Agent skill

AWS Cloudformation Vpc

by giuseppe-trisciuoglio in giuseppe-trisciuoglio/developer-kit

Provides AWS CloudFormation patterns for VPC foundations, including subnets, route tables, internet and NAT gateways, endpoints, and reusable outputs.

MITAuto-check: notesDevOps & Cloud

Install AWS Cloudformation Vpc

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-vpc -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit aws-cloudformation-vpc --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-vpc .claude/skills/aws-cloudformation-vpc && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-cloudformation-vpc
GitHub stars
357
Token cost
~2.2k tokens
SKILL.md length
516 words
Files
3 (incl. references)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides AWS CloudFormation patterns for VPC foundations, including subnets, route tables, internet and NAT gateways, endpoints, and reusable outputs.

  • Works in 5 steps: Start with the address plan → Build the core network resources in layers → Parameterize only the… → …
  • Creating a new network baseline
  • SKILL.md covers Overview, When to Use, Instructions and Examples, plus 3 more sections
  • Calls aws

What it does

AWS Cloudformation Vpc is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides AWS CloudFormation patterns for VPC foundations, including subnets, route tables, internet and NAT gateways, endpoints, and reusable outputs. Use when creating a new network baseline, segmenting public and private workloads, or preparing CloudFormation networking stacks for application deployments.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/examples.md` and `references/reference.md`).

It sits in DevOps & Cloud, covering Cloud networking, Deployment and Infrastructure as code. It works with AWS CloudFormation. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • Creating a new network baseline
  • Segmenting public and private workloads
  • Preparing CloudFormation networking stacks for application deployments

Example prompts

  • “Use the aws-cloudformation-vpc skill to provide AWS CloudFormation patterns for VPC foundations, including subnets, route tables, internet and NAT…”
  • “/aws-cloudformation-vpc”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Bash

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Start with the address plan
  2. Build the core network resources in layers
  3. Parameterize only the environment-dependent values
  4. Export only what consumers really need
  5. Validate before deployment

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Cloudformation Vpc loads about 2.2k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 83 tokens; SKILL.md has 516 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~83
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 516 words, ~2,163 tokens.

Download SKILL.mdSave it as .claude/skills/aws-cloudformation-vpc/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
aws-cloudformation-vpc
description
Provides AWS CloudFormation patterns for VPC foundations, including subnets, route tables, internet and NAT gateways, endpoints, and reusable outputs. Use when creating a new network baseline, segmenting public and private workloads, or preparing CloudFormation networking stacks for application deployments.
allowed-tools
Read, Write, Bash

AWS CloudFormation VPC Infrastructure

Overview

Build a VPC foundation with CloudFormation that stays readable, reusable, and safe to evolve. Provides a clear subnet and routing model with predictable connectivity for public and private workloads, plus outputs that downstream stacks can consume without duplicating network logic.

Use the references/ files for larger templates and extended service combinations.

When to Use

  • Creating a new VPC stack for an application or shared platform
  • Adding public and private subnets across one or more Availability Zones
  • Wiring internet access, NAT egress, or private endpoints
  • Exporting VPC, subnet, route table, and security-group-adjacent identifiers for other stacks
  • Preparing reusable infrastructure for ECS, EKS, Lambda, EC2, or RDS stacks

Instructions

1. Start with the address plan

Before writing resources, define:

  • VPC CIDR range
  • Number of Availability Zones
  • Public, private, and isolated subnet ranges
  • Which workloads need internet ingress, NAT egress, or only private AWS service access

This prevents route-table sprawl and painful subnet replacement later.

2. Build the core network resources in layers

Create the stack in this order:

  1. VPC and subnets
  2. Internet Gateway for public ingress and egress
  3. NAT gateways if private subnets need outbound internet access
  4. Route tables and subnet associations
  5. Optional VPC endpoints for private access to AWS services

Keep each layer easy to inspect in the template and avoid mixing unrelated application resources into the same stack.

