt;p&gt;This pattern uses four purpose-built agents. The architecture attaches to a migration program at three points: the systems holding migration inputs, IaC composition, and operations after cutover. The pattern applies security at each of those points. The following diagram shows how the agent…
&lt;div style="width: 810px" class="wp-caption alignnone"&gt;
- &lt;a href="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/09/28/ML-21629-1.png" target="_blank" rel="noopener"&gt;&lt;img src="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/09/28/ML-21629-1.png" alt="Architecture with an in…
- &lt;p class="wp-caption-text"&gt;Figure 1: Conversational claims assistant with Amazon Bedrock Knowledge Bases&lt;/p&gt;
+ &lt;a href="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/10/01/REVBLOG-1301-1-1.png" target="_blank" rel="noopener"&gt;&lt;img src="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/10/01/REVBLOG-1301-1-1.png" alt="How the age…
+ &lt;p class="wp-caption-text"&gt;Figure 1: How the agents connect across the migration and operations journeys through Model Context Protocol tool calling&lt;/p&gt;
&lt;/div&gt;
-&lt;p&gt;The ingestion lane runs as documents arrive:&lt;/p&gt;
-&lt;ol type="1"&gt;
- &lt;li&gt;Claim documents in PDF, Word, or text format land in Amazon S3 with matching metadata sidecars.&lt;/li&gt;
- &lt;li&gt;An ingestion job synchronizes the S3 data source with the knowledge base as documents change.&lt;/li&gt;
- &lt;li&gt;The knowledge base parses, chunks, embeds, and indexes the documents and their metadata in managed vector storage.&lt;/li&gt;
-&lt;/ol&gt;
-&lt;p&gt;The retrieval lane runs for each question:&lt;/p&gt;
-&lt;ol start="4" type="1"&gt;
- &lt;li&gt;The application calls &lt;code&gt;AgenticRetrieveStream&lt;/code&gt; with the question, conversation history, and optional metadata filters that scope the search.&lt;/li&gt;
- &lt;li&gt;A foundation model creates sub-queries and repeats retrieval until it has enough evidence, up to maxAgentIteration rounds.&lt;/li&gt;
- &lt;li&gt;A contextual grounding check blocks answers that are unsupported by the retrieved records.&lt;/li&gt;
- &lt;li&gt;Amazon Bedrock streams the answer, trace events, and citations, so the application can display output as it arrives.&lt;/li&gt;
-&lt;/ol&gt;
-&lt;h2 id="prerequisites"&gt;Prerequisites&lt;/h2&gt;
-&lt;p&gt;Before you begin, verify that you have the following:&lt;/p&gt;
+&lt;p&gt;The pattern organizes agents into two journeys. The migration journey agents handle discovery through deployment. The operations journey agent handles post-migration monitoring.&lt;/p&gt;
+&lt;p&gt;Migration journey agents:&lt;/p&gt;
&lt;ul&gt;
- &lt;li&gt;An AWS account with AWS Identity and Access Management (IAM) permissions for Amazon Bedrock and Amazon S3.&lt;/li&gt;
- &lt;li&gt;Access to a foundation model (FM) enabled through &lt;a href="https://docs.aws.amazon.com/bedrock/latest/userguide/model-access.html" target="_blank" rel="noopener"&gt;Amazon Bedrock model access&lt;/a&gt;.&lt;/li&gt;
- &lt;li&gt;An AWS Region that supports the selected foundation model and Amazon Bedrock Knowledge Bases. This walkthrough uses US West (Oregon), us-west-2. Check &lt;a href="https://docs.aws.amazon.com/bedrock/latest/userguide/models-regions.html" target="_blank" rel="noopener"&gt;Supported models b…
- &lt;li&gt;The &lt;a href="https://aws.amazon.com/sdk-for-python/" target="_blank" rel="noopener"&gt;AWS SDK for Python (Boto3)&lt;/a&gt;, configured with credentials and a version that supports the APIs used here.&lt;/li&gt;
- &lt;li&gt;An S3 bucket for the synthetic claim documents and metadata.&lt;/li&gt;
- &lt;li&gt;Familiarity with Python and with basic RAG concepts.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;Intake Agent (Phase 1):&lt;/strong&gt; Reads architecture documents, questionnaires, and dependency records through MCP tools, then defines target state architecture.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;IaC Agent (Phase 2):&lt;/strong&gt; Generates IaC that composes your approved internal modules for each application.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;Migration Intelligence and Governance Agent:&lt;/strong&gt; Provides automated portfolio reporting, well-architected assessments, and governance across Jira, Confluence, and Webex.&lt;/li&gt;
