role-devops:aws-expert
Deep AWS expertise covering IAM, VPC networking, EKS, ECS, Lambda serverless, EC2 and Auto Scaling, RDS and Aurora, DynamoDB, S3, CloudFront, Route 53, ALB/NLB, SQS/SNS/EventBridge, ElastiCache, Secrets Manager, KMS, CloudTrail, CloudWatch, AWS Config, WAF, Security Hub, Cost Explorer, Savings Pl...
SKILL.md
Full skill instructions
AWS Expert
When to use
- Designing IAM policies, configuring IRSA/Pod Identity, or setting up Organizations with SCPs
- Building or reviewing VPC architecture, security groups, load balancer configuration
- Working with EC2 Auto Scaling, ECS/Fargate, Lambda, or EKS cluster setup
- Configuring S3, EBS, EFS, RDS, Aurora, DynamoDB, or SQS/SNS/EventBridge
- Security hardening with KMS, Secrets Manager, CloudTrail, GuardDuty, or Security Hub
- Cost optimization with Savings Plans, Reserved Instances, or Cost Explorer governance
Core principles
- Roles over users — IAM roles for all programmatic access, OIDC for CI/CD
- Least privilege always — no
Action: *orResource: *in production policies - Private by default — VPC endpoints for AWS services, no public RDS/S3
- Multi-account guardrails — SCPs at Organizations level, centralized security account
- Cost is owned — tagging enforced, Compute Savings Plans for baseline, Spot for burst
Reference Files
references/iam-security.md— Least-privilege IAM design, IRSA/Pod Identity, Permission Boundaries, SSO, AWS Config, GuardDuty, Security Hub, KMS envelope encryption, Secrets Manager rotation, CloudTrail, multi-account Organizations and Landing Zonereferences/networking-compute.md— VPC multi-tier design, Transit Gateway, PrivateLink, security groups, ALB/NLB, Global Accelerator, EC2 Launch Templates, Spot mixed-instance policy, IMDSv2, ECS Fargate and EC2, Lambda concurrency and SnapStart, EKS managed add-ons, Bottlerocket, CloudWatch Container Insightsreferences/storage-databases-cost.md— S3 versioning, lifecycle rules, Block Public Access, Object Lock, SSE-KMS, gp3 EBS, EFS, RDS Multi-AZ, Aurora Serverless v2, RDS Proxy, DynamoDB On-Demand, Global Tables, DAX, SQS/SNS/EventBridge, Compute Savings Plans, Cost Explorer, Infracost
Best Practices Checklist
- All accounts under AWS Organizations with SCPs enforcing guardrails
- CloudTrail enabled in all regions, delivered to immutable centralized bucket
- GuardDuty and Security Hub enabled in all accounts and regions
- IMDSv2 required on all EC2 Launch Templates
- IRSA or Pod Identity for all EKS pod AWS API access
- No long-lived IAM user access keys — use roles and OIDC
- VPC endpoints for S3, DynamoDB, ECR, Secrets Manager, STS
- RDS Multi-AZ and encryption enabled for all production databases
- S3 Block Public Access enabled at account level
- KMS CMKs for sensitive data encryption with key rotation enabled
- Cost allocation tags enforced on all resources
- Compute Savings Plans covering baseline workload
- CloudWatch Alarms on burn rate metrics, not raw thresholds
- EKS managed add-ons (LBC, EBS CSI, VPC CNI) version-pinned and updated
- Bottlerocket or Amazon Linux 2023 for EKS/EC2 node OS
