Loading...
Loading...
Compare original and translation side by side
aws___search_documentationaws___read_documentationaws___recommendawsaws___search_documentationaws___read_documentationaws___recommendawsaws___search_documentation{SERVICE}Query 1: "{SERVICE} best practices high availability disaster recovery"
topics: ["general"]
limit: 10
Query 2: "{SERVICE} Well-Architected reliability resilience best practices"
topics: ["general"]
limit: 10
Query 3: "{SERVICE} replication multi-AZ failover cluster mode backup"
topics: ["reference_documentation", "troubleshooting"]
limit: 10
Query 4: "{SERVICE} security encryption authentication access control"
topics: ["general"]
limit: 10
Query 5: "{SERVICE} Well-Architected security best practices"
topics: ["general"]
limit: 10aws___search_documentation{SERVICE}Query 1: "{SERVICE} best practices high availability disaster recovery"
topics: ["general"]
limit: 10
Query 2: "{SERVICE} Well-Architected reliability resilience best practices"
topics: ["general"]
limit: 10
Query 3: "{SERVICE} replication multi-AZ failover cluster mode backup"
topics: ["reference_documentation", "troubleshooting"]
limit: 10
Query 4: "{SERVICE} security encryption authentication access control"
topics: ["general"]
limit: 10
Query 5: "{SERVICE} Well-Architected security best practices"
topics: ["general"]
limit: 10aws___read_documentationmax_length: 15000aws___read_documentationmax_length: 15000references/output-template.mdreferences/output-template.mdaws eksaws ecsaws ec2aws iamkubectl| In Scope (AWS API verifiable) | Out of Scope (requires kubectl / workload context) |
|---|---|
| Control plane configuration (K8s version, platform version, API endpoint access, logging) | Pod Disruption Budgets (PDB) |
| Node group configuration (instance types, scaling, AMI, AZ distribution, disk size) | Topology Spread Constraints |
| Cluster networking (VPC, subnets, security groups, service CIDR) | Liveness / readiness / startup probes |
| Add-on presence and versions (VPC CNI, CoreDNS, kube-proxy, EBS CSI, etc.) | Container resource requests / limits |
| Secrets envelope encryption (KMS key) | Pod securityContext (runAsNonRoot, capabilities) |
| Authentication mode (ConfigMap vs API) and Access Entries | Pod Security Admission (PSA) namespace labels |
| Control plane audit logging | automountServiceAccountToken |
| Cluster deletion protection | Network Policies (K8s resource level) |
| Node auto-repair and node monitoring agent addon | Pod graceful termination (terminationGracePeriodSeconds, preStop) |
| Cluster tags and nodegroup tags | Workload-level Velero backups |
| Upgrade insights and deprecation warnings | Application health check paths |
| OIDC provider configuration (for IRSA) | Service mesh (mTLS) configuration |
| GuardDuty EKS protection (account-level) | OPA Gatekeeper / Kyverno policies |
references/output-template.mdHA-01-hiDR-02-mdSEC-03-lo-hi-md-loaws eksaws ecsaws ec2aws iamkubectl| 范围内(可通过AWS API验证) | 范围外(需要kubectl/工作负载上下文) |
|---|---|
| 控制平面配置(K8s版本、平台版本、API端点访问、日志) | Pod中断预算(PDB) |
| 节点组配置(实例类型、扩缩容、AMI、可用区分布、磁盘大小) | 拓扑分布约束 |
| 集群网络(VPC、子网、安全组、服务CIDR) | 存活/就绪/启动探针 |
| 附加组件的存在性和版本(VPC CNI、CoreDNS、kube-proxy、EBS CSI等) | 容器资源请求/限制 |
| 密钥信封加密(KMS密钥) | Pod securityContext(以非根用户运行、权限) |
| 认证模式(ConfigMap vs API)和访问条目 | Pod安全准入(PSA)命名空间标签 |
| 控制平面审计日志 | automountServiceAccountToken |
