Cloud Devops
davila7/claude-code-templates
Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.
Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.
$ npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-best-practices --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kiro/skills/eks-best-practices .claude/skills/eks-best-practices && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "eks-best-practices" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-best-practices into .claude/skills/eks-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-best-practices", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-best-practicesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-best-practices --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.kiro/skills/eks-best-practices .agents/skills/eks-best-practices && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "eks-best-practices" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-best-practices into .agents/skills/eks-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-best-practices", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-best-practices --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.kiro/skills/eks-best-practices .cursor/skills/eks-best-practices && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "eks-best-practices" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-best-practices into .cursor/skills/eks-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-best-practices", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aws-samples/appmod-blueprints.git --path .kiro/skills/eks-best-practices--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-best-practices --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.kiro/skills/eks-best-practices .gemini/skills/eks-best-practices && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "eks-best-practices" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-best-practices into .gemini/skills/eks-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-best-practices", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aws-samples/appmod-blueprints eks-best-practicesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .github/skills && cp -r skills-src/.kiro/skills/eks-best-practices .github/skills/eks-best-practices && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "eks-best-practices" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-best-practices into .github/skills/eks-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-best-practices", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aws-samples/appmod-blueprints eks-best-practices --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.kiro/skills/eks-best-practices .opencode/skills/eks-best-practices && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "eks-best-practices" agent skill from https://github.com/aws-samples/appmod-blueprints/tree/main/.kiro/skills/eks-best-practices into .opencode/skills/eks-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eks-best-practices", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
eks-best-practicesAdvisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.
Eks Best Practices is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning. Also answers Terraform configuration questions about terraform-aws-modules/terraform-aws-eks. Use for any EKS planning or architectural judgment call, even when phrased casually. Do NOT use for generating documents or code (eks-design, eks-build), scoring or auditing a live cluster (eks-operation-review…
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including reference files (for example `references/argocd-patterns.md`, `references/autoscaling.md` and `references/cluster-upgrades.md`).
It sits in DevOps & Cloud, covering Infrastructure as code, Multi-tenancy and Platform engineering. It works with Amazon Web Services, Model Context Protocol, Terraform and vLLM. The licence is MIT-0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 42ea29c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comdocs.aws.amazon.comaws.amazon.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Eks Best Practices loads about 5k tokens when it runs, and up to ~85k if it reads all its reference files. Until then it costs about 234 tokens; SKILL.md has 1,770 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aws-samples/appmod-blueprints at commit 42ea29c, republished under its MIT-0 licence (© aws-samples). 1,770 words, ~5,026 tokens.
.claude/skills/eks-best-practices/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.Comprehensive guidance for designing, deploying, and operating Amazon EKS clusters. Consolidates guidance from the AWS EKS Best Practices Guide, AWS EKS HA/Resiliency Guide, and terraform-aws-modules/terraform-aws-eks examples.
Activate this skill when:
Don't use this skill for:
