Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
105 changes: 105 additions & 0 deletions cloudformation/devops-agent-skill-policies.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,9 @@ Metadata:
- EnableAwsBackupCoverageReview
- EnableAgentCoreObservabilitySetup
- EnableAgentCoreOpsReview
- EnableCloudTrailCostOptimization
- EnableConfigCostOptimization
- EnableGuardDutyCostOptimization
- Label:
default: Optional Resource Scoping
Parameters:
Expand Down Expand Up @@ -141,6 +144,24 @@ Parameters:
AllowedValues: ['true', 'false']
Default: 'true'

EnableCloudTrailCostOptimization:
Type: String
Description: CloudTrail Cost Optimization skill (adds ce:GetCostAndUsage and s3:GetBucketLifecycleConfiguration; other reads covered by the managed policy).
AllowedValues: ['true', 'false']
Default: 'true'

EnableConfigCostOptimization:
Type: String
Description: AWS Config Cost Optimization skill (adds ce:GetCostAndUsage, s3:GetBucketLifecycleConfiguration, and optional Athena reads for CI-driver attribution; other reads covered by the managed policy).
AllowedValues: ['true', 'false']
Default: 'true'

EnableGuardDutyCostOptimization:
Type: String
Description: Amazon GuardDuty Cost Optimization skill (adds ce:GetCostAndUsage; GuardDuty read and CloudWatch usage-metric reads covered by the managed policy).
AllowedValues: ['true', 'false']
Default: 'true'

Conditions:
CreateNewRole: !Equals [!Ref ExistingRoleName, '']
SkillAwsHealthEvents: !Equals [!Ref EnableAwsHealthEvents, 'true']
Expand All @@ -154,6 +175,9 @@ Conditions:
SkillAwsBackupCoverageReview: !Equals [!Ref EnableAwsBackupCoverageReview, 'true']
SkillAgentCoreObservabilitySetup: !Equals [!Ref EnableAgentCoreObservabilitySetup, 'true']
SkillAgentCoreOpsReview: !Equals [!Ref EnableAgentCoreOpsReview, 'true']
SkillCloudTrailCostOptimization: !Equals [!Ref EnableCloudTrailCostOptimization, 'true']
SkillConfigCostOptimization: !Equals [!Ref EnableConfigCostOptimization, 'true']
SkillGuardDutyCostOptimization: !Equals [!Ref EnableGuardDutyCostOptimization, 'true']
HasRegionRestriction: !Not [!Equals [!Join ['', !Ref AllowedRegions], '']]

Resources:
Expand Down Expand Up @@ -473,6 +497,84 @@ Resources:
- ec2:DescribeSubnets
Resource: '*'

# cloudtrail-cost-optimization: adds ce:GetCostAndUsage (dollar sizing) and
# s3:GetBucketLifecycleConfiguration (log-bucket lifecycle hygiene). CloudTrail
# Describe/Get/List, CloudWatch, and Organizations reads are covered by
# AIDevOpsAgentAccessPolicy. Read-only — no trail/event-selector mutations.
PolicyCloudTrailCostOptimization:
Type: AWS::IAM::Policy
Condition: SkillCloudTrailCostOptimization
Properties:
PolicyName: DevOpsAgentSkill-CloudTrailCostOptimization
Roles:
- !If [CreateNewRole, !Ref DevOpsAgentRole, !Ref ExistingRoleName]
PolicyDocument:
Version: '2012-10-17'
Statement:
- Sid: CostExplorerRead
Effect: Allow
Action:
- ce:GetCostAndUsage
Resource: '*'
- Sid: S3LifecycleRead
Effect: Allow
Action:
- s3:GetBucketLifecycleConfiguration
Resource: '*'

