AWS Agents For Devsecops
AWS Core
Core Skills · AWS…
Messaging And Streaming Skills
Migration And Modernization Skills
Networking And Content Delivery Skills
Security And Identity Skills
System Table Skills
Web And Mobile Development
120 chapters · 648 min
Analytics Skills
Chapter 53 of 120
Helps migrate self-managed Apache Kafka workloads to Amazon MSK Express.
9 minutes · 1,970 words · 24 sections
This skill helps customers migrate self-managed Apache Kafka workloads to Amazon MSK Express. It provides three phases — Discovery, Assessment, and an optional Simulation — that can be run end-to-end or individually depending on the customer’s needs.
This skill covers migrations from self-managed Apache Kafka (on-premises, EC2, Docker, Kubernetes, or other non-MSK deployments) to MSK Express. Migrations from MSK Standard (Provisioned) to MSK Express are out of scope.
The AWS MCP server is recommended for documentation lookups and informational questions, but is not required. The assessment scripts are pure file processors with no AWS API calls.
Route the customer’s request based on their intent:
Explain what this skill offers:
This skill helps you migrate to MSK Express in three phases:
Phase 1 — Discovery: Inventory your source Kafka cluster — brokers, topics, partition counts, configs, authentication, and workload metrics. I can discover this from IaC files (Terraform, CDK, Docker Compose, Kubernetes manifests), provide commands for you to run on your cluster, or you can provide the information manually. Output:
migrate-to-msk-skill-artifacts/<cluster_name>/cluster-config.json.Phase 2 — Assessment: Validate your cluster against MSK Express across 5 compatibility pillars (topology, Kafka version, configs, auth, quotas) and produce a target Express specification using the AWS-published MSK Sizing/Pricing workbook. I’ll flag what Express will refuse vs what Express will silently convert. Outputs:
compatibility.<cluster_name>.json, the filledMSK_Sizing_Pricing.<cluster_name>.xlsx, andmsk-sizing-inputs.<cluster_name>.json.Phase 3 — Simulation: Spin up an MSK Express cluster with load-testing infrastructure to see how Express performs on your own workload, then run a vended test (End-to-End Latency or Broker Restart Under Load) and review the results on a CloudWatch dashboard.
Data replication: For migrating data to your Express cluster, you can use MSK Replicator. I can provide guidance on setup and configuration.
Where would you like to start? I can begin with discovery if you point me to your infrastructure code or describe your cluster, or jump to assessment if you already have a
cluster-config.jsonfile, or go straight to simulation if you already know your target Express configuration.
Guardrails for this overview response:
cluster-config.json.compatibility.py, sizing.py, simulation_load_test_config.py, or the reference files to explain how a phase works. Describe the phases at the level shown above; do not walk the customer through the implementation.If the customer provides a directory path, IaC files, or says “here’s our infra” —
this is discovery intent. Run ONLY Phase 1 (Discovery). Do NOT run assessment,
do NOT suggest migration steps, do NOT mention blockers or compatibility.
Produce the migrate-to-msk-skill-artifacts/<cluster_name>/cluster-config.json file and stop.
Customer explicitly asks to assess or has a migrate-to-msk-skill-artifacts/<cluster_name>/cluster-config.json file
already produced. Run Phase 2 (Assessment) only.
Customer wants to test MSK Express with their workload. They can provide cluster sizing directly (instance type, broker count, Kafka version) or reference an earlier assessment. Proceed directly to Phase 3 — Simulation. An assessment is helpful but not required — the simulation asks for sizing inputs directly.
Customer asks about Express capabilities, constraints, configuration differences,
authentication support, pricing, or compaction behavior without providing
cluster-specific data. Use AWS documentation tools (aws___search_documentation,
aws___read_documentation) if available to look up the answer from MSK Express
documentation. If MCP tools are not available, reference the
MSK Express documentation (opens in a new tab)
and answer based on knowledge of AWS MSK.
Customer asks about MSK Replicator compatibility, version upgrade paths, MirrorMaker 2,
or migration strategies. MSK Replicator is the native AWS-supported solution for data
replication and works for both MSK-to-MSK and non-MSK-to-MSK migrations. Use AWS
documentation tools (aws___search_documentation, aws___read_documentation) if
available to retrieve current requirements and supported configurations. If MCP tools
are not available, reference the
MSK Replicator documentation (opens in a new tab)
and answer based on knowledge of AWS MSK.
Purpose: Inventory the source cluster to build a migration profile.
Input: One of:
Output: migrate-to-msk-skill-artifacts/<cluster_name>/cluster-config.json — saved to the working directory.
Before doing ANYTHING else in discovery, you MUST read the reference file:
references/discovery.md (located at the skill path shown above).
Use file_read to read the full content of references/discovery.md. This file
contains the REQUIRED response template and JSON schema. You MUST follow the
template exactly — your response format, forbidden content, and JSON structure
are all defined there. Do NOT respond until you have read this file.
