AWS releases open-source MCP server to automate cross-account promotion of Amazon Quick agents
AWS has published the Quick Resource Migrator, a sample MCP server on Amazon Bedrock AgentCore that promotes Amazon Quick resources between AWS accounts in a single tool call. It is idempotent, never deletes from the target, and writes versioned S3 backups before every update.
AWS has published the Quick Resource Migrator, a sample Model Context Protocol (MCP) server that promotes Amazon Quick resources from one AWS account to another in a single tool call. The server runs on Amazon Bedrock AgentCore runtime, and the code is available in the aws-samples repository. This is a reference implementation, not a new managed Amazon Quick feature.
The problem it targets
Amazon Quick is described by AWS as its agentic AI companion for work. Teams build chat agents, action connectors (Slack, Jira and others), knowledge bases, flows and spaces in a development account. According to AWS, there is no native one-click way to promote those resources to QA or production accounts. Teams currently rebuild each resource by hand: recreating agents with the same instructions and starter prompts, re-attaching connectors, re-granting permissions, and reprovisioning the S3 bucket, bucket policy and data source behind each knowledge base.
The migrator relies on the fact that these resources are managed through the Amazon Quick API, part of the Quick Sight API surface. The API covers create, read, update, delete and list operations, permissions included.
How it works
- Selection: Choose a resource type (agent, connector, knowledge base, flow or space), then select by id, by name, or all. Migrating a space brings its linked resources across.
- Upsert behavior: The server describes the target first, then creates or updates. Re-running a migration converges on the same state rather than creating duplicates.
- No deletes: The migrator never issues a delete against the target.
- Preview: A read-only mode reports what a run would create or update before it commits.
- Permissions: The server calls the relevant Describe*Permissions API on each source resource and replays the same actions in the target, remapping principals to registered users there.
- Backups: Before updating any existing target resource, it writes a versioned snapshot of the resource and its dependencies to a dedicated S3 backup bucket. If the backup fails, the update is aborted. A restore tool can roll a resource back to an earlier version.
What does and doesn't move
- Agents: Instructions, identity, tone, starter prompts and welcome message are recreated. Action connectors are re-attached and remapped to the target account.
- Action connectors: Configuration is recreated. Secret values are never read from the source. Connectors are created with placeholder credentials and must be re-authenticated in the target.
- Knowledge bases: The knowledge base is registered, its data source recreated and permissions copied. For S3-backed knowledge bases, the target bucket and bucket policy are provisioned. The documents themselves are not copied.
- Flows: Flow IDs differ across accounts, so flows are matched by name. A same-named flow is updated, otherwise a new one is created.
- Spaces: Spaces are recreated and re-linked to agents, connectors and knowledge bases, with ARNs remapped. Linked resources must be migrated first so the target ARNs resolve.
Architecture and security
The design uses three accounts. A central runner account hosts the MCP server on AgentCore runtime. The server uses AWS STS to assume a read-only role in the source account and a read-write role in the target account, so no long-lived credentials are stored. Callers authenticate with an Amazon Cognito JWT (client-credentials grant, scope invoke). The runtime can run in VPC network mode. Any MCP-compatible client can drive it, including Amazon Quick itself.
Pricing is not disclosed in the post. Costs would come from the underlying AWS services (AgentCore runtime, S3, Cognito, CloudWatch Logs), and the source excerpt does not give figures.
What this means
The post shows a gap in agent platforms: building an agent is easy, but moving it through dev, QA and production is not. AWS is filling that gap with sample code rather than a built-in promotion feature, so enterprises must deploy and maintain the migrator themselves.
The design choices are what regulated teams look for. These include additive-only operations, mandatory pre-update backups, a dry-run preview, and replayed permissions in place of hard-coded ones. Two limits remain. Connector credentials need manual re-authentication, and knowledge base documents are not copied, so a promotion is not a complete environment clone. The post also shows MCP and AgentCore being used for infrastructure operations as well as end-user agents.
Related Articles
AWS adds managed Web Search to Claude Desktop via Bedrock AgentCore Gateway in three Regions
AWS published a walkthrough for connecting Claude Desktop on Amazon Bedrock to a managed, MCP-compatible Web Search capability through Amazon Bedrock AgentCore Gateway. According to AWS, the search is backed by an Amazon web index spanning tens of billions of documents, and query traffic stays within AWS infrastructure. Web Search is available in three AWS Regions; pricing is not disclosed in the post.
AWS details ambient agent pattern on Bedrock AgentCore: S3 events trigger jobs, one ask_human tool pauses for approval
AWS published a reference implementation for ambient agents on Amazon Bedrock AgentCore. S3 uploads or scheduled events create jobs that an agent runs, pausing for human input through a single ask_human tool. Each agent turn is capped at the 15-minute Lambda timeout.
Pi 1.0 agent harness goes stable; Pi Durable ports it to TypeScript with crash-resumable state
Pi, the minimalist agent harness now under Earendil, has reached version 1.0. A companion release, Pi Durable, ports it to TypeScript and externalizes all stateful components so agents can resume after crashes. Pricing and licensing were not disclosed in the source.
Amazon open-sources Strands Decider 2B, a small decision model built on a Qwen3.5-2B base
Amazon Web Services has released Strands Decider 2B, an open-source model that chooses among pre-decided options and returns a confidence score instead of generating text. It is inspired by TypeSafe's Jev and is small enough to run locally. Amazon says it briefly topped the Jevbench ranking for models of its size.
Comments
Loading...