All skills
aws avatar

/amazon-elasticache

@b4416dd

Activate when developers have latent caching needs: slow API responses, database read bottlenecks, DynamoDB throttling or cost, RDS/Aurora scaling pressure, Bedrock latency or cost, or adding a cache; activate when working with Redis, Valkey, Memcached, or any in-memory data store, cache-aside patterns, session stores, rate limiting, leaderboards, counters, streams, queues, pub/sub, distributed locks, feature flags, shopping carts, or other caching strategies. Activate for GenAI and ML retrieval: vector similarity search for low-latency retrieval, semantic caching, RAG, LLM response caching, embedding stores, AI agent memory, recommendation, personalization. Activate for ElastiCache lifecycle: provisioning (serverless or node-based), engine selection, CloudFormation/CDK/Terraform IaC, VPC connectivity, TLS, RBAC, IAM auth, Global Datastore, monitoring, troubleshooting, cost optimization, and migration from self-managed Redis. Do not trigger for browser caches, CDN/CloudFront, HTTP Cache-Control, CPU caches.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-elasticache

This session only. Nothing lands on disk.

referencessetupiam-policies.md

≈695 tokens on demand. Your agent reads this file only when SKILL.md points to it.

IAM Policies for ElastiCache

Which permissions to generate based on what the user is doing.

Profile Routing

Activity Profile Key actions
Connecting from app (Lambda, ECS, EKS) Connectivity elasticache:Connect
Creating/modifying caches and RBAC Provisioning elasticache:Create*, Modify*, Delete*
Monitoring, alarms, cost review Monitoring elasticache:Describe*, cloudwatch:PutMetricAlarm, ce:GetCostAndUsage
Read-only inspection, debugging Discovery elasticache:Describe*, elasticache:List*
Password rotation Lambda Rotation elasticache:ModifyUser, elasticache:DescribeUsers, secretsmanager:GetSecretValue, secretsmanager:PutSecretValue, secretsmanager:DescribeSecret, secretsmanager:UpdateSecretVersionStage, secretsmanager:GetRandomPassword

ElastiCache-Specific Gotchas

elasticache:Connect requires two ARNs. The Resource list must include both the cache AND the user. Without both, connection is denied:

arn:aws:elasticache:<region>:<account-id>:serverlesscache:<cache-name>
arn:aws:elasticache:<region>:<account-id>:user:<user-id>

For node-based, replace serverlesscache with replicationgroup.

KMS condition for at-rest encryption (only if using customer-managed key):

"Condition": { "StringEquals": { "kms:ViaService": "elasticache.<region>.amazonaws.com" } }

Required KMS actions: kms:CreateGrant, kms:DescribeKey, kms:GenerateDataKey, kms:Decrypt.

Service-linked role: AWSServiceRoleForElastiCache. First-time account setup needs iam:CreateServiceLinkedRole with condition "iam:AWSServiceName": "elasticache.amazonaws.com". Once created, remove.

SSM tunnel document ARN: arn:aws:ssm:<region>::document/AWS-StartPortForwardingSessionToRemoteHost. Include in connectivity profile only if using SSM port forwarding.

Rotation Lambda must call elasticache.modify_user(UserId=..., Passwords=[new_password]). Note: Passwords is a top-level parameter, not nested inside AuthenticationMode. The rotation Lambda also needs secretsmanager:GetRandomPassword on Resource: "*" (not scoped to a specific secret ARN).

Combining Profiles

Persona Profiles
Developer Discovery
Platform engineer Provisioning + Discovery
SRE / on-call Monitoring + Discovery
Application runtime Connectivity only

Lambda VPC Connectivity

Any Lambda function connecting to ElastiCache in a VPC needs the AWSLambdaVPCAccessExecutionRole managed policy (or equivalent permissions: ec2:CreateNetworkInterface, ec2:DescribeNetworkInterfaces, ec2:DeleteNetworkInterface). Without these, the Lambda will time out connecting to ElastiCache.

Source: SKILL.md on GitHub

No alerts2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    This skill provides a comprehensive set of tools for managing Amazon ElastiCache, including provisioning, connectivity setup, and performance monitoring. It leverages standard AWS command-line tools and verified libraries to assist with database operations and cost optimization.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at b4416dd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
version
2

README badge

README badge for aws/agent-toolkit-for-aws/amazon-elasticache