Conversation
|
Tested the DataOps maturity skill and works as expected. Full maturity assessment generated. |
ams-thakkar
left a comment
There was a problem hiding this comment.
What needs to change
Add a gated IAM policy for the actions AIDevOpsAgentAccessPolicy doesn't grant. I checked all 61 actions the skill calls against the live policy: 52 are covered, these five are not.
| Action | Policy has |
|---|---|
cost-optimization-hub:ListRecommendations |
nothing for this service |
quicksight:ListDashboards |
nothing for this service |
glue:GetJobs |
glue:GetJob (singular) and glue:List*, no Get* wildcard |
iam:ListPolicies |
ListRoles, ListUsers, ListEntitiesForPolicy — not ListPolicies |
lakeformation:GetDataLakeSettings |
Describe*, GetLFTag, GetResourceLFTags, List* |
Add an EnableAnalyticsDataopsExpertise parameter, condition, inline policy, and SkillPolicySummary line to cloudformation/devops-agent-skill-policies.yaml. #71 is a good model.
Reframe README.md:25 against AIDevOpsAgentAccessPolicy. It currently reads "Most are covered by a ViewOnly/read-only managed policy; attach a supplemental policy for any gaps" — that names the wrong policy and leaves the gaps unnamed. State coverage against the agent's own managed policy and point at the CloudFormation gate above.
Fix four action names that look like API names rather than IAM actions. In each case the capability is already granted under the correct name, so this is a docs fix — please confirm each:
mwaa:ListEnvironments→ MWAA authorises underairflow;airflow:List*is grantedresourcegroupstaggingapi:GetResources→ prefix istag;tag:GetResourcesis grantedkinesisanalyticsv2:ListApplications→ v2 authorises underkinesisanalytics;kinesisanalytics:List*is granteds3:GetBucketLifecycleConfiguration→ the IAM action iss3:GetLifecycleConfiguration, which is granted
Rebase — llms.txt conflicts with main. Routine churn from six merges today, not your doing.
Nits
None blocking.
Thanks
Mapping each of the 26 questions to specific read-only APIs and fields, with a documented rule for scoring them 1–5, is what makes this auditable rather than a vibe check — and capping a question at 3 when control-plane signals can't fully confirm it is the right call over guessing. Scoping the whole assessment to control-plane reads with no data-plane access keeps the blast radius small for something that touches 16 services.
Verified myself: mkdocs build --strict passes with zero warnings; all six JSON files parse; extensions limited to md/json/yaml/html; name matches the directory; description is 907 characters; version: 1.1.0 matches the CHANGELOG top entry; llms.txt has an entry; no relative .md links; and the evals check reports WARN under the predating-PR waiver.
Thanks @andrehass for testing this. One ask while we're here: for a skill scoring 26 questions across 16 services, could you note which dimensions you exercised and on what kind of account? That makes the sign-off reusable when this skill changes.
Read-only, API-driven DataOps maturity assessment: 26 questions scored 1-5 across five dimensions (Architecture; Security & Governance; Incident Management & Observability; Automation & Testing; Cost), with a verbatim remediation reference (official AWS doc links) and evals. Control-plane APIs only; no data-plane access, no scripts. Adds an llms.txt index entry.
…orecard layout (v1.1.0) Add an optional downloadable HTML report and a companion Markdown report as static templates under assets/templates/, filled by the agent (no scripts, no renderer — same pattern as redshift-support-specialist). Reproduces the account maturity scorecard layout: executive score-card tiles, per-dimension collapsible sections with RAG summaries, per-question cards with confidence badges, evidence tiles, flags and discussion prompts, and the 26-row score matrix. Also moves the report layout to references/report-format.md (progressive disclosure) to keep SKILL.md lean, and adds HTML-escaping + template-is-not-a- data-source rules. Audit remains 98/100 (A).
…AM policy + action-name/README fixes (v1.1.1) - Add EnableAnalyticsDataopsExpertise gated inline policy to cloudformation/devops-agent-skill-policies.yaml for the five read-only actions AIDevOpsAgentAccessPolicy does not grant (cost-optimization-hub:ListRecommendations, quicksight:ListDashboards, glue:GetJobs, iam:ListPolicies, lakeformation:GetDataLakeSettings), with a SkillPolicySummary line. - Correct four IAM action names (docs-only; capability already granted): mwaa:ListEnvironments -> airflow:ListEnvironments, resourcegroupstaggingapi:GetResources -> tag:GetResources, kinesisanalyticsv2:ListApplications -> kinesisanalytics:ListApplications, s3:GetBucketLifecycleConfiguration -> s3:GetLifecycleConfiguration. - Reframe README IAM section against AIDevOpsAgentAccessPolicy and point at the CloudFormation gate for the five supplemental actions. Audit remains 98/100 (A).
94c8d4d to
9eac67b
Compare
|
@ams-thakkar. All four items are addressed in 9eac67b (v1.1.1):
All read only. The skill degrades gracefully if any is absent (the affected question is scored as a floor with a caveat rather than failing).
