Skip to content

enterprise blueprint: migrate Agent Registry before 2026-09-17 preview cutoff #29

Description

@dgallitelli

Summary

enterprise-agentic-ai-platform-blueprint still provisions and consumes Agent Registry through the preview bedrock-agentcore-control / bedrock-agentcore Registry APIs.

AWS moved Agent Registry to the separate GA agent-registry-control and agent-registry namespaces on August 6, 2026. The transition guide says support for the preview APIs ends on September 17, 2026, and the FAQ confirms that endpoints, SigV4 service name, IAM actions, ARNs, request/response schemas, and stored Registry data are separate and are not migrated automatically.

I checked current main at e6cf0182e4c0484de719fc259e41c40db409805c. This report is scoped to Registry operations only; other AgentCore Runtime, Gateway, Memory, Identity, and Policy calls should remain on their AgentCore service namespaces.

Evidence in current main

  • PlatformRegistryConstruct calls createRegistry, updateRegistry, and deleteRegistry through service: 'bedrock-agentcore-control'.
  • RegistryRecordConstruct uses the same preview service for record creation, approval, reads, and deletion.
  • registry-record-spec.ts still models preview descriptorType values (MCP, A2A, AGENT_SKILLS, CUSTOM) and renders preview inlineContent descriptor shapes. GA uses recordType (MCP, AGENT, SKILL, CUSTOM) and different descriptor/data shapes.
  • RegistryConsumerGrant grants preview bedrock-agentcore:*Registry* actions.
  • SCP-11 protects preview IAM actions and the preview arn:aws:bedrock-agentcore:*:*:registry/* resource shape.
  • The workstream deploy-time validator hardcodes the preview endpoint and signing service: bedrock-agentcore-control.<region>.amazonaws.com, with the request assembled here.
  • There are no agent-registry-control, agent-registry:*, or GA recordType references under this blueprint.

PR #16 already completed the preview-to-GA migration for Agentic-ai-self-service, but its changes are confined to that subdirectory.

Expected impact

After the preview cutoff, Registry create/update/delete/read/search operations in the enterprise blueprint are expected to fail or become unsupported. Existing preview registries and records also need an explicit data migration because the GA service does not reuse the preview data store.

The affected paths include:

  • platform Registry provisioning and record lifecycle;
  • workstream subscription validation during deployment;
  • developer and runtime discovery permissions;
  • SCP enforcement around Registry mutation;
  • any existing deployment whose records remain only in the preview Registry.

Suggested remediation

  1. Move Registry control-plane calls to agent-registry-control and discovery/search calls to agent-registry.
  2. Replace preview IAM actions and Registry ARN patterns with agent-registry:* equivalents.
  3. Migrate schemas from descriptorType / preview descriptors to GA recordType and descriptor/data contracts, including A2A → AGENT and AGENT_SKILLS → SKILL.
  4. Update the inline workstream validator to the GA endpoint and SigV4 signing name.
  5. Prefer the GA CloudFormation resources AWS::AgentRegistry::Registry and AWS::AgentRegistry::RegistryRecord where they cover the required lifecycle; otherwise update the custom resources to the GA SDK/API.
  6. Provide an upgrade path for existing preview resources using AWS's migration sample.
  7. Add a regression check that rejects Registry-specific bedrock-agentcore:*Registry* actions, preview descriptor fields, and preview Registry endpoints while allowing unrelated AgentCore APIs to remain unchanged.

Verification performed

Source inspection only; no repository code or AWS deployment was run.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions