All skills
aws avatar

/timestream-influxdb

@ba14cd9

Retrieves authoritative guidance on Amazon Timestream for InfluxDB across its supported engine variants. Applicable to any InfluxDB-on-AWS request including engine variant and licensing selection, provisioning and IAM, encryption at rest (AWS-owned and customer-managed KMS keys, key policies, and key lifecycle), schema design (tags vs fields, cardinality, HTTP/sensor/metric data modeling), migration from LiveAnalytics, Processing Engine plugins, connectivity (database endpoints and private or public access), and write/query errors.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/timestream-influxdb

This session only. Nothing lands on disk.

referencess3-vpc-endpoint-troubleshooting.md

≈440 tokens on demand. Your agent reads this file only when SKILL.md points to it.

S3 VPC Endpoint Troubleshooting (InfluxDB 3)

Problem

Before diagnosing S3 connectivity, verify the private-cluster S3 prerequisites. For an existing resource, read publiclyAccessible from GetDbCluster; inspect the Create and Update API models before asserting whether public access is available or mutable.

When the documentation requires an S3 VPC endpoint, inspect the endpoint's type, state, service name, VPC ownership, and RouteTableIds, plus every selected subnet's effective route table. Do not infer compliance from an internet-gateway route alone.

Symptoms

  • Instance fails to start or becomes unhealthy after provisioning
  • "S3 endpoint does not exist" errors in logs
  • Write failures with no clear error message

Fix

When the prerequisites require a gateway endpoint, use the documented VPC and account placement and service name. For example:

aws ec2 create-vpc-endpoint \
  --vpc-id <vpc-id> \
  --service-name com.amazonaws.<region>.s3 \
  --route-table-ids <route-table-id> \
  --vpc-endpoint-type Gateway

Important Notes

  • Verify the VPC and account ownership constraints before rejecting shared-subnet or cross-account designs
  • When the prerequisites require route-table associations, inspect the effective route table for every selected subnet, including inheritance from the VPC's main route table
  • Read publiclyAccessible from the resource and verify endpoint requirements instead of treating a 0.0.0.0/0 internet-gateway route as proof
  • Verify the affected engine variants before applying this runbook
  • Verify with: aws ec2 describe-vpc-endpoints --filters Name=vpc-id,Values=<vpc-id>

Source: SKILL.md on GitHub

1 warning1d3 checks · Risk SAFE
  • Gen Agent Trust Hub1d

    This skill provides authoritative guidance for Amazon Timestream for InfluxDB and follows established security best practices. It incorporates input validation for CLI parameters, secure secret retrieval via AWS Secrets Manager, and restrictive file permissions for local tokens. The skill also handles data handoffs from parent skills using schema validation and scope checks to manage potential injection risks.

  • Socket1d

    No alerts

  • Snyk1d

    Risk: MEDIUM · 1 issue

Signed by skilld at ba14cd9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 days ago
version
2

README badge

README badge for aws/agent-toolkit-for-aws/timestream-influxdb