Cloud & Infrastructure News: AWS Well-Architected Agent, Kiro Workflows, Spanner Queues and a Managed gcloud MCP Server, 2026-10-10
cloud

Cloud & Infrastructure News: AWS Well-Architected Agent, Kiro Workflows, Spanner Queues and a Managed gcloud MCP Server, 2026-10-10

5 min read

AWS Well-Architected Agent (Preview) Turns Architecture Reviews Into a Continuous Service

AWS announced the Well-Architected Agent in public preview on October 1. It analyses resource configurations, utilisation metrics and application topology in your accounts and checks them against Well-Architected best practices for more than 65 AWS services. Recommendations cover cost, security, performance and resilience, and are ranked by impact and effort against business goals you declare up front, with explicit trade-offs across pillars. It can also review Terraform, CloudFormation or CDK projects before deployment.

Findings come at three levels: individual resources (with dollar impact where relevant), consolidated application-scoped findings, and architecture-wide patterns with suggested IaC changes. Remediation is offered as console walkthroughs, updated IaC templates or AWS CLI commands. Setup means provisioning customer-managed IAM roles for read access and creating an agent profile listing the accounts, Regions, pillars and goals; first recommendations arrive within 24 hours.

The agent is reachable from the Well-Architected console, via APIs, and through the AWS MCP Server and plugins for AI coding tools, so a coding agent can pull architecture findings into the same session where it edits IaC. The preview runs in US East (N. Virginia), US East (Ohio) and US West (Oregon) but can onboard workloads from any commercial Region. It is delivered by AWS Support and requires a Support plan. AWS cautions that generated recommendations may contain errors and should be validated before applying.

Read more — AWS News Blog


Kiro Workflows: Model-Planned Multi-Agent Graphs Across IDE, CLI and Web

AWS's Kiro introduced workflows on September 30, letting it run complex, multi-step tasks across several agents with less supervision. The model plans which agents do the work and in what order, and the Kiro runtime executes that plan as a graph of steps, sequences, parallel branches and loops (for example, "repeat until the review approves"). Each step runs in its own session with fresh context, so a reviewer step checks the code without inheriting the coder's reasoning. Results flow between steps via double-brace template variables.

Workflows run in the background while you keep chatting. Step sessions can be paused, resumed or steered, steps can send questions back to the main session, and Kiro can revise a plan mid-run without discarding completed work. Useful plans can be saved as reusable JSON or YAML "recipes" and stored in Kiro Web's cloud configuration for reuse across projects and devices. Workflows can also run in cloud sessions started from the CLI or IDE. The Kiro team says it built most of the workflow runtime itself using workflows, with parallel workflows in separate Git worktrees.

The feature is opt-in (Workspace Configuration → Workflows, or kiroAgent.workflows.enabled) and available in Kiro IDE, CLI and Web on the same runtime. It uses the normal Kiro credit model, so larger graphs cost proportionally more.

Read more — Kiro


Spanner Queues: Transactional Messaging Built Into the Database

Google Cloud made Spanner queues generally available on October 3. They are native, transactional message queues defined with CREATE QUEUE in GoogleSQL and stored as first-class relational tables, optionally interleaved in a parent table. Enqueuing is just an INSERT inside the same read-write transaction as your state change, so "update the order to REFUND_APPROVED" and "schedule the EXECUTE_REFUND task" commit or fail together, removing the need for a separate outbox table and relay process.

Consumers pull with a long-lived streaming SQL read (SELECT ... FROM RECEIVE_OrderAgentTasks(max_duration => '20m')), which returns a SpannerLeaseToken and lease expiry per message. They can extend leases with RENEWLEASE_..., and acknowledge by deleting the row in the same transaction that checkpoints results. Messages can be delayed with a DeliverTime column, which makes timers like "escalate if not approved in 72 hours" a single insert that can later be cancelled atomically.

Google's guidance pairs DELETE ... ASSERT_ROWS_MODIFIED 1 with the task ID as an external idempotency key: if a stalled worker's lease expires and another worker finishes the task first, the stale worker's acknowledgment fails at the statement level instead of overwriting state. Combined with at-least-once delivery and at-most-once acknowledgment, that yields effectively-once processing. Google pitches queues for agent decide-and-act steps, human-in-the-loop approvals and A2A handoffs, as well as classic order and notification pipelines. Pricing isn't covered in the announcement.

Read more — Google Cloud Blog


Google Cloud Ships a Managed gcloud MCP Server and Takes Data Agent Kit GA

On October 1 Google Cloud previewed a remote, managed MCP server for the Google Cloud CLI, exposing two tools: run_gcloud_command and run_bq_command. Commands execute in an isolated, network-restricted sandbox on Google Cloud with no ambient credentials, so agents (including web-hosted ones) don't need the CLI installed locally. Every command runs with the caller's own IAM permissions and organisation policies. Authentication is keyless Agent Identity on Google Cloud runtimes or OAuth 2.0 elsewhere, and callers need roles/mcp.toolUser. Invocations can be screened by Model Armor and written to Data Access audit logs. The announcement does not describe read-only modes or approval gates, so scope IAM grants carefully before pointing an agent at production.

Separately, Data Agent Kit reached GA on September 30. It is a free bundle of MCP tools covering more than 15 Google Data Cloud services (BigQuery, Spanner, AlloyDB, Cloud SQL, Bigtable, Managed Spark, dbt, Dataform, Airflow and more) plus open-source Google-authored skills for tasks like optimising BigQuery SQL and designing Bigtable row keys. GA adds BigQuery Graph skills, full Bigtable support and a skill for federating Iceberg catalogs with AWS Glue and Databricks Unity Catalog.

Data Agent Kit installs as a plugin for Claude Code (claude plugin install data-agent-kit-starter-pack@claude-plugins-official), Codex CLI and Antigravity, or as an extension for VS Code, Cursor and other Open VSX editors, and comes pre-installed in Cloud Shell and Cloud Workstations. There is no extra charge beyond the underlying services.

Read more — Google Cloud Blog


Stanislav Lentsov

Written by

Stanislav Lentsov

Software Architect

You May Also Enjoy