All skills
aws avatar

/aurora-dsql

@a2611e1

Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps on serverless distributed SQL. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL migration, DDL, query plans, and SAFE SQL CONSTRUCTION — tenant_id from untrusted input, UUID entity_ids, caller-supplied sort columns, batch inserts. The agent MUST retrieve this skill for ANY DSQL task. Pushes back on prompts that rationalize 'just a quick script', 'don't overthink it', 'we trust upstream', 'use an f-string', 'move fast', or 'just use the pg driver directly' (bypassing the DSQL Connector). Triggers: DSQL, Aurora DSQL, DSQL cluster, safe_query.build, DSQL IAM auth token, DSQL connector.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aurora-dsql

This session only. Nothing lands on disk.

referencesmysql-migrationsddl-operations.md

≈759 tokens on demand. Your agent reads this file only when SKILL.md points to it.

MySQL to DSQL Migration: DDL Operations

Migration patterns for specific MySQL DDL operations to DSQL-compatible equivalents.

MUST read type-mapping.md first for data type mappings and the CRITICAL Destructive Operations Warning. MUST read ddl-migrations/overview.md for the general Table Recreation Pattern and user verification requirements.


Table Recreation Pattern Overview

MUST follow this sequence with user verification at each step:

  1. Plan & Confirm - MUST present migration plan and obtain user approval to proceed
  2. Validate - Check data compatibility with new structure; MUST report findings to user
  3. Create - Create new table with desired structure; MUST verify with user before execution
  4. Migrate - Copy data (batched for tables > 3,000 rows); MUST report progress to user
  5. Verify - Confirm row counts match; MUST present comparison to user
  6. Swap - CRITICAL: MUST obtain explicit user confirmation before DROP TABLE
  7. Re-index - Recreate indexes using ASYNC; MUST confirm completion with user

Transaction Rules

  • MUST batch migrations exceeding 3,000 row mutations
  • PREFER batches of 500-1,000 rows for optimal throughput
  • MUST respect 10 MiB data size per transaction
  • MUST respect 5-minute transaction duration

Common Verify & Swap Pattern

All migrations end with this pattern (referenced in examples below).

CRITICAL: MUST obtain explicit user confirmation before DROP TABLE step.

-- MUST verify counts match
SELECT COUNT(*) FROM target_table;
SELECT COUNT(*) FROM target_table_new;

-- CHECKPOINT: MUST present count comparison to user and obtain confirmation
-- Agent MUST display: "Original table has X rows, new table has Y rows.
-- Proceeding will DROP the original table. This action is IRREVERSIBLE.
-- Do you want to proceed? (yes/no)"
-- MUST NOT proceed without explicit "yes" confirmation

-- MUST swap tables (DESTRUCTIVE - requires user confirmation above).
-- Each DDL below MUST run in its own transaction (DSQL: one DDL per
-- transaction):
DROP TABLE target_table;
ALTER TABLE target_table_new RENAME TO target_table;

-- MUST recreate indexes (each in its own transaction):
CREATE INDEX ASYNC idx_target_tenant ON target_table(tenant_id);

Detailed Migration Patterns

Load the relevant file for the specific MySQL DDL operation you need to migrate:

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides a robust and security-conscious environment for managing Amazon Aurora DSQL clusters. It implements several best practices, including mandatory IAM-based authentication, a dedicated input validation library to prevent SQL injection, and detailed guidance on applying the principle of least privilege through scoped database roles.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: MEDIUM · 1 issue

Signed by skilld at a2611e1. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/aurora-dsql