IaC analysis — Read infrastructure files and extract cluster metadata.
Kafka CLI commands — Display standard Kafka CLI commands for the customer to run on their cluster (kafka-topics.sh, kafka-configs.sh, kafka-broker-api-versions.sh). Do NOT generate or offer Python scripts.
Runtime metrics intake — Ingest metrics provided by the customer.
Manual conversation — Ask the customer for cluster details.
references/discovery.md before responding.migrate-to-msk-skill-artifacts/<cluster_name>/cluster-config.json in the working directory.Purpose: Assess the cluster against MSK Express requirements and produce a target Express specification (instance type, broker count, monthly cost projection).
Input: migrate-to-msk-skill-artifacts/<cluster_name>/cluster-config.json from Phase 1.
Outputs:
migrate-to-msk-skill-artifacts/<cluster_name>/compatibility.<cluster_name>.json — five-pillar verdict.migrate-to-msk-skill-artifacts/<cluster_name>/MSK_Sizing_Pricing.<cluster_name>.xlsx — the AWS-published MSK Sizing/Pricing workbook (downloaded by the agent) with the six workload inputs filled into the MSK Provisioned sheet. Open it to read the broker count and cost recommendations.migrate-to-msk-skill-artifacts/<cluster_name>/msk-sizing-inputs.<cluster_name>.json — a record of the six input values and the cell each maps to.Assessment is implemented as two file processors (no live AWS API calls):
scripts/compatibility.py — five-pillar compatibility assessment.scripts/sizing.py — computes the six workbook inputs from the discovery contract and fills them into the AWS-published workbook the agent downloads.Both run via uv run with PEP 723 inline dependencies. For the exact
invocation commands, see “Running the assessment” in
references/assessment-compatibility.md (opens in a new tab).
compatibility.py validates the source against MSK Express across five pillars:
docs.aws.amazon.com/msk).See references/assessment-compatibility.md (opens in a new tab) for the full pseudocode, evidence codes, and verdict mapping.
Each pillar emits one of three verdicts; the overall is the worst across pillars.
| Verdict | Meaning |
|---|---|
INFO | Your source cluster already lines up with MSK Express here. Surfaced for informational purposes. No action needed. |
ADVISORY | Your source cluster differs from MSK Express here, but Express handles this for you at the target by adjusting or replacing the setting. Migration can proceed; review it so the resulting behavior change is expected. |
ACTION_REQUIRED | Identifies a configuration or condition that MSK Express is not expected to accept in its current form. Remediation on the source prior to migration is recommended. |
sizing.py computes the six workbook inputs from the source workload (peak
in/out, total partitions, retention). The agent downloads the AWS-published
workbook by reading the Express best-practices page and following its workbook
hyperlink, then runs sizing.py --workbook <downloaded.xlsx>, which fills the
MSK Provisioned sheet and writes the filled
MSK_Sizing_Pricing.<cluster_name>.xlsx (plus a
msk-sizing-inputs.<cluster_name>.json record). Open the filled workbook to
read the per-instance broker count and monthly cost; its formulas recalculate
on open. The workbook is downloaded at assessment time, not packaged with the
skill, and the script itself performs no network access (it fills a workbook
the agent already downloaded, using the Python standard library). See
references/assessment-sizing.md (opens in a new tab) for the cell
mapping, the download flow, and caveats.
compatibility.py and sizing.py independently; neither blocks the other.ACTION_REQUIRED evidence to the user for awareness, but do not gate further phases on it. Express may still accept the workload with mitigations.cluster-config.json as-is. Partial data is fine — the scripts emit
ADVISORY evidence (METRICS_MISSING, AZ_COUNT_UNKNOWN, etc.) for
missing fields; surface those findings and stop. Do not propose Kafka CLI
commands, IaC walks, scripts, or questionnaires to fill the gaps. Full
forbidden-behavior list in
references/assessment-compatibility.md (opens in a new tab).Deploy a temporary, isolated MSK Express cluster and client fleet in the customer’s account so they can see how Express performs on their own workload, then run one of two vended tests (End-to-End Latency, Broker Restart Under Load) and hand over a CloudWatch dashboard. Follow the 12-step conversational flow and all deploy, sizing, and guardrail details in references/simulation.md (opens in a new tab); the deterministic artifacts it drives are scripts/simulation_load_test_config.py (opens in a new tab) and the static assets/simulation-stack.yaml (opens in a new tab).
Scripts run on the customer’s local machine via uv run. They declare their own
dependencies (PEP 723) and are pure file processors — no AWS API calls, no
network access, and no third-party dependencies (standard library only).
Apply these controls at every phase. For additional detail, see MSK Security best practices (opens in a new tab) and MSK IAM access control (opens in a new tab).
