All skills
aws avatar

/amazon-elasticache

@b4416dd

Activate when developers have latent caching needs: slow API responses, database read bottlenecks, DynamoDB throttling or cost, RDS/Aurora scaling pressure, Bedrock latency or cost, or adding a cache; activate when working with Redis, Valkey, Memcached, or any in-memory data store, cache-aside patterns, session stores, rate limiting, leaderboards, counters, streams, queues, pub/sub, distributed locks, feature flags, shopping carts, or other caching strategies. Activate for GenAI and ML retrieval: vector similarity search for low-latency retrieval, semantic caching, RAG, LLM response caching, embedding stores, AI agent memory, recommendation, personalization. Activate for ElastiCache lifecycle: provisioning (serverless or node-based), engine selection, CloudFormation/CDK/Terraform IaC, VPC connectivity, TLS, RBAC, IAM auth, Global Datastore, monitoring, troubleshooting, cost optimization, and migration from self-managed Redis. Do not trigger for browser caches, CDN/CloudFront, HTTP Cache-Control, CPU caches.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-elasticache

This session only. Nothing lands on disk.

referencesshared-securityvpc-patterns.md

≈723 tokens on demand. Your agent reads this file only when SKILL.md points to it.

VPC Patterns for ElastiCache

ElastiCache-specific networking rules. Generic VPC knowledge is omitted (the model already knows how subnets and security groups work).

Port Requirements

Deployment Type Port Purpose
Serverless 6379 Primary endpoint (read/write)
Serverless 6380 Reader endpoint (same DNS name as primary, port 6380 for read-optimized access; node-based reader endpoints use a separate DNS name on port 6379)
Node-based 6379 Valkey/Redis OSS data port (both primary and reader endpoints)
Node-based (cluster mode) 16379 Cluster bus port (node-to-node, auto-managed)
Node-based (Memcached) 11211 Memcached data port
Serverless (Memcached) 11211 Memcached serverless endpoint (TLS mandatory)

TLS note: TLS is mandatory for all serverless caches (Valkey/Redis OSS and Memcached). There is no option to disable in-transit encryption on serverless deployments.

Security Group Anti-Patterns

  • Do not open 0.0.0.0/0 on any port. ElastiCache is VPC-internal only.
  • Do not use IP-based rules when security-group-based rules are possible. SG references survive IP changes.
  • Do not allow port ranges (e.g., 6379-6400). Use specific ports only.
  • Do not attach the cache to a default security group that allows all inbound from itself.
  • For serverless (Valkey/Redis OSS): open ports 6379 (primary) and 6380 (reader) from the app security group. The primary and reader endpoints use the same DNS name on different ports (6379 for primary, 6380 for read-optimized).
  • For serverless (Memcached): open port 11211 from the app security group.

Subnet Group Requirements

  • Node-based clusters require a cache subnet group. ElastiCache uses the subnet group to select subnets and assign IP addresses to cache nodes.
  • Serverless caches do not use a subnet group resource. Instead, pass a list of subnet IDs directly during creation.

Subnet IP Address Capacity

  • CIDR blocks for each subnet must be large enough to provide spare IP addresses for ElastiCache to use during maintenance activities.
  • Common pitfalls: subnets in the subnet group have too small a CIDR range, or subnets are shared and heavily used by other clusters.
  • For large cluster-mode-enabled deployments (up to 500 nodes), ensure sufficient available IP addresses to accommodate scaling.

PrivateLink and Cross-VPC Access

  • PrivateLink (VPC Endpoints) covers ElastiCache control-plane APIs only (e.g., CreateCacheCluster, DescribeReplicationGroups). It does not provide data-plane connectivity to cache endpoints.
  • Cross-VPC data access requires VPC Peering, Transit Gateway (TGW), AWS Direct Connect, or site-to-site VPN. Use security group references (preferred, when peering supports it) or CIDR-based rules to allow traffic between the application VPC and the cache VPC.

Source: SKILL.md on GitHub

No alerts2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    This skill provides a comprehensive set of tools for managing Amazon ElastiCache, including provisioning, connectivity setup, and performance monitoring. It leverages standard AWS command-line tools and verified libraries to assist with database operations and cost optimization.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at b4416dd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
version
2

README badge

README badge for aws/agent-toolkit-for-aws/amazon-elasticache