Agent skill

AWS Cloudformation Ec2

by giuseppe-trisciuoglio in giuseppe-trisciuoglio/developer-kit

Provides AWS CloudFormation patterns for EC2 instances, Security Groups, IAM roles, and load balancers.

MITAuto-check: notesDevOps & Cloud

Install AWS Cloudformation Ec2

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-ec2 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit aws-cloudformation-ec2 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-ec2 .claude/skills/aws-cloudformation-ec2 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-cloudformation-ec2
GitHub stars
357
Token cost
~2.5k tokens
SKILL.md length
556 words
Files
9 (incl. references)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides AWS CloudFormation patterns for EC2 instances, Security Groups, IAM roles, and load balancers.

  • Works in 6 steps: Define Template Parameters → Create Security Group → Configure IAM Role → …
  • Creating EC2 instances
  • SKILL.md covers Overview, When to Use, Instructions and Examples, plus 3 more sections
  • Calls aws

What it does

AWS Cloudformation Ec2 is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides AWS CloudFormation patterns for EC2 instances, Security Groups, IAM roles, and load balancers. Use when creating EC2 instances, SPOT instances, Security Groups, IAM roles for EC2, Application Load Balancers (ALB), Target Groups, and implementing template structure with Parameters, Outputs, Mappings, Conditions, and cross-stack references.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `references/best-practices.md`, `references/constraints.md` and `references/ec2-instances.md`).

It sits in DevOps & Cloud, covering Cloud networking. It works with AWS CloudFormation and Amazon Web Services. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • Creating EC2 instances
  • Security Groups
  • IAM roles for EC2
  • Application Load Balancers (ALB)

Example prompts

  • “Use the aws-cloudformation-ec2 skill to provide AWS CloudFormation patterns for EC2 instances, Security Groups, IAM roles, and load balancers”
  • “/aws-cloudformation-ec2”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Bash

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Define Template Parameters
  2. Create Security Group
  3. Configure IAM Role
  4. Launch EC2 Instance
  5. Add Application Load Balancer
  6. Define Outputs

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Cloudformation Ec2 loads about 2.5k tokens when it runs, and up to ~30k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 556 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~30k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 556 words, ~2,486 tokens.

Download SKILL.mdSave it as .claude/skills/aws-cloudformation-ec2/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
aws-cloudformation-ec2
description
Provides AWS CloudFormation patterns for EC2 instances, Security Groups, IAM roles, and load balancers. Use when creating EC2 instances, SPOT instances, Security Groups, IAM roles for EC2, Application Load Balancers (ALB), Target Groups, and implementing template structure with Parameters, Outputs, Mappings, Conditions, and cross-stack references.
allowed-tools
Read, Write, Bash

AWS CloudFormation EC2 Infrastructure

Overview

Create production-ready EC2 infrastructure using AWS CloudFormation templates. Covers EC2 instances (On-Demand and SPOT), Security Groups, IAM roles, Application Load Balancers (ALB), template structure, parameters, outputs, and cross-stack references.

When to Use

  • Creating EC2 instances (On-Demand or SPOT) with Security Groups and IAM roles
  • Setting up Application Load Balancers with target groups
  • Implementing template Parameters, Mappings, Conditions, and cross-stack references

Instructions

Step 1 — Define Template Parameters

Use AWS-specific parameter types for validation and console dropdowns.

yaml
Parameters:
  LatestAmiId:
    Type: AWS::SSM::Parameter::Value<AWS::EC2::Image::Id>
    Default: /aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2

  InstanceType:
    Type: AWS::EC2::InstanceType
    Default: t3.micro
    AllowedValues: [t3.micro, t3.small, t3.medium]

  KeyName:
    Type: AWS::EC2::KeyPair::KeyName

See template-structure.md for advanced parameter patterns, mappings, conditions, and cross-stack references.

