{
  "meta": {
    "name": "AWS Atlas",
    "date": "2026-10-08",
    "scope": "Broad coverage of the AWS documentation product directory, supplemented with services and capabilities referenced in integrations. Includes AWS services, selected developer tools, infrastructure capabilities, support offerings, and legacy services. Language SDK variants, generic reference pages, and every individual product feature are outside this catalog; it is a researched snapshot rather than a claim of an exhaustive, permanently current AWS inventory.",
    "researchBatches": [
      "ai-analytics",
      "infrastructure",
      "operations-security",
      "specialized",
      "expanded",
      "emerging",
      "supplemental"
    ],
    "serviceCount": 284,
    "connectionCount": 611
  },
  "services": [
    {
      "id": "augmented-ai",
      "name": "Amazon Augmented AI (A2I)",
      "shortName": "A2I",
      "category": "ai",
      "summary": "Adds human review workflows to selected machine-learning predictions and document processing.",
      "details": "A2I defines review workflows and routes selected items to human workers, including integration paths for supported AWS services and custom predictions. It is a review layer around inference, not a model service itself.",
      "useCases": [
        "review low-confidence document fields",
        "approve image classifications",
        "sample predictions for quality control"
      ],
      "concepts": [
        "human loops",
        "worker tasks",
        "confidence thresholds",
        "review output"
      ],
      "considerations": [
        "Design clear reviewer instructions and protect sensitive data",
        "service integrations and workforce options differ."
      ],
      "docs": "https://docs.aws.amazon.com/sagemaker/latest/dg/a2i.html",
      "sources": [
        {
          "title": "Amazon Augmented AI (A2I) documentation",
          "url": "https://docs.aws.amazon.com/sagemaker/latest/dg/a2i.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "agentcore",
      "name": "Amazon Bedrock AgentCore",
      "shortName": "AgentCore",
      "category": "ai",
      "summary": "Modular managed services for deploying, connecting, securing, and observing production AI agents.",
      "details": "Runtime, Gateway, Identity, Memory, Browser, Code Interpreter, and observability are independently usable capabilities rather than one mandatory stack. AgentCore documents its own data storage in DynamoDB and S3; customer-selected integrations such as Lambda targets, private VPC resources, and customer-managed KMS keys are conditional on configuration.",
      "useCases": [
        "run a hosted agent with session isolation",
        "expose approved tools through MCP-compatible Gateway",
        "retain optional long-term memory across sessions"
      ],
      "concepts": [
        "Runtime hosts agents in isolated sessions.",
        "Gateway exposes configured tools and APIs to agents.",
        "Memory is an optional component for retaining context across sessions.",
        "Identity provides workload identity and credential access for selected resources.",
        "Observability records traces, logs, and metrics for agent workflows."
      ],
      "considerations": [
        "Permissions and network access depend on selected components",
        "VPC attachment changes outbound connectivity, and storage/encryption options differ by resource."
      ],
      "docs": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/what-is-bedrock-agentcore.html",
      "sources": [
        {
          "title": "Amazon Bedrock AgentCore documentation",
          "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/what-is-bedrock-agentcore.html"
        },
        {
          "title": "AgentCore Runtime hosting and compute choices",
          "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agents-tools-runtime.html"
        },
        {
          "title": "AgentCore Gateway",
          "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway.html"
        },
        {
          "title": "AgentCore Identity",
          "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html"
        },
        {
          "title": "AgentCore Memory",
          "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory.html"
        },
        {
          "title": "AgentCore Observability",
          "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/observability.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service",
      "topics": [
        {
          "title": "A modular agent platform",
          "bullets": [
            "AgentCore provides services for building, deploying and operating agents with your chosen models",
            "Use its components together or independently; an agent framework is still a separate choice",
            "Runtime hosts agents and tools; Gateway connects tools; Memory retains conversation context",
            "Identity manages credentials; Policy governs tools; Observability and Evaluations assess behavior",
            "Harness offers a managed agent loop; Registry catalogs agents, tools and related resources"
          ]
        },
        {
          "title": "Runtime and session isolation",
          "bullets": [
            "Serverless Runtime sessions use isolated microVMs with separate CPU, memory and filesystems",
            "Reuse a runtime session ID for one conversation; keep different users in separate sessions",
            "Runtime supports real-time responses, streaming and asynchronous agent workloads",
            "Choose managed EC2 Instances when you need supported GPU workloads or longer-lived sessions",
            "Filesystem persistence is configurable; durable business records still need a deliberate storage plan"
          ]
        },
        {
          "title": "Deployments and endpoints",
          "bullets": [
            "Deploy an ECR container image or use supported direct code deployment through the AgentCore tooling",
            "Implement the contract for your protocol: HTTP, MCP, A2A or AG-UI have different interfaces",
            "For HTTP agents, /invocations receives work and /ping reports readiness and background activity",
            "Updating a Runtime creates an immutable version; named endpoints can stay pinned to a tested version",
            "The DEFAULT endpoint follows the latest version; use a separate production endpoint for controlled rollouts"
          ]
        },
        {
          "title": "Gateway and tool discovery",
          "bullets": [
            "Gateway can convert APIs and Lambda functions into MCP-compatible tools behind one endpoint",
            "Attach existing MCP servers as targets and aggregate their available tools for your agents",
            "Tool definitions describe inputs; clear schemas and descriptions help the model select valid calls",
            "Semantic tool search finds relevant tools without putting an entire large catalog in every prompt",
            "Gateway also supports HTTP passthrough and inference targets; choose the target type explicitly"
          ]
        },
        {
          "title": "Inbound and outbound access",
          "bullets": [
            "Inbound authentication verifies callers; outbound credentials authorize access to a target service",
            "Runtime calls can use IAM SigV4 signing or configured OAuth bearer-token authentication",
            "Gateway authorization and its target credentials are separate configurations with separate permissions",
            "A runtime execution role grants AWS API access; a model prompt does not grant that authority",
            "Restrict model, tool and data permissions to the operations each agent actually needs"
          ]
        },
        {
          "title": "Identity and credentials",
          "bullets": [
            "AgentCore Identity represents agents as workload identities and manages access to credential providers",
            "Credential providers support OAuth flows and API keys for external services",
            "User-delegated OAuth access requires the user consent flow; autonomous access uses a suitable grant",
            "Integrate an existing identity provider rather than creating another user directory for each agent",
            "Keep tokens and API keys out of prompts and logs; scope credentials to the intended user and provider"
          ]
        },
        {
          "title": "Short-term and long-term Memory",
          "bullets": [
            "Short-term Memory stores conversation events grouped by actor ID and session ID",
            "Long-term Memory extracts useful knowledge across sessions through configured memory strategies",
            "Strategies can retain facts, user preferences and summaries; no strategy means no automatic extraction",
            "Namespaces organize long-term records; choose retrieval scope and access rules for each tenant",
            "Your agent retrieves and supplies relevant memories as context; this does not train the model weights"
          ]
        },
        {
          "title": "Browser and Code Interpreter",
          "bullets": [
            "Browser provides isolated sessions for navigating sites, filling forms and reading web content",
            "Browser automation works with libraries such as Playwright; Live View allows human interaction",
            "Custom browsers can record sessions to S3 for replay; recording is a configured feature",
            "Code Interpreter executes Python, JavaScript and TypeScript in a managed sandbox for data tasks",
            "Configure tool networking and roles, save useful outputs, and close sessions when work is complete"
          ]
        },
        {
          "title": "Policy for tool governance",
          "bullets": [
            "Associate a policy engine with Gateway to evaluate tool requests before the target is called",
            "Policies can constrain the caller, tool and input parameters, such as a permitted transaction amount",
            "Author rules in Cedar or compatible Dogwood; natural language authoring generates policies for review",
            "The policy engine uses default-deny and forbid-wins semantics; test both allowed and denied calls",
            "Gateway policy governs that access path; backend IAM and application authorization still matter"
          ]
        },
        {
          "title": "Observability and debugging",
          "bullets": [
            "AgentCore Observability exposes logs, metrics and traces through Amazon CloudWatch",
            "OpenTelemetry-compatible instrumentation records model calls, tool spans and agent execution paths",
            "Built-in metrics exist by default; detailed traces and additional spans depend on telemetry setup",
            "Inspect session latency, token usage and error rates; separate model delays from failed tool calls",
            "Choose log retention and redact sensitive content before adding prompts or tool results to telemetry"
          ]
        },
        {
          "title": "Evaluations and quality checks",
          "bullets": [
            "Evaluations measures agent and tool behavior using built-in evaluators or custom evaluation logic",
            "Use on-demand or batch assessment for test data, and online evaluation for sampled production traces",
            "Evaluation requires supported framework instrumentation and the relevant telemetry configuration",
            "Compare task completion, answer quality and tool use before changing prompts, models or tool schemas",
            "Quality scores help diagnose behavior; they do not replace deterministic tool access policies"
          ]
        },
        {
          "title": "Practical deployment choices",
          "bullets": [
            "Check Region availability for every chosen component, model and credential-provider integration",
            "Budget for the AgentCore components you use plus model inference and downstream service charges",
            "Keep development and production endpoints, credentials and memory scopes separate",
            "Make tools retry-safe: a repeated model or network request must not repeat an unwanted side effect",
            "Pin dependencies and validate auth, memory retrieval and tool failures with realistic test sessions"
          ]
        }
      ],
      "guide": "services/agentcore.html"
    },
    {
      "id": "mq",
      "name": "Amazon MQ",
      "shortName": "Amazon MQ",
      "category": "integration",
      "summary": "Managed message brokers compatible with Apache ActiveMQ and RabbitMQ.",
      "details": "Amazon MQ provisions managed brokers for applications that use supported messaging protocols and broker APIs. It can reduce broker operations when migrating existing applications, while retaining broker concepts such as queues, exchanges, and connections.",
      "useCases": [
        "Lift-and-shift broker workloads",
        "Existing AMQP or JMS applications",
        "Managed ActiveMQ or RabbitMQ"
      ],
      "concepts": [
        "Broker engines and deployment modes",
        "Protocols and client libraries",
        "VPC connectivity",
        "Broker storage and failover"
      ],
      "considerations": [
        "Applications remain coupled to broker semantics and client compatibility.",
        "Broker sizing, networking, and engine versions require planning."
      ],
      "docs": "https://docs.aws.amazon.com/amazon-mq/latest/developer-guide/welcome.html",
      "sources": [
        {
          "title": "Amazon MQ documentation",
          "url": "https://docs.aws.amazon.com/amazon-mq/latest/developer-guide/welcome.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "amplify",
      "name": "AWS Amplify",
      "shortName": "Amplify",
      "category": "developer",
      "summary": "Builds and hosts web and mobile apps with AWS-connected tooling.",
      "details": "Amplify offers frontend hosting and application development tooling that can connect apps to AWS backend capabilities. Amplify Hosting builds from source repositories; backend workflows and supported frameworks evolve, so consult current feature support before choosing an architecture.",
      "useCases": [
        "Host a frontend from Git commits",
        "Add authentication and data capabilities to an app",
        "Preview branch deployments"
      ],
      "concepts": [
        "Hosting connects to Git repositories",
        "build settings define build output",
        "branch deployments support preview flows",
        "backend resources use AWS services"
      ],
      "considerations": [
        "Framework and backend feature support changes over time",
        "Secure build secrets and generated backend permissions"
      ],
      "docs": "https://docs.aws.amazon.com/amplify/latest/userguide/welcome.html",
      "sources": [
        {
          "title": "AWS Amplify documentation",
          "url": "https://docs.aws.amazon.com/amplify/latest/userguide/welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "api-gateway",
      "name": "Amazon API Gateway",
      "shortName": "API Gateway",
      "category": "integration",
      "summary": "Creates and manages HTTP, REST, and WebSocket APIs.",
      "details": "API Gateway handles API entry points, request routing, authorization, throttling, and integrations with services such as Lambda and HTTP backends. Private APIs can use VPC endpoints, while regional and edge-optimized API patterns differ.",
      "useCases": [
        "Serverless API front ends",
        "Public or private REST endpoints",
        "WebSocket applications"
      ],
      "concepts": [
        "REST, HTTP, and WebSocket APIs",
        "Stages and deployments",
        "Authorizers and throttling",
        "Lambda and service integrations"
      ],
      "considerations": [
        "API type determines available features and pricing.",
        "Authentication and backend permissions require explicit configuration."
      ],
      "docs": "https://docs.aws.amazon.com/apigateway/latest/developerguide/welcome.html",
      "sources": [
        {
          "title": "Amazon API Gateway documentation",
          "url": "https://docs.aws.amazon.com/apigateway/latest/developerguide/welcome.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "app-mesh",
      "name": "AWS App Mesh",
      "shortName": "App Mesh",
      "category": "network",
      "summary": "Service mesh for controlling communication between microservices.",
      "details": "AWS App Mesh provides service-to-service traffic management, observability, and security patterns through Envoy proxies and mesh configuration. AWS announced end of support effective September 30, 2026, so as of this catalog date it is retired; workloads should migrate to a supported alternative.",
      "useCases": [
        "legacy microservice traffic management",
        "service-level telemetry",
        "gradual traffic shifting"
      ],
      "concepts": [
        "The retired service used Envoy proxies to apply mesh routing and telemetry configuration to workloads.",
        "Virtual services, routers, and nodes represented application communication paths in a mesh.",
        "AWS ended App Mesh support on September 30, 2026; existing architectures need a documented migration plan."
      ],
      "considerations": [
        "Service reached end of support on 2026-09-30",
        "Plan migration; existing applications may require mesh-specific configuration changes"
      ],
      "docs": "https://docs.aws.amazon.com/app-mesh/",
      "sources": [
        {
          "title": "AWS App Mesh documentation",
          "url": "https://docs.aws.amazon.com/app-mesh/"
        },
        {
          "title": "AWS App Mesh service details",
          "url": "https://docs.aws.amazon.com/app-mesh/latest/userguide/what-is-app-mesh.html"
        },
        {
          "title": "AWS App Mesh end of support",
          "url": "https://docs.aws.amazon.com/app-mesh/latest/userguide/what-is-app-mesh.html"
        }
      ],
      "status": "retired",
      "statusNote": "AWS ended support for App Mesh on 2026-09-30. See lifecycle notice.",
      "kind": "service"
    },
    {
      "id": "app-runner",
      "name": "AWS App Runner",
      "shortName": "App Runner",
      "category": "compute",
      "summary": "Builds and runs web applications and APIs from source code or container images.",
      "details": "App Runner provisions a managed application service from a source repository or ECR image and handles deployment, scaling, health checks, and an HTTPS endpoint. It can connect to private VPC resources through a VPC connector.",
      "useCases": [
        "Web services from source repositories",
        "Containerized APIs",
        "Small services with managed deployment"
      ],
      "concepts": [
        "Services and deployments",
        "Source or image configuration",
        "Auto scaling",
        "VPC connectors"
      ],
      "considerations": [
        "Private outbound access uses a VPC connector; public ingress and outbound access are separate concerns.",
        "Runtime, Region, and feature availability should be checked for the target workload."
      ],
      "docs": "https://docs.aws.amazon.com/apprunner/latest/dg/what-is-apprunner.html",
      "sources": [
        {
          "title": "AWS App Runner documentation",
          "url": "https://docs.aws.amazon.com/apprunner/latest/dg/what-is-apprunner.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "app-studio",
      "name": "AWS App Studio",
      "shortName": "App Studio",
      "category": "developer",
      "summary": "Creates business applications through a generative AI-assisted interface.",
      "details": "App Studio helps users build, publish, and manage business applications using visual tooling and AWS-connected data sources. It targets internal business apps and is distinct from a general-purpose application runtime; access and data connections need organizational governance.",
      "useCases": [
        "Create an internal operations application",
        "Build a workflow over business data",
        "Publish an app to organizational users"
      ],
      "concepts": [
        "visual app builder defines pages and actions",
        "data sources connect business systems",
        "applications can be published to users",
        "identity and access govern app use"
      ],
      "considerations": [
        "Assess current Region and preview/GA availability",
        "Constrain connected data and published user access"
      ],
      "docs": "https://docs.aws.amazon.com/appstudio/latest/userguide/welcome.html",
      "sources": [
        {
          "title": "AWS App Studio documentation",
          "url": "https://docs.aws.amazon.com/appstudio/latest/userguide/welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "app2container",
      "name": "AWS App2Container",
      "shortName": "App2Container",
      "category": "containers",
      "summary": "Assessment and migration tool for containerizing existing applications.",
      "details": "AWS App2Container analyzes supported application servers, generates container artifacts, and can produce deployment templates for AWS targets. It is a migration tool that helps create artifacts; customers still review, build, secure, deploy, and operate the resulting containers.",
      "useCases": [
        "migrating Java applications",
        "containerizing .NET applications",
        "creating deployment artifacts"
      ],
      "concepts": [
        "The tool analyzes supported application servers and creates containerization artifacts from application workloads.",
        "Generated artifacts can include Dockerfiles, container images, and deployment templates for AWS targets.",
        "The tool prepares a migration starting point; teams still review and operate the resulting containers."
      ],
      "considerations": [
        "Generated containers may need application-specific changes",
        "Check current supported operating systems and application platforms"
      ],
      "docs": "https://docs.aws.amazon.com/app2container/",
      "sources": [
        {
          "title": "AWS App2Container documentation",
          "url": "https://docs.aws.amazon.com/app2container/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "appconfig",
      "name": "AWS AppConfig",
      "shortName": "AppConfig",
      "category": "management",
      "summary": "Safely changes application behavior through feature flags and dynamic configuration without redeploying application code.",
      "details": "Applications retrieve validated configuration through the AppConfig Agent or data-plane APIs. Deployment strategies can gradually expose a change, while CloudWatch alarms can trigger rollback; configuration sources include the hosted store, Systems Manager Parameter Store, Secrets Manager, and S3.",
      "useCases": [
        "release a feature to a small audience before general availability",
        "change operational limits or logging levels without redeploying",
        "roll back a configuration that correlates with a CloudWatch alarm"
      ],
      "concepts": [
        "applications and environments scope configuration",
        "validators check configuration before rollout",
        "AppConfig Agent caches configuration and polls for updates",
        "deployment strategies control rollout pace"
      ],
      "considerations": [
        "applications must read and apply the configuration safely",
        "retrieval volume, polling cadence, and rollout strategy affect cost and risk"
      ],
      "docs": "https://docs.aws.amazon.com/appconfig/latest/userguide/what-is-appconfig.html",
      "sources": [
        {
          "title": "What is AWS AppConfig?",
          "url": "https://docs.aws.amazon.com/appconfig/latest/userguide/what-is-appconfig.html"
        },
        {
          "title": "How AWS AppConfig works",
          "url": "https://docs.aws.amazon.com/appconfig/latest/userguide/what-is-appconfig.html"
        },
        {
          "title": "What is AWS AppConfig Agent?",
          "url": "https://docs.aws.amazon.com/appconfig/latest/userguide/appconfig-agent.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "appfabric",
      "name": "AWS AppFabric",
      "shortName": "AppFabric",
      "category": "business",
      "summary": "Connects supported SaaS apps to normalize audit logs and apply security policies.",
      "details": "AppFabric can ingest audit data from supported SaaS applications and normalize records for security tools. It also offers user-access management for selected apps; connector coverage determines available functions.",
      "useCases": [
        "centralize SaaS audit events",
        "investigate account activity",
        "apply access policies across supported apps"
      ],
      "concepts": [
        "App bundles group selected SaaS connections",
        "Audit events can be normalized to OCSF",
        "Application support determines access and ingestion features"
      ],
      "considerations": [
        "SaaS API permissions and subscription tiers limit collected data",
        "Check current app support and service availability before adoption."
