AWS Agent Registry Cutover: A UK Checklist Before the 17 September 2026 Namespace Shutdown
Agent Registry GA moved to the agent-registry namespace; bedrock-agentcore registry APIs shut on 17 Sep 2026. UK SRE cutover: endpoints, IAM, schema, migration tooling — with ~2 days left.

Agent Registry GA moved to the agent-registry namespace; bedrock-agentcore registry APIs shut on 17 Sep 2026. UK SRE cutover: endpoints, IAM, schema, migration tooling — with ~2 days left.
- bedrock-agentcore registry namespace shuts 17 Sep 2026 — migrate to agent-registry or lose access.
- Update endpoints (*.api.aws), IAM agent-registry:*, AgentRegistryFullAccess, SDK/CLI and EventBridge/CloudTrail sources.
- Schema breaks: discoveryConfiguration, recordType, descriptors, search_discoverable_registry_records.
- Keep workload identity under bedrock-agentcore; fix sync role trust to agent-registry.amazonaws.com.
- 7-day emergency plan: inventory → IAM/trust → migrate → cut clients → verify events before shutdown.
~2 days left: cut over Agent Registry before the old namespace goes dark
On 31 August 2026, AWS positioned Agent Registry as generally available in the dedicated agent-registry namespace. If your estate still holds registries or records under the legacy bedrock-agentcore registry APIs, you are inside a hard migration window that closes on 17 September 2026. After that date the old registry namespace shuts down: you lose read/write access and any remaining data left behind.
This is a UK platform / SRE cutover checklist — endpoints, IAM, SDK/CLI, EventBridge/CloudTrail, schema changes, migration tooling and sync-role trust policies — with urgency appropriate to a deadline measured in days, not quarters.
Cloud AI infrastructure
What is changing (and what is not)
| Area | Change | Stay put |
|---|---|---|
| Registry service namespace | bedrock-agentcore → agent-registry | — |
| Endpoints | *.amazonaws.com → *.api.aws hostnames for registry | — |
| IAM action prefix | bedrock-agentcore:* (registry actions) → agent-registry:* | — |
| Managed policy | Replace registry use of BedrockAgentCoreFullAccess with AgentRegistryFullAccess | — |
| Workload identity / OAuth credential providers | — | Remain under bedrock-agentcore |
| Other AgentCore (Runtime, Gateway, Policy, Identity) | — | Not renamed by this cutover |
Critical nuance: only Agent Registry moves. Do not blanket-replace every bedrock-agentcore permission — keep workload identity APIs on the old namespace when URL sync uses OAuth/IAM credentials.
Timeline that matters
| Date | Meaning |
|---|---|
| 6 Aug 2026 | agent-registry namespace launch; dual access for existing registry customers; migration tooling available |
| 31 Aug 2026 | GA / what's-new positioning for Agent Registry (plan as production-ready) |
| 17 Sep 2026 | bedrock-agentcore registry namespace shutdown — migrate or lose access |
New customers without pre-existing registries after 6 Aug already start on agent-registry. Existing estates that delayed migration now have a ~2-day fuse from this article's publish date (15 Sep 2026).
Surface-by-surface cutover map
Endpoints
| Plane | Old | New |
|---|---|---|
| Data | bedrock-agentcore.{region}.amazonaws.com | agent-registry.{region}.api.aws |
| Control | bedrock-agentcore-control.{region}.amazonaws.com | agent-registry-control.{region}.api.aws |
UK estates commonly run control and data paths in eu-west-1 (Ireland) and/or eu-west-2 (London) depending on residency design — update every hardcoded endpoint URL, VPC endpoint assumption and private DNS alias.
