End-of-life runtimes, engine versions and IaC drift fixed at scale.
Connect your accounts and repositories. Agents find every end-of-life runtime, engine version and drifted resource, work out what each upgrade will break, and open changes ready to review and merge. The upgrade backlog shrinks every week instead of growing.
payments-prod on Kubernetes 1.29, end of standard support
Plan built in 6m. Waiting for platform team review
[The work behind every upgrade]
01The manual work
Audit
Someone lists every runtime and engine version, reads release notes, hunts for breaking changes and estimates the risk. Then the roadmap pushes it back.
02The agent handoff
Change ready
Frontier agents map what is out of date, find what each upgrade breaks and open the code and config changes to fix it.
03Your engineers’ role
Merge
Set the order and the maintenance windows. Review each change and decide when it reaches production.
[Where CloudThinker fits]
01What is aging
Already in your estate
Inventory from what you run
02Code and config
Your system of record
Source of truth stays put
03Remediation
CloudThinker
Changes go through review
04Response
Upgrades, not tickets
Each wave runs on approval
[Example scenario]
A 4-person platform team running 3 EKS clusters for 41 workloads. Product teams own the manifests. Extended support fees start when standard support ends.
Version scan flags itSignal
Weekly scan: payments-prod, payments-staging and tools run Kubernetes 1.29, 6 weeks from end of standard support.
Agent maps the blast radiusAgent
Reads every manifest and Helm chart, checks add-on versions and compares them with the 1.30 and 1.31 release notes.
Blockers foundAgent
2 manifests use a removed autoscaling API. CoreDNS and the VPC CNI need newer versions first.
Changes openedAgent
Merge requests for the 2 manifests to the owning teams, and an upgrade plan: add-ons, then staging, then production.
Platform lead approves stagingYour team
Reviews the plan, books the staging window and approves. The agent upgrades staging and runs the smoke tests.
Production upgradedAgent
Node groups rolled one at a time. All 41 workloads healthy. The ticket closes with the full change log attached.
CloudThinker10:08
EKS 1.29 to 1.31 plan ready for 3 clusters. Blockers: 2 manifests on a removed API (MRs !311, !312 sent to owners), CoreDNS and VPC CNI bumps. Order: add-ons, staging, production.
Platform leadWed 14:00
Both manifest MRs merged. Staging approved for now.
CloudThinkerWed 14:52
Staging on 1.31. Smoke tests pass, 0 restarts. Production window proposed for Thursday 22:00.
CloudThinkerThu 23:10
payments-prod on 1.31. 41 of 41 workloads healthy. PLAT-482 closed with the change log.
An illustrative example. Team, systems and times are representative, not a specific customer.
[Frontier remediation agents]
Agents keep an inventory of what runs where, so an end-of-life date turns into a reviewed change well before the deadline, and drift gets fixed in code instead of in the console.
[What changes]
| Moment | Today | With frontier agents |
|---|---|---|
| Knowing what is outdated | A spreadsheet updated once a year | A live inventory with support dates |
| Breaking changes | Found during the upgrade | Found and fixed before it starts |
| Infrastructure drift | Discovered in the next outage | Traced to code and corrected |
| Doing the upgrade | A project nobody has time for | A merge request ready to review |
| The backlog | Grows every quarter | Shrinks every week |
[Integrations]
[Adoption path]
The rollout follows the four phases of the AWS Cloud Adoption Framework, so it fits the plan your cloud team already runs.
01Envision
Pick one upgrade
Choose the deadline that worries you most. Connect read-only and let agents build the plan and the changes.
02Align
Agree the rollout rules
Decide the order of environments, the maintenance windows and who approves each change.
03Launch
Roll out account by account
Add each team’s accounts and repositories on the same policies, plan format and audit trail.
04Scale
Make it the default
New end-of-life dates turn into planned changes automatically, long before they become urgent.
[Customer proof]
NextPay upgraded its production EKS clusters with zero downtime and kept its payment-critical apps running throughout.
[AWS guidance]
[Trust and control]
[Questions]
[Go deeper]
Start with the upgrade that worries you most, read-only. See the plan and the changes before you grant a single permission more.

Up to $200K in AWS credits
Applied to your own AWS account.

AWS AI Services Competency
Validated for Agentic AI Consulting.

Covered 24/7, on your approval
Under HIPAA, GDPR and SOC 2 controls.