AWS RDS relational database service for managed databases. An agent skill from itsmostafa/aws-agent-skills.

MITAuto-check passedDevOps & Cloud

Install Rds

skills CLI
$ npx skills add itsmostafa/aws-agent-skills --skill rds -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install itsmostafa/aws-agent-skills rds --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/rds .claude/skills/rds && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rds
GitHub stars
1.2k
Token cost
~2.4k tokens
SKILL.md length
417 words
Files
2
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

AWS RDS relational database service for managed databases. An agent skill from itsmostafa/aws-agent-skills.

  • Works in 4 steps: Security group not allowing access → Instance not in VPC subnet → SSL required but not used → …
  • Provisioning databases
  • SKILL.md covers Table of Contents, Core Concepts, Common Patterns and CLI Reference, plus 3 more sections
  • Calls aws

What it does

Rds is an agent skill from itsmostafa/aws-agent-skills. AWS RDS relational database service for managed databases. Use when provisioning databases, configuring backups, managing replicas, troubleshooting connectivity, or optimizing performance.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `administration.md`).

It sits in DevOps & Cloud, covering Backup and disaster recovery. It works with Amazon Web Services. The repository describes itself as: AWS Skills for Agents. The licence is MIT.

When your agent uses it

  • Provisioning databases
  • Configuring backups
  • Managing replicas
  • Troubleshooting connectivity

Example prompts

  • “/rds”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Security group not allowing access
  2. Instance not in VPC subnet
  3. SSL required but not used
  4. Wrong endpoint/port

What it can do on your machine

Read from SKILL.md and the folder at commit e786d25. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • boto3.amazonaws.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rds loads about 2.4k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 417 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from itsmostafa/aws-agent-skills at commit e786d25, republished under its MIT licence (© itsmostafa). 417 words, ~2,431 tokens.

Download SKILL.mdSave it as .claude/skills/rds/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
rds
description
AWS RDS relational database service for managed databases. Use when provisioning databases, configuring backups, managing replicas, troubleshooting connectivity, or optimizing performance.
last_updated
2026-01-07
doc_source
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/

AWS RDS

Amazon Relational Database Service (RDS) provides managed relational databases including MySQL, PostgreSQL, MariaDB, Oracle, SQL Server, and Aurora. RDS handles provisioning, patching, backups, and failover.

Table of Contents

Core Concepts

DB Instance Classes
CategoryExampleUse Case
Standarddb.m6g.largeGeneral purpose
Memory Optimizeddb.r6g.largeHigh memory workloads
Burstabledb.t3.mediumVariable workloads, dev/test
Storage Types
TypeIOPSUse Case
gp33,000-16,000Most workloads
io1/io2Up to 256,000High-performance OLTP
magneticN/ALegacy, avoid
Multi-AZ Deployments
  • Multi-AZ Instance: Synchronous standby in different AZ
  • Multi-AZ Cluster: One writer, two reader instances (Aurora-like)
Read Replicas

Asynchronous copies for read scaling. Can be cross-region.

Common Patterns

Create a PostgreSQL Instance

AWS CLI:

bash
# Create DB subnet group
aws rds create-db-subnet-group \
  --db-subnet-group-name my-db-subnet-group \
  --db-subnet-group-description "Private subnets for RDS" \
  --subnet-ids subnet-12345678 subnet-87654321

# Create security group (allow PostgreSQL from app)
aws ec2 create-security-group \
  --group-name rds-postgres-sg \
  --description "RDS PostgreSQL access" \
  --vpc-id vpc-12345678

aws ec2 authorize-security-group-ingress \
  --group-id sg-rds12345 \
  --protocol tcp \
  --port 5432 \
  --source-group sg-app12345