IAM
| Surface | Old | New |
|---|---|---|
| Action prefix | bedrock-agentcore:... registry actions | agent-registry:... |
| Service principal | bedrock-agentcore.amazonaws.com | agent-registry.amazonaws.com |
| Registry ARN | arn:aws:bedrock-agentcore:...:registry/... | arn:aws:agent-registry:...:registry/... |
| Record ARN | .../record/... under old NS | same path under new NS |
| Managed policy | BedrockAgentCoreFullAccess (will not gain agent-registry:*) | AgentRegistryFullAccess |
Also update SCPs, permission boundaries, CI role policies and any IAM Conditions that match the old prefix.
Retain alongside new permissions when using URL sync with identity:
bedrock-agentcore:CreateWorkloadIdentitybedrock-agentcore:GetWorkloadIdentitybedrock-agentcore:DeleteWorkloadIdentity
SDK / CLI / quotas
| Surface | Old | New |
|---|---|---|
| Dataplane client | BedrockAgentCoreClient | AgentRegistryClient |
| Control client | BedrockAgentCoreControlClient | AgentRegistryControlClient |
| CLI | aws bedrock-agentcore / bedrock-agentcore-control | aws agent-registry / agent-registry-control |
| Service Quotas code | bedrock-agentcore | agent-registry (re-request custom quotas) |
Observability
| Surface | Old | New |
|---|---|---|
| CloudTrail event source | bedrock-agentcore.amazonaws.com | agent-registry.amazonaws.com |
| EventBridge source | aws.bedrock-agentcore | aws.agent-registry |
| CloudWatch namespace | AWS/BedrockAgentCore | AWS/AgentRegistry |
EventBridge detail-types expand. Especially: registry ready events change from a long sentence (Registry State transitions from Creating to Ready) to short status strings such as Registry Ready. Record approval lifecycle gains multiple detail-types (Draft, Pending Approval, Approved, Rejected, Deprecated). Update SIEM parsers and automation rules before you cut reads to the new bus source.
Schema changes you must code for
This is not a rename-only migration. Application code that builds or parses registry payloads will break if you only swap endpoints.
Registry entity
authorizerType/authorizerConfigurationmove underdiscoveryConfigurationapprovalConfiguration.autoApproval(boolean) →autoApprovalRules(enum array;"APPROVE_ALL"≈ oldtrue)
Registry records
| Old concept | New concept |
|---|---|
Display-ish name | Becomes displayName; new required name is the dedup key |
descriptorType | Removed; required recordType: AGENT | MCP | SKILL | CUSTOM |
Nested descriptors + descriptorType | Flat keyed descriptors (a2aAgentCard, mcpServer, agentSkillsDefinition, custom) |
inlineContent | data |
schemaVersion / protocolVersion | dataSchemaVersion |
| Top-level sync config | Per-descriptor source (only fromUrl supported in new NS) |
Search / MCP tool rename: search_registry_records → search_discoverable_registry_records. List filters move to structured filters arrays; several List operations become POST-style list APIs. New browse APIs (ListDiscoverableRegistryRecords, BatchGetDiscoverableRegistryRecord) help catalog UX after cutover.
Data migration approach
AWS provides migration tooling (agentcore-samples) to extract, transform and load into the same account/region under the new namespace. Choose deliberately:
| Profile | Approach |
|---|---|
| Small / one-shot | Run migration tool from terminal or CloudShell |
| Parallel + incremental | Managed Glue/CDK path; full load then incremental at cutover |
| Active writers | Active-active dual-write until confidence, then cut reads/writes |
Verification minimum:
- Registry count match (
list-registries). - Per-registry record count match.
- Spot-check descriptor transforms (
recordType,descriptors,source). - App read/write smoke tests on new clients.
- EventBridge / CloudTrail rule hits on new sources.
Sync role trust policies (easy to miss)
If records synchronize with an IAM role credential type, update the role trust principal to agent-registry.amazonaws.com before live load. The migration tool does not assume the sync role; the service does asynchronously after create. Miss this and migrated records can land in CREATE_FAILED. Recovery: fix trust → delete failed record → re-load. OAuth / no-auth sync paths are unaffected by this specific trust change.
Platform notes UK teams ask about
- Regions: Agent Registry availability includes major EU regions used by UK estates (plan explicitly for eu-west-1 / London designs). Confirm every account/region pair you actually use.