      ],
      "docs": "https://docs.aws.amazon.com/appfabric/",
      "sources": [
        {
          "title": "AWS AppFabric documentation",
          "url": "https://docs.aws.amazon.com/appfabric/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "appflow",
      "name": "Amazon AppFlow",
      "shortName": "AppFlow",
      "category": "integration",
      "summary": "Moves records between supported SaaS applications and AWS services.",
      "details": "AppFlow defines flows with source and destination connectors, field mappings, filters, and on-demand, scheduled, or event-based triggers. Destinations include services such as S3 and Redshift, and private transfer is supported for selected connectors.",
      "useCases": [
        "SaaS data ingestion",
        "Scheduled CRM synchronization",
        "No-code data movement to AWS analytics"
      ],
      "concepts": [
        "Connector catalogs",
        "Source/destination mappings",
        "Filters and triggers",
        "Private flow options"
      ],
      "considerations": [
        "Connector and trigger support varies by SaaS provider.",
        "Data transformation is designed for flow mapping, not arbitrary ETL code."
      ],
      "docs": "https://docs.aws.amazon.com/appflow/latest/userguide/",
      "sources": [
        {
          "title": "What is Amazon AppFlow?",
          "url": "https://docs.aws.amazon.com/appflow/latest/userguide/"
        },
        {
          "title": "AppFlow flows",
          "url": "https://docs.aws.amazon.com/appflow/latest/userguide/flows.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "application-discovery-service",
      "name": "AWS Application Discovery Service",
      "shortName": "Application Discovery Service",
      "category": "migration",
      "summary": "Collects server inventory and dependency data to plan migrations.",
      "details": "Discovery Service gathers configuration, utilization, and behavior data from on-premises servers to support migration planning. AWS stopped accepting new customers on November 7, 2025; existing projects can continue, and AWS Transform is the recommended path for new discovery work.",
      "useCases": [
        "Inventory servers before migration",
        "Map dependencies between workloads",
        "Export utilization data for planning"
      ],
      "concepts": [
        "agentless collector uses VMware data",
        "agents collect detailed server metrics",
        "data can be grouped into applications",
        "Migration Hub can consume discovery inventory"
      ],
      "considerations": [
        "Restricted to existing customers since 2025-11-07",
        "AWS Transform is recommended for new discovery projects"
      ],
      "docs": "https://docs.aws.amazon.com/application-discovery/latest/userguide/what-is-appdiscovery.html",
      "sources": [
        {
          "title": "AWS Application Discovery Service documentation",
          "url": "https://docs.aws.amazon.com/application-discovery/latest/userguide/what-is-appdiscovery.html"
        },
        {
          "title": "AWS lifecycle announcement / guidance",
          "url": "https://docs.aws.amazon.com/application-discovery/latest/userguide/application-discovery-service-availability-change.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS stopped accepting new customers on 2025-11-07; AWS Transform is recommended for new work.",
      "kind": "service"
    },
    {
      "id": "application-migration-service",
      "name": "AWS Application Migration Service (AWS MGN)",
      "shortName": "Application Migration Service (MGN)",
      "category": "migration",
      "summary": "Replicates source servers for lift-and-shift migration to AWS.",
      "details": "AWS MGN continuously replicates source disks into a staging area and launches test or cutover instances in AWS. It is designed for rehosting and supports non-disruptive tests; application validation, cutover planning, and source compatibility remain customer responsibilities.",
      "useCases": [
        "Rehost VMware or physical servers to EC2",
        "Test migrated servers before cutover",
        "Migrate workloads with limited downtime"
      ],
      "concepts": [
        "agent-based replication captures block data",
        "staging area holds replicated volumes",
        "test and cutover launches create target instances",
        "Migration Hub can receive status updates"
      ],
      "considerations": [
        "Validate boot, networking, and application behavior in tests",
        "Plan replication network and cutover sequencing"
      ],
      "docs": "https://docs.aws.amazon.com/mgn/latest/ug/what-is-application-migration-service.html",
      "sources": [
        {
          "title": "AWS Application Migration Service (AWS MGN) documentation",
          "url": "https://docs.aws.amazon.com/mgn/latest/ug/what-is-application-migration-service.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "amazonarc",
      "name": "Amazon Application Recovery Controller (ARC)",
      "shortName": "Application Recovery Controller (ARC)",
      "category": "network",
      "summary": "Application Recovery Controller features for managing failover and recovery readiness.",
      "details": "Amazon Application Recovery Controller (ARC) provides routing control, readiness checks, and zonal shift capabilities for supported AWS workloads. It helps operators coordinate recovery actions but does not automatically make an application resilient; architecture and recovery procedures must be designed and tested.",
      "useCases": [
        "multi-Region recovery controls",
        "readiness checks",
        "zonal traffic shift"
      ],
      "concepts": [
        "Routing controls let operators shift traffic between application cells through supported routing integrations.",
        "Readiness checks compare application configuration against defined recovery readiness rules.",
        "ARC provides control and assessment features; application redundancy and tested recovery procedures remain design responsibilities."
      ],
      "considerations": [
        "Feature support differs by resource and Region",
        "Failover actions need tested runbooks and carefully scoped permissions"
      ],
      "docs": "https://docs.aws.amazon.com/amazonarc/",
      "sources": [
        {
          "title": "Amazon Application Recovery Controller (ARC) documentation",
          "url": "https://docs.aws.amazon.com/amazonarc/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "appsync",
      "name": "AWS AppSync",
      "shortName": "AppSync",
      "category": "integration",
      "summary": "Managed GraphQL and real-time API service.",
      "details": "AppSync exposes GraphQL APIs with schema-based resolvers to data sources including DynamoDB, Lambda, and HTTP endpoints. It supports subscriptions for real-time updates and can federate data through resolver logic.",
      "useCases": [
        "GraphQL application backends",
        "Real-time collaboration features",
        "Unified API over multiple data sources"
      ],
      "concepts": [
        "Schemas and resolvers",
        "DynamoDB and Lambda data sources",
        "Subscriptions",
        "API authorization modes"
      ],
      "considerations": [
        "Resolver design controls data access and performance.",
        "GraphQL authorization and subscription behavior need explicit policy choices."
      ],
      "docs": "https://docs.aws.amazon.com/appsync/latest/devguide/what-is-appsync.html",
      "sources": [
        {
          "title": "AWS AppSync documentation",
          "url": "https://docs.aws.amazon.com/appsync/latest/devguide/what-is-appsync.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "artifact",
      "name": "AWS Artifact",
      "shortName": "Artifact",
      "category": "security",
      "summary": "Provides on-demand access to AWS compliance reports and agreements.",
      "details": "Artifact is a self-service portal for AWS audit reports and certain agreements. Customers can review applicable reports, accept agreements where offered, and manage account-level compliance documentation.",
      "useCases": [
        "Retrieve AWS audit reports",
        "Review service compliance documentation",
        "Accept applicable AWS agreements"
      ],
      "concepts": [
        "reports are downloadable documents",
        "agreements may require acceptance",
        "access is account-scoped",
        "reports describe AWS controls"
      ],
      "considerations": [
        "AWS reports do not establish customer workload compliance",
        "Report availability and scope depend on service"
      ],
      "docs": "https://docs.aws.amazon.com/artifact/latest/ug/what-is-aws-artifact.html",
      "sources": [
        {
          "title": "AWS Artifact documentation",
          "url": "https://docs.aws.amazon.com/artifact/latest/ug/what-is-aws-artifact.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "athena",
      "name": "Amazon Athena",
      "shortName": "Athena",
      "category": "analytics",
      "summary": "Serverless SQL query service for data in S3 and supported federated sources.",
      "details": "Analysts submit SQL without provisioning database servers; query engines and connectors determine supported formats and sources. Athena commonly uses Glue Data Catalog metadata, but catalog and connector configuration are choices.",
      "useCases": [
        "ad hoc analysis of S3 logs",
        "query lakehouse tables",
        "federate SQL to supported databases"
      ],
      "concepts": [
        "Workgroups separate query workloads, settings, access, and usage controls.",
        "Catalogs provide metadata that helps Athena locate tables and schemas.",
        "Athena runs SQL queries over data in Amazon S3.",
        "Federated connectors let Athena query supported external data sources in place."
      ],
      "considerations": [
        "Queries still consume scanned or provisioned resources",
        "partitioning, formats, and access policies affect cost and performance."
      ],
      "docs": "https://docs.aws.amazon.com/athena/latest/ug/what-is.html",
      "sources": [
        {
          "title": "Amazon Athena documentation",
          "url": "https://docs.aws.amazon.com/athena/latest/ug/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "audit-manager",
      "name": "AWS Audit Manager",
      "shortName": "Audit Manager",
      "category": "security",
      "summary": "Collects evidence to help assess AWS usage against audit frameworks.",
      "details": "Audit Manager maps controls to evidence sources and can collect evidence from supported AWS services. Assessments organize evidence for review and export; the service helps prepare audits but does not certify compliance or replace auditor judgment.",
      "useCases": [
        "Prepare evidence for a compliance assessment",
        "Track control evidence over time",
        "Organize audit artifacts by framework"
      ],
      "concepts": [
        "assessments contain controls and evidence",
        "frameworks can be standard or custom",
        "evidence is collected from integrations",
        "delegated administration supports Organizations"
      ],
      "considerations": [
        "Validate evidence relevance with auditors",
        "Enable the required data collection integrations"
      ],
      "docs": "https://docs.aws.amazon.com/audit-manager/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "AWS Audit Manager documentation",
          "url": "https://docs.aws.amazon.com/audit-manager/latest/userguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "aurora",
      "name": "Amazon Aurora",
      "shortName": "Aurora",
      "category": "database",
      "summary": "AWS relational database compatible with MySQL and PostgreSQL, built for managed cloud operation.",
      "details": "Aurora separates compute instances from a distributed cluster storage layer and offers provisioned and Serverless options. Compatibility is not identical to every upstream engine feature.",
      "useCases": [
        "run a highly available web application database",
        "scale a PostgreSQL-compatible service",
        "support read-heavy transactional workloads"
      ],
      "concepts": [
        "An Aurora cluster combines database instances with a shared cluster storage volume.",
        "Writer instances handle updates; reader instances can serve read traffic.",
        "Cluster storage grows as data is written, within service limits.",
        "Aurora Serverless configurations adjust database capacity based on workload demand."
      ],
      "considerations": [
        "Check engine compatibility, failover behavior, and regional feature availability",
        "architecture differs from self-managed upstream databases."
      ],
      "docs": "https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/CHAP_AuroraOverview.html",
      "sources": [
        {
          "title": "Amazon Aurora documentation",
          "url": "https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/CHAP_AuroraOverview.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "aurora-dsql",
      "name": "Amazon Aurora DSQL",
      "shortName": "Aurora DSQL",
      "category": "database",
      "summary": "Serverless distributed SQL database for resilient applications requiring multi-Region operation.",
      "details": "Aurora DSQL supports PostgreSQL-compatible interfaces and active-active multi-Region clusters with managed consistency behavior. Its cluster lifecycle can scale idle resources down while preserving data.",
      "useCases": [
        "build globally distributed transactional services",
        "coordinate multi-Region business records",
        "run PostgreSQL-compatible SQL without managing servers"
      ],
      "concepts": [
        "clusters",
        "multi-Region peering",
        "PostgreSQL compatibility",
        "scale to zero"
      ],
      "considerations": [
        "Validate SQL and transaction semantics against application needs",
        "first connections after idle or inactive states may be slower."
      ],
      "docs": "https://docs.aws.amazon.com/aurora-dsql/latest/userguide/what-is-aurora-dsql.html",
      "sources": [
        {
          "title": "Amazon Aurora DSQL documentation",
          "url": "https://docs.aws.amazon.com/aurora-dsql/latest/userguide/what-is-aurora-dsql.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "backup",
      "name": "AWS Backup",
      "shortName": "AWS Backup",
      "category": "storage",
      "summary": "Centralizes policy-based backup and recovery for supported AWS resources.",
      "details": "AWS Backup defines backup plans, vaults, retention, and restore operations across supported services and selected hybrid resources. It can apply organization-wide governance and support logically air-gapped vaults in supported configurations.",
      "useCases": [
        "Centralized backup policies",
        "Cross-account recovery controls",
        "Compliance retention"
      ],
      "concepts": [
        "Backup plans and rules",
        "Vaults and recovery points",
        "Resource assignments",
        "Cross-account and cross-Region copies"
      ],
      "considerations": [
        "Supported resource types and advanced capabilities vary.",
        "Backup policy does not replace workload-specific recovery testing."
      ],
      "docs": "https://docs.aws.amazon.com/aws-backup/latest/devguide/whatisbackup.html",
      "sources": [
        {
          "title": "AWS Backup documentation",
          "url": "https://docs.aws.amazon.com/aws-backup/latest/devguide/whatisbackup.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "cli",
      "name": "AWS Command Line Interface",
      "shortName": "AWS CLI",
      "category": "management",
      "summary": "A command-line tool for managing AWS services from scripts, terminals, and automation.",
      "details": "The AWS CLI sends signed API requests using a configured credential and Region context, and exposes commands for many AWS services. Named profiles and credential providers let operators separate accounts and environments, while commands can be composed into repeatable operational workflows.",
      "useCases": [
        "inspect resources from a terminal",
        "automate repeatable deployments in CI",
        "manage multiple accounts through named profiles"
      ],
      "concepts": [
        "service commands map to AWS API operations",
        "profiles select credentials and default settings",
        "credential providers include IAM Identity Center and role assumption",
        "output formats support scripting and inspection"
      ],
      "considerations": [
        "protect credentials and prefer short-lived role credentials",
        "CLI command coverage and options can vary by version"
      ],
      "docs": "https://docs.aws.amazon.com/cli/latest/userguide/cli-chap-welcome.html",
      "sources": [
        {
          "title": "What is the AWS Command Line Interface?",
          "url": "https://docs.aws.amazon.com/cli/latest/userguide/cli-chap-welcome.html"
        },
        {
          "title": "Configuration and credential file settings",
          "url": "https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-files.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "signin",
      "name": "AWS Sign-In",
      "shortName": "AWS Sign-In",
      "category": "security",
      "summary": "AWS Sign-In provides authentication entry points for AWS accounts, consoles, and supported applications. Its console access controls can evaluate policies before and after authentication.",
      "details": "The sign-in path depends on the identity type, including root users, IAM users, IAM Identity Center users, and federated identities. AWS Sign-In policies can restrict supported console access using conditions such as source network and principal, but do not control API calls signed with SigV4.",
      "useCases": [
        "sign in to AWS accounts and the Management Console",
        "apply supported network conditions to console access",
        "authorize supported OAuth sign-in flows"
      ],
      "concepts": [
        "Identity type determines the applicable sign-in experience",
        "Pre-authentication policy checks can evaluate source and principal conditions",
        "Post-authentication checks can evaluate the authenticated principal"
      ],
      "considerations": [
        "Sign-in policies do not govern programmatic API requests signed with SigV4",
        "Policy mistakes can block console access, so preserve tested emergency access."
      ],
      "docs": "https://docs.aws.amazon.com/signin/",
      "sources": [
        {
          "title": "AWS Sign-In Documentation",
          "url": "https://docs.aws.amazon.com/signin/"
        },
        {
          "title": "Controlling console access with resource-based policies and resource control policies",
          "url": "https://docs.aws.amazon.com/signin/latest/userguide/console-access-control.html"
        }
      ],
      "status": "active",
      "statusNote": "Active; AWS Sign-In has its own service endpoints and authorization reference.",
      "kind": "tool"
    },
    {
      "id": "b2b-data-interchange",
      "name": "AWS B2B Data Interchange",
      "shortName": "B2B Data Interchange",
      "category": "integration",
      "summary": "Managed service for exchanging and transforming electronic data interchange (EDI) documents.",
      "details": "AWS B2B Data Interchange ingests EDI documents, validates them against trading-partner agreements, and converts supported formats to and from JSON or XML. It integrates with S3 and EventBridge to support event-driven exchange workflows.",
      "useCases": [
        "automated trading-partner document exchange",
        "EDI validation and translation",
        "event-driven supply-chain workflows"
      ],
      "concepts": [
        "Trading-partner agreements define the validation rules applied to incoming EDI documents.",
        "Supported EDI formats can be transformed to JSON or XML, and mappings can be configured for partner workflows.",
        "S3 document events and EventBridge rules can connect file arrival to processing workflows."
      ],
      "considerations": [
        "Confirm supported EDI standards and transaction sets",
        "Trading-partner onboarding and exception handling require configuration"
      ],
      "docs": "https://docs.aws.amazon.com/b2bi/",
      "sources": [
        {
          "title": "AWS B2B Data Interchange documentation",
          "url": "https://docs.aws.amazon.com/b2bi/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "batch",
      "name": "AWS Batch",
      "shortName": "Batch",
      "category": "compute",
      "summary": "Queues and schedules batch jobs across managed AWS compute capacity.",
      "details": "AWS Batch uses job definitions, queues, and compute environments to schedule containerized work. Compute environments can use EC2, Fargate, ECS Managed Instances, or EKS, with scaling and placement driven by queued demand.",
      "useCases": [
        "Scientific simulations",
        "Media and data processing",
        "High-throughput ML training queues"
      ],
      "concepts": [
        "Job definitions",
        "Queue priorities and dependencies",
        "Compute environments",
        "EC2, Fargate, ECS Managed Instances or EKS"
      ],
      "considerations": [
        "Fargate compute environments use ECS orchestration, not EKS.",
        "Jobs must be designed for queueing, retries, timeouts, and available resource shapes."
      ],
      "docs": "https://docs.aws.amazon.com/batch/latest/userguide/what-is-batch.html",
      "sources": [
        {
          "title": "What is AWS Batch?",
          "url": "https://docs.aws.amazon.com/batch/latest/userguide/what-is-batch.html"
        },
        {
          "title": "AWS Batch components",
          "url": "https://docs.aws.amazon.com/batch/latest/userguide/batch_components.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "bedrock",
      "name": "Amazon Bedrock",
      "shortName": "Bedrock",
      "category": "ai",
      "summary": "Managed access to foundation models and tools for building generative AI applications.",
      "details": "Applications call a unified API to use models from AWS and third-party providers, then add knowledge bases, guardrails, agents, or evaluations as needed. Model choice and feature availability vary by Region and provider.",
      "useCases": [
        "grounded support assistants",
        "content summarization pipelines",
        "model evaluation before release"
      ],
      "concepts": [
        "Choose from supported foundation models through a common set of service APIs; model availability varies by Region.",
        "Knowledge Bases can retrieve connected source data to ground model responses.",
        "Guardrails apply selected content filters and policies to model inputs and outputs.",
        "Agents can coordinate model calls and configured actions for multi-step tasks."
      ],
      "considerations": [
        "Model behavior and costs vary by model",
        "evaluate quality, safety, and latency with representative prompts."
      ],
      "docs": "https://docs.aws.amazon.com/bedrock/latest/userguide/what-is-bedrock.html",
      "sources": [
        {
          "title": "Amazon Bedrock documentation",
          "url": "https://docs.aws.amazon.com/bedrock/latest/userguide/what-is-bedrock.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "account-billing",
      "name": "AWS Billing and Cost Management",
      "shortName": "Billing and Cost Management",
      "category": "cost",
      "summary": "Account tools for viewing charges, managing payment, and understanding AWS spend.",
      "details": "The billing console brings together invoices, payments, credits, tax settings, cost analysis, and account-level billing preferences. Cost allocation tags, consolidated billing, and exports help organizations connect charges to teams and workloads, but require deliberate account and data configuration.",
      "useCases": [
        "review monthly invoices and payment status",
        "allocate costs to teams using tags and accounts",
        "export usage data for internal finance analysis"
      ],
      "concepts": [
        "Bills shows charges by service and linked account",
        "Cost Explorer supports historical and forecast views",
        "billing data exports can deliver detailed cost and usage data to S3"
      ],
      "considerations": [
        "cost allocation tags must be activated before they appear in reports",
        "billing views can lag usage and do not replace organization-specific accounting"
      ],
      "docs": "https://docs.aws.amazon.com/cost-management/latest/userguide/what-is-costmanagement.html",
      "sources": [
        {
          "title": "What is AWS Billing and Cost Management?",
          "url": "https://docs.aws.amazon.com/cost-management/latest/userguide/what-is-costmanagement.html"
        },
        {
          "title": "Understanding your bill",
          "url": "https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/billing-what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "braket",
      "name": "Amazon Braket",
      "shortName": "Braket",
      "category": "specialist",
      "summary": "Managed quantum service for algorithms, simulators, and quantum hardware.",
      "details": "Braket provides notebooks, circuit and analog tools, simulators, and selected quantum processing units. Hybrid jobs coordinate classical and quantum work; providers, devices, and Regions vary.",
      "useCases": [
        "prototype quantum algorithms",
        "compare simulator and hardware results",
        "run hybrid experiments"
      ],
      "concepts": [
        "Device abstractions expose simulator and hardware options",
        "Jobs submit tasks and retrieve results asynchronously",
        "Hybrid jobs coordinate classical and quantum steps"
      ],
      "considerations": [
        "Hardware has provider-specific queues and error behavior",
        "Notebook, simulator, and device usage can incur separate costs."
