resilience-hub-getting-started — Sets up AWS Resilience Hub v2 from scratch: creates resilience policies with SLO targets, registers systems and user journeys.
resilience-hub-multi-account — Configures AWS Resilience Hub v2 for multi-account resilience management across an AWS Organization.
resilience-program-design — Designs a resilience program: how to structure and standardize resilience policies across an organization, team.
route53 — Configures Amazon Route 53 DNS: public and private records, traffic-steering routing policies, health checks, DNS Firewall, Route 53 Profiles.
running-release-tests — Run automated release testing (UI or API) via the AWS DevOps Agent using a pre-configured test profile.
scanning-with-aws-security-agent — Run an AWS Security Agent scan on the workspace — uploads the source to AWS, scans it with the managed Security Agent service, and returns ranked.
securing-s3-buckets — Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations.
setting-up-ec2-instance-profiles — Configures EC2 instances to securely call AWS services by creating and attaching IAM roles via instance profiles, eliminating hardcoded credentials.
setup — Set up the AWS DevOps Agent and AWS Security Agent connections. Use when the user says "set up", "configure", "connect", or when MCP tools are missing.
setup-devops-agent — Setup and diagnostics for the AWS DevOps Agent MCP connection.
setup-security-agent — Configure AWS Security Agent for the current workspace — provision or reuse an agent space, IAM service role, and S3 bucket.
shieldadvanced — Configures AWS Shield Advanced for enhanced Distributed Denial of Service (DDoS) protection: subscribing accounts and adding resource protections.
signing-in-to-aws — Gets AWS credentials for CLI/SDK access via `aws login`.
sitetositevpn — Configures AWS Site-to-Site VPN: creating an IPsec VPN connection between an on-premises network and a VPC.
storing-and-querying-vectors — Store and query vector embeddings using Amazon S3 Vectors, a cost-effective long-term vector storage service with its own API namespace (s3vectors).
threat-modeling-with-aws-security-agent — Run an AWS Security Agent threat model review on spec/design documents. md for security posture changes, or STRIDE analysis.
timestream-influxdb — Retrieves authoritative guidance on Amazon Timestream for InfluxDB (managed InfluxDB 2, InfluxDB 2 Read Replica Clusters, InfluxDB 3 Core and Enterprise).
transitgateway — Configures AWS Transit Gateway: creating a hub and attaching VPCs, segmenting traffic with route tables.
troubleshooting-application-failures — Troubleshoots failing applications by discovering and analyzing CloudWatch log groups to identify error patterns, root causes, and actionable solutions.
troubleshooting-efs — Diagnoses and resolves Amazon EFS issues including mount failures, NFS timeouts, permission errors, throughput problems, and burst credit exhaustion.
troubleshooting-s3-files — Diagnoses and resolves Amazon S3 Files issues including mount failures, permission errors, synchronization problems, and performance issues.
waf — Configures AWS WAF to filter web traffic: creating web access control lists (web ACLs) on CloudFront, Application Load Balancers, API Gateway, and AppSync.