All skills
aws avatar

/recovery-controller-setup

@7618003

Configures AWS Application Recovery Controller (ARC) for operational resilience: routing controls with safety rules for cross-Region failover, and zonal shift / zonal autoshift for AZ-impairment recovery. Applies when setting up failover routing, configuring safety rules, enabling zonal shift, or configuring zonal autoshift with practice runs. Also applies when shifting traffic out of a specific Availability Zone (AZ) for an ALB/NLB or other resource. For a broader "an AZ is impaired, what is my response across services" question, see aws-resilience-lifecycle. Does not apply to Resilience Hub setup or FIS experiments.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/recovery-controller-setup

This session only. Nothing lands on disk.

referencessecurity-considerations.md

≈629 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Considerations — recovery-controller-setup

Guidance for securing ARC routing controls, safety rules, and zonal shift / zonal autoshift.

  • Least privilege: scope the IAM principals that operate routing controls and zonal shift to the specific actions they need — never service-level wildcards. For zonal shift / zonal autoshift: arc-zonal-shift:StartZonalShift, arc-zonal-shift:GetManagedResource, arc-zonal-shift:CreatePracticeRunConfiguration, and arc-zonal-shift:UpdateZonalAutoshiftConfiguration. For data-plane failover: route53-recovery-cluster:GetRoutingControlState, route53-recovery-cluster:UpdateRoutingControlState, route53-recovery-cluster:UpdateRoutingControlStates, and route53-recovery-cluster:ListRoutingControls. Scope each statement to the specific routing-control / resource ARNs involved.
  • Condition keys: further restrict access with IAM condition keys — e.g. scope route53-recovery-cluster:UpdateRoutingControlState to specific routing-control ARNs via the statement Resource, and use aws:ResourceTag to limit which resources a principal may shift. For cross-service access (such as Route53 health-check association), constrain with aws:SourceAccount / aws:SourceArn to avoid the confused-deputy problem.
  • Safety rules are a control: never create routing controls without safety rules — they prevent an operator from accidentally turning off all Regions at once. Consider a gating rule requiring approval for production failover.
  • Restrict failover access: limit which principals can change routing-control state, as a state change can shift production traffic between Regions.
  • Failover notifications: SNS topics and CloudWatch Logs groups carrying routing-control state-change or zonal-shift notifications SHOULD be KMS-encrypted and restricted to authorized personnel, since failover events reveal production resilience posture. Validate that SNS subscription endpoints (email, HTTP/S, Lambda ARNs) belong to authorized recipients before subscribing, and use an SNS topic access policy to restrict who may subscribe. (Notification/alarm setup itself is owned by the AWS Observability companion skill.)
  • Further reading: see Security in Amazon Application Recovery Controller and the AWS Well-Architected Reliability Pillar for guidance on securing resilience infrastructure.

Source: SKILL.md on GitHub

No alerts2mo3 checks · Risk SAFE
  • Gen Agent Trust Hub2mo

    This skill provides standard procedures for configuring AWS Application Recovery Controller (ARC). It follows operational best practices and includes security considerations for infrastructure management.

  • Socket2mo

    No alerts

  • Snyk2mo

    Risk: LOW · No issues

Signed by skilld at 7618003. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/recovery-controller-setup