Skip to content

feat: add aws-fsxn-operations-review skill - #117

Open
aneeshamz wants to merge 1 commit into
aws:mainfrom
aneeshamz:add-aws-fsxn-operations-review
Open

aneeshamz wants to merge 1 commit into
aws:mainfrom
aneeshamz:add-aws-fsxn-operations-review

Conversation

@aneeshamz

@aneeshamz aneeshamz commented Oct 4, 2026 •

Copy link
Copy Markdown

What this adds

A new skill, aws-fsxn-operations-review: a strictly read-only, fully automated
operational review for Amazon FSx for NetApp ONTAP (FSxN). It self-discovers all
ONTAP file systems in an account/region and evaluates 46 checks across 5 pillars
— Backup, Observability, Operations, Performance, Security — using only public AWS
APIs via use_aws (fsx, cloudwatch, backup, ec2). Output is a prioritized,
evidence-based findings report keyed to check IDs; a full tabular report template is
available for the Evaluation agent / on request.

Works for production and pre-production. No manual steps, no ONTAP CLI, no
Create*/Update*/Delete*, no data-plane access.

Why it's not a duplicate

  • aws-backup-coverage-review answers "what across my account isn't protected by AWS
    Backup" — account-wide, AWS Backup-centric.
  • This skill answers "is this FSxN footprint operationally healthy across five
    pillars" — FSxN-specific, multi-pillar. Its backup checks look at FSxN-native
    snapshots, SnapMirror/DR, and AWS Backup coverage for FSxN volumes specifically,
    alongside performance/security/ops checks the backup skill doesn't cover.

FSxN-specific correctness

  • Gen2 file systems (DeploymentType ending _2) don't emit
    StorageCapacityUtilization; SSD utilization is computed from per-tier
    StorageUsed{SSD} / StorageCapacity{SSD}.
  • The SVM root volume (JunctionPath = "/") is detected from returned fields,
    excluded only where the metric is invalid (OPS-10), tagged elsewhere, and never a
    deletion candidate.
  • Evidence guardrails: every result is based solely on values returned this run;
    missing/failed/empty data → "Not evaluated" with a reason, never a guessed result.

IAM

Least-privilege, read-only. Wired into the shared
cloudformation/devops-agent-skill-policies.yaml via a new
EnableAwsFsxnOperationsReview toggle + inline policy (no per-skill IAM file).
Note: these actions were not delta-trimmed against AIDevOpsAgentAccessPolicy
with iam:SimulatePrincipalPolicy (no account access at authoring time) — a
maintainer may remove any already covered by the managed policy (e.g. backup:List*,
CloudWatch reads). sts:GetCallerIdentity is intentionally omitted (needs no IAM
permission).

Testing

  • Ran live read-only reviews against a real FSxN file system (SINGLE_AZ_2 Gen2) with
    and without the skill, across multiple iterations.
  • Eval results committed under evals/: structure, best-practices, and functional
    (3 scenarios × 3 iterations, with_skill vs without_skill). The functional comparison
    favored with_skill on both evaluations.
  • python3 .github/scripts/validate_skill_evals.py --skill aws-fsxn-operations-review
    passes locally.

Relates to #118.

By submitting this pull request, I confirm that my contribution is made under the
terms of the Apache License 2.0.

Read-only, fully automated Amazon FSx for NetApp ONTAP operational review: 46 checks across Backup, Observability, Operations, Performance, and Security via public AWS APIs (fsx, cloudwatch, backup, ec2). Includes references, report template, and structure/best-practices/functional eval results. Wires least-privilege IAM into the shared cloudformation/devops-agent-skill-policies.yaml via a new EnableAwsFsxnOperationsReview toggle.
@aneeshamz

Copy link
Copy Markdown
Author

@aws/tools-for-devops-agent-admins first-time contribution — a read-only FSx for NetApp ONTAP operational-review skill (Storage domain). Could a maintainer help triage and assign a Storage TFC SME for the domain review? Happy to iterate. Eval results are committed and the local validate-skill-evals check passes.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant