AWSArchitecture

AWS Agent Registry Cutover: A UK Checklist Before the 17 September 2026 Namespace Shutdown

Agent Registry GA moved to the agent-registry namespace; bedrock-agentcore registry APIs shut on 17 Sep 2026. UK SRE cutover: endpoints, IAM, schema, migration tooling — with ~2 days left.

AQ
Ali Qaiser
AWS Certified | ServiceNow Architect | Enterprise AI Consultant
15 September 2026
8 min read
AWS Agent Registry Cutover: A UK Checklist Before the 17 September 2026 Namespace Shutdown
In brief

Agent Registry GA moved to the agent-registry namespace; bedrock-agentcore registry APIs shut on 17 Sep 2026. UK SRE cutover: endpoints, IAM, schema, migration tooling — with ~2 days left.

Key Takeaways
  • bedrock-agentcore registry namespace shuts 17 Sep 2026 — migrate to agent-registry or lose access.
  • Update endpoints (*.api.aws), IAM agent-registry:*, AgentRegistryFullAccess, SDK/CLI and EventBridge/CloudTrail sources.
  • Schema breaks: discoveryConfiguration, recordType, descriptors, search_discoverable_registry_records.
  • Keep workload identity under bedrock-agentcore; fix sync role trust to agent-registry.amazonaws.com.
  • 7-day emergency plan: inventory → IAM/trust → migrate → cut clients → verify events before shutdown.

~2 days left: cut over Agent Registry before the old namespace goes dark

On 31 August 2026, AWS positioned Agent Registry as generally available in the dedicated agent-registry namespace. If your estate still holds registries or records under the legacy bedrock-agentcore registry APIs, you are inside a hard migration window that closes on 17 September 2026. After that date the old registry namespace shuts down: you lose read/write access and any remaining data left behind.

This is a UK platform / SRE cutover checklist — endpoints, IAM, SDK/CLI, EventBridge/CloudTrail, schema changes, migration tooling and sync-role trust policies — with urgency appropriate to a deadline measured in days, not quarters.

Cloud AI infrastructureCloud AI infrastructure

What is changing (and what is not)

AreaChangeStay put
Registry service namespacebedrock-agentcore → agent-registry—
Endpoints*.amazonaws.com → *.api.aws hostnames for registry—
IAM action prefixbedrock-agentcore:* (registry actions) → agent-registry:*—
Managed policyReplace registry use of BedrockAgentCoreFullAccess with AgentRegistryFullAccess—
Workload identity / OAuth credential providers—Remain under bedrock-agentcore
Other AgentCore (Runtime, Gateway, Policy, Identity)—Not renamed by this cutover

Critical nuance: only Agent Registry moves. Do not blanket-replace every bedrock-agentcore permission — keep workload identity APIs on the old namespace when URL sync uses OAuth/IAM credentials.

Timeline that matters

DateMeaning
6 Aug 2026agent-registry namespace launch; dual access for existing registry customers; migration tooling available
31 Aug 2026GA / what's-new positioning for Agent Registry (plan as production-ready)
17 Sep 2026bedrock-agentcore registry namespace shutdown — migrate or lose access

New customers without pre-existing registries after 6 Aug already start on agent-registry. Existing estates that delayed migration now have a ~2-day fuse from this article's publish date (15 Sep 2026).

Surface-by-surface cutover map

Endpoints

PlaneOldNew
Databedrock-agentcore.{region}.amazonaws.comagent-registry.{region}.api.aws
Controlbedrock-agentcore-control.{region}.amazonaws.comagent-registry-control.{region}.api.aws

UK estates commonly run control and data paths in eu-west-1 (Ireland) and/or eu-west-2 (London) depending on residency design — update every hardcoded endpoint URL, VPC endpoint assumption and private DNS alias.