      ],
      "docs": "https://docs.aws.amazon.com/braket/",
      "sources": [
        {
          "title": "Amazon Braket documentation",
          "url": "https://docs.aws.amazon.com/braket/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "budgets",
      "name": "AWS Budgets",
      "shortName": "Budgets",
      "category": "cost",
      "summary": "Sets cost, usage, or reservation alert thresholds.",
      "details": "Budgets track actual or forecasted values against defined limits and can notify subscribers or invoke supported actions. Alerts are useful guardrails, but they may arrive after usage occurs and do not inherently cap every AWS charge.",
      "useCases": [
        "Alert owners when monthly spend rises",
        "Track service-specific usage thresholds",
        "Notify on reservation utilization"
      ],
      "concepts": [
        "budget periods can be monthly, quarterly, or annual",
        "actual and forecast thresholds are available",
        "SNS notifications can deliver alerts",
        "actions can apply selected controls"
      ],
      "considerations": [
        "Budgets are not instantaneous hard spending caps",
        "Verify alert recipients and action permissions"
      ],
      "docs": "https://docs.aws.amazon.com/cost-management/latest/userguide/budgets-managing-costs.html",
      "sources": [
        {
          "title": "AWS Budgets documentation",
          "url": "https://docs.aws.amazon.com/cost-management/latest/userguide/budgets-managing-costs.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "certificate-manager",
      "name": "AWS Certificate Manager",
      "shortName": "Certificate Manager",
      "category": "security",
      "summary": "Issues and manages TLS certificates for supported AWS endpoints.",
      "details": "ACM provisions public certificates and manages renewal for integrated services, while private certificates can be issued through ACM Private CA. Certificate deployment is constrained by supported services and Regions; exported public certificates have separate usage patterns.",
      "useCases": [
        "Secure CloudFront or load balancer endpoints",
        "Automate certificate renewal",
        "Manage certificates for internal services"
      ],
      "concepts": [
        "public certificates can be free for integrated services",
        "renewal is managed for eligible integrations",
        "private certificates use Private CA",
        "certificates have DNS or email validation"
      ],
      "considerations": [
        "Check regional and service integration requirements",
        "Track imported certificates and expiration separately"
      ],
      "docs": "https://docs.aws.amazon.com/acm/latest/userguide/acm-overview.html",
      "sources": [
        {
          "title": "AWS Certificate Manager documentation",
          "url": "https://docs.aws.amazon.com/acm/latest/userguide/acm-overview.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "chime",
      "name": "Amazon Chime",
      "shortName": "Chime",
      "category": "business",
      "summary": "Former meetings and business-calling service; AWS support ended February 20, 2026.",
      "details": "Amazon Chime provided meetings, chat, and business calling to existing Team and Enterprise accounts. AWS ended support on February 20, 2026; the separate Chime SDK remains available.",
      "useCases": [
        "historical service reference",
        "inventory legacy meeting use",
        "distinguish Chime from Chime SDK"
      ],
      "concepts": [
        "Chime application and Chime SDK were separate offerings",
        "The service included meetings, chat, and business calling",
        "AWS ended support on February 20, 2026"
      ],
      "considerations": [
        "The service is no longer available or supported",
        "Chime SDK availability does not continue the former application."
      ],
      "docs": "https://docs.aws.amazon.com/chime/latest/ag/amazon-chime-transition-features.html",
      "sources": [
        {
          "title": "Amazon Chime documentation",
          "url": "https://docs.aws.amazon.com/chime/latest/ag/amazon-chime-transition-features.html"
        }
      ],
      "status": "retired",
      "statusNote": "Retired; AWS ended support February 20, 2026. Verified 2026-10-08.",
      "kind": "service"
    },
    {
      "id": "chime-sdk",
      "name": "Amazon Chime SDK",
      "shortName": "Chime SDK",
      "category": "business",
      "summary": "SDK building blocks for adding real-time audio, video, and messaging to applications.",
      "details": "Client libraries and APIs provide communication sessions while developers supply the user experience and business logic. The SDK is distinct from the retired Chime meetings service and features vary by Region.",
      "useCases": [
        "in-app video appointments",
        "live audio rooms",
        "application chat"
      ],
      "concepts": [
        "Meeting sessions provide audio, video, and screen-share primitives",
        "Messaging APIs support persistent conversations and channels",
        "Applications integrate SDK clients with their own backend"
      ],
      "considerations": [
        "Applications must implement identity, authorization, and interface behavior",
        "Check current feature and Region availability."
      ],
      "docs": "https://docs.aws.amazon.com/chime-sdk/",
      "sources": [
        {
          "title": "Amazon Chime SDK documentation",
          "url": "https://docs.aws.amazon.com/chime-sdk/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "claude-platform",
      "name": "Claude Platform on AWS",
      "shortName": "Claude Platform on AWS",
      "category": "ai",
      "summary": "Anthropic Claude platform APIs available through AWS account access and billing.",
      "details": "Claude Platform on AWS exposes Anthropic's Messages API and platform features using AWS access controls and billing integration, while Anthropic operates the inference infrastructure. This differs from Amazon Bedrock: data may not reside in AWS, and geography, retention, terms, and available features need deliberate review.",
      "useCases": [
        "Messages API applications",
        "batch model inference",
        "agent workflows using Anthropic tools"
      ],
      "concepts": [
        "The offering exposes Anthropic's Messages API through AWS account access and billing integration.",
        "Anthropic operates the inference infrastructure, so data location and processing terms differ from Bedrock's AWS-operated model path.",
        "API features and model availability follow Anthropic's platform documentation and can differ by account or geography."
      ],
      "considerations": [
        "Anthropic and AWS have distinct data-processing roles; review applicable terms and residency controls",
        "Model availability, retention settings, and feature support differ from Bedrock"
      ],
      "docs": "https://docs.aws.amazon.com/claude-platform/",
      "sources": [
        {
          "title": "Claude Platform on AWS documentation",
          "url": "https://docs.aws.amazon.com/claude-platform/"
        },
        {
          "title": "Claude Platform on AWS service details",
          "url": "https://docs.aws.amazon.com/claude-platform/latest/userguide/welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "clean-rooms",
      "name": "AWS Clean Rooms",
      "shortName": "Clean Rooms",
      "category": "analytics",
      "summary": "Enables organizations to collaborate on data analysis without sharing underlying raw datasets directly.",
      "details": "Collaboration members configure tables, analysis rules, and approved query or ML workflows. Results and allowed operations are constrained by collaboration privacy controls.",
      "useCases": [
        "measure campaign overlap",
        "analyze partner audience cohorts",
        "collaborate on approved SQL metrics"
      ],
      "concepts": [
        "collaborations",
        "configured tables",
        "analysis rules",
        "privacy controls"
      ],
      "considerations": [
        "Privacy depends on query restrictions and governance choices",
        "validate permitted outputs with collaborators."
      ],
      "docs": "https://docs.aws.amazon.com/clean-rooms/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "AWS Clean Rooms documentation",
          "url": "https://docs.aws.amazon.com/clean-rooms/latest/userguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "client-vpn",
      "name": "AWS Client VPN",
      "shortName": "Client VPN",
      "category": "network",
      "summary": "Managed client VPN for remote user access to AWS and on-premises networks.",
      "details": "Client VPN provides a TLS-based VPN endpoint through which authorized clients connect to target networks. Authorization rules, authentication configuration, routes, and subnet associations determine reachable resources.",
      "useCases": [
        "Remote workforce access",
        "Contractor access to VPCs",
        "Secure remote administration"
      ],
      "concepts": [
        "Client VPN endpoint",
        "Mutual, directory, or federated auth",
        "Routes and authorization rules",
        "Target network associations"
      ],
      "considerations": [
        "Client routes and authorization rules are separate controls.",
        "Capacity, split-tunnel behavior, and endpoint placement affect connectivity."
      ],
      "docs": "https://docs.aws.amazon.com/vpn/latest/clientvpn-user/client-vpn-user-what-is.html",
      "sources": [
        {
          "title": "AWS Client VPN documentation",
          "url": "https://docs.aws.amazon.com/vpn/latest/clientvpn-user/client-vpn-user-what-is.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "cloudcontrolapi",
      "name": "AWS Cloud Control API",
      "shortName": "Cloud Control API",
      "category": "developer",
      "summary": "Consistent API for creating, reading, updating, deleting, and listing AWS resources.",
      "details": "AWS Cloud Control API exposes a common resource operation interface backed by CloudFormation resource types. It can also manage some third-party resources through registered extensions; coverage depends on available resource providers and does not make every service feature available through the API.",
      "useCases": [
        "custom infrastructure tooling",
        "consistent resource lifecycle operations",
        "multi-provider automation"
      ],
      "concepts": [
        "Create, read, update, delete, and list operations use a common API shape across supported resource types.",
        "Resource types must be available and activated in the account; some CloudFormation registry types do not support Cloud Control API operations.",
        "A resource type schema defines its properties and handler permissions, which determine how a request can be made."
      ],
      "considerations": [
        "Check provider support and handler capabilities for each resource",
        "Operations can be asynchronous and return progress events"
      ],
      "docs": "https://docs.aws.amazon.com/cloudcontrolapi/",
      "sources": [
        {
          "title": "AWS Cloud Control API documentation",
          "url": "https://docs.aws.amazon.com/cloudcontrolapi/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "cdk",
      "name": "AWS Cloud Development Kit (AWS CDK)",
      "shortName": "Cloud Development Kit (CDK)",
      "category": "developer",
      "summary": "Defines cloud infrastructure with general-purpose programming languages.",
      "details": "CDK constructs synthesize to CloudFormation templates, combining reusable abstractions with imperative language tooling. The synthesized output is what CloudFormation deploys, so teams should review it and manage bootstrap resources and deployment permissions.",
      "useCases": [
        "Build reusable infrastructure patterns",
        "Version infrastructure with application code",
        "Deploy stacks through CI pipelines"
      ],
      "concepts": [
        "constructs compose into apps and stacks",
        "synth generates CloudFormation templates",
        "bootstrap provisions deployment support resources",
        "context and assets affect synthesis"
      ],
      "considerations": [
        "Review synthesized templates and dependency changes",
        "Pin dependencies and control bootstrap privileges"
      ],
      "docs": "https://docs.aws.amazon.com/cdk/v2/guide/home.html",
      "sources": [
        {
          "title": "AWS Cloud Development Kit (AWS CDK) documentation",
          "url": "https://docs.aws.amazon.com/cdk/v2/guide/home.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "clouddirectory",
      "name": "Amazon Cloud Directory",
      "shortName": "Cloud Directory",
      "category": "security",
      "summary": "A managed hierarchical directory for application-specific data organized across multiple dimensions.",
      "details": "Cloud Directory stores nodes and typed facets in a schema-controlled tree that can support multiple parent-child relationships. Applications use it for flexible directory structures where a relational table or a single LDAP-style hierarchy is not a natural fit. AWS no longer accepts new customers and has announced end of support for July 24, 2027.",
      "useCases": [
        "model organizational units with alternate reporting views",
        "store device or user relationships across dimensions",
        "build an application directory with evolving typed attributes"
      ],
      "concepts": [
        "schemas define facets and allowed attributes",
        "nodes hold directory objects and relationships",
        "indexes support lookup by selected attributes",
        "multiple parent relationships support different hierarchies"
      ],
      "considerations": [
        "Cloud Directory is an application data store, not a general identity provider",
        "design schemas and indexes around access patterns and lifecycle needs"
      ],
      "docs": "https://docs.aws.amazon.com/clouddirectory/latest/developerguide/what_is_cloud_directory.html",
      "sources": [
        {
          "title": "What is Amazon Cloud Directory?",
          "url": "https://docs.aws.amazon.com/clouddirectory/latest/developerguide/what_is_cloud_directory.html"
        },
        {
          "title": "Cloud Directory Resources and lifecycle notice",
          "url": "https://docs.aws.amazon.com/clouddirectory/latest/developerguide/resources.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS no longer accepts new Cloud Directory customers and has announced end of support on July 24, 2027; AWS identifies DynamoDB and Neptune as alternatives.",
      "kind": "service"
    },
    {
      "id": "cloud-map",
      "name": "AWS Cloud Map",
      "shortName": "Cloud Map",
      "category": "network",
      "summary": "Service discovery for cloud resources and application services.",
      "details": "Cloud Map lets applications register named resources and discover them through DNS or API calls. ECS and other applications can publish service instances, while clients resolve names to endpoints.",
      "useCases": [
        "Service discovery in microservices",
        "Resource discovery by custom attributes",
        "Dynamic endpoint lookup"
      ],
      "concepts": [
        "Namespaces and services",
        "Instances and attributes",
        "DNS and API discovery",
        "Health-aware discovery"
      ],
      "considerations": [
        "Clients must use supported discovery mechanisms and correct namespace scope.",
        "Registration and health state need to reflect actual service readiness."
      ],
      "docs": "https://docs.aws.amazon.com/cloud-map/latest/dg/what-is-cloud-map.html",
      "sources": [
        {
          "title": "AWS Cloud Map documentation",
          "url": "https://docs.aws.amazon.com/cloud-map/latest/dg/what-is-cloud-map.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "cloud9",
      "name": "AWS Cloud9",
      "shortName": "Cloud9",
      "category": "developer",
      "summary": "Browser-based IDE with a managed cloud development environment.",
      "details": "Cloud9 provides a browser IDE and backed environment that can run on EC2 or connect to SSH hosts. AWS closed access to new customers on July 25, 2024, while existing customers can continue; AWS points users toward IDE toolkits or CloudShell.",
      "useCases": [
        "Maintain an existing Cloud9 environment",
        "Develop from a browser-accessible workspace",
        "Run AWS CLI commands beside cloud resources"
      ],
      "concepts": [
        "environment can be EC2-backed or SSH-connected",
        "shared environment access has IAM implications",
        "browser IDE includes terminal and editor",
        "CloudShell and IDE toolkits are suggested alternatives"
      ],
      "considerations": [
        "Restricted to existing customers",
        "Plan migration of repositories, extensions, and environment setup"
      ],
      "docs": "https://docs.aws.amazon.com/cloud9/latest/user-guide/welcome.html",
      "sources": [
        {
          "title": "AWS Cloud9 documentation",
          "url": "https://docs.aws.amazon.com/cloud9/latest/user-guide/welcome.html"
        },
        {
          "title": "AWS lifecycle announcement / guidance",
          "url": "https://aws.amazon.com/blogs/devops/how-to-migrate-from-aws-cloud9-to-aws-ide-toolkits-or-aws-cloudshell/"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS stopped new customer access on 2024-07-25; existing customers can continue.",
      "kind": "service"
    },
    {
      "id": "cloudformation",
      "name": "AWS CloudFormation",
      "shortName": "CloudFormation",
      "category": "management",
      "summary": "Models AWS infrastructure as declarative stacks.",
      "details": "CloudFormation provisions resources from templates and tracks them as stacks or stack sets. Change sets preview proposed updates, while drift detection identifies differences between declared and live state for supported resource properties.",
      "useCases": [
        "Create repeatable infrastructure environments",
        "Roll out resources across accounts and Regions",
        "Review proposed infrastructure changes"
      ],
      "concepts": [
        "templates describe resources and dependencies",
        "stacks manage lifecycle",
        "change sets preview changes",
        "StackSets deploy across accounts and Regions"
      ],
      "considerations": [
        "Template updates can replace or delete resources",
        "Drift detection covers supported properties only"
      ],
      "docs": "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/Welcome.html",
      "sources": [
        {
          "title": "AWS CloudFormation documentation",
          "url": "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/Welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "cloudfront",
      "name": "Amazon CloudFront",
      "shortName": "CloudFront",
      "category": "network",
      "summary": "Global content delivery and application edge service.",
      "details": "CloudFront serves content through edge locations and can use S3 buckets, load balancers, API endpoints, or other origins. Caching behavior, origin access, TLS, and optional security integrations shape delivery.",
      "useCases": [
        "Static and media delivery",
        "Application acceleration",
        "Edge request handling"
      ],
      "concepts": [
        "Distributions and origins",
        "Cache behaviors and invalidations",
        "Origin access control",
        "TLS and edge functions"
      ],
      "considerations": [
        "Cache configuration affects freshness and origin load.",
        "Private origin access and viewer access policies require careful setup."
      ],
      "docs": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/Introduction.html",
      "sources": [
        {
          "title": "Amazon CloudFront documentation",
          "url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/Introduction.html"
        },
        {
          "title": "CloudFront cache expiration",
          "url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/Expiration.html"
        },
        {
          "title": "CloudFront standard logging v2",
          "url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/standard-logging.html"
        },
        {
          "title": "CloudFront flat-rate pricing plans",
          "url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/flat-rate-pricing-plan.html"
        },
        {
          "title": "CloudFront pricing",
          "url": "https://aws.amazon.com/cloudfront/pricing/"
        }
      ],
      "status": "active",
      "kind": "service",
      "topics": [
        {
          "title": "Distributions and behaviors",
          "bullets": [
            "A distribution has a dxxxx.cloudfront.net domain and one or more origins.",
            "Origins can be S3 buckets, load balancers, EC2 or other HTTP servers, API Gateway.",
            "Path behaviors are checked in order; the default behavior catches the rest.",
            "Path patterns are case-sensitive; the first matching pattern wins.",
            "GET and HEAD are cached (OPTIONS if enabled); POST, PUT and DELETE go to the origin."
          ]
        },
        {
          "title": "Caching and invalidation",
          "bullets": [
            "The cache key decides which requests share an object; each extra part splits it.",
            "Forward extra headers, cookies or query strings with an origin request policy instead.",
            "Min, default and max TTL control caching; positive min TTL overrides private and no-store.",
            "Invalidations are not instant; check their status. Wildcard paths are allowed.",
            "Versioned file names avoid invalidation: a changed file gets a new URL."
          ]
        },
        {
          "title": "OAC for S3 origins",
          "bullets": [
            "Origin access control (OAC) lets CloudFront sign requests to a private S3 bucket.",
            "Keep Block Public Access on; the bucket policy grants access to this distribution only.",
            "OAC is the current method; origin access identity (OAI) is the legacy setup.",
            "The S3 static website endpoint cannot use OAC; point the origin at the REST endpoint.",
            "SSE-KMS objects also need the distribution allowed in the KMS key policy."
          ]
        },
        {
          "title": "HTTPS and custom domains",
          "bullets": [
            "Viewer protocol policy can allow HTTP, redirect HTTP to HTTPS, or require HTTPS.",
            "Custom domains are alternate domain names (CNAMEs) on the distribution.",
            "The ACM certificate for CloudFront must be requested in us-east-1 (N. Virginia).",
            "A bare apex domain needs an ALIAS or Route 53 alias record; a CNAME is not allowed.",
            "One alternate domain name can be attached to only one distribution at a time."
