1. Amazon Bedrock agents (highest priority)
- AWS::Bedrock::Agent
- AWS::BedrockAgentCore::Runtime
Goal: catalog the AI agents running in AWS, with ownership and governance in Port.
  1. Amazon OpenSearch Service domains
- AWS::OpenSearchService::Domain
  1. IAM roles, including usage data
- AWS::IAM::Role
- Must include RoleLastUsed (LastUsedDate, Region), as returned by the IAM GetRole API.
Goal: identify unused or stale roles for security and governance reviews.
Why this is needed
  • AWS v3 doesn't support custom kinds, so users can't add these resources themselves.
  • The AWS Legacy integration isn't a full workaround: Cloud Control has no List operation for OpenSearch domains, and Cloud Control doesn't return RoleLastUsed for IAM roles.
  • The only remaining option today is custom code (a script or a standalone Ocean integration), which customers don't want to build and maintain.
Since v3 uses service-specific AWS APIs, it shouldn't be affected by these Cloud Control limitations.
Related
Bedrock agents may overlap with the native Bedrock integration planned for Q4. If that integration will cover them, the scope here can narrow to OpenSearch and IAM.