aws-blocks

작성자: aws

AWS Blocks로 풀스택 애플리케이션을 구축하는 방법을 안내합니다 — Infrastructure-from-Code 프레임워크입니다. API 생성, Building Blocks 선택 시 적용됩니다…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill aws-blocks

AWS Blocks Application Development

Package naming: All packages are published under the @aws-blocks scope (e.g., @aws-blocks/core, @aws-blocks/blocks, @aws-blocks/bb-kv-store).

Overview

AWS Blocks is an Infrastructure-from-Code framework where Building Blocks bundle CDK, SDK, and local mocks into a single API. It provides 18+ Building Blocks covering storage, authentication, real-time communication, background jobs, file management, AI/search, email, and observability — all working locally without AWS credentials.

Key characteristics:

  • One aws-blocks/ directory defines the entire backend
  • Frontend imports are fully typed — no client generation needed
  • All Building Blocks work locally without AWS (mocks persist to .bb-data/)
  • Deploy ephemeral, individual testing environments with npm run sandbox and long-lived environments with npm run deploy using least-privilege credentials

Scaffolding a New Project

npx @aws-blocks/create-blocks-app my-app
cd my-app

To add AWS Blocks to an existing project:

npx @aws-blocks/create-blocks-app .

This detects the existing project and adds an aws-blocks/ workspace alongside your code.

To add AWS Blocks to an Amplify Gen 2 project:

npx @aws-blocks/create-blocks-app .

When the CLI detects amplify/backend.ts, it automatically integrates AWS Blocks with your Amplify backend.

With a specific template:

npx @aws-blocks/create-blocks-app my-app --template demo
cd my-app

Available Templates

TemplateDescription
defaultVite + lit-html starter app with basic authentication, data persistence, and realtime to help demonstrate basic app architecture and patterns (used when --template is omitted)
bareVite + lit-html starter with a single "hello world" API method and a bare frontend
reactReact + Vite starter with a single API endpoint and typed React frontend
backendBackend-only — no frontend, just the AWS Blocks API with a single endpoint
demoTodo app with AuthBasic, KVStore, DistributedTable, Zod schemas, indexes, and auth-protected CRUD
auth-cognitoFull AuthCognito passwordless email-OTP with roles, device management, and Authenticator UI
nextjsNext.js + React starter with AWS Blocks backend integration (SSR + Server Components)

Development Workflow

After scaffolding, refer to node_modules/@aws-blocks/blocks/README.md for the complete development workflow including:

  • Core concepts (Architecture, Building Block selection)
  • Project structure and Scope organization
  • Error handling patterns
  • Schema validation
  • Local development
  • Best practices and common mistakes
  • Deployment IAM role setup and security guidance

When implementing a specific Building Block, read its package README for the detailed API reference (e.g., node_modules/@aws-blocks/bb-kv-store/README.md). These are the authoritative docs for your installed version.

Security Considerations

  • Use await auth.requireAuth(context) in every method that shouldn't be public — ApiNamespace methods are unauthenticated by default
  • Use new AppSetting(scope, id, { secret: true }) for API keys and credentials — never hardcode or use .env files
  • Always attach a schema to KVStore/AppSetting that accepts user data — the RPC layer validates structure but not business logic
  • Do not add broad * IAM policies — each Building Block already grants least-privilege scoped to its own resources
  • Never change blockPublicAccess on FileBucket — serve public files through CloudFront instead
  • Configure CORS_ALLOWED_ORIGINS explicitly for production — avoid wildcards
  • For cross-domain deployments, pass crossDomain: true to auth constructors (enables SameSite=None; Secure; Partitioned)
  • Enable monitoring: { enabled: true, snsTopicArn: '...' } on Hosting for production alerts
  • Add WAF and API Gateway throttling via CDK for public-facing apps — not included by default
  • Logger provides serialization safety (circular refs, type coercion) but does NOT redact sensitive content — never pass raw credentials, tokens, or secrets to Logger methods; sanitize context objects before logging

aws의 다른 스킬

analyzing-release-readiness
aws
GitHub PR, GitLab MR 또는 로컬 브랜치에서 병합 전 릴리스 준비 검토를 트리거합니다. 사용자가 코드 변경 사항의 위험성, 정확성 등을 분석하려 할 때 사용합니다.
scanning-with-aws-security-agent
aws
작업 공간에서 AWS Security Agent 스캔 실행 — 소스를 AWS에 업로드하고, 관리형 Security Agent 서비스로 스캔한 후, 순위가 매겨진 검증된 결과를 반환합니다…
coordinating-multi-space-devops-agent
aws
하나의 Claude Code 세션에서 여러 AgentSpaces에 걸쳐 AWS DevOps Agent를 조정하세요 — 질문을 올바른 공간(프로덕션 vs 스테이징 vs 지식)으로 라우팅하고,…
aws-security
aws
AWS 보안 서비스 및 워크플로우를 다룹니다 — Security Hub V2 (OCSF) findings, 커넥터, 애그리게이터, 자동화 규칙, 보안 상태 요약 등…
querying-aws-sagemaker-catalog
aws
SageMaker Catalog 자산 메타데이터 테이블에서 SQL 분석을 실행하며, S3 Tables에서 Apache Iceberg로 내보낸 데이터를 대상으로 합니다. 거버넌스 쿼리, 자산 성장 추적 등을 다룹니다.
agents-connect
aws
에이전트를 Gateway를 통해 외부 API, 도구 또는 서비스에 연결하거나 Cedar 정책으로 도구 접근을 제한할 때 사용합니다. 게이트웨이 설정, 대상...
aurora-dsql
aws
Aurora DSQL 클러스터를 프로비저닝하고 관리하며, psql 또는 DSQL 커넥터를 통해 연결하고, 스키마를 관리하고, 쿼리를 실행하고, MySQL에서 마이그레이션하고, 쿼리 계획을 진단합니다.
transitgateway
aws
AWS Transit Gateway를 구성합니다: 허브를 생성하고 VPC를 연결하며, 라우팅 테이블로 트래픽을 분리하고, 허브를 통해 이그레스 및 검사를 중앙화합니다…