3. Parameterize only the environment-dependent values

Useful parameters include:

  • Environment name
  • VPC CIDR and subnet CIDRs
  • Number of AZs or explicit subnet IDs in nested-stack scenarios
  • Flags for optional endpoints or NAT layout

Do not parameterize every route or tag unless it meaningfully changes between environments.

4. Export only what consumers really need

Typical outputs:

  • VPC ID
  • Public, private, and isolated subnet IDs
  • Route table IDs when downstream stacks must attach routes
  • Security boundaries or prefix-list references only when another stack consumes them

Stable outputs make application stacks easier to compose and migrate.

Show full SKILL.md (195 more words)Show less
5. Validate before deployment

Run these commands to validate the template and verify routing:

bash
# Validate CloudFormation template syntax
aws cloudformation validate-template --template-body file://vpc.yaml

# Review change set before applying
aws cloudformation create-change-set \
  --stack-name my-vpc \
  --template-body file://vpc.yaml \
  --change-set-type CREATE

# Verify route table associations
aws ec2 describe-route-tables \
  --filters "Name=vpc-id,Values=<vpc-id>"

# Check subnet to route table mappings
aws ec2 describe-route-tables \
  --filters "Name=association.subnet-id,Values=<subnet-id>"

# Verify internet gateway attachment
aws ec2 describe-internet-gateways \
  --filters "Name=attachment.vpc-id,Values=<vpc-id>"

Examples

Example 1: Complete two-tier VPC with routing

This template creates a VPC with public and private subnets, internet gateway, NAT gateway, and properly configured route tables.

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: "Two-tier VPC with public and private subnets"

Resources:
  # VPC
  MainVpc:
    Type: AWS::EC2::VPC
    Properties:
      CidrBlock: 10.0.0.0/16
      EnableDnsHostnames: true
      EnableDnsSupport: true
      Tags:
        - Key: Name
          Value: !Sub "${AWS::StackName}-main"

  # Internet Gateway
  InternetGateway:
    Type: AWS::EC2::InternetGateway
    Properties:
      Tags:
        - Key: Name
          Value: !Sub "${AWS::StackName}-igw"

  # Attach IGW to VPC
  GatewayToInternet:
    Type: AWS::EC2::VPCGatewayAttachment
    Properties:
      VpcId: !Ref MainVpc
      InternetGatewayId: !Ref InternetGateway

  # Public Subnet (AZ 1)
  PublicSubnetA:
    Type: AWS::EC2::Subnet
    Properties:
      VpcId: !Ref MainVpc
      CidrBlock: 10.0.1.0/24
      AvailabilityZone: !Select [0, !GetAZs ""]
      MapPublicIpOnLaunch: true
      Tags:
        - Key: Name
          Value: !Sub "${AWS::StackName}-public-a"

  # Private Subnet (AZ 1)
  PrivateSubnetA:
    Type: AWS::EC2::Subnet
    Properties:
      VpcId: !Ref MainVpc
      CidrBlock: 10.0.11.0/24
      AvailabilityZone: !Select [0, !GetAZs ""]
      Tags:
        - Key: Name
          Value: !Sub "${AWS::StackName}-private-a"

  # Elastic IP for NAT Gateway
  NatEip:
    Type: AWS::EC2::EIP
    DependsOn: GatewayToInternet
    Properties:
      Domain: vpc

  # NAT Gateway
  NatGateway:
    Type: AWS::EC2::NatGateway
    Properties:
      SubnetId: !Ref PublicSubnetA
      AllocationId: !GetAtt NatEip.AllocationId

  # Public Route Table
  PublicRouteTable:
    Type: AWS::EC2::RouteTable
    Properties:
      VpcId: !Ref MainVpc
      Tags:
        - Key: Name
          Value: !Sub "${AWS::StackName}-public-rt"