IAM

SurfaceOldNew
Action prefixbedrock-agentcore:... registry actionsagent-registry:...
Service principalbedrock-agentcore.amazonaws.comagent-registry.amazonaws.com
Registry ARNarn:aws:bedrock-agentcore:...:registry/...arn:aws:agent-registry:...:registry/...
Record ARN.../record/... under old NSsame path under new NS
Managed policyBedrockAgentCoreFullAccess (will not gain agent-registry:*)AgentRegistryFullAccess

Also update SCPs, permission boundaries, CI role policies and any IAM Conditions that match the old prefix.

Retain alongside new permissions when using URL sync with identity:

  • bedrock-agentcore:CreateWorkloadIdentity
  • bedrock-agentcore:GetWorkloadIdentity
  • bedrock-agentcore:DeleteWorkloadIdentity

SDK / CLI / quotas

SurfaceOldNew
Dataplane clientBedrockAgentCoreClientAgentRegistryClient
Control clientBedrockAgentCoreControlClientAgentRegistryControlClient
CLIaws bedrock-agentcore / bedrock-agentcore-controlaws agent-registry / agent-registry-control
Service Quotas codebedrock-agentcoreagent-registry (re-request custom quotas)

Observability

SurfaceOldNew
CloudTrail event sourcebedrock-agentcore.amazonaws.comagent-registry.amazonaws.com
EventBridge sourceaws.bedrock-agentcoreaws.agent-registry
CloudWatch namespaceAWS/BedrockAgentCoreAWS/AgentRegistry

EventBridge detail-types expand. Especially: registry ready events change from a long sentence (Registry State transitions from Creating to Ready) to short status strings such as Registry Ready. Record approval lifecycle gains multiple detail-types (Draft, Pending Approval, Approved, Rejected, Deprecated). Update SIEM parsers and automation rules before you cut reads to the new bus source.

Schema changes you must code for

This is not a rename-only migration. Application code that builds or parses registry payloads will break if you only swap endpoints.

Registry entity

  • authorizerType / authorizerConfiguration move under discoveryConfiguration
  • approvalConfiguration.autoApproval (boolean) → autoApprovalRules (enum array; "APPROVE_ALL" ≈ old true)

Registry records

Old conceptNew concept
Display-ish nameBecomes displayName; new required name is the dedup key
descriptorTypeRemoved; required recordType: AGENT | MCP | SKILL | CUSTOM
Nested descriptors + descriptorTypeFlat keyed descriptors (a2aAgentCard, mcpServer, agentSkillsDefinition, custom)
inlineContentdata
schemaVersion / protocolVersiondataSchemaVersion
Top-level sync configPer-descriptor source (only fromUrl supported in new NS)

Search / MCP tool rename: search_registry_records → search_discoverable_registry_records. List filters move to structured filters arrays; several List operations become POST-style list APIs. New browse APIs (ListDiscoverableRegistryRecords, BatchGetDiscoverableRegistryRecord) help catalog UX after cutover.

Data migration approach

AWS provides migration tooling (agentcore-samples) to extract, transform and load into the same account/region under the new namespace. Choose deliberately:

ProfileApproach
Small / one-shotRun migration tool from terminal or CloudShell
Parallel + incrementalManaged Glue/CDK path; full load then incremental at cutover
Active writersActive-active dual-write until confidence, then cut reads/writes

Verification minimum:

  1. Registry count match (list-registries).
  2. Per-registry record count match.
  3. Spot-check descriptor transforms (recordType, descriptors, source).
  4. App read/write smoke tests on new clients.
  5. EventBridge / CloudTrail rule hits on new sources.

Sync role trust policies (easy to miss)

If records synchronize with an IAM role credential type, update the role trust principal to agent-registry.amazonaws.com before live load. The migration tool does not assume the sync role; the service does asynchronously after create. Miss this and migrated records can land in CREATE_FAILED. Recovery: fix trust → delete failed record → re-load. OAuth / no-auth sync paths are unaffected by this specific trust change.