&lt;/ul&gt;
-&lt;h2 id="prepare-the-claims-documents-and-metadata"&gt;Prepare the claims documents and metadata&lt;/h2&gt;
-&lt;p&gt;Store one document per claim in Amazon S3. The knowledge base reads PDF adjuster reports, Word correspondence, and text notes directly, so you can keep documents in their native format.&lt;/p&gt;
-&lt;p&gt;Figure 2 shows a synthetic claim record. Current exposure is the estimated total claim cost. Its evidence index identifies a superseded fax draft, meaning a record replaced by a newer version. The metadata sidecar repeats fields that the assistant can filter.&lt;/p&gt;
-&lt;div style="width: 810px" class="wp-caption alignnone"&gt;
- &lt;a href="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/09/28/ML-21629-2.png" target="_blank" rel="noopener"&gt;&lt;img src="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/09/28/ML-21629-2.png" alt="A synthetic claim recor…
- &lt;p class="wp-caption-text"&gt;Figure 2: A synthetic claim record with its file-control fields and evidence index&lt;/p&gt;
-&lt;/div&gt;
-&lt;p&gt;For filtering, add an accompanying metadata file with the same name plus &lt;code&gt;.metadata.json&lt;/code&gt;. For &lt;code&gt;CLM-100482.pdf&lt;/code&gt;, use &lt;code&gt;CLM-100482.pdf.metadata.json&lt;/code&gt;. Subrogation is an insurer’s effort to recover costs from a responsible th…
+&lt;p&gt;Operations journey agents:&lt;/p&gt;
+&lt;ul&gt;
+ &lt;li&gt;&lt;strong&gt;SRE Agent (Phase 3):&lt;/strong&gt; Provides monitoring and automated remediation after cutover.&lt;/li&gt;
+&lt;/ul&gt;
+&lt;p&gt;AWS managed services carry the migration and complement the custom agents:&lt;/p&gt;
+&lt;ul&gt;
+ &lt;li&gt;&lt;a href="https://docs.aws.amazon.com/dms/" target="_blank" rel="noopener"&gt;AWS Database Migration Service (AWS DMS)&lt;/a&gt;: Generative AI-assisted schema conversion and automated cutover for database migration.&lt;/li&gt;
+ &lt;li&gt;&lt;a href="https://docs.aws.amazon.com/transform/" target="_blank" rel="noopener"&gt;AWS Transform&lt;/a&gt;: Discovery, wave planning, landing zone creation, network conversion, rehost or replatform execution, and modernization for mainframe, virtualized, and .NET workloads.&lt;/li&gt;
+&lt;/ul&gt;
+&lt;h3 id="how-the-components-connect"&gt;How the components connect&lt;/h3&gt;
+&lt;p&gt;This section describes how the framework components interact at runtime.&lt;/p&gt;
+&lt;p&gt;Each agent is a Strands agent, defined by a foundation model, a system prompt, and a set of tools. Amazon Bedrock AgentCore runtime hosts them in a serverless environment with session isolation and multi-agent orchestration. Amazon Bedrock foundation models power the reasoning that interpre…
+&lt;p&gt;Each agent calls MCP tools scoped to its function through &lt;a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-quick-start.html" target="_blank" rel="noopener"&gt;AgentCore Gateway&lt;/a&gt;, a capability of Amazon Bedrock AgentCore, which converts your APIs, AW…
+&lt;p&gt;Amazon Bedrock &lt;a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory.html" target="_blank" rel="noopener"&gt;AgentCore memory&lt;/a&gt; stores agent session state and shared context. Agents use this shared context to persist outputs and track migration progress ac…
+&lt;h3 id="defining-an-agent-in-code"&gt;Defining an agent in code&lt;/h3&gt;
+&lt;p&gt;The following Python example defines the IaC Agent and prepares it for Amazon Bedrock AgentCore runtime. The agent reaches your MCP tools through AgentCore Gateway, and it calls a foundation model through Amazon Bedrock with an &lt;a href="https://docs.aws.amazon.com/bedrock/latest/userguid…
+&lt;div class="hide-language"&gt;
+ &lt;pre&gt;&lt;code class="language-python"&gt;
+ import json
+ import logging
+ import os
+ import uuid
+ from bedrock_agentcore.runtime import BedrockAgentCoreApp
+ from strands import Agent
+ from strands.models import BedrockModel
+ from strands.tools.mcp import MCPClient
+ from strands.tools.mcp.mcp_types import MCPClientCredentials
+
+ logger = logging.getLogger(__name__)
+ app = BedrockAgentCoreApp()
+
+ REGION = os.environ["AWS_REGION"]
+
+ # url+auth lets the SDK run the client_credentials grant and re-mint the
+ # token on expiry. A statically captured bearer token would go stale.
