All skills

Advises on Amazon RDS open-source engines (MySQL, MariaDB, PostgreSQL) for instance creation, upgrade planning, commitment pricing, proxy evaluation, and Blue/Green deployments. Handles any RDS MySQL, MariaDB, or PostgreSQL question, including create a production-ready RDS MySQL instance, provision an RDS PostgreSQL database, run the RDS upgrade advisor for my RDS MySQL instance, what are my upgrade options, upgrade RDS MariaDB from 10.6 to the latest version, should I buy reserved instances or a savings plan for db.r7g.2xlarge RDS MySQL, change a VARCHAR to INT column on RDS MySQL 8.0 with Blue/Green, and does RDS Proxy help when PgBouncer already runs in transaction mode. Covers instance creation with production best practices, describe-db-instances and describe-db-engine-versions upgrade-target workflow, live prechecks via SSM or direct connection, RI versus DSP commitment pricing, RDS Proxy versus PgBouncer, and Blue/Green lifecycle with binlog replay compatibility.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/rds-oss

This session only. Nothing lands on disk.

referencesproxy-pinning-mysql.md

≈709 tokens on demand. Your agent reads this file only when SKILL.md points to it.

MySQL/MariaDB RDS Proxy Pinning Risks

Pinning means the proxy locks a frontend connection to a specific backend database connection, preventing multiplexing. When pinned, the proxy can't reuse that backend connection for other clients, reducing the benefit of connection pooling.

High Pinning Risk (defeats proxy purpose)

Pattern Why It Pins Diagnostic Query
Prepared statements (server-side) Proxy can't move prepared state between backends SHOW GLOBAL STATUS LIKE 'Com_stmt_prepare'; — if high, pinning is frequent
SET SESSION variables Session state is backend-specific SELECT s.VARIABLE_NAME, s.VARIABLE_VALUE AS session_val, g.VARIABLE_VALUE AS global_val FROM performance_schema.session_variables s JOIN performance_schema.global_variables g USING (VARIABLE_NAME) WHERE s.VARIABLE_VALUE <> g.VARIABLE_VALUE; — rows where session differs from global indicate a SET SESSION was issued
User-defined variables (@var) Session-scoped, can't be transferred Check application code for SET @var = ... patterns
LOCK TABLES Explicit lock is backend-specific SHOW GLOBAL STATUS LIKE 'Com_lock_tables';
GET_LOCK() / RELEASE_LOCK() Advisory locks are session-scoped Check application code for GET_LOCK() usage
Temporary tables CREATE TEMPORARY TABLE is session-scoped SHOW GLOBAL STATUS LIKE 'Created_tmp_tables'; — high values indicate risk
FOUND_ROWS() Depends on previous query's state Check application code

Medium Pinning Risk

Pattern Notes
SET NAMES / SET CHARACTER SET Pins if different from proxy default. Configure proxy default charset to match app.
SET TRANSACTION ISOLATION LEVEL Pins for the duration of the transaction
Multi-statement transactions Pinned for transaction duration (expected, not a problem if transactions are short)

Low / No Pinning Risk

Pattern Notes
Simple SELECT/INSERT/UPDATE/DELETE No session state. Full multiplexing.
Autocommit single statements No pinning.
Connection attributes Proxy handles these transparently.

Diagnostic: Check Current Pinning Rate

If RDS Proxy is already deployed, check pinning via CloudWatch:

  • ClientConnectionsSetupSucceeded vs DatabaseConnectionsCurrentlySessionPinned
  • Pinning rate = pinned / total × 100
  • If > 30%, proxy benefit is significantly reduced

Mitigation Strategies

  1. Move prepared statements to client-side (use useServerPrepStmts=false in JDBC)
  2. Avoid SET SESSION — use proxy's default connection init query instead
  3. Keep transactions short to minimize pin duration
  4. Avoid temporary tables — use CTEs or subqueries instead
  5. Replace GET_LOCK() with application-level locking (Redis, DynamoDB)

Source: SKILL.md on GitHub

No alerts3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill is a specialized advisor for Amazon RDS open-source engines, providing workflows for resource provisioning, upgrades, and cost optimization. It adheres to security best practices by enforcing encryption, multi-factor availability, and secure credential management via AWS Secrets Manager. No malicious patterns were identified.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at aea59f3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/rds-oss