          ]
        },
        {
          "title": "AWS WAF integration",
          "bullets": [
            "A web ACL attached to the distribution filters requests at the edge.",
            "CloudFront-scope web ACLs must be created in us-east-1.",
            "Start from AWS managed rule groups, then add rate-based rules for abusive clients.",
            "Pay-as-you-go WAF bills per ACL, rule and request; flat-rate plans include eligible WAF usage.",
            "Requests that reach the origin directly skip WAF, so lock the origin to CloudFront."
          ]
        },
        {
          "title": "Restricting viewer access",
          "bullets": [
            "Signed URLs grant one object; signed cookies grant access to several files.",
            "Use trusted key groups to verify signatures; root-account key pairs are legacy.",
            "Sign on the server; the private key must never reach the browser.",
            "Geo restriction allowlists or blocklists countries by viewer IP address.",
            "Geo rules use the viewer IP, so VPNs bypass them; they are not authentication."
          ]
        },
        {
          "title": "Functions vs Lambda@Edge",
          "bullets": [
            "CloudFront Functions run JavaScript at edge locations, on viewer events only.",
            "CloudFront Functions have tight run time and memory limits and cannot make network calls.",
            "Lambda@Edge runs Node.js or Python on viewer and origin events and can call services.",
            "Lambda@Edge functions must be created in us-east-1 and attached by published version.",
            "Use CloudFront Functions for header and URL rewrites; Lambda@Edge for heavier logic."
          ]
        },
        {
          "title": "Origin groups and failover",
          "bullets": [
            "An origin group pairs one primary origin with one secondary origin.",
            "The secondary is used when the primary returns a status code you list, such as 503.",
            "Failover applies only to GET, HEAD and OPTIONS; other methods get no failover.",
            "Test failover by making the primary return a listed status code.",
            "Origin Shield adds one regional cache layer that reduces origin load; it is billed extra."
          ]
        },
        {
          "title": "Logging and metrics",
          "bullets": [
            "Standard logging v2 sends delayed access logs to S3, CloudWatch Logs or Firehose.",
            "Real-time logs send chosen fields and a sampling rate to Kinesis Data Streams.",
            "Standard CloudWatch metrics are free and are reported in us-east-1.",
            "Origin latency is a paid additional-metrics option, enabled per distribution.",
            "Logging is not retroactive; turn it on before an incident, not during one."
          ]
        },
        {
          "title": "Pricing model",
          "bullets": [
            "Pay-as-you-go bills viewer transfer per GB and requests by region and HTTP/HTTPS type.",
            "Flat-rate plans bundle CDN, eligible WAF, DNS, Functions and log ingestion for a monthly price.",
            "Price classes drop some edge locations to lower cost; excluded regions use farther edges.",
            "Lambda@Edge bills per request and GB-second; Functions bill per invocation outside flat-rate plans.",
            "Pay-as-you-go invalidations beyond the free allowance bill per path; version assets to avoid them."
          ]
        },
        {
          "title": "Common patterns",
          "bullets": [
            "Static site: private S3 bucket behind OAC, with a default root object of index.html.",
            "Static site: short TTL on HTML, long TTL on hashed asset file names.",
            "Single-page app: map 403 and 404 responses to index.html with a 200 status.",
            "API acceleration: use CachingDisabled or short TTLs; forward needed headers via policy.",
            "Mixed site: path behaviors route /static/ to S3 and /api/ to the API origin."
          ]
        },
        {
          "title": "Common pitfalls",
          "bullets": [
            "Putting all cookies or headers in the cache key drops the hit ratio sharply.",
            "For private user responses, disable caching or use min TTL 0 with private/no-store headers.",
            "The default root object applies only to the site root, not to subfolder URLs.",
            "S3 returns 403, not 404, for missing objects unless ListBucket is granted.",
            "By default the origin sees its own Host; forward Host if it routes by Host header."
          ]
        }
      ],
      "guide": "services/cloudfront.html"
    },
    {
      "id": "cloudhsm",
      "name": "AWS CloudHSM",
      "shortName": "CloudHSM",
      "category": "security",
      "summary": "Provides customer-controlled hardware security modules in an AWS VPC.",
      "details": "CloudHSM offers dedicated HSMs in a cluster for cryptographic workloads requiring control of HSM users and keys. Applications connect through supported client software and use standard cryptographic interfaces; AWS manages underlying availability infrastructure while customers administer HSM contents.",
      "useCases": [
        "Meet HSM-backed key custody requirements",
        "Run PKCS #11 or JCE cryptographic applications",
        "Perform signing with customer-controlled keys"
      ],
      "concepts": [
        "single-tenant HSMs in customer VPC",
        "cluster spans Availability Zones",
        "customer manages HSM users and keys",
        "supports industry standard interfaces"
      ],
      "considerations": [
        "Application integration and HSM administration are customer tasks",
        "Design quorum and backup procedures"
      ],
      "docs": "https://docs.aws.amazon.com/cloudhsm/latest/userguide/introduction.html",
      "sources": [
        {
          "title": "AWS CloudHSM documentation",
          "url": "https://docs.aws.amazon.com/cloudhsm/latest/userguide/introduction.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "cloudsearch",
      "name": "Amazon CloudSearch",
      "shortName": "CloudSearch",
      "category": "analytics",
      "summary": "Managed search service for indexing and querying application content.",
      "details": "Amazon CloudSearch provisions a search domain and manages indexing, query endpoints, and scaling configuration for supported text-search workloads. It is no longer available to new customers; AWS documentation points existing customers to Amazon OpenSearch Service for modern search needs.",
      "useCases": [
        "site and catalog search",
        "application document search",
        "basic faceted queries"
      ],
      "concepts": [
        "A search domain indexes documents and exposes endpoints for submitting search queries.",
        "Domain configuration controls indexing fields, search behavior, and scaling settings.",
        "CloudSearch is closed to new customers; AWS identifies OpenSearch Service as a migration option for existing users."
      ],
      "considerations": [
        "Existing-customer-only service; verify account eligibility before planning a deployment",
        "Assess migration to Amazon OpenSearch Service and review schema and query portability"
      ],
      "docs": "https://docs.aws.amazon.com/cloudsearch/",
      "sources": [
        {
          "title": "Amazon CloudSearch documentation",
          "url": "https://docs.aws.amazon.com/cloudsearch/"
        },
        {
          "title": "Amazon CloudSearch service details",
          "url": "https://docs.aws.amazon.com/cloudsearch/latest/developerguide/what-is-cloudsearch.html"
        },
        {
          "title": "Amazon CloudSearch availability and overview",
          "url": "https://docs.aws.amazon.com/cloudsearch/latest/developerguide/what-is-cloudsearch.html"
        }
      ],
      "status": "restricted",
      "statusNote": "Amazon CloudSearch is no longer available to new customers; existing customers can continue to use it.",
      "kind": "service"
    },
    {
      "id": "cloudshell",
      "name": "AWS CloudShell",
      "shortName": "CloudShell",
      "category": "developer",
      "summary": "Browser-based shell with AWS CLI access in the AWS console.",
      "details": "AWS CloudShell provides a per-Region shell environment with common tools and credentials for the signed-in console identity. Files persist within documented limits, while home-directory data and environment behavior are Region-specific; it is a console tool, not a general-purpose managed host.",
      "useCases": [
        "one-off AWS CLI administration",
        "testing SDK and CLI commands",
        "working with files in the console"
      ],
      "concepts": [
        "CloudShell starts with credentials for the signed-in console identity in the selected Region.",
        "The shell includes common command-line tools and AWS CLI access without requiring a local installation.",
        "Files and home-directory data are retained within CloudShell's documented storage limits and Region scope."
      ],
      "considerations": [
        "Use least-privilege console permissions and protect stored files",
        "Session and storage limits apply"
      ],
      "docs": "https://docs.aws.amazon.com/cloudshell/",
      "sources": [
        {
          "title": "AWS CloudShell documentation",
          "url": "https://docs.aws.amazon.com/cloudshell/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "cloudtrail",
      "name": "AWS CloudTrail",
      "shortName": "CloudTrail",
      "category": "management",
      "summary": "Records AWS API activity for governance, investigation, and audit.",
      "details": "CloudTrail event history shows recent management events, while trails or event data stores provide configurable retention and analysis. Organization trails can capture activity across accounts; data events must be selected for supported high-volume resource operations.",
      "useCases": [
        "Audit console and API actions",
        "Detect changes to sensitive resources",
        "Analyze data access events"
      ],
      "concepts": [
        "management events record control-plane actions",
        "data events are separately configurable",
        "organization trails cover member accounts",
        "CloudTrail Lake supports SQL queries"
      ],
      "considerations": [
        "Configure multi-Region collection and protected storage",
        "Data event selectors determine coverage and volume"
      ],
      "docs": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-user-guide.html",
      "sources": [
        {
          "title": "AWS CloudTrail documentation",
          "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-user-guide.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "cloudwatch",
      "name": "Amazon CloudWatch",
      "shortName": "CloudWatch",
      "category": "management",
      "summary": "Collects metrics, logs, traces, and alarms for AWS resources and applications.",
      "details": "CloudWatch provides telemetry ingestion, dashboards, alarms, and log analysis. AWS services publish metrics or logs through different paths; actions can notify SNS or invoke automation, while detailed retention and dimensions need deliberate design.",
      "useCases": [
        "Alert on service health thresholds",
        "Search application logs",
        "Visualize infrastructure metrics"
      ],
      "concepts": [
        "metrics are time series with dimensions",
        "alarms evaluate metric or composite conditions",
        "Logs Insights queries log groups",
        "dashboards combine widgets"
      ],
      "considerations": [
        "Choose retention and cardinality intentionally",
        "Telemetry coverage varies by service and configuration"
      ],
      "docs": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/WhatIsCloudWatch.html",
      "sources": [
        {
          "title": "Amazon CloudWatch documentation",
          "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/WhatIsCloudWatch.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "codeartifact",
      "name": "AWS CodeArtifact",
      "shortName": "CodeArtifact",
      "category": "developer",
      "summary": "Managed artifact repository for software packages and dependencies.",
      "details": "AWS CodeArtifact stores and shares packages for supported ecosystems, including npm, Maven, Python, NuGet, and generic packages. Repositories can proxy public upstreams and connect to other repositories; clients authenticate with AWS credentials and package-manager configuration.",
      "useCases": [
        "private package hosting",
        "dependency caching",
        "sharing packages across teams"
      ],
      "concepts": [
        "A domain groups repositories and is the encryption boundary for package assets.",
        "Repositories can use upstream repositories to proxy external package sources and can connect through repository endpoints.",
        "Package clients obtain a short-lived authorization token before publishing or installing artifacts."
      ],
      "considerations": [
        "Repository access requires IAM and package-manager setup",
        "Storage and requests are billed; consider retention and upstream policy"
      ],
      "docs": "https://docs.aws.amazon.com/codeartifact/",
      "sources": [
        {
          "title": "AWS CodeArtifact documentation",
          "url": "https://docs.aws.amazon.com/codeartifact/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "codebuild",
      "name": "AWS CodeBuild",
      "shortName": "CodeBuild",
      "category": "developer",
      "summary": "Builds and tests source code in managed build environments.",
      "details": "CodeBuild executes build commands in projects using selected source, environment, and artifacts settings. It can run within a VPC and integrate with CodePipeline; build roles should have only the permissions and secret access required by the build.",
      "useCases": [
        "Compile and test application commits",
        "Build container images for ECR",
        "Run pipeline build stages"
      ],
      "concepts": [
        "buildspec.yml describes build phases",
        "project service role grants AWS access",
        "artifacts can go to S3",
        "webhooks and pipelines trigger builds"
      ],
      "considerations": [
        "Untrusted pull requests need restricted secrets and roles",
        "Pin build images and dependencies"
      ],
      "docs": "https://docs.aws.amazon.com/codebuild/latest/userguide/welcome.html",
      "sources": [
        {
          "title": "AWS CodeBuild documentation",
          "url": "https://docs.aws.amazon.com/codebuild/latest/userguide/welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "codecatalyst",
      "name": "Amazon CodeCatalyst",
      "shortName": "CodeCatalyst",
      "category": "developer",
      "summary": "Provides an integrated space for planning, source, workflows, and development environments.",
      "details": "CodeCatalyst combines project management, source repositories, workflows, and Dev Environments in a managed development space. AWS closed access to new customers on November 7, 2025; existing customers can continue under the announced lifecycle, making it a restricted legacy option.",
      "useCases": [
        "Continue existing CodeCatalyst projects",
        "Run source workflows in an existing space",
        "Use managed dev environments for legacy projects"
      ],
      "concepts": [
        "spaces contain projects",
        "workflows automate CI/CD",
        "Dev Environments are cloud development environments",
        "AWS account connections enable deployments"
      ],
      "considerations": [
        "New customers cannot onboard after 2025-11-07",
        "Use AWS’s lifecycle guidance when planning transition"
      ],
      "docs": "https://docs.aws.amazon.com/codecatalyst/latest/userguide/welcome.html",
      "sources": [
        {
          "title": "Amazon CodeCatalyst documentation",
          "url": "https://docs.aws.amazon.com/codecatalyst/latest/userguide/welcome.html"
        },
        {
          "title": "AWS lifecycle announcement / guidance",
          "url": "https://docs.aws.amazon.com/codecatalyst/latest/userguide/migration.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS stopped accepting new customers and creating new spaces on 2025-11-07; existing customers can continue.",
      "kind": "service"
    },
    {
      "id": "codecommit",
      "name": "AWS CodeCommit",
      "shortName": "CodeCommit",
      "category": "developer",
      "summary": "Hosts private Git repositories integrated with AWS identity and developer tools.",
      "details": "CodeCommit provides managed Git repositories with IAM access controls and CloudTrail logging. AWS announced that new customer sign-ups reopened in November 2025 after a 2024 de-emphasis, so lifecycle assumptions based on the older announcement are outdated.",
      "useCases": [
        "Host AWS-contained application source",
        "Connect repository changes to CodePipeline",
        "Control Git access with IAM policies"
      ],
      "concepts": [
        "managed Git repositories",
        "IAM authorization and HTTPS/SSH access",
        "CloudTrail records repository API activity",
        "integrates with CodeBuild and CodePipeline"
      ],
      "considerations": [
        "Confirm regional availability for the account",
        "Older 2024 retirement messaging was superseded by Nov 2025 GA announcement"
      ],
      "docs": "https://docs.aws.amazon.com/codecommit/latest/userguide/welcome.html",
      "sources": [
        {
          "title": "AWS CodeCommit documentation",
          "url": "https://docs.aws.amazon.com/codecommit/latest/userguide/welcome.html"
        },
        {
          "title": "AWS lifecycle announcement / guidance",
          "url": "https://aws.amazon.com/blogs/devops/aws-codecommit-returns-to-general-availability/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "codedeploy",
      "name": "AWS CodeDeploy",
      "shortName": "CodeDeploy",
      "category": "developer",
      "summary": "Automates application deployments to supported compute targets.",
      "details": "CodeDeploy coordinates deployments to EC2/on-premises instances, Lambda, or ECS through target-specific deployment configurations. Application revisions, deployment groups, and lifecycle hooks define rollout behavior and rollback handling.",
      "useCases": [
        "Roll out EC2 application revisions",
        "Shift Lambda traffic between versions",
        "Deploy ECS task definition updates"
      ],
      "concepts": [
        "deployment groups select targets",
        "AppSpec defines deployment steps",
        "hooks run lifecycle scripts",
        "deployment configurations control rollout"
      ],
      "considerations": [
        "Validate rollback and health checks before production",
        "EC2 deployments need agents and correctly scoped roles"
      ],
      "docs": "https://docs.aws.amazon.com/codedeploy/latest/userguide/welcome.html",
      "sources": [
        {
          "title": "AWS CodeDeploy documentation",
          "url": "https://docs.aws.amazon.com/codedeploy/latest/userguide/welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "codeguru",
      "name": "Amazon CodeGuru",
      "shortName": "CodeGuru",
      "category": "ai",
      "summary": "Developer tools for code review and runtime performance recommendations.",
      "details": "Amazon CodeGuru includes Reviewer for automated code-review recommendations and Profiler for analyzing application runtime behavior. These capabilities integrate into developer workflows but do not replace human review, testing, or production observability; check current availability and supported languages before adoption.",
      "useCases": [
        "finding code quality issues",
        "profiling application CPU and latency",
        "reviewing changes in CI"
      ],
      "concepts": [
        "Reviewer produces code-review recommendations, while Profiler identifies runtime behavior and performance patterns.",
        "Profiler findings depend on supported runtimes and application instrumentation.",
        "Recommendations supplement developer review and testing; they do not establish that code is correct or performant."
      ],
      "considerations": [
        "Recommendation coverage and supported languages are limited",
        "Compare current service availability and costs with alternatives"
      ],
      "docs": "https://docs.aws.amazon.com/codeguru/",
      "sources": [
        {
          "title": "Amazon CodeGuru documentation",
          "url": "https://docs.aws.amazon.com/codeguru/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "codepipeline",
      "name": "AWS CodePipeline",
      "shortName": "CodePipeline",
      "category": "developer",
      "summary": "Orchestrates source, build, test, and deployment stages.",
      "details": "CodePipeline models a release as stages and actions, coordinating provider integrations and artifact handoffs. It can use CodeBuild and CodeDeploy or third-party actions; approvals and IAM roles define deployment boundaries.",
      "useCases": [
        "Automate a multi-stage release",
        "Promote artifacts from test to production",
        "Require approval before production deployment"
      ],
      "concepts": [
        "pipelines contain stages and actions",
        "artifacts are passed between actions",
        "connections integrate external source providers",
        "execution modes affect concurrency"
      ],
      "considerations": [
        "Protect pipeline roles and artifact stores",
        "Review action provider availability by Region"
      ],
      "docs": "https://docs.aws.amazon.com/codepipeline/latest/userguide/welcome.html",
      "sources": [
        {
          "title": "AWS CodePipeline documentation",
          "url": "https://docs.aws.amazon.com/codepipeline/latest/userguide/welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "cognito",
      "name": "Amazon Cognito",
      "shortName": "Cognito",
      "category": "security",
      "summary": "Adds user sign-up, sign-in, and identity federation to applications.",
      "details": "Cognito user pools provide user directories and token-based authentication; identity pools exchange identities for temporary AWS credentials. Hosted UI and federation can simplify common sign-in flows, while application authorization remains the app’s responsibility.",
      "useCases": [
        "Add registration and sign-in to a mobile app",
        "Federate social or enterprise identities",
        "Issue temporary credentials for selected AWS access"
      ],
      "concepts": [
        "user pools authenticate and issue JWTs",
        "identity pools broker AWS credentials",
        "supports OIDC and SAML federation",
        "triggers can customize select workflows"
      ],
      "considerations": [
        "Validate tokens and configure app clients carefully",
        "Do not treat authentication as application authorization"
      ],
      "docs": "https://docs.aws.amazon.com/cognito/latest/developerguide/what-is-amazon-cognito.html",
      "sources": [
        {
          "title": "Amazon Cognito documentation",
          "url": "https://docs.aws.amazon.com/cognito/latest/developerguide/what-is-amazon-cognito.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "comprehend",
      "name": "Amazon Comprehend",
      "shortName": "Comprehend",
      "category": "ai",
      "summary": "Extracts language insights such as entities, sentiment, key phrases, and classification from text.",
      "details": "It supports pretrained analysis and custom classifiers or entity recognizers, with synchronous and batch workflows. Some capabilities are specialized for medical text under Comprehend Medical.",
      "useCases": [
        "route feedback by topic",
        "extract entities from contracts",
        "classify support messages"
      ],
      "concepts": [
        "entities",
        "sentiment",
        "custom classification",
        "batch analysis"
      ],
      "considerations": [
        "Outputs are model predictions and need evaluation on representative text",
        "language and feature support varies."
