Inspiration...
I'm a second-year Network and Cloud Architecture student at Northwest Vista College (graduating 2027), on the AWS path and headed toward cloud operations work — there's a data center being built across from my campus, and I want to earn my practicum internship in a place like that. As I study how real infrastructure is run, one thing keeps standing out: too much of operations still lives in ad-hoc CLI sessions and one-off scripts, where it's hard to prove later exactly what ran, when, and who approved it.
BedrockOps is my answer to that, pointed at where interfaces are going next. As voice and ambient assistants like Alexa+ become a front door to systems, the agent behind them should never be a black box with a shell. It should propose, a human should approve anything destructive or expensive, and every action should land in an audit trail that can be verified afterward.
What it does... BedrockOps is a self-hosted Model Context Protocol (MCP) server that lets an assistant like Alexa+ safely help with cloud operations. It exposes three tools over Streamable HTTP (spec 2025-11-25): system_probe reports system status, bedrock_route routes high-level requests toward Amazon Bedrock, and audit_ledger records every action in a SHA-256-chained log with a DynamoDB write path. Destructive or high-spend requests — delete, destroy, provision — stop at a human approval gate and never reach AWS. Every result honestly labels what is live, stubbed, or in-memory.
How we built it... I built BedrockOps in Python on the official MCP Python SDK (mcp==2.3.0) with Streamable HTTP transport, so any MCP client can negotiate a session and call the tools. Routing uses boto3 toward Amazon Bedrock, and the audit ledger hashes each entry with SHA-256 and writes to DynamoDB when a table is configured. The AWS footprint — the DynamoDB table plus a least-privilege IAM policy matching exactly what the code calls — is defined in Terraform. A suite of 13 automated tests covers the protocol handshake, the tool calls, the approval gate, and the ledger's write path, and the whole project is MIT-licensed and public on GitHub.
Challenges we ran into... The hardest challenge was honesty at every layer. A README claim isn't proof, so the tests assert the real protocol handshake instead of trusting the docs. An early draft also described pieces that didn't exist yet — I cut them rather than submit a description the code couldn't back up. The other challenge was designing the approval gate so it fails safe: if there's any doubt about an action's impact, the server refuses and asks a human, instead of guessing.
Accomplishments that we're proud of... I'm proud that the demo video is a real run, not a mockup — a client negotiates MCP 2025-11-25, lists the tools, and a "delete production" request is visibly stopped by the approval gate. I'm proud of the 13 passing tests, including one that proves the gate holds. And I'm proud of the honest labeling: live, stubbed, and in-memory results say exactly what they are. As a student building toward a career in cloud operations, shipping something a judge can clone, run, and verify means more to me than a polished slide.
What we learned... I learned that building an agent isn't mainly about getting the model to answer — it's about everything around the answer: the protocol it speaks, the permissions it holds, and the proof of what it did. Implementing MCP properly taught me to verify the negotiated session instead of trusting documentation, and to test the handshake the way a real client experiences it. Building the approval gate taught me that the most important feature of an operations agent is knowing when not to act, and that a refused action with a clear reason is a success, not a failure. And wiring the audit ledger taught me that if an action can't be verified afterward, it might as well not have happened. That lesson — propose, approve, record, verify — is exactly how I want to work in cloud operations after I graduate.
What's next for BedrockOps — Autonomous Cloud Operations & Audit Agent
Log in or sign up for Devpost to join the conversation.