resilience-hub-failure-mode-assessment

作成者: aws

AWS Resilience Hub v2の障害モード評価を実行し、解釈します。評価の開始、調査結果(重大度、カテゴリなど)の理解をカバーします。

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill resilience-hub-failure-mode-assessment

Failure Mode Assessment

Overview

Domain expertise for running Resilience Hub v2 failure mode assessments, interpreting findings, triaging by severity and achievability, and driving remediation.

The AWS MCP server is recommended for executing this skill's AWS API calls, but it is not required — all operations also work with the AWS CLI directly.

Guardrail — where this skill's own files live (MCP vs local install)

Before reading a reference file, determine how this skill was loaded:

  • Loaded via the AWS MCP retrieve_skill tool: the skill's reference files are not on the local filesystem. Fetch each one through retrieve_skill with the file parameter (e.g. file="references/assessment-workflow.md") — do NOT file_read these paths locally or search the filesystem for them.
  • Installed locally (e.g. .kiro/skills/resilience-hub-failure-mode-assessment/ or ~/.claude/skills/resilience-hub-failure-mode-assessment/): read reference files from the local skill directory using the relative paths shown here.

This applies only to the skill's own reference files; always read and write user or session data in the working directory, never through retrieve_skill.

Run and interpret assessments

To run assessments and triage findings, follow the procedure exactly. See references/assessment-workflow.md.

Troubleshooting

Assessment fails with INVALID_PERMISSIONS

The service's permission model (invokerRoleName / crossAccountRoles) doesn't have access to the resources. Verify the invoker role (and any cross-account roles) can describe resources in all configured regions.

Too many findings — where to start?

Prioritize by finding severity, highest first (HIGH, then MEDIUM, then LOW). For HIGH-severity findings, check the service's achievability for the relevant policy component (from get-service / list-failure-mode-assessments): NOT_ACHIEVABLE means the architecture must change before testing; ACHIEVABLE means validate the fix with an FIS experiment. MEDIUM findings: plan remediation this sprint; LOW findings: track but don't block (see the priority matrix in references/assessment-workflow.md Step 5).

AI-generated service functions are wrong

Update them: aws resiliencehubv2 update-service-function to rename or change criticality (there is no service-function "type" parameter). Reassign resources by calling create-service-function-resources with the desired resource set (see references/assessment-workflow.md for the service-function operations).

Security Considerations

  • Least privilege: the invoker role should be scoped to read-only discovery of only the resource types in the service's input sources; avoid granting access beyond what assessment needs.
  • Encryption & access control: recommend that S3 buckets used for report output have server-side encryption (SSE-S3 or SSE-KMS) and block public access — assessment reports can contain sensitive architectural detail. If a bucket policy grants the Resilience Hub service principal write access, scope it with aws:SourceArn / aws:SourceAccount condition keys to prevent confused-deputy writes.
  • Further reading: see Security in AWS Resilience Hub and the AWS Well-Architected Security Pillar for securing assessment outputs and IAM configurations.

awsのその他のスキル

analyzing-release-readiness
aws
GitHub PR、GitLab MR、またはローカルブランチに対して、マージ前のリリース準備状況レビューをトリガーします。ユーザーがコード変更をリスク、正確性、…について分析したい場合に使用します。
scanning-with-aws-security-agent
aws
ワークスペースでAWS Security Agentスキャンを実行します — ソースをAWSにアップロードし、マネージドSecurity Agentサービスでスキャンし、ランク付けされ検証済みの…を返します。
coordinating-multi-space-devops-agent
aws
1つのClaude Codeセッションから、複数のAgentSpacesにわたってAWS DevOps Agentを調整します — 質問を適切なスペース(prod vs staging vs knowledge)にルーティングし、…
aws-security
aws
AWSセキュリティサービスとワークフローをカバー — Security Hub V2(OCSF)の検出結果、コネクタ、アグリゲータ、自動化ルール、セキュリティ態勢の要約;…
querying-aws-sagemaker-catalog
aws
SageMaker Catalogのアセットメタデータテーブル(Apache IcebergとしてS3 Tablesにエクスポート)に対してSQL分析を実行します。ガバナンスクエリ、アセット成長の追跡などをカバーします。
agents-connect
aws
エージェントをGateway経由で外部API、ツール、またはサービスに接続する場合、またはCedarポリシーでツールアクセスを制限する場合に使用します。ゲートウェイのセットアップ、ターゲット…
aurora-dsql
aws
Aurora DSQLクラスターのプロビジョニングと管理、psqlまたはDSQL Connectorsを介した接続、スキーマの管理、クエリの実行、MySQLからの移行、クエリプランの診断、…
transitgateway
aws
AWS Transit Gatewayを設定します:ハブを作成しVPCを接続し、ルートテーブルでトラフィックをセグメント化し、ハブを通じてegressとインスペクションを集中管理します…