aws-serverless

por aws

Cria, implementa, gerencia, depura, configura e otimiza aplicações serverless na AWS usando Lambda, API Gateway, Step Functions, EventBridge e SAM/CDK.…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill aws-serverless

AWS Serverless

Domain expertise for building serverless applications on AWS: Lambda, API Gateway, Step Functions, EventBridge, event source mappings, concurrency, cold starts, deployment, and troubleshooting.

Works best with the AWS MCP server — run CLI commands, query CloudWatch, validate configs directly. All guidance also works with standard AWS CLI access.

Specialized skills — check these first

These cover capabilities and procedures the general references below do not. Several are specialized features or step-by-step tested procedures you would otherwise miss. Route to the matching skill before falling back to the references.

Advanced Lambda compute (easy to overlook)

Use this skillWhen the workload involves
aws-lambda-microvmsStrong tenant isolation, sandboxed/untrusted code execution (AI agent code sandboxes, REPLs, notebooks, CI runners), long-lived sessions, suspend/resume with preserved state, port-listening servers (gRPC, WebSocket, custom TCP), Firecracker microVMs, snapshot-resumable compute, up to 8-hour lifetimes
aws-lambda-durable-functionsDurable execution, checkpoint-and-replay, long-running multi-step workflows written as plain code (TS/Python/Java), automatic state persistence, saga pattern in code, human-in-the-loop callbacks, executions up to 1 year, context.step/context.wait/context.invoke, withDurableExecution, durable-execution-sdk
aws-lambda-managed-instancesLambda Managed Instances (LMI), capacity providers, EC2-backed Lambda, steady high-volume traffic (50M+ req/mo) wanting Savings Plans / Reserved Instance pricing, PerExecutionEnvironmentMaxConcurrency, CapacityProviderConfig, multi-concurrent execution environments

Workflow orchestration

Route here when the user wants to coordinate multiple steps, services, or functions. Triggers include "orchestration", "workflow", "state machine", "multi-step coordination", "coordinate Lambda functions", "durable execution", "pipeline with retries", or intent to build saga/compensation, human-in-the-loop approval, fan-out, or long-running async coordination.

When starting a new orchestration or multi-step workflow, you MUST surface the choice between AWS Step Functions and AWS Lambda Durable Functions before implementing — do not silently pick one. Route on the signals below. When the request names only a generic pattern (saga/compensation, human-in-the-loop, fan-out, or "workflow orchestration") with no technology, present both options and the one-line tradeoff, then let the user decide. Do not lead with the tradeoff caveats when the signals already point to one service.

Use this skillWhen the workload involves
aws-step-functionsOrchestration whose primary work is calling AWS services directly; coordinating non-Lambda compute (ECS/Fargate, Glue, SageMaker, Batch) through native managed integrations; a visual, auditable workflow definition required for compliance, cross-team operational observability, or as a shared contract between teams that do not share a codebase (ASL is the specification, not application code); authoring or editing state machines and Amazon States Language (ASL) — state types, JSONata data transformation, Retry/Catch error handling, .sync/waitForTaskToken service integrations, Distributed Map, TestState unit testing, JSONPath-to-JSONata migration
aws-lambda-durable-functionsCode-first orchestration in-process when already building on Lambda (context.step/context.wait/context.invoke, withDurableExecution); many fine-grained steps per execution where cumulative Step Functions Standard state-transition cost may be significant — compare Step Functions pricing (Standard vs Express) against Lambda invocation cost at the expected volume before choosing; orchestration steps written in a general-purpose language within the same application codebase (share modules, data types, and test suites with application code); teams applying standard software-engineering practices (unit tests, code review, type checking) to orchestration logic without learning a declarative workflow language

Tradeoff (use when either fits): Durable Functions keeps orchestration in your Lambda codebase; Step Functions externalizes it into a managed, visual state machine with built-in service integrations.

Security: Both services persist workflow state and payloads — Step Functions records full input/output in execution history (viewable in the console and, if logging is enabled, CloudWatch Logs). As a baseline, enable execution logging (CloudTrail) and CloudWatch alarms on execution failures, and use least-privilege per-workflow execution roles. Do not pass secrets, tokens, or PII through workflow state; reference them by Secrets Manager/ARN pointer, and apply a customer-managed KMS key to encrypt state when the data is sensitive.

Event-driven architectures

Route here when the user is designing or operating an event-driven system rather than orchestrating a known sequence of steps. Triggers include "event bus", "event-driven architecture", "pub/sub", "publish/subscribe", "fan-out", "event ordering", "ordered delivery", "FIFO events", "event replay", "replay events", "event retention", "event store", "CloudEvents", "Avro", "Protobuf", "schema registry", "deduplication", "choreography", "decoupling", "asynchronous integration", "event broker", or a central bus shared across teams and accounts.

