Official agent skill

Arc Region Switch

by aws in aws/agent-toolkit-for-aws

Answers questions about Amazon Application Recovery Controller (ARC) Region switch including architecture, plans, execution blocks, workflows, triggers, active/active vs active/passive…

OfficialApache-2.0Auto-check passedMarketing & SEO

Install Arc Region Switch

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill arc-region-switch -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws arc-region-switch --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/resilience-skills/arc-region-switch .claude/skills/arc-region-switch && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
arc-region-switch
GitHub stars
2.8k
Token cost
~3.4k tokens
SKILL.md length
1,603 words
Files
3 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Answers questions about Amazon Application Recovery Controller (ARC) Region switch including architecture, plans, execution blocks, workflows, triggers, active/active vs active/passive…

  • Works in 4 steps: Classify the question: technical… → Answer from embedded knowledge in this… → If the knowledge base is insufficient,… → …
  • Tasks that involve Positioning and messaging
  • SKILL.md covers Overview, Guardrail — where this skill's…, When Not to Use and Terminology Constraints, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Arc Region Switch is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Answers questions about Amazon Application Recovery Controller (ARC) Region switch including architecture, plans, execution blocks, workflows, triggers, active/active vs active/passive, cross-account support, recovery time, dashboards, and customer positioning. Applicable when users ask about ARC Region switch adoption, design, or troubleshooting.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/doc-links.md` and `references/positioning.md`).

It sits in Marketing & SEO, covering Positioning and messaging. It works with Amazon Web Services and Amazon DynamoDB. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Positioning and messaging

Example prompts

  • “Use the arc-region-switch skill to answer questions about Amazon Application Recovery Controller (ARC) Region switch including architecture, plans…”
  • “/arc-region-switch”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Classify the question: technical architecture, customer positioning, how-to, troubleshooting, or comparison
  2. Answer from embedded knowledge in this skill
  3. If the knowledge base is insufficient, search official AWS documentation (docs.aws.amazon.com)
  4. Format the response for the audience (engineer, SA, customer)

What it can do on your machine

Read from SKILL.md and the folder at commit 188af2f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Arc Region Switch loads about 3.4k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 1,603 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit 188af2f, republished under its Apache-2.0 licence (© aws). 1,603 words, ~3,420 tokens.

Download SKILL.mdSave it as .claude/skills/arc-region-switch/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
arc-region-switch
description
Answers questions about Amazon Application Recovery Controller (ARC) Region switch including architecture, plans, execution blocks, workflows, triggers, active/active vs active/passive, cross-account support, recovery time, dashboards, and customer positioning. Applicable when users ask about ARC Region switch adoption, design, or troubleshooting.
version
1

ARC Region switch Expert

Overview

Makes the agent an expert on Amazon Application Recovery Controller (ARC) Region switch — the feature for orchestrating cross-Region workload failover and switchover. Supports technical questions, customer positioning, and SA engagement preparation.

Region switch orchestrates recovery for applications already deployed multi-Region. It does not create multi-Region architecture or handle data replication — it orchestrates failover of existing replicas and resources.

Guardrail — where this skill's own files live (MCP vs local install)

Before reading a reference file, determine how this skill was loaded:

  • Loaded via the AWS MCP retrieve_skill tool: the skill's reference files are not on the local filesystem. Fetch each one through retrieve_skill with the file parameter (e.g. file="references/positioning.md" or file="references/doc-links.md") — do NOT file_read these paths locally or search the filesystem for them.
  • Installed locally (e.g. .kiro/skills/arc-region-switch/ or ~/.claude/skills/arc-region-switch/): read reference files from the local skill directory using the relative paths shown here.

This applies only to the skill's own reference files; always read and write user or session data in the working directory, never through retrieve_skill.

When Not to Use

  • In-Region failover — Region switch is for cross-Region recovery only. Use AZ-level mechanisms (ALB, Auto Scaling) for in-Region resilience.
  • Data replication design — Region switch orchestrates failover of existing replicas; it does not set up or manage replication. Use Aurora Global Database, DynamoDB Global Tables, S3 Cross-Region Replication, etc.
  • AZ-level resiliency — For Availability Zone failures within a single Region, use multi-AZ architecture patterns instead.

