AivexaNewsSearch
AI news for builders and product teamsChecked every hour

Making Amazon Quick enterprise-ready: Automated, auditable cross-account resource promotion

Collected Oct 5, 2026

AWS described the Quick Resource Migrator, a sample Model Context Protocol (MCP) server hosted on the Amazon Bedrock AgentCore runtime that automates cross-account promotion of Amazon Quick resources. The post says promoting chat agents, action connectors, knowledge bases, flows, and spaces from a development to a production AWS account has been a manual, error-prone chore, as enterprises typically run separate AWS accounts for development and production, sometimes with QA in between.

The migrator is resource-driven: users pick a resource type and select resources by id, by name, or all. It is idempotent, meaning re-runs converge on the same target state, and it copies permissions by calling the relevant Describe*Permissions API on each source resource and replaying the identical action list in the target, remapping principals to registered users in the target account.

The work is an upsert: resources that do not exist in the target are created, and existing ones are updated in place. Before updating an existing target resource, the migrator writes a versioned snapshot of that resource and its dependencies to a dedicated backup bucket; if the backup cannot be written, the update is aborted. A read-only preview reports what a run would create or update before committing.

Chat agents are recreated with custom instructions, identity, tone, starter prompts, and welcome message, with action connectors re-attached and remapped to the target account. Action connectors are recreated with their configuration; secret values are never read from the source, and connectors are created with placeholder credentials then re-authenticated in the target. Knowledge bases are registered in the target, their data source recreated, and permissions copied; for S3-backed knowledge bases the migrator provisions the target bucket and bucket policy, but S3 objects themselves are not copied. Flows are matched by name because flow IDs differ across accounts. Spaces are recreated and re-linked to their agents, connectors, and knowledge bases with ARNs remapped.

The server exposes five tools defined in server.py: preview_migration, migrate_resources, list_backups, get_backup, and restore_backup. The solution uses a three-account model. A central runner account hosts the MCP server, which assumes a read-only role in the source account and a read-write role in the target using AWS STS; the post states no long-lived credentials are stored. The runtime authenticates callers with a Cognito JWT and can run in VPC network mode. The full source code is available in the aws-samples repository.

Read at AWS Machine Learning Blog

Based on reporting from the original publisher. Visit the source for full context and later updates.

Publisher excerpt

Promoting Amazon Quick resources (agents, action connectors, knowledge bases, flows, and spaces) from a development to a production AWS account has been a manual, error-prone chore. This post shows how to automate cross-account promotion with an idempotent, auditable MCP server on Amazon Bedrock AgentCore.