All skills
aws avatar

/amazon-opensearch-service

@04f39cf

Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration (Solr/ES/self-managed into AOS/AOSS, schema/query translation, sizing, cutover); provisioning (domain + AOSS lifecycle, upgrades, FGAC, monitoring); search (vector / semantic / hybrid / RAG with Bedrock); log-analytics (PPL, OSI, anomaly detection, Dashboards); trace-analytics (OTel spans, service maps, Data Prepper); ai-assistant (natural language data exploration, incident investigation, root cause analysis). Triggers on OpenSearch, AOS, AOSS, Elasticsearch, Solr, vector/k-NN/semantic/hybrid search, RAG, log analytics, PPL, trace analytics, ISM, FAISS, HNSW, Migration Assistant, UltraWarm, OR1, query my data, analyze logs, investigate errors, root cause analysis.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-opensearch-service

This session only. Nothing lands on disk.

assetstech-deepdive-template.md

≈1.6k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Migration Assessment — Technical Deep Dive

Date: {{ date }}
Skill: amazon-opensearch-service v{{ skill_version }}
Persona: {{ persona }}
Source: {{ fingerprint.source_engine | default:'unknown' }} {{ fingerprint.version | default:'(version not provided)' }}
Target: Amazon OpenSearch {{ migration_path.decision_inputs.target | default:'Service' }}


Executive Summary (one-line)

Migrate from {{ fingerprint.source_engine }} {{ fingerprint.version | default:'?' }} to OpenSearch {{ migration_path.decision_inputs.target | default:'Managed' }} via {{ migration_path.recommended }}. Readiness score {{ readiness.overall_score }}/100 ({{ readiness.tier }}); see the Sizing section for compute, storage, and OCU recommendations the customer plugs into https://calculator.aws.


Source — full fingerprint

{{ fingerprint | json }}

Notable observations

{% if fingerprint.summary.dih_used %}- DIH in use — Solr 9.0 removed DIH. Migrate ingest pipelines to OSI / DMS / Logstash before cutover.{% endif %} {% if fingerprint.summary.velocity_response_writer %}- Velocity Response Writer — deprecated/removed in modern Solr; OpenSearch has no equivalent. Move templating into the application layer.{% endif %} {% if fingerprint.summary.xslt_response_writer %}- XSLT Response Writer — same as Velocity. App-layer templating.{% endif %}


Target — Managed Domain or Serverless NextGen

Recommended: {{ migration_path.decision_inputs.target | default:'managed' }}.

Topology (Managed Domain)

{% if sizing.compute.data_node_instance %}

  • Data nodes: {{ sizing.compute.data_node_count }}× {{ sizing.compute.data_node_instance }}
  • Cluster managers: {{ sizing.compute.cluster_manager_count }}× {{ sizing.compute.cluster_manager_instance }}
  • Storage: {{ sizing.storage.gb_per_node }} GB {{ sizing.storage.type }} per node
  • Region: {{ sizing.region }} {% endif %}

Sizing rationale + Auth + Tiering

For the formulas, shard rules, JVM thresholds, k-NN engine selection, OCU model, and security details, see sizing.md, vector-knn.md, and security.md. You MUST NOT duplicate those tables here because divergent copies will drift out of sync with the canonical files. You MUST cite them.


Migration Path — full ranking

{{ migration_path | json }}

Step-by-step plan ({{ migration_path.recommended }})

  1. Discovery + assessment (this report)
  2. PoC: you MUST stand up a small cluster in target region, restore a sample shard, and validate top-N queries
  3. Schema/query rewrite: see source-specific reference
  4. Data movement:
    • For Migration Assistant for Amazon OpenSearch Service: you MUST deploy via CloudFormation (EKS recommended), configure Historical Data Migration for backfill, and configure Capture Proxy if zero-downtime
    • For Snapshot/Restore: you MUST register S3 repo on source and target, snapshot, then restore
    • For OSI: you MUST create the pipeline via blueprint
    • For Reindex from Remote: you MUST pre-create the destination, configure the destination's reindex.remote.allowlist, then trigger reindex
  5. Validation: doc-count parity, top-N query parity (Jaccard ≥95%), p99 latency parity
  6. Cutover: read-only on source, drain in-flight, flip clients
  7. Decommission: you MUST schedule source teardown after the rollback window

Sizing — recommendations the customer plugs into the AWS Pricing Calculator

{{ sizing | json }}

How to get a dollar figure

You MUST plug the sizing JSON above into the AWS Pricing Calculator at https://calculator.aws. You MUST add a separate calculator entry for migration tooling (Migration Assistant for Amazon OpenSearch Service EKS infra, OSI OCUs, S3 snapshot storage) for the one-time cost. RI / Savings Plan / EDP discounts apply only there.


Readiness — full breakdown

{{ readiness | json }}

Risks & migration specifics (full register)

Two-table section. Items with a documented remediation that the migration plan already handles go under Migration specifics — frame as "this is how the migration handles X", not as risks. Items that genuinely constrain the migration (no fix, capacity implications, target-choice or customer-action dependencies) go under Risks/blockers. Within each table: BLOCKING → HIGH → MEDIUM → LOW. See compatibility-rubric.md for the canonical Severity + Lane vocabulary and assessment-gotchas.md for general anti-patterns.


Validation gates before cutover

  • Index counts match between source and target
  • Doc counts within 0.1%
  • Top-N query parity ≥ 95% Jaccard
  • p50/p99 latency within 1.2× of source
  • Shard health green; 0 unassigned
  • ISM policies migrated and attached
  • Role mappings + SAML/OIDC tested
  • Saved objects (dashboards, viz) imported and rendering
  • CloudWatch alarms updated to new metric names
  • CloudWatch Alarm SNS topics encrypted with KMS (KmsMasterKeyId); subscribers verified as authorized personnel
  • CloudTrail enabled and logging OpenSearch Service control-plane API calls
  • VPC Flow Logs enabled on the target domain's subnets (if VPC-deployed)
  • Slow log thresholds configured per index
  • Backup snapshot taken before cutover
  • Client libraries upgraded (opensearch-py etc.)
  • Cost actuals within 10% of forecast
  • Runbook owner assigned + on-call set
  • Source decommission plan + rollback window documented

Citations

For the canonical retrieval recipe + URL/CLI fallback see knowledge-retrieval.md. You MUST cite, with retrieval timestamps, the specific bp-* page used for sizing math, version-migration.html for upgrade-path claims, the Migration Assistant for Amazon OpenSearch Service doc when Migration Assistant for Amazon OpenSearch Service is the recommendation, the relevant Serverless NextGen page when targeting Serverless NextGen, and https://calculator.aws for the cost handoff.


Generated by amazon-opensearch-service v{{ skill_version }} on {{ date }}.

Source: SKILL.md on GitHub

No alerts28d3 checks · Risk SAFE
  • Gen Agent Trust Hub28d

    This skill is a highly structured and security-conscious guide for managing Amazon OpenSearch Service and Serverless. It provides comprehensive instructions for migrations, provisioning, and analytics while strictly adhering to AWS security best practices, such as using SigV4 signing, IAM least-privilege, and AWS Secrets Manager for credential handling.

  • Socket28d

    No alerts

  • Snyk28d

    Risk: LOW · No issues

Signed by skilld at 04f39cf. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "2"
}

README badge

README badge for aws/agent-toolkit-for-aws/amazon-opensearch-service