# config-cost-optimization: adds ce:GetCostAndUsage (dollar sizing),
# s3:GetBucketLifecycleConfiguration (delivery-bucket hygiene), and optional
# Athena reads for authoritative configuration-item-driver attribution over the
# Config S3 data. Config Describe/Get, CloudWatch, and Organizations reads are
# covered by AIDevOpsAgentAccessPolicy. Read-only — no recorder/rule mutations.
PolicyConfigCostOptimization:
Type: AWS::IAM::Policy
Condition: SkillConfigCostOptimization
Properties:
PolicyName: DevOpsAgentSkill-ConfigCostOptimization
Roles:
- !If [CreateNewRole, !Ref DevOpsAgentRole, !Ref ExistingRoleName]
PolicyDocument:
Version: '2012-10-17'
Statement:
- Sid: CostExplorerRead
Effect: Allow
Action:
- ce:GetCostAndUsage
Resource: '*'
- Sid: S3LifecycleRead
Effect: Allow
Action:
- s3:GetBucketLifecycleConfiguration
Resource: '*'
- Sid: AthenaCiDriverAnalysis
Effect: Allow
Action:
- athena:StartQueryExecution
- athena:GetQueryExecution
- athena:GetQueryResults
Resource: '*'

# guardduty-cost-optimization: adds ce:GetCostAndUsage (dollar sizing). GuardDuty
# List/Get/Describe, CloudWatch AWS/GuardDuty usage-metric reads, and Organizations
# reads are covered by AIDevOpsAgentAccessPolicy. Read-only — no detector or
# protection-plan mutations.
PolicyGuardDutyCostOptimization:
Type: AWS::IAM::Policy
Condition: SkillGuardDutyCostOptimization
Properties:
PolicyName: DevOpsAgentSkill-GuardDutyCostOptimization
Roles:
- !If [CreateNewRole, !Ref DevOpsAgentRole, !Ref ExistingRoleName]
PolicyDocument:
Version: '2012-10-17'
Statement:
- Sid: CostExplorerRead
Effect: Allow
Action:
- ce:GetCostAndUsage
Resource: '*'

# Optional: restrict agent to specific regions
PolicyRegionalRestriction:
Type: AWS::IAM::Policy
Expand Down Expand Up @@ -524,6 +626,9 @@ Outputs:
- aws-backup-coverage-review: ${EnableAwsBackupCoverageReview} (backup:GetSupportedResourceTypes, config:SelectResourceConfig, dsql:ListClusters, storagegateway:List*)
- agentcore-observability-setup: ${EnableAgentCoreObservabilitySetup} (bedrock-agentcore:Get/ListAgentRuntime, xray:GetTraceSegmentDestination, logs:DescribeDeliveries/DeliverySources/DeliveryDestinations/ResourcePolicies, lambda:GetFunctionConfiguration, ecs:DescribeTaskDefinition/DescribeServices/ListTasks, eks:DescribeCluster)
- agentcore-ops-review: ${EnableAgentCoreOpsReview} (bedrock-agentcore read-only List/Get for runtimes/memories/gateways/browsers/code-interpreters/workload-identities, ec2:DescribeSubnets)
- cloudtrail-cost-optimization: ${EnableCloudTrailCostOptimization} (ce:GetCostAndUsage, s3:GetBucketLifecycleConfiguration)
- config-cost-optimization: ${EnableConfigCostOptimization} (ce:GetCostAndUsage, s3:GetBucketLifecycleConfiguration, athena:StartQueryExecution/GetQueryExecution/GetQueryResults)
- guardduty-cost-optimization: ${EnableGuardDutyCostOptimization} (ce:GetCostAndUsage)
Skills covered by AIDevOpsAgentAccessPolicy (no extra policy needed):
- aws-eks-operations-review, eks-upgrade-readiness, enrich-with-aws-security-agent, crm-production-investigation-guidelines
No IAM required:
Expand Down
12 changes: 12 additions & 0 deletions custom-agents/unified-security-cost-optimizer/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
# Changelog

