All skills
aws avatar

/amazon-opensearch-service

@04f39cf

Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration (Solr/ES/self-managed into AOS/AOSS, schema/query translation, sizing, cutover); provisioning (domain + AOSS lifecycle, upgrades, FGAC, monitoring); search (vector / semantic / hybrid / RAG with Bedrock); log-analytics (PPL, OSI, anomaly detection, Dashboards); trace-analytics (OTel spans, service maps, Data Prepper); ai-assistant (natural language data exploration, incident investigation, root cause analysis). Triggers on OpenSearch, AOS, AOSS, Elasticsearch, Solr, vector/k-NN/semantic/hybrid search, RAG, log analytics, PPL, trace analytics, ISM, FAISS, HNSW, Migration Assistant, UltraWarm, OR1, query my data, analyze logs, investigate errors, root cause analysis.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-opensearch-service

This session only. Nothing lands on disk.

referencesprovisioning-serverless-deprovision.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Amazon OpenSearch Serverless — Deprovision (Teardown)

Delete serverless resources in strict dependency order. Reversing the order fails, because a collection group cannot be deleted while it still has collections, and a security policy cannot be deleted while a collection it covers still exists.

The AWS MCP server is recommended for executing these teardown commands but is not required — all steps use standard AWS CLI syntax.

Order (MUST follow)

  1. Delete collection(s)
  2. Wait until each collection is fully gone
  3. Delete the collection group (NextGen only)
  4. Delete the security/data access policies

Destructive-action rule: before deleting anything below, list every resource that will be removed and get explicit user confirmation, because collection deletion (Step 1) is irreversible and destroys all indexed data.

Step 1: Delete collection(s)

aws opensearchserverless delete-collection --id <collection-id>

A collection MUST be ACTIVE (or FAILED) before it can be deleted. If delete returns ConflictException about status, the collection is still being created — wait and retry, because AOSS rejects deletes on collections mid-creation.

Step 2: Confirm deletion completed

aws opensearchserverless batch-get-collection --ids <id1> <id2>

Deletion is complete when EITHER the id appears in collectionErrorDetails with "errorCode":"NOT_FOUND" OR collectionDetails is empty. Do NOT poll for a DELETED status, because AOSS removes the collection entirely and returns NOT_FOUND rather than a terminal status.

Step 3: Delete the collection group (NextGen)

aws opensearchserverless delete-collection-group --id <group-id>

If this returns ValidationException ("has collections associated"), a collection in the group is still active or still deleting — delete/await remaining collections first, because a non-empty group cannot be removed.

Step 4: Delete policies

aws opensearchserverless delete-security-policy --type network    --name <name>-network
aws opensearchserverless delete-security-policy --type encryption --name <name>-encryption
aws opensearchserverless delete-access-policy   --type data       --name <name>-data

Security Considerations

  • Verify a backup exists first, and that it is encrypted at rest. Collection deletion is irrecoverable — confirm a snapshot or exported copy exists before proceeding if the data may still be needed, because there is no undo. Ensure the backup itself is encrypted at rest (e.g., S3 server-side encryption with a customer-managed KMS key for a manual snapshot or export), because an unencrypted copy of sensitive data is a standing exposure risk even after the collection is deleted.
  • Audit who initiated the teardown. Confirm AWS CloudTrail is enabled so the DeleteCollection/DeleteCollectionGroup/Delete*Policy calls are recorded with the caller identity and timestamp.
  • Alert in real time on teardown calls. Beyond passive CloudTrail logging, configure an EventBridge rule (or a CloudTrail → CloudWatch metric filter) on DeleteCollection/DeleteCollectionGroup from unexpected principals that notifies via SNS, because an irreversible delete warrants immediate detection rather than after-the-fact log review. Encrypt the SNS topic with a customer-managed KMS key and restrict sns:Subscribe to authorized principals via a topic policy, because teardown alerts carry resource identifiers that should not reach unintended recipients.
  • Use least-privilege, collection-scoped permissions. The caller SHOULD hold only the delete actions needed on the specific collection/group ARNs rather than aoss:* on all resources, because a broad teardown identity can remove unrelated production collections.
  • Guard against accidental production teardown. Assume any collection is production unless its name/tags clearly indicate otherwise, and require explicit confirmation before deleting, because an accidental delete causes an outage and permanent data loss.

Source: SKILL.md on GitHub

No alerts28d3 checks · Risk SAFE
  • Gen Agent Trust Hub28d

    This skill is a highly structured and security-conscious guide for managing Amazon OpenSearch Service and Serverless. It provides comprehensive instructions for migrations, provisioning, and analytics while strictly adhering to AWS security best practices, such as using SigV4 signing, IAM least-privilege, and AWS Secrets Manager for credential handling.

  • Socket28d

    No alerts

  • Snyk28d

    Risk: LOW · No issues

Signed by skilld at 04f39cf. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "2"
}

README badge

README badge for aws/agent-toolkit-for-aws/amazon-opensearch-service