Skip to content
Apixo
Blog
news· 3 min read· via AWS Machine Learning

How Agentic AI on Amazon Bedrock AgentCore Accelerates Enterprise Cloud Migrations

An enterprise cloud migration of 300+ applications used a four-agent pattern on Bedrock AgentCore to reduce IaC development times from weeks to minutes.

How Agentic AI on Amazon Bedrock AgentCore Accelerates Enterprise Cloud Migrations

Large-scale enterprise cloud migrations often face tight timelines and massive workloads, leaving organizations to balance managed cloud services with custom automation. During a migration program covering over 300 applications with a strict fiscal year deadline, a specialized four-agent pattern was deployed to automate complex tasks. According to internal project tracking data, this agentic AI approach reduced the time required to write infrastructure as code (IaC) from three to four weeks per application down to just minutes.

The Four-Agent Migration Architecture

This pattern does not replace existing AWS migration tools but operates as a hybrid alongside them. While AWS Transform manages the broader migration and modernization of workloads like mainframe, .NET, and application servers, and AWS Database Migration Service (AWS DMS) handles the database tier, the custom AI agents address organization-specific requirements.

The framework uses the Strands Agents SDK and runs on Amazon Bedrock AgentCore, utilizing Model Context Protocol (MCP) tools exposed by the AgentCore Gateway. The system coordinates four distinct agents across the migration and operations lifecycle:

  • Intake Agent: This agent reads architecture documents, questionnaires, and dependency records via MCP tools to define the target state architecture and mapping.
  • IaC Agent: It ingests the Intake Agent's outputs and automatically generates IaC that composes approved internal modules.
  • Migration Intelligence and Governance Agent: It connects to Jira, Confluence, and Webex to automate portfolio reporting, track progress, and run well-architected assessments.
  • SRE Agent: Operating after the workload cutover, this agent handles post-migration monitoring and proactive remediation.

The agents share context and persist progress data through Amazon Bedrock AgentCore memory, allowing a seamless handoff between stages without manual intervention.

Security, Governance, and Policy Integration

A critical element of this architecture is its embedded security framework. The system ensures that no agent acts autonomously on production systems without explicit human-in-the-loop approval.

To enforce organizational standards, the security office curates a versioned policy set. An AWS Lambda function serves this policy document, which is exposed via the AgentCore Gateway as an MCP tool called get_policies. When generating code, the IaC Agent requests only the policies relevant to the specific resource types in its current migration wave.

Furthermore, AgentCore Policy evaluates each tool call against Cedar rules to calculate the scope of potential changes and prevent unauthorized operations. AgentCore Identity manages authentication using scoped AWS Identity and Access Management (IAM) roles, ensuring least-privilege access. Because secrets are resolved at runtime from a centralized provider, sensitive credentials never pass through the agent's prompt context.

What it means for developers

For developers tasked with migrating legacy systems, this agentic approach shifts their primary role from manual code generation to high-level architecture review. Instead of spending weeks manually composing approved internal infrastructure modules, developers can rely on the IaC Agent to output fully compliant configurations, automated test cases, and deployment runbooks directly into repositories like GitLab, Bitbucket, or AWS CodeCommit.

This pattern highlights how Model Context Protocol tools and multi-agent orchestration can streamline complex developer workflows. For teams looking to build and test similar custom agentic systems, developers can try top AI models cheaply through one API at https://apixoai.online, simplifying the process of evaluating different foundation models for reasoning and code generation.

Ultimately, this framework demonstrates that combining managed cloud services with highly tailored, MCP-enabled AI agents can eliminate the engineering bottleneck of enterprise cloud migrations while maintaining strict compliance and safety standards.


Source: Scaling cloud migrations with agentic AI on Amazon Bedrock AgentCore | Amazon Web Services — AWS Machine Learning. Written by the Apixo team from that report.

#ai-news#aws#generative-ai#cloud-migration#iac#devops
Try it with your own tools

One key for Claude, GPT, GLM, DeepSeek and more. Pay per token with crypto.

Get your API key

Keep reading