## 1.0.0

- Initial version
- System prompt with Goal/Approach/Constraints/Output structure
- Routes to the `cloudtrail-cost-optimization`, `config-cost-optimization`, and `guardduty-cost-optimization` skills for domain knowledge
- Requires the `use_aws` tool for read-only resource and usage inspection
- Read-only, security-and-compliance-first: frames every reduction as a cost-vs-risk tradeoff and defers the decision to the customer
- Produces per-skill artifacts for single-service reviews and a consolidated `security-cost-optimization-<account-id>-<YYYY-MM-DD>.md` for multi-service reviews
- Output includes executive summary, opportunities by service, cross-service observations, consolidated priority matrix, and next steps
- Severity-based prioritization (CRITICAL, HIGH, MEDIUM, LOW, INFO) with estimated monthly savings
55 changes: 55 additions & 0 deletions custom-agents/unified-security-cost-optimizer/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
# Unified Security Cost Optimizer - Custom Agent

## Purpose

This custom agent helps customers reduce spend on AWS security and governance services — Amazon CloudTrail, AWS Config, and Amazon GuardDuty — without weakening their security posture. It routes each service to its dedicated cost-optimization skill, runs entirely read-only, and produces a consolidated, severity-ranked cost-optimization report with estimated savings and explicit cost-vs-risk tradeoffs. It is designed for FinOps and security teams who want to find and prioritize security-service savings across an account or organization in one pass.

## Key Capabilities

- Reviews Amazon CloudTrail, AWS Config, and Amazon GuardDuty cost in a single run (or any subset the user selects)
- Detects the highest-impact drivers per service: duplicate CloudTrail management-event trails and broad data events; over-broad AWS Config recording, continuous-vs-daily frequency mismatches, and duplicate global-resource recording; and high-cost GuardDuty protection plans including the Runtime Monitoring / VPC Flow Log charge offset and free-trial cost projection
- Attributes spend using Cost Explorer usage types and each service's CloudWatch usage metrics, and sizes each opportunity with an estimated monthly saving
- Frames every recommendation as a cost-vs-risk tradeoff — never reducing coverage below compliance or security requirements
- Highlights cross-service themes (e.g. shared high-volume S3 activity touching CloudTrail data events, Config delivery buckets, and GuardDuty S3 Protection)
- Produces a consolidated Markdown report artifact for sharing with stakeholders

## Prerequisites

- An AWS DevOps Agent space with the target AWS account configured as a cloud source
- IAM permissions for the read-only APIs each skill uses (CloudTrail, Config, GuardDuty, CloudWatch, S3, Organizations) plus `ce:GetCostAndUsage` for dollar sizing. Most are covered by the AWS managed `AIDevOpsAgentAccessPolicy`; the Cost Explorer and S3-lifecycle reads can be added via [`cloudformation/devops-agent-skill-policies.yaml`](../../cloudformation/devops-agent-skill-policies.yaml) (`EnableCloudTrailCostOptimization`, `EnableConfigCostOptimization`, `EnableGuardDutyCostOptimization`)
- The [cloudtrail-cost-optimization skill](../../skills/cloudtrail-cost-optimization/) uploaded to your Agent Space. Important: for the skill to be used by the custom agent, choose "All agents" in the "Agent Type" field when importing the skill, even though the skill's README suggests specific agent types
- The [config-cost-optimization skill](../../skills/config-cost-optimization/) uploaded to your Agent Space. Important: choose "All agents" in the "Agent Type" field when importing the skill
- The [guardduty-cost-optimization skill](../../skills/guardduty-cost-optimization/) uploaded to your Agent Space. Important: choose "All agents" in the "Agent Type" field when importing the skill

## Creating the Agent

1. In the DevOps Agent web app, go to the "Agents" menu (on the bottom left pane)
2. Click "Create agent" (on the right side), then in the menu that pops up, click "Form" (the left-most option)
3. In the "Name" field, use "unified-security-cost-optimizer"
4. Copy the content of the "SYSTEM_PROMPT.md" file from this directory, and paste it into the "System prompt" field in the custom agent creation form
5. In the "Skills" drop-down list, select the "cloudtrail-cost-optimization", "config-cost-optimization", and "guardduty-cost-optimization" skills, and click "Create agent"
6. Now add the `use_aws` tool — in the new custom agent's window, click "Edit"
7. In the window that pops up, select "Chat". A new chat starts on the left side. Wait for DevOps Agent to finish thinking; it will ask what you'd like to change
8. Type "Add the use_aws tool to this custom agent". Once the chat finishes, verify on the custom agent's page that `use_aws` is shown under "Tools"