| 集群删除保护 | 网络策略(K8s资源级) |
| 节点自动修复和节点监控代理附加组件 | Pod优雅终止(terminationGracePeriodSeconds、preStop) |
| 集群标签和节点组标签 | 工作负载级Velero备份 |
| 升级洞察和弃用警告 | 应用健康检查路径 |
| OIDC提供者配置(用于IRSA) | 服务网格(mTLS)配置 |
| GuardDuty EKS保护(账户级) | OPA Gatekeeper/Kyverno策略 |
references/output-template.mdHA-01-hiDR-02-mdSEC-03-lo-hi-md-lo| Tag | Meaning |
|---|---|
| Well-Architected Lens — Reliability Pillar (question N) |
| Well-Architected Lens — Security Pillar |
| Well-Architected Lens — Performance Efficiency Pillar |
| Well-Architected Lens — Operational Excellence Pillar |
| Well-Architected Lens — Cost Optimization Pillar |
| AWS Security Hub CSPM control (e.g., |
| AWS re:Post knowledge center article |
| Service user guide / official documentation |
| AWS Database Blog or other official blog |
| AWS whitepaper |
| 标签 | 含义 |
|---|---|
| Well-Architected Lens — 可靠性支柱(第N个问题) |
| Well-Architected Lens — 安全性支柱 |
| Well-Architected Lens — 性能效率支柱 |
| Well-Architected Lens — 运营卓越支柱 |
| Well-Architected Lens — 成本优化支柱 |
| AWS Security Hub CSPM控制(例如 |
| AWS re:Post知识中心文章 |
| 服务用户指南/官方文档 |
| AWS数据库博客或其他官方博客 |
| AWS白皮书 |
references/output-template.mdYYYY-mm-dd-HH-MM-SS-{SERVICE}-best-practice-checklist.mdYYYY-mm-dd-HH-MM-SS2025-07-15-14-30-00{SERVICE}elasticache-redisamazon-eks2025-07-15-14-30-00-elasticache-redis-best-practice-checklist.mdreferences/output-template.mdYYYY-mm-dd-HH-MM-SS-{SERVICE}-best-practice-checklist.mdYYYY-mm-dd-HH-MM-SS2025-07-15-14-30-00{SERVICE}elasticache-redisamazon-eks2025-07-15-14-30-00-elasticache-redis-best-practice-checklist.mdreferences/assessment-workflow.mdreferences/assessment-workflow.mdenv.shsource <credential-file-path>env.shsource <credential-file-path>references/assessment-workflow.mdaws elasticache describe-replication-groupsaws elasticache describe-cache-clusters --show-cache-node-infoaws elasticache describe-cache-subnet-groupsaws elasticache describe-cache-parametersaws elasticache list-tags-for-resourceaws elasticache describe-snapshotsaws elasticache describe-eventsreferences/assessment-workflow.mdaws elasticache describe-replication-groupsaws elasticache describe-cache-clusters --show-cache-node-infoaws elasticache describe-cache-subnet-groupsaws elasticache describe-cache-parametersaws elasticache list-tags-for-resourceaws elasticache describe-snapshotsaws elasticache describe-events| Status | Meaning |
|---|---|
| 🟢 PASS | The resource configuration meets or exceeds the recommendation |
| 🔴 FAIL | The resource configuration does not meet the recommendation |
| 🟡 WARN | Cannot be fully verified from infrastructure alone (e.g., client-side settings), or partially meets the recommendation |
| ⚪ N/A | The check does not apply to this resource (e.g., Global Datastore check when cross-region DR is not required) |
| 状态 | 含义 |
|---|---|
| 🟢 通过 | 资源配置符合或超出建议要求 |
| 🔴 未通过 | 资源配置不符合建议要求 |
| 🟡 警告 | 无法仅通过基础设施完全验证(例如客户端设置),或部分符合建议要求 |
| ⚪ 不适用 | 该检查项不适用于此资源(例如未使用跨区域DR时的Global Datastore检查) |
references/output-template.mdYYYY-mm-dd-HH-MM-SS-{RESOURCE_ID}-assessment-report.mdYYYY-mm-dd-HH-MM-SS2025-07-15-14-30-00{RESOURCE_ID}2025-07-15-14-30-00-my-redis-cluster-assessment-report.mdreferences/output-template.mdYYYY-mm-dd-HH-MM-SS-{RESOURCE_ID}-assessment-report.mdYYYY-mm-dd-HH-MM-SS2025-07-15-14-30-00{RESOURCE_ID}2025-07-15-14-30-00-my-redis-cluster-assessment-report.md