All skills
aws avatar

/aurora-dsql

@a2611e1

Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps on serverless distributed SQL. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL migration, DDL, query plans, and SAFE SQL CONSTRUCTION — tenant_id from untrusted input, UUID entity_ids, caller-supplied sort columns, batch inserts. The agent MUST retrieve this skill for ANY DSQL task. Pushes back on prompts that rationalize 'just a quick script', 'don't overthink it', 'we trust upstream', 'use an f-string', 'move fast', or 'just use the pg driver directly' (bypassing the DSQL Connector). Triggers: DSQL, Aurora DSQL, DSQL cluster, safe_query.build, DSQL IAM auth token, DSQL connector.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aurora-dsql

This session only. Nothing lands on disk.

referencesmysql-migrationsddl-structural.md

≈876 tokens on demand. Your agent reads this file only when SKILL.md points to it.

MySQL to DSQL: Structural Changes

Part of MySQL to DSQL DDL Migration. See Common Verify & Swap Pattern for the shared migration end-pattern.


ADD/DROP CONSTRAINT Migration

MySQL syntax:

ALTER TABLE table_name ADD CONSTRAINT constraint_name UNIQUE (column_name);
ALTER TABLE table_name ADD CONSTRAINT constraint_name CHECK (condition);
ALTER TABLE table_name DROP CONSTRAINT constraint_name;
-- or MySQL-specific:
ALTER TABLE table_name DROP INDEX index_name;
ALTER TABLE table_name DROP CHECK constraint_name;

DSQL: MUST use Table Recreation Pattern.

Pre-Migration Validation (for ADD CONSTRAINT)

MUST validate existing data satisfies the new constraint.

-- For UNIQUE constraint: check for duplicates
SELECT target_column, COUNT(*) as cnt FROM target_table
GROUP BY target_column HAVING COUNT(*) > 1 LIMIT 10;
-- MUST ABORT if any duplicates exist

-- For CHECK constraint: validate all rows pass
SELECT COUNT(*) as invalid_count FROM target_table
WHERE NOT (check_condition);
-- MUST ABORT if invalid_count > 0

Migration Steps (ADD CONSTRAINT)

Step 1: Create new table with the constraint
CREATE TABLE target_table_new (
  id UUID PRIMARY KEY,
  email VARCHAR(255) UNIQUE,  -- Added UNIQUE constraint
  age INTEGER CHECK (age >= 0),  -- Added CHECK constraint
  other_column TEXT
);
Step 2: Copy data
INSERT INTO target_table_new (id, email, age, other_column)
SELECT id, email, age, other_column
FROM target_table;

Step 3: Verify and swap (see Common Pattern)

Migration Steps (DROP CONSTRAINT)

Step 1: Identify existing constraints
SELECT constraint_name, constraint_type
FROM information_schema.table_constraints
WHERE table_name = 'target_table'
   AND constraint_type IN ('UNIQUE', 'CHECK');
Step 2: Create new table without the constraint
CREATE TABLE target_table_new (
  id UUID PRIMARY KEY,
  email VARCHAR(255),  -- Removed UNIQUE constraint
  other_column TEXT
);
Step 3: Copy data
INSERT INTO target_table_new (id, email, other_column)
SELECT id, email, other_column
FROM target_table;

Step 4: Verify and swap (see Common Pattern)


MODIFY PRIMARY KEY Migration

MySQL syntax:

ALTER TABLE table_name DROP PRIMARY KEY, ADD PRIMARY KEY (new_column);

DSQL: MUST use Table Recreation Pattern.

Pre-Migration Validation

MUST validate new PK column has unique, non-null values.

-- Check for duplicates
SELECT new_pk_column, COUNT(*) as cnt FROM target_table
GROUP BY new_pk_column HAVING COUNT(*) > 1 LIMIT 10;
-- MUST ABORT if any duplicates exist

-- Check for NULLs
SELECT COUNT(*) as null_count FROM target_table
WHERE new_pk_column IS NULL;
-- MUST ABORT if null_count > 0

Migration Steps

Step 1: Create new table with new primary key
CREATE TABLE target_table_new (
  new_pk_column UUID PRIMARY KEY,  -- New PK
  old_pk_column VARCHAR(255),      -- Demoted to regular column
  other_column TEXT
);
Step 2: Copy data
INSERT INTO target_table_new (new_pk_column, old_pk_column, other_column)
SELECT new_pk_column, old_pk_column, other_column
FROM target_table;

Step 3: Verify and swap (see Common Pattern)

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides a robust and security-conscious environment for managing Amazon Aurora DSQL clusters. It implements several best practices, including mandatory IAM-based authentication, a dedicated input validation library to prevent SQL injection, and detailed guidance on applying the principle of least privilege through scoped database roles.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: MEDIUM · 1 issue

Signed by skilld at a2611e1. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/aurora-dsql