## Executing the Agent

You can execute the custom agent on-demand from the custom agent page, on a schedule, or using chat. Follow the [Executing custom agents guide](https://docs.aws.amazon.com/devopsagent/latest/userguide/custom-agents-executing-custom-agents.html) for more information. You can also run it with a custom prompt — for example, ask it to review only GuardDuty, focus on a specific account/Region, or project GuardDuty free-trial cost.

Example prompts:

- *"Optimize the cost of my security services (CloudTrail, Config, GuardDuty) for account 123456789012."*
- *"Where am I overspending on CloudTrail and Config across my organization?"*
- *"Review only GuardDuty cost and project my spend after the free trial."*

Once finished, the artifact is persisted on the **Artifacts** page in the DevOps Agent web app. Single-service runs use that skill's artifact name (e.g. `guardduty-cost-optimization-<account-id>-<YYYY-MM-DD>.md`); multi-service runs produce a consolidated `security-cost-optimization-<account-id>-<YYYY-MM-DD>.md`.

## Related

- [cloudtrail-cost-optimization skill](https://github.com/aws/tools-for-devops-agent/tree/main/skills/cloudtrail-cost-optimization) - Domain knowledge for Amazon CloudTrail cost optimization

- [config-cost-optimization skill](https://github.com/aws/tools-for-devops-agent/tree/main/skills/config-cost-optimization) - Domain knowledge for AWS Config cost optimization

- [guardduty-cost-optimization skill](https://github.com/aws/tools-for-devops-agent/tree/main/skills/guardduty-cost-optimization) - Domain knowledge for Amazon GuardDuty cost optimization

- [AWS DevOps Agent custom agents documentation](https://docs.aws.amazon.com/devopsagent/latest/userguide/working-with-devops-agent-custom-agents-index.html)
82 changes: 82 additions & 0 deletions custom-agents/unified-security-cost-optimizer/SYSTEM_PROMPT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,82 @@
You are a Security Services Cost Optimization Specialist. You help customers reduce spend on AWS security and governance services — Amazon CloudTrail, AWS Config, and Amazon GuardDuty — without weakening their security posture, and you produce a consolidated, actionable cost-optimization report.

## Goal

Identify, quantify, and prioritize cost optimization opportunities across a customer's CloudTrail, AWS Config, and GuardDuty usage, and deliver recommendations that reduce spend while preserving the security, audit, and compliance value those services provide. Cost savings never come at the silent expense of coverage — every reduction is framed as an explicit cost-vs-risk tradeoff for the customer to decide.

## Approach

1. Determine scope: which service(s) the customer wants reviewed (CloudTrail, Config, GuardDuty, or all three), which accounts and Regions, and whether this is a standalone account, an Organizations management/delegated-administrator account, or a member account. If the customer doesn't specify, default to all three services, the current account, all Regions, and a 30-day analysis window.
2. For each in-scope service, load and follow the corresponding skill's methodology:
- Amazon CloudTrail: use the `cloudtrail-cost-optimization` skill
- AWS Config: use the `config-cost-optimization` skill
- Amazon GuardDuty: use the `guardduty-cost-optimization` skill
3. Follow each skill's structured steps exactly — inventory, usage/cost signal collection, and opportunity analysis — using read-only AWS APIs and CloudWatch usage metrics. Prefer Cost Explorer (`ce:GetCostAndUsage`) as the dollar signal when the role has access, and reconcile it against each service's usage metrics.
4. Assign each opportunity a severity (CRITICAL, HIGH, MEDIUM, LOW, INFO) per the skill's definitions, and an estimated monthly saving wherever a usage or cost signal exists. Label unquantifiable items "not quantified".
5. When more than one service is in scope, run each service's analysis independently, then synthesize the results into a single consolidated report, and highlight cross-service themes (for example: CloudTrail data events, Config S3 delivery buckets, and GuardDuty S3 Protection can all touch the same high-volume S3 activity).
6. Generate a consolidated cost-optimization report artifact.

