Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions llms.txt
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ Tools can be used with these AWS DevOps Agent types:
- [AWS Routing Skill](skills/aws-routing/SKILL.md): Read-only analysis and troubleshooting of AWS routing and BGP path selection across Cloud WAN, Direct Connect, Transit Gateway, VPC, and VPN — traces the end-to-end path, applies each construct's route-evaluation order, engineers traffic with local-preference communities and AS-path, flags non-deterministic selection, and produces describe/get/list validation commands grounded in public AWS documentation
- [Bedrock Adoption Readiness Skill](skills/bedrock-adoption-readiness/SKILL.md): Assesses an AWS account's readiness to run Amazon Bedrock at production scale across IAM governance, data retention (ZDR), quota and capacity headroom, and operational observability, covering both the standard Bedrock and bedrock-mantle (OpenAI-compatible) surfaces with multi-region discovery
- [Analytics OpenSearch Expertise Skill](skills/analytics-opensearch-expertise/SKILL.md): Performs read-only health assessments of Amazon OpenSearch Service domains through 24 deterministic checks across cluster health, storage and shards, performance, security, and cost optimization, producing a structured findings report with prioritized remediation guidance
- [FSx for Windows SLA Optimizer Skill](skills/storage-fsx-windows-sla-optimizer/SKILL.md): Reviews one or many Amazon FSx for Windows File Server file systems for SLA readiness across seven availability dimensions (deployment type, Active Directory health, throughput and storage sizing, backups, maintenance window, and alarms) using read-only control-plane calls, with usage-pattern trend analysis (peak-aware throughput sizing, weekday/weekend profile, and storage growth projection) that produces a rated report and flags over-provisioned or idle capacity as cost-optimization opportunities
- [AI/ML Access Diagnostics Skill](skills/aiml-access-diagnostics/SKILL.md): Diagnoses IAM and access failures for Amazon Bedrock and SageMaker calls by tracing the authorization chain from caller identity through iam:PassRole, role trust policy, role permissions, resource policies, and SCPs to identify which hop denied the call
- [Bedrock Operation Review Skill](skills/bedrock-operation-review/SKILL.md): Performs comprehensive Amazon Bedrock operational reviews aligned with the AWS Well-Architected Framework and Bedrock best practices across five pillars — security, performance, service quotas, cost optimization, and resilience — using control-plane and CloudWatch APIs only (no model invocations or prompt/response content read)
- [AgentCore Observability Setup Skill](skills/agentcore-observability-setup/SKILL.md): Validates and bootstraps Amazon Bedrock AgentCore observability across runtime agents, Memory and Gateway resources, built-in tools, and agents hosted outside the runtime, verifying telemetry wiring via read-only CloudWatch, X-Ray, and AgentCore APIs and prescribing exact remediation for gaps it cannot directly read
Expand Down
3 changes: 3 additions & 0 deletions skills/storage-fsx-windows-sla-optimizer/.skilleval.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
audit:
ignore:
- STR-016 # README alongside SKILL.md is intentional
96 changes: 96 additions & 0 deletions skills/storage-fsx-windows-sla-optimizer/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
# Changelog

All notable changes to this skill are documented here. New entries go at the top.

## [1.0.0] - 2026-09-01

Initial release for AWS DevOps Agent.

### Review scope
- Read-only SLA-readiness and availability review of Amazon FSx for Windows File
Server file systems across seven dimensions: deployment type (Single-AZ vs
Multi-AZ), Active Directory health, throughput capacity sizing, storage capacity
headroom, backups, maintenance window, and CloudWatch alarm coverage.
- **SLA Readiness rating** (High / Medium / Low / Indeterminate) with per-dimension
findings and remediation, grounded in AWS documentation thresholds (the 20%
free-storage guidance, the read + 2 × write throughput sizing formula, the Multi-AZ
recommendation from Security Hub control FSx.5, and the Misconfigured / Active
Directory reachability model). Rating precedence: any Critical → Low; else any
Warning or unverifiable dimension → Medium; else High.
- Automatic single-file-system vs multi-file-system (fleet) routing by input count,
including batched review with manifest tracking and resume for 21+ file systems.

