Imported from ferdinandobons/AWSBestPracticesSkill (
SKILL.md). Install upstream withnpx skills add ferdinandobons/AWSBestPracticesSkill. Copyright stays with the author.
AWS Best Practices
A curated, source-linked collection of AWS best practices for every AWS service, plus cross-service general guidance. Organized so you can find what matters for a specific use case.
No live web for ordinary answers: use the local files in this repository. Do not search the web, open AWS documentation URLs, or use live documentation tools unless the user explicitly asks for a current/live refresh or the local catalog is missing the requested service/topic.
Unofficial project: this skill is independently maintained. It is not an official AWS skill, AWS product, or AWS-maintained resource, and it is not affiliated with or endorsed by Amazon Web Services.
What this contains / does NOT contain
- ✅ Only best practices, per service, organized by the 6 AWS Well-Architected
pillars, each practice tagged with a
[when-it-applies]context and linked to the official AWS source. - ❌ No service descriptions/overviews, no pricing or cost estimates, no tutorials or getting-started guides, no extended code samples. If you need those, go to the AWS docs directly; this skill is best practices only.
How to use this skill
- From the user's use case, identify (a) the AWS service(s) involved and (b) the concern/pillar that matters (security, reliability, performance, cost, operations, sustainability).
- Open
catalog.md(or the index below) and find the service's file path. - Open
services/<category>/<service>.md. - Read the
## Common scenariosblock first to map the use case to the relevant pillars, then read those pillar sections. Each bullet's[context]tag tells you whether it applies to the user's situation. - For cross-service questions (account setup, multi-account, cost governance,
DR, observability, tagging), use the General section under
general/. - When you cite a best practice, include the source URL already present in the local file. Copy the URL text from the local Markdown; do not open it.
Web access policy
For ordinary best-practice answers, use this repository as the source of truth:
read SKILL.md, catalog.md, and the relevant local services/ or general/
file. Do not call web search, open AWS documentation URLs, fetch pages, or
use live documentation tools just to verify or cite a bullet that is already in
the local file. The [doc](...) URLs in those files are pre-recorded citations:
copy them from the local Markdown when useful, but do not visit them.
Use live web/documentation access only when the user explicitly asks for a current/live refresh, asks you to verify whether AWS changed something, or when the requested service/topic is not covered by the local catalog.
If a service is not yet covered, say so plainly; do not invent best practices.
Use-case targeting
Prefer a targeted answer over an exhaustive dump. If the user gives a specific scenario, workload, constraint, or concern, select only the best practices that apply to that case.
Examples:
- "secure my S3 bucket" → focus on Security, access control, encryption, public access prevention, audit, and network restrictions.
- "SQS queue in production" → give a production baseline across reliability, security, performance, cost, and operations.
- "reduce DynamoDB cost" → focus on Cost Optimization and any performance or operational practices that directly affect spend.
- "is this Lambda setup production-ready?" → structure the answer as gaps, risks, and concrete fixes.
If the user does not provide a specific scenario, give the general production baseline for that service: the most broadly useful practices across Security, Reliability, Performance Efficiency, Cost Optimization, and Operational Excellence. Do not list every bullet in the file unless the user asks for a complete/deep-dive answer.
Answer style
Default to an actionable production baseline, not an encyclopedia. Use this shape unless the user asks for another format:
- Start with one sentence that names the local service file used.
- Give a short "baseline consigliata" / "recommended baseline" list of the highest-impact settings or practices.
- Add "decisioni chiave" / "key decisions" when the service has important trade-offs (for example Standard vs FIFO, SSE-S3 vs SSE-KMS, single-Region vs replication).
- Group additional guidance by relevant Well-Architected pillars only when it helps the user act.
- Add caveats for special cases, such as Lambda consumers, FIFO ordering, sensitive data, private networking, compliance, or high throughput.
- End with the local file path and last_reviewed date when available. Include only a few source URLs, copied from the local Markdown, unless the user asks for full citations.
Avoid very wide tables by default because they often wrap poorly in terminals. Use compact bullets unless the user explicitly asks for a table.
