MikhbarMIKHBAR
Artificial Intelligence

Automating Cross-Account Amazon Quick Promotion

A new automated approach addresses the manual challenges of promoting Amazon Quick resources between development and production AWS accounts.

Automating Cross-Account Amazon Quick Promotion

The Challenge of Cross-Account Promotion

Amazon Quick functions as Amazon’s agentic AI companion built for work, allowing teams to build agents that reason over data, call action connectors, and execute multi-step tasks. However, moving these resources—including chat agents, action connectors, knowledge bases, flows, and spaces—from a development AWS account to a production account has historically been a manual and error-prone chore.

Enterprise environments typically segregate development, quality assurance, and production into separate AWS accounts. Previously, when teams validated resources in a development account, no native one-click promotion method existed, forcing engineers to manually recreate agents, re-attach action connectors, re-grant permissions, and reprovision underlying storage buckets.

Three-account architecture: a runner account hosts the MCP server on Amazon Bedrock AgentCore and assumes roles into the source and target accounts
Image related to the report from AWS Machine Learning Blog · Source: AWS Machine Learning Blog

Programmable Resource Architecture

Fortunately, Amazon Quick resources are fully programmable. Managed through the Amazon Quick API, which is part of the Amazon Quick Sight API surface, these components support full lifecycle management including create, read, update, delete, and list operations.

This programmable surface enables governed promotion. By reading resource configurations and permissions via the API, administrators can reapply them in target accounts with exact fidelity, executing repeatable workflows that only add or update resources without issuing destructive delete operations.

Quick App landing page with fields for source and target account IDs, resource type, and selector
Image related to the report from AWS Machine Learning Blog · Source: AWS Machine Learning Blog

Quick Resource Migrator Overview

The Quick Resource Migrator is a sample Model Context Protocol (MCP) server hosted on the Amazon Bedrock AgentCore runtime. It automates cross-account promotion in a single tool call, operating in a resource-driven manner where users can select specific resource types by ID, name, or choose all available items.

Developers seeking to implement this solution can examine the implementation details and full source code provided within the official aws-samples repository.

Additional migration options on the Quick App landing page
Image related to the report from AWS Machine Learning Blog · Source: AWS Machine Learning Blog

Resource Types and Selection Models

The migrator handles various resource categories uniquely. Chat agents are recreated with their custom instructions, tone, starter prompts, and welcome messages, with action connectors remapped to the target account. Action connectors are built using placeholder credentials due to security protocols, requiring re-authentication in the target environment.

Knowledge bases involve registering the resource in the target account, recreating data sources, and copying permissions. For Amazon S3-backed knowledge bases, the migrator provisions the target bucket and associated bucket policy while leaving the underlying S3 objects in place. Additionally, spaces bring their linked resources across seamlessly when migrated.

Confirmation view shown after choosing Confirm and migrate
Image related to the report from AWS Machine Learning Blog · Source: AWS Machine Learning Blog

Security, Idempotency, and Backups

To ensure enterprise-grade security and governance, the server operates on a three-account model. A central runner account hosts the MCP server on Amazon Bedrock AgentCore runtime, utilizing AWS Security Token Service (AWS STS) to assume a read-only role in the source account and a read-write role in the target account.

Furthermore, every update is protected by a versioned snapshot written to Amazon S3 before changes occur, ensuring that updates are fully auditable and capable of being rolled back using dedicated recovery tools if necessary.

Sources

Continue chronologically

Related entity coverage