  # Default route to IGW
  PublicDefaultRoute:
    Type: AWS::EC2::Route
    DependsOn: GatewayToInternet
    Properties:
      RouteTableId: !Ref PublicRouteTable
      DestinationCidrBlock: 0.0.0.0/0
      GatewayId: !Ref InternetGateway

  # Associate public subnet
  PublicSubnetARouteTableAssociation:
    Type: AWS::EC2::SubnetRouteTableAssociation
    Properties:
      SubnetId: !Ref PublicSubnetA
      RouteTableId: !Ref PublicRouteTable

  # Private Route Table
  PrivateRouteTable:
    Type: AWS::EC2::RouteTable
    Properties:
      VpcId: !Ref MainVpc
      Tags:
        - Key: Name
          Value: !Sub "${AWS::StackName}-private-rt"

  # Default route via NAT Gateway
  PrivateDefaultRoute:
    Type: AWS::EC2::Route
    Properties:
      RouteTableId: !Ref PrivateRouteTable
      DestinationCidrBlock: 0.0.0.0/0
      NatGatewayId: !Ref NatGateway

  # Associate private subnet
  PrivateSubnetARouteTableAssociation:
    Type: AWS::EC2::SubnetRouteTableAssociation
    Properties:
      SubnetId: !Ref PrivateSubnetA
      RouteTableId: !Ref PrivateRouteTable

Outputs:
  VpcId:
    Description: VPC ID
    Value: !Ref MainVpc
    Export:
      Name: !Sub "${AWS::StackName}-VpcId"

  PublicSubnetA:
    Description: Public subnet AZ1
    Value: !Ref PublicSubnetA
    Export:
      Name: !Sub "${AWS::StackName}-PublicSubnetA"

  PrivateSubnetA:
    Description: Private subnet AZ1
    Value: !Ref PrivateSubnetA
    Export:
      Name: !Sub "${AWS::StackName}-PrivateSubnetA"

  PublicRouteTableId:
    Description: Public route table ID
    Value: !Ref PublicRouteTable
    Export:
      Name: !Sub "${AWS::StackName}-PublicRouteTableId"

  PrivateRouteTableId:
    Description: Private route table ID
    Value: !Ref PrivateRouteTable
    Export:
      Name: !Sub "${AWS::StackName}-PrivateRouteTableId"
Example 2: VPC endpoint for private S3 access
yaml
Resources:
  # S3 VPC Endpoint
  S3Endpoint:
    Type: AWS::EC2::VPCEndpoint
    Properties:
      VpcId: !Ref MainVpc
      ServiceName: !Sub "com.amazonaws.${AWS::Region}.s3"
      RouteTableIds:
        - !Ref PrivateRouteTable
      VpcEndpointType: Gateway

Best Practices

  • Keep public, private, and isolated subnet purposes explicit in names and tags
  • Prefer one NAT gateway per AZ for resilient production environments when budget allows
  • Use VPC endpoints to reduce unnecessary NAT traffic for AWS service access
  • Export VPC and subnet identifiers from the network stack instead of recreating network assumptions elsewhere
  • Review network changes with dependency stacks because route and subnet changes can have broad blast radius
  • Keep the root skill focused and move larger networking variants to references/examples.md

Constraints and Warnings

  • NAT gateways incur hourly costs and data transfer charges—consider VPC endpoints for AWS service access
  • CIDR overlap blocks peering, transit, and future network expansion
  • Route-table or subnet replacements can interrupt traffic even when the template is valid
  • Endpoint quotas, AZ availability, and service-specific subnet requirements vary by region
  • Hardcoding Availability Zones can reduce portability across accounts and regions

References

  • references/examples.md
  • references/reference.md

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-vpc of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • references/examples.md
  • references/reference.md

