[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-aws-aws-storage":3,"mdc-7ys45b-key":38,"related-org-aws-aws-storage":1513,"related-repo-aws-aws-storage":1685},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":11,"stars":27,"repoUrl":28,"updatedAt":29,"license":30,"forks":31,"topics":32,"repo":33,"sourceUrl":36,"mdContent":37},"aws-storage","manage and compare AWS storage services","Selects, investigates, and compares AWS object, file, and block storage services, and answers cost, performance, configuration, security, and troubleshooting questions about storage services. Applies when a user asks where to store or archive data based on their usage patterns; which storage service to choose or how two compare; how to migrate data from on-premises or between AWS services; how to protect, replicate, or recover data; how to optimize storage costs; where to deploy shared NFS, SMB, or POSIX file systems; where to store vector embeddings or tabular data; what storage backs enterprise file shares, self-managed databases on EC2, VMware, or stateful containers; or asks what an AWS storage service can do or how it works. Relevant for storage needs for workloads such as AI\u002FML, analytics, EDA, HPC, media, genomics, or financial trading. Not applicable for SQL query engines (Athena, Spark, Redshift, EMR), ETL (Glue), streaming (Kafka, MSK, Kinesis), or managed database services (RDS, Aurora, DynamoDB).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},"aws","AWS (Amazon)","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Faws.png",[12,16,19,22,25],{"name":13,"slug":14,"type":15},"Performance","performance","tag",{"name":17,"slug":18,"type":15},"File Storage","file-storage",{"name":20,"slug":21,"type":15},"Cloud","cloud",{"name":23,"slug":24,"type":15},"Storage","storage",{"name":26,"slug":8,"type":15},"AWS",1822,"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws","2026-08-23T04:00:39.407781",null,157,[],{"repoUrl":28,"stars":27,"forks":31,"topics":34,"description":35},[],"Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS","https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002FHEAD\u002Fskills\u002Fcore-skills\u002Faws-storage","---\nname: aws-storage\ndescription: \"Selects, investigates, and compares AWS object, file, and block storage services, and answers cost, performance, configuration, security, and troubleshooting questions about storage services. Applies when a user asks where to store or archive data based on their usage patterns; which storage service to choose or how two compare; how to migrate data from on-premises or between AWS services; how to protect, replicate, or recover data; how to optimize storage costs; where to deploy shared NFS, SMB, or POSIX file systems; where to store vector embeddings or tabular data; what storage backs enterprise file shares, self-managed databases on EC2, VMware, or stateful containers; or asks what an AWS storage service can do or how it works. Relevant for storage needs for workloads such as AI\u002FML, analytics, EDA, HPC, media, genomics, or financial trading. Not applicable for SQL query engines (Athena, Spark, Redshift, EMR), ETL (Glue), streaming (Kafka, MSK, Kinesis), or managed database services (RDS, Aurora, DynamoDB).\"\nmetadata:\n  version: \"1\"\n---\n## Overview\n\nThis skill provides domain expertise for choosing among AWS storage services, selecting storage classes, optimizing cost, and routing to resources for operating storage services. It covers object storage (S3 General Purpose buckets and their storage classes, S3 Express One Zone on directory buckets, S3 Tables, S3 Vectors), file storage (Amazon EFS, S3 Files, FSx for Lustre, FSx for NetApp ONTAP, FSx for OpenZFS, and FSx for Windows File Server), block storage (EBS volume types and EC2 instance store), and the data-movement and protection services that connect them (DataSync, Storage Gateway, Transfer Family, and AWS Backup). It does not advise on databases or analytics query engines. It works with or without the AWS MCP server; when available, the [AWS MCP server](https:\u002F\u002Fdocs.aws.amazon.com\u002Fagent-toolkit\u002F) is recommended for verifying current specifications and pricing, and all guidance also works with the standard AWS CLI. For deep single-service tasks, route to the specialized skills listed in the Routing section below.\n\n## How to Handle User Queries\n\nWhen this skill is triggered, classify the user's request and follow the appropriate path.\n\n### Rules\n\nThese apply to all responses regardless of path:\n\n1. You MUST verify current numbers. When the AWS MCP server is available, use search_documentation and read_documentation to cross-check before citing specifics. When quoting costs, you MUST include a link to the relevant pricing page. When quoting performance metrics, you MUST include a link to the relevant product page. Otherwise, verify against linked AWS documentation pages or use the AWS CLI to confirm current values. Where a reference file directs you to documentation for a current value, you MUST retrieve that value from the linked page before answering. Do not substitute a remembered figure, and do not offer an approximation or a range in place of a retrieved value. If retrieval is not possible in the current environment, name the value you could not verify rather than citing one from memory.\n2. You MUST retrieve the relevant service reference file from the Routing section below before answering questions about that service. AWS storage specifications, limits, and service capabilities change frequently. You MUST NOT answer from memory alone. You MUST surface relevant troubleshooting guidance and 'gotchas' from reference files in your response. Justify recommendations by workload fit, not by mentioning that a reference file 'explicitly' mentions a workload for a given service.\n3. You MUST include cost implications when recommending services or approaches. Do not wait for the user to ask. Do not compare services on storage charges alone; per-object fees such as metadata charges can materially change TCO. For deep cost analysis, monitoring, or optimization beyond storage selection, route to the [`billing-and-cost-management`](https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fe2588f4b494416e68c5a991e51b21c2d99038de3\u002Fskills\u002Fcore-skills\u002Faws-billing-and-cost-management) skill.\n4. You MUST have clarity on the user's need when making a recommendation. Match the specificity of your response to the specificity of the request. When the query determines the storage category and the relevant services, retrieve information and recommend directly. When the query is not fully specified, YOU MUST mention the assumptions and limitations of your recommendation and include the additional questions that would confirm or change it. Ask follow up questions in place of a recommendation only when the query does not let you determine the storage category at all. Recommend the best-fit service for the workload even when it falls outside this skill's scope; add relevant in-scope options as alternatives.\n\n---\n\n### Step 1: Classify Intent\n\nDetermine what the user needs:\n\n| Intent | Example Triggers | What this means |\n| --- | --- | --- |\n| SELECT | \"What should I use?\", \"Which service?\", \"Compare Service A vs Service B\", \"Help me choose\", \"I want to migrate X to AWS\" (workload description without a named service) | User needs help choosing a storage service or approach |\n| INVESTIGATE | \"How do I configure Service X?\", \"Why is Service Y failing?\", \"What are the limits of Service Z?\", \"How do I get started with Service X?\" (names a specific service and asks an operational question) | User knows what they are using and needs getting started, troubleshooting, or operational help |\n\nYou MUST follow the interaction logic in the corresponding path instructions below.\n\nAmbiguous cases: If the user's primary ask is a recommendation, it is SELECT regardless of context. If they need help executing a known plan, it is INVESTIGATE.\n\n---\n\n### Step 2a: SELECT Path\n\nThe user needs help choosing. You MUST use the following decision factors to inform your recommendation, asking questions to fill gaps that would change the choice.\n\nDecision Factors:\n\n| # | Decision Factor | What to understand |\n| --- | --- | --- |\n| 1 | Workload Context | Is this a new workload or a migration of an existing workload? If migrating, what is the source system (e.g., NetApp, ZFS, Windows File Server, Lustre, GPFS, etc.)? What application or workload will access this storage? How does it access data (API, file protocol, block device)? What OS or platform are clients running? What is the data model (structured\u002Ftabular, vector embeddings, unstructured objects, file system)? |\n| 2 | Capacity and Access Patterns | How much data, how many files or objects, what are the typical sizes? Sequential or random access pattern? Read-heavy, write-heavy, or mixed? |\n| 3 | Performance Requirements | Are there specific latency, throughput, or IOPS requirements? What is the expected concurrency (number of clients or compute nodes accessing simultaneously)? |\n| 4 | Durability and Data Protection | What is the recovery time objective (RTO)? Recovery point objective (RPO)? Compliance retention mandates? Cross-region resilience? Immutability needs? |\n| 5 | Availability | Multi-AZ or Single-AZ acceptable? Co-located with specific compute? |\n\nUse the Storage Options table to identify candidate services, not to cut services; keyword matches against the Common Workloads column are not the only answers. You MUST retrieve the reference files for each of the candidate services using the Routing section below.\n\nConsidering these factors, recommend specific AWS storage service(s) and:\n1. You MUST include clear rationale tied to the user's stated requirements.\n2. You MUST present alternatives where the choice is close or dependent on unspecified information, explaining the tradeoff.\n\n---\n\n### Step 2b: INVESTIGATE Path\n\nThe user knows their service or approach and needs operational help.\n\n1. Classify the Question Domain based on the table below to identify which context matters.\n\n| Question Domain | Example Triggers | What to clarify |\n| --- | --- | --- |\n| Migration and Data Transfer | \"How do I move my data to AWS?\", \"Set up DataSync\", \"Sync from on-premises NFS to EFS\", source-to-destination questions | Source system and protocol, destination service, data volume, network path to AWS (Direct Connect, VPN, internet) |\n| Data Protection and Resiliency | \"Set up backup\", \"Cross-region replication\", \"What's my DR strategy?