+ gateway = MCPClient(
+ url=os.environ["GATEWAY_MCP_URL"],
+ auth=MCPClientCredentials(
+ client_id=os.environ["GATEWAY_CLIENT_ID"],
+ client_secret=get_secret("gateway/client_secret"),
+ scopes=[os.environ["GATEWAY_SCOPE"]],
+ ),
+ )
+
+ model = BedrockModel(
+ model_id=os.environ["MODEL_ID"],
+ region_name=REGION,
+ guardrail_id=os.environ["GUARDRAIL_ID"],
+ guardrail_version=os.environ.get("GUARDRAIL_VERSION", "1"),
+ guardrail_trace="enabled",
+ )
+
+
+
+ @app.entrypoint
+ def invoke(payload, context):
+ prompt = (payload.get("prompt") or "").strip()
+ if not prompt:
+ return {"status": "error", "error": "missing required field: prompt"}
+
+ try:
+ with gateway:
+ # Fetch the approved policies for this wave first, so the rules
+ # travel in the system prompt instead of depending on the model
+ # to ask for them.
+ lookup = gateway.call_tool_sync(
+ tool_use_id=str(uuid.uuid4()),
+ name="get_policies",
+ arguments={
+ "resource_types": payload.get("resource_types", []),
+ "wave": payload.get("wave"),
+ },
+ )
+ if lookup["status"] != "success":
+ return {"status": "error", "error": "policy lookup failed"}
+ policies = lookup.get("structuredContent", {})
+
+ # tools=[gateway]: SDK owns the connection lifecycle and paginates
+ # tool discovery, which list_tools_sync() alone does not.
+ agent = Agent(
+ model=model,
+ system_prompt=(
+ f"{IAC_AGENT_PROMPT}\n\n"
+ f"Generated IaC satisfies these approved policies:\n"
+ f"{json.dumps(policies.get('policies', []), indent=2)}"
+ ),
+ tools=[gateway],
+ )
+ result = agent(prompt)
+
+ if result.stop_reason == "guardrail_intervened":
+ logger.warning("guardrail blocked request, session_id=%s",
+ getattr(context, "session_id", None))
+ return {"status": "blocked_by_guardrail"}
+
+ return {
+ "status": "ok",
+ "iac": str(result),
+ "policy_set_version": policies.get("version"),
+ "waived_policies": policies.get("waived", []),
+ }
+
+ except Exception as e:
+ logger.exception("invocation failed, session_id=%s",
+ getattr(context, "session_id", None))
+ return {"status": "error", "error": str(e)}
+
+
+ if __name__ == "__main__":
+ app.run()&lt;/code&gt;&lt;/pre&gt;
+&lt;/div&gt;
+&lt;p&gt;The entrypoint returns the generated IaC together with the policy set version that shaped it, so a reviewer traces the output back to a signed-off standard. AgentCore Runtime handles session isolation and scaling. For deployable examples, see the &lt;a href="https://github.com/awslabs/amazo…
+&lt;h2 id="phase-1-intake-agent-for-automated-discovery"&gt;Phase 1: Intake Agent for automated discovery&lt;/h2&gt;
+&lt;p&gt;The Intake Agent reads the migration inputs that live in your document and collaboration systems. On this program, those systems were reachable through MCP tools the delivery team built and maintained.&lt;/p&gt;
+&lt;p&gt;The agent ingests architecture documentation, application inventory lists, intake questionnaires, and dependency records through those tools. It then produces a target AWS architecture with a recommended migration pattern, resource sizing specifications, and a compliance validation report.&…
+&lt;p&gt;The output feeds directly into the IaC Agent, creating an automated handoff from intake to infrastructure provisioning.&lt;/p&gt;
+&lt;h2 id="phase-2-iac-agent-for-automated-infrastructure-code-generation"&gt;Phase 2: IaC Agent for automated infrastructure code generation&lt;/h2&gt;
+&lt;p&gt;AWS Professional Services deployed the IaC Agent first in the portfolio, and it delivers the most immediately measurable impact. It generates IaC code adhering to your security best practices and standards.&lt;/p&gt;
+&lt;h3 id="how-it-works"&gt;How it works&lt;/h3&gt;
+&lt;p&gt;The agent workflow proceeds through five steps:&lt;/p&gt;
+&lt;p&gt;&lt;strong&gt;Step 1: Ingest the steering document.&lt;/strong&gt; The agent reads the steering document from the wave team. It extracts deployment scope, compliance constraints, and Security Office-approved wave-specific overrides.&lt;/p&gt;
