Resilience Hub Failure Mode Assessment

作者 aws188af2f810ce無授權條款2.8K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Runs and interprets AWS Resilience Hub v2 failure mode assessments. Covers starting assessments, understanding findings (severity, categories, recommendations), triaging by achievability, working with AI-generated service functions, and resolving findings. Applies when the user wants to run an assessment, review findings, or understand failure modes, or has a specific finding and asks how to resolve, remediate, or fix it. Does not apply to initial setup (use resilience-hub-getting-started) or FIS experiments.

AI 產生的概覽

指導執行與解讀 AWS Resilience Hub v2 故障模式評估,將發現項目分級並推動修復。

功能
提供執行 AWS Resilience Hub v2 故障模式評估並解讀其發現項目的領域指引,涵蓋嚴重性、類別與建議。說明如何依嚴重性與可達成性將發現項目分級、處理 AI 產生的服務功能,以及解決發現項目。也涵蓋權限錯誤的疑難排解與評估報告的安全考量。
適用情境
當使用者想執行 Resilience Hub v2 評估、檢視其發現項目或了解故障模式時使用。也適用於使用者已有特定發現項目並詢問如何解決、修復或改善的情況。不適用於初始設定或 FIS 實驗。
執行需求
需要存取 AWS Resilience Hub v2 及其 API 呼叫,透過 AWS MCP 伺服器(建議)或直接使用 AWS CLI 執行,並具備適當的 IAM 權限。不隨附指令碼,僅為指示文件加一份參考文件。

Failure Mode Assessment

Overview

Domain expertise for running Resilience Hub v2 failure mode assessments, interpreting findings, triaging by severity and achievability, and driving remediation.

The AWS MCP server is recommended for executing this skill's AWS API calls, but it is not required — all operations also work with the AWS CLI directly.

Guardrail — where this skill's own files live (MCP vs local install)

Before reading a reference file, determine how this skill was loaded:

  • Loaded via the AWS MCP retrieve_skill tool: the skill's reference files are not on the local filesystem. Fetch each one through retrieve_skill with the file parameter (e.g. file="references/assessment-workflow.md") — do NOT file_read these paths locally or search the filesystem for them.
  • Installed locally (e.g. .kiro/skills/resilience-hub-failure-mode-assessment/ or ~/.claude/skills/resilience-hub-failure-mode-assessment/): read reference files from the local skill directory using the relative paths shown here.

This applies only to the skill's own reference files; always read and write user or session data in the working directory, never through retrieve_skill.

Run and interpret assessments

To run assessments and triage findings, follow the procedure exactly. See references/assessment-workflow.md [blocked].

Troubleshooting

Assessment fails with INVALID_PERMISSIONS

The service's permission model (invokerRoleName / crossAccountRoles) doesn't have access to the resources. Verify the invoker role (and any cross-account roles) can describe resources in all configured regions.

Too many findings — where to start?

Prioritize by finding severity, highest first (HIGH, then MEDIUM, then LOW). For HIGH-severity findings, check the service's achievability for the relevant policy component (from get-service / list-failure-mode-assessments): NOT_ACHIEVABLE means the architecture must change before testing; ACHIEVABLE means validate the fix with an FIS experiment. MEDIUM findings: plan remediation this sprint; LOW findings: track but don't block (see the priority matrix in references/assessment-workflow.md [blocked] Step 5).

AI-generated service functions are wrong

Update them: aws resiliencehubv2 update-service-function to rename or change criticality (there is no service-function "type" parameter). Reassign resources by calling create-service-function-resources with the desired resource set (see references/assessment-workflow.md [blocked] for the service-function operations).

Security Considerations

  • Least privilege: the invoker role should be scoped to read-only discovery of only the resource types in the service's input sources; avoid granting access beyond what assessment needs.
  • Encryption & access control: recommend that S3 buckets used for report output have server-side encryption (SSE-S3 or SSE-KMS) and block public access — assessment reports can contain sensitive architectural detail. If a bucket policy grants the Resilience Hub service principal write access, scope it with aws:SourceArn / aws:SourceAccount condition keys to prevent confused-deputy writes.
  • Further reading: see Security in AWS Resilience Hub and the AWS Well-Architected Security Pillar for securing assessment outputs and IAM configurations.

來源與署名

來源:aws/agent-toolkit-for-aws位於skills/specialized-skills/resilience-skills/resilience-hub-failure-mode-assessment提交188af2f

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架