Aws Cleanrooms

by aws188af2f810ceNo license2.8K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Troubleshoots and debugs AWS Clean Rooms collaboration issues related to IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions, and CloudWatch logging for custom ML model training and inference jobs. Use when a customer reports permission failures, access errors, or log publishing issues in Clean Rooms.

Instructions onlyDevOps & Cloud
AI-generated overview

Troubleshoots AWS Clean Rooms collaboration failures involving IAM, S3, KMS, Lake Formation permissions and CloudWatch logging.

What it does
Provides domain guidance for diagnosing AWS Clean Rooms collaboration problems, routing the agent to one of two reference procedures based on the failure type. One procedure covers access-denied and permission errors across IAM role policies, S3 bucket policies, KMS key policies, Lake Formation permissions and cross-account trust. The other covers missing CloudWatch logs for custom ML model training and inference jobs, including Configured Model Algorithm Association privacy configuration and ML Configuration role permissions. It also lists AWS documentation resources for role setup, confused deputy prevention, ML roles and Lake Formation onboarding.
When to use it
Use when a customer reports permission failures, access errors or log publishing issues in AWS Clean Rooms. It is intended for troubleshooting existing collaborations and custom ML modeling jobs rather than setting them up from scratch.
Requirements
Instructions only; no scripts are shipped. The agent needs access to the referenced AWS documentation and to the customer's AWS configuration details (IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions, CloudWatch log groups) to apply the procedures.

AWS Clean Rooms

Overview

Domain expertise for troubleshooting AWS Clean Rooms collaborations and custom ML modeling. Covers permission debugging, data access issues, and CloudWatch logging configuration.

Common tasks

Debugging Clean Rooms errors

Determine the failure type:

Access denied or permission error? → See permission debugging procedure [blocked]. Covers IAM role policies (inline + attached managed), S3 bucket policies, KMS key policies, Lake Formation permissions, and cross-account trust.

Missing CloudWatch logs for custom model jobs? → See custom model logging debugging procedure [blocked]. Covers Configured Model Algorithm Association privacy configuration, ML Configuration role permissions, and log group verification.

Additional resources

Source and attribution

Source:aws/agent-toolkit-for-awsinskills/specialized-skills/analytics-skills/aws-cleanroomsat commit188af2f

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

Aws Cleanrooms Agent Skill | SourceWeft