Automated Remediation Workflow for AWS DevOps Agent Investigations Released
A new workflow uses AWS Lambda Durable Functions, Amazon EventBridge, and Amazon Bedrock to convert AWS DevOps Agent investigation summaries into pre-validated fixes, enabling on-call engineers to approve remediations with a single action.
What changed?
AWS has released a reference workflow that automates the remediation of issues discovered by AWS DevOps Agent. The workflow integrates AWS Lambda Durable Functions, Amazon EventBridge, and Amazon Bedrock. When AWS DevOps Agent completes an investigation, this solution analyzes the findings, proposes pre-validated fixes using a curated set of Lambda tools, and supports one-click human approval before mutating actions are applied. Read-only actions can be executed autonomously, while infrastructure-changing operations are held for explicit user confirmation.

Why does it matter to an everyday developer?
This workflow reduces manual diagnostic and remediation work for on-call engineers by automating routine fixes that follow a production incident. By keeping AWS DevOps Agent in observe-and-report mode, it avoids the risks of autonomous production changes, yet accelerates recovery by preparing safe, approved actions ahead of time. It makes incident remediation safer, faster, and less error-prone for teams responsible for operational reliability.
What can the developer do now?
Developers can adopt this workflow by deploying the AWS CDK project available in the official AWS sample repository. Prerequisites include an AWS account, the AWS CLI, Python 3.14 or later, AWS CDK, and an active AWS DevOps Agent space. The solution can be customized to fit team requirements, including extending reviewer input beyond approve or reject. AWS Bedrock is used to propose remediations, but only pre-approved Lambda tools from a curated allowlist are used for automation, supporting both safety and compliance practices.
- Review the workflow and code in the official AWS sample GitHub repository.