# Create RDS instance
aws rds create-db-instance \
  --db-instance-identifier my-postgres \
  --db-instance-class db.t3.medium \
  --engine postgres \
  --engine-version 16.1 \
  --master-username admin \
  --master-user-password 'SecurePassword123!' \
  --allocated-storage 100 \
  --storage-type gp3 \
  --db-subnet-group-name my-db-subnet-group \
  --vpc-security-group-ids sg-rds12345 \
  --multi-az \
  --backup-retention-period 7 \
  --storage-encrypted \
  --no-publicly-accessible

boto3:

python
import boto3

rds = boto3.client('rds')

response = rds.create_db_instance(
    DBInstanceIdentifier='my-postgres',
    DBInstanceClass='db.t3.medium',
    Engine='postgres',
    EngineVersion='16.1',
    MasterUsername='admin',
    MasterUserPassword='SecurePassword123!',
    AllocatedStorage=100,
    StorageType='gp3',
    DBSubnetGroupName='my-db-subnet-group',
    VpcSecurityGroupIds=['sg-rds12345'],
    MultiAZ=True,
    BackupRetentionPeriod=7,
    StorageEncrypted=True,
    PubliclyAccessible=False
)
Create Read Replica
bash
aws rds create-db-instance-read-replica \
  --db-instance-identifier my-postgres-replica \
  --source-db-instance-identifier my-postgres \
  --db-instance-class db.t3.medium \
  --availability-zone us-east-1b
Take a Snapshot
bash
aws rds create-db-snapshot \
  --db-snapshot-identifier my-postgres-snapshot-2024-01-15 \
  --db-instance-identifier my-postgres
Restore from Snapshot
bash
aws rds restore-db-instance-from-db-snapshot \
  --db-instance-identifier my-postgres-restored \
  --db-snapshot-identifier my-postgres-snapshot-2024-01-15 \
  --db-instance-class db.t3.medium \
  --db-subnet-group-name my-db-subnet-group \
  --vpc-security-group-ids sg-rds12345
Point-in-Time Recovery
bash
aws rds restore-db-instance-to-point-in-time \
  --source-db-instance-identifier my-postgres \
  --target-db-instance-identifier my-postgres-pitr \
  --restore-time 2024-01-15T10:30:00Z \
  --db-instance-class db.t3.medium
Modify Instance
bash
# Change instance class (with downtime)
aws rds modify-db-instance \
  --db-instance-identifier my-postgres \
  --db-instance-class db.m6g.large \
  --apply-immediately

# Scale storage (no downtime)
aws rds modify-db-instance \
  --db-instance-identifier my-postgres \
  --allocated-storage 200 \
  --apply-immediately
Connect with IAM Authentication
python
import boto3
import psycopg2

rds = boto3.client('rds')

# Generate auth token
token = rds.generate_db_auth_token(
    DBHostname='my-postgres.abc123.us-east-1.rds.amazonaws.com',
    Port=5432,
    DBUsername='iam_user',
    Region='us-east-1'
)

# Connect
conn = psycopg2.connect(
    host='my-postgres.abc123.us-east-1.rds.amazonaws.com',
    port=5432,
    database='mydb',
    user='iam_user',
    password=token,
    sslmode='require'
)

CLI Reference

Instance Management
CommandDescription
aws rds create-db-instanceCreate instance
aws rds describe-db-instancesList instances
aws rds modify-db-instanceModify settings
aws rds delete-db-instanceDelete instance
aws rds reboot-db-instanceReboot instance
aws rds start-db-instanceStart stopped instance
aws rds stop-db-instanceStop instance
Backups
CommandDescription
aws rds create-db-snapshotManual snapshot
aws rds describe-db-snapshotsList snapshots
aws rds restore-db-instance-from-db-snapshotRestore from snapshot
aws rds restore-db-instance-to-point-in-timePoint-in-time restore
aws rds copy-db-snapshotCopy snapshot
Replicas
CommandDescription
aws rds create-db-instance-read-replicaCreate read replica
aws rds promote-read-replicaPromote to standalone