      ],
      "docs": "https://docs.aws.amazon.com/comprehend/latest/dg/what-is.html",
      "sources": [
        {
          "title": "Amazon Comprehend documentation",
          "url": "https://docs.aws.amazon.com/comprehend/latest/dg/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "comprehend-medical",
      "name": "Amazon Comprehend Medical",
      "shortName": "Comprehend Medical",
      "category": "ai",
      "summary": "Natural-language processing service for extracting information from clinical text.",
      "details": "Amazon Comprehend Medical identifies medical entities, relationships, and protected health information in unstructured clinical text through APIs and batch jobs. It supports healthcare text processing, but output is machine-generated and must be validated for the intended clinical or operational use.",
      "useCases": [
        "clinical note entity extraction",
        "de-identification workflows",
        "coding and analytics preparation"
      ],
      "concepts": [
        "Medical entity recognition extracts clinical concepts such as medications, conditions, and procedures from text.",
        "PHI detection identifies protected health information and supports de-identification workflows.",
        "Batch APIs process document collections from S3, while synchronous APIs handle individual text requests."
      ],
      "considerations": [
        "Do not treat output as diagnosis or clinical advice",
        "Review HIPAA eligibility, Region coverage, and data handling requirements"
      ],
      "docs": "https://docs.aws.amazon.com/comprehend-medical/",
      "sources": [
        {
          "title": "Amazon Comprehend Medical documentation",
          "url": "https://docs.aws.amazon.com/comprehend-medical/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "compute-optimizer",
      "name": "AWS Compute Optimizer",
      "shortName": "Compute Optimizer",
      "category": "management",
      "summary": "Recommends right-sizing for supported compute resources.",
      "details": "Compute Optimizer analyzes historical utilization and configuration to recommend resource types or settings for supported EC2, EBS, Lambda, ECS, and other resources. Recommendations are decision support; workload performance requirements and licensing still matter.",
      "useCases": [
        "Right-size underused EC2 instances",
        "Review EBS volume configuration",
        "Evaluate Lambda memory settings"
      ],
      "concepts": [
        "recommendations use utilization lookback data",
        "enhanced metrics can improve granularity",
        "organization management aggregates accounts",
        "recommendation preferences tune assumptions"
      ],
      "considerations": [
        "Recommendations reflect observed history, not future peaks",
        "Validate performance and licensing before changing resources"
      ],
      "docs": "https://docs.aws.amazon.com/compute-optimizer/latest/ug/what-is-compute-optimizer.html",
      "sources": [
        {
          "title": "AWS Compute Optimizer documentation",
          "url": "https://docs.aws.amazon.com/compute-optimizer/latest/ug/what-is-compute-optimizer.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "config",
      "name": "AWS Config",
      "shortName": "Config",
      "category": "management",
      "summary": "Records resource configurations and evaluates configuration rules.",
      "details": "Config discovers supported resources, stores configuration history, and evaluates rules for desired settings. Conformance packs group rules and remediation actions can be attached, while account and Region coverage must be configured.",
      "useCases": [
        "Track resource configuration changes",
        "Check compliance with internal rules",
        "Investigate a resource’s historical state"
      ],
      "concepts": [
        "configuration items capture resource state",
        "managed and custom rules evaluate settings",
        "conformance packs bundle controls",
        "aggregators centralize multi-account views"
      ],
      "considerations": [
        "Coverage depends on recorder configuration and resource support",
        "Automated remediation can affect production resources"
      ],
      "docs": "https://docs.aws.amazon.com/config/latest/developerguide/WhatIsConfig.html",
      "sources": [
        {
          "title": "AWS Config documentation",
          "url": "https://docs.aws.amazon.com/config/latest/developerguide/WhatIsConfig.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "connect",
      "name": "Amazon Connect Customer",
      "shortName": "Connect Customer",
      "category": "business",
      "summary": "Cloud contact center for voice and digital customer interactions.",
      "details": "Contact flows, queues, and routing profiles direct work to agents. Optional analytics, outbound campaigns, and customer profiles add distinct capabilities with separate configuration.",
      "useCases": [
        "customer support queues",
        "web chat operations",
        "outbound appointment reminders"
      ],
      "concepts": [
        "Contact flows define interaction paths and routing",
        "Queues and routing profiles connect work with available agents",
        "Channel and add-on availability varies by Region"
      ],
      "considerations": [
        "Telephony features and channel availability vary by Region",
        "Staffing, compliance, and flow design remain customer responsibilities."
      ],
      "docs": "https://docs.aws.amazon.com/connect/",
      "sources": [
        {
          "title": "Amazon Connect Customer documentation",
          "url": "https://docs.aws.amazon.com/connect/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "connect-decisions",
      "name": "Amazon Connect Decisions",
      "shortName": "Connect Decisions",
      "category": "business",
      "summary": "Supply-chain planning and decisioning with AI teammates for coordination tasks.",
      "details": "AWS documentation now covers Amazon Connect Decisions and keeps separate legacy AWS Supply Chain material. It combines planning workflows with supply-chain data; verify current feature and account eligibility.",
      "useCases": [
        "demand planning",
        "coordinate supply-chain exceptions",
        "review planning scenarios"
      ],
      "concepts": [
        "Data connections provide planning inputs",
        "Forecasts and insights help planners identify exceptions",
        "AI teammates assist coordination within the product"
      ],
      "considerations": [
        "New and legacy product documentation coexist",
        "Check onboarding and Region availability."
      ],
      "docs": "https://docs.aws.amazon.com/connect-decisions/",
      "sources": [
        {
          "title": "Amazon Connect Decisions documentation",
          "url": "https://docs.aws.amazon.com/connect-decisions/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "connecthealth",
      "name": "Amazon Connect Health",
      "shortName": "Connect Health",
      "category": "ai",
      "summary": "Healthcare AI service for automating patient engagement and clinical documentation workflows.",
      "details": "Amazon Connect Health provides prebuilt agents for voice-based patient interactions and clinical workflows, with EHR integration through FHIR R4 APIs; current documentation identifies compatibility with Epic. Generated information can be wrong and must be reviewed by qualified staff; regulatory status depends on feature and jurisdiction.",
      "useCases": [
        "patient scheduling and engagement",
        "clinical ambient documentation",
        "healthcare contact-center workflows"
      ],
      "concepts": [
        "Prebuilt agents support voice patient interactions and clinical documentation workflows.",
        "EHR connectivity uses FHIR R4 APIs, with current documentation identifying Epic compatibility.",
        "AI-generated clinical content requires review by qualified staff before it is relied on in care workflows."
      ],
      "considerations": [
        "Confirm regional feature and medical-device status; UK ambient documentation is Class I",
        "Clinicians remain responsible for accuracy and care decisions"
      ],
      "docs": "https://docs.aws.amazon.com/connecthealth/",
      "sources": [
        {
          "title": "Amazon Connect Health documentation",
          "url": "https://docs.aws.amazon.com/connecthealth/"
        },
        {
          "title": "Amazon Connect Health service details",
          "url": "https://docs.aws.amazon.com/connecthealth/latest/userguide/what-is-service.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "talent",
      "name": "Amazon Connect Talent",
      "shortName": "Connect Talent",
      "category": "business",
      "summary": "AI-supported recruiting tools for candidate evaluation and hiring workflows.",
      "details": "Amazon Connect Talent provides recruiter-facing tools to organize candidate information and support evaluation. It is a hiring workflow product, not a general authority for employment decisions.",
      "useCases": [
        "organize candidate reviews",
        "assist recruiter workflows",
        "coordinate hiring tasks"
      ],
      "concepts": [
        "Recruiter workflows organize candidate information",
        "AI-assisted evaluation supports a broader hiring process",
        "Candidate-data access requires organizational controls"
      ],
      "considerations": [
        "Human review and fair hiring practices remain essential",
        "Verify current features and data integrations."
      ],
      "docs": "https://docs.aws.amazon.com/talent/latest/userguide/what-is-talent.html",
      "sources": [
        {
          "title": "Amazon Connect Talent documentation",
          "url": "https://docs.aws.amazon.com/talent/latest/userguide/what-is-talent.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "consolemobileapp",
      "name": "AWS Console Mobile Application",
      "shortName": "Console Mobile",
      "category": "management",
      "summary": "A mobile application for checking AWS resources and responding to operational events from a phone.",
      "details": "The app provides a mobile view into selected AWS services, resource health, alarms, and support workflows. Its capabilities are narrower than the web console, so it is best treated as an on-call companion for inspection and bounded actions.",
      "useCases": [
        "check service health during an incident",
        "review CloudWatch alarms while away from a desk",
        "contact AWS Support from a mobile device"
      ],
      "concepts": [
        "mobile console access exposes selected service views and actions",
        "biometric sign-in can protect app access",
        "push notifications can surface supported alarms and events"
      ],
      "considerations": [
        "mobile screens do not expose every console feature",
        "protect the device and sign out or revoke sessions when it is lost"
      ],
      "docs": "https://docs.aws.amazon.com/consolemobileapp/latest/userguide/what-is-consolemobileapp.html",
      "sources": [
        {
          "title": "What is the AWS Console Mobile Application?",
          "url": "https://docs.aws.amazon.com/consolemobileapp/latest/userguide/what-is-consolemobileapp.html"
        },
        {
          "title": "AWS Console Mobile Application User Guide",
          "url": "https://docs.aws.amazon.com/consolemobileapp/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "control-tower",
      "name": "AWS Control Tower",
      "shortName": "Control Tower",
      "category": "management",
      "summary": "Sets up and governs a multi-account AWS landing zone.",
      "details": "Control Tower coordinates an Organizations-based landing zone with accounts, organizational units, controls, and account provisioning. It provides a managed starting point for governance; changes made outside its workflows can create drift that must be resolved.",
      "useCases": [
        "Establish governed accounts for teams",
        "Apply preventive and detective controls",
        "Provision accounts through Account Factory"
      ],
      "concepts": [
        "landing zone configures shared foundations",
        "controls map to underlying AWS mechanisms",
        "Account Factory provisions accounts",
        "drift detection compares expected state"
      ],
      "considerations": [
        "Understand control effects before enabling",
        "Keep landing-zone changes aligned with Control Tower workflows"
      ],
      "docs": "https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html",
      "sources": [
        {
          "title": "AWS Control Tower documentation",
          "url": "https://docs.aws.amazon.com/controltower/latest/userguide/what-is-control-tower.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "corretto",
      "name": "Amazon Corretto",
      "shortName": "Corretto",
      "category": "developer",
      "summary": "No-cost, multiplatform distribution of OpenJDK maintained by Amazon.",
      "details": "Amazon Corretto provides production-ready OpenJDK builds with long-term support for selected Java versions and operating systems. It can run locally, on premises, or on AWS; Corretto is a downloadable Java distribution, not a separately metered cloud service.",
      "useCases": [
        "Java application runtimes",
        "standardized developer JDKs",
        "long-term supported Java deployments"
      ],
      "concepts": [
        "Corretto is an OpenJDK distribution delivered as installable builds for supported operating systems.",
        "Amazon publishes security updates and long-term support for selected Corretto Java versions.",
        "The same Java distribution can run on local machines, on premises, EC2, or as a base for Java container images."
      ],
      "considerations": [
        "Select a supported Java version and update cadence",
        "Verify operating-system and architecture support for each release"
      ],
      "docs": "https://docs.aws.amazon.com/corretto/",
      "sources": [
        {
          "title": "Amazon Corretto documentation",
          "url": "https://docs.aws.amazon.com/corretto/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "cost-explorer",
      "name": "AWS Cost Explorer",
      "shortName": "Cost Explorer",
      "category": "cost",
      "summary": "Explores historical and forecasted AWS spending.",
      "details": "Cost Explorer provides interactive cost and usage reports with filters, grouping, and forecasts. Data is aggregated from billing records and can be organized by service, account, tag, or cost category when those dimensions are available.",
      "useCases": [
        "Investigate spend changes by service",
        "Forecast monthly costs",
        "Compare tagged application spending"
      ],
      "concepts": [
        "billing data is time-granular by available option",
        "cost categories group billing dimensions",
        "forecast is an estimate",
        "tags need activation for cost allocation"
      ],
      "considerations": [
        "Billing data can arrive with delay",
        "Forecasts do not guarantee future spend"
      ],
      "docs": "https://docs.aws.amazon.com/cost-management/latest/userguide/ce-what-is.html",
      "sources": [
        {
          "title": "AWS Cost Explorer documentation",
          "url": "https://docs.aws.amazon.com/cost-management/latest/userguide/ce-what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "data-exchange",
      "name": "AWS Data Exchange",
      "shortName": "Data Exchange",
      "category": "analytics",
      "summary": "Marketplace for discovering, subscribing to, and exchanging third-party data.",
      "details": "AWS Data Exchange lets subscribers find data products and access provider data sets through supported delivery methods, including files and data APIs. Providers publish products with terms and entitlements, while subscribers manage subscriptions, destinations, and downstream use.",
      "useCases": [
        "subscribing to market data",
        "sharing data products with customers",
        "automating data delivery"
      ],
      "concepts": [
        "Providers publish data products with terms that govern subscription and use.",
        "Subscribers receive datasets through supported delivery methods such as files or provider data APIs.",
        "Entitlements and subscription status control access to subscribed products and their revisions."
      ],
      "considerations": [
        "Subscription terms and permitted use are provider-specific",
        "Review delivery method, Region availability, and downstream data charges"
      ],
      "docs": "https://docs.aws.amazon.com/data-exchange/",
      "sources": [
        {
          "title": "AWS Data Exchange documentation",
          "url": "https://docs.aws.amazon.com/data-exchange/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "cost-and-usage-report",
      "name": "AWS Data Exports (Cost and Usage Reports)",
      "shortName": "Data Exports (Cost and Usage Reports)",
      "category": "cost",
      "summary": "Delivers detailed billing and usage data for analysis.",
      "details": "Cost and Usage Reports provide granular line-item billing data to an S3 destination; newer Data Exports interfaces configure export datasets. Consumers can query files with analytics services, but report schemas and refresh behavior should be handled explicitly.",
      "useCases": [
        "Analyze line-item costs with Athena",
        "Build custom chargeback reporting",
        "Audit usage by resource and tag"
      ],
      "concepts": [
        "exports deliver to S3",
        "CUR includes billing line items",
        "resource IDs and tags require configuration",
        "Athena can query exported data"
      ],
      "considerations": [
        "Choose format, granularity, and refresh cadence",
        "Protect billing exports as sensitive account data"
      ],
      "docs": "https://docs.aws.amazon.com/cur/latest/userguide/what-is-cur.html",
      "sources": [
        {
          "title": "AWS Data Exports (Cost and Usage Reports) documentation",
          "url": "https://docs.aws.amazon.com/cur/latest/userguide/what-is-cur.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "firehose",
      "name": "Amazon Data Firehose",
      "shortName": "Data Firehose",
      "category": "analytics",
      "summary": "Delivers streaming data to supported destinations with optional transformation and buffering.",
      "details": "Producers send records to delivery streams; Firehose batches and delivers them to configured destinations, with optional Lambda transformations and backup paths. It is designed for managed delivery rather than arbitrary stream processing.",
      "useCases": [
        "deliver application logs to S3",
        "buffer events into a warehouse",
        "archive streaming metrics"
      ],
      "concepts": [
        "delivery streams",
        "buffering",
        "transformations",
        "destinations"
      ],
      "considerations": [
        "Delivery buffering adds latency",
        "destination formats, retries, and transformation limits need review."
      ],
      "docs": "https://docs.aws.amazon.com/firehose/latest/dev/what-is-this-service.html",
      "sources": [
        {
          "title": "Amazon Data Firehose documentation",
          "url": "https://docs.aws.amazon.com/firehose/latest/dev/what-is-this-service.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "data-lifecycle-manager",
      "name": "Amazon Data Lifecycle Manager",
      "shortName": "Data Lifecycle Manager",
      "category": "management",
      "summary": "Automates EBS snapshot and EBS-backed AMI creation, retention, and cleanup through lifecycle policies.",
      "details": "Policies target eligible EBS volumes or instances using tags and create scheduled backups with configured retention. DLM can also manage cross-Region copies and AMI lifecycle actions, but it complements rather than replaces a workload-specific recovery plan.",
      "useCases": [
        "schedule snapshots for tagged EBS volumes",
        "retain a rolling set of application recovery points",
        "copy snapshots to another Region for resilience"
      ],
      "concepts": [
        "lifecycle policies select resources by tags",
        "schedules define creation cadence and retention",
        "cross-Region copy rules can protect snapshots",
        "EBS-backed AMI policies can manage image lifecycle"
      ],
      "considerations": [
        "tag changes can alter which resources a policy manages",
        "validate restore procedures and application consistency separately"
      ],
      "docs": "https://docs.aws.amazon.com/ebs/latest/userguide/snapshot-lifecycle.html",
      "sources": [
        {
          "title": "Automate backups with Amazon Data Lifecycle Manager",
          "url": "https://docs.aws.amazon.com/ebs/latest/userguide/snapshot-lifecycle.html"
        },
        {
          "title": "Amazon Data Lifecycle Manager concepts",
          "url": "https://docs.aws.amazon.com/ebs/latest/userguide/snapshot-lifecycle.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "data-pipeline",
      "name": "AWS Data Pipeline",
      "shortName": "Data Pipeline",
      "category": "analytics",
      "summary": "Legacy orchestration service for scheduled, data-driven processing workflows.",
      "details": "AWS Data Pipeline coordinates scheduled activities and dependencies across compute and data resources such as EC2, EMR, and S3. It no longer accepts new customers as of 2025-07-25; existing customers can continue to use it, and AWS documents migration paths to Glue, Step Functions, or MWAA.",
      "useCases": [
        "maintaining existing scheduled ETL jobs",
        "sequencing legacy data transfers",
        "planning workflow migration"
      ],
      "concepts": [
        "Pipelines model scheduled activities and the dependencies that determine execution order.",
        "Activities can coordinate resources such as EC2, EMR, and S3 as part of a data workflow.",
        "The service closed to new customers on July 25, 2025; AWS documents migration options including Glue, Step Functions, and MWAA."
      ],
      "considerations": [
        "Restricted to existing customers; not suitable for new adoption",
        "Map workflow semantics and retry behavior when migrating"
      ],
      "docs": "https://docs.aws.amazon.com/data-pipeline/",
      "sources": [
        {
          "title": "AWS Data Pipeline documentation",
          "url": "https://docs.aws.amazon.com/data-pipeline/"
        },
        {
          "title": "AWS Data Pipeline service details",
          "url": "https://docs.aws.amazon.com/datapipeline/latest/DeveloperGuide/migration.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS Data Pipeline has not accepted new customers since 2025-07-25; existing customers may continue.",
      "kind": "service"
    },
    {
      "id": "datatransferterminal",
      "name": "AWS Data Transfer Terminal",
      "shortName": "Data Transfer Terminal",
      "category": "migration",
      "summary": "Physical, network-ready facilities where customers can transfer data using their own storage equipment.",
      "details": "Customers schedule a reservation, bring compatible storage and networking equipment, and transfer data to or from AWS services over the facility connection. AWS documents this service as available only to Enterprise Support customers, with facility locations revealed through the reservation workflow.",
      "useCases": [
        "upload large field-collected datasets to S3",
        "move offline data when WAN transfer is impractical",
        "transfer data near a supported AWS facility"
      ],
      "concepts": [
        "reservations allocate time at a physical terminal",
        "customers bring and configure compatible equipment",
        "facility networking connects the transfer workflow to AWS services"
      ],
      "considerations": [
        "Enterprise Support is currently required",
        "facility locations, equipment compatibility, and reservation availability constrain planning"
      ],
      "docs": "https://docs.aws.amazon.com/datatransferterminal/latest/userguide/what-is-dtt.html",
      "sources": [
        {
          "title": "What is Data Transfer Terminal?",
          "url": "https://docs.aws.amazon.com/datatransferterminal/latest/userguide/what-is-dtt.html"
        },
        {
          "title": "Getting started with Data Transfer Terminal",
          "url": "https://docs.aws.amazon.com/datatransferterminal/latest/userguide/getting-started.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS documentation states Data Transfer Terminal is available only to Enterprise Support customers.",
      "kind": "service"
    },
    {
      "id": "datasync",
      "name": "AWS DataSync",
      "shortName": "DataSync",
      "category": "storage",
      "summary": "Automates high-speed online data movement between storage systems.",
      "details": "DataSync copies data between on-premises or other-cloud storage and AWS destinations such as S3, EFS, FSx, and supported object or file systems. Tasks can schedule and verify transfers, while an agent is needed for many non-AWS storage locations.",
      "useCases": [
        "File-system migration",
        "Recurring data replication",
        "Data ingestion into S3 or EFS"
      ],
      "concepts": [
        "Locations and tasks",
        "Agents for self-managed storage",
        "Scheduling and verification",
        "Online transfer"
      ],
      "considerations": [
        "Throughput depends on source, destination, network, and task configuration.",
        "DataSync is online movement; physical transfer may fit extreme bandwidth constraints."