\", \"RTO under 1 hour\", failover, immutability | Failure scenario (deletion, corruption, AZ\u002Fregion loss, compliance hold), RTO and RPO targets, replication scope (same-region, cross-region, cross-account) |\n| Cost and Lifecycle | \"Reduce my storage bill\", \"Right-size my volumes\", \"Cost optimize\", lifecycle rules, tiering decisions, storage class selection | Current service and configuration, access frequency (daily, weekly, rarely), data volume and growth trajectory |\n| Performance | \"My reads are slow\", \"Throughput bottleneck\", \"Need more IOPS\", sizing | Observed vs. required (latency, IOPS, or throughput), access pattern (random\u002Fsequential, read\u002Fwrite mix), whether storage or compute\u002Fnetwork is the suspected bottleneck |\n| Security and Compliance | \"Encrypt at rest\", \"Restrict bucket access\", \"Meet HIPAA\", access control, compliance frameworks | Security objective (restrict access, audit access, encrypt, isolate network, meet compliance mandate), compliance framework if any |\n| Configuration and Guidance | \"Mount EFS on EKS\", \"Set up replication\", \"Does Service X support Y?\", deployment steps, best practices | Client environment (OS, compute type, VPC\u002Fon-premises), target operation or feature |\n| Troubleshooting | \"Getting AccessDenied errors\", \"Mount is hanging\", \"Unexpected latency spike\", \"Why is my lifecycle rule not transitioning?\" | Error message or symptom, what changed recently, what they have attempted |\n\n2. Ask scoping questions per the \"What to clarify\" column for information not already in the query. Where the missing detail would not change the guidance, answer under a stated assumption instead of waiting to ask more questions.\n3. You MUST retrieve the reference files from the Routing section below for all candidate services.\n4. Provide the answer with specific, actionable guidance, gotchas, and documentation links.\n5. When answering Configuration or Security questions, you MUST recommend enabling access logging, CloudTrail data events, and CloudWatch metrics for observability.\n\n## Storage Options\n\nAWS storage services covered by this skill, grouped by storage category. For more information on storage categories, see [Block, file, and object storage compared](https:\u002F\u002Faws.amazon.com\u002Fcompare\u002Fthe-difference-between-block-file-object-storage\u002F).\n\n### Object Storage\n\n| Service | Key Characteristics | Common Workloads |\n| --- | --- | --- |\n| S3 General Purpose | Virtually unlimited-scale object storage with multiple storage classes spanning frequent-access to low-cost archive; lifecycle rules move data to lower-cost storage classes optimized for less-frequently accessed data. Regional availability. Accessed over a REST\u002FHTTP API from anywhere. | Data lakes and analytics, backup and archive targets, ML training data, media storage and content distribution, log and event data, static website and application assets, regulatory and compliance archives |\n| S3 Express One Zone | Single-AZ directory buckets optimized for single-digit millisecond latency on frequently accessed, latency-sensitive data. | large-scale ML training and inference, Spark and EMR shuffle, ML checkpoints, scratch, and model loading, ETL intermediate data, interactive analytics on hot partitions, observability and log analytics (hot tier), Kafka tiered storage, media and video editing, high-frequency transactional access, caching for machine learning inference |\n| S3 Tables | Managed Apache Iceberg tables on S3 with automatic compaction and query optimization. Regional availability. Built for structured, tabular data queried with SQL engines. | Data lake tables, structured analytics data, ETL pipeline outputs, streaming into tables for SQL analysis, migration of open table format data outside of S3 or self-managed Iceberg on S3 |\n| S3 Vectors | Vector storage and similarity search on S3 with native support to cost-effectively store and query vector embeddings. Provides the same elasticity, durability and availability as S3 General Purpose buckets. Regional availability. | RAG pipelines, semantic search, recommendation systems, vector deduplication and matching, anomaly and fraud detection, AI agent memory, cost-effective storage of large vector datasets |\n| S3 Metadata | Queryable object metadata in fully managed, read-only Apache Iceberg tables including system-defined details, user-defined metadata, object tags, and annotations | Business analytics, content cataloging, data governance and compliance, storage optimization, real-time inference applications, AI agents |\n\n### File Storage\n\nWhen naming a service, you MUST always specify the full name (FSx for Lustre, FSx for Windows File Server, FSx for NetApp ONTAP, or FSx for OpenZFS). EFS and S3 Files can be mounted by Lambda and Fargate. Verify additional services mountable from serverless compute with the latest AWS documentation. FSx for NetApp ONTAP and FSx for OpenZFS data is accessible from serverless compute and S3-based pipelines via S3 Access Points for FSx (exposes file data through the S3 API without copying; surface this when a user needs to read FSx-resident data from S3-native consumers or analytics services).\n\n| Service | Key Characteristics | Common Workloads |\n| --- | --- | --- |\n| EFS | EFS Standard, EFS Infrequent Access (EFS IA), and EFS Archive storage classes, managed by EFS Lifecycle Management for automatic cost optimization. Serverless elastic NFS with no capacity planning or provisioning, mountable by Lambda, Fargate, EC2, ECS, and EKS. Multi-AZ by default (Regional) or One Zone. Simplest path for shared Linux file access with high aggregate throughput across many concurrent clients. | Containers (ECS, EKS, Fargate), cloud-native Linux applications, serverless persistent storage, analytics and ML training data (including SageMaker), big data, media processing, content management, shared home directories, web serving, dev\u002Ftest, infrequently accessed file data |\n| FSx for Lustre | SSD and Intelligent-Tiering storage classes, where Intelligent-Tiering is fully elastic and SSD is fixed-capacity. Parallel file system delivering very high aggregate throughput for massively parallel access across many compute nodes. | ML and GPU training and inference at scale, HPC, genomics and seismic processing, financial modeling, media rendering, back-end EDA |\n| FSx for OpenZFS | Intelligent-Tiering alongside SSD, with ZFS data management (instant writable clones, snapshots, compression, on-demand replication). Very low latency with high IOPS, simple to operate and cost-effective for performance-sensitive workloads and fast dev\u002Ftest cycles. Single-AZ and Multi-AZ deployment model. S3-API access via S3 Access Points for FSx. | Databases (including on EC2), dev\u002Ftest with fast clones, ZFS or Linux-NFS migrations, front-end EDA, financial modeling, media processing, latency-sensitive line-of-business applications |\n| FSx for NetApp ONTAP | Full ONTAP data management (SnapMirror replication, FlexClone, dedup, compression, SnapLock WORM, QoS, vscan antivirus, file-access auditing). Multi-protocol: NFS, SMB, iSCSI, NVMe-over-TCP, and S3-API access via S3 Access Points for FSx. Scales to high aggregate throughput and IOPS. Single-AZ and Multi-AZ deployment model. | Enterprise network-attached storage (NAS) migrations, multi-protocol environments, general-purpose file shares and home directories, business-critical databases including on EC2 (SAP HANA, Oracle, SQL Server), VMware datastores, line-of-business applications (medical imaging, product lifecycle management), front-end EDA (chip design and verification), hybrid and DR |\n| FSx for Windows File Server | Fully managed SMB file storage built on Windows Server with Active Directory identity (Kerberos, NTFS ACLs), DFS namespaces, shadow copies, and FSRM quotas; shares are also accessible from Linux and macOS clients. Single-AZ and Multi-AZ deployment model. | Windows file, home, and department shares, .NET applications, Microsoft SQL Server, Windows Server migrations |\n\n### Block Storage\n\n| Service | Key Characteristics | Common Workloads |\n| --- | --- | --- |\n| EBS | High-performance virtual disk that attaches to an EC2 instance over the network. Durable, resizable SSD or HDD that persists independently of the instance, supports snapshots for backup, time-based snapshot copy, and provisions performance independently of capacity on gp3 (confirm latest volume limits). Supports instant volume clones. AZ-scoped. | Databases, transactional applications and file systems, boot volumes, dev\u002Ftest environments, sequential batch processing, log and data warehouse scans |\n| EC2 Instance Store | Physically local SSD storage built into the host server, delivering the lowest latency and highest throughput. Ephemeral: data is lost if the instance stops or the hardware fails. | Temporary scratch data, caches, and buffers you can afford to lose |\n\n---\n\n## Cross-Service Overlap\n\nSome storage features cross category boundaries, giving a service from one storage category an interface normally associated with another. Surface these when a workload needs access to shared data from multiple protocols or interfaces.\n\n| Feature | What it enables | What it is | Additional sources |\n| --- | --- | --- | --- |\n| S3 Files | Makes S3 data accessible to file-based applications | Fully managed NFS file access over an S3 bucket, built on EFS infrastructure. Data stays in S3 as the system of record. File locking, POSIX permissions, and full read-write. Choose over EFS when data already lives in S3 and needs file-path access alongside object access. | `references\u002Fs3-files-knowledge.md`, `references\u002Fefs-knowledge.md` |\n| S3 Access Points for FSx | Makes FSx-resident data accessible to S3-based applications and services | Exposes FSx for NetApp ONTAP or FSx for OpenZFS data through the S3 API without copying it to a bucket. Surface when file data must reach S3-native consumers, or when serverless or S3-based applications need to access data that lives on FSx for NetApp ONTAP or FSx for OpenZFS. | `references\u002Ffsx-ontap-knowledge.md`, `references\u002Ffsx-openzfs-knowledge.md` |\n\n---\n\n## Security\n\nCloud security at AWS is the highest priority and is a shared responsibility between AWS and the customer. You MUST include security guidance when recommending or configuring storage resources. You MUST always recommend enabling encryption at rest and encryption in transit. Where encryption at rest is optional or not the default, explicitly advise enabling it at creation time, because it is often immutable after creation. You MUST recommend scoping IAM policies to the authorized principals with least-privileged permissions. You MUST recommend adding condition keys (e.g., aws:SourceArn, aws:SourceAccount, aws:SourceVpc) to resource policies to prevent cross-service confused deputy attacks. You MUST recommend encrypting log destinations: AWS KMS for CloudTrail trails and CloudWatch Logs groups, server-side encryption for server access log buckets, and AWS KMS for SNS topics. Prefer short-lived credentials or IAM-based authentication (e.g., via custom IdP with temporary tokens) over long-lived SSH keys. Where SSH keys are required, enforce rotation policies and store private keys in AWS Secrets Manager for supported services. You MUST recommend restricting security group inbound rules to the narrowest applicable source (specific client security group or minimal CIDR). Service-specific security controls, encryption models, and documentation links are in the Security row of each reference's Service Information table; you MUST read it before advising on that service.