- Auto-detect AgentCore Runtime / Gateway: registries can discover and catalogue runtime/gateway-backed agents — retest discovery after namespace cutover so catalogs do not silently empty.
- RAM org sharing: if you share registries across accounts/OUs, re-validate share principals and consumer IAM against new ARNs.
- MCP search tool rename: update agent tool manifests and Gateway tool lists the same day as the client cutover.
7-day emergency cutover plan (use now)
| Day | Action | Owner |
|---|---|---|
| D0 (today) | Inventory registries/records per account/region; freeze non-essential writes if possible | Platform lead |
| D0 | Diff IAM/SCP/CI for bedrock-agentcore registry actions; draft agent-registry:* + AgentRegistryFullAccess | Security IAM |
| D0–D1 | Patch endpoints, SDK clients, CLI scripts, Terraform/CDK | SRE / App teams |
| D1 | Update EventBridge rules, CloudTrail Lake/SIEM parsers, CloudWatch dashboards | Observability |
| D1 | Fix sync role trust policies to agent-registry.amazonaws.com | IAM |
| D1 | Run migration tool (full load); verify counts | Platform |
| D2 morning | Incremental sync if dual-running; dual-read smoke tests | SRE |
| D2 | Cut application traffic to agent-registry; disable old writers | Release manager |
| By 17 Sep | Confirm old namespace unused; document evidence for audit | Platform + Security |
If you are already past D0 with no inventory, collapse to a war-room: inventory → IAM+trust → migrate → cut clients → verify events in that order. Schema code fixes that are incomplete will fail loudly — better than silent empty catalogs after shutdown.
Failure modes in the last 48 hours
| Failure | Why it happens late | Immediate mitigation |
|---|---|---|
| Partial IAM | Custom policies updated, SCPs not | Grep org SCPs for bedrock-agentcore registry actions |
| Managed policy trap | Still on BedrockAgentCoreFullAccess | Attach AgentRegistryFullAccess; remove false confidence |
| Event rule silence | Source updated but detail-type still old sentence | Match Registry Ready and record state prefixes |
| CREATE_FAILED sync | Trust still on old principal | Fix trust, delete failed record, re-load |
| Identity over-edit | Someone replaced all bedrock-agentcore actions | Restore workload identity permissions |
| Hardcoded ARNs | Secrets, Parameter Store, tickets | Search arn:aws:bedrock-agentcore and rewrite |
| Quota surprises | Custom limits left on old service code | Re-request under agent-registry |
Run a single war-room checklist owner — split ownership is how dual namespaces linger past shutdown.
Acceptance tests before you call cutover done
- Create/list/get registry on
agent-registryin each production region you use. - Create a sample MCP and AGENT record with required
name+recordType+ newdescriptorsshape. - Run discoverable search / MCP
search_discoverable_registry_recordsfrom a non-prod agent. - Confirm CloudTrail shows
agent-registry.amazonaws.comfor the test calls. - Fire a record approval transition and prove EventBridge automation still ticks.
- Confirm Runtime/Gateway auto-detect still populates expected entries.
- Confirm RAM consumers (if any) can still read shared approved records.
- Confirm old namespace is idle (no writes for a defined soak) before 17 Sep.
Anything less is hope. Hope is not a cutover strategy when the source of truth disappears on a calendar date.
Strategic takeaway
Agent Registry's move to agent-registry is a deliberate service split with a hard stop on 17 September 2026. UK platform teams should treat this like a DNS cutover plus an API version bump: endpoints, IAM, events, schema and data must move together, while workload identity stays on bedrock-agentcore.
If you need a rapid cutover review across accounts/regions before the shutdown, AIATS offers a Free Evaluation for AWS AgentCore / Agent Registry readiness on UK estates.
This is a DNS-plus-API cutover with a calendar kill switch. UK platforms that only rename endpoints will fail on schema, events and sync-role trust.