      ],
      "docs": "https://docs.aws.amazon.com/datasync/latest/userguide/what-is-datasync.html",
      "sources": [
        {
          "title": "AWS DataSync documentation",
          "url": "https://docs.aws.amazon.com/datasync/latest/userguide/what-is-datasync.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "datazone",
      "name": "Amazon DataZone",
      "shortName": "DataZone",
      "category": "analytics",
      "summary": "Business data catalog and governance service for publishing, discovering, and sharing data.",
      "details": "Producers publish governed assets into project-based catalogs and consumers request access through defined workflows. Integrations with sources and analytics services are configured by administrators.",
      "useCases": [
        "discover approved sales datasets",
        "publish analytics products",
        "manage cross-team data access requests"
      ],
      "concepts": [
        "domains",
        "projects",
        "data products",
        "subscriptions"
      ],
      "considerations": [
        "Catalog entries do not automatically fix source data quality",
        "access workflows and source integrations require setup."
      ],
      "docs": "https://docs.aws.amazon.com/datazone/latest/userguide/what-is-datazone.html",
      "sources": [
        {
          "title": "Amazon DataZone documentation",
          "url": "https://docs.aws.amazon.com/datazone/latest/userguide/what-is-datazone.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "dcv",
      "name": "Amazon DCV",
      "shortName": "DCV",
      "category": "enduser",
      "summary": "Remote display protocol and clients for graphics-intensive desktops and applications.",
      "details": "DCV streams remote desktop visuals while sending user input to a server. It runs on customer-managed infrastructure or supported AWS services; licensing and features depend on host and client platform.",
      "useCases": [
        "remote 3D workstation",
        "engineering visualization",
        "interactive graphics in the cloud"
      ],
      "concepts": [
        "A DCV server runs with the desktop or application",
        "Clients connect securely to interact with the remote session",
        "Session and peripheral features depend on platform support"
      ],
      "considerations": [
        "Network latency and GPU capacity shape performance",
        "Check licensing and host support."
      ],
      "docs": "https://docs.aws.amazon.com/dcv/",
      "sources": [
        {
          "title": "Amazon DCV documentation",
          "url": "https://docs.aws.amazon.com/dcv/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "deadline-cloud",
      "name": "AWS Deadline Cloud",
      "shortName": "Deadline Cloud",
      "category": "media",
      "summary": "Managed render-farm service for visual effects and animation jobs.",
      "details": "Deadline Cloud coordinates jobs, farms, queues, fleets, and attachments. Workers can use managed or customer-managed infrastructure; studios define software environments and asset access.",
      "useCases": [
        "render animation frames",
        "scale visual-effects projects",
        "coordinate artist render queues"
      ],
      "concepts": [
        "Farms contain queues and worker fleets",
        "Jobs describe tasks and dependencies",
        "Attachments move inputs and outputs"
      ],
      "considerations": [
        "Software licensing and storage transfer can dominate cost",
        "Worker environments and asset permissions need consistency."
      ],
      "docs": "https://docs.aws.amazon.com/deadline-cloud/",
      "sources": [
        {
          "title": "AWS Deadline Cloud documentation",
          "url": "https://docs.aws.amazon.com/deadline-cloud/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "dlami",
      "name": "AWS Deep Learning AMIs",
      "shortName": "Deep Learning AMIs",
      "category": "ai",
      "summary": "EC2 images preconfigured with deep-learning frameworks and development tools.",
      "details": "AWS Deep Learning AMIs provide GPU and CPU machine images with selected machine-learning frameworks, drivers, and libraries. They run on customer-managed EC2 instances; users choose instance types, update software, and manage data, access, and runtime costs.",
      "useCases": [
        "interactive model development",
        "framework compatibility testing",
        "GPU-based training experiments"
      ],
      "concepts": [
        "Deep Learning AMIs combine selected ML frameworks, drivers, and libraries in EC2 machine images.",
        "Users choose the EC2 instance and accelerator type that fit the framework and workload.",
        "Because the instances are customer-managed, users handle framework updates, instance security, and compute charges."
      ],
      "considerations": [
        "AMI contents and framework versions vary by release",
        "GPU instances and attached storage can be costly; patch and secure hosts"
      ],
      "docs": "https://docs.aws.amazon.com/dlami/",
      "sources": [
        {
          "title": "AWS Deep Learning AMIs documentation",
          "url": "https://docs.aws.amazon.com/dlami/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "deep-learning-containers",
      "name": "AWS Deep Learning Containers",
      "shortName": "Deep Learning Containers",
      "category": "ai",
      "summary": "AWS-maintained Docker images for machine-learning frameworks.",
      "details": "AWS Deep Learning Containers provide optimized container images for selected frameworks and accelerator environments, used on services such as ECS, EKS, and SageMaker. Containers supply software layers; customers select compute, manage orchestration, and verify image versions and security updates.",
      "useCases": [
        "reproducible training environments",
        "GPU inference containers",
        "framework workloads on Kubernetes"
      ],
      "concepts": [
        "Container images package selected ML frameworks with optimized libraries for supported compute hardware.",
        "Images can be run through services such as ECS, EKS, or SageMaker, each with its own deployment model.",
        "The image supplies the software environment; customers select compute and track image version and security updates."
      ],
      "considerations": [
        "Image and framework support varies by release and target service",
        "Pin versions and scan images as part of deployment controls"
      ],
      "docs": "https://docs.aws.amazon.com/deep-learning-containers/",
      "sources": [
        {
          "title": "AWS Deep Learning Containers documentation",
          "url": "https://docs.aws.amazon.com/deep-learning-containers/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "detective",
      "name": "Amazon Detective",
      "shortName": "Detective",
      "category": "security",
      "summary": "Investigates security findings by linking related activity and entities.",
      "details": "Detective builds a behavior graph from supported AWS telemetry and surfaces linked entities, timelines, and investigations. It complements detection services by helping analysts explore context rather than replacing prevention or response systems.",
      "useCases": [
        "Investigate a GuardDuty finding",
        "Trace an IAM principal’s activity",
        "Examine a compromised instance timeline"
      ],
      "concepts": [
        "behavior graph is regional",
        "GuardDuty findings can link into investigations",
        "organization accounts can share delegated administration",
        "security profiles summarize behavior"
      ],
      "considerations": [
        "Data source availability affects context",
        "Use findings and analyst judgment to guide conclusions"
      ],
      "docs": "https://docs.aws.amazon.com/detective/latest/userguide/what-is-detective.html",
      "sources": [
        {
          "title": "Amazon Detective documentation",
          "url": "https://docs.aws.amazon.com/detective/latest/userguide/what-is-detective.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "devicefarm",
      "name": "AWS Device Farm",
      "shortName": "Device Farm",
      "category": "developer",
      "summary": "Cloud service for testing mobile and web applications on real devices.",
      "details": "AWS Device Farm provides access to a fleet of physical devices and browser environments for automated or interactive tests. Customers upload app packages or provide web targets, select devices and test suites, and review logs, screenshots, and performance data.",
      "useCases": [
        "mobile compatibility testing",
        "browser testing",
        "automated release validation"
      ],
      "concepts": [
        "A test run selects device models and test suites, then records logs, screenshots, and performance information.",
        "Private device fleets dedicate physical devices to an AWS account and support remote sessions as well as automated runs.",
        "With VPC-ENI enabled for eligible private devices, tests can reach isolated endpoints without making those apps public."
      ],
      "considerations": [
        "Device availability and test duration affect execution planning and cost",
        "Protect test credentials and sensitive test data"
      ],
      "docs": "https://docs.aws.amazon.com/devicefarm/",
      "sources": [
        {
          "title": "AWS Device Farm documentation",
          "url": "https://docs.aws.amazon.com/devicefarm/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "devopsagent",
      "name": "AWS DevOps Agent",
      "shortName": "DevOps Agent",
      "category": "management",
      "summary": "An operations agent that investigates incidents and supports reliability work across connected AWS, third-party, and on-premises systems.",
      "details": "An Agent Space defines the AWS accounts, observability sources, repositories, and collaboration tools an investigation can use. The agent correlates telemetry, changes, and runbooks to produce findings and suggested actions; access boundaries, connected-source quality, and human review remain central.",
      "useCases": [
        "correlate alarms, logs, and recent deployments during an incident",
        "investigate recurring reliability problems across services",
        "connect operational findings to runbooks and source changes"
      ],
      "concepts": [
        "Agent Spaces scope account access and integrations",
        "investigations correlate metrics, logs, traces, deployments, and knowledge",
        "IAM roles grant access to connected accounts",
        "journal entries preserve investigation activity"
      ],
      "considerations": [
        "grant only the read access needed for investigation",
        "connected data can contain sensitive content or malicious instructions and should be governed"
      ],
      "docs": "https://docs.aws.amazon.com/devopsagent/latest/userguide/about-aws-devops-agent-what-is-a-devops-agent-topology.html",
      "sources": [
        {
          "title": "What is AWS DevOps Agent?",
          "url": "https://docs.aws.amazon.com/devopsagent/latest/userguide/about-aws-devops-agent-what-is-a-devops-agent-topology.html"
        },
        {
          "title": "AWS DevOps Agent security",
          "url": "https://docs.aws.amazon.com/devopsagent/latest/userguide/aws-devops-agent-security.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "devops-guru",
      "name": "Amazon DevOps Guru",
      "shortName": "DevOps Guru",
      "category": "ai",
      "summary": "ML-powered operational insights from application metrics and events.",
      "details": "Amazon DevOps Guru analyzes selected CloudWatch metrics and CloudTrail events to identify anomalous behavior and create operational insights. AWS has announced end of support on 2027-09-30 and closes access to new customers on 2026-10-29; existing eligible customers may continue until the end date.",
      "useCases": [
        "anomaly-based application alerts",
        "correlating operational signals",
        "reviewing incident recommendations"
      ],
      "concepts": [
        "Operational insights correlate selected CloudWatch metrics and CloudTrail events to surface anomalous behavior.",
        "Insights group related anomalies and provide recommendations for investigation.",
        "AWS announced end of support for September 30, 2027 and closure to new customers on October 29, 2026."
      ],
      "considerations": [
        "No new features; migrate alerting to CloudWatch and investigation workflows as advised by AWS",
        "Export insights and remove DevOps Guru resource declarations before 2027-09-30"
      ],
      "docs": "https://docs.aws.amazon.com/devops-guru/",
      "sources": [
        {
          "title": "Amazon DevOps Guru documentation",
          "url": "https://docs.aws.amazon.com/devops-guru/"
        },
        {
          "title": "Amazon DevOps Guru service details",
          "url": "https://docs.aws.amazon.com/devops-guru/latest/userguide/devops-guru-end-of-support.html"
        }
      ],
      "status": "active",
      "statusNote": "AWS will stop accepting new customers beginning October 29, 2026, and end support September 30, 2027.",
      "kind": "service"
    },
    {
      "id": "direct-connect",
      "name": "AWS Direct Connect",
      "shortName": "Direct Connect",
      "category": "network",
      "summary": "Dedicated network connection between customer facilities and AWS.",
      "details": "Direct Connect uses dedicated or hosted connections and virtual interfaces to reach public AWS services or private VPC resources. It can be combined with a transit gateway or Direct Connect gateway for broader network connectivity.",
      "useCases": [
        "Predictable hybrid connectivity",
        "High-volume data transfer",
        "Private access to VPC workloads"
      ],
      "concepts": [
        "Dedicated and hosted connections",
        "Private, public, and transit VIFs",
        "Direct Connect gateway",
        "Redundancy and BGP"
      ],
      "considerations": [
        "A Direct Connect link is not encrypted by default; add encryption where required.",
        "Resiliency depends on diverse connections and locations."
      ],
      "docs": "https://docs.aws.amazon.com/directconnect/latest/UserGuide/Welcome.html",
      "sources": [
        {
          "title": "AWS Direct Connect documentation",
          "url": "https://docs.aws.amazon.com/directconnect/latest/UserGuide/Welcome.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "directory-service",
      "name": "AWS Directory Service",
      "shortName": "Directory Service",
      "category": "security",
      "summary": "Runs or connects directory services for AWS workloads.",
      "details": "Directory Service offers managed Microsoft AD, AD Connector, and Simple AD options for different integration needs. Directory choice affects trust, identity source, domain join, and which AWS services can use directory authentication.",
      "useCases": [
        "Join EC2 instances to a managed domain",
        "Connect AWS apps to existing AD",
        "Provide directory-aware sign-in for supported services"
      ],
      "concepts": [
        "Managed Microsoft AD is AWS-operated AD",
        "AD Connector proxies to on-premises AD",
        "trusts link directory domains",
        "directories are deployed in selected VPC subnets"
      ],
      "considerations": [
        "Plan DNS, network routes, and directory availability",
        "Directory features differ by edition and option"
      ],
      "docs": "https://docs.aws.amazon.com/directoryservice/latest/admin-guide/what_is.html",
      "sources": [
        {
          "title": "AWS Directory Service documentation",
          "url": "https://docs.aws.amazon.com/directoryservice/latest/admin-guide/what_is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "dms",
      "name": "AWS Database Migration Service",
      "shortName": "DMS",
      "category": "database",
      "summary": "Moves database data between supported sources and targets with ongoing replication options.",
      "details": "DMS tasks can perform full loads, change data capture, or both, while schema conversion is handled by a separate tool where needed. Source and target engine support determine migration constraints.",
      "useCases": [
        "migrate Oracle data to Aurora",
        "replicate operational changes to an S3 lake",
        "move databases between Regions"
      ],
      "concepts": [
        "replication instances",
        "tasks",
        "CDC",
        "schema conversion"
      ],
      "considerations": [
        "Validate data types, transaction behavior, and cutover consistency",
        "DMS does not automatically resolve every schema incompatibility."
      ],
      "docs": "https://docs.aws.amazon.com/dms/latest/userguide/Welcome.html",
      "sources": [
        {
          "title": "AWS Database Migration Service documentation",
          "url": "https://docs.aws.amazon.com/dms/latest/userguide/Welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "documentdb",
      "name": "Amazon DocumentDB",
      "shortName": "DocumentDB",
      "category": "database",
      "summary": "Managed document database service with MongoDB compatibility for JSON-style application data.",
      "details": "Applications use MongoDB-compatible drivers against clusters, but supported API versions and behavior can differ from community MongoDB. AWS manages cluster infrastructure and backup features.",
      "useCases": [
        "content metadata store",
        "product catalog documents",
        "application records with evolving fields"
      ],
      "concepts": [
        "documents",
        "clusters",
        "instances",
        "MongoDB-compatible APIs"
      ],
      "considerations": [
        "Test driver and command compatibility",
        "engine version and scaling choices affect behavior and cost."
      ],
      "docs": "https://docs.aws.amazon.com/documentdb/latest/developerguide/what-is.html",
      "sources": [
        {
          "title": "Amazon DocumentDB documentation",
          "url": "https://docs.aws.amazon.com/documentdb/latest/developerguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "dynamodb",
      "name": "Amazon DynamoDB",
      "shortName": "DynamoDB",
      "category": "database",
      "summary": "Serverless key-value and document database with single-digit millisecond performance at scale.",
      "details": "Applications model access patterns around partition and sort keys; optional streams, transactions, and global tables add specialized behaviors. Capacity mode and indexes shape throughput and cost.",
      "useCases": [
        "shopping-cart state",
        "user profile lookups",
        "event-driven application state"
      ],
      "concepts": [
        "Tables store items organized by a primary key.",
        "Partition keys determine how DynamoDB distributes table data.",
        "Secondary indexes support queries using attributes other than the table key.",
        "Streams capture ordered changes to table items for downstream processing."
      ],
      "considerations": [
        "Design keys around known access patterns",
        "scans and hot partitions can be costly or constrain performance."
      ],
      "docs": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/Introduction.html",
      "sources": [
        {
          "title": "Amazon DynamoDB documentation",
          "url": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/Introduction.html"
        },
        {
          "title": "DynamoDB constraints",
          "url": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/Constraints.html"
        },
        {
          "title": "DynamoDB Streams and TTL",
          "url": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/time-to-live-ttl-streams.html"
        },
        {
          "title": "How global tables work",
          "url": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/V2globaltables_HowItWorks.html"
        },
        {
          "title": "DynamoDB transactions",
          "url": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/transaction-apis.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service",
      "topics": [
        {
          "title": "Tables, items and keys",
          "bullets": [
            "A table holds items; an item is a set of named attributes",
            "Only key attributes are declared up front; other attributes are schemaless",
            "Simple key: partition key alone. Composite: partition key plus sort key",
            "Key attributes must be string, number or binary, never map or list",
            "Partition key is hashed to pick a partition; sort key orders items sharing it"
          ]
        },
        {
          "title": "Partition key design",
          "bullets": [
            "Pick a high-cardinality partition key so traffic spreads over partitions",
            "Low-cardinality keys, like a status flag, concentrate load on few partitions",
            "Hot partitions can throttle even when total table capacity looks sufficient",
            "Write sharding appends a suffix to split one hot key into N keys",
            "Reads for a sharded key must query every suffix and merge the results"
          ]
        },
        {
          "title": "Secondary indexes",
          "bullets": [
            "GSI: own partition key and optional sort key; can be added or dropped later",
            "GSI reads are eventually consistent only; projection picks copied attributes",
            "Sparse GSI: items lacking the index key attributes are not indexed",
            "LSI: same partition key, different sort key; must be set at table creation",
            "LSI supports strongly consistent reads and uses the table's capacity"
          ]
        },
        {
          "title": "Query vs scan",
          "bullets": [
            "Query reads items for one partition key value, optionally by sort key",
            "Scan reads every item in a table or index; avoid it on request paths",
            "Filter expressions run after the read, so filtered-out items still cost",
            "Each Query or Scan call reads at most 1 MB, so large results span several calls",
            "Parallel scan splits a scan into segments; the total read is unchanged"
          ]
        },
        {
          "title": "Read consistency and DAX",
          "bullets": [
            "Reads are eventually consistent by default and cost half as much",
            "ConsistentRead=true requests a strong read from a table or an LSI",
            "Strong reads cost double, so use them only where a stale value would cause harm",
            "DAX caches eventually consistent reads; it suits hot, frequently read items",
            "DAX passes strong reads through; apps need the DAX client library"
          ]
        },
        {
          "title": "Transactions and batches",
          "bullets": [
            "TransactWriteItems applies up to 100 actions atomically, all or nothing",
            "Transactions span tables in one account and Region; they cannot target indexes",
            "Conflicts cancel the whole call; retry it with a ClientRequestToken",
            "Transactional calls cost double the normal read or write units",
            "Batch calls are not atomic; resend UnprocessedItems and UnprocessedKeys"
          ]
        },
        {
          "title": "TTL for expiring items",
          "bullets": [
            "TTL reads a number attribute holding a Unix epoch time in seconds",
            "Expired items are deleted in the background, usually well after their expiry time",
            "Expired items still appear in reads and scans until actually deleted",
            "TTL deletes use no write capacity in the source Region; replicas do bill",
            "TTL deletes have a service identity in the source Region stream; replicated deletes do not"
          ]
        },
        {
          "title": "DynamoDB Streams",
          "bullets": [
            "Streams log item-level changes; changes to one item stay in order",
            "View types: keys only, new image, old image, or both images",
            "Stream records are kept for 24 hours, then they expire",
            "Each record appears once, but a retried batch means handlers must be idempotent",
            "Design for at most two readers per shard; AWS recommends one for global tables"
          ]
        },
        {
          "title": "Global tables",
          "bullets": [
            "Global tables replicate one table across AWS Regions, one replica per Region",
            "Default MREC mode replicates asynchronously, usually with only a short delay",
            "MREC conflicts resolve per item by last writer wins; any replica accepts writes",
            "MREC strong reads are current only for items last written in that Region",
            "MRSC replicates synchronously across supported Regions; TTL and transactions are unsupported"
          ]
        },
        {
          "title": "Backups and recovery",
          "bullets": [
            "On-demand backups are full copies, kept until you delete them",
            "PITR keeps continuous backups for up to 35 days, configurable from 1",
            "PITR restores to any second in that window, into a new table",
            "PITR covers only times after it was enabled; turn it on early",
            "Export to S3 reads a snapshot without using table read capacity"
          ]
        },
        {
          "title": "Capacity modes and pricing",
          "bullets": [
            "On-demand: pay per read and write request, no capacity planning",
            "Provisioned: set read and write units per second, optionally auto scaled",
            "1 read unit = one strongly consistent read up to 4 KB; 1 write unit = 1 KB",
            "Storage is billed per GB-month; Standard-IA suits tables where storage dominates",
            "Backups, PITR, DAX nodes and replicated writes have separate charges"
          ]
        },
        {
          "title": "Modelling and pitfalls",
          "bullets": [
            "Model from access patterns first; keys follow the queries you need",
            "Overloaded PK and SK values let one Query fetch related item types",
            "Item size limit is 400 KB; put large blobs in S3 and keep a pointer",
            "Pitfall: stop paging only when LastEvaluatedKey is absent; pages can be empty",
            "Pitfall: retrying throttled calls without backoff amplifies the throttling"
          ]
        }
      ],
      "guide": "services/dynamodb.html"
    },
    {
      "id": "ebs",
      "name": "Amazon EBS",
      "shortName": "EBS",
      "category": "storage",
      "summary": "Durable block storage volumes for EC2 instances.",
      "details": "EBS volumes attach to EC2 instances in the same Availability Zone and provide block devices for operating systems, databases, and applications. Snapshots are incremental point-in-time backups stored in AWS-managed infrastructure.",
      "useCases": [
        "Boot and data volumes for EC2",
        "Transactional database storage",
        "Snapshot-based recovery"
      ],
      "concepts": [
        "Volume types and performance",
        "Availability Zone attachment",
        "Snapshots and encryption",
        "Multi-Attach for supported types"
      ],
      "considerations": [
        "EBS volumes are zonal resources; cross-AZ use requires snapshot/replication workflows.",
        "Volume performance and cost depend on provisioned type and configuration."