\n\n## Routing\n\nWhen loaded through the AWS MCP server's retrieve_skill tool: the skill is not installed on the local filesystem. You MUST retrieve each reference via retrieve_skill with the file parameter (e.g. file=\"references\u002Fs3-general-purpose-knowledge.md\"). Do NOT file_read these paths locally. When loaded outside the AWS MCP server (for example from the local filesystem in the Agent Toolkit), read the reference files directly from their relative paths in the skill directory.\n\n### Reference files\n\n| Topic | Reference |\n| --- | --- |\n| S3 (General Purpose) | `references\u002Fs3-general-purpose-knowledge.md` |\n| S3 Metadata | `references\u002Fs3-general-purpose-knowledge.md` |\n| S3 Tables | `references\u002Fs3-tables-knowledge.md` |\n| S3 Vectors | `references\u002Fs3-vectors-knowledge.md` |\n| S3 Express One Zone | `references\u002Fs3-express-knowledge.md` |\n| S3 Files | `references\u002Fs3-files-knowledge.md` |\n| Amazon EFS | `references\u002Fefs-knowledge.md` |\n| FSx for Lustre | `references\u002Ffsx-lustre-knowledge.md` |\n| FSx for NetApp ONTAP | `references\u002Ffsx-ontap-knowledge.md` |\n| FSx for OpenZFS | `references\u002Ffsx-openzfs-knowledge.md` |\n| FSx for Windows File Server | `references\u002Ffsx-windows-knowledge.md` |\n| Amazon EBS | `references\u002Febs-knowledge.md` |\n| Data Movement and Protection (DataSync, Transfer Family, Storage Gateway, AWS Backup) | `references\u002Fdata-movement-and-protection-knowledge.md` |\n\n### Specialized skills\n\n| Topic | Reference |\n| --- | --- |\n| Security on S3 | [`securing-s3-buckets`](https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fstorage-skills\u002Fsecuring-s3-buckets) |\n| Using S3 Tables | [`creating-data-lake-table`](https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fstorage-skills\u002Fcreating-data-lake-table) |\n| Using S3 Vectors | [`storing-and-querying-vectors`](https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fstorage-skills\u002Fstoring-and-querying-vectors) |\n| Troubleshooting S3 Files | [`troubleshooting-s3-files`](https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fstorage-skills\u002Ftroubleshooting-s3-files) |\n| Troubleshooting EFS | [`troubleshooting-efs`](https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fstorage-skills\u002Ftroubleshooting-efs) |\n| Querying S3 System Tables | [`querying-aws-s3`](https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fsystem-table-skills\u002Fquerying-aws-s3) |\n| Ingesting data into a data lake | [`ingesting-into-data-lake`](https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fanalytics-skills\u002Fingesting-into-data-lake) |\n| Finding data lake assets | [`finding-data-lake-assets`](https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fanalytics-skills\u002Ffinding-data-lake-assets) |\n| Querying data lakes | [`querying-data-lake`](https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fanalytics-skills\u002Fquerying-data-lake) |",{"data":39,"body":42},{"name":4,"description":6,"metadata":40},{"version":41},"1",{"type":43,"children":44},"root",[45,54,71,77,82,89,94,133,137,143,148,217,222,227,230,236,241,246,362,367,372,385,388,394,399,407,558,582,588,602,608,725,729,734,848,854,914,917,923,928,1029,1032,1038,1043,1049,1054,1060,1289,1295],{"type":46,"tag":47,"props":48,"children":50},"element","h2",{"id":49},"overview",[51],{"type":52,"value":53},"text","Overview",{"type":46,"tag":55,"props":56,"children":57},"p",{},[58,60,69],{"type":52,"value":59},"This skill provides domain expertise for choosing among AWS storage services, selecting storage classes, optimizing cost, and routing to resources for operating storage services. It covers object storage (S3 General Purpose buckets and their storage classes, S3 Express One Zone on directory buckets, S3 Tables, S3 Vectors), file storage (Amazon EFS, S3 Files, FSx for Lustre, FSx for NetApp ONTAP, FSx for OpenZFS, and FSx for Windows File Server), block storage (EBS volume types and EC2 instance store), and the data-movement and protection services that connect them (DataSync, Storage Gateway, Transfer Family, and AWS Backup). It does not advise on databases or analytics query engines. It works with or without the AWS MCP server; when available, the ",{"type":46,"tag":61,"props":62,"children":66},"a",{"href":63,"rel":64},"https:\u002F\u002Fdocs.aws.amazon.com\u002Fagent-toolkit\u002F",[65],"nofollow",[67],{"type":52,"value":68},"AWS MCP server",{"type":52,"value":70}," is recommended for verifying current specifications and pricing, and all guidance also works with the standard AWS CLI. For deep single-service tasks, route to the specialized skills listed in the Routing section below.",{"type":46,"tag":47,"props":72,"children":74},{"id":73},"how-to-handle-user-queries",[75],{"type":52,"value":76},"How to Handle User Queries",{"type":46,"tag":55,"props":78,"children":79},{},[80],{"type":52,"value":81},"When this skill is triggered, classify the user's request and follow the appropriate path.",{"type":46,"tag":83,"props":84,"children":86},"h3",{"id":85},"rules",[87],{"type":52,"value":88},"Rules",{"type":46,"tag":55,"props":90,"children":91},{},[92],{"type":52,"value":93},"These apply to all responses regardless of path:",{"type":46,"tag":95,"props":96,"children":97},"ol",{},[98,104,109,128],{"type":46,"tag":99,"props":100,"children":101},"li",{},[102],{"type":52,"value":103},"You MUST verify current numbers. When the AWS MCP server is available, use search_documentation and read_documentation to cross-check before citing specifics. When quoting costs, you MUST include a link to the relevant pricing page. When quoting performance metrics, you MUST include a link to the relevant product page. Otherwise, verify against linked AWS documentation pages or use the AWS CLI to confirm current values. Where a reference file directs you to documentation for a current value, you MUST retrieve that value from the linked page before answering. Do not substitute a remembered figure, and do not offer an approximation or a range in place of a retrieved value. If retrieval is not possible in the current environment, name the value you could not verify rather than citing one from memory.",{"type":46,"tag":99,"props":105,"children":106},{},[107],{"type":52,"value":108},"You MUST retrieve the relevant service reference file from the Routing section below before answering questions about that service. AWS storage specifications, limits, and service capabilities change frequently. You MUST NOT answer from memory alone. You MUST surface relevant troubleshooting guidance and 'gotchas' from reference files in your response. Justify recommendations by workload fit, not by mentioning that a reference file 'explicitly' mentions a workload for a given service.",{"type":46,"tag":99,"props":110,"children":111},{},[112,114,126],{"type":52,"value":113},"You MUST include cost implications when recommending services or approaches. Do not wait for the user to ask. Do not compare services on storage charges alone; per-object fees such as metadata charges can materially change TCO. For deep cost analysis, monitoring, or optimization beyond storage selection, route to the ",{"type":46,"tag":61,"props":115,"children":118},{"href":116,"rel":117},"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fe2588f4b494416e68c5a991e51b21c2d99038de3\u002Fskills\u002Fcore-skills\u002Faws-billing-and-cost-management",[65],[119],{"type":46,"tag":120,"props":121,"children":123},"code",{"className":122},[],[124],{"type":52,"value":125},"billing-and-cost-management",{"type":52,"value":127}," skill.",{"type":46,"tag":99,"props":129,"children":130},{},[131],{"type":52,"value":132},"You MUST have clarity on the user's need when making a recommendation. Match the specificity of your response to the specificity of the request. When the query determines the storage category and the relevant services, retrieve information and recommend directly. When the query is not fully specified, YOU MUST mention the assumptions and limitations of your recommendation and include the additional questions that would confirm or change it. Ask follow up questions in place of a recommendation only when the query does not let you determine the storage category at all. Recommend the best-fit service for the workload even when it falls outside this skill's scope; add relevant in-scope options as alternatives.",{"type":46,"tag":134,"props":135,"children":136},"hr",{},[],{"type":46,"tag":83,"props":138,"children":140},{"id":139},"step-1-classify-intent",[141],{"type":52,"value":142},"Step 1: Classify Intent",{"type":46,"tag":55,"props":144,"children":145},{},[146],{"type":52,"value":147},"Determine what the user needs:",{"type":46,"tag":149,"props":150,"children":151},"table",{},[152,176],{"type":46,"tag":153,"props":154,"children":155},"thead",{},[156],{"type":46,"tag":157,"props":158,"children":159},"tr",{},[160,166,171],{"type":46,"tag":161,"props":162,"children":163},"th",{},[164],{"type":52,"value":165},"Intent",{"type":46,"tag":161,"props":167,"children":168},{},[169],{"type":52,"value":170},"Example Triggers",{"type":46,"tag":161,"props":172,"children":173},{},[174],{"type":52,"value":175},"What this means",{"type":46,"tag":177,"props":178,"children":179},"tbody",{},[180,199],{"type":46,"tag":157,"props":181,"children":182},{},[183,189,194],{"type":46,"tag":184,"props":185,"children":186},"td",{},[187],{"type":52,"value":188},"SELECT",{"type":46,"tag":184,"props":190,"children":191},{},[192],{"type":52,"value":193},"\"What should I use?\", \"Which service?\", \"Compare Service A vs Service B\", \"Help me choose\", \"I want to migrate X to AWS\" (workload description without a named service)",{"type":46,"tag":184,"props":195,"children":196},{},[197],{"type":52,"value":198},"User needs help choosing a storage service or approach",{"type":46,"tag":157,"props":200,"children":201},{},[202,207,212],{"type":46,"tag":184,"props":203,"children":204},{},[205],{"type":52,"value":206},"INVESTIGATE",{"type":46,"tag":184,"props":208,"children":209},{},[210],{"type":52,"value":211},"\"How do I configure Service X?\", \"Why is Service Y failing?\", \"What are the limits of Service Z?\", \"How do I get started with Service X?