All skills
aws avatar

/connecting-to-data-source

@b33847d

Create and troubleshoot AWS Glue connections to JDBC databases (Oracle, SQL Server, PostgreSQL, MySQL, RDS), Redshift, Snowflake, and BigQuery. Gathers connection hints from user, discovers existing connections and RDS/Redshift candidates, registers credentials in Secrets Manager or IAM DB auth, configures VPC, and tests. Triggers on: connect to database, set up Glue connection, register data source, connect to Snowflake/BigQuery/RDS, connection timeout, test connection, troubleshoot connection. Do NOT use for moving data (use ingesting-into-data-lake), creating tables (use creating-data-lake-table), queries (use querying-data-lake), catalog exploration (use exploring-data-catalog), or SaaS (Salesforce, ServiceNow, SAP, MongoDB, Kafka).

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/connecting-to-data-source

This session only. Nothing lands on disk.

referencesdiscovery.md

≈917 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Discovering Connections and Candidate Sources

Before creating a new Glue connection, check what exists and what the user has available in their account. Users often forget about previously registered connections or don't realize they already have running databases that can be registered.

Contents

Existing Glue Connections

List all connections, optionally filtered by type:

# All connections
aws glue get-connections --region <REGION> --query 'ConnectionList[].{Name:Name,Type:ConnectionType,LastUpdated:LastUpdatedTimestamp}'

# Filter by type
aws glue get-connections --filter ConnectionType=JDBC --region <REGION>
aws glue get-connections --filter ConnectionType=SNOWFLAKE --region <REGION>
aws glue get-connections --filter ConnectionType=BIGQUERY --region <REGION>

Inspect a specific connection's properties (credentials are redacted in the response):

aws glue get-connection --name <NAME> --region <REGION>

If a connection matching the user's intent already exists, confirm with the user and skip creation. Re-test it (Step 7 of the skill) before handing off.

RDS and Aurora Candidates

RDS instances:

aws rds describe-db-instances \
  --query 'DBInstances[].{Id:DBInstanceIdentifier,Endpoint:Endpoint.Address,Port:Endpoint.Port,Engine:Engine,DBName:DBName,VpcId:DBSubnetGroup.VpcId,Status:DBInstanceStatus,IAMAuth:IAMDatabaseAuthenticationEnabled}' \
  --region <REGION>

Aurora clusters:

aws rds describe-db-clusters \
  --query 'DBClusters[].{Id:DBClusterIdentifier,Endpoint:Endpoint,ReaderEndpoint:ReaderEndpoint,Port:Port,Engine:Engine,DatabaseName:DatabaseName,IAMAuth:IAMDatabaseAuthenticationEnabled}' \
  --region <REGION>

Prefer the Aurora reader endpoint for ETL reads to avoid impacting the writer. The reader endpoint is load-balanced across reader instances.

Note IAMDatabaseAuthenticationEnabled: true -- if set, recommend IAM DB auth over password per credential-security.md.

Redshift Candidates

Provisioned clusters:

aws redshift describe-clusters \
  --query 'Clusters[].{Id:ClusterIdentifier,Endpoint:Endpoint.Address,Port:Endpoint.Port,DBName:DBName,VpcId:VpcId,IAMRoles:IamRoles[*].IamRoleArn,Status:ClusterStatus}' \
  --region <REGION>

Serverless workgroups:

aws redshift-serverless list-workgroups \
  --query 'workgroups[].{Name:workgroupName,Endpoint:endpoint.address,Port:endpoint.port,Status:status}' \
  --region <REGION>

Presenting Candidates

When you find candidates, present them as a numbered list and let the user pick. Example:

I found these databases in your account. Which would you like to register?

1. RDS PostgreSQL: analytics-prod (analytics-prod.abc123.us-east-1.rds.amazonaws.com:5432, DB: analytics, IAM auth: enabled)
2. Aurora MySQL cluster: orders-writer (orders.cluster-abc123.us-east-1.rds.amazonaws.com, reader: orders.cluster-ro-abc123..., DB: orders)
3. Redshift: warehouse-prod (warehouse-prod.abc123.us-east-1.redshift.amazonaws.com:5439, DB: analytics)
4. None of these -- I want to register a source outside my account.

Never auto-select. The user may have multiple candidates or want to register a source that isn't visible to these discovery APIs (on-premises, peered account, Snowflake, BigQuery).

Snowflake and BigQuery sources are not discoverable via AWS APIs -- always ask the user for account/project details directly.

Source: SKILL.md on GitHub

No alerts17d3 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill includes some security considerations such as dynamic script generation for troubleshooting and a surface for indirect prompt injection. While these warrant review, they are used within the skill's intended functionality to register and test data source connections. See detailed analysis for context.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

Signed by skilld at b33847d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
Other metadata
metadata
{
  "version": "1",
  "argument-hint": "'[source-type|connection-name|hostname]'"
}

README badge

README badge for aws/agent-toolkit-for-aws/connecting-to-data-source