      ],
      "docs": "https://docs.aws.amazon.com/ebs/latest/userguide/what-is-ebs.html",
      "sources": [
        {
          "title": "Amazon EBS documentation",
          "url": "https://docs.aws.amazon.com/ebs/latest/userguide/what-is-ebs.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "ec2",
      "name": "Amazon EC2",
      "shortName": "EC2",
      "category": "compute",
      "summary": "Resizable virtual servers with a choice of instance families and purchase models.",
      "details": "EC2 launches virtual machines from AMIs into VPC subnets. Instance type, attached EBS volumes, security groups, IAM roles, and scaling policies shape the operating environment.",
      "useCases": [
        "Web and application servers",
        "Custom operating systems or software",
        "Burst and high-performance compute"
      ],
      "concepts": [
        "Instances and AMIs",
        "Instance families and purchase options",
        "Security groups and key pairs",
        "EBS and instance store"
      ],
      "considerations": [
        "Customers manage guest operating systems and installed software.",
        "Instance and feature availability varies by Region and instance family."
      ],
      "docs": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/",
      "sources": [
        {
          "title": "What is Amazon EC2?",
          "url": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/"
        },
        {
          "title": "EC2 On-Demand pricing",
          "url": "https://aws.amazon.com/ec2/pricing/on-demand/"
        },
        {
          "title": "EC2 Capacity Reservations",
          "url": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-capacity-reservations.html"
        },
        {
          "title": "Deregister an EC2 AMI",
          "url": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/deregister-ami.html"
        },
        {
          "title": "VPC security groups",
          "url": "https://docs.aws.amazon.com/vpc/latest/userguide/vpc-security-groups.html"
        }
      ],
      "status": "active",
      "kind": "service",
      "topics": [
        {
          "title": "Instance types and sizing",
          "bullets": [
            "Letter sets the purpose: M general, C compute, R memory, I storage, P and G GPU",
            "Suffixes add traits: g is Graviton (Arm), a is AMD, d adds local NVMe instance store",
            "Each size step roughly doubles vCPU and memory; metal sizes give the whole host",
            "T types are burstable: they earn CPU credits below baseline and spend them above it",
            "Standard mode throttles once credits run out; watch CPUCreditBalance"
          ]
        },
        {
          "title": "AMIs and launch templates",
          "bullets": [
            "An AMI holds volume snapshots, launch permissions and the block device mapping",
            "AMIs are regional; copy one to each region you launch in",
            "Deregistering an AMI keeps snapshots by default; optionally delete them in the same request",
            "Launch templates version AMI, type, security groups, storage and user data together",
            "On Linux, cloud-init runs user data once at first boot; never put secrets in it"
          ]
        },
        {
          "title": "EBS volume types",
          "bullets": [
            "gp3 is the usual SSD, with IOPS and throughput set apart from size; prefer it to gp2",
            "io2 and io2 Block Express give provisioned IOPS for latency-sensitive databases",
            "st1 and sc1 are HDD types for large sequential reads; neither can be a boot volume",
            "A volume lives in one AZ; move data across AZs or regions with snapshots",
            "Type, size and IOPS can change online; the filesystem must be extended separately"
          ]
        },
        {
          "title": "Instance store",
          "bullets": [
            "Instance store is disk physically on the host; it is not network attached",
            "Data survives a reboot but is lost on stop, terminate, or underlying hardware failure",
            "Resizing requires a stop, which erases instance store contents; copy data off first",
            "Use it for caches, scratch space and data replicated elsewhere, never as the only copy",
            "Only some instance types include it; check the storage details before you choose"
          ]
        },
        {
          "title": "Pricing and purchasing",
          "bullets": [
            "On-Demand has no term; most OS options bill per second with a 60-second minimum; SLES hourly",
            "A stopped instance skips compute charges; its EBS volumes and any Elastic IP still bill",
            "Savings Plans and Reserved Instances trade a one or three year term for a lower rate",
            "Spot uses spare capacity at a discount and can be reclaimed on a two-minute notice",
            "Capacity Reservations hold one-AZ capacity and bill unused slots; future-dated ones require a term"
          ]
        },
        {
          "title": "Placement groups",
          "bullets": [
            "Cluster groups pack instances together in one AZ for low latency and high throughput",
            "Spread groups use separate hardware; seven running instances per AZ maximum",
            "Partition groups put instances in separate rack partitions, for large systems like Kafka",
            "Launch cluster members in one request to reduce insufficient-capacity errors",
            "An instance joins a placement group at launch; moving it later requires it stopped"
          ]
        },
        {
          "title": "Networking and public IPs",
          "bullets": [
            "Each instance keeps a primary ENI; how many extra ENIs it takes depends on type",
            "Security groups are stateful; new custom groups start with no inbound rules and allow outbound",
            "A security group can name another security group as a source instead of an IP range",
            "Elastic IPs keep their address across stop and start; auto-assigned public IPs do not",
            "Public IPv4 addresses bill per hour, attached or not, so release unused Elastic IPs"
          ]
        },
        {
          "title": "Instance metadata (IMDSv2)",
          "bullets": [
            "Metadata lives at 169.254.169.254 and serves instance identity and role credentials",
            "IMDSv2 needs a session token: PUT to /latest/api/token, then send it on each GET",
            "Set HttpTokens to required to refuse IMDSv1 requests on an instance",
            "Containers need an extra hop; raise the metadata hop limit if they cannot reach it",
            "Use SDK credential chains rather than reading raw metadata URLs in application code"
          ]
        },
        {
          "title": "Access: keys, roles, SSM",
          "bullets": [
            "AWS keeps only the public half of a key pair; a lost private key cannot be recovered",
            "An instance profile attaches an IAM role; SDKs get rotating temporary credentials",
            "Do not store long-lived access keys on instances; the attached role replaces them",
            "Session Manager opens a shell through the SSM agent, so port 22 need not be open",
            "Session Manager needs role permissions; session logs can go to S3 or CloudWatch"
          ]
        },
        {
          "title": "Scaling and load balancing",
          "bullets": [
            "Auto Scaling groups hold capacity between min and max and replace failed instances",
            "Target tracking policies hold a metric, such as average CPU, near a chosen target",
            "Spread a group across AZs; a mixed-instances policy can blend Spot and On-Demand",
            "ALB routes HTTP and HTTPS at layer 7; NLB routes TCP, UDP and TLS at layer 4",
            "Enable ELB health checks on the group so failed LB checks also replace instances"
          ]
        },
        {
          "title": "CloudWatch monitoring",
          "bullets": [
            "Basic metrics come every 5 minutes; detailed monitoring is 1 minute and costs extra",
            "Memory, disk and process metrics are not built in; install the CloudWatch agent",
            "StatusCheckFailed metrics split host faults from instance faults; alarm on both",
            "A system check alarm can trigger the EC2 recover action on supported instance types"
          ]
        },
        {
          "title": "Common pitfalls",
          "bullets": [
            "Unattached EBS volumes and old snapshots keep billing after the instance is gone",
            "Security groups open to 0.0.0.0/0 on ports 22 or 3389 invite brute-force logins",
            "Cross-AZ and internet transfer bill per GB; check transfer lines in cost reports",
            "Root volumes are deleted on termination by default; data volumes are not",
            "Termination protection is off by default; while on, it blocks terminate calls"
          ]
        }
      ],
      "guide": "services/ec2.html"
    },
    {
      "id": "ec2-auto-scaling",
      "name": "Amazon EC2 Auto Scaling",
      "shortName": "EC2 Auto Scaling",
      "category": "management",
      "summary": "Maintains EC2 capacity by adding or removing instances in response to demand and health signals.",
      "details": "An Auto Scaling group defines desired, minimum, and maximum capacity across selected subnets and Availability Zones. Launch templates, scaling policies, health checks, and lifecycle hooks shape how instances enter, leave, and recover within the group.",
      "useCases": [
        "scale a web tier with request demand",
        "replace instances that fail health checks",
        "maintain capacity across multiple Availability Zones"
      ],
      "concepts": [
        "Auto Scaling groups own a fleet and capacity bounds",
        "launch templates specify instance configuration",
        "target tracking adjusts capacity to a metric target",
        "lifecycle hooks pause launch or termination workflows"
      ],
      "considerations": [
        "scaling signals need suitable metrics and cooldown behavior",
        "EC2 quotas, subnet IP space, and launch capacity can constrain scale-out"
      ],
      "docs": "https://docs.aws.amazon.com/autoscaling/ec2/userguide/what-is-amazon-ec2-auto-scaling.html",
      "sources": [
        {
          "title": "What is Amazon EC2 Auto Scaling?",
          "url": "https://docs.aws.amazon.com/autoscaling/ec2/userguide/what-is-amazon-ec2-auto-scaling.html"
        },
        {
          "title": "Target tracking scaling policies",
          "url": "https://docs.aws.amazon.com/autoscaling/ec2/userguide/as-scaling-target-tracking.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "imagebuilder",
      "name": "EC2 Image Builder",
      "shortName": "EC2 Image Builder",
      "category": "compute",
      "summary": "Automates creation, testing, and distribution of machine images.",
      "details": "EC2 Image Builder defines image pipelines that apply components to a source image, run tests, and distribute outputs such as AMIs or container images. It can publish images across Regions or accounts when configured, but the resulting images and instances remain customer-managed.",
      "useCases": [
        "standardized EC2 AMI pipelines",
        "container image builds",
        "cross-account image distribution"
      ],
      "concepts": [
        "A pipeline applies ordered components to a source image and can run tests before distribution.",
        "Image Builder can produce AMIs and container images through different recipes and workflows.",
        "Cross-account or cross-Region distribution must be configured; consumers receive images that they operate themselves."
      ],
      "considerations": [
        "Build infrastructure and output storage can incur charges",
        "Validate patches and tests before promoting images"
      ],
      "docs": "https://docs.aws.amazon.com/imagebuilder/",
      "sources": [
        {
          "title": "EC2 Image Builder documentation",
          "url": "https://docs.aws.amazon.com/imagebuilder/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "ecr",
      "name": "Amazon ECR",
      "shortName": "ECR",
      "category": "containers",
      "summary": "Managed registry for private and public container images and OCI artifacts.",
      "details": "ECR stores and distributes container images for ECS, EKS, and other container runtimes. IAM-based repository policies control access, while lifecycle policies and image scanning support image operations.",
      "useCases": [
        "Image storage for ECS and EKS",
        "Build pipeline artifact publishing",
        "Image replication across Regions"
      ],
      "concepts": [
        "Repositories and image tags",
        "OCI and Docker image formats",
        "IAM repository policies",
        "Lifecycle policies"
      ],
      "considerations": [
        "Image storage and transfer incur charges.",
        "Image access from isolated networks can require VPC endpoints."
      ],
      "docs": "https://docs.aws.amazon.com/AmazonECR/latest/userguide/what-is-ecr.html",
      "sources": [
        {
          "title": "Amazon ECR documentation",
          "url": "https://docs.aws.amazon.com/AmazonECR/latest/userguide/what-is-ecr.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "ecs",
      "name": "Amazon ECS",
      "shortName": "ECS",
      "category": "containers",
      "summary": "Managed orchestration for containerized applications on AWS.",
      "details": "ECS schedules tasks from task definitions and can run them on EC2 capacity, Fargate, or ECS Managed Instances. Services maintain desired task counts and integrate with load balancers, Cloud Map, and VPC Lattice.",
      "useCases": [
        "Web services and APIs",
        "Background workers",
        "Containerized scheduled tasks"
      ],
      "concepts": [
        "Clusters, services, tasks",
        "Task and execution roles",
        "Capacity providers",
        "awsvpc networking"
      ],
      "considerations": [
        "EC2 capacity requires instance lifecycle management; Fargate has supported task shapes and platform limits.",
        "The ECS control plane does not remove application-level availability or security design."
      ],
      "docs": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/Welcome.html",
      "sources": [
        {
          "title": "Amazon ECS documentation",
          "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/Welcome.html"
        },
        {
          "title": "ECS task definitions, tasks and services",
          "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task_definitions.html"
        },
        {
          "title": "ECS launch types and capacity providers",
          "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/capacity-launch-type-comparison.html"
        },
        {
          "title": "ECS IAM role guidance",
          "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/security-iam-roles.html"
        },
        {
          "title": "ECS deployment controllers and strategies",
          "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs_service-options.html"
        },
        {
          "title": "ECS storage with Amazon EBS",
          "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ebs-volumes.html"
        },
        {
          "title": "Amazon ECS pricing",
          "url": "https://aws.amazon.com/ecs/pricing/"
        }
      ],
      "status": "active",
      "kind": "service",
      "topics": [
        {
          "title": "Clusters, tasks and services",
          "bullets": [
            "ECS is a managed container orchestrator; the selected compute option runs your containers",
            "A cluster is a regional grouping of tasks, services and their compute capacity",
            "A task definition describes an application; a task is one running copy of that definition",
            "A service maintains a desired task count and replaces tasks that fail or stop",
            "Standalone tasks suit jobs that finish; EventBridge Scheduler can launch them on a schedule"
          ]
        },
        {
          "title": "Task definitions and images",
          "bullets": [
            "Task definitions version images, CPU, memory, networking, roles, logs and volume settings together",
            "A task can contain an app and sidecars that share its lifecycle; scale independent apps separately",
            "Use a unique build tag or image digest so each release can be identified and reproduced",
            "Register a new task definition revision, then update the service to deploy that revision",
            "Put container health checks in the task definition; image-only Docker checks are not monitored"
          ]
        },
        {
          "title": "Choosing compute capacity",
          "bullets": [
            "Fargate runs each task in an isolated environment while AWS manages its underlying servers",
            "Self-managed EC2 gives host and instance control; you maintain the OS, agent and instance capacity",
            "ECS Managed Instances handles EC2 provisioning, scaling and patching and supports specialized hardware",
            "ECS Anywhere registers external servers to the ECS control plane for supported container workloads",
            "Validate task compatibility and feature support before moving between compute options"
          ]
        },
        {
          "title": "Capacity providers",
          "bullets": [
            "A capacity provider strategy chooses compute; a cluster default can be overridden per service or task",
            "Base places an initial task count on one provider; weights distribute tasks after that base",
            "FARGATE and FARGATE_SPOT can share a strategy to combine regular and interruptible capacity",
            "A cluster can mix provider types, but one strategy cannot mix Fargate, EC2 ASG and Managed Instances",
            "EC2 ASG providers with managed scaling adjust host capacity for tasks assigned to that provider"
          ]
        },
        {
          "title": "Networking and load balancing",
          "bullets": [
            "The awsvpc mode gives each task an ENI and private IP; Fargate requires this network mode",
            "Choose subnets and security groups for awsvpc tasks; allow application ports from intended callers",
            "An ALB routes HTTP and HTTPS; an NLB handles transport traffic such as TCP, UDP and TLS",
            "Use IP target groups for awsvpc tasks; instance targets are for applicable EC2 network modes",
            "Image pulls, logs and AWS APIs need reachable endpoints through NAT, public routing or VPC endpoints"
          ]
        },
        {
          "title": "IAM roles and secrets",
          "bullets": [
            "The task role grants AWS permissions to application code; SDKs obtain temporary credentials",
            "The execution role lets the ECS or Fargate agent pull images, publish logs and fetch startup secrets",
            "The EC2 instance role serves the host agent; keep application permissions in separate task roles",
            "Reference Secrets Manager or Parameter Store instead of placing secret values in images or definitions",
            "Secrets injected into environment variables do not refresh after rotation; launch new tasks"
          ]
        },
        {
          "title": "Deployments and health",
          "bullets": [
            "Rolling deployments replace existing tasks with new ones while the service remains running",
            "Minimum healthy and maximum percent control how many tasks a rolling deployment keeps or adds",
            "Blue/green, canary and linear strategies support traffic shifting with compatible routing integrations",
            "Enable the rolling deployment circuit breaker and rollback to recover from failed deployments",
            "Set health-check grace time for startup and let apps finish requests during graceful shutdown"
          ]
        },
        {
          "title": "Service scaling and availability",
          "bullets": [
            "Service Auto Scaling changes desired task count within the minimum and maximum you configure",
            "Target tracking can follow service CPU or memory; compatible ALB services can track requests per target",
            "Scheduled scaling prepares for known peaks; cooldowns limit rapid repeated scaling actions",
            "Task scaling and EC2 host scaling solve separate problems; ensure enough host capacity for new tasks",
            "Use multiple AZ subnets and replicas; check service placement and Availability Zone rebalancing"
          ]
        },
        {
          "title": "Service-to-service communication",
          "bullets": [
            "Service Connect gives ECS services stable short names, managed proxies and communication metrics",
            "Name container ports in the task definition, then select those ports in Service Connect settings",
            "A Cloud Map namespace groups Service Connect endpoints across services in the same AWS Region",
            "Allow the required proxy ports through security groups; discovery does not create network access",
            "Clients outside Service Connect need another discovery or routing method, such as a load balancer"
          ]
        },
        {
          "title": "Storage and data lifetime",
          "bullets": [
            "Ephemeral task storage suits temporary files; keep durable application state outside the task",
            "Supported Linux tasks can mount EFS for shared files that survive task replacement",
            "Task-managed EBS creates a new volume per task, optionally initialized from an existing snapshot",
            "Service-managed EBS volumes are deleted when tasks stop; standalone tasks can preserve their volumes",
            "EC2 host bind mounts depend on that host; a replacement task on another host will not inherit the files"
          ]
        },
        {
          "title": "Logs, metrics and debugging",
          "bullets": [
            "Configure the awslogs driver to send container stdout and stderr to CloudWatch Logs",
            "CloudWatch service metrics show CPU and memory; Container Insights adds detail at extra cost",
            "Use EventBridge task and deployment events to react to stopped tasks or failed rollouts",
            "Inspect service events, stoppedReason and container exit codes when tasks cannot start or remain healthy",
            "ECS Exec uses Systems Manager for container commands; enable it on new tasks and scope IAM access"
          ]
        },
        {
          "title": "Costs and common pitfalls",
          "bullets": [
            "ECS orchestration has no extra fee for EC2 or Fargate; Managed Instances adds a management fee",
            "Fargate bills requested resources from image pull; EC2 bills whole instances, including idle capacity",
            "Include load balancers, NAT, public IPv4, storage, transfer and log ingestion in the estimate",
            "A service replaces stopped tasks until you reduce desired count or delete it; stopping one is temporary",
            "Pending tasks can signal insufficient compute or subnet IPs; image pull failures also need IAM and routing checks"
          ]
        }
      ],
      "guide": "services/ecs.html"
    },
    {
      "id": "efs",
      "name": "Amazon EFS",
      "shortName": "EFS",
      "category": "storage",
      "summary": "Elastic shared NFS file storage for Linux workloads.",
      "details": "EFS provides a managed network file system that multiple compute clients can mount concurrently. It scales storage automatically and offers regional and One Zone classes, with lifecycle management for infrequently accessed data.",
      "useCases": [
        "Shared Linux application files",
        "Container persistent file storage",
        "Home directories and content repositories"
      ],
      "concepts": [
        "NFS mount targets",
        "Regional or One Zone storage",
        "Performance and throughput modes",
        "Lifecycle management"
      ],
      "considerations": [
        "Clients need network paths and security-group rules to mount targets.",
        "Performance and cost vary by storage class and throughput configuration."
