All skills
aws avatar

/amazon-opensearch-service

@04f39cf

Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration (Solr/ES/self-managed into AOS/AOSS, schema/query translation, sizing, cutover); provisioning (domain + AOSS lifecycle, upgrades, FGAC, monitoring); search (vector / semantic / hybrid / RAG with Bedrock); log-analytics (PPL, OSI, anomaly detection, Dashboards); trace-analytics (OTel spans, service maps, Data Prepper); ai-assistant (natural language data exploration, incident investigation, root cause analysis). Triggers on OpenSearch, AOS, AOSS, Elasticsearch, Solr, vector/k-NN/semantic/hybrid search, RAG, log analytics, PPL, trace analytics, ISM, FAISS, HNSW, Migration Assistant, UltraWarm, OR1, query my data, analyze logs, investigate errors, root cause analysis.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-opensearch-service

This session only. Nothing lands on disk.

referencesprovisioning-domain-provision.md

≈876 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Amazon OpenSearch Service Domain — Provision

Prerequisites

  1. Confirm AWS credentials: aws sts get-caller-identity
  2. Verify call_aws or AWS CLI is available

Step 1: Get Latest OpenSearch Version

aws opensearch list-versions

Pick the latest OpenSearch_X.Y version. Ignore Elasticsearch_* versions.

For agentic search, confirm version is 3.3 or higher.

Step 2: Create Domain

The example below provisions a single-node t3.medium.search for development/test only.

aws opensearch create-domain \
  --domain-name <domain-name> \
  --engine-version <latest-version> \
  --cluster-config InstanceType=t3.medium.search,InstanceCount=1 \
  --ebs-options EBSEnabled=true,VolumeType=gp3,VolumeSize=100 \
  --node-to-node-encryption-options Enabled=true \
  --encryption-at-rest-options Enabled=true \
  --domain-endpoint-options EnforceHTTPS=true

For production: use a current-generation Graviton instance — r7g.large.search (or larger per references/sizing.md) — with 3+ data nodes and 3 dedicated cluster managers (the AWS API still uses "DedicatedMaster" in CLI/SDK; prose: "cluster managers"). r6g is previous-generation and only used with explicit compatibility justification.

Step 3: Enable Fine-Grained Access Control

Recommended (production): IAM-based authentication with MasterUserARN:

aws opensearch update-domain-config \
  --domain-name <domain-name> \
  --advanced-security-options "Enabled=true,InternalUserDatabaseEnabled=false,MasterUserOptions={MasterUserARN=arn:aws:iam::<account>:role/AdminRole}"

Development Only: Internal User Database

WARNING: NEVER use internal users in production. Production deployments MUST use IAM-based authentication (shown above). Internal user database is for local development/testing only.

PASSWORD=$(aws secretsmanager get-secret-value --secret-id opensearch-admin-password --query SecretString --output text)

aws opensearch update-domain-config \
  --domain-name <domain-name> \
  --advanced-security-options "Enabled=true,InternalUserDatabaseEnabled=true,MasterUserOptions={MasterUserName=admin,MasterUserPassword=$PASSWORD}"

Security note: If using internal users, store the password in AWS Secrets Manager with automatic rotation enabled.

Step 4: Configure Network Access

  • Development: Public access with IP-based policies + fine-grained access control

Warning: Never use 0.0.0.0/0. Always restrict to specific source CIDR ranges.

AWS WAF for any public domain (defense-in-depth, beyond throwaway dev): associate an AWS WAF web ACL with the domain to block common web exploits, rate-limit by IP, and apply AWS-managed rule groups (AWSManagedRulesCommonRuleSet, AWSManagedRulesKnownBadInputsRuleSet, AWSManagedRulesAmazonIpReputationList). Without WAF, public domains are exposed to the open internet with no L7 protection beyond the IP allowlist.

aws wafv2 associate-web-acl \
  --web-acl-arn arn:aws:wafv2:<region>:<account>:regional/webacl/<name>/<id> \
  --resource-arn arn:aws:es:<region>:<account>:domain/<domain-name>
  • Production: Deploy within VPC, configure security groups

Step 5: Wait for Domain Active

aws opensearch describe-domain --domain-name <domain-name>

Wait for Processing: false and DomainStatus.Endpoint available (10-15 min).

Next Step

Proceed to provisioning-domain-deploy-search.md.

Source: SKILL.md on GitHub

No alerts28d3 checks · Risk SAFE
  • Gen Agent Trust Hub28d

    This skill is a highly structured and security-conscious guide for managing Amazon OpenSearch Service and Serverless. It provides comprehensive instructions for migrations, provisioning, and analytics while strictly adhering to AWS security best practices, such as using SigV4 signing, IAM least-privilege, and AWS Secrets Manager for credential handling.

  • Socket28d

    No alerts

  • Snyk28d

    Risk: LOW · No issues

Signed by skilld at 04f39cf. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "2"
}

README badge

README badge for aws/agent-toolkit-for-aws/amazon-opensearch-service