+&lt;p&gt;&lt;strong&gt;Step 2: Interpret the target state architecture diagram.&lt;/strong&gt; Using the Intake Agent’s output, the IaC Agent identifies infrastructure components, their relationships, and dependencies.&lt;/p&gt;
+&lt;p&gt;&lt;strong&gt;Step 3: Generate IaC.&lt;/strong&gt; Based on this interpretation, the agent generates IaC using your defined and established patterns. It populates configurations with wave-specific parameters and configures remote state management. It then applies mandatory tagging and adds …
+&lt;p&gt;&lt;strong&gt;Step 4: Validate through Policy in Amazon Bedrock AgentCore.&lt;/strong&gt; Before execution, Policy in AgentCore evaluates each tool call against Cedar rules. It calculates the scope of potential change, checks dependency conflicts with concurrent waves, and confirms complian…
+&lt;p&gt;&lt;strong&gt;Step 5: Execute and report.&lt;/strong&gt; The centralized execution plane triggers the IaC, monitors deployment, and reports outcomes through AgentCore Observability, a capability of Amazon Bedrock AgentCore. Post-deployment validation runs automatically and compliance metric…
+&lt;h3 id="custom-mcp-tools-the-security-foundation"&gt;Custom MCP tools: The security foundation&lt;/h3&gt;
+&lt;p&gt;Each action passes through custom MCP tools exposed by Amazon Bedrock AgentCore Gateway and governed by AgentCore Identity and Policy in AgentCore. AgentCore Identity authenticates each agent action through scoped IAM roles with least-privilege access. The framework validates inputs against…
+&lt;p&gt;No credentials or sensitive values pass through agent context, because AgentCore Identity resolves secrets at runtime from a centralized credential provider. AgentCore Observability and AWS CloudTrail write each agent action to an immutable, centralized audit trail. &lt;a href="https://docs…
+&lt;h3 id="curated-organizational-policies-as-mcp-tools"&gt;Curated organizational policies as MCP tools&lt;/h3&gt;
+&lt;p&gt;The security office curates the policy set, not the agent. A versioned document holds each rule, the resource types it covers, a machine-checkable assertion, and the approval record. The following example shows three policies and one wave exception.&lt;/p&gt;
&lt;div class="hide-language"&gt;
&lt;pre&gt;&lt;code class="language-json"&gt;{
- "metadataAttributes": {
- "claim_id": "CLM-100482",
- "claim_type": "auto",
- "status": "open",
- "date_filed": 20260709,
- "amount": 14250,
- "region": "us-west",
- "adjuster": "Martha Rivera",
- "policyholder": "Mary Major",
- "policy_number": "POL-AUTO-78432",
- "customer_id": "CUST-MM-1042",
- "household_id": "HHD-MM-1042",
- "document_type": "adjuster_report",
- "carrier": "Example Insurance",
- "has_subrogation": true,
- "has_litigation": false,
- "complexity_tier": "high"
- }
-}&lt;/code&gt;&lt;/pre&gt;
+ "policy_set": "security-office/baseline",
+ "version": "2026.09.1",
+ "policies": [
+ {
+ "id": "SEC-ENC-001",
+ "applies_to": ["aws_s3_bucket", "aws_ebs_volume", "aws_rds_cluster"],
+ "requirement": "Encrypt data at rest with a customer managed KMS key",
+ "assertion": "kms_key_id != null and sse_algorithm == 'aws:kms'",
+ "severity": "blocking",
+ "source": "SecOffice/Encryption-Standard-v4"
+ },
+ {
+ "id": "SEC-NET-014",
+ "applies_to": ["aws_security_group_rule"],
+ "requirement": "No ingress from 0.0.0.0/0 on administrative ports",
+ "assertion": "not (cidr_blocks contains '0.0.0.0/0' and to_port in [22, 3389])",
+ "severity": "blocking",
+ "source": "SecOffice/Network-Standard-v7"
+ },
+ {
+ "id": "OPS-TAG-003",
+ "applies_to": ["*"],
+ "requirement": "Carry owner, cost-center, data-classification, and wave tags",
+ "assertion": "tags has_keys ['owner', 'cost-center', 'data-classification', 'wave']",
+ "severity": "blocking",
+ "source": "SecOffice/Tagging-Standard-v2"
+ }
+ ],
+ "wave_overrides": [
+ {
+ "wave": "wave-14",
+ "policy_id": "SEC-NET-014",
+ "decision": "exception",
+ "expires_on": "2026-10-31",
+ "approved_by": "security-office"
+ }
+ ]
+ }&lt;/code&gt;&lt;/pre&gt;
&lt;/div&gt;
-&lt;p&gt;The sidecar contains scalar string, number, and Boolean values. Value types determine available filters. The following table lists fields used later in the queries.&lt;/p&gt;
