All skills
aws avatar

/amazon-opensearch-service

@04f39cf

Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration (Solr/ES/self-managed into AOS/AOSS, schema/query translation, sizing, cutover); provisioning (domain + AOSS lifecycle, upgrades, FGAC, monitoring); search (vector / semantic / hybrid / RAG with Bedrock); log-analytics (PPL, OSI, anomaly detection, Dashboards); trace-analytics (OTel spans, service maps, Data Prepper); ai-assistant (natural language data exploration, incident investigation, root cause analysis). Triggers on OpenSearch, AOS, AOSS, Elasticsearch, Solr, vector/k-NN/semantic/hybrid search, RAG, log analytics, PPL, trace analytics, ISM, FAISS, HNSW, Migration Assistant, UltraWarm, OR1, query my data, analyze logs, investigate errors, root cause analysis.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-opensearch-service

This session only. Nothing lands on disk.

assetssolr-index-template-skeleton.md

≈953 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Index Template Skeleton

You MUST fill in the placeholders during Step 3 (Translate Schema). You MUST emit one properties entry per Solr field. You MUST map the Solr uniqueKey to OpenSearch _id and set _id explicitly on every index request. You MUST NOT rely on auto-generated IDs because doing so breaks idempotent re-indexing and dedup-by-fingerprint workflows.

{
  "index_patterns": ["<index-name>-*"],
  "template": {
    "settings": {
      "number_of_shards": 1,
      "number_of_replicas": 1,
      "refresh_interval": "30s",
      "analysis": {
        "analyzer": {
          "<custom_analyzer>": {
            "type": "custom",
            "tokenizer": "<tokenizer>",
            "filter": ["lowercase", "<filter>"]
          }
        },
        "filter": {
          "<filter>": {
            "type": "synonym_graph",
            "synonyms_path": "analyzers/<file>.txt"
          }
        }
      }
    },
    "mappings": {
      "dynamic_templates": [
        {
          "strings_as_keyword": {
            "match_mapping_type": "string",
            "mapping": { "type": "keyword" }
          }
        }
      ],
      "properties": {
        "<solr_uniqueKey>": { "type": "keyword" },
        "<text_field>": {
          "type": "text",
          "analyzer": "<custom_analyzer>",
          "fields": { "raw": { "type": "keyword", "ignore_above": 256 } }
        },
        "<int_field>": { "type": "integer" },
        "<long_field>": { "type": "long" },
        "<date_field>": { "type": "date", "format": "epoch_millis||strict_date_optional_time" },
        "<geo_field>": { "type": "geo_point" }
      }
    }
  }
}

Fill-in checklist

  • index_patterns matches the target index name.
  • number_of_shards / number_of_replicas come from Step 5 (Estimate Sizing).
  • Every Solr field has an explicit properties entry. You MUST NOT rely on dynamic mapping for production fields because dynamic mapping causes type conflicts.
  • Solr uniqueKey is mapped to a keyword field AND set as _id on every index request.
  • Date "format" matches the on-the-wire encoding — strict_date_optional_time for ISO-8601 strings (default), epoch_millis for long integers, or both (strict_date_optional_time||epoch_millis) per solr-transformation-rules.
  • Solr geo strings ("lat,lon") are converted to geo_point objects.
  • Solr internal fields (_version_, _root_, _nest_path_) are stripped before indexing.
  • Field names containing dots (e.g. product.id) are renamed to use underscores.
  • Custom analyzers from schema.xml are replicated as analysis.analyzer blocks; filter order preserved.
  • Domain-level security settings (configured separately from the index template, but verified before deployment): encryption at rest with a customer-managed KMS key (EncryptionAtRestOptions); node-to-node encryption (NodeToNodeEncryptionOptions); HTTPS enforced (EnforceHTTPS: true, TLSSecurityPolicy: Policy-Min-TLS-1-2-2019-07); fine-grained access control (FGAC) with IAM/SAML/OIDC authentication; access policy scoped by principal and source ARN/account. You MUST NOT use 0.0.0.0/0 because it exposes the cluster to the entire internet.
  • If using a custom domain endpoint, an ACM-managed certificate ARN is configured (CustomEndpoint.CertificateArn) for automated rotation. You MUST NOT use a self-managed certificate because expiry will silently break TLS in production.

What goes where in the final report

You MUST embed the filled-in template in section 2. Schema Mapping of report-template. You MUST cite the source schema.xml line range (or Schema API field name) for each non-trivial mapping decision in the table.

Source: SKILL.md on GitHub

No alerts28d3 checks · Risk SAFE
  • Gen Agent Trust Hub28d

    This skill is a highly structured and security-conscious guide for managing Amazon OpenSearch Service and Serverless. It provides comprehensive instructions for migrations, provisioning, and analytics while strictly adhering to AWS security best practices, such as using SigV4 signing, IAM least-privilege, and AWS Secrets Manager for credential handling.

  • Socket28d

    No alerts

  • Snyk28d

    Risk: LOW · No issues

Signed by skilld at 04f39cf. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "2"
}

README badge

README badge for aws/agent-toolkit-for-aws/amazon-opensearch-service