AivexaNewsSearch
AI news for builders and product teamsChecked every hour

Automate remediation post AWS DevOps Agent investigation

Collected Oct 7, 2026

AWS detailed an automated remediation workflow that follows an AWS DevOps Agent investigation, using Amazon EventBridge, AWS Lambda Durable Functions, and Amazon Bedrock. AWS DevOps Agent, which performs root cause analysis and recommends actions, typically stays in observe-and-report mode and does not modify production resources.

In the workflow, AWS DevOps Agent completes an investigation and emits an event with symptoms, findings, and root cause analysis. An EventBridge rule triggers the devops-agent-trigger Lambda function, which fetches the investigation summary from the AWS DevOps Agent journal and invokes the devops-agent-remediation-durable durable function. That function sends investigation context to Amazon Bedrock, which identifies tools from an allowlisted set of Lambda functions and proposes remediation actions.

Read-only operations run autonomously, while mutating actions suspend execution for human approval. AWS Lambda Durable Functions checkpoint progress, pause without consuming compute resources, and resume after receiving a callback signal. The implementation accepts an approve or reject signal, and because the callback takes arbitrary JSON, AWS said it can be extended to carry parameter overrides or reviewer observations.

Prerequisites include the AWS CLI, Python 3.14 or later, the AWS CDK, and an active AWS DevOps Agent space. Kiro with the Agent Toolkit for AWS is optional. The CDK provisions three Lambda functions (devops-agent-trigger, devops-agent-remediation-durable, and devops-agent-lambda-tool) plus an EventBridge rule, with IAM permissions handled using least-privilege principles.

In a demonstration, a devops-agent-timeout function exceeded its timeout. AWS DevOps Agent identified the timeout as insufficient. Amazon Bedrock selected lambda_get_function_configuration, a read-only tool, which confirmed a 3-second timeout, then proposed increasing it to 30 seconds via lambda_update_function_configuration. Because that is a mutating action, the durable function suspended for approval; after approval, the timeout was updated to 30 seconds. AWS noted the investigation summary and proposed remediation are AI-generated and should always be reviewed before approval.

Read at AWS Machine Learning Blog

Based on reporting from the original publisher. Visit the source for full context and later updates.

Publisher excerpt

AWS DevOps Agent can diagnose production incidents but is kept in observe-and-report mode so it does not change resources directly. This post shows how to use AWS Lambda Durable Functions, Amazon EventBridge, and Amazon Bedrock to turn its investigation summaries into pre-validated fixes an on-call engineer can approve with a single action.