MikhbarMIKHBAR
Artificial Intelligence

Automate Remediation with AWS DevOps Agent and Bedrock

A new architectural pattern combines autonomous incident triage with pre-validated remediation steps to help engineers resolve production issues quickly and securely.

Automate Remediation with AWS DevOps Agent and Bedrock

Bridging Incident Diagnosis and Remediation

Reducing the time between incident detection, investigation, and remediation remains a critical priority for engineering teams running production workloads. When an issue occurs, on-call engineers typically need to diagnose problems across multiple application components, identify root causes, and apply fixes under high-pressure conditions. While the [AWS DevOps Agent] can autonomously triage incidents all day using correlated metrics, logs, and topologies to provide root cause analysis, organizations often maintain observability tools in an observe-and-report mode to retain control over production changes.

To bridge the gap between diagnosis and safe execution, technical guides demonstrate how to integrate [Amazon Bedrock], [Amazon EventBridge], and durable execution capabilities to transform investigation summaries into pre-validated fixes. This approach aims to reduce mean time to resolution while keeping human oversight central to mutating actions.

Architecture diagram showing AWS DevOps Agent sending an investigation-completed event to Amazon EventBridge, which triggers an AWS Lambda function that invokes an AWS Lambda durable function; the durable function calls
Image related to the report from AWS Machine Learning Blog · Source: AWS Machine Learning Blog

Orchestrating Workflows with Durable Functions

Building resilient multi-step applications requires robust state management and error recovery. Utilizing [AWS Lambda Durable Functions] allows developers to construct AI workflows that can run for up to one year without custom state management code. These functions automatically checkpoint progress and recover from interruptions while maintaining reliable execution during long-running tasks.

AWS DevOps Agent console with a prompt asking what is happening with the devops-agent-timeout function
Image related to the report from AWS Machine Learning Blog · Source: AWS Machine Learning Blog

Step-by-Step Remediation Workflow

The automated workflow begins when the diagnostic agent completes an investigation and emits an event containing symptoms, findings, and root cause analysis. [Amazon EventBridge] receives this event and invokes the initial Lambda function, which packages the investigation summary and passes it to the durable orchestrator function.

Next, [Amazon Bedrock] analyzes the context and reviews a curated allowlist of approved remediation tools. For read-only operations, the orchestrator executes tools autonomously. For actions that modify infrastructure state, the workflow suspends execution to wait for a human approval signal before proceeding.

AWS DevOps Agent investigation in progress, correlating Amazon CloudWatch metrics, logs, and the function configuration
Image related to the report from AWS Machine Learning Blog · Source: AWS Machine Learning Blog

Maintaining Safety and Control with Human Approval

To keep automated actions safe and auditable, the system enforces a strict allowlist where each tool is a purpose-built function handling a specific task. By distinguishing between read-only and mutating operations, the architecture ensures that risky changes pause execution until an engineer reviews the pre-validated plan. The orchestrator checkpoints its progress during this pause, consuming no compute resources until the approval signal is received.

CloudWatch log group showing the parsed investigation summary with symptoms, root causes, contributing causes, and investigation gaps
Image related to the report from AWS Machine Learning Blog · Source: AWS Machine Learning Blog

Deployment and Setup Options

Teams can deploy the entire solution architecture using the [AWS Cloud Development Kit]. Prerequisites include configuring the [AWS Command Line Interface] and optionally utilizing specialized agent toolkits to execute natural language prompts for incident simulation and stack deployment.

Sources

Continue chronologically

Related entity coverage