| Requirement | EKS | ECS | Lambda |
|---|---|---|---|
| Kubernetes ecosystem | ✅ Native K8s | ❌ AWS-proprietary | ❌ |
| Portable across clouds | ✅ Standard K8s API | ❌ AWS-only | ❌ AWS-only |
| Long-running services | ✅ | ✅ | ⚠️ 15 min limit |
| Minimal ops overhead | Medium | Low | Lowest |
| GPU/ML workloads | ✅ Best support | Limited | ❌ |
| Complex networking | ✅ Full control | Medium | Limited |
| Team has K8s expertise | Required | Not required | Not required |
| Model | Description | Operational Overhead | Use When |
|---|---|---|---|
| EKS Standard | Full control over nodes, add-ons, networking | Medium-High | Need full customization |
| EKS Auto Mode | AWS manages nodes, add-ons, scaling | Low | Want minimal ops, standard workloads |
| EKS with Fargate | Serverless pods, per-pod billing | Low | Batch, low-density workloads |
| EKS on Outposts | Run EKS on-premises | High | Data residency, low-latency edge |
| EKS Anywhere | EKS on your own infrastructure | Highest | Air-gapped, custom hardware |
| Component | AWS Manages | You Manage |
|---|---|---|
| Control plane | API server, etcd, HA, patching | RBAC, admission control, audit logging |
| Data plane (MNG) | AMI updates, node health | Instance type, scaling, pod scheduling |
| Data plane (Fargate) | Everything | Pod spec, resource requests |
| Data plane (Auto Mode) | Node lifecycle, OS patching | Workload definitions |
| Networking | ENI attachment, VPC CNI releases | Subnet design, IP planning, ingress |
| Security | Control plane auth | IAM, pod security, secrets, network policies |
| Factor | Fargate | MNG | Karpenter | Auto Mode | Self-Managed |
|---|---|---|---|---|---|
| Best for | Batch, small scale | Stable, predictable | Dynamic, varied | Minimal ops | Custom AMI/kernel |
| Scaling | Per-pod | ASG-based | Fast, flexible | AWS-managed | Manual ASG |
| Spot support | ❌ | ✅ | ✅ Native | ✅ | ✅ |
| GPU support | ❌ | ✅ | ✅ | ✅ | ✅ |
| DaemonSets | ❌ | ✅ | ✅ | ✅ | ✅ |
| Cost model | Per vCPU/GB/hr | Per EC2 instance | Per EC2 instance | Per EC2 instance | Per EC2 instance |
| Max pods/node | 1 | ENI-based | ENI-based | AWS-managed | ENI-based |
| Node SSH | ❌ | ✅ | ✅ | ❌ | ✅ |
| Operational | Lowest | Low | Low | Lowest | Highest |
✅ DO:
❌ DON'T:
| Mode | Use When | Pod Density |
|---|---|---|
| Secondary IP (default) | Most workloads, simple setup | Limited by ENI × IPs per ENI |
| Prefix Delegation | >30 pods/node, IP-constrained VPC | 4-16× more pods per node |
| Custom Networking | Pods need different CIDR than nodes | Same as underlying mode |
| Pattern | Best For | Key Feature |
|---|---|---|
| ALB (via LBC) | HTTP/HTTPS web apps | Native WAF, Cognito auth |
| NLB (via LBC) | TCP/UDP, gRPC, low latency | Static IPs, source IP preservation |
| Gateway API | Multi-team, new deployments | ✅ Recommended standard |
| VPC Lattice | Cross-VPC service-to-service | No sidecar, IAM auth |
| Factor | IPv4 | IPv6 |
|---|---|---|
| Default choice | ✅ Yes | When facing IP exhaustion |
| AWS service support | Full | Most (check specific services) |
| Complexity | Standard | Requires dual-stack VPC |
For detailed networking guidance, see: Networking — VPC CNI & IP | Networking — Ingress & DNS
| Approach | Use When | Setup |
|---|---|---|
| Pod Identity | ✅ New workloads (EKS 1.24+) | EKS add-on + association |
| IRSA | Older clusters, Fargate | OIDC provider + trust policy |
Key rules:
Apply Pod Security Admission (PSA) labels to all namespaces:
# Minimum: enforce baseline, warn on restricted
metadata:
labels:
pod-security.kubernetes.io/enforce: baseline
pod-security.kubernetes.io/warn: restricted| Approach | Complexity | Best For |
|---|---|---|
| External Secrets Operator | Medium | ✅ GitOps workflows |
| Secrets Store CSI | Medium | Mount secrets as volumes |
| KMS envelope encryption | Low | Encrypt etcd secrets |
Always enable KMS envelope encryption for Kubernetes secrets.
For detailed security guidance, see: Security Reference | Runtime & Network | Supply Chain & Compliance
Create PDBs for every production workload with >1 replica:
| Workload | Recommended PDB |
|---|---|
| Stateless (3+ replicas) | minAvailable: "50%" |
| Stateful quorum (3) | maxUnavailable: 1 |
| Batch/job | maxUnavailable: "50%" |
| Singleton | No PDB (would block all disruptions) |
| Probe | Purpose | Key Rule |
|---|---|---|
| Startup | Wait for slow init | Use for apps >10s startup |
| Readiness | Traffic routing | ✅ Check dependencies here |
| Liveness | Detect deadlocks | ❌ Never check dependencies |
Critical rule: Liveness probes must NOT check external dependencies. If the database goes down and liveness checks the DB, ALL pods restart — causing cascading failure.
spec:
terminationGracePeriodSeconds: 60
containers:
- lifecycle:
preStop:
exec:
command: ["/bin/sh", "-c", "sleep 15"]Why sleep 15: Gives kube-proxy and load balancer time to remove the pod from traffic routing before SIGTERM.