Terminology Constraints

  • ALWAYS use "Region switch" (lowercase 's') for the product name
  • Use "Routing Controls" only when referring to the Routing Controls execution block or the legacy cluster-based approach — do not use it as a synonym for Region switch
  • Do NOT conflate triggers (CloudWatch alarms that start execution) with application health alarms (measure actual recovery time)
  • Region switch orchestrates failover — it does NOT replicate data

Critical Warnings

  • Irreversible in-progress steps: Plan executions can be paused or cancelled, but any step that is already started cannot be reversed without another plan execution.
  • Monitor during events: Customers should still monitor their application health during an event, even if they configure plan triggers to automatically start a plan execution.
  • Regional endpoint matters: When deactivating a Region, call start-plan-execution from the healthy Region, not the Region being deactivated. When activating a Region, call from the Region being activated. See StartPlanExecution API.

Workflow

  1. Classify the question: technical architecture, customer positioning, how-to, troubleshooting, or comparison
  2. Answer from embedded knowledge in this skill
  3. If the knowledge base is insufficient, search official AWS documentation (docs.aws.amazon.com)
  4. Format the response for the audience (engineer, SA, customer)

Always validate:

  • Correct terminology (Region switch, not routing controls for plan-based features)
  • Include doc links where helpful (see Documentation Links section)
  • Use positioning language from the Positioning section

Architecture

Components
ComponentDescription
PlanTop-level resource scoped to a multi-Region application. Contains workflows.
Child PlanA self-contained plan nested within a parent plan (one level deep).
WorkflowOrdered sequence of steps within a plan. Defines activation/deactivation logic.
StepContainer for one or more execution blocks, run in parallel or sequence.
Execution BlockPerforms a specific recovery action (e.g., scale up, reroute traffic, failover DB).
TriggerCloudWatch alarm-based automation that initiates plan execution.
Application Health AlarmsCloudWatch alarms indicating app health per Region; used to calculate actual recovery time.
Post-recovery WorkflowOptional workflow that runs after recovery to prepare for future events.
Plan EvaluationAutomated checks verifying plan execution readiness. Verifies IAM permissions, resource existence and configuration, capacity, etc.
Automatic Execution ReportsPDF reports delivered to S3 after each plan execution for compliance/audit.
Execution Modes

Recommend using graceful execution unless not possible (e.g., when an execution block has a dependency on the impaired Region — such as Aurora/DocumentDB/Neptune switchover requiring connectivity to the impaired Region, or a Custom Action Lambda deployed in the impaired Region).

  • Graceful: Runs all steps in orderly sequence. Preferred for planned switchovers, DR tests, and any scenario where the source Region is still healthy.
  • Ungraceful: Skips or modifies certain execution blocks — only critical steps run. Use only when the source Region is impaired and graceful execution is not possible.
  • Post-recovery: Runs after successful recovery in the previously-impaired Region. Requires both Regions to be healthy. Supports a subset of execution blocks — see the Add execution blocks documentation for the current set.
Active/Passive vs Active/Active
ApproachWorkflows NeededBehavior
Active/Passive1 activation workflow (either Region) OR 2 separate activation workflows (one per Region)Failover from primary to standby; failback when primary recovers
Active/Active1 activation workflow + 1 deactivation workflow per RegionShift-away from impaired Region + return when healthy
Supported Execution Blocks

Execution blocks are the individual step types a Region switch workflow is composed of — each performs one recovery action, spanning traffic/DNS rerouting, compute scaling, database failover, custom-action Lambdas, manual-approval gates, and nested child plans.

Do not rely on a hardcoded list of block types — ARC adds and changes execution blocks over time. Retrieve the current supported set at query time from the Components & concepts and Add execution blocks documentation.

Recovery Time Tracking
  • Recovery Time Objective (RTO): Set when creating a plan
  • Actual Recovery Time: Plan execution time + time for application health alarms to return to green
  • Visible on plan execution details page for comparison against RTO
Plan Evaluation
  • Validates: IAM permissions, resource configurations, running capacity
  • Warnings surfaced in console, EventBridge, and API
  • Passing evaluation alone is NOT sufficient — always test by executing plans
Automatic Execution Reports
  • PDF reports generated after each plan execution
  • Delivered to customer-specified S3 bucket (within ~30 min)
  • Customers must configure the S3 bucket and update permissions for the PlanExecutionRole to enable reporting
  • Contents: executive summary, plan config, execution timeline, resource states, alarm history, child plan details, glossary
  • Useful for regulatory compliance and DR audit evidence
  • See Security Considerations for encryption and access control guidance
Show full SKILL.md (648 more words)Show less

Cross-Account Support

Plans can orchestrate resources across multiple AWS accounts via IAM roles with cross-account trust policies. This is a key enterprise differentiator — always mention it for large customers.