Best Practices

Security
  • Never make publicly accessible — use VPC and security groups
  • Enable encryption at rest (KMS) and in transit (SSL)
  • Use IAM authentication for application access
  • Store credentials in Secrets Manager with rotation
  • Use parameter groups to enforce SSL
bash
# Enforce SSL in PostgreSQL
aws rds modify-db-parameter-group \
  --db-parameter-group-name my-pg-params \
  --parameters "ParameterName=rds.force_ssl,ParameterValue=1,ApplyMethod=pending-reboot"
Show full SKILL.md (154 more words)Show less
Performance
  • Right-size instances — monitor CPU, memory, IOPS
  • Use gp3 for cost-effective performance
  • Enable Performance Insights for query analysis
  • Use read replicas for read scaling
  • Optimize queries — check slow query log
High Availability
  • Enable Multi-AZ for production
  • Use Aurora for mission-critical workloads
  • Configure appropriate backup retention
  • Test failover periodically
  • Monitor replication lag for replicas
Cost Optimization
  • Use Reserved Instances for steady-state workloads
  • Stop dev/test instances when not in use
  • Delete old snapshots regularly
  • Right-size instance classes

Troubleshooting

Cannot Connect

Causes:

  1. Security group not allowing access
  2. Instance not in VPC subnet
  3. SSL required but not used
  4. Wrong endpoint/port

Debug:

bash
# Check security group
aws ec2 describe-security-groups --group-ids sg-rds12345

# Check instance status
aws rds describe-db-instances \
  --db-instance-identifier my-postgres \
  --query "DBInstances[0].{Status:DBInstanceStatus,Endpoint:Endpoint}"

# Test connectivity from EC2
nc -zv my-postgres.abc123.us-east-1.rds.amazonaws.com 5432
High CPU/Memory

Debug:

bash
# Enable Enhanced Monitoring
aws rds modify-db-instance \
  --db-instance-identifier my-postgres \
  --monitoring-interval 60 \
  --monitoring-role-arn arn:aws:iam::123456789012:role/rds-monitoring-role

# Enable Performance Insights
aws rds modify-db-instance \
  --db-instance-identifier my-postgres \
  --enable-performance-insights \
  --performance-insights-retention-period 7

Solutions:

  • Scale up instance class
  • Optimize slow queries
  • Add read replicas
  • Check for locking/blocking
Storage Full

Symptom: Instance becomes unavailable

Prevention:

bash
# Enable storage autoscaling
aws rds modify-db-instance \
  --db-instance-identifier my-postgres \
  --max-allocated-storage 500

# Set CloudWatch alarm
aws cloudwatch put-metric-alarm \
  --alarm-name "RDS-Storage-Low" \
  --metric-name FreeStorageSpace \
  --namespace AWS/RDS \
  --dimensions Name=DBInstanceIdentifier,Value=my-postgres \
  --statistic Average \
  --period 300 \
  --threshold 10000000000 \
  --comparison-operator LessThanThreshold \
  --evaluation-periods 2 \
  --alarm-actions arn:aws:sns:us-east-1:123456789012:alerts
Replication Lag

Monitor:

bash
aws cloudwatch get-metric-statistics \
  --namespace AWS/RDS \
  --metric-name ReplicaLag \
  --dimensions Name=DBInstanceIdentifier,Value=my-postgres-replica \
  --start-time $(date -d '1 hour ago' -u +%Y-%m-%dT%H:%M:%SZ) \
  --end-time $(date -u +%Y-%m-%dT%H:%M:%SZ) \
  --period 60 \
  --statistics Average

Causes:

  • Replica instance too small
  • Heavy write load
  • Network issues
  • Long-running queries on replica

References

© itsmostafa, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/rds of itsmostafa/aws-agent-skills.

  • SKILL.md
  • administration.md

Open the folder on GitHubat commit e786d25

Compare with similar skills

Rds next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rds compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rds this skillitsmostafa/aws-agent-skills1.2k—~2.4kAutomated safety check: PassMIT
Cloud ArchitectJeffallan/claude-skills12k—~1.9kAutomated safety check: PassMIT
Rds Operation Reviewaws/tools-for-devops-agent100—~4.8kAutomated safety check: PassApache-2.0
AWS Rdssickn33/agentic-awesome-skills47k2 repos~3.3kAutomated safety check: PassMIT
Storage S3 Resiliency Expertiseaws/tools-for-devops-agent100—~2.8kAutomated safety check: PassApache-2.0
Frappe Ops BackupImpertio-Studio/Frappe_Claude_Skill_Package187—~2.9kAutomated safety check: NotesMIT

Similar skills

  • Cloud Architect

    Jeffallan/claude-skills

    Designs cloud architectures, migration plans, cost optimization recommendations and disaster recovery strategies across AWS, Azure and GCP.

