AWS Details AgentCore AI-DLC Workflows
- •AWS shows 2 AgentCore reference implementations for AI-driven software development lifecycle construction workflows
- •SQL workflow generates Mermaid ER diagrams from schema metadata without accessing table row data
- •Security workflow scores code from 1 to 10 and checks CVE risks and policy violations
AWS published an AI-driven development lifecycle guide on September 3, 2026, showing how engineering teams can use Amazon Bedrock AgentCore, Kiro, OpenAI ChatGPT Codex, and Claude Code to move from AI-assisted planning to deployed agent workflows. Amazon Bedrock AgentCore is described as a service for building, connecting, and optimizing agents at scale with any framework or model, while AI-DLC puts AI in the role of a collaborator for routine software work and leaves critical decisions to humans.
The guide provides 2 working reference implementations for the AI-DLC construction phase. The first converts SQL schema files into Mermaid ER diagrams through AgentCore runtime. The second performs automated security analysis for Python or Java code with a multi-agent architecture that uses AgentCore Gateway, AgentCore memory, AWS Lambda, Amazon S3, Amazon Cognito, Amazon CloudWatch, GitLab, MCP tools (standardized agent-tool connections), and Anthropic Claude Sonnet models on Amazon Bedrock.
The SQL-to-ER diagram system starts when developers upload SQL files to Amazon S3 manually or through a CI/CD pipeline. An Amazon S3 event triggers an AWS Lambda function, Cognito OAuth2 machine-to-machine authentication uses client credentials stored in AWS Systems Manager Parameter Store, and a containerized Strands framework agent runs on AgentCore runtime. The agent uses Claude Sonnet 4 through Amazon Bedrock to parse SQL DDL statements and generate Mermaid erDiagram syntax.
The schema workflow reads only metadata, including tables, constraints, and foreign keys, and does not access row data. Generated .mmd files are stored in Amazon S3 under a dedicated prefix with source-file metadata and a generation timestamp. AgentCore memory keeps persistent session context with a 90-day expiry, supports semantic search across previous analyses, and helps with incremental schema understanding.
AWS says the ER diagram implementation uses chunked processing for large SQL files, splitting schemas into manageable segments and consolidating them into a unified diagram so schemas with hundreds of tables can stay within context limits. The agent also uses structured prompting to extract tables, columns, data types, primary keys, and foreign key relationships before creating diagram syntax. OpenTelemetry tracing records spans and attributes for processing duration, chunk counts, and error attribution.
The secure software handoff system begins when code is pushed from a GitLab pipeline to Amazon S3. A Lambda trigger detects new uploads and starts the AgentCore analysis workflow with OAuth2 authentication. A Strands-based agent reviews code structure, logic quality, memory and performance characteristics, security issues, and best practices, while AgentCore Gateway routes tool calls to Lambda-based policy checks and CVE database checks.
The security workflow produces quality scores from 1 to 10, recommendations, CVE risk checks, and policy compliance reports. Results are stored in AgentCore memory with semantic search and displayed in a real-time, session-based web dashboard served by Dashboard Lambda. The dashboard supports search and multi-tab navigation across files, violations, and quality metrics, while AgentCore Observability and Amazon CloudWatch provide monitoring.
The guide lists 3 self-managed memory strategies for the security system: a semantic strategy for detailed findings, CVE results, and policy violations; a summary strategy for aggregated metrics and trends; and a user preference strategy for dashboard layout and filter preferences. Each analysis run creates a unique session in AgentCore memory, allowing developers to retrieve results by session ID and compare quality scores across multiple submissions.
The local workflow connects AgentCore deployments with developer-side tools. Kiro converts natural-language requirements into specifications with acceptance criteria, generates implementation plans, supports reusable agent skills, and performs multi-file work with human review at specification checkpoints. Codex is connected through a local stdio-based MCP server that queries MySQL or Amazon Aurora MySQL INFORMATION_SCHEMA and exposes 3 tools: schema_summary, generate_er_markdown, and generate_mermaid. Claude Code is used for rapid prototyping, deployment scripts, Dockerfiles, IAM policies, AWS CloudFormation templates, first-pass code review, and refactoring before CI/CD validation.