-
-
CloudFix architecture — Strands Agent connects the AI model with read-only AWS S3 and IAM inspection tools.
-
CloudFix web interface — engineers describe an AWS access issue in plain English.
-
Real AWS evidence collected by CloudFix from the IAM user and S3 bucket configuration.
-
CloudFix identifies the root cause and recommends a least-privilege IAM policy for human review.
Inspiration
AWS permission issues can look simple but often take significant time to troubleshoot. When an IAM user cannot access an S3 bucket, engineers may need to inspect IAM policies, group policies, permissions boundaries, bucket policies, resource ARNs, Block Public Access, and other configuration before finding the real cause.
I built CloudFix to make this repetitive troubleshooting process faster using an AI agent.
What it does
CloudFix is a read-only AI agent that troubleshoots AWS S3 and IAM access issues.
A cloud engineer can describe a problem in plain English, such as:
"Why can't cloudfix-demo-user download files from cloudfix-demo-bucket?"
CloudFix inspects the actual AWS configuration, analyzes the evidence, identifies the likely root cause, and recommends a least-privilege fix.
The result follows a simple workflow:
Evidence → Root Cause → Recommended Fix → Human Review
CloudFix does not automatically modify AWS resources.
How we built it
CloudFix is built using the Strands Agents SDK for agent orchestration and tool calling.
I created boto3-backed tools that allow the agent to inspect real AWS configuration, including:
- S3 bucket configuration
- IAM user policies
- IAM group memberships and policies
- Permissions boundaries
- S3 bucket policies
- Block Public Access
- Server-side encryption
- Ownership controls
- Relevant S3 resource ARNs
The Strands agent decides which tools to use and reasons over the returned AWS evidence.
The application uses:
- Strands Agents SDK
- Python and boto3
- Ollama with Qwen2.5:7b
- Flask
- Amazon S3
- AWS IAM
For the demo, I intentionally created an IAM user that has s3:ListBucket but is missing s3:GetObject.
When CloudFix investigates the problem, it discovers the missing object-level permission and generates a corrected least-privilege IAM policy for human review.
Challenges we ran into
I initially explored Amazon Bedrock for model inference, but model invocation was unavailable for the AWS account I was using.
Because Strands Agents SDK supports different model providers, I was able to continue building the same agent architecture using Ollama and a local Qwen2.5:7b model without redesigning the AWS inspection tools.
Another challenge was making the agent distinguish between AWS configuration that is simply present and configuration that is actually responsible for an authorization failure.
I addressed this by giving the agent a structured diagnostic process based on evidence returned by its tools.
Accomplishments that we're proud of
CloudFix goes beyond giving generic AWS troubleshooting advice.
The agent retrieves configuration from a real AWS environment, uses multiple tools through Strands, reasons over the evidence, identifies the likely root cause, and produces an actionable recommendation.
I am also proud that CloudFix follows a safety-first design. Its AWS inspection operations are read-only, and suggested IAM fixes are never automatically applied.
What we learned
Building CloudFix helped me understand the difference between a chatbot and a tool-using AI agent.
Instead of answering only from model knowledge, CloudFix can gather evidence using tools, analyze that evidence, and use it to produce a recommendation.
I also gained practical experience with Strands Agents SDK, boto3, IAM policy evaluation, S3 permissions, local LLM inference, and designing human-in-the-loop agent workflows.
What's next for CloudFix
The current MVP focuses on S3 and IAM access troubleshooting.
Future versions could extend the same agent-based approach to:
- VPC and security group troubleshooting
- Lambda permissions
- AWS KMS access issues
- CloudTrail evidence
- CloudWatch logs
- Cross-account IAM access
- RDS connectivity
The long-term goal is to expand CloudFix into a broader AWS troubleshooting agent that handles repetitive investigation automatically and involves engineers when a decision or infrastructure change is required.
Built With
- amazon-web-services
- amazoniam
- amazons3
- boto3
- flask
- ollama
- python
- qwen2.5
- strandsagentsdk
Log in or sign up for Devpost to join the conversation.