Step 2 — Create Security Group

Define ingress/egress rules for network access.

yaml
InstanceSecurityGroup:
  Type: AWS::EC2::SecurityGroup
  Properties:
    GroupDescription: Security group for EC2 instance
    VpcId: !Ref VpcId
    SecurityGroupIngress:
      - IpProtocol: tcp
        FromPort: 80
        ToPort: 80
        CidrIp: 0.0.0.0/0
      - IpProtocol: tcp
        FromPort: 22
        ToPort: 22
        CidrIp: 10.0.0.0/16

See security-iam.md for advanced security group patterns, self-references, and IAM roles.

Step 3 — Configure IAM Role

Define instance profile with least privilege permissions.

yaml
Ec2Role:
  Type: AWS::IAM::Role
  Properties:
    AssumeRolePolicyDocument:
      Version: "2012-10-17"
      Statement:
        - Effect: Allow
          Principal:
            Service: ec2.amazonaws.com
          Action: sts:AssumeRole
    ManagedPolicyArns:
      - arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore

Ec2InstanceProfile:
  Type: AWS::IAM::InstanceProfile
  Properties:
    Roles: [!Ref Ec2Role]

See security-iam.md for least privilege policies, SSM roles, and trust policies.

Step 4 — Launch EC2 Instance

Configure instance with security group, IAM role, and user data.

yaml
Ec2Instance:
  Type: AWS::EC2::Instance
  Properties:
    ImageId: !Ref LatestAmiId
    InstanceType: !Ref InstanceType
    KeyName: !Ref KeyName
    SecurityGroupIds: [!Ref InstanceSecurityGroup]
    IamInstanceProfile: !Ref Ec2InstanceProfile
    SubnetId: !Ref SubnetId
    UserData:
      Fn::Base64: |
        #!/bin/bash
        yum update -y
        yum install -y httpd
        systemctl start httpd
    Tags:
      - Key: Name
        Value: !Sub ${AWS::StackName}-instance

See ec2-instances.md for multi-volume configurations, detailed monitoring, SPOT instances, and complete stack examples.

Validate template: aws cloudformation validate-template --template-body file://template.yaml

Step 5 — Add Application Load Balancer

Create ALB with target group and listener for traffic distribution.

yaml
ApplicationLoadBalancer:
  Type: AWS::ElasticLoadBalancingV2::LoadBalancer
  Properties:
    Name: !Sub ${AWS::StackName}-alb
    Scheme: internet-facing
    SecurityGroups: [!Ref AlbSecurityGroup]
    Subnets: [!Ref PublicSubnet1, !Ref PublicSubnet2]

ApplicationTargetGroup:
  Type: AWS::ElasticLoadBalancingV2::TargetGroup
  Properties:
    Port: 80
    Protocol: HTTP
    VpcId: !Ref VpcId
    HealthCheckPath: /health

ApplicationListener:
  Type: AWS::ElasticLoadBalancingV2::Listener
  Properties:
    DefaultActions:
      - Type: forward
        TargetGroupArn: !Ref ApplicationTargetGroup
    LoadBalancerArn: !Ref ApplicationLoadBalancer
    Port: 80
    Protocol: HTTP

See load-balancers.md for HTTPS configuration, path-based routing, host-based routing, listener rules, and ALB attributes.

Step 6 — Define Outputs

Export values for cross-stack references.

yaml
Outputs:
  InstanceId:
    Description: EC2 Instance ID
    Value: !Ref Ec2Instance
    Export:
      Name: !Sub ${AWS::StackName}-InstanceId

  SecurityGroupId:
    Description: Security Group ID
    Value: !Ref InstanceSecurityGroup
    Export:
      Name: !Sub ${AWS::StackName}-SecurityGroupId

  LoadBalancerDnsName:
    Description: ALB DNS Name
    Value: !GetAtt ApplicationLoadBalancer.DNSName

See template-structure.md for cross-stack reference patterns and import/export strategies.