### Active Directory / Misconfigured handling
- `MISCONFIGURED` lifecycle is a 🔴 Critical availability finding (AD unreachable).
- Targeted AD root-cause matching: the finding matches the reported failure detail
against known lifecycle codes and quotes a specific fix —
`ACTIVE_DIRECTORY_INVALID_CREDENTIALS` (rotated/expired service-account password,
plus the Protected Users / NTLM caveat),
`ACTIVE_DIRECTORY_INSUFFICIENT_PERMISSIONS` (OU delegation), and
`ACTIVE_DIRECTORY_COMP_ACC_REUSE_BLOCKED_BY_POLICY` (KB5020276 netjoin hardening →
"Allow computer account re-use" GPO).
- `MISCONFIGURED_UNAVAILABLE` (quarantined) recognized as the most severe AD state —
data currently inaccessible after prolonged AD failure.
- Names the read-only `AWSSupport-ValidateFSxWindowsADConfig` runbook as a follow-up
diagnostic (never executes it).

### Trend / usage-pattern analysis
- Usage-pattern (trend) analysis on the throughput and storage dimensions, built on
daily-aggregate CloudWatch metrics (`Period=86400`) over a configurable lookback
(default 30 days; 14 / 21 / 30 / 60 accepted).
- **Peak-aware throughput sizing:** evaluates provisioned capacity against measured
**peak** demand (read + 2 × write at the highest 5-minute interval average), not
just the window average, catching short demand peaks that a daily average hides.
Peak figures are labeled approximate and use the FSx byte metrics' supported
`Sum` statistic.
- **Weekday/weekend usage profile** classification, used as evidence for the
throughput cost note.
- **Storage growth projection** to the 20%-full floor; a projection of ≤ 4 weeks is
surfaced as at least a Warning even when current free % is healthy.
- New file systems (< ~14 days of history) report `insufficient-data` and skip
projections rather than extrapolating.

### Cost optimization (advisory; never lowers the SLA rating)
- Heavily over-provisioned throughput or storage flagged as 💰 right-sizing
opportunities.
- **Idle-file-system** signal (near-zero data I/O and operations across the window) —
the strongest cost signal, surfaced first as a decommission candidate; supersedes
the over-provisioned-throughput note.
- Throughput cost note carries a caveat when the recommended tier is at or below
32 MBps: FSx emits throughput-utilization metrics only at ≥ 32 MBps, so the 8/16
MBps tiers cannot be validated from CloudWatch and require customer-side observation.

### Availability nuances
- **Multi-AZ client-side failover caveat:** Linux/macOS clients and DNS-caching
runtimes (.NET on Linux, Lambda) do not auto-fail-over like Windows SMB clients;
third-party DNS (e.g. Infoblox) needs two A records (one per file-system IP); a
throughput-capacity update is a safe way to test failover.
- **Single-AZ maintenance wording** is honest that the AWS "typically under ~20
minutes" figure is best-effort, not a guarantee; the whole window is treated as
potentially unavailable.
- **Storage-optimization sequencing:** a storage increase triggers a background
optimization phase that can pin `FileServerDiskThroughputUtilization` near 100%, so
throughput should be raised before storage (notes the 4-modifications-per-24h
limit); an in-progress `STORAGE_OPTIMIZATION` action is surfaced as an ℹ️ info note
so elevated throughput metrics are read as transient.

### Safety & operations
- Self-contained data collection via read-only control-plane API calls and CloudWatch
metric reads (`use_aws`); no AWS profile or credentials requested from the user. The
skill never reads file/share data over SMB and never performs a write, update,
create, or delete.
- Fully covered by the `AIDevOpsAgentAccessPolicy` managed policy — no additional IAM.
- Pre-flight permissions/tooling handling reports unverifiable checks instead of
inferring configuration, capping the rating at Medium.
- Deployment-type remediation correctly states Single-AZ cannot be converted to
Multi-AZ in place (create-new-and-migrate).
- Final Delivery Contract: the report is emitted as a persisted artifact (when the
runtime supports it) and returned verbatim, preventing the host agent from
summarizing or reformatting it.
- README documents out-of-scope FSx for Windows support themes (shadow copies/VSS, SMB
over WAN, file-search indexing, NTFS/SYSTEM ACLs, GPOs not applying to FSx nodes,
anti-malware) so the skill does not over-promise.

### Notes
- The frontmatter description uses the repository's standard plain multiline YAML
style and remains within the AWS DevOps Agent 1024-character limit.
Loading
Loading