All skills
aws avatar

/amazon-opensearch-service

@04f39cf

Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration (Solr/ES/self-managed into AOS/AOSS, schema/query translation, sizing, cutover); provisioning (domain + AOSS lifecycle, upgrades, FGAC, monitoring); search (vector / semantic / hybrid / RAG with Bedrock); log-analytics (PPL, OSI, anomaly detection, Dashboards); trace-analytics (OTel spans, service maps, Data Prepper); ai-assistant (natural language data exploration, incident investigation, root cause analysis). Triggers on OpenSearch, AOS, AOSS, Elasticsearch, Solr, vector/k-NN/semantic/hybrid search, RAG, log analytics, PPL, trace analytics, ISM, FAISS, HNSW, Migration Assistant, UltraWarm, OR1, query my data, analyze logs, investigate errors, root cause analysis.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-opensearch-service

This session only. Nothing lands on disk.

referencessearch-bedrock-connectors.md

≈970 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Bedrock Connector Setup for AOS/AOSS

Creating a Bedrock Connector

Step 1: Create IAM Role for Connector

# Service principal: opensearchservice.amazonaws.com (AOS managed domains)
# For AOSS, use ml.opensearchservice.amazonaws.com instead (see AOSS-Specific Notes below)
# Both aws:SourceAccount and aws:SourceArn conditions are required to prevent
# confused-deputy: ArnLike narrows trust to a specific domain (or collection
# for AOSS — replace the resource pattern accordingly) so other domains in
# the same account can't assume this role.
aws iam create-role --role-name OpenSearchBedrockRole \
  --assume-role-policy-document '{
    "Version": "2012-10-17",
    "Statement": [{
      "Effect": "Allow",
      "Principal": {"Service": "opensearchservice.amazonaws.com"},
      "Action": "sts:AssumeRole",
      "Condition": {
        "StringEquals": {"aws:SourceAccount": "<account>"},
        "ArnLike":      {"aws:SourceArn":     "arn:aws:es:<region>:<account>:domain/<domain-name>"}
      }
    }]
  }'

Attach Bedrock access (least-privilege inline policy):

aws iam put-role-policy --role-name OpenSearchBedrockRole \
  --policy-name BedrockInvokeModel \
  --policy-document '{
    "Version": "2012-10-17",
    "Statement": [{"Effect": "Allow", "Action": "bedrock:InvokeModel", "Resource": "arn:aws:bedrock:<region>::foundation-model/amazon.titan-embed-text-v2:0"}]
  }'

Step 2: Create Connector

For Titan Embeddings V2 (1024 dimensions):

Use awscurl to call the OpenSearch API directly:

POST /_plugins/_ml/connectors/_create
{
  "name": "Amazon Bedrock Titan Embedding V2",
  "description": "Connector for Titan Text Embeddings V2",
  "version": 1,
  "protocol": "aws_sigv4",
  "parameters": {
    "region": "<region>",
    "service_name": "bedrock",
    "model": "amazon.titan-embed-text-v2:0"
  },
  "credential": {
    "roleArn": "arn:aws:iam::<account>:role/OpenSearchBedrockRole"
  },
  "actions": [{
    "action_type": "predict",
    "method": "POST",
    "url": "https://bedrock-runtime.<region>.amazonaws.com/model/amazon.titan-embed-text-v2:0/invoke",
    "headers": {"content-type": "application/json"},
    "request_body": "{\"inputText\": \"${parameters.inputText}\"}",
    "pre_process_function": "connector.pre_process.bedrock.embedding",
    "post_process_function": "connector.post_process.bedrock.embedding"
  }]
}

For Cohere Embed English V3 (1024 dimensions):

Replace model references with cohere.embed-english-v3 and update URL and request body accordingly.

Step 3: Register and Deploy Model

POST /_plugins/_ml/models/_register
{
  "name": "Bedrock Titan Embedding",
  "function_name": "remote",
  "connector_id": "<connector_id>"
}

Then deploy:

POST /_plugins/_ml/models/<model_id>/_deploy

Monitoring: Enable CloudTrail to audit bedrock:InvokeModel calls. Set up CloudWatch alarms on invocation latency and errors. Encryption: Ensure the OpenSearch domain/collection has encryption at rest enabled (KMS) before deploying the model and ingesting embeddings.

Supported Models

Model Dimensions Use Case
amazon.titan-embed-text-v2:0 256/512/1024 General-purpose English embeddings
cohere.embed-english-v3 1024 High-quality English embeddings
cohere.embed-multilingual-v3 1024 Multilingual embeddings

AOSS-Specific Notes

  • Trust policy: On AOSS, the connector role must use ml.opensearchservice.amazonaws.com as service principal
  • On AOSS, connector creation uses the same API but authentication flows through the collection endpoint
  • Data access policies must grant the connector role aoss:ReadDocument, aoss:WriteDocument, and aoss:CreateIndex permissions on the collection
  • Model deployment status can be checked via GET /_plugins/_ml/models/<model_id>

Source: SKILL.md on GitHub

No alerts28d3 checks · Risk SAFE
  • Gen Agent Trust Hub28d

    This skill is a highly structured and security-conscious guide for managing Amazon OpenSearch Service and Serverless. It provides comprehensive instructions for migrations, provisioning, and analytics while strictly adhering to AWS security best practices, such as using SigV4 signing, IAM least-privilege, and AWS Secrets Manager for credential handling.

  • Socket28d

    No alerts

  • Snyk28d

    Risk: LOW · No issues

Signed by skilld at 04f39cf. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "2"
}

README badge

README badge for aws/agent-toolkit-for-aws/amazon-opensearch-service