Examples

Minimal EC2 with ALB Template
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: EC2 instance with ALB

Parameters:
  LatestAmiId:
    Type: AWS::SSM::Parameter::Value<AWS::EC2::Image::Id>
    Default: /aws/service/ami-amazon-linux-latest/amzn2-ami-hvm-x86_64-gp2
  InstanceType:
    Type: AWS::EC2::InstanceType
    Default: t3.micro

Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Enable HTTP and SSH
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 0.0.0.0/0

  Ec2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: !Ref LatestAmiId
      InstanceType: !Ref InstanceType
      SecurityGroupIds: [!Ref InstanceSecurityGroup]

  LoadBalancer:
    Type: AWS::ElasticLoadBalancingV2::LoadBalancer
    Properties:
      Scheme: internet-facing
      SecurityGroups: [!Ref InstanceSecurityGroup]
      Subnets: [subnet-12345678, subnet-87654321]

Outputs:
  InstanceId:
    Value: !Ref Ec2Instance
  LoadBalancerDns:
    Value: !GetAtt LoadBalancer.DNSName
Deploy with Change Set
bash
# Create change set
aws cloudformation create-change-set \
  --stack-name my-ec2-stack \
  --template-body file://template.yaml \
  --change-set-type CREATE

# Execute after review
aws cloudformation execute-change-set \
  --change-set-name <change-set-name>

See examples.md for complete production-ready templates.

Best Practices

Template Structure
  • Use AWS-specific parameter types for validation (AWS::EC2::VPC::Id, AWS::EC2::InstanceType)
  • Organize by lifecycle - separate network, security, and application stacks
  • Use meaningful names with AWS::StackName prefix
  • Enable termination protection on production stacks
Security
  • Apply least privilege to IAM roles - grant minimum required permissions
  • Use security group references instead of IP addresses where possible
  • Enable IMDSv2 on all EC2 instances
  • Restrict security group rules to specific CIDR blocks
Cost & Availability
  • Use SPOT instances for fault-tolerant, interruptible workloads
  • Deploy across multiple AZs for high availability
  • Set up CloudWatch alarms for CPU and status checks
  • Use EBS gp3 volumes for cost-effective storage
Show full SKILL.md (221 more words)Show less
Operations
  • Always use change sets for production stack updates
  • Enable drift detection to maintain template compliance
  • Apply stack policies to protect critical resources
  • Validate templates before deployment with aws cloudformation validate-template

See best-practices.md for detailed guidance on stack policies, termination protection, drift detection, change set automation, and validation scripts.

References

Core Configuration
  • template-structure.md — Template sections, parameters, mappings, conditions, outputs, cross-stack references
  • ec2-instances.md — EC2 instances, SPOT fleets, multi-volume configurations, complete stack examples
  • security-iam.md — Security groups, IAM roles, instance profiles, least privilege policies
  • load-balancers.md — ALB configuration, target groups, listeners, path-based routing, HTTPS
Operational Guides
  • best-practices.md — Stack policies, termination protection, drift detection, change sets, validation
  • constraints.md — Resource limits, instance constraints, cost considerations, common issues, monitoring
Additional Resources
  • examples.md — Complete production-ready examples and use cases
  • reference.md — CloudFormation EC2 resource reference documentation

Constraints and Warnings

Resource Limits
  • Maximum 500 resources per CloudFormation stack
  • Maximum 500 security groups per VPC
  • Instance types vary by region/A availability
Cost Considerations
  • EC2 instances incur costs while running
  • EBS volumes charged per GB-month even when not attached
  • ALBs have hourly + LCU data processing costs
  • Unattached Elastic IPs incur hourly costs
Security Considerations
  • Key pairs cannot be recovered if lost
  • Instance profile roles cannot be changed after creation
  • IMDSv1 has security vulnerabilities - use IMDSv2
  • Spot instances can be terminated with 2-minute notice

See constraints.md for complete constraints, troubleshooting guides, and monitoring setup.