File layout
services/<category>/<service>.md # per-service best practices (pillar-organized)
general/<topic>.md # cross-service best practices
catalog.md # human index (generated)
catalog.json # machine-readable source of truth
Index
Compute
- AWS App Runner
- AWS Batch
- AWS Elastic Beanstalk
- AWS Lambda
- AWS Outposts
- AWS Parallel Computing Service
- Amazon EC2
- Amazon EC2 Auto Scaling
- Amazon Elastic VMware Service
- Amazon Lightsail
- VMware Cloud on AWS
Containers
- AWS Fargate
- Amazon ECR
- Amazon ECR Public
- Amazon ECS
- Amazon EKS
- Amazon EKS Anywhere
- Red Hat OpenShift Service on AWS (ROSA)
Storage
- AWS Backup
- AWS Elastic Disaster Recovery
- AWS Snow Family
- AWS Storage Gateway
- Amazon EBS
- Amazon EFS
- Amazon FSx
- Amazon File Cache
- Amazon S3
- Amazon S3 Glacier
Database
- Amazon Aurora
- Amazon Aurora DSQL
- Amazon DocumentDB
- Amazon DynamoDB
- Amazon DynamoDB Accelerator (DAX)
- Amazon ElastiCache
- Amazon Keyspaces
- Amazon MemoryDB
- Amazon Neptune
- Amazon Neptune Analytics
- Amazon RDS
- Amazon Redshift
- Amazon Timestream
- Oracle Database@AWS
Networking & Content Delivery
- AWS App Mesh
- AWS Cloud Map
- AWS Cloud WAN
- AWS Direct Connect
- AWS Global Accelerator
- AWS Network Firewall
- AWS PrivateLink
- AWS Transit Gateway
- AWS Verified Access
- Amazon API Gateway
- Amazon Application Recovery Controller (ARC)
- Amazon CloudFront
- Amazon Route 53
- Amazon VPC
- Amazon VPC Lattice
- Elastic Load Balancing
Security, Identity & Compliance
- AWS Artifact
- AWS Audit Manager
- AWS Certificate Manager
- AWS CloudHSM
- AWS Directory Service
- AWS Firewall Manager
- AWS IAM
- AWS IAM Access Analyzer
- AWS IAM Identity Center
- AWS KMS
- AWS Payment Cryptography
- AWS Secrets Manager
- AWS Security Hub
- AWS Security Incident Response
- AWS Shield
- AWS WAF
- Amazon Cognito
- Amazon Detective
- Amazon GuardDuty
- Amazon Inspector
- Amazon Macie
- Amazon Security Lake
- Amazon Verified Permissions
Management & Governance
- AWS Auto Scaling
- AWS CloudFormation
- AWS CloudTrail
- AWS Compute Optimizer
- AWS Config
- AWS Control Tower
- AWS Fault Injection Service
- AWS Health
- AWS License Manager
- AWS Organizations
- AWS Resilience Hub
- AWS Resource Access Manager
- AWS Service Catalog
- AWS Systems Manager
- AWS Trusted Advisor
- AWS Well-Architected Tool
- Amazon CloudWatch
- Amazon DevOps Guru
- Amazon Managed Grafana
- Amazon Managed Service for Prometheus
Application Integration
- AWS B2B Data Interchange
- AWS Step Functions
- Amazon AppFlow
- Amazon EventBridge
- Amazon MQ
- Amazon MWAA
- Amazon SNS
- Amazon SQS
- Amazon SWF
Analytics
- AWS Clean Rooms
- AWS Data Exchange
- AWS Data Pipeline
- AWS Entity Resolution
- AWS Glue
- AWS Lake Formation
- Amazon Athena
- Amazon Data Firehose
- Amazon DataZone
- Amazon EMR
- Amazon FinSpace
- Amazon Kinesis Data Streams
- Amazon Kinesis Video Streams
- Amazon MSK
- Amazon Managed Service for Apache Flink
- Amazon OpenSearch Service
- Amazon QuickSight
- Amazon S3 Tables
Machine Learning
- AWS HealthImaging
- Amazon Bedrock
- Amazon Bedrock AgentCore
- Amazon Comprehend
- Amazon Comprehend Medical
- Amazon Forecast
- Amazon Fraud Detector
- Amazon HealthLake
- Amazon Kendra
- Amazon Lex
- Amazon Omics
- Amazon Personalize
- Amazon Polly
- Amazon Q
- Amazon Rekognition
- Amazon SageMaker
- Amazon Textract
- Amazon Transcribe
- Amazon Translate
Developer Tools
- AWS CloudShell
- AWS CodeArtifact
- AWS CodeBuild
- AWS CodeCommit
- AWS CodeDeploy
- AWS CodePipeline
- AWS Infrastructure Composer
- AWS X-Ray
- Amazon CodeCatalyst
- Amazon CodeGuru
Migration & Transfer
- AWS Application Migration Service
- AWS DataSync
- AWS Database Migration Service
- AWS Mainframe Modernization
- AWS Migration Hub
- AWS Migration Hub Refactor Spaces
- AWS Transfer Family
Front-End Web & Mobile
Internet of Things
- AWS IoT Core
- AWS IoT Device Defender
- AWS IoT Device Management
- AWS IoT ExpressLink
- AWS IoT FleetWise
- AWS IoT Greengrass
- AWS IoT SiteWise
- AWS IoT TwinMaker
- FreeRTOS
Media Services
- AWS Deadline Cloud
- AWS Elemental MediaConnect
- AWS Elemental MediaConvert
- AWS Elemental MediaLive
- AWS Elemental MediaPackage
- AWS Elemental MediaStore
- AWS Elemental MediaTailor
- Amazon IVS
End User Computing
- Amazon WorkSpaces
- Amazon WorkSpaces Applications
- Amazon WorkSpaces Secure Browser
- Amazon WorkSpaces Thin Client
Business Applications
Cloud Financial Management
- AWS Billing Conductor
- AWS Budgets
- AWS Cost Anomaly Detection
- AWS Cost Explorer
- AWS Cost Optimization Hub
- AWS Cost and Usage Report