When configuring cross-account trust policies:

  • Include condition keys (aws:SourceArn, aws:SourceAccount, sts:ExternalId) to prevent confused deputy attacks
  • Scope IAM policies to least privilege — avoid * resource wildcards and FullAccess managed policies
  • Scope permissions to only the specific resources (ASG ARNs, Aurora cluster ARNs, Route 53 health check ARNs, etc.) referenced in execution blocks

Regional Availability

Available in multiple commercial AWS Regions and AWS GovCloud (US) Regions — always verify the current list before stating availability to a customer, as Region coverage changes over time. Each Region has its own data-plane endpoint (arc-region-switch.<region>.api.aws), ensuring execution doesn't depend on the impaired Region.

Verify the complete list of available regions/endpoints at AWS Regions & endpoints.

Security Considerations

IAM Least Privilege
  • Scope cross-account IAM roles to only the specific resources referenced in execution blocks (ASG ARNs, Aurora cluster ARNs, Route 53 health check ARNs, Lambda function ARNs, etc.)
  • Avoid * resource wildcards and FullAccess managed policies
  • Include condition keys (aws:SourceArn, aws:SourceAccount, sts:ExternalId) in cross-account trust policies to prevent confused deputy attacks
Execution Reports S3 Bucket
  • Enable default encryption (SSE-KMS preferred) on the reports S3 bucket
  • Add a bucket policy denying requests where aws:SecureTransport is false (enforce TLS)
  • Restrict bucket access to authorized personnel only — reports contain sensitive infrastructure details (plan config, execution timeline, resource states, alarm history)
  • Enable S3 bucket versioning and MFA Delete for tamper protection
  • Ensure the bucket is not publicly accessible
Custom Action Lambda Security
  • Apply least-privilege execution roles to Custom Action Lambda functions
  • Validate inputs within Lambda functions
  • Do not embed secrets in Lambda environment variables — use Secrets Manager or Parameter Store
Notification & Event Targets
  • Restrict EventBridge rule targets (SNS topics, Lambda functions, etc.) that receive plan-evaluation warnings and execution events to authorized recipients only
  • Lock down SNS topic subscription policies and Lambda resource policies so sensitive infrastructure details (plan configuration, resource ARNs, execution state) are not exposed to unauthorized parties
Logging and Monitoring
  • Enable AWS CloudTrail for auditing all ARC Region switch API calls
  • Configure CloudWatch alarms for unexpected or unauthorized plan executions
  • Enable S3 access logging on the execution reports bucket
  • See Logging and monitoring for Region switch

Positioning

Customer-facing framing, the Region switch vs Routing Controls comparison, analyst talking points, and per-audience conversation guidance are maintained in Positioning. Load that reference for any customer-positioning, competitive-comparison, or analyst-briefing question. Key rules that always apply:

  • Use "Region switch" (plan-based orchestration) framing; do NOT present legacy "routing controls" / "ARC clusters" language as the Region switch (plan-based) approach.
  • Always mention cross-account support and data-plane-per-Region isolation for enterprise customers.

The curated documentation index and the "when to link which doc" guidance live in Documentation Links. Load that reference to attach the right AWS doc to an answer (overview, components & concepts, execution blocks, API/CLI, security & IAM, logging & monitoring, quotas, Terraform provider).

Troubleshooting

Customer confuses triggers with health alarms

Triggers are CloudWatch alarms that start plan execution. Application health alarms measure when recovery is complete. They serve different purposes and are configured separately.

Customer assumes Region switch handles data sync

Clarify: Region switch orchestrates failover of existing replicas (e.g., Aurora Global DB promotion). The customer must set up multi-Region data replication independently.

Cross-account execution fails

Usually missing IAM permissions. Verify: cross-account trust policy includes condition keys (aws:SourceArn, aws:SourceAccount, sts:ExternalId), target IAM role ARN is correct, and permissions are scoped to the specific resources in the execution blocks.

Plan evaluation warnings

Warnings indicate IAM, resource, or capacity issues. Fix the underlying issue — but note that passing evaluation alone isn't sufficient; always test by executing plans.

Wrong Regional endpoint used

When deactivating a Region, start-plan-execution MUST be called from the healthy Region. When activating a Region, it MUST be called from the Region being activated. Using the wrong endpoint will fail or produce unexpected behavior. See StartPlanExecution API.

