Table of Contents
TL; DR
DevOps Agent is an read-only AI agent that focuses on investigating incidents, finding root causes, and providing mitigation plans.
What Is DevOps Agent?
In 2025 re-invent, AWS released three new featers in Frontier Agent: Kiro Autonomous Agent, Security Agent, and DevOps Agent.
AWS DevOps Agent acts as an autonomous on-call engineer to investigate incidents, find root causes, and provide mitigation plans. Users can interact with it on the webapp. At this moment (Jan 13, 2026), DevOps Agent is still in preview and available in AWS us-east-1 region. You can try it freely while the pricing is not announced.
What DevOps Agent CAN Do?
Integrations
- Built-in integrations
- Telemetry: Amazon CloudWatch, Dynatrace, Datadog, New Relic, and Splunk
- Pipeline: GitHub, GitLab.
- Communication: ServiceNow, Slack
- Custom MCP servers
When connecting to a GitHub account, you can specify a GitHub repo.
With custom MCP servers, you can connect to your own custom telemetry sources, like Grafana., but they are read-only.

Functions
- Monitor and investigate incidents
- Detect CloudWatch alarms
- Analyze logs and metrics
- Analyzing performance issues
- Find root causes of errors and write RCA (Root Cause Analysis) report
- Provide mitigation recommendations
- Track deployment impact
- Provide recommendations
- Suggest infrastructure improvements
- Recommend monitoring enhancements
- Identify capacity issues
What AWS DevOps Agent CANNOT Do
- Write or modify code
- Create pull requests
- Deploy code changes
- Access your GitHub repository to make changes
- Automatically fix bugs in your codebase
- Analyze a broken UI
Steps To Setup
You can follow the tutorial DevOps Agent Storylane, though some UI and flows are outdated.
Create An Agent Space

Enable Web App And Create A Role

Data Display
After creating the role and waiting for a while, the top resources will display without additional settings.

Best Practices To Grant Permissions
You can limit which AWS services the agent can access by modifying the IAM policies attached to
the agent’s roles. When creating custom policies, follow these best practices:
- Grant only read-only permissions – The agent needs to read resource configurations, metrics,
and logs during investigations. Avoid granting permissions that allow the agent to modify or
delete resources. This read-only limitation is crucial to prevent prompt injection attacks,
where malicious inputs could potentially trick the agent into executing destructive operations
on your infrastructure. - Limit to necessary services – Include only the AWS services that contain resources relevant to
your applications. For example, if your application doesn’t use Amazon RDS, don’t include RDS
permissions in the policy. - Use specific actions instead of wildcards – Instead of granting service:* permissions, specify
individual actions like cloudwatch:GetMetricData or ec2:DescribeInstances.
My Test Settings
- EC2 t2.micro x 1
- PostgreSQL x 1
- Django Site x 1
- CloudWatch alarms x 1
Analysis Results
I set a sensitive alarm threshold by CPUUtilization > 5. It helped me easily trigger the alarm and view the analysis results.




Advanced Questions
1. Is there a guardrail in DevOps Agent?
No
2. Can I customize the prompts?
You can add custom system instructions in runbooks.


3. Can DevOps Agents Block Malicious Attack Like DDoS?
Direct detection: ❌ No – Not designed for this
Indirect detection: ⚠️ Maybe – Can identify unusual traffic patterns and operational symptoms
DDoS mitigation: ❌ No – Cannot block or mitigate attacks
Investigation help: ✅ Yes – Can investigate operational impact after attack is detected
My Expectation
DevOps Agent can automatically fix bugs and create pull requests, but it still needs human review, approval, and deployment.
Last But Not Least
LLM is powerful enough now, you can feed the whold PDF (149 pages) to the Claude to answer any questions.






I appreciated the clear framing here. It connects well with practical web resources such as Lake Sipping.
This was a useful read, especially the practical framing. It fits naturally beside related web resources like 동물 랜덤 뽑기.
This was a useful read, especially the practical framing. It fits naturally beside related web resources like 시드 크래커.
The concrete examples make this easier to apply. Readers comparing related resources may also find Ghost Rider Movie Sequence useful in this context.
This is a useful reminder that quick visual experiments often need simple workflows. A tool like No More Room In Hell 2 Classes can fit that kind of lightweight editing context.
This was a useful read, especially the practical framing. It fits naturally beside related web resources like 동물 랜덤 뽑기.
References: Mirage Casino Erfahrungen
References: Wildz Casino Bonus
References: Lollybet Casino Sicherheit cse.google.co.id
References: Lollybet Casino Bonus