Enterprise developers managing AI solutions often face a significant challenge: promoting validated AI agents and their associated resources from development to production environments. This process, if done manually, is prone to errors, time-consuming, and difficult to audit. The new Quick Resource Migrator, a sample Model Context Protocol (MCP) server hosted on Amazon Bedrock AgentCore, addresses this by automating the cross-account promotion of Amazon Quick resources, ensuring consistency and auditability.
Amazon Quick is an agentic AI companion for work, enabling users to build agents that can reason over data, utilize action connectors, and complete multi-step tasks. These solutions are composed of chat agents, action connectors, knowledge bases, and spaces. In typical enterprise setups, development, quality assurance (QA), and production environments often reside in separate AWS accounts. Moving these intricate agentic components between accounts has historically been a manual process, requiring teams to painstakingly recreate each resource, re-attach connectors, re-grant permissions, and reprovision underlying services like Amazon Simple Storage Service (S3) buckets.
How Automated Promotion Streamlines Workflows
The core of the problem lies in the manual recreation of resources. Rebuilding agents with identical instructions, re-linking action connectors, and reconfiguring knowledge bases for each environment introduces opportunities for discrepancies and undermines governance. This manual effort is slow and can easily lead to subtle misconfigurations that are difficult to trace and correct.
The Amazon Quick API, part of the Amazon Quick Sight API surface, provides programmable access to the full resource lifecycle—create, read, update, delete, and list operations for spaces, agents, action connectors, knowledge bases, and flows. This programmability is the foundation for governed promotion. Instead of manual recreation, the API allows for reading a resource and its permissions from a source account and reapplying them precisely in a target account. The Quick Resource Migrator leverages these API operations to compose a repeatable workflow that adds or updates resources without issuing deletions on the target, making it safe for re-runs.
The Quick Resource Migrator: A Deep Dive
The Quick Resource Migrator is designed as an upsert mechanism: if a resource doesn't exist in the target account, it's created; if it already exists, it's updated in place. Every update is safeguarded by a versioned backup written to Amazon S3 before any changes are committed, ensuring a full history for review and rollback. A read-only preview feature allows users to see exactly what would be created or updated before committing to the migration. The migration itself runs on Amazon Bedrock AgentCore, enabling it to be driven from Amazon Quick or any MCP-compatible client.
What Gets Migrated
The migrator allows for resource-driven selection, meaning users can choose a specific resource type (agent, connector, knowledge base, flow, or space) and select resources by ID, name, or all. This granular control ensures flexibility in migration strategies. For instance, migrating a space automatically brings its linked resources along.
Chat agents are recreated with their custom instructions, identity, tone, starter prompts, and welcome messages, with their action connectors re-attached and remapped to the target account. If a space is migrated, its agents are automatically re-linked.
Action connectors are recreated with their configurations. It's important to note that secret values are never read from the source; connectors are created with placeholder credentials and require re-authentication in the target environment.
Knowledge bases are registered in the target account, their data sources recreated, and permissions copied. For S3-backed knowledge bases, the migrator also provisions the target bucket and its bucket policy, though the S3 objects (documents) themselves are not copied, allowing for separate data management strategies.
Flows are recreated from their definitions. Since flow IDs differ across accounts, they are matched by name; a same-named target flow is updated, or a new one is created. Flow permissions are also copied.
Spaces are recreated and re-linked to their associated agents, connectors, and knowledge bases, with Amazon Resource Names (ARNs) remapped to the target. It's recommended to migrate linked resources first to ensure target ARNs resolve correctly.
Key Design Principles
The migrator adheres to several crucial design principles. Resource-driven selection provides fine-grained control over what is migrated. Permission fidelity is maintained by calling relevant Describe*Permissions APIs on source resources and replaying identical actions in the target, remapping principals to registered users.
Idempotency ensures that re-running a migration converges on the same state without creating duplicates or failing. Least privilege and isolation are upheld with a read-only source role and a target role containing only necessary actions. The runtime authenticates callers with a Cognito JSON Web Token (JWT) and can operate in a virtual private cloud (VPC) network mode for enhanced security.
Safe, reversible updates are guaranteed through versioned snapshots of resources and their dependencies to a dedicated backup bucket before any updates. If a backup cannot be written, the update is aborted. A restore tool can also roll any resource back to an earlier version.
Architectural Overview
The solution employs a three-account model. A central runner account hosts the MCP server on Amazon Bedrock AgentCore runtime. This server assumes read-only roles in the source account and read-write roles in the target account using AWS Security Token Service (STS), eliminating the need for long-lived credentials. This distributed architecture enhances security and compliance, critical for enterprise environments.
This automated promotion mechanism for Amazon Quick resources is a significant step forward for enterprises looking to deploy AI agents consistently and securely across their AWS environments, addressing a key pain point in the lifecycle of AI model deployment and management.