\" (names a specific service and asks an operational question)",{"type":46,"tag":184,"props":213,"children":214},{},[215],{"type":52,"value":216},"User knows what they are using and needs getting started, troubleshooting, or operational help",{"type":46,"tag":55,"props":218,"children":219},{},[220],{"type":52,"value":221},"You MUST follow the interaction logic in the corresponding path instructions below.",{"type":46,"tag":55,"props":223,"children":224},{},[225],{"type":52,"value":226},"Ambiguous cases: If the user's primary ask is a recommendation, it is SELECT regardless of context. If they need help executing a known plan, it is INVESTIGATE.",{"type":46,"tag":134,"props":228,"children":229},{},[],{"type":46,"tag":83,"props":231,"children":233},{"id":232},"step-2a-select-path",[234],{"type":52,"value":235},"Step 2a: SELECT Path",{"type":46,"tag":55,"props":237,"children":238},{},[239],{"type":52,"value":240},"The user needs help choosing. You MUST use the following decision factors to inform your recommendation, asking questions to fill gaps that would change the choice.",{"type":46,"tag":55,"props":242,"children":243},{},[244],{"type":52,"value":245},"Decision Factors:",{"type":46,"tag":149,"props":247,"children":248},{},[249,270],{"type":46,"tag":153,"props":250,"children":251},{},[252],{"type":46,"tag":157,"props":253,"children":254},{},[255,260,265],{"type":46,"tag":161,"props":256,"children":257},{},[258],{"type":52,"value":259},"#",{"type":46,"tag":161,"props":261,"children":262},{},[263],{"type":52,"value":264},"Decision Factor",{"type":46,"tag":161,"props":266,"children":267},{},[268],{"type":52,"value":269},"What to understand",{"type":46,"tag":177,"props":271,"children":272},{},[273,290,308,326,344],{"type":46,"tag":157,"props":274,"children":275},{},[276,280,285],{"type":46,"tag":184,"props":277,"children":278},{},[279],{"type":52,"value":41},{"type":46,"tag":184,"props":281,"children":282},{},[283],{"type":52,"value":284},"Workload Context",{"type":46,"tag":184,"props":286,"children":287},{},[288],{"type":52,"value":289},"Is this a new workload or a migration of an existing workload? If migrating, what is the source system (e.g., NetApp, ZFS, Windows File Server, Lustre, GPFS, etc.)? What application or workload will access this storage? How does it access data (API, file protocol, block device)? What OS or platform are clients running? What is the data model (structured\u002Ftabular, vector embeddings, unstructured objects, file system)?",{"type":46,"tag":157,"props":291,"children":292},{},[293,298,303],{"type":46,"tag":184,"props":294,"children":295},{},[296],{"type":52,"value":297},"2",{"type":46,"tag":184,"props":299,"children":300},{},[301],{"type":52,"value":302},"Capacity and Access Patterns",{"type":46,"tag":184,"props":304,"children":305},{},[306],{"type":52,"value":307},"How much data, how many files or objects, what are the typical sizes? Sequential or random access pattern? Read-heavy, write-heavy, or mixed?",{"type":46,"tag":157,"props":309,"children":310},{},[311,316,321],{"type":46,"tag":184,"props":312,"children":313},{},[314],{"type":52,"value":315},"3",{"type":46,"tag":184,"props":317,"children":318},{},[319],{"type":52,"value":320},"Performance Requirements",{"type":46,"tag":184,"props":322,"children":323},{},[324],{"type":52,"value":325},"Are there specific latency, throughput, or IOPS requirements? What is the expected concurrency (number of clients or compute nodes accessing simultaneously)?",{"type":46,"tag":157,"props":327,"children":328},{},[329,334,339],{"type":46,"tag":184,"props":330,"children":331},{},[332],{"type":52,"value":333},"4",{"type":46,"tag":184,"props":335,"children":336},{},[337],{"type":52,"value":338},"Durability and Data Protection",{"type":46,"tag":184,"props":340,"children":341},{},[342],{"type":52,"value":343},"What is the recovery time objective (RTO)? Recovery point objective (RPO)? Compliance retention mandates? Cross-region resilience? Immutability needs?",{"type":46,"tag":157,"props":345,"children":346},{},[347,352,357],{"type":46,"tag":184,"props":348,"children":349},{},[350],{"type":52,"value":351},"5",{"type":46,"tag":184,"props":353,"children":354},{},[355],{"type":52,"value":356},"Availability",{"type":46,"tag":184,"props":358,"children":359},{},[360],{"type":52,"value":361},"Multi-AZ or Single-AZ acceptable? Co-located with specific compute?",{"type":46,"tag":55,"props":363,"children":364},{},[365],{"type":52,"value":366},"Use the Storage Options table to identify candidate services, not to cut services; keyword matches against the Common Workloads column are not the only answers. You MUST retrieve the reference files for each of the candidate services using the Routing section below.",{"type":46,"tag":55,"props":368,"children":369},{},[370],{"type":52,"value":371},"Considering these factors, recommend specific AWS storage service(s) and:",{"type":46,"tag":95,"props":373,"children":374},{},[375,380],{"type":46,"tag":99,"props":376,"children":377},{},[378],{"type":52,"value":379},"You MUST include clear rationale tied to the user's stated requirements.",{"type":46,"tag":99,"props":381,"children":382},{},[383],{"type":52,"value":384},"You MUST present alternatives where the choice is close or dependent on unspecified information, explaining the tradeoff.",{"type":46,"tag":134,"props":386,"children":387},{},[],{"type":46,"tag":83,"props":389,"children":391},{"id":390},"step-2b-investigate-path",[392],{"type":52,"value":393},"Step 2b: INVESTIGATE Path",{"type":46,"tag":55,"props":395,"children":396},{},[397],{"type":52,"value":398},"The user knows their service or approach and needs operational help.",{"type":46,"tag":95,"props":400,"children":401},{},[402],{"type":46,"tag":99,"props":403,"children":404},{},[405],{"type":52,"value":406},"Classify the Question Domain based on the table below to identify which context matters.",{"type":46,"tag":149,"props":408,"children":409},{},[410,430],{"type":46,"tag":153,"props":411,"children":412},{},[413],{"type":46,"tag":157,"props":414,"children":415},{},[416,421,425],{"type":46,"tag":161,"props":417,"children":418},{},[419],{"type":52,"value":420},"Question Domain",{"type":46,"tag":161,"props":422,"children":423},{},[424],{"type":52,"value":170},{"type":46,"tag":161,"props":426,"children":427},{},[428],{"type":52,"value":429},"What to clarify",{"type":46,"tag":177,"props":431,"children":432},{},[433,451,469,487,504,522,540],{"type":46,"tag":157,"props":434,"children":435},{},[436,441,446],{"type":46,"tag":184,"props":437,"children":438},{},[439],{"type":52,"value":440},"Migration and Data Transfer",{"type":46,"tag":184,"props":442,"children":443},{},[444],{"type":52,"value":445},"\"How do I move my data to AWS?\", \"Set up DataSync\", \"Sync from on-premises NFS to EFS\", source-to-destination questions",{"type":46,"tag":184,"props":447,"children":448},{},[449],{"type":52,"value":450},"Source system and protocol, destination service, data volume, network path to AWS (Direct Connect, VPN, internet)",{"type":46,"tag":157,"props":452,"children":453},{},[454,459,464],{"type":46,"tag":184,"props":455,"children":456},{},[457],{"type":52,"value":458},"Data Protection and Resiliency",{"type":46,"tag":184,"props":460,"children":461},{},[462],{"type":52,"value":463},"\"Set up backup\", \"Cross-region replication\", \"What's my DR strategy?\", \"RTO under 1 hour\", failover, immutability",{"type":46,"tag":184,"props":465,"children":466},{},[467],{"type":52,"value":468},"Failure scenario (deletion, corruption, AZ\u002Fregion loss, compliance hold), RTO and RPO targets, replication scope (same-region, cross-region, cross-account)",{"type":46,"tag":157,"props":470,"children":471},{},[472,477,482],{"type":46,"tag":184,"props":473,"children":474},{},[475],{"type":52,"value":476},"Cost and Lifecycle",{"type":46,"tag":184,"props":478,"children":479},{},[480],{"type":52,"value":481},"\"Reduce my storage bill\", \"Right-size my volumes\", \"Cost optimize\", lifecycle rules, tiering decisions, storage class selection",{"type":46,"tag":184,"props":483,"children":484},{},[485],{"type":52,"value":486},"Current service and configuration, access frequency (daily, weekly, rarely), data volume and growth trajectory",{"type":46,"tag":157,"props":488,"children":489},{},[490,494,499],{"type":46,"tag":184,"props":491,"children":492},{},[493],{"type":52,"value":13},{"type":46,"tag":184,"props":495,"children":496},{},[497],{"type":52,"value":498},"\"My reads are slow\", \"Throughput bottleneck\", \"Need more IOPS\", sizing",{"type":46,"tag":184,"props":500,"children":501},{},[502],{"type":52,"value":503},"Observed vs. required (latency, IOPS, or throughput), access pattern (random\u002Fsequential, read\u002Fwrite mix), whether storage or compute\u002Fnetwork is the suspected bottleneck",{"type":46,"tag":157,"props":505,"children":506},{},[507,512,517],{"type":46,"tag":184,"props":508,"children":509},{},[510],{"type":52,"value":511},"Security and Compliance",{"type":46,"tag":184,"props":513,"children":514},{},[515],{"type":52,"value":516},"\"Encrypt at rest\", \"Restrict bucket access\", \"Meet HIPAA\", access control, compliance frameworks",{"type":46,"tag":184,"props":518,"children":519},{},[520],{"type":52,"value":521},"Security objective (restrict access, audit access, encrypt, isolate network, meet compliance mandate), compliance framework if any",{"type":46,"tag":157,"props":523,"children":524},{},[525,530,535],{"type":46,"tag":184,"props":526,"children":527},{},[528],{"type":52,"value":529},"Configuration and Guidance",{"type":46,"tag":184,"props":531,"children":532},{},[533],{"type":52,"value":534},"\"Mount EFS on EKS\", \"Set up replication\", \"Does Service X support Y?\", deployment steps, best practices",{"type":46,"tag":184,"props":536,"children":537},{},[538],{"type":52,"value":539},"Client environment (OS, compute type, VPC\u002Fon-premises), target operation or feature",{"type":46,"tag":157,"props":541,"children":542},{},[543,548,553],{"type":46,"tag":184,"props":544,"children":545},{},[546],{"type":52,"value":547},"Troubleshooting",{"type":46,"tag":184,"props":549,"children":550},{},[551],{"type":52,"value":552},"\"Getting AccessDenied errors\", \"Mount is hanging\", \"Unexpected latency spike\", \"Why is my lifecycle rule not transitioning?\"",{"type":46,"tag":184,"props":554,"children":555},{},[556],{"type":52,"value":557},"Error message or symptom, what changed recently, what they have attempted",{"type":46,"tag":95,"props":559,"children":561},{"start":560},2,[562,567,572,577],{"type":46,"tag":99,"props":563,"children":564},{},[565],{"type":52,"value":566},"Ask scoping questions per the \"What to clarify\" column for information not already in the query. Where the missing detail would not change the guidance, answer under a stated assumption instead of waiting to ask more questions.",{"type":46,"tag":99,"props":568,"children":569},{},[570],{"type":52,"value":571},"You MUST retrieve the reference files from the Routing section below for all candidate services.",{"type":46,"tag":99,"props":573,"children":574},{},[575],{"type":52,"value":576},"Provide the answer with specific, actionable guidance, gotchas, and documentation links.",{"type":46,"tag":99,"props":578,"children":579},{},[580],{"type":52,"value":581},"When answering Configuration or Security questions, you MUST recommend enabling access logging, CloudTrail data events, and CloudWatch metrics for observability.",{"type":46,"tag":47,"props":583,"children":585},{"id":584},"storage-options",[586],{"type":52,"value":587},"Storage Options",{"type":46,"tag":55,"props":589,"children":590},{},[591,593,600],{"type":52,"value":592},"AWS storage services covered by this skill, grouped by storage category. For more information on storage categories, see ",{"type":46,"tag":61,"props":594,"children":597},{"href":595,"rel":596},"https:\u002F\u002Faws.amazon.com\u002Fcompare\u002Fthe-difference-between-block-file-object-storage\u002F",[65],[598],{"type":52,"value":599},"Block, file, and object storage compared",{"type":52,"value":601},".",{"type":46,"tag":83,"props":603,"children":605},{"id":604},"object-storage",[606],{"type":52,"value":607},"Object