    12k GitHub stars~1.9k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Rds Operation Review

    aws/tools-for-devops-agent

    Official

    Comprehensive Amazon RDS and Aurora operational review aligned with the AWS Well-Architected Framework and RDS/Aurora best practices.

    100 GitHub stars~4.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Rds

    sickn33/agentic-awesome-skills

    Provision and manage RDS databases. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.3k tokens
    DevOps & CloudAuto-check passed
  • Storage S3 Resiliency Expertise

    aws/tools-for-devops-agent

    Official

    S3 resiliency, security, and data protection review. An agent skill from aws/tools-for-devops-agent.

    100 GitHub stars~2.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Frappe Ops Backup

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when configuring backups, restoring sites, encrypting backup files, scheduling automated backups, or planning disaster recovery.

    187 GitHub stars~2.9k tokensUpdated 20 days ago
    DevOps & CloudAuto-check: notes
  • Directconnect

    aws/agent-toolkit-for-aws

    Official

    Configures AWS Direct Connect: choosing a connection model (dedicated, hosted, or a link aggregation group) and completing the cross connect; creating private, public, and transit virtual interfaces…

    2.8k GitHub stars~2.3k tokensUpdated today
    DevOps & CloudAuto-check passed

More from itsmostafa/aws-agent-skills

All 17 skills in this repo
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Bedrock

    itsmostafa/aws-agent-skills

    AWS Bedrock foundation models for generative AI. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Ecs

    itsmostafa/aws-agent-skills

    AWS ECS container orchestration for running Docker containers.

    1.2k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed
  • Cloudformation

    itsmostafa/aws-agent-skills

    AWS CloudFormation infrastructure as code for stack management.

    1.2k GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Cloudwatch

    itsmostafa/aws-agent-skills

    AWS CloudWatch monitoring for logs, metrics, alarms, and dashboards.

    1.2k GitHub stars~3.5k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Rds

What does Rds do?

AWS RDS relational database service for managed databases. An agent skill from itsmostafa/aws-agent-skills. Rds is an agent skill from itsmostafa/aws-agent-skills. AWS RDS relational database service for managed databases.

When should I use Rds?

Rds fits situations like: provisioning databases; configuring backups; managing replicas; troubleshooting connectivity.

How do I install Rds in Claude Code?

Run `npx skills add itsmostafa/aws-agent-skills --skill rds -a claude-code`. Or copy the skill folder (skills/rds in itsmostafa/aws-agent-skills) into .claude/skills/rds in your project. Claude Code loads it when a task matches its description.

How do I install Rds in Codex?

Run `npx skills add itsmostafa/aws-agent-skills --skill rds -a codex`. Or copy the skill folder (skills/rds in itsmostafa/aws-agent-skills) into .agents/skills/rds in your project. Codex loads it when a task matches its description.

Can I use Rds in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add itsmostafa/aws-agent-skills --skill rds -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rds, .gemini/skills/rds, .github/skills/rds and .opencode/skills/rds in your project.

What does Rds need to run?

Going by SKILL.md and its folder, Rds needs the command-line tools its instructions call (aws). Our summary lists: Python 3.

Does Rds access the network?

SKILL.md names 2 domains. As links in the text: docs.aws.amazon.com and boto3.amazonaws.com. This is read from the text; nothing was executed.

Is Rds safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rds use?

Rds is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rds use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rds?

Skills that share tags, products or a category with Rds: Cloud Architect (Jeffallan/claude-skills, 12k stars), Rds Operation Review (aws/tools-for-devops-agent, 100 stars), AWS Rds (sickn33/agentic-awesome-skills, 47k stars) and Storage S3 Resiliency Expertise (aws/tools-for-devops-agent, 100 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rds?

itsmostafa (a GitHub user) maintains it in itsmostafa/aws-agent-skills, which has 1,161 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 5, 2026.

Source: itsmostafa/aws-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.