Agentic AI for Cloud Infrastructure Review & Implementation for Tensorty
Agentic AI for Cloud Infrastructure Review & Implementation
Use Case - Agentic AI for Cloud Infrastructure Review & Implementation
Industry: Technology
Geography: Singapore
Employee Size: 50+
Solution: AWS
About Customer
Tensorty Co., Ltd. is a Thailand based technology company focused on research, innovation, and technology driven product development. The company helps businesses transform ideas into working prototypes and enhance existing products through emerging technologies. With a focus on innovation and practical solutions, Tensorty works across research, product development, and technology implementation to help organizations bring new ideas to life.
Client Requirements
Automated IaC Generation
Generate CloudFormation and Terraform templates from natural-language requirements while following organizational standards.
Policy-Driven Compliance Validation
Validate infrastructure templates against governance policies, AWS Well-Architected Framework guidance, IAM standards, naming conventions, security controls, and compliance requirements.
Faster Pull Request Reviews
Reduce the effort required from senior architects and DevOps engineers to review infrastructure, IAM, Lambda, and application changes.
Standardized Review Quality
Apply consistent security, compliance, architecture, performance, and cost checks across projects regardless of the reviewer.
Centralized Knowledge base
Make security policies, architecture guidelines, and operational best practices searchable and reusable through a centralized knowledge base.
Scalable & Responsible AI Automation
Scale infrastructure authoring and technical QA without proportional senior-headcount growth while maintaining secure, auditable, and responsible AI controls.
Our Approach
enreap designed and implemented an Agentic AI for Cloud Infrastructure Review & Implementation Platform using Amazon Bedrock and AWS-native services. The platform combines Infrastructure-as-Code generation, policy-grounded compliance validation, and context-aware pull request review. The solution uses Retrieval-Augmented Generation (RAG) to ground AI recommendations in TENSORTY’s governance documents, security policies, architecture guidelines, and AWS Well-Architected best practices.
Our Solution
1. AI-Powered Template Generation
Enabled teams to generate CloudFormation and Terraform templates from natural-language requirements using Amazon Bedrock, incorporating security, IAM, encryption, HA, tagging, and governance best practices.
2. Automated Compliance Validation
Validated AI-generated and manually authored templates against enterprise policies, AWS Well-Architected guidance, IAM standards, naming conventions, and compliance requirements, with structured findings and remediation recommendations.
3. Automated Pull Request Review
Integrated GitHub using OAuth and used Amazon SQS and AWS Lambda to asynchronously review pull requests, including infrastructure changes, IAM policies, application changes, and linked Jira context.
4. RAG-Based Governance Knowledge
Centralized governance documents in Amazon S3 and indexed them through Amazon Bedrock Knowledge Bases and Amazon OpenSearch Serverless so AI responses were grounded in TENSORTY’s own standards.
5.Responsible AI & Secure Integration
Implemented Amazon Bedrock Guardrails for prompt-injection protection, content filtering, and controlled AI interactions, alongside secure GitHub and Jira integrations.
6. Scalable & Auditable Processing
Used SQS and Lambda for asynchronous, retryable processing, DynamoDB and S3 for findings and audit history, and CloudWatch and X-Ray for end-to-end monitoring and distributed tracing.
Business Outcome
1. Faster Infrastructure Delivery - Automated template generation reduces manual first-draft authoring and accelerates compliant IaC development.
2. Reduced Senior Engineering Dependency - AI performs the first-pass compliance and PR review, reducing routine review effort for senior architects and engineers.
3. Consistent Governance & QA - RAG-based policy grounding applies the same indexed organizational standards across reviews, improving consistency across teams.
4. Earlier Security & Compliance Detection - Automated validation identifies risks such as excessive IAM permissions, missing encryption, and public exposure before merge or deployment.
5. Scalable Review Capacity - Event-driven SQS and Lambda processing enables review capacity to grow with deployment volume without proportional senior-headcount growth.
6. Reusable Institutional Knowledge - Structured findings and governance documents are retained in a searchable knowledge base, enabling reuse and continuous improvement.