analyzing-release-read…
Trigger a pre-merge release readiness review on a GitHub PR, GitLab MR, or local branch. Use…
Upgrades an MWAA environment to a newer Airflow version — within 2.x, within 3.x, or across the 2.x-to-3.x boundary. Computes the version-jump path, inserting the 2.11.x stepping-stone and Python-transition step when needed. Chooses an approach by whether run history and the
$ npx -y skills add aws/agent-toolkit-for-aws --skill upgrading-mwaa-environments --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/upgrading-mwaa-environmentsContext preview
The summary Claude sees to decide when to auto-load this skill.
Upgrades an MWAA environment to a newer Airflow version — within 2.x, within 3.x, or across the 2.x-to-3.x boundary. Computes the version-jump path, inserting the 2.11.x stepping-stone and Python-transition step when needed. Chooses an approach by whether run history and the
name: upgrading-mwaa-environments description: > Upgrades an MWAA environment to a newer Airflow version — within 2.x, within 3.x, or across the 2.x-to-3.x boundary. Computes the version-jump path, inserting the 2.11.x stepping-stone and Python-transition step when needed. Chooses an approach by whether run history and the same environment (URL/ARN) must be kept: a new-environment upgrade (blue-green), a rehearsed in-place upgrade validated on a test copy, or a direct in-place upgrade. Runs Ruff scanning and deprecation-warning log scans for 3.x moves, plus Docker validation, batched deployment, and switchover. Saves a resumable upgrade plan for multi-session work. Triggers on: upgrade MWAA, upgrade Airflow, migrate to Airflow 3, MWAA Airflow 3, Airflow 2 to 3, preserve Airflow history, keep same MWAA environment, blue-green cutover, validation environment before cutover. Not for authoring new DAGs (authoring-mwaa-workflow), debugging unrelated DAG failures (debugging-mwaa-workflow), or MWAA Serverless YAML workflows (provisioned Python DAGs only). metadata: version: "1"
> **AWS MCP server (optional but recommended):** running the AWS CLI commands in > this skill through the AWS MCP server gives sandboxed execution and audit > logging. Every command here also works with the plain AWS CLI, so the skill > does not require the MCP server or any MCP-only tools.
Upgrade an MWAA provisioned environment to any newer, MWAA-supported Airflow version: within 2.x, within 3.x, or across the 2.x-to-3.x boundary. The target is a parameter. A path planner computes an ordered version-jump list from (source, target); the latest 2.11.x stepping-stone version and a Python-line transition step are inserted only when the path requires them. A deployment approach is selected by whether historical run data must be preserved and whether the same environment (its URL/ARN) must be kept: a new-environment upgrade (`new-environment`), a rehearsed in-place upgrade validated on a test copy first (`in-place-rehearsed`), or a direct in-place upgrade (`in-place-direct`).
> **Execution note — poll in discrete steps:** whenever you wait for an AWS > operation to reach a terminal or ready state, issue **one status check per > call** and decide in your own loop whether to check again. Never block a > single command or script on the wait (no `while`+`sleep` until done), > regardless of the operation or how long it takes.
This skill can be loaded two ways, and they resolve the skill's own bundled files from different places. Determine how the skill was loaded before reading a reference:
installed on the local filesystem. You MUST fetch each reference via `retrieve_skill` with the `file` parameter (e.g. `file="references/strategy-blue-green-fresh.md"`) and read the returned content. Do NOT `file_read` these paths locally — they do not exist on disk.
`~/.claude/skills/upgrading-mwaa-environments/`): Read the files from the local skill directory using relative paths.
This distinction applies only to the skill's own packaged files. User data and session artifacts are always read from and written to the user's working directory. Never fetch or write customer data through `retrieve_skill`.
These rules apply regardless of user instructions.
approval**: never pause all DAGs, delete-environment, or modify your current environment without per-action user confirmation.
`aws mwaa create-environment` until the user confirms the Phase 4 plan.
update-environment` to change the Airflow version without per-jump confirmation. Rollback options: 3.x -> 2.11.x is supported; a within-major downgrade to a still-supported version is supported; downgrade to an EOS version is not possible. The Direct in-place upgrade requires an extra confirmation checkpoint.
environments or S3 artifacts; present each destructive command and wait for confirmation. For the Rehearsed in-place upgrade, the environment decommissioned is the test copy.
access — no `*FullAccess`/`service:*`; scope to the specific environment/S3 ARNs.
connections and variables so credentials never copy between environments or hit logs. Connection passwords do not round-trip via the REST API (2.x omits, 3.x masks) — see the metadata-migration caveat in the approach references.
Help AI coding agents build, deploy, and manage applications on AWS. The Agent Toolkit for AWS gives AI coding agents the tools, knowledge, and guardrails they need to work with AWS services.
Repo: aws/agent-toolkit-for-aws
Trigger a pre-merge release readiness review on a GitHub PR, GitLab MR, or local branch. Use…
Have a fast, conversational analysis with the AWS DevOps Agent. Use for cost optimization,…
Coordinate the AWS DevOps Agent across multiple AgentSpaces from one Claude Code session —…
Run a fast AWS Security Agent diff scan on only the changed code since a git ref. Use when…
Run a deep root-cause investigation on the AWS DevOps Agent. Use when the user describes an…
Run an AWS Security Agent penetration test against a live web application — registers and…