Storage",{"type":46,"tag":149,"props":609,"children":610},{},[611,632],{"type":46,"tag":153,"props":612,"children":613},{},[614],{"type":46,"tag":157,"props":615,"children":616},{},[617,622,627],{"type":46,"tag":161,"props":618,"children":619},{},[620],{"type":52,"value":621},"Service",{"type":46,"tag":161,"props":623,"children":624},{},[625],{"type":52,"value":626},"Key Characteristics",{"type":46,"tag":161,"props":628,"children":629},{},[630],{"type":52,"value":631},"Common Workloads",{"type":46,"tag":177,"props":633,"children":634},{},[635,653,671,689,707],{"type":46,"tag":157,"props":636,"children":637},{},[638,643,648],{"type":46,"tag":184,"props":639,"children":640},{},[641],{"type":52,"value":642},"S3 General Purpose",{"type":46,"tag":184,"props":644,"children":645},{},[646],{"type":52,"value":647},"Virtually unlimited-scale object storage with multiple storage classes spanning frequent-access to low-cost archive; lifecycle rules move data to lower-cost storage classes optimized for less-frequently accessed data. Regional availability. Accessed over a REST\u002FHTTP API from anywhere.",{"type":46,"tag":184,"props":649,"children":650},{},[651],{"type":52,"value":652},"Data lakes and analytics, backup and archive targets, ML training data, media storage and content distribution, log and event data, static website and application assets, regulatory and compliance archives",{"type":46,"tag":157,"props":654,"children":655},{},[656,661,666],{"type":46,"tag":184,"props":657,"children":658},{},[659],{"type":52,"value":660},"S3 Express One Zone",{"type":46,"tag":184,"props":662,"children":663},{},[664],{"type":52,"value":665},"Single-AZ directory buckets optimized for single-digit millisecond latency on frequently accessed, latency-sensitive data.",{"type":46,"tag":184,"props":667,"children":668},{},[669],{"type":52,"value":670},"large-scale ML training and inference, Spark and EMR shuffle, ML checkpoints, scratch, and model loading, ETL intermediate data, interactive analytics on hot partitions, observability and log analytics (hot tier), Kafka tiered storage, media and video editing, high-frequency transactional access, caching for machine learning inference",{"type":46,"tag":157,"props":672,"children":673},{},[674,679,684],{"type":46,"tag":184,"props":675,"children":676},{},[677],{"type":52,"value":678},"S3 Tables",{"type":46,"tag":184,"props":680,"children":681},{},[682],{"type":52,"value":683},"Managed Apache Iceberg tables on S3 with automatic compaction and query optimization. Regional availability. Built for structured, tabular data queried with SQL engines.",{"type":46,"tag":184,"props":685,"children":686},{},[687],{"type":52,"value":688},"Data lake tables, structured analytics data, ETL pipeline outputs, streaming into tables for SQL analysis, migration of open table format data outside of S3 or self-managed Iceberg on S3",{"type":46,"tag":157,"props":690,"children":691},{},[692,697,702],{"type":46,"tag":184,"props":693,"children":694},{},[695],{"type":52,"value":696},"S3 Vectors",{"type":46,"tag":184,"props":698,"children":699},{},[700],{"type":52,"value":701},"Vector storage and similarity search on S3 with native support to cost-effectively store and query vector embeddings. Provides the same elasticity, durability and availability as S3 General Purpose buckets. Regional availability.",{"type":46,"tag":184,"props":703,"children":704},{},[705],{"type":52,"value":706},"RAG pipelines, semantic search, recommendation systems, vector deduplication and matching, anomaly and fraud detection, AI agent memory, cost-effective storage of large vector datasets",{"type":46,"tag":157,"props":708,"children":709},{},[710,715,720],{"type":46,"tag":184,"props":711,"children":712},{},[713],{"type":52,"value":714},"S3 Metadata",{"type":46,"tag":184,"props":716,"children":717},{},[718],{"type":52,"value":719},"Queryable object metadata in fully managed, read-only Apache Iceberg tables including system-defined details, user-defined metadata, object tags, and annotations",{"type":46,"tag":184,"props":721,"children":722},{},[723],{"type":52,"value":724},"Business analytics, content cataloging, data governance and compliance, storage optimization, real-time inference applications, AI agents",{"type":46,"tag":83,"props":726,"children":727},{"id":18},[728],{"type":52,"value":17},{"type":46,"tag":55,"props":730,"children":731},{},[732],{"type":52,"value":733},"When naming a service, you MUST always specify the full name (FSx for Lustre, FSx for Windows File Server, FSx for NetApp ONTAP, or FSx for OpenZFS). EFS and S3 Files can be mounted by Lambda and Fargate. Verify additional services mountable from serverless compute with the latest AWS documentation. FSx for NetApp ONTAP and FSx for OpenZFS data is accessible from serverless compute and S3-based pipelines via S3 Access Points for FSx (exposes file data through the S3 API without copying; surface this when a user needs to read FSx-resident data from S3-native consumers or analytics services).",{"type":46,"tag":149,"props":735,"children":736},{},[737,755],{"type":46,"tag":153,"props":738,"children":739},{},[740],{"type":46,"tag":157,"props":741,"children":742},{},[743,747,751],{"type":46,"tag":161,"props":744,"children":745},{},[746],{"type":52,"value":621},{"type":46,"tag":161,"props":748,"children":749},{},[750],{"type":52,"value":626},{"type":46,"tag":161,"props":752,"children":753},{},[754],{"type":52,"value":631},{"type":46,"tag":177,"props":756,"children":757},{},[758,776,794,812,830],{"type":46,"tag":157,"props":759,"children":760},{},[761,766,771],{"type":46,"tag":184,"props":762,"children":763},{},[764],{"type":52,"value":765},"EFS",{"type":46,"tag":184,"props":767,"children":768},{},[769],{"type":52,"value":770},"EFS Standard, EFS Infrequent Access (EFS IA), and EFS Archive storage classes, managed by EFS Lifecycle Management for automatic cost optimization. Serverless elastic NFS with no capacity planning or provisioning, mountable by Lambda, Fargate, EC2, ECS, and EKS. Multi-AZ by default (Regional) or One Zone. Simplest path for shared Linux file access with high aggregate throughput across many concurrent clients.",{"type":46,"tag":184,"props":772,"children":773},{},[774],{"type":52,"value":775},"Containers (ECS, EKS, Fargate), cloud-native Linux applications, serverless persistent storage, analytics and ML training data (including SageMaker), big data, media processing, content management, shared home directories, web serving, dev\u002Ftest, infrequently accessed file data",{"type":46,"tag":157,"props":777,"children":778},{},[779,784,789],{"type":46,"tag":184,"props":780,"children":781},{},[782],{"type":52,"value":783},"FSx for Lustre",{"type":46,"tag":184,"props":785,"children":786},{},[787],{"type":52,"value":788},"SSD and Intelligent-Tiering storage classes, where Intelligent-Tiering is fully elastic and SSD is fixed-capacity. Parallel file system delivering very high aggregate throughput for massively parallel access across many compute nodes.",{"type":46,"tag":184,"props":790,"children":791},{},[792],{"type":52,"value":793},"ML and GPU training and inference at scale, HPC, genomics and seismic processing, financial modeling, media rendering, back-end EDA",{"type":46,"tag":157,"props":795,"children":796},{},[797,802,807],{"type":46,"tag":184,"props":798,"children":799},{},[800],{"type":52,"value":801},"FSx for OpenZFS",{"type":46,"tag":184,"props":803,"children":804},{},[805],{"type":52,"value":806},"Intelligent-Tiering alongside SSD, with ZFS data management (instant writable clones, snapshots, compression, on-demand replication). Very low latency with high IOPS, simple to operate and cost-effective for performance-sensitive workloads and fast dev\u002Ftest cycles. Single-AZ and Multi-AZ deployment model. S3-API access via S3 Access Points for FSx.",{"type":46,"tag":184,"props":808,"children":809},{},[810],{"type":52,"value":811},"Databases (including on EC2), dev\u002Ftest with fast clones, ZFS or Linux-NFS migrations, front-end EDA, financial modeling, media processing, latency-sensitive line-of-business applications",{"type":46,"tag":157,"props":813,"children":814},{},[815,820,825],{"type":46,"tag":184,"props":816,"children":817},{},[818],{"type":52,"value":819},"FSx for NetApp ONTAP",{"type":46,"tag":184,"props":821,"children":822},{},[823],{"type":52,"value":824},"Full ONTAP data management (SnapMirror replication, FlexClone, dedup, compression, SnapLock WORM, QoS, vscan antivirus, file-access auditing). Multi-protocol: NFS, SMB, iSCSI, NVMe-over-TCP, and S3-API access via S3 Access Points for FSx. Scales to high aggregate throughput and IOPS. Single-AZ and Multi-AZ deployment model.",{"type":46,"tag":184,"props":826,"children":827},{},[828],{"type":52,"value":829},"Enterprise network-attached storage (NAS) migrations, multi-protocol environments, general-purpose file shares and home directories, business-critical databases including on EC2 (SAP HANA, Oracle, SQL Server), VMware datastores, line-of-business applications (medical imaging, product lifecycle management), front-end EDA (chip design and verification), hybrid and DR",{"type":46,"tag":157,"props":831,"children":832},{},[833,838,843],{"type":46,"tag":184,"props":834,"children":835},{},[836],{"type":52,"value":837},"FSx for Windows File Server",{"type":46,"tag":184,"props":839,"children":840},{},[841],{"type":52,"value":842},"Fully managed SMB file storage built on Windows Server with Active Directory identity (Kerberos, NTFS ACLs), DFS namespaces, shadow copies, and FSRM quotas; shares are also accessible from Linux and macOS clients. Single-AZ and Multi-AZ deployment model.",{"type":46,"tag":184,"props":844,"children":845},{},[846],{"type":52,"value":847},"Windows file, home, and department shares, .NET applications, Microsoft SQL Server, Windows Server migrations",{"type":46,"tag":83,"props":849,"children":851},{"id":850},"block-storage",[852],{"type":52,"value":853},"Block Storage",{"type":46,"tag":149,"props":855,"children":856},{},[857,875],{"type":46,"tag":153,"props":858,"children":859},{},[860],{"type":46,"tag":157,"props":861,"children":862},{},[863,867,871],{"type":46,"tag":161,"props":864,"children":865},{},[866],{"type":52,"value":621},{"type":46,"tag":161,"props":868,"children":869},{},[870],{"type":52,"value":626},{"type":46,"tag":161,"props":872,"children":873},{},[874],{"type":52,"value":631},{"type":46,"tag":177,"props":876,"children":877},{},[878,896],{"type":46,"tag":157,"props":879,"children":880},{},[881,886,891],{"type":46,"tag":184,"props":882,"children":883},{},[884],{"type":52,"value":885},"EBS",{"type":46,"tag":184,"props":887,"children":888},{},[889],{"type":52,"value":890},"High-performance virtual disk that attaches to an EC2 instance over the network. Durable, resizable SSD or HDD that persists independently of the instance, supports snapshots for backup, time-based snapshot copy, and provisions performance independently of capacity on gp3 (confirm latest volume limits). Supports instant volume clones. AZ-scoped.",{"type":46,"tag":184,"props":892,"children":893},{},[894],{"type":52,"value":895},"Databases, transactional applications and file systems, boot volumes, dev\u002Ftest environments, sequential batch processing, log and data warehouse