-&lt;p&gt;This post uses synthetic data. Don’t place real personally identifiable information (PII) or protected health information in these resources without the required controls and approvals.&lt;/p&gt;
+&lt;p&gt;An AWS Lambda function serves that document, and AgentCore Gateway exposes the function as an MCP tool named get_policies. The IaC Agent requests only the policies in scope for the resource types in the wave it generates.&lt;/p&gt;
+&lt;div class="hide-language"&gt;
+ &lt;pre&gt;&lt;code class="language-python"&gt; import json
+ from datetime import date
+ from pathlib import Path
+
+ POLICY_SET = Path("policies/security-office-baseline.json")
+
+ def get_policies(event, context):
+ """Return the approved policies for the requested resource types and wave.
+
+ AgentCore Gateway exposes this function as the get_policies MCP tool.
+ """
+ doc = json.loads(POLICY_SET.read_text())
+ requested = set(event.get("resource_types") or [])
+ today = date.today()
+ waived = {
+ o["policy_id"]
+ for o in doc["wave_overrides"]
+ if o["wave"] == event.get("wave")
+ and date.fromisoformat(o["expires_on"]) &amp;gt;= today
+ }
+ policies = [
+ p for p in doc["policies"]
+ if (p["applies_to"] == ["*"] or requested &amp;amp; set(p["applies_to"]))
+ and p["id"] not in waived
+ ]
+ return {
+ "version": doc["version"],
+ "policies": policies,
+ "waived": sorted(waived),
+ }&lt;/code&gt;&lt;/pre&gt;
+&lt;/div&gt;
+&lt;p&gt;The response carries the policy set version, so generated code records which rules produced it and a reviewer traces a resource back to a signed-off standard. Waived policies travel in their own field rather than disappearing, and the compliance report lists them for the wave. Each exceptio…
+&lt;p&gt;Two policy layers operate here, and they answer different questions. AgentCore Policy evaluates Cedar rules to decide whether an agent calls a tool at all. The curated policy set decides what the generated infrastructure satisfies.&lt;/p&gt;
+&lt;h3 id="iac-generation-based-on-your-patterns"&gt;IaC generation based on your patterns&lt;/h3&gt;
+&lt;p&gt;The IaC Agent generates infrastructure code based on your defined and established patterns. These patterns encode organizational standards into reusable constructs. They include network configurations, security group rules, IAM roles, &lt;a href="https://docs.aws.amazon.com/cloudwatch/" tar…
+&lt;p&gt;This approach provides consistency across waves, speed for wave teams who don’t write infrastructure code from scratch, and governance where security updates propagate to consumers on their next deployment cycle.&lt;/p&gt;
+&lt;h3 id="output-artifacts"&gt;Output artifacts&lt;/h3&gt;
+&lt;p&gt;The agent produces IaC code, automated test cases, compliance reports, and deployment runbooks for each application.&lt;/p&gt;
+&lt;p&gt;The IaC Agent pushes generated code directly to your code repository (such as &lt;a href="https://docs.aws.amazon.com/codecommit/" target="_blank" rel="noopener"&gt;AWS CodeCommit&lt;/a&gt;, GitLab, or Bitbucket). From there, it enters your existing review and deployment pipeline without re…
+&lt;h2 id="migration-intelligence-and-governance-agent-portfolio-wide-visibility"&gt;Migration Intelligence and Governance Agent: Portfolio-wide visibility&lt;/h2&gt;
+&lt;p&gt;A 300+ application portfolio needs status reporting, progress tracking, follow-up actions, and well-architected validation. On this program, that work ran inside the customer’s own Jira, Confluence, and Webex. Performing it by hand creates significant overhead for project managers and deliv…
+&lt;p&gt;The Migration Intelligence and Governance Agent addresses this with automated, on-demand intelligence and governance across the portfolio. It aggregates data from three sources through AgentCore Gateway. Jira provides sprint progress and impediments. Confluence provides architecture documen…
+&lt;p&gt;The agent provides well-architected assessments across migrated workloads, compliance and governance validation, and architecture pattern adherence tracking.&lt;/p&gt;