Encryption in transit (mandatory). Enforce TLS for client-broker traffic
on the MSK Express target (EncryptionInTransit.ClientBroker = TLS).
Encryption at rest (mandatory). Provision the target cluster with a customer-managed KMS key (or AWS-managed if your compliance posture allows).
Authentication — prefer IAM over long-lived credentials. Configure the MSK Express target with IAM authentication as the sole client auth method. This gives ephemeral, role-based credentials with full CloudTrail coverage.
Credential storage — use AWS Secrets Manager. Store SASL/SCRAM and TLS credentials for source cluster access in Secrets Manager. Never pass passwords as CLI arguments.
Network isolation. Deploy MSK clusters in private subnets. Use security groups scoped to specific CIDR ranges or security group references. Do NOT use 0.0.0.0/0 ingress rules.
CloudTrail logging and CloudWatch alarms. Ensure CloudTrail is enabled in
the target account and covers kafka.amazonaws.com API calls. Configure alarms:
ClientAuthenticationFailure — surge indicates credential problems or attackConnectionCloseCount — abnormal spike may indicate connection-floodingkafka-cluster:* actionsSensitive data handling. Discovery and assessment outputs contain broker addresses, auth hints, and broker config values. Treat these as sensitive — do not paste into public channels or ticketing systems without redaction.
Single-broker / single-AZ source. Topology pillar emits BROKER_COUNT_LT_3 /
AZ_COUNT_NOT_3 ADVISORY — Express auto-fixes at the target by deploying across 3
AZs with ≥3 brokers regardless of source.
Out-of-range topic configs. max.compaction.lag.ms < 1 day is the only
Express-rejected topic-config bound encoded in compatibility.py. Adjust on the
source before migration.
Workbook recommendations look blank or stale. The recommendation and cost
cells are workbook formulas; they populate once the filled workbook is opened
in Excel / LibreOffice / Sheets and its formulas recalculate. sizing.py sets
fullCalcOnLoad so this happens automatically on open — if your spreadsheet
app has automatic recalculation disabled, trigger a manual recalculation.
Install this repository
npx skills add aws/agent-toolkit-for-aws/plugin marketplace add aws/agent-toolkit-for-awsSkills install per repository, not per chapter — the CLI has no documented per-skill form, so we do not print one.
Helps migrate self-managed Apache Kafka workloads to Amazon MSK Express. Inventories the source cluster (from IaC files, Kafka CLI output, or manual input), assesses MSK Express compatibility across topology, Kafka version, configs, auth, and quotas, produces a target Express specification (instance type, broker count, monthly cost) by filling the AWS-published MSK Sizing/Pricing workbook, and guides migration execution using MSK Replicator. Applicable when the user mentions migrating Kafka, MSK, MSK Express, Kafka migration, analyzing Kafka infrastructure, moving to MSK, moving streaming platform to MSK, streaming migration, moving streaming workloads to AWS, MSK workload compatibility, choosing an MSK cluster type, or MSK Replicator. Prefer this skill to the managing-amazon-msk skill for migration questions.
The verbatim description from this skill’s front matter — the string an agent matches on to decide whether to load it.
main, last pushed 10 August 2026.SKILL.md, not by matching a directory convention. 17 distinct layouts observed: plugins/aws-agents-for-devsecops/skills/*/SKILL.md, plugins/aws-agents/skills/*/SKILL.md, plugins/aws-core/skills/*/SKILL.md, skills/core-skills/*/SKILL.md, skills/specialized-skills/analytics-skills/*/SKILL.md, skills/specialized-skills/database-skills/*/SKILL.md, skills/specialized-skills/ec2-skills/*/SKILL.md, skills/specialized-skills/messaging-and-streaming-skills/*/SKILL.md, skills/specialized-skills/migration-and-modernization-skills/*/SKILL.md, skills/specialized-skills/networking-and-content-delivery-skills/*/SKILL.md, skills/specialized-skills/operations-skills/*/SKILL.md, skills/specialized-skills/resilience-skills/*/SKILL.md, skills/specialized-skills/security-and-identity-skills/*/SKILL.md, skills/specialized-skills/serverless-skills/*/SKILL.md.skills/specialized-skills/storage-skills/*/SKILL.mdskills/specialized-skills/system-table-skills/*/SKILL.mdskills/specialized-skills/web-and-mobile-development/*/SKILL.mdh1 and no skipped levels:.claude-plugin/marketplace.json by Amazon Web Services, declaring 4 plugins. It is read for editorial metadata only — never as the skill index, which is always the repository tree./aws/agent-toolkit-for-aws.md, and each chapter at its own .md URL.8 files · 205 KB
Everything this skill ships beside its prose. All of it is set here, as subchapters of chapter 53.
Documentation the agent loads on demand, rather than up front.
Executable code the skill can run.
Templates, schemas and fixtures the skill draws on.