aws-cdk

โดย aws

เขียน จัด部署 และแก้ไขปัญหา AWS infrastructure โดยใช้ CDK กับ TypeScript หรือ Python ครอบคลุม best practices สถาปัตยกรรม stack และรูปแบบ construct

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill aws-cdk

AWS CDK

Overview

Domain expertise for CDK construct authoring, deployment workflows, compliance, drift, importing resources, safe refactoring, and troubleshooting CDK CLI / CloudFormation errors.

When NOT to use: Raw CloudFormation YAML/JSON. SAM. Terraform/Pulumi. CI/CD beyond CDK Pipelines. Use builtin knowledge or specialized skills for these.

Critical Warnings

Deadly embrace: Removing a cross-stack reference deadlocks deployment (Export ... cannot be deleted as it is in use by ...). Preferred fix: weaken the reference first — CrossStackReferences.of($RESOURCE).produce(ReferenceStrength.BOTH) then WEAK, then remove (three deploys). Legacy fallback: two-deploy this.exportValue() recipe. See troubleshooting-deployment.

Construct ID changes cause replacement: Renaming/moving a construct changes its logical ID → CloudFormation replaces the resource (data loss for stateful resources). Always cdk diff before deploy. See refactor-and-prevent-replacement.

UPDATE_ROLLBACK_FAILED: Stack is stuck. Fix with cdk rollback $STACK or cdk rollback $STACK --orphan <LogicalId>. See troubleshooting-deployment.

Non-empty S3 buckets persist after destroy: You MUST set both removalPolicy: DESTROY and autoDeleteObjects: true. Versioned buckets are worse — delete markers persist even after apparent deletion.

Common Workflows

TaskQuick CommandDetails
Bootstrapcdk bootstrap aws://$ACCOUNT/$REGIONbootstrap-and-project-setup
New TS projectcdk init app --language typescript — use tsx, eslint-plugin-awscdkbootstrap-and-project-setup
New Python projectcdk init app --language python — pin deps, use virtualenvbootstrap-and-project-setup
Deploycdk synth --strictcdk diffcdk deployAlways diff before deploy to prod
cdk-nagAspects.of(app).add(new AwsSolutionsChecks())compliance-and-drift
Driftcdk drift $STACK (use --fail in CI)compliance-and-drift
Import resourcecdk import (interactive or --resource-mapping for CI), cdk deploy --import-existing-resourcesimport-and-migrate
Refactor safelycdk refactor --unstable=refactor — no property changes in same deployrefactor-and-prevent-replacement

Troubleshooting

ErrorCause → Fix
DeployFailed / DeploymentErrorCDK error isn't the root cause. cdk deploy $STACK --verbose, then cdk --unstable=diagnose diagnose $STACK (CLI ≥ 2.1120.0); else aws cloudformation describe-events --stack-name $STACK --filters FailedEvents=true — the first _FAILED event is the cause. Details
NoCredentials / ExpiredToken / AssumeRoleFailedaws sts get-caller-identity + cdk doctor. Expired SSO, missing env, missing sts:AssumeRole. Details
Asset errors (CannotFindAsset, FailedToBundleAsset, AssetBuildFailed, AssetPublishFailed)Path wrong, Docker not running, or bootstrap bucket perms. Use path.join(__dirname, ...). Details
AppRequiredAdd "app": "npx tsx bin/my-app.ts" to cdk.json. Details
AnnotationErrorsFix the underlying issue; suppress with NagSuppressions only as last resort. Details
ConcurrentReadLock / ConcurrentWriteLockrm -rf cdk.out then re-run. Parallel CI: --output ./cdk.out.$BUILD_ID. Details
BootstrapVersionValidationRe-bootstrap. Match --qualifier everywhere. Details
DependencyCycleExtract shared resource into third stack or use SSM for late-binding. Details
UnresolvedAccountSet explicit env: { account, region } on stack. Commit cdk.context.json. Details
NoStacksMatchedCDK uses logical ID (2nd constructor arg), not CFN name. cdk list to find IDs. Details
Cannot find module (synth time)Run npx tsc --noEmit, check cdk.json app path matches tsconfig.json outDir, delete stale .js files. Python: activate venv. Details
V1 import paths / duplicate aws-cdk-libV1 @aws-cdk/* imports, wrong Construct import, duplicate lib copies in monorepos. Details
Lambda Cannot find module (runtime)Wrong handler value, missing SDK v3 migration, Python deps not bundled. Details
API Gateway multi-stage conflictsSet deploy: false on RestApi, create Deployment and Stage explicitly. Details

Construct Patterns

Prefer L2. Use L1 with Mixins/Facades when L2 lacks a property. Escape hatches: node.defaultChildaddPropertyOverride. See construct-patterns.

Additional Resources

  • Search AWS documentation for "CDK Developer Guide", "CDK API Reference" and "CDK Pipelines" respectively

Security Considerations

  • OIDC for CI/CD credentials (no static keys)
  • --custom-permissions-boundary on bootstrap
  • grant*() for inter-resource IAM
  • cdk-nag + --strict in CI
  • Stateful resources in own stack with terminationProtection: true
  • Commit cdk.context.json

Skills เพิ่มเติมจาก aws

agents-build
aws
ใช้เพื่อขยายโปรเจกต์ agent ที่มีอยู่ด้วย memory, การผสานรวมแอป, VPC, multi-agent, การย้ายระบบ, โมเดล, เบราว์เซอร์, code interpreter, การชำระเงิน หรือทรัพยากร…
official
agents-connect
aws
ใช้เมื่อเชื่อมต่อเอเจนต์ของคุณกับ API เครื่องมือ หรือบริการภายนอกผ่าน Gateway หรือจำกัดการเข้าถึงเครื่องมือด้วยนโยบาย Cedar จัดการการตั้งค่า Gateway เป้าหมาย…
official
agents-debug
aws
ใช้เมื่อเอเจนต์หรือสภาพแวดล้อมของคุณมีปัญหา เช่น คำตอบที่ผิด ข้อผิดพลาด หมดเวลา เครื่องมือล้มเหลว หรือปัญหา CLI อ่านเทรซและล็อกเพื่อวินิจฉัยสาเหตุต้นตอ…
official
agents-deploy
aws
ใช้เมื่อกำลัง部署เอเจนต์ของคุณไปยัง AWS หรือเมื่อการ部署ล้มเหลว จัดการการตรวจสอบก่อน部署 การวินิจฉัยข้อผิดพลาด CDK/IAM/โควตา การจัดการเวอร์ชัน การย้อนกลับ…
official
agents-get-started
aws
ใช้เมื่อนักพัฒนาต้องการสร้างโปรเจกต์เอเจนต์ใหม่หรือเริ่มต้นใช้งาน AgentCore จัดการเกี่ยวกับการเลือกเฟรมเวิร์ก การสร้างโครงโปรเจกต์ การดีพลอยครั้งแรก และ…
official
agents-harden
aws
Use when preparing your agent for production — IAM scoping, inbound auth (JWT, SigV4), secrets management, cold start optimization, session lifecycle, rate…
official
agents-pay
aws
Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying…
official
amazon-aurora-mysql
aws
Amazon Aurora MySQL — creates, modifies, and advises on Aurora MySQL clusters specifically (MySQL-compatible engine, Aurora serverless, parallel query).…
official