topologySpreadConstraints:
- maxSkew: 1
topologyKey: topology.kubernetes.io/zone
whenUnsatisfiable: DoNotScheduleFor detailed reliability guidance, see: Reliability & Resiliency — Core (see also reliability-advanced.md for DR, deployment strategies, and large-cluster guidance)
1. Control Plane → 2. EKS Add-ons → 3. Data Plane → 4. Custom Add-ons| Factor | In-Place | Blue-Green |
|---|---|---|
| Risk | Low-Medium | Lowest |
| Cost | No extra | 2× during migration |
| Rollback | ❌ No CP rollback | ✅ Switch back |
| Use when | ✅ Most upgrades | Critical workloads |
Karpenter automatically replaces nodes via drift detection after control plane upgrade. Control the speed with disruption.budgets:
disruption:
budgets:
- nodes: "10%" # Max 10% of nodes replaced at a timeFor detailed upgrade guidance, see: Cluster Upgrades Reference
| Karpenter | Cluster Autoscaler | Auto Mode | |
|---|---|---|---|
| Default choice | ✅ Yes | Legacy/Outposts | Minimal ops |
| Scale-up speed | ~30s | ~60-90s | AWS-managed |
| Consolidation | ✅ Built-in | ❌ | ✅ |
| Customization | High | Medium | Low |
| Scaler | Trigger | Use Case |
|---|---|---|
| HPA | CPU, memory, custom | Stateless services |
| VPA | Historical usage | Right-sizing (recommendation mode) |
| KEDA | External events (SQS, Kafka) | Event-driven workloads |
For detailed autoscaling guidance, see: Autoscaling Reference | Karpenter Reference
Based on terraform-aws-modules/terraform-aws-eks.
| Starting Point | Recommended Example |
|---|---|
| General production | karpenter (MNG for system + Karpenter for workloads) |
| Minimal ops | eks-auto-mode |
| Managed nodes | eks-managed-node-group (AL2023 or Bottlerocket) |
| Full node control | self-managed-node-group |
| Platform capabilities | eks-capabilities (ArgoCD, ACK, KRO) |
| Hybrid/edge | eks-hybrid-nodes |
Private cluster with Karpenter:
VPC (3 AZs, terraform-aws-modules/vpc/aws)
├── Private subnets → EKS nodes (MNG for system, Karpenter for workloads)
├── Public subnets → ALB (internet-facing)
├── Intra subnets → EKS control plane ENIs
└── NAT Gateway → 1 per AZ for productionMulti-tenant platform:
EKS Cluster (terraform-aws-modules/eks/aws)
├── kube-system (platform: CoreDNS, kube-proxy, VPC CNI)
├── karpenter (Karpenter controller on MNG)
├── monitoring (shared: Prometheus, Grafana)
├── ingress (shared: AWS LBC)
├── team-a namespace (RBAC, NetworkPolicy, ResourceQuota)
├── team-b namespace (RBAC, NetworkPolicy, ResourceQuota)
└── team-c namespace (RBAC, NetworkPolicy, ResourceQuota)For detailed examples and terraform patterns, see: Terraform Examples Reference
| Action | Savings | Effort |
|---|---|---|
| Graviton (arm64) | 20-40% | Low |
| Spot for non-critical | 60-90% | Low |
| Karpenter consolidation | 20-30% | Low |
| VPA right-sizing | 15-30% | Medium |
| gp3 over gp2 | 20% on EBS | Low |
| VPC endpoints | Eliminate NAT costs | Low |
For detailed cost guidance, see: Cost Optimization Reference | For scalability guidance, see: Scalability Reference
| Pillar | AWS-Managed | Open Source |
|---|---|---|
| Metrics | Container Insights | AMP + Grafana |
| Logs | CloudWatch Logs | OpenSearch, Loki |
| Traces | X-Ray | ADOT + Jaeger/Tempo |
Essential: Enable EKS audit logging and GuardDuty EKS Runtime Monitoring for security visibility.