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/specialized-skills/resilience-skills/arc-region-switch of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/doc-links.md
  • references/positioning.md

Open the folder on GitHubat commit 188af2f

Compare with similar skills

Arc Region Switch next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Arc Region Switch compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Arc Region Switch this skillaws/agent-toolkit-for-aws2.8k—~3.4kAutomated safety check: PassApache-2.0
Implementdynamodb-toolbox/dynamodb-toolbox2k—~1.8kAutomated safety check: PassMIT
Plandynamodb-toolbox/dynamodb-toolbox2k—~1.5kAutomated safety check: PassMIT
Specdynamodb-toolbox/dynamodb-toolbox2k—~1.2kAutomated safety check: PassMIT
Dynamodbitsmostafa/aws-agent-skills1.2k—~2.5kAutomated safety check: PassMIT
AWS Cloud Patternsrohitg00/awesome-claude-code-toolkit2.7k—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Implement

    dynamodb-toolbox/dynamodb-toolbox

    Implement a planned DynamoDB-Toolbox feature end-to-end and open a pull request.

    2k GitHub stars~1.8k tokensUpdated 5 days ago
    DatabasesAuto-check passed
  • Plan

    dynamodb-toolbox/dynamodb-toolbox

    Write the technical implementation strategy for a spec'd DynamoDB-Toolbox task.

    2k GitHub stars~1.5k tokensUpdated 5 days ago
    DatabasesAuto-check passed
  • Spec

    dynamodb-toolbox/dynamodb-toolbox

    Formalise a product spec for a DynamoDB-Toolbox task — interview, codebase analysis, and Notion write-back.

    2k GitHub stars~1.2k tokensUpdated 5 days ago
    DatabasesAuto-check passed
  • Dynamodb

    itsmostafa/aws-agent-skills

    AWS DynamoDB NoSQL database for scalable data storage. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub stars~2.5k tokensUpdated 2 days ago
    DatabasesAuto-check passed
  • AWS Cloud Patterns

    rohitg00/awesome-claude-code-toolkit

    AWS cloud patterns for Lambda, ECS, S3, DynamoDB, and Infrastructure as Code with CDK/Terraform

    2.7k GitHub stars~1.1k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Ak Dev New Multimodal Storage

    yaalalabs/agent-kernel

    Step-by-step guide for adding a new multimodal attachment storage backend to Agent Kernel.

    191 GitHub stars~4.3k tokensUpdated today
    DatabasesAuto-check passed

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Questions about Arc Region Switch

What does Arc Region Switch do?

Answers questions about Amazon Application Recovery Controller (ARC) Region switch including architecture, plans, execution blocks, workflows, triggers, active/active vs active/passive…. Arc Region Switch is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Answers questions about Amazon Application Recovery Controller (ARC) Region switch including architecture, plans, execution blocks, workflows, triggers, active/active vs active/passive, cross-account support, recovery time, dashboards, and customer positioning.

When should I use Arc Region Switch?

Arc Region Switch fits situations like: tasks that involve Positioning and messaging.

How do I install Arc Region Switch in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill arc-region-switch -a claude-code`. Or copy the skill folder (skills/specialized-skills/resilience-skills/arc-region-switch in aws/agent-toolkit-for-aws) into .claude/skills/arc-region-switch in your project. Claude Code loads it when a task matches its description.

How do I install Arc Region Switch in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill arc-region-switch -a codex`. Or copy the skill folder (skills/specialized-skills/resilience-skills/arc-region-switch in aws/agent-toolkit-for-aws) into .agents/skills/arc-region-switch in your project. Codex loads it when a task matches its description.

Can I use Arc Region Switch in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill arc-region-switch -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/arc-region-switch, .gemini/skills/arc-region-switch, .github/skills/arc-region-switch and .opencode/skills/arc-region-switch in your project.

What does Arc Region Switch need to run?

SKILL.md names no scripts, command-line tools or credentials: Arc Region Switch is instructions for the agent only.

Does Arc Region Switch access the network?

SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Arc Region Switch safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Arc Region Switch use?

Arc Region Switch is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Arc Region Switch use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Arc Region Switch?

Skills that share tags, products or a category with Arc Region Switch: Implement (dynamodb-toolbox/dynamodb-toolbox, 2k stars), Plan (dynamodb-toolbox/dynamodb-toolbox, 2k stars), Spec (dynamodb-toolbox/dynamodb-toolbox, 2k stars) and Dynamodb (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Arc Region Switch?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,825 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.