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (references) in plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-ec2 of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • references/best-practices.md
  • references/constraints.md
  • references/ec2-instances.md
  • references/examples.md
  • references/load-balancers.md
  • references/reference.md
  • references/security-iam.md
  • references/template-structure.md

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

AWS Cloudformation Ec2 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Cloudformation Ec2 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Cloudformation Ec2 this skillgiuseppe-trisciuoglio/developer-kit357—~2.5kAutomated safety check: NotesMIT
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
AWS Cloud Advisortech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0
Dangling DNS Finderanirudhbiyani/findmytakeover180—~1.8kAutomated safety check: PassGPL-3.0
AWS Native Runtime Investigationpulumi/pulumi-aws-native108—~753Automated safety check: PassApache-2.0
Cloudformationitsmostafa/aws-agent-skills1.2k—~2.5kAutomated safety check: PassMIT

Similar skills

  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Dangling DNS Finder

    anirudhbiyani/findmytakeover

    Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.

    180 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • AWS Native Runtime Investigation

    pulumi/pulumi-aws-native

    Official

    Use after triage or repository evidence establishes that an issue involves Pulumi AWS Native runtime behavior across the Pulumi provider protocol, generated CloudFormation metadata, and AWS Cloud…

    108 GitHub stars~753 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Cloudformation

    itsmostafa/aws-agent-skills

    AWS CloudFormation infrastructure as code for stack management.

    1.2k GitHub stars~2.5k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Hunt Bugs

    go-to-k/cdkd

    Proactively hunt for cdkd bugs by deploying real CDK apps that exercise common-but-untested AWS resources, configs, and CloudFormation notations against real AWS, then fix what breaks.

    146 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    357 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    357 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check: notes

Categories

Questions about AWS Cloudformation Ec2

What does AWS Cloudformation Ec2 do?

Provides AWS CloudFormation patterns for EC2 instances, Security Groups, IAM roles, and load balancers. AWS Cloudformation Ec2 is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides AWS CloudFormation patterns for EC2 instances, Security Groups, IAM roles, and load balancers.

When should I use AWS Cloudformation Ec2?

AWS Cloudformation Ec2 fits situations like: creating EC2 instances; security Groups; IAM roles for EC2; application Load Balancers (ALB).

How do I install AWS Cloudformation Ec2 in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-ec2 -a claude-code`. Or copy the skill folder (plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-ec2 in giuseppe-trisciuoglio/developer-kit) into .claude/skills/aws-cloudformation-ec2 in your project. Claude Code loads it when a task matches its description.

How do I install AWS Cloudformation Ec2 in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-ec2 -a codex`. Or copy the skill folder (plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-ec2 in giuseppe-trisciuoglio/developer-kit) into .agents/skills/aws-cloudformation-ec2 in your project. Codex loads it when a task matches its description.

Can I use AWS Cloudformation Ec2 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-ec2 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-cloudformation-ec2, .gemini/skills/aws-cloudformation-ec2, .github/skills/aws-cloudformation-ec2 and .opencode/skills/aws-cloudformation-ec2 in your project.

What does AWS Cloudformation Ec2 need to run?

Going by SKILL.md and its folder, AWS Cloudformation Ec2 needs the command-line tools its instructions call (aws). Its frontmatter pre-approves these tools: Read, Write, Bash.

Does AWS Cloudformation Ec2 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AWS Cloudformation Ec2 safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does AWS Cloudformation Ec2 use?

AWS Cloudformation Ec2 is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Cloudformation Ec2 use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 28k tokens, read only when the agent opens those files.

What are the alternatives to AWS Cloudformation Ec2?

Skills that share tags, products or a category with AWS Cloudformation Ec2: AWS Cdk Development (zxkane/aws-skills, 367 stars), AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars), Dangling DNS Finder (anirudhbiyani/findmytakeover, 180 stars) and AWS Native Runtime Investigation (pulumi/pulumi-aws-native, 108 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Cloudformation Ec2?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.