For detailed observability guidance, see: Observability Reference
EKS Capabilities are AWS-managed features installed and updated as part of the EKS platform. They run in AWS-owned infrastructure separate from your clusters, with AWS handling scaling, patching, and upgrading.
| Capability | What It Does | When to Use Managed | When to Self-Manage |
|---|---|---|---|
| ArgoCD | GitOps continuous delivery | Multi-account hub-and-spoke, IAM IDC integration, minimal ops | Custom plugins, air-gapped, existing ArgoCD investment |
| ACK | Manage AWS resources via K8s CRDs (S3, RDS, IAM, etc.) | Standard AWS resource management | Specific controller version pinning, custom config |
| KRO | Platform abstractions via ResourceGroupDefinitions | Golden path templates, multi-resource compositions | Early adoption risk concerns, custom reconciliation logic |
Combined pattern: ArgoCD deploys ACK resources + KRO compositions via GitOps, providing a single workflow for both infrastructure and applications.
For detailed ArgoCD patterns, see: ArgoCD Patterns Reference
Sources:
This skill uses progressive disclosure — essential guidance is in this main file, detailed reference material is loaded on demand:
How to use: When you need detailed information on a topic, reference the appropriate guide. Claude will load it on demand.
© aws-samples, MIT-0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 17 other files (references) in .kiro/skills/eks-best-practices of aws-samples/appmod-blueprints.
Open the folder on GitHubat commit 42ea29c
Eks Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Eks Best Practices this skillaws-samples/appmod-blueprints | 113 | — | ~5k | Automated safety check: Pass | MIT-0 | |
| Cloud Devopsdavila7/claude-code-templates | 32k | 4 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Iac Securityhardw00t/ai-security-arsenal | 104 | — | ~2.4k | Automated safety check: Pass | None | |
| Agent Bom Scan InfraLeoYeAI/openclaw-master-skills | 2.2k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Discover Infrarand/cc-polymath | 181 | — | ~783 | Automated safety check: Pass | MIT | |
| Platform Engineeringmagnus919/agent-skills | 113 | — | ~2.4k | Automated safety check: Pass | MIT |
davila7/claude-code-templates
Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.
hardw00t/ai-security-arsenal
Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.
LeoYeAI/openclaw-master-skills
Scan infrastructure-as-code, cloud configurations, and find secrets.
rand/cc-polymath
Automatically discover cloud, infrastructure, deployment, and container skills when working with AWS, GCP, Azure, Docker, Kubernetes, Terraform, Netlify, Heroku, serverless, or IaC
magnus919/agent-skills
A skill your agent uses when building or operating internal developer platforms: infrastructure as code, CI/CD, container orchestration, service networking, secrets, and observability, or when…
Yikai-Liao/symusic
Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.
aws-samples/appmod-blueprints
Systematic troubleshooting for the PEEKS workshop platform — EKS clusters, Terraform state, ingress, load balancers, MCP tool failures, YAML validation.
aws-samples/appmod-blueprints
EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints.
aws-samples/appmod-blueprints
Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts.
aws-samples/appmod-blueprints
Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…
aws-samples/appmod-blueprints
A skill your agent uses whenever someone is designing or building an Internal Developer Platform (IDP) or doing platform engineering on Amazon EKS — phrased as "build a developer platform"…
aws-samples/appmod-blueprints
A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…
Categories
Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning. Eks Best Practices is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.
Eks Best Practices fits situations like: any EKS planning; architectural judgment call; even when phrased casually; generating documents.
Run `npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a claude-code`. Or copy the skill folder (.kiro/skills/eks-best-practices in aws-samples/appmod-blueprints) into .claude/skills/eks-best-practices in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a codex`. Or copy the skill folder (.kiro/skills/eks-best-practices in aws-samples/appmod-blueprints) into .agents/skills/eks-best-practices in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/appmod-blueprints --skill eks-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eks-best-practices, .gemini/skills/eks-best-practices, .github/skills/eks-best-practices and .opencode/skills/eks-best-practices in your project.
SKILL.md names no scripts, command-line tools or credentials: Eks Best Practices is instructions for the agent only.
SKILL.md names 3 domains. As links in the text: github.com, docs.aws.amazon.com and aws.amazon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Eks Best Practices is published under the MIT-0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 80k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Eks Best Practices: Cloud Devops (davila7/claude-code-templates, 32k stars), Iac Security (hardw00t/ai-security-arsenal, 104 stars), Agent Bom Scan Infra (LeoYeAI/openclaw-master-skills, 2.2k stars) and Discover Infra (rand/cc-polymath, 181 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/appmod-blueprints, which has 113 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 7, 2026.
Source: aws-samples/appmod-blueprints on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.