+&lt;p&gt;Automated actions include updating Confluence pages with latest migration status, creating Jira tasks for identified action items, and generating ServiceNow tickets for escalations. These actions require explicit human approval before execution. This approval-gated architecture is a core de…
+&lt;p&gt;On-demand reporting across the 300+ application portfolio replaces manual aggregation, based on internal project tracking data. Your results might vary based on portfolio size and tool integrations.&lt;/p&gt;
+&lt;h2 id="phase-3-sre-agent-for-proactive-post-migration-operations"&gt;Phase 3: SRE Agent for proactive post-migration operations&lt;/h2&gt;
+&lt;p&gt;The SRE Agent covers the phase after handover. The migration services complete at cutover. After applications run on AWS, the SRE Agent shifts the team from reactive response to proactive improvement.&lt;/p&gt;
+&lt;p&gt;The agent monitors &lt;a href="https://docs.aws.amazon.com/cloudwatch/" target="_blank" rel="noopener"&gt;Amazon CloudWatch&lt;/a&gt; metrics, application performance data, and historical patterns. It raises alerts before issues affect production. The agent also publishes automated remediat…
+&lt;p&gt;Target areas (with human-in-the-loop approval) include database cluster right-sizing, performance tuning, storage tiering, and compute scaling and efficiency improvements.&lt;/p&gt;
+&lt;p&gt;The SRE Agent extends the pattern past migration. Applications don’t land on AWS and stop there. They continuously improve over time.&lt;/p&gt;
+&lt;h2 id="data-migration-with-aws-dms"&gt;Data migration with AWS DMS&lt;/h2&gt;
+&lt;p&gt;Alongside the custom AI agents, two AWS managed services handle the data and application modernization, server and network migration layer.&lt;/p&gt;
+&lt;p&gt;&lt;a href="https://docs.aws.amazon.com/dms/latest/userguide/schema-conversion-convert.databaseobjects.html" target="_blank" rel="noopener"&gt;DMS Schema Conversion with generative AI&lt;/a&gt; reduces manual schema mapping effort. It converts code objects that rules-based conversion leaves…
+&lt;p&gt;AWS Transform covers the server, network, and code layers of the same program. The &lt;a href="https://docs.aws.amazon.com/transform/latest/userguide/what-is-service.html" target="_blank" rel="noopener"&gt;AWS Transform User Guide&lt;/a&gt; lists the current capabilities by workload type.&l…
+&lt;h2 id="security-and-compliance-embedded-not-bolted-on"&gt;Security and compliance: Embedded, not bolted on&lt;/h2&gt;
+&lt;p&gt;This architecture embeds security from the start, not as an afterthought, applying it at each phase of the migration lifecycle. Key controls across the agent suite:&lt;/p&gt;
+&lt;ul&gt;
+ &lt;li&gt;&lt;strong&gt;Security standards enforcement:&lt;/strong&gt; The IaC Agent pulls your security office standards directly from Confluence and applies them across generated IaC using custom MCP tools.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;Landing zone validation:&lt;/strong&gt; The framework validates generated infrastructure against the enterprise’s landing zone compliance requirements before deployment.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;Human-in-the-loop approval gates:&lt;/strong&gt; Automated actions across all agents in the suite require explicit human approval before execution. No agent acts autonomously on production systems.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;AgentCore Gateway coordination:&lt;/strong&gt; Amazon Bedrock AgentCore Gateway coordinates context and security controls across agents, maintaining consistent policy application throughout the migration lifecycle.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;Continuous integration and continuous delivery (CI/CD) integration:&lt;/strong&gt; The framework integrates security controls into the CI/CD pipeline, with automated test cases generated alongside IaC to catch compliance issues before they reach production.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;Responsible AI controls at the inference layer:&lt;/strong&gt; Amazon Bedrock Guardrails applies content filters, denied topics, sensitive information filters, and contextual grounding checks to each prompt and each model response. An agent acts only on output that clears th…