Platform notes UK teams ask about

  • Regions: Agent Registry availability includes major EU regions used by UK estates (plan explicitly for eu-west-1 / London designs). Confirm every account/region pair you actually use.
  • Auto-detect AgentCore Runtime / Gateway: registries can discover and catalogue runtime/gateway-backed agents — retest discovery after namespace cutover so catalogs do not silently empty.
  • RAM org sharing: if you share registries across accounts/OUs, re-validate share principals and consumer IAM against new ARNs.
  • MCP search tool rename: update agent tool manifests and Gateway tool lists the same day as the client cutover.

7-day emergency cutover plan (use now)

DayActionOwner
D0 (today)Inventory registries/records per account/region; freeze non-essential writes if possiblePlatform lead
D0Diff IAM/SCP/CI for bedrock-agentcore registry actions; draft agent-registry:* + AgentRegistryFullAccessSecurity IAM
D0–D1Patch endpoints, SDK clients, CLI scripts, Terraform/CDKSRE / App teams
D1Update EventBridge rules, CloudTrail Lake/SIEM parsers, CloudWatch dashboardsObservability
D1Fix sync role trust policies to agent-registry.amazonaws.comIAM
D1Run migration tool (full load); verify countsPlatform
D2 morningIncremental sync if dual-running; dual-read smoke testsSRE
D2Cut application traffic to agent-registry; disable old writersRelease manager
By 17 SepConfirm old namespace unused; document evidence for auditPlatform + Security

If you are already past D0 with no inventory, collapse to a war-room: inventory → IAM+trust → migrate → cut clients → verify events in that order. Schema code fixes that are incomplete will fail loudly — better than silent empty catalogs after shutdown.

Failure modes in the last 48 hours

FailureWhy it happens lateImmediate mitigation
Partial IAMCustom policies updated, SCPs notGrep org SCPs for bedrock-agentcore registry actions
Managed policy trapStill on BedrockAgentCoreFullAccessAttach AgentRegistryFullAccess; remove false confidence
Event rule silenceSource updated but detail-type still old sentenceMatch Registry Ready and record state prefixes
CREATE_FAILED syncTrust still on old principalFix trust, delete failed record, re-load
Identity over-editSomeone replaced all bedrock-agentcore actionsRestore workload identity permissions
Hardcoded ARNsSecrets, Parameter Store, ticketsSearch arn:aws:bedrock-agentcore and rewrite
Quota surprisesCustom limits left on old service codeRe-request under agent-registry

Run a single war-room checklist owner — split ownership is how dual namespaces linger past shutdown.

Acceptance tests before you call cutover done

  1. Create/list/get registry on agent-registry in each production region you use.
  2. Create a sample MCP and AGENT record with required name + recordType + new descriptors shape.
  3. Run discoverable search / MCP search_discoverable_registry_records from a non-prod agent.
  4. Confirm CloudTrail shows agent-registry.amazonaws.com for the test calls.
  5. Fire a record approval transition and prove EventBridge automation still ticks.
  6. Confirm Runtime/Gateway auto-detect still populates expected entries.
  7. Confirm RAM consumers (if any) can still read shared approved records.
  8. Confirm old namespace is idle (no writes for a defined soak) before 17 Sep.

Anything less is hope. Hope is not a cutover strategy when the source of truth disappears on a calendar date.

Strategic takeaway

Agent Registry's move to agent-registry is a deliberate service split with a hard stop on 17 September 2026. UK platform teams should treat this like a DNS cutover plus an API version bump: endpoints, IAM, events, schema and data must move together, while workload identity stays on bedrock-agentcore.

If you need a rapid cutover review across accounts/regions before the shutdown, AIATS offers a Free Evaluation for AWS AgentCore / Agent Registry readiness on UK estates.

Expert Commentary

This is a DNS-plus-API cutover with a calendar kill switch. UK platforms that only rename endpoints will fail on schema, events and sync-role trust.

Topics
AWSAmazon BedrockAgentCoreAgent Registryagent-registryMigrationIAMEventBridgeeu-west-1UKSREMCP
All insights

Need Help With Your Implementation?

Get expert guidance from our certified ServiceNow and AWS architects.

Schedule a Consultation