Agent Skill Eval audit remains 98/100 (A) |
ams-thakkar
left a comment
There was a problem hiding this comment.
Re-reviewed at 9eac67b. Three of the four items are done and verified. One is half done, and my original ask is why — I pointed at the wrong file. Numbers below are also corrected; mine were wrong the first time.
What needs to change
Reframe the IAM section in SKILL.md too. You fixed README.md, and it reads well now — it names AIDevOpsAgentAccessPolicy, lists the five supplemental actions with the reason each one isn't covered, and points at the CloudFormation gate. But SKILL.md:33-34 still carries the original text verbatim:
IAM permissions required (all read-only). Most are covered by a read-only / ViewOnly managed policy; attach the supplemental permissions for any gaps:
SKILL.md doesn't mention AIDevOpsAgentAccessPolicy, the gate, or EnableAnalyticsDataopsExpertise anywhere — I grepped for all three. That's the file the agent reads and the one an operator lands on first, so as it stands they'd attach a ViewOnly policy and have no way to know which five actions are missing. The README paragraph you already wrote is the fix; it just needs to exist here as well.
This one is on me. My ask cited README.md:25 when the same text appeared in both files, so you fixed exactly what I pointed at.
Nits
Neither is blocking.
SKILL.md:35lists bothglue:GetJobsandglue:GetJob, whereREADME.md's equivalent list has only the plural. The singular is granted by the managed policy so it costs nothing, but the two lists should agree.- The action counts are off in a couple of places, including mine. The new comment in
devops-agent-skill-policies.yamlsays "52 of the 57 IAM actions"; my last review said 61 with 52 covered. Neither is right:README.md's canonical list has 58 actions, of which 53 are covered and 5 are not. My 61 double-counted the four misnamed actions alongside their replacements, and 57 drops them entirely. Worth fixing in the template comment since it will outlive this thread.
Thanks
The gated policy is exactly the shape I asked for and then some — the inline comment records the five actions with the specific reason each falls outside the managed policy, which means the next person to touch it doesn't have to re-derive the delta. Noting in both the comment and the CHANGELOG that the skill degrades to a floor score rather than failing when a permission is absent is the detail that makes the Default: 'true' defensible.
Verified myself against 9eac67b, with the live managed policy rather than from memory. AIDevOpsAgentAccessPolicy is at v11, 931 Allow entries and no Deny. Of the 58 actions in your canonical list, 53 match the policy and 5 do not, and those 5 are exactly the ones in PolicyAnalyticsDataopsExpertise — nothing uncovered is missing from the gate, and nothing in the gate is redundant. All four renamed actions resolve: airflow:ListEnvironments via airflow:List*, tag:GetResources exactly, kinesisanalytics:ListApplications via kinesisanalytics:List*, s3:GetLifecycleConfiguration exactly. All four of the old names are genuinely uncovered, which confirms the renames were necessary and not cosmetic; they now survive only in the CHANGELOG entry describing the change, which is right.
On the rest: the CloudFormation template adds the parameter to the Metadata interface group, the condition, the policy, and the SkillPolicySummary line, following the existing per-skill blocks. cfn-lint on it reports the same four pre-existing W2001 unused-parameter warnings as main and nothing new, and EnableAnalyticsDataopsExpertise is not among them. mkdocs build --strict passes with zero warnings and the catalog page generates. All six eval JSON files parse. Extensions are limited to md/json/yaml/html. Frontmatter name matches the directory, description is 909 characters, version: 1.1.1 matches the CHANGELOG top entry. The llms.txt entry survived the rebase. Rebased onto current main at 301ee08, zero commits behind, and the required check passes.
One fix and I'll approve. Mergeable state is BLOCKED on the approval alone — the required check is green and there are no open threads.
… counts (v1.1.2) Address re-review on PR aws#67: - Reframe the SKILL.md IAM section to match README.md: name AIDevOpsAgentAccessPolicy, list the five supplemental actions with the reason each is uncovered, and point at the EnableAnalyticsDataopsExpertise gate in the CloudFormation template (previously only README.md carried this; SKILL.md still had the old ViewOnly wording). - Remove a duplicate glue:GetJob (singular) from the SKILL.md permission list so it agrees with README.md. - Correct the action count in the CloudFormation template comment: the canonical list has 58 actions, 53 covered and 5 in the gate (was 52 of 57). Audit remains 98/100 (A).
|
Thanks for the re-review and for catching the split, @ams-thakkar. Fixed in 8a485fd (v1.1.2): SKILL.md IAM section now carries the same framing as README.md: it names AIDevOpsAgentAccessPolicy, lists the five supplemental actions with the reason each is uncovered, and points at the EnableAnalyticsDataopsExpertise gate in |
Read-only, API-driven DataOps maturity assessment: 26 questions scored 1-5 across five dimensions (Architecture; Security & Governance; Incident Management & Observability; Automation & Testing; Cost), with a verbatim remediation reference (official AWS doc links) and evals. Control-plane APIs only; no data-plane access, no scripts. Adds an llms.txt index entry.
Description
Type of change
Testing
License confirmation