AWS architecture expertise including Well-Architected Framework, account strategy, VPC and networking design, compute and serverless patterns, data architecture, security architecture, and cost optimization strategies. Use proactively when designing systems on AWS, evaluating AWS services, planning AWS landing zones, or architecting for AWS-specific capabilities.
Resources
1Install
npx skillscat add rnavarych/alpha-engineer/role-architect-aws-architect Install via the SkillsCat registry.
SKILL.md
AWS Architect
When to use
- Designing or reviewing AWS multi-account strategy and Control Tower landing zones
- Selecting between ECS Fargate, EKS, and Lambda for a workload
- Architecting VPC design, Transit Gateway topology, or Direct Connect hybrid connectivity
- Choosing between Aurora, DynamoDB, ElastiCache, Redshift, and Kinesis for data needs
- Configuring GuardDuty, Security Hub, IAM Identity Center, or KMS for security posture
- Designing multi-Region active-passive or active-active architectures
- Optimizing AWS costs with Savings Plans, Spot Instances, Graviton, and data transfer strategies
Core principles
- Multi-account by default — never mix production and non-production in the same account
- SCPs as guardrails — enforce baseline security at the Organizations level
- Roles over keys — IAM roles for everything; eliminate long-lived access keys
- Tagging from day one — cost allocation and compliance require consistent tags before spend grows
- Savings Plans before Reserved Instances — flexibility matters more than maximum discount for most workloads
Reference Files
references/aws-platform-and-compute.md— Well-Architected six pillars, multi-account architecture, Control Tower, Account Vending, VPC design, Transit Gateway, Direct Connect vs VPN, PrivateLink, ECS Fargate vs EKS, Lambda cold start mitigation, Step Functions, and EC2 Auto Scaling with Gravitonreferences/aws-data-security-cost.md— Aurora, DynamoDB, ElastiCache selection; Lake Formation, Redshift, Kinesis, Athena analytics stack; EventBridge, SQS/SNS, MSK event-driven patterns; IAM Identity Center, KMS encryption, Secrets Manager, GuardDuty, Security Hub, AWS Config; Compute Savings Plans, Spot strategy, Graviton migration, data transfer cost optimization, multi-Region patterns, and CloudWatch/X-Ray observability