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

AWS Cloudformation Vpc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Cloudformation Vpc compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Cloudformation Vpc this skillgiuseppe-trisciuoglio/developer-kit357—~2.2kAutomated safety check: NotesMIT
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Cloudformationitsmostafa/aws-agent-skills1.2k—~2.5kAutomated safety check: PassMIT
Stackbionic-gpt/bionic-gpt2.4k—~635Automated safety check: PassApache-2.0
Ocioracle/skills877—~2.4kAutomated safety check: PassUPL-1.0
AWS Observabilityaws/agent-toolkit-for-aws2.8k—~7.2kAutomated safety check: PassApache-2.0

Similar skills

  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Cloudformation

    itsmostafa/aws-agent-skills

    AWS CloudFormation infrastructure as code for stack management.

    1.2k GitHub stars~2.5k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Stack

    bionic-gpt/bionic-gpt

    Create or modify StackApp infrastructure-as-code manifests and Stack-managed application infrastructure.

    2.4k GitHub stars~635 tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Oci

    oracle/skills

    Official

    Oracle Cloud Infrastructure guidance for designing, operating, and troubleshooting OCI services, including OCI Kubernetes Engine (OKE), OCI Internet of Things Platform, OCI Functions deployment and…

    877 GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Observability

    aws/agent-toolkit-for-aws

    Official

    Builds, configures, debugs, and optimizes AWS observability - operator-symptom questions and detecting Omni vs classic CloudWatch.

    2.8k GitHub stars~7.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Cdk

    aws/agent-toolkit-for-aws

    Official

    Authors, deploys, and troubleshoots AWS infrastructure using CDK with TypeScript or Python.

    2.8k GitHub stars~2.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    357 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    357 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check: notes

Categories

Questions about AWS Cloudformation Vpc

What does AWS Cloudformation Vpc do?

Provides AWS CloudFormation patterns for VPC foundations, including subnets, route tables, internet and NAT gateways, endpoints, and reusable outputs. AWS Cloudformation Vpc is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides AWS CloudFormation patterns for VPC foundations, including subnets, route tables, internet and NAT gateways, endpoints, and reusable outputs.

When should I use AWS Cloudformation Vpc?

AWS Cloudformation Vpc fits situations like: creating a new network baseline; segmenting public and private workloads; preparing CloudFormation networking stacks for application deployments.

How do I install AWS Cloudformation Vpc in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-vpc -a claude-code`. Or copy the skill folder (plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-vpc in giuseppe-trisciuoglio/developer-kit) into .claude/skills/aws-cloudformation-vpc in your project. Claude Code loads it when a task matches its description.

How do I install AWS Cloudformation Vpc in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-vpc -a codex`. Or copy the skill folder (plugins/developer-kit-aws/skills/aws-cloudformation/aws-cloudformation-vpc in giuseppe-trisciuoglio/developer-kit) into .agents/skills/aws-cloudformation-vpc in your project. Codex loads it when a task matches its description.

Can I use AWS Cloudformation Vpc in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-cloudformation-vpc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-cloudformation-vpc, .gemini/skills/aws-cloudformation-vpc, .github/skills/aws-cloudformation-vpc and .opencode/skills/aws-cloudformation-vpc in your project.

What does AWS Cloudformation Vpc need to run?

Going by SKILL.md and its folder, AWS Cloudformation Vpc needs the command-line tools its instructions call (aws). Its frontmatter pre-approves these tools: Read, Write, Bash.

Does AWS Cloudformation Vpc access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AWS Cloudformation Vpc safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does AWS Cloudformation Vpc use?

AWS Cloudformation Vpc is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS Cloudformation Vpc use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to AWS Cloudformation Vpc?

Skills that share tags, products or a category with AWS Cloudformation Vpc: AWS Cdk Development (zxkane/aws-skills, 367 stars), Cloudformation (itsmostafa/aws-agent-skills, 1.2k stars), Stack (bionic-gpt/bionic-gpt, 2.4k stars) and Oci (oracle/skills, 877 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Cloudformation Vpc?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.