Amazon Quick now supports an automated, auditable pathway for moving agents, connectors, knowledge bases, flows, and spaces from a development AWS account to a production account using a Model Context Protocol (MCP) server hosted on Amazon Bedrock AgentCore. This replaces the previous manual copy‑and‑paste process, giving engineers a repeatable, idempotent workflow that preserves configuration and permissions while providing versioned backups.
How the Automated Migration Works
The migrator leverages the Amazon Quick API—exposed through the QuickSight service—to perform create, read, update, and list operations on each resource type. A single call selects a resource (by ID, name, or all) and triggers an upsert: missing resources are created, existing ones are updated, and no delete actions are issued against the target account. Before any change, the current definition is written to an Amazon S3 bucket, creating a versioned backup that can be inspected or rolled back.
Resource‑by‑Resource Details
- Agents: Re‑instantiated with their custom instructions, identity, tone, starter prompts, and welcome message. Action connectors are re‑attached using the target account’s ARNs.
- Action connectors: Recreated with the same configuration but without copying secret values; placeholders are used and must be re‑authenticated in the target environment.
- Knowledge bases: The definition and permissions are copied; for S3‑backed sources a new bucket and bucket policy are provisioned, though the underlying documents are not transferred.
- Flows: Defined from the source flow JSON. Because flow IDs differ across accounts, matching is performed by name; a same‑named flow is updated, otherwise a new flow is created.
- Spaces: Recreated and linked to the migrated agents, connectors, and knowledge bases, with all ARNs remapped to the target account.
Architectural and Operational Implications
Deploying the MCP server introduces a new component in the architecture: a Bedrock AgentCore runtime that must have cross‑account permissions to invoke the Quick API in both source and destination accounts. The backup bucket adds a storage dependency that should be secured with appropriate bucket policies and lifecycle rules. Because the process is idempotent, it can be integrated into CI/CD pipelines, enabling automated promotion as part of a release workflow.
From an operations perspective, the read‑only preview mode allows teams to validate the exact set of creates and updates before committing, reducing the risk of unintended changes. Versioned backups provide an audit trail and a rollback point, aligning with governance requirements for regulated environments.
Security Considerations
Permissions attached to each Quick resource are copied verbatim, so the target account must have compatible IAM policies to accept them. Secret values for action connectors are never read from the source; instead, placeholder credentials are created, requiring a manual or automated re‑authentication step in the target account. The S3 backup location must be protected against unauthorized access, as it contains full resource definitions.
Related CloudNinjas coverage: AWS.
What This Means For Practitioners
Teams can replace a fragile, manual promotion process with a scripted, auditable workflow that fits into existing DevOps tooling. Before adoption, verify that cross‑account roles grant the necessary Quick API actions, secure the backup bucket, and plan for connector credential re‑creation. Once in place, the migration can be run repeatedly without side effects, providing a reliable path from development to production for all Amazon Quick assets.