+&lt;/ul&gt;
+&lt;p&gt;This approach aligns with the AWS shared responsibility model. AWS provides security of the underlying infrastructure, while you’re responsible for security in the cloud. The agents automate your configuration responsibilities while maintaining human oversight for approval decisions.&lt;/p&…
+&lt;p&gt;In this implementation, the pattern maintained enterprise security standards across the over 300 application portfolio at speeds manual processes could not match. Your results might vary based on your security requirements and organizational standards.&lt;/p&gt;
+&lt;h2 id="measurable-impact"&gt;Measurable impact&lt;/h2&gt;
+&lt;p&gt;Across the migration program, this framework delivered the following results. These metrics reflect this specific implementation. Your results might vary based on application complexity, team size, and organizational requirements.&lt;/p&gt;
+&lt;ul&gt;
+ &lt;li&gt;&lt;strong&gt;IaC development time reduced from weeks to minutes:&lt;/strong&gt; from 3–4 weeks per application to minutes of automated generation (based on internal project tracking data).&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;Pattern consistency applied across waves:&lt;/strong&gt; no wave can deviate from the approved IaC patterns baseline.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;Security compliance:&lt;/strong&gt; verified automatically at each deployment, with a complete audit trail requiring zero manual effort.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;Architecture-to-deployment fidelity improved:&lt;/strong&gt; the agent interprets the diagram, and the IaC realizes it as designed.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;On-demand portfolio reporting&lt;/strong&gt; across over 300 applications with precise metrics and zero manual aggregation.&lt;/li&gt;
+ &lt;li&gt;&lt;strong&gt;Wave team onboarding improved:&lt;/strong&gt; teams upload documents and the agents produce the IaC and the reports.&lt;/li&gt;
+&lt;/ul&gt;
+&lt;h2 id="cost-considerations"&gt;Cost considerations&lt;/h2&gt;
+&lt;p&gt;Running this pattern adds cost in a few predictable places. Foundation model tokens usually dominate, because intake and IaC generation push documents, policies, and architecture context through a model and return generated code. Amazon Bedrock AgentCore bills on consumption. Runtime charge…
+&lt;p&gt;Across a 300+ application portfolio the agents run for the length of the migration program rather than as a single job, so treat this as a running cost that tracks wave activity. Token volume follows document size and tool-call count more than application count, so a pilot wave gives you a …
+&lt;h2 id="clean-up-resources"&gt;Clean up resources&lt;/h2&gt;
+&lt;p&gt;To avoid ongoing charges after you finish testing the framework, remove the resources that you created:&lt;/p&gt;
+&lt;ul&gt;
+ &lt;li&gt;Delete the agents from AgentCore runtime, then remove the Gateway targets and the Gateway.&lt;/li&gt;
+ &lt;li&gt;Delete the AgentCore memory resources that hold session state and shared context.&lt;/li&gt;
+ &lt;li&gt;Delete the guardrail, the Policy in AgentCore definitions, and the IAM roles created for the agents.&lt;/li&gt;
+ &lt;li&gt;Delete the CloudWatch log groups that AgentCore Observability wrote to, if you no longer need the history.&lt;/li&gt;
+ &lt;li&gt;Delete any AWS DMS replication instances and endpoints provisioned for test migrations.&lt;/li&gt;
+&lt;/ul&gt;
+&lt;p&gt;Confirm in the Amazon Bedrock AgentCore console that no agent sessions remain active.&lt;/p&gt;

Diff display stops at 400 lines. The line counts above are from the whole diff. 42 lines shown here cut at 300 characters. The raw artifact at this commit is linked above.