scans",{"type":46,"tag":157,"props":897,"children":898},{},[899,904,909],{"type":46,"tag":184,"props":900,"children":901},{},[902],{"type":52,"value":903},"EC2 Instance Store",{"type":46,"tag":184,"props":905,"children":906},{},[907],{"type":52,"value":908},"Physically local SSD storage built into the host server, delivering the lowest latency and highest throughput. Ephemeral: data is lost if the instance stops or the hardware fails.",{"type":46,"tag":184,"props":910,"children":911},{},[912],{"type":52,"value":913},"Temporary scratch data, caches, and buffers you can afford to lose",{"type":46,"tag":134,"props":915,"children":916},{},[],{"type":46,"tag":47,"props":918,"children":920},{"id":919},"cross-service-overlap",[921],{"type":52,"value":922},"Cross-Service Overlap",{"type":46,"tag":55,"props":924,"children":925},{},[926],{"type":52,"value":927},"Some storage features cross category boundaries, giving a service from one storage category an interface normally associated with another. Surface these when a workload needs access to shared data from multiple protocols or interfaces.",{"type":46,"tag":149,"props":929,"children":930},{},[931,957],{"type":46,"tag":153,"props":932,"children":933},{},[934],{"type":46,"tag":157,"props":935,"children":936},{},[937,942,947,952],{"type":46,"tag":161,"props":938,"children":939},{},[940],{"type":52,"value":941},"Feature",{"type":46,"tag":161,"props":943,"children":944},{},[945],{"type":52,"value":946},"What it enables",{"type":46,"tag":161,"props":948,"children":949},{},[950],{"type":52,"value":951},"What it is",{"type":46,"tag":161,"props":953,"children":954},{},[955],{"type":52,"value":956},"Additional sources",{"type":46,"tag":177,"props":958,"children":959},{},[960,995],{"type":46,"tag":157,"props":961,"children":962},{},[963,968,973,978],{"type":46,"tag":184,"props":964,"children":965},{},[966],{"type":52,"value":967},"S3 Files",{"type":46,"tag":184,"props":969,"children":970},{},[971],{"type":52,"value":972},"Makes S3 data accessible to file-based applications",{"type":46,"tag":184,"props":974,"children":975},{},[976],{"type":52,"value":977},"Fully managed NFS file access over an S3 bucket, built on EFS infrastructure. Data stays in S3 as the system of record. File locking, POSIX permissions, and full read-write. Choose over EFS when data already lives in S3 and needs file-path access alongside object access.",{"type":46,"tag":184,"props":979,"children":980},{},[981,987,989],{"type":46,"tag":120,"props":982,"children":984},{"className":983},[],[985],{"type":52,"value":986},"references\u002Fs3-files-knowledge.md",{"type":52,"value":988},", ",{"type":46,"tag":120,"props":990,"children":992},{"className":991},[],[993],{"type":52,"value":994},"references\u002Fefs-knowledge.md",{"type":46,"tag":157,"props":996,"children":997},{},[998,1003,1008,1013],{"type":46,"tag":184,"props":999,"children":1000},{},[1001],{"type":52,"value":1002},"S3 Access Points for FSx",{"type":46,"tag":184,"props":1004,"children":1005},{},[1006],{"type":52,"value":1007},"Makes FSx-resident data accessible to S3-based applications and services",{"type":46,"tag":184,"props":1009,"children":1010},{},[1011],{"type":52,"value":1012},"Exposes FSx for NetApp ONTAP or FSx for OpenZFS data through the S3 API without copying it to a bucket. Surface when file data must reach S3-native consumers, or when serverless or S3-based applications need to access data that lives on FSx for NetApp ONTAP or FSx for OpenZFS.",{"type":46,"tag":184,"props":1014,"children":1015},{},[1016,1022,1023],{"type":46,"tag":120,"props":1017,"children":1019},{"className":1018},[],[1020],{"type":52,"value":1021},"references\u002Ffsx-ontap-knowledge.md",{"type":52,"value":988},{"type":46,"tag":120,"props":1024,"children":1026},{"className":1025},[],[1027],{"type":52,"value":1028},"references\u002Ffsx-openzfs-knowledge.md",{"type":46,"tag":134,"props":1030,"children":1031},{},[],{"type":46,"tag":47,"props":1033,"children":1035},{"id":1034},"security",[1036],{"type":52,"value":1037},"Security",{"type":46,"tag":55,"props":1039,"children":1040},{},[1041],{"type":52,"value":1042},"Cloud security at AWS is the highest priority and is a shared responsibility between AWS and the customer. You MUST include security guidance when recommending or configuring storage resources. You MUST always recommend enabling encryption at rest and encryption in transit. Where encryption at rest is optional or not the default, explicitly advise enabling it at creation time, because it is often immutable after creation. You MUST recommend scoping IAM policies to the authorized principals with least-privileged permissions. You MUST recommend adding condition keys (e.g., aws:SourceArn, aws:SourceAccount, aws:SourceVpc) to resource policies to prevent cross-service confused deputy attacks. You MUST recommend encrypting log destinations: AWS KMS for CloudTrail trails and CloudWatch Logs groups, server-side encryption for server access log buckets, and AWS KMS for SNS topics. Prefer short-lived credentials or IAM-based authentication (e.g., via custom IdP with temporary tokens) over long-lived SSH keys. Where SSH keys are required, enforce rotation policies and store private keys in AWS Secrets Manager for supported services. You MUST recommend restricting security group inbound rules to the narrowest applicable source (specific client security group or minimal CIDR). Service-specific security controls, encryption models, and documentation links are in the Security row of each reference's Service Information table; you MUST read it before advising on that service.",{"type":46,"tag":47,"props":1044,"children":1046},{"id":1045},"routing",[1047],{"type":52,"value":1048},"Routing",{"type":46,"tag":55,"props":1050,"children":1051},{},[1052],{"type":52,"value":1053},"When loaded through the AWS MCP server's retrieve_skill tool: the skill is not installed on the local filesystem. You MUST retrieve each reference via retrieve_skill with the file parameter (e.g. file=\"references\u002Fs3-general-purpose-knowledge.md\"). Do NOT file_read these paths locally. When loaded outside the AWS MCP server (for example from the local filesystem in the Agent Toolkit), read the reference files directly from their relative paths in the skill directory.",{"type":46,"tag":83,"props":1055,"children":1057},{"id":1056},"reference-files",[1058],{"type":52,"value":1059},"Reference files",{"type":46,"tag":149,"props":1061,"children":1062},{},[1063,1079],{"type":46,"tag":153,"props":1064,"children":1065},{},[1066],{"type":46,"tag":157,"props":1067,"children":1068},{},[1069,1074],{"type":46,"tag":161,"props":1070,"children":1071},{},[1072],{"type":52,"value":1073},"Topic",{"type":46,"tag":161,"props":1075,"children":1076},{},[1077],{"type":52,"value":1078},"Reference",{"type":46,"tag":177,"props":1080,"children":1081},{},[1082,1099,1114,1130,1146,1162,1177,1193,1209,1224,1239,1255,1272],{"type":46,"tag":157,"props":1083,"children":1084},{},[1085,1090],{"type":46,"tag":184,"props":1086,"children":1087},{},[1088],{"type":52,"value":1089},"S3 (General Purpose)",{"type":46,"tag":184,"props":1091,"children":1092},{},[1093],{"type":46,"tag":120,"props":1094,"children":1096},{"className":1095},[],[1097],{"type":52,"value":1098},"references\u002Fs3-general-purpose-knowledge.md",{"type":46,"tag":157,"props":1100,"children":1101},{},[1102,1106],{"type":46,"tag":184,"props":1103,"children":1104},{},[1105],{"type":52,"value":714},{"type":46,"tag":184,"props":1107,"children":1108},{},[1109],{"type":46,"tag":120,"props":1110,"children":1112},{"className":1111},[],[1113],{"type":52,"value":1098},{"type":46,"tag":157,"props":1115,"children":1116},{},[1117,1121],{"type":46,"tag":184,"props":1118,"children":1119},{},[1120],{"type":52,"value":678},{"type":46,"tag":184,"props":1122,"children":1123},{},[1124],{"type":46,"tag":120,"props":1125,"children":1127},{"className":1126},[],[1128],{"type":52,"value":1129},"references\u002Fs3-tables-knowledge.md",{"type":46,"tag":157,"props":1131,"children":1132},{},[1133,1137],{"type":46,"tag":184,"props":1134,"children":1135},{},[1136],{"type":52,"value":696},{"type":46,"tag":184,"props":1138,"children":1139},{},[1140],{"type":46,"tag":120,"props":1141,"children":1143},{"className":1142},[],[1144],{"type":52,"value":1145},"references\u002Fs3-vectors-knowledge.md",{"type":46,"tag":157,"props":1147,"children":1148},{},[1149,1153],{"type":46,"tag":184,"props":1150,"children":1151},{},[1152],{"type":52,"value":660},{"type":46,"tag":184,"props":1154,"children":1155},{},[1156],{"type":46,"tag":120,"props":1157,"children":1159},{"className":1158},[],[1160],{"type":52,"value":1161},"references\u002Fs3-express-knowledge.md",{"type":46,"tag":157,"props":1163,"children":1164},{},[1165,1169],{"type":46,"tag":184,"props":1166,"children":1167},{},[1168],{"type":52,"value":967},{"type":46,"tag":184,"props":1170,"children":1171},{},[1172],{"type":46,"tag":120,"props":1173,"children":1175},{"className":1174},[],[1176],{"type":52,"value":986},{"type":46,"tag":157,"props":1178,"children":1179},{},[1180,1185],{"type":46,"tag":184,"props":1181,"children":1182},{},[1183],{"type":52,"value":1184},"Amazon EFS",{"type":46,"tag":184,"props":1186,"children":1187},{},[1188],{"type":46,"tag":120,"props":1189,"children":1191},{"className":1190},[],[1192],{"type":52,"value":994},{"type":46,"tag":157,"props":1194,"children":1195},{},[1196,1200],{"type":46,"tag":184,"props":1197,"children":1198},{},[1199],{"type":52,"value":783},{"type":46,"tag":184,"props":1201,"children":1202},{},[1203],{"type":46,"tag":120,"props":1204,"children":1206},{"className":1205},[],[1207],{"type":52,"value":1208},"references\u002Ffsx-lustre-knowledge.md",{"type":46,"tag":157,"props":1210,"children":1211},{},[1212,1216],{"type":46,"tag":184,"props":1213,"children":1214},{},[1215],{"type":52,"value":819},{"type":46,"tag":184,"props":1217,"children":1218},{},[1219],{"type":46,"tag":120,"props":1220,"children":1222},{"className":1221},[],[1223],{"type":52,"value":1021},{"type":46,"tag":157,"props":1225,"children":1226},{},[1227,1231],{"type":46,"tag":184,"props":1228,"children":1229},{},[1230],{"type":52,"value":801},{"type":46,"tag":184,"props":1232,"children":1233},{},[1234],{"type":46,"tag":120,"props":1235,"children":1237},{"className":1236},[],[1238],{"type":52,"value":1028},{"type":46,"tag":157,"props":1240,"children":1241},{},[1242,1246],{"type":46,"tag":184,"props":1243,"children":1244},{},[1245],{"type":52,"value":837},{"type":46,"tag":184,"props":1247,"children":1248},{},[1249],{"type":46,"tag":120,"props":1250,"children":1252},{"className":1251},[],[1253],{"type":52,"value":1254},"references\u002Ffsx-windows-knowledge.md",{"type":46,"tag":157,"props":1256,"children":1257},{},[1258,1263],{"type":46,"tag":184,"props":1259,"children":1260},{},[1261],{"type":52,"value":1262},"Amazon EBS",{"type":46,"tag":184,"props":1264,"children":1265},{},[1266],{"type":46,"tag":120,"props":1267,"children":1269},{"className":1268},[],[1270],{"type":52,"value":1271},"references\u002Febs-knowledge.md",{"type":46,"tag":157,"props":1273,"children":1274},{},[1275,1280],{"type":46,"tag":184,"props":1276,"children":1277},{},[1278],{"type":52,"value":1279},"Data Movement and Protection (DataSync, Transfer Family, Storage