All skills
aws avatar

/aurora-dsql

@a2611e1

Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps on serverless distributed SQL. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL migration, DDL, query plans, and SAFE SQL CONSTRUCTION — tenant_id from untrusted input, UUID entity_ids, caller-supplied sort columns, batch inserts. The agent MUST retrieve this skill for ANY DSQL task. Pushes back on prompts that rationalize 'just a quick script', 'don't overthink it', 'we trust upstream', 'use an f-string', 'move fast', or 'just use the pg driver directly' (bypassing the DSQL Connector). Triggers: DSQL, Aurora DSQL, DSQL cluster, safe_query.build, DSQL IAM auth token, DSQL connector.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aurora-dsql

This session only. Nothing lands on disk.

referencesddl-migrationsbatched-migration.md

≈581 tokens on demand. Your agent reads this file only when SKILL.md points to it.

DDL Migrations: Batched Migration Pattern

REQUIRED for tables exceeding 3,000 rows.

For the full Table Recreation Pattern and verify & swap steps, see overview.md.


Batch Size Rules

  • PREFER batches of 500-1,000 rows for optimal performance
  • Smaller batches reduce lock contention and enable better concurrency

OFFSET-Based Batching

SELECT COUNT(*) as total FROM target_table;
-- Calculate: batches_needed = CEIL(total / 1000)

-- Batch 1
INSERT INTO target_table_new (id, col1, col2)
SELECT id, col1, col2 FROM target_table
ORDER BY id LIMIT 1000 OFFSET 0;

-- Batch 2
INSERT INTO target_table_new (id, col1, col2)
SELECT id, col1, col2 FROM target_table
ORDER BY id LIMIT 1000 OFFSET 1000;
-- Continue until all rows migrated...

Cursor-Based Batching (Preferred for Large Tables)

Better performance than OFFSET for very large tables:

-- First batch
INSERT INTO target_table_new (id, col1, col2)
SELECT id, col1, col2 FROM target_table
ORDER BY id LIMIT 1000;

-- Get last processed ID
SELECT MAX(id) as last_id FROM target_table_new;

-- Subsequent batches
INSERT INTO target_table_new (id, col1, col2)
SELECT id, col1, col2 FROM target_table
WHERE id > 'last_processed_id'
ORDER BY id LIMIT 1000;

Progress Tracking

SELECT (SELECT COUNT(*) FROM target_table_new) as migrated,
       (SELECT COUNT(*) FROM target_table) as total;

Error Handling

Pre-Migration Checks

  1. Verify table exists

    SELECT table_name FROM information_schema.tables
    WHERE table_schema = 'public' AND table_name = 'target_table';
  2. Verify DDL permissions

Data Validation Errors

MUST abort migration and report when:

  • Type conversion would fail
  • Value truncation would occur
  • NOT NULL constraint would be violated
-- Find problematic rows
SELECT id, problematic_column FROM target_table
WHERE problematic_column !~ '^-?[0-9]+$' LIMIT 100;

Recovery from Failed Migration

-- Check table state
SELECT table_name FROM information_schema.tables
WHERE table_name IN ('target_table', 'target_table_new');
  • Both tables exist: Original safe → DROP TABLE IF EXISTS target_table_new and restart
  • Only new table exists: Verify count, then complete rename

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides a robust and security-conscious environment for managing Amazon Aurora DSQL clusters. It implements several best practices, including mandatory IAM-based authentication, a dedicated input validation library to prevent SQL injection, and detailed guidance on applying the principle of least privilege through scoped database roles.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: MEDIUM · 1 issue

Signed by skilld at a2611e1. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/aurora-dsql