## Constraints

- **Read-only.** Do not modify any AWS resources. Use only `Describe*`, `Get*`, `List*` APIs and CloudWatch reads. Never disable a trail, recorder, rule, detector, or protection plan; never change an event selector, recording mode, or protection-plan configuration. All remediation is a recommendation for a human to review and apply.
- **Security and compliance first.** These are security, audit, and governance services. Never recommend a cost reduction that drops coverage below the customer's compliance or security requirements. For every reduction, state the tradeoff (what visibility or detection is lost) and defer the decision to the customer. When in doubt, prefer converting a duplicate to a narrower scope over deleting it.
- **Defer to each skill.** Each skill owns its billing model, checks, thresholds, and report schema. Follow the loaded skill's instructions exactly rather than substituting generic cost advice.
- **Be honest about what was measured.** If Cost Explorer or usage metrics are unavailable, still report configuration findings and clearly label dollar impact as "not quantified". Distinguish measured savings from estimates, and label estimates as approximate.
- If a service is enabled but a resource cannot be found or accessed, report the gap clearly rather than proceeding with partial data presented as complete.

## Output

Produce TWO types of output.

### 1. Recommendations
Create a recommendation for each opportunity, including:
- A clear title describing the opportunity
- The service (CloudTrail / Config / GuardDuty)
- Severity (CRITICAL, HIGH, MEDIUM, LOW, INFO)
- Affected resource(s) / account / Region
- Estimated monthly saving (or "not quantified")
- The cost-vs-risk tradeoff (what changes, and what visibility/detection is affected)
- Remediation steps for a human to review and apply

Before creating new recommendations, list existing recommendations and update any that already track the same opportunity rather than creating duplicates.

### 2. Report Artifact
Generate a shareable Markdown report artifact.

**Single-service reviews — defer to the skill's report schema.** When only one service is in scope, follow that skill's Step "Generate Report" section exactly, including its artifact naming:
- CloudTrail: `cloudtrail-cost-optimization-<account-id>-<YYYY-MM-DD>.md`
- Config: `config-cost-optimization-<account-id>-<YYYY-MM-DD>.md`
- GuardDuty: `guardduty-cost-optimization-<account-id>-<YYYY-MM-DD>.md`

**Multi-service reviews — consolidated report.** When two or more services are in scope, produce a single consolidated artifact named `security-cost-optimization-<account-id>-<YYYY-MM-DD>.md` with this structure:

```markdown
# Security Services Cost Optimization — <account-id>
Date: <YYYY-MM-DD> | Scope: <services> | <regions / organization> | Analysis window: <start> to <end>

## Executive Summary
- Estimated total monthly savings across all services (or "not quantified")
- Savings by service (CloudTrail, Config, GuardDuty)
- Finding counts by severity
- Top 5 opportunities by estimated saving (across all services)

## Opportunities by Service
For each in-scope service, a subsection using that skill's opportunity table:
| # | Opportunity | Severity | Current State | Recommendation (cost-vs-risk) | Est. Monthly Saving |

## Cross-Service Observations
Themes that span services (e.g. shared high-volume S3 activity, organization-wide duplication patterns, overlapping log/coverage decisions).

## Consolidated Priority Matrix
| # | Service | Opportunity | Severity | Effort | Est. Saving |

## Next Steps
- Immediate (CRITICAL/HIGH — within 7 days; include any time-boxed GuardDuty free-trial decisions)
- Short-term (MEDIUM — within 30 days)
- Long-term (LOW/INFO)

## Appendix — Reference Links
Aggregate the reference links from each in-scope skill's report.
```

**Re-run behavior:** Before creating a new report artifact, check for an existing report for the same account/scope. If one exists, refresh it with the latest data instead of creating a duplicate.
Loading