Use this skillWhen the workload involves
amazon-eventbridge-event-busA new event-driven workload; a platform team owning a central bus that many teams and accounts publish to and subscribe from; governance of that bus (subscriber control, revocation, per-account throttling, cost allocation, end-to-end observability); open event formats (Avro, Protobuf, CloudEvents) decoded through a schema registry; ordered or FIFO delivery per event group; high fan-out where per-account forwarding cost matters; durable retention and replay of past events into a newly created subscriber; per-subscriber JSONata transformation; deduplication; choreography and decoupling across services; event-driven architecture spanning multiple accounts. This skill MUST NOT be used for questions regarding the EventBridge classic custom event bus, EventBridge Scheduler, EventBridge Pipes, EventBridge Global Endpoints, the EventBridge Schema Registry, EventBridge API Destinations, or EventBridge Connections.

Step-by-step task procedures (tested CLI SOPs)

Use this skillFor the task
connecting-lambda-to-api-gatewayWire an existing Lambda to a new REST/HTTP API: proxy integration, permissions, CORS, throttling, access logging, deployment
connecting-lambda-to-dynamodbConnect Lambda to DynamoDB: IAM execution role, read/write permissions, stream event source mapping
creating-api-gateway-stageCreate an API Gateway stage with CloudWatch logging, X-Ray tracing, throttling, WAF association, and authorization
deploying-custom-domain-rest-apiDeploy a Regional REST API with custom domain: ACM cert, Lambda backend, request authorizer, base path mapping, Route 53 DNS
debugging-lambda-timeoutsSystematically diagnose a timing-out Lambda: config, CloudWatch logs/metrics, VPC, cold starts, memory, downstream calls
processing-s3-uploads-with-step-functionsDeploy an event-driven workflow: S3 upload → EventBridge → Step Functions → Lambda (small files) or Fargate (large files), with VPC/ECR/ECS/IAM

Routing (general references in this skill)

User needRead
Building a new serverless app — pattern selectionarchitecture.md
Lambda config, cold starts, SnapStart, memory, VPC, layers, Function URLslambda.md
Concurrency (reserved, provisioned, ESM controls)concurrency.md
Event sources (SQS, DynamoDB Streams, SNS, Kinesis), filtering, batch failuresevent-sources.md
Step Functions, EventBridge rules/pipes/schedulerorchestration.md
API Gateway quotas, authorizers, WebSocketapi-gateway.md
SAM/CDK resource types and fast iterationdeployment.md
Production readiness, observability, anti-patternsproduction.md
Debugging an error (exact string → cause → fix)troubleshooting.md
Powertools handler templatepowertools-handler.py

Note: Reference files contain specific runtime versions, quotas, and feature matrices that change. When precision matters (production, runtime choice, quotas), confirm against current AWS documentation. The references focus on values and gotchas that are easy to get wrong — not on basics.

Mais skills de aws

analyzing-release-readiness
aws
Acione uma revisão de prontidão de release pré-merge em um PR do GitHub, MR do GitLab ou branch local. Use quando o usuário quiser analisar alterações de código quanto a risco, correção,…
scanning-with-aws-security-agent
aws
Execute uma varredura do AWS Security Agent no workspace — envia o código-fonte para a AWS, realiza a varredura com o serviço gerenciado Security Agent e retorna resultados classificados e verificados…
coordinating-multi-space-devops-agent
aws
Coordene o AWS DevOps Agent em vários AgentSpaces a partir de uma única sessão do Claude Code — direcione perguntas para o espaço certo (prod vs staging vs knowledge),…
aws-security
aws
Cobre serviços e fluxos de trabalho de segurança da AWS — descobertas do Security Hub V2 (OCSF), conectores, agregadores, regras de automação e resumos de postura de segurança;…
querying-aws-sagemaker-catalog
aws
Executa análises SQL em tabelas de metadados do catálogo SageMaker Catalog exportadas como Apache Iceberg em S3 Tables. Abrange consultas de governança, acompanhamento de crescimento de ativos,…
agents-connect
aws
Use ao conectar seu agente a APIs, ferramentas ou serviços externos via Gateway, ou ao restringir o acesso a ferramentas com políticas Cedar. Lida com a configuração do gateway, destino…
aurora-dsql
aws
Provisiona e gerencia clusters Aurora DSQL, conecta via psql ou DSQL Connectors, gerencia schemas, executa consultas, migra do MySQL, diagnostica planos de consulta,…
transitgateway
aws
Configura o AWS Transit Gateway: cria um hub e anexa VPCs, segmenta o tráfego com tabelas de rotas, centraliza a saída e a inspeção por meio de um hub…