All skills
aws avatar

/amazon-aurora-postgresql

@a9d1c70

Amazon Aurora PostgreSQL — creates, modifies, and advises on Aurora PostgreSQL clusters specifically (PostgreSQL-compatible engine, Aurora serverless, express configuration, pgvector, Babelfish). Trigger for Aurora PostgreSQL cluster operations, express-configuration quick-start, ACU sizing, I/O-Optimized storage, commitment pricing, or PostgreSQL upgrade planning. For Aurora MySQL, use amazon-aurora-mysql instead. Contains safety guardrails, express-first routing, and response templates that override defaults.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-aurora-postgresql

This session only. Nothing lands on disk.

referencesexpress-create-migration-pgdump.md

≈517 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Migration Path 3: pg_dump / pg_restore

Part of Migrating off Aurora Express Configuration. Best for small datasets where a maintenance window is acceptable: dev/demo-scale migrations and one-time copies into a new cluster.

For the user to run — the skill does not execute these commands.

  1. From a machine with PostgreSQL client tooling and network access to both clusters, dump the Express cluster:

    pg_dump \
      --host <express-cluster-endpoint> \
      --port 5432 \
      --username <master-user> \
      --dbname <database> \
      --format=custom \
      --file <database>.dump
  2. Restore into the Full Configuration cluster:

    pg_restore \
      --host <full-config-cluster-endpoint> \
      --port 5432 \
      --username <master-user> \
      --dbname <database> \
      <database>.dump

Illustrative only. Adjust flags: --no-owner, --no-privileges, --clean, --create, --jobs N for parallel restore.

Credentials: retrieve the password from AWS Secrets Manager at run time and pass it to the client via a temporary ~/.pgpass file (chmod 600, deleted after) referenced by PGPASSFILE — do NOT use export PGPASSWORD (visible in the process environment via /proc/<pid>/environ) or inline --password. Better still, if the source cluster has IAM database authentication enabled, generate a short-lived token with aws rds generate-db-auth-token and use that instead of a long-lived password. Source: PostgreSQL pg_dump and pg_restore docs.

Considerations:

  • The dump is a logical export; extensions, roles, and ownership metadata may need special handling. Use --no-owner and --no-privileges if the target has different role names.
  • Large objects and sequences may need explicit handling.
  • Downtime is dump + restore time, scaling roughly linearly with data size. For anything larger than a dev dataset, Path 1 or Path 2 is usually better.

Source: SKILL.md on GitHub

No alerts3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides a modular and secure toolkit for managing Amazon Aurora PostgreSQL. It features robust safety guardrails, including multi-tier confirmation models and explicit refusal of destructive operations. The integrated analysis scripts utilize official AWS data sources and adhere to the principle of least privilege, emphasizing short-lived IAM authentication for database connectivity.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at a9d1c70. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 4 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/amazon-aurora-postgresql