Prompt library

AWS prompts

Prompts for AWS work: writing least-privilege IAM policies, reviewing architectures, and finding cost savings in a bill.

  • iam
  • security
  • least privilege
97/100 · 147 tokens

Least-privilege IAM policy

Writes an IAM policy granting only the actions and resources a workload needs.

Use it when: Replacing a wildcard policy, or writing the first policy for a new Lambda function or service role.

prompt
You are an AWS security engineer writing IAM policies.

## Task
Draft an IAM identity policy that allows exactly the access described below.

## Requirements
- Never use "*" as an action or as a whole resource.
- Scope every statement to the ARNs named in the description.
- Add a condition key wherever the description restricts access by tag, prefix, or encryption.
- Use one statement per service with a Sid that names its purpose.
- Do not grant any action the description does not require.

## Output format
Return the policy document as one fenced JSON block, followed by a table with the columns Sid, Why it is needed, and What it does not allow.

## Input
<access>
{{access}}
</access>

Variables

{{access}}
What the workload must do, with resource names or ARNs.

Example input

access: a Lambda function reads objects under the reports/ prefix of the bucket acme-data and writes items to the DynamoDB table Orders.

Example output

```json
{ "Version": "2012-10-17", "Statement": [ { "Sid": "ReadReports", "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::acme-data/reports/*" } ] }
```
| Sid | Why it is needed | What it does not allow |
|---|---|---|
| ReadReports | Reads report files | Listing the bucket or reading other prefixes |

Illustrative: written to show the expected shape, not generated by a model.

  • architecture
  • well-architected
  • review
100/100 · 162 tokens

AWS architecture review

Reviews an architecture against reliability, security, cost, and operations, with prioritized findings.

Use it when: Before a design review, or when taking over a workload you did not build.

prompt
You are an AWS solutions architect reviewing a workload design.

## Task
Review the architecture described below for reliability, security, cost, and operational risks.

## Requirements
- Report only risks that follow from the description; do not assume components it does not mention.
- Rank each finding as high, medium, or low, and state the failure it leads to.
- Give one concrete change for every high finding, naming the AWS service or setting.
- List the questions you need answered where the description is not specific enough to judge.

## Output format
Return markdown with three sections: Findings (a table with the columns Area, Severity, Risk, and Recommended change), Open questions (bulleted list), and Top 3 actions (numbered list).

## Input
<architecture>
{{architecture}}
</architecture>

Variables

{{architecture}}
The components, how they connect, the regions and zones used, and the expected load.

Example input

architecture: one EC2 instance in a single zone running an API, an RDS MySQL instance without Multi-AZ, and an S3 bucket for uploads.

Example output

## Findings
| Area | Severity | Risk | Recommended change |
|---|---|---|---|
| Reliability | High | A zone failure takes the API offline | Run 2 instances in an Auto Scaling group across 2 zones behind an Application Load Balancer |

Illustrative: written to show the expected shape, not generated by a model.

Make it yours

Edit the requirements to match your standards, then check the result. Theprompt analyzer re-scores it as you type, theoptimizer removes filler without dropping a requirement, and thesecurity scanner flags secrets and personal data before you send it to a model.

More categories