All skills
aws avatar

/aws-observability

@bb272a8

Builds, configures, debugs, and optimizes AWS observability — operator-symptom questions and detecting Omni vs classic CloudWatch. CloudWatch: Log Insights, alarms, Dynamic Instrumentation, and Application Signals — instrumenting/onboarding a service to Application Signals with ADOT on EC2/ECS/EKS/Lambda: auto-instrumentation, monitored service, reporting telemetry, ServiceEvents, CI/CD metadata, Terraform/manifest. Also fleet health views. CloudWatch Omni on an existing Space: SQL over logs and traces, PromQL over metrics, Omni dashboards, Omni alerts, context graph for root cause, programmatic/IaC access (API/SDK/CLI/CloudFormation) and driving Omni from a coding agent or skills, and evaluating AI agent quality from traces — on-demand and continuous online scoring of live agent traffic, readback, and custom trace evaluators. For first-time Omni setup — creating a Space, granting access, ingestion, or ADOT instrumentation — use setting-up-cloudwatch-observability. Not for app logging or threat detection.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-observability

This session only. Nothing lands on disk.

referencescloudwatchappsignals-guideslambda-dotnet.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Enable AWS Application Signals for .NET on AWS Lambda

Your task is to modify Infrastructure as Code (IaC) files to enable AWS Application Signals for .NET Lambda functions. You will:

  1. Add IAM permissions for Application Signals
  2. Configure X-Ray tracing
  3. Add the ADOT Lambda layer
  4. Set the required environment variables.

If you cannot determine a value (such as AWS Region): Ask the user for clarification before proceeding. Do not guess or make up values.

Region-Specific Layer ARNs

The ADOT Lambda layer ARN is region-specific, and its layer version changes over time. Do not hardcode a version from this guide — look up the current value from the source of truth, which lists all supported regions and the latest layer version:

ARN format — fill in <REGION> and <LAYER_VERSION> (the latest version for that region from the source above):

arn:aws:lambda:<REGION>:<ACCOUNT_ID>:layer:AWSOpenTelemetryDistroDotNet:<LAYER_VERSION>

A few sample regions (illustrative — confirm the current <LAYER_VERSION> and account ID from the source of truth, and use it for any supported region, not just these):

us-east-1:      arn:aws:lambda:us-east-1:615299751070:layer:AWSOpenTelemetryDistroDotNet:<LAYER_VERSION>
us-west-2:      arn:aws:lambda:us-west-2:615299751070:layer:AWSOpenTelemetryDistroDotNet:<LAYER_VERSION>
ca-central-1:   arn:aws:lambda:ca-central-1:615299751070:layer:AWSOpenTelemetryDistroDotNet:<LAYER_VERSION>
ap-east-1:      arn:aws:lambda:ap-east-1:888577020596:layer:AWSOpenTelemetryDistroDotNet:<LAYER_VERSION>
ap-southeast-1: arn:aws:lambda:ap-southeast-1:615299751070:layer:AWSOpenTelemetryDistroDotNet:<LAYER_VERSION>
eu-west-1:      arn:aws:lambda:eu-west-1:615299751070:layer:AWSOpenTelemetryDistroDotNet:<LAYER_VERSION>
eu-south-1:     arn:aws:lambda:eu-south-1:257394471194:layer:AWSOpenTelemetryDistroDotNet:<LAYER_VERSION>
...

Note: some partitions use a different ARN prefix and account ID (arn:aws-cn: for China, arn:aws-us-gov: for GovCloud). The source of truth has the exact ARN for every supported region.

Instructions

Step 1: Add IAM Permissions

Add CloudWatchLambdaApplicationSignalsExecutionRolePolicy to the Lambda function's execution role.

Which policy, and when it applies. CloudWatchLambdaApplicationSignalsExecutionRolePolicy is the purpose-built managed policy for this configuration — Application Signals enabled on Lambda — and it is genuinely scoped rather than broad: its logs: actions are limited to arn:aws:logs:*:*:log-group:/aws/application-signals/data:*, and both of its statements are conditioned on aws:ResourceAccount matching aws:PrincipalAccount. It is the right grant here.

Do not carry it over to the ADOT-SDK-only path where Application Signals is disabled: the setting-up-cloudwatch-observability skill's references/cloudwatch-omni/instrumentation/instrumentation.md states it is out of scope there. That path grants the execution role xray:PutTraceSegments and xray:PutTelemetryRecords — usually via the AWSXRayDaemonWriteAccess managed policy (or the inline grant CDK adds when tracing is enabled); the two-action inline form is the optional least-privilege alternative, not the default. Note the two policies are not interchangeable in either direction: this one does not grant xray:PutTelemetryRecords, so it is not a superset of the ADOT-only grant. Say which of the two setups this change is for, since the correct IAM differs.

Step 2: Enable X-Ray Active Tracing

CDK: tracing: lambda.Tracing.ACTIVE Terraform: tracing_config { mode = "Active" }

Step 3: Add ADOT .NET Lambda Layer

Use the layer name AWSOpenTelemetryDistroDotNet with automatic region detection. See Region-Specific Layer ARNs section above for complete mapping.

Step 4: Set Environment Variable

Add AWS_LAMBDA_EXEC_WRAPPER = "/opt/otel-instrument".

Completion

Tell the user:

"I've completed the Application Signals enablement for your .NET Lambda function.

Configuration Changes:

  • IAM Permissions: Added CloudWatchLambdaApplicationSignalsExecutionRolePolicy
  • X-Ray Tracing: Enabled active tracing
  • ADOT Layer: Added AWSOpenTelemetryDistroDotNet layer
  • Environment Variable: Set AWS_LAMBDA_EXEC_WRAPPER=/opt/otel-instrument

Next Steps:

  1. Ensure that Application Signals is enabled in AWS account.
  2. Review the changes using git diff
  3. Deploy your infrastructure
  4. After deployment, invoke your Lambda function to generate telemetry data

Verification:

  • Open AWS CloudWatch Console → Application Signals → Services

Troubleshooting Refer to the CloudWatch APM troubleshooting guide.

Let me know if you'd like me to make any adjustments before you deploy!"

Source: SKILL.md on GitHub

1 warning6d3 checks · Risk SAFE
  • Gen Agent Trust Hub6d

    This skill provides comprehensive capabilities for AWS observability and debugging, including agent evaluation and dynamic instrumentation. It includes some security considerations, such as the processing of untrusted telemetry data and the use of external scripts for service onboarding, which are handled with a focus on user confirmation and best practices.

  • Socket6d

    2 alerts: gptAnomaly

  • Snyk6d

    Risk: LOW · No issues

Signed by skilld at bb272a8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
metadata
{
  "version": "6"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-observability