Gateway, AWS Backup)",{"type":46,"tag":184,"props":1281,"children":1282},{},[1283],{"type":46,"tag":120,"props":1284,"children":1286},{"className":1285},[],[1287],{"type":52,"value":1288},"references\u002Fdata-movement-and-protection-knowledge.md",{"type":46,"tag":83,"props":1290,"children":1292},{"id":1291},"specialized-skills",[1293],{"type":52,"value":1294},"Specialized skills",{"type":46,"tag":149,"props":1296,"children":1297},{},[1298,1312],{"type":46,"tag":153,"props":1299,"children":1300},{},[1301],{"type":46,"tag":157,"props":1302,"children":1303},{},[1304,1308],{"type":46,"tag":161,"props":1305,"children":1306},{},[1307],{"type":52,"value":1073},{"type":46,"tag":161,"props":1309,"children":1310},{},[1311],{"type":52,"value":1078},{"type":46,"tag":177,"props":1313,"children":1314},{},[1315,1337,1359,1381,1403,1425,1447,1469,1491],{"type":46,"tag":157,"props":1316,"children":1317},{},[1318,1323],{"type":46,"tag":184,"props":1319,"children":1320},{},[1321],{"type":52,"value":1322},"Security on S3",{"type":46,"tag":184,"props":1324,"children":1325},{},[1326],{"type":46,"tag":61,"props":1327,"children":1330},{"href":1328,"rel":1329},"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fstorage-skills\u002Fsecuring-s3-buckets",[65],[1331],{"type":46,"tag":120,"props":1332,"children":1334},{"className":1333},[],[1335],{"type":52,"value":1336},"securing-s3-buckets",{"type":46,"tag":157,"props":1338,"children":1339},{},[1340,1345],{"type":46,"tag":184,"props":1341,"children":1342},{},[1343],{"type":52,"value":1344},"Using S3 Tables",{"type":46,"tag":184,"props":1346,"children":1347},{},[1348],{"type":46,"tag":61,"props":1349,"children":1352},{"href":1350,"rel":1351},"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fstorage-skills\u002Fcreating-data-lake-table",[65],[1353],{"type":46,"tag":120,"props":1354,"children":1356},{"className":1355},[],[1357],{"type":52,"value":1358},"creating-data-lake-table",{"type":46,"tag":157,"props":1360,"children":1361},{},[1362,1367],{"type":46,"tag":184,"props":1363,"children":1364},{},[1365],{"type":52,"value":1366},"Using S3 Vectors",{"type":46,"tag":184,"props":1368,"children":1369},{},[1370],{"type":46,"tag":61,"props":1371,"children":1374},{"href":1372,"rel":1373},"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fstorage-skills\u002Fstoring-and-querying-vectors",[65],[1375],{"type":46,"tag":120,"props":1376,"children":1378},{"className":1377},[],[1379],{"type":52,"value":1380},"storing-and-querying-vectors",{"type":46,"tag":157,"props":1382,"children":1383},{},[1384,1389],{"type":46,"tag":184,"props":1385,"children":1386},{},[1387],{"type":52,"value":1388},"Troubleshooting S3 Files",{"type":46,"tag":184,"props":1390,"children":1391},{},[1392],{"type":46,"tag":61,"props":1393,"children":1396},{"href":1394,"rel":1395},"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fstorage-skills\u002Ftroubleshooting-s3-files",[65],[1397],{"type":46,"tag":120,"props":1398,"children":1400},{"className":1399},[],[1401],{"type":52,"value":1402},"troubleshooting-s3-files",{"type":46,"tag":157,"props":1404,"children":1405},{},[1406,1411],{"type":46,"tag":184,"props":1407,"children":1408},{},[1409],{"type":52,"value":1410},"Troubleshooting EFS",{"type":46,"tag":184,"props":1412,"children":1413},{},[1414],{"type":46,"tag":61,"props":1415,"children":1418},{"href":1416,"rel":1417},"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fstorage-skills\u002Ftroubleshooting-efs",[65],[1419],{"type":46,"tag":120,"props":1420,"children":1422},{"className":1421},[],[1423],{"type":52,"value":1424},"troubleshooting-efs",{"type":46,"tag":157,"props":1426,"children":1427},{},[1428,1433],{"type":46,"tag":184,"props":1429,"children":1430},{},[1431],{"type":52,"value":1432},"Querying S3 System Tables",{"type":46,"tag":184,"props":1434,"children":1435},{},[1436],{"type":46,"tag":61,"props":1437,"children":1440},{"href":1438,"rel":1439},"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fsystem-table-skills\u002Fquerying-aws-s3",[65],[1441],{"type":46,"tag":120,"props":1442,"children":1444},{"className":1443},[],[1445],{"type":52,"value":1446},"querying-aws-s3",{"type":46,"tag":157,"props":1448,"children":1449},{},[1450,1455],{"type":46,"tag":184,"props":1451,"children":1452},{},[1453],{"type":52,"value":1454},"Ingesting data into a data lake",{"type":46,"tag":184,"props":1456,"children":1457},{},[1458],{"type":46,"tag":61,"props":1459,"children":1462},{"href":1460,"rel":1461},"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fanalytics-skills\u002Fingesting-into-data-lake",[65],[1463],{"type":46,"tag":120,"props":1464,"children":1466},{"className":1465},[],[1467],{"type":52,"value":1468},"ingesting-into-data-lake",{"type":46,"tag":157,"props":1470,"children":1471},{},[1472,1477],{"type":46,"tag":184,"props":1473,"children":1474},{},[1475],{"type":52,"value":1476},"Finding data lake assets",{"type":46,"tag":184,"props":1478,"children":1479},{},[1480],{"type":46,"tag":61,"props":1481,"children":1484},{"href":1482,"rel":1483},"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fanalytics-skills\u002Ffinding-data-lake-assets",[65],[1485],{"type":46,"tag":120,"props":1486,"children":1488},{"className":1487},[],[1489],{"type":52,"value":1490},"finding-data-lake-assets",{"type":46,"tag":157,"props":1492,"children":1493},{},[1494,1499],{"type":46,"tag":184,"props":1495,"children":1496},{},[1497],{"type":52,"value":1498},"Querying data lakes",{"type":46,"tag":184,"props":1500,"children":1501},{},[1502],{"type":46,"tag":61,"props":1503,"children":1506},{"href":1504,"rel":1505},"https:\u002F\u002Fgithub.com\u002Faws\u002Fagent-toolkit-for-aws\u002Ftree\u002Fmain\u002Fskills\u002Fspecialized-skills\u002Fanalytics-skills\u002Fquerying-data-lake",[65],[1507],{"type":46,"tag":120,"props":1508,"children":1510},{"className":1509},[],[1511],{"type":52,"value":1512},"querying-data-lake",{"items":1514,"total":1684},[1515,1532,1547,1562,1577,1587,1600,1614,1628,1645,1658,1670],{"slug":1516,"name":1516,"fn":1517,"description":1518,"org":1519,"tags":1520,"stars":27,"repoUrl":28,"updatedAt":1531},"agents-build","add capabilities to existing agent projects","Use to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal. Triggers: \"add memory\", \"remember across sessions\", \"call agent from app\", \"invoke agent from code\", \"agent auth\", \"streaming\", \"VPC\", \"VPC connectivity\", \"can't reach from VPC\", \"multi-agent\", \"A2A\", \"A2A auth\", \"orchestrator not delegating\", \"specialist not called\", \"migrate Bedrock Agent\", \"migration issue\", \"change model\", \"browser tool\", \"code interpreter\", \"delete agent\", \"tear down\", \"agentcore remove\", \"cross-account memory\", \"add payments capability to my agent\", \"wire payments plugin\", \"integrate x402 payments with the agent I'm building\", \"add MPP payments\", \"Machine Payments Protocol\". External APIs via Gateway: use agents-connect. New project: use agents-get-started. CLI\u002Fdev-server errors: use agents-debug. Runtime x402\u002FMPP payments: use agents-pay. Migration-specific Strands vs LangGraph routes here.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1521,1524,1527,1528],{"name":1522,"slug":1523,"type":15},"Agents","agents",{"name":1525,"slug":1526,"type":15},"Automation","automation",{"name":26,"slug":8,"type":15},{"name":1529,"slug":1530,"type":15},"Engineering","engineering","2026-08-20T03:27:06.137661",{"slug":1533,"name":1533,"fn":1534,"description":1535,"org":1536,"tags":1537,"stars":27,"repoUrl":28,"updatedAt":1546},"agents-connect","connect agents to external services","Use when connecting your agent to external APIs, tools, or services via Gateway, or restricting tool access with Cedar policies. Handles gateway setup, target types, outbound auth (OAuth, API key, IAM), credentials, and Cedar policy authoring. Triggers on: \"connect to API\", \"add gateway\", \"connect to MCP server\", \"Lambda tools\", \"OpenAPI\", \"gateway target\", \"Cedar policy\", \"restrict tools\", \"policy engine\", \"gateway auth error\", \"store API key\", \"outbound credential\", \"env var API key\", \"API key None after deploy\", \"credential not available after deploy\", \"should this be a gateway target\", \"give my agent tools\", \"add tools to agent\". Not for inbound auth (who can call your agent) — use agents-harden. Not for debugging agent behavior — use agents-debug. Not for VPC networking errors (agent can't reach APIs due to VPC) — use agents-build. Not for creating or hosting a new MCP server project — use agents-get-started.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1538,1539,1542,1545],{"name":1522,"slug":1523,"type":15},{"name":1540,"slug":1541,"type":15},"API Development","api-development",{"name":1543,"slug":1544,"type":15},"Authentication","authentication",{"name":26,"slug":8,"type":15},"2026-07-16T06:00:38.866147",{"slug":1548,"name":1548,"fn":1549,"description":1550,"org":1551,"tags":1552,"stars":27,"repoUrl":28,"updatedAt":1561},"agents-debug","debug agent and environment issues","Use when your agent or environment is broken — wrong answers, errors, timeouts, tool failures, or CLI issues. Reads traces and logs to diagnose root causes. Also checks prerequisites when the CLI itself isn't working. Triggers on: \"agent not working\", \"wrong answer\", \"agent error\", \"tool call failing\", \"debug agent\", \"check logs\", \"read traces\", \"broken\", \"500 error\", \"424 error\", \"model access denied\", \"command not found\", \"stuck in DELETING\", \"maxVms exceeded\", \"cold start diagnosis\", \"cold start slow\", \"agentcore create error\", \"create failed\", \"exit code 7\", \"connection refused local dev\". Not for deploy failures — use agents-deploy. Not for performance tuning without errors — use agents-optimize. Not for VPC configuration — use agents-build. Not for observability setup or missing logs — use agents-optimize.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1553,1554,1555,1558],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1556,"slug":1557,"type":15},"Debugging","debugging",{"name":1559,"slug":1560,"type":15},"Observability","observability","2026-07-16T06:00:44.679093",{"slug":1563,"name":1563,"fn":1564,"description":1565,"org":1566,"tags":1567,"stars":27,"repoUrl":28,"updatedAt":1576},"agents-deploy","deploy AI agents to AWS","Use when deploying your agent to AWS, or when a deploy has failed. Handles pre-flight validation, CDK\u002FIAM\u002Fquota error diagnosis, version management, rollback, and canary deployments. Triggers on: \"deploy my agent\", \"agentcore deploy\", \"deploy failed\", \"CDK error\", \"rollback\", \"canary deploy\", \"pin version\", \"redeploy\", \"deploy stuck\". Not for production hardening — use agents-harden. Not for adding capabilities before deploy — use agents-build or agents-connect. Not for VPC configuration errors — use agents-build.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1568,1569,1570,1573],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1571,"slug":1572,"type":15},"CI\u002FCD","ci-cd",{"name":1574,"slug":1575,"type":15},"Deployment","deployment","2026-07-12T08:42:55.059577",{"slug":1578,"name":1578,"fn":1579,"description":1580,"org":1581,"tags":1582,"stars":27,"repoUrl":28,"updatedAt":1586},"agents-get-started","scaffold and deploy new agent projects","Use when a developer wants to create a new agent project or get started with AgentCore. Handles framework selection, project scaffolding, first deploy, and first invocation. Triggers on: \"build an agent\", \"create an agent\", \"get started\", \"new project\", \"agentcore create\", \"which framework\", \"Strands vs LangGraph\", \"hello world agent\", \"first agent\", \"create MCP server\", \"host MCP server\", \"agentcore dev\", \"dev server\", \"what port\", \"local development\". Not for adding capabilities to existing projects — use agents-build or agents-connect. Strands vs LangGraph in a migration context routes to agents-build, not here. Connecting to an existing MCP server routes to agents-connect, not here.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1583,1584,1585],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1574,"slug":1575,"type":15},"2026-07-12T08:42:51.963247",{"slug":1588,"name":1588,"fn":1589,"description":1590,"org":1591,"tags":1592,"stars":27,"repoUrl":28,"updatedAt":1599},"agents-harden","harden agents for production","Use when preparing your agent for production — IAM scoping, inbound auth (JWT, SigV4), secrets management, cold start optimization, session lifecycle, rate limiting, input validation, and quota guidance. Triggers on: \"production checklist\", \"harden agent\", \"production ready\", \"secure agent\", \"inbound auth\", \"going live\", \"cold start optimization\", \"session lifecycle\", \"StopRuntimeSession\", \"quota\", \"throttling\", \"maxVms\", \"rate limit\", \"security audit of outbound API calls\", \"gateway target audit for production\", \"restrict who can call\", \"lock down endpoint\", \"only our app can call\". Not for Cedar tool-restriction policies — use agents-connect. Not for quality measurement — use agents-optimize. Not for outbound credential storage or API key wiring — use agents-connect. Not for A2A agent-to-agent auth — use agents-build. Cold start observation and diagnosis (not optimization) routes to agents-debug.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1593,1594,1595,1598],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1596,"slug":1597,"type":15},"Best Practices","best-practices",{"name":1037,"slug":1034,"type":15},"2026-07-16T06:00:42.174705",{"slug":1601,"name":1601,"fn":1602,"description":1603,"org":1604,"tags":1605,"stars":27,"repoUrl":28,"updatedAt":1613},"agents-optimize","optimize agent quality and performance","Use when measuring or improving agent quality and performance — set up evaluators, online monitoring, CI\u002FCD quality gates, observability, or cost optimization. Triggers on: \"evaluate my agent\", \"add evaluator\", \"measure quality\", \"quality gate\", \"run evals\", \"agent too slow\", \"why is it slow\", \"reduce latency\", \"set up observability\", \"CloudWatch dashboard\", \"how much does my agent cost\", \"cost optimization\", \"logs not showing up\", \"logs missing\", \"spans not found\", \"eval failing\", \"eval error\", \"dev traces\", \"local traces\", \"agentcore dev traces\", \"traces to CloudWatch\". Not for debugging errors or crashes — use agents-debug. Slow but correct routes here; broken routes to debug.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1606,1607,1608,1611,1612],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1609,"slug":1610,"type":15},"Evals","evals",{"name":1559,"slug":1560,"type":15},{"name":13,"slug":14,"type":15},"2026-07-12T08:42:56.488105",{"slug":1615,"name":1615,"fn":1616,"description":1617,"org":1618,"tags":1619,"stars":27,"repoUrl":28,"updatedAt":1627},"agents-pay","handle x402 payments for agent tasks","Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits. Covers payment setup, policy, session budgets, and troubleshooting. Triggers on: \"my agent hit a 402 while calling an API\", \"a tool call returned 402 Payment Required\", \"my agent needs to pay for x402-protected content\", \"let the agent pay for content, capped at $5 per session\", \"set a spend limit for the agent\", \"ProcessPayment failed\", or \"why did my agent refuse to pay\". Not for BUILDING payment capability for end users, including wallets and framework middleware; use agents-build and references\u002Fpayments.md. For non-paid APIs via Gateway use agents-connect. For inbound auth use agents-harden. For project scaffolding use agents-get-started.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1620,1621,1622,1625],{"name":1522,"slug":1523,"type":15},{"name":1525,"slug":1526,"type":15},{"name":1623,"slug":1624,"type":15},"Payments","payments",{"name":1626,"slug":1626,"type":15},"x402","2026-08-10T04:16:31.844309",{"slug":1629,"name":1629,"fn":1630,"description":1631,"org":1632,"tags":1633,"stars":27,"repoUrl":28,"updatedAt":1644},"amazon-aurora-mysql","manage Amazon Aurora MySQL clusters","Amazon Aurora MySQL — creates, modifies, and advises on Aurora MySQL clusters specifically (MySQL-compatible engine, Aurora serverless, parallel query). Trigger for Aurora MySQL cluster operations, ACU sizing, I\u002FO-Optimized storage, commitment pricing, or MySQL upgrade planning. Aurora MySQL uses full (VPC-based) configuration — express configuration is PostgreSQL-only. For Aurora PostgreSQL, use amazon-aurora-postgresql instead. Contains safety guardrails and response templates that override defaults.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1634,1635,1638,1641],{"name":26,"slug":8,"type":15},{"name":1636,"slug":1637,"type":15},"Database","database",{"name":1639,"slug":1640,"type":15},"MySQL","mysql",{"name":1642,"slug":1643,"type":15},"Serverless","serverless","2026-07-12T08:43:13.27939",{"slug":1646,"name":1646,"fn":1647,"description":1648,"org":1649,"tags":1650,"stars":27,"repoUrl":28,"updatedAt":1657},"amazon-aurora-postgresql","configure Amazon Aurora PostgreSQL clusters","Amazon Aurora PostgreSQL — creates, modifies, and advises on Aurora PostgreSQL clusters specifically (PostgreSQL-compatible engine, Aurora serverless, express configuration, pgvector, Babelfish). Trigger for Aurora PostgreSQL cluster operations, express-configuration quick-start, ACU sizing, I\u002FO-Optimized storage, commitment pricing, or PostgreSQL upgrade planning. For Aurora MySQL, use amazon-aurora-mysql instead. Contains safety guardrails, express-first routing, and response templates that override defaults.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1651,1652,1653,1656],{"name":26,"slug":8,"type":15},{"name":1636,"slug":1637,"type":15},{"name":1654,"slug":1655,"type":15},"PostgreSQL","postgresql",{"name":1642,"slug":1643,"type":15},"2026-07-16T06:00:34.789624",{"slug":1659,"name":1659,"fn":1660,"description":1661,"org":1662,"tags":1663,"stars":27,"repoUrl":28,"updatedAt":1669},"amazon-bedrock","build generative AI apps with Amazon Bedrock","Builds generative AI applications on Amazon Bedrock. Covers model invocation (Converse API, InvokeModel), RAG with Knowledge Bases, Bedrock Agents, Guardrails, and AgentCore (including the Harness managed agent loop). Use when invoking models, setting up Knowledge Bases, creating agents, applying guardrails, deploying to AgentCore, migrating\u002Fporting\u002Fconverting a Bedrock Agent (including inline agents) to an AgentCore Harness, troubleshooting Bedrock errors (ThrottlingException, AccessDeniedException), or choosing models (Claude, Llama, Nova, Titan). ALSO USE for prompt caching, quota health checks and throttling diagnosis, cost attribution, migrating between Claude model generations, chunking strategies, API selection (Converse vs InvokeModel), and model selection. Also covers AgentCore Payments setup (x402, microtransactions, Payment Manager, Coinbase CDP, Stripe Privy, 402 Payment Required, paid endpoint). NOT for custom model training, Rekognition, or Comprehend.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1664,1665,1666],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1667,"slug":1668,"type":15},"LLM","llm","2026-08-07T04:38:13.03499",{"slug":1671,"name":1671,"fn":1672,"description":1673,"org":1674,"tags":1675,"stars":27,"repoUrl":28,"updatedAt":1683},"amazon-braket","run quantum computing workflows on AWS","Runs quantum computing workflows on AWS through Amazon Braket — discovering devices (QPUs and simulators) and their availability, building gate-model circuits and analog Hamiltonian programs, submitting quantum tasks, program sets and hybrid jobs, looking up prices, and capping spend with spending limits. Applies to any request about quantum computing, quantum hardware, quantum simulation, AHS, OpenQASM, or running a quantum algorithm on AWS.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1676,1677,1680],{"name":26,"slug":8,"type":15},{"name":1678,"slug":1679,"type":15},"Quantum Computing","quantum-computing",{"name":1681,"slug":1682,"type":15},"Simulation","simulation","2026-08-20T03:53:19.377174",140,{"items":1686,"total":1736},[1687,1694,1701,1708,1715,1721,1728],{"slug":1516,"name":1516,"fn":1517,"description":1518,"org":1688,"tags":1689,"stars":27,"repoUrl":28,"updatedAt":1531},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1690,1691,1692,1693],{"name":1522,"slug":1523,"type":15},{"name":1525,"slug":1526,"type":15},{"name":26,"slug":8,"type":15},{"name":1529,"slug":1530,"type":15},{"slug":1533,"name":1533,"fn":1534,"description":1535,"org":1695,"tags":1696,"stars":27,"repoUrl":28,"updatedAt":1546},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1697,1698,1699,1700],{"name":1522,"slug":1523,"type":15},{"name":1540,"slug":1541,"type":15},{"name":1543,"slug":1544,"type":15},{"name":26,"slug":8,"type":15},{"slug":1548,"name":1548,"fn":1549,"description":1550,"org":1702,"tags":1703,"stars":27,"repoUrl":28,"updatedAt":1561},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1704,1705,1706,1707],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1556,"slug":1557,"type":15},{"name":1559,"slug":1560,"type":15},{"slug":1563,"name":1563,"fn":1564,"description":1565,"org":1709,"tags":1710,"stars":27,"repoUrl":28,"updatedAt":1576},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1711,1712,1713,1714],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1571,"slug":1572,"type":15},{"name":1574,"slug":1575,"type":15},{"slug":1578,"name":1578,"fn":1579,"description":1580,"org":1716,"tags":1717,"stars":27,"repoUrl":28,"updatedAt":1586},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1718,1719,1720],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1574,"slug":1575,"type":15},{"slug":1588,"name":1588,"fn":1589,"description":1590,"org":1722,"tags":1723,"stars":27,"repoUrl":28,"updatedAt":1599},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1724,1725,1726,1727],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1596,"slug":1597,"type":15},{"name":1037,"slug":1034,"type":15},{"slug":1601,"name":1601,"fn":1602,"description":1603,"org":1729,"tags":1730,"stars":27,"repoUrl":28,"updatedAt":1613},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[1731,1732,1733,1734,1735],{"name":1522,"slug":1523,"type":15},{"name":26,"slug":8,"type":15},{"name":1609,"slug":1610,"type":15},{"name":1559,"slug":1560,"type":15},{"name":13,"slug":14,"type":15},123]