      ],
      "docs": "https://docs.aws.amazon.com/efs/latest/ug/whatisefs.html",
      "sources": [
        {
          "title": "Amazon EFS documentation",
          "url": "https://docs.aws.amazon.com/efs/latest/ug/whatisefs.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "eks",
      "name": "Amazon EKS",
      "shortName": "EKS",
      "category": "containers",
      "summary": "Managed Kubernetes control planes for Kubernetes applications on AWS.",
      "details": "EKS runs the Kubernetes control plane and offers managed node groups, self-managed nodes, and Fargate profiles for supported Pods. Cluster networking, IAM integration, add-ons, and Kubernetes version upgrades remain important operational choices.",
      "useCases": [
        "Kubernetes application hosting",
        "Platform teams operating clusters",
        "Portable Kubernetes workloads"
      ],
      "concepts": [
        "Managed control plane",
        "Node groups and Fargate profiles",
        "EKS access entries and IAM",
        "VPC CNI networking"
      ],
      "considerations": [
        "Customers still operate workloads, add-ons, policies, and worker capacity choices.",
        "Kubernetes and feature version support follows an evolving lifecycle."
      ],
      "docs": "https://docs.aws.amazon.com/eks/latest/userguide/what-is-eks.html",
      "sources": [
        {
          "title": "Amazon EKS documentation",
          "url": "https://docs.aws.amazon.com/eks/latest/userguide/what-is-eks.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "elastic-beanstalk",
      "name": "AWS Elastic Beanstalk",
      "shortName": "Elastic Beanstalk",
      "category": "compute",
      "summary": "Deploys web applications while provisioning and operating an AWS environment.",
      "details": "Elastic Beanstalk accepts application code or container artifacts and provisions supporting resources such as EC2, load balancing, and Auto Scaling according to the selected environment tier. It exposes configuration and health tools while leaving access to underlying resources.",
      "useCases": [
        "Conventional web applications",
        "Managed application deployment",
        "Teams that want AWS resources with platform conventions"
      ],
      "concepts": [
        "Application versions and environments",
        "Web and worker tiers",
        "Platform branches",
        "Underlying AWS resources"
      ],
      "considerations": [
        "Users remain responsible for application code, settings, and lifecycle updates.",
        "Platform branch support and runtime availability change over time."
      ],
      "docs": "https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/Welcome.html",
      "sources": [
        {
          "title": "AWS Elastic Beanstalk documentation",
          "url": "https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/Welcome.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "elastic-disaster-recovery",
      "name": "AWS Elastic Disaster Recovery",
      "shortName": "Elastic Disaster Recovery",
      "category": "storage",
      "summary": "Block-level replication and recovery service for restoring servers on AWS.",
      "details": "AWS Elastic Disaster Recovery continuously replicates supported source servers into a staging area and launches recovery instances during drills or failover. It supports recovery from on-premises and cloud environments, but recovery objectives depend on replication health, application dependencies, and tested procedures.",
      "useCases": [
        "on-premises server recovery",
        "cross-cloud disaster recovery",
        "periodic recovery drills"
      ],
      "concepts": [
        "The service continuously replicates source server block data into a staging area on AWS.",
        "Recovery instances are launched during drills or recovery actions from replicated source data.",
        "Recovery time and data loss depend on replication status, application dependencies, and tested recovery settings."
      ],
      "considerations": [
        "Replication and recovery infrastructure incur charges",
        "Test application consistency, network dependencies, and recovery time objectives"
      ],
      "docs": "https://docs.aws.amazon.com/drs/",
      "sources": [
        {
          "title": "AWS Elastic Disaster Recovery documentation",
          "url": "https://docs.aws.amazon.com/drs/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "evs",
      "name": "Amazon Elastic VMware Service",
      "shortName": "Elastic VMware Service",
      "category": "migration",
      "summary": "Runs VMware Cloud Foundation software on Amazon EC2 capacity within a customer VPC.",
      "details": "EVS lets customers deploy and operate a VMware environment on AWS infrastructure while retaining VMware management constructs and supported integrations. The service orchestrates deployment, while customers continue to own VMware configuration, workload operation, and the surrounding AWS network design.",
      "useCases": [
        "extend an existing VMware estate onto AWS",
        "migrate VMware workloads with familiar vSphere operations",
        "host a VMware Cloud Foundation environment close to AWS services"
      ],
      "concepts": [
        "EVS environments deploy VCF components on EC2",
        "the environment resides in a customer VPC",
        "VMware Cloud Foundation supplies the virtualization and management layer",
        "EVS APIs and console coordinate deployment"
      ],
      "considerations": [
        "check VCF release and Region prerequisites before designing capacity",
        "customers manage workload placement, licensing, networking, and VMware operations"
      ],
      "docs": "https://docs.aws.amazon.com/evs/latest/userguide/what-is-evs.html",
      "sources": [
        {
          "title": "What is Amazon Elastic VMware Service?",
          "url": "https://docs.aws.amazon.com/evs/latest/userguide/what-is-evs.html"
        },
        {
          "title": "EVS architecture and requirements",
          "url": "https://docs.aws.amazon.com/evs/latest/userguide/architecture.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "elasticache",
      "name": "Amazon ElastiCache",
      "shortName": "ElastiCache",
      "category": "database",
      "summary": "Managed in-memory data stores for caching and low-latency data access.",
      "details": "It supports Redis OSS and Memcached-compatible options with deployment modes and feature sets that differ. Applications use it as a cache or purpose-built in-memory layer alongside a durable system of record.",
      "useCases": [
        "cache catalog reads",
        "store short-lived sessions",
        "accelerate repeated query results"
      ],
      "concepts": [
        "caches",
        "nodes or serverless",
        "eviction",
        "replication"
      ],
      "considerations": [
        "Cache invalidation and durability expectations belong in application design",
        "compare engine feature and failover behavior."
      ],
      "docs": "https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/WhatIs.html",
      "sources": [
        {
          "title": "Amazon ElastiCache documentation",
          "url": "https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/WhatIs.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "elastic-load-balancing",
      "name": "Elastic Load Balancing",
      "shortName": "ELB",
      "category": "network",
      "summary": "Distributes incoming traffic across targets in one or more Availability Zones.",
      "details": "Elastic Load Balancing includes Application, Network, Gateway, and Classic Load Balancers. Load balancers integrate with EC2, ECS, EKS, and Auto Scaling target groups or IP targets depending on type.",
      "useCases": [
        "Web traffic distribution",
        "TLS termination and routing",
        "Private service ingress"
      ],
      "concepts": [
        "ALB, NLB, GWLB, Classic",
        "Listeners and target groups",
        "Health checks",
        "Cross-zone and zonal behavior"
      ],
      "considerations": [
        "Choose a load balancer by protocol, routing, performance, and network placement needs.",
        "Target registration mode and health checks affect service reachability."
      ],
      "docs": "https://docs.aws.amazon.com/elasticloadbalancing/latest/userguide/what-is-load-balancing.html",
      "sources": [
        {
          "title": "Elastic Load Balancing documentation",
          "url": "https://docs.aws.amazon.com/elasticloadbalancing/latest/userguide/what-is-load-balancing.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "elemental-inference",
      "name": "AWS Elemental Inference",
      "shortName": "Elemental Inference",
      "category": "media",
      "summary": "Machine-learning analysis for live video, including subtitles, crops, clips, and metadata.",
      "details": "Inference processes media through configured feeds and outputs; MediaLive integrates setup for several live-channel features. It has its own API and guide, while the product index currently links to MediaLive integration documentation.",
      "useCases": [
        "generate live subtitles",
        "smart-crop different formats",
        "emit event or contextual metadata"
      ],
      "concepts": [
        "Feeds associate media sources with inference outputs",
        "Subtitle and crop features produce media-aware results",
        "Metadata can feed downstream ad workflows"
      ],
      "considerations": [
        "Region, quota, format, and content limits apply",
        "Some MediaLive event-clipping features support specified sports only."
      ],
      "docs": "https://docs.aws.amazon.com/elemental-inference/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "AWS Elemental Inference documentation",
          "url": "https://docs.aws.amazon.com/elemental-inference/latest/userguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "mediaconnect",
      "name": "AWS Elemental MediaConnect",
      "shortName": "Elemental MediaConnect",
      "category": "media",
      "summary": "Managed contribution and distribution flows for live video transport.",
      "details": "MediaConnect receives, distributes, and shares live video between cloud and on-premises endpoints. Entitlements grant other AWS accounts access; protocol, encryption, and redundancy shape delivery.",
      "useCases": [
        "contribute a live feed",
        "distribute broadcast streams",
        "share video across accounts"
      ],
      "concepts": [
        "Flows define sources, outputs, and transport",
        "Entitlements grant authorized accounts access",
        "Redundancy can use multiple sources or paths"
      ],
      "considerations": [
        "Protocol and source compatibility determine options",
        "Bandwidth and cross-Region transfer affect cost."
      ],
      "docs": "https://docs.aws.amazon.com/mediaconnect/",
      "sources": [
        {
          "title": "AWS Elemental MediaConnect documentation",
          "url": "https://docs.aws.amazon.com/mediaconnect/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "mediaconvert",
      "name": "AWS Elemental MediaConvert",
      "shortName": "Elemental MediaConvert",
      "category": "media",
      "summary": "File-based video transcoding into delivery-ready formats.",
      "details": "MediaConvert runs jobs from input files to configured output groups using presets or custom encoding. Jobs can be submitted directly or through queues and integrated with S3 and event-driven workflows.",
      "useCases": [
        "prepare video for streaming",
        "create broadcast mezzanine files",
        "generate device renditions"
      ],
      "concepts": [
        "Jobs define inputs, outputs, and encoding settings",
        "Queues manage scheduling and reserved capacity",
        "Outputs include adaptive packages or standalone files"
      ],
      "considerations": [
        "Codec, resolution, and queue choices affect cost and time",
        "Check supported formats and Region features."
      ],
      "docs": "https://docs.aws.amazon.com/mediaconvert/",
      "sources": [
        {
          "title": "AWS Elemental MediaConvert documentation",
          "url": "https://docs.aws.amazon.com/mediaconvert/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "medialive",
      "name": "AWS Elemental MediaLive",
      "shortName": "Elemental MediaLive",
      "category": "media",
      "summary": "AWS Elemental MediaLive is a real-time video processing service for live broadcast and streaming outputs. It ingests and transcodes live sources, then packages outputs for playback and delivery.",
      "details": "A MediaLive channel combines configured inputs, processing pipelines, and outputs. Standard channels use two pipelines for resilience, while single-pipeline channels use one; downstream packaging and content delivery are handled by other services or systems.",
      "useCases": [
        "live event streaming",
        "broadcast channel origination",
        "transcoding live feeds for multiple playback formats"
      ],
      "concepts": [
        "Inputs describe the live source and how MediaLive receives it",
        "Channels transcode and package content into configured outputs",
        "Standard and single-pipeline channel classes provide different pipeline layouts"
      ],
      "considerations": [
        "Input protocols, output formats, and Region availability constrain channel design",
        "Channel class, running time, and output configuration affect cost and resilience."
      ],
      "docs": "https://docs.aws.amazon.com/medialive/latest/ug/what-is.html",
      "sources": [
        {
          "title": "What is AWS Elemental MediaLive?",
          "url": "https://docs.aws.amazon.com/medialive/latest/ug/what-is.html"
        },
        {
          "title": "AWS Elemental MediaLive User Guide",
          "url": "https://docs.aws.amazon.com/medialive/latest/ug/"
        }
      ],
      "status": "active",
      "statusNote": "Active; service lifecycle checked against current AWS Elemental MediaLive documentation on 2026-10-08.",
      "kind": "service"
    },
    {
      "id": "mediapackage",
      "name": "AWS Elemental MediaPackage",
      "shortName": "Elemental MediaPackage",
      "category": "media",
      "summary": "Packages and protects video streams for playback devices.",
      "details": "MediaPackage ingests media from supported encoders and creates packaged outputs such as HLS or DASH. It can integrate with DRM and CDNs; it is an origin layer rather than a viewer player.",
      "useCases": [
        "create adaptive manifests",
        "protect video content",
        "originate live outputs"
      ],
      "concepts": [
        "Endpoints expose configured packaging formats",
        "Just-in-time packaging adapts delivery format",
        "Content protection uses supported DRM providers"
      ],
      "considerations": [
        "Codec, DRM, and player support must align",
        "Requests and egress shape cost."
      ],
      "docs": "https://docs.aws.amazon.com/mediapackage/",
      "sources": [
        {
          "title": "AWS Elemental MediaPackage documentation",
          "url": "https://docs.aws.amazon.com/mediapackage/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "mediatailor",
      "name": "AWS Elemental MediaTailor",
      "shortName": "Elemental MediaTailor",
      "category": "media",
      "summary": "Personalizes streams with server-side ads and channel assembly.",
      "details": "MediaTailor inserts ads into live and VOD streams using ad-decision responses and can assemble linear channels from source content. Ad signaling and asset readiness affect playback continuity.",
      "useCases": [
        "server-side ad insertion",
        "personalized VOD",
        "scheduled linear channels"
      ],
      "concepts": [
        "Ad-decision systems return break selections",
        "Personalized manifests reflect viewer sessions",
        "Channel assembly schedules programs"
      ],
      "considerations": [
        "Markers, assets, and decision latency affect playback",
        "Ad-provider traffic adds cost and dependencies."
      ],
      "docs": "https://docs.aws.amazon.com/mediatailor/",
      "sources": [
        {
          "title": "AWS Elemental MediaTailor documentation",
          "url": "https://docs.aws.amazon.com/mediatailor/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "elemental-on-premises",
      "name": "AWS Elemental On-Premises",
      "shortName": "Elemental On-Premises",
      "category": "media",
      "summary": "On-premises Elemental software for encoding and processing video near local sources.",
      "details": "Elemental appliances run AWS media software near studio and production systems. Hardware, licensing, networking, and maintenance are part of deployment, unlike fully managed cloud services.",
      "useCases": [
        "encode studio feeds locally",
        "process venue contribution video",
        "connect broadcast systems to AWS"
      ],
      "concepts": [
        "Appliances perform encoding near sources",
        "Elemental software integrates with cloud media workflows",
        "Local network design shapes media handoff"
      ],
      "considerations": [
        "Confirm hardware support, versions, and licensing with AWS",
        "Customers operate local power, networking, and resilience."
      ],
      "docs": "https://docs.aws.amazon.com/elemental-on-premises/",
      "sources": [
        {
          "title": "AWS Elemental On-Premises documentation",
          "url": "https://docs.aws.amazon.com/elemental-on-premises/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "emr",
      "name": "Amazon EMR",
      "shortName": "EMR",
      "category": "analytics",
      "summary": "Managed big-data platforms for open-source frameworks such as Spark, Hive, and Trino.",
      "details": "EMR offers deployment choices including clusters on EC2, EMR Serverless, and EMR on EKS, each with distinct operations and compute control. It processes data held in services such as S3 or HDFS depending on architecture.",
      "useCases": [
        "run Spark transformations over lake data",
        "execute Hive analytics",
        "operate a shared Trino cluster"
      ],
      "concepts": [
        "EMR on EC2 runs open-source data frameworks on clusters of EC2 instances.",
        "EMR Serverless runs supported Spark and Hive workloads without cluster provisioning.",
        "EMR on EKS runs EMR jobs on Kubernetes clusters managed by Amazon EKS.",
        "Release versions select framework releases and their included patches."
      ],
      "considerations": [
        "Choose deployment mode based on control and operations",
        "framework versions and workload sizing affect compatibility and cost."
      ],
      "docs": "https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-what-is-emr.html",
      "sources": [
        {
          "title": "Amazon EMR documentation",
          "url": "https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-what-is-emr.html"
        },
        {
          "title": "EMR clusters, nodes and deployment concepts",
          "url": "https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-overview.html"
        },
        {
          "title": "EMR Serverless concepts",
          "url": "https://docs.aws.amazon.com/emr/latest/EMR-Serverless-UserGuide/emr-serverless.html"
        },
        {
          "title": "EMR on EKS concepts",
          "url": "https://docs.aws.amazon.com/emr/latest/EMR-on-EKS-DevelopmentGuide/emr-eks-concepts.html"
        },
        {
          "title": "EMR release bundles and application versions",
          "url": "https://docs.aws.amazon.com/emr/latest/ReleaseGuide/emr-release-components.html"
        },
        {
          "title": "Security in Amazon EMR",
          "url": "https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-security.html"
        },
        {
          "title": "EMR pricing by deployment option",
          "url": "https://aws.amazon.com/emr/pricing/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service",
      "topics": [
        {
          "title": "Three deployment choices",
          "bullets": [
            "Amazon EMR runs open-source analytics engines such as Spark and Hive for data processing",
            "EMR on EC2 provisions clusters in your account, with control over instances and installed applications",
            "EMR Serverless runs Spark or Hive jobs without requiring you to provision a cluster",
            "EMR on EKS runs analytics jobs as containers on an EKS cluster that your team manages",
            "Engine versions and features vary by release and deployment option; check compatibility first"
          ]
        },
        {
          "title": "EC2 primary, core and task nodes",
          "bullets": [
            "The primary node coordinates cluster services and monitors workload and node health",
            "Core nodes run computation and hold HDFS data; removing them carelessly can lose local data",
            "Task nodes add compute capacity and do not hold HDFS data, making them useful for elastic workers",
            "Instance groups use one instance type per group; fleets can mix types and On-Demand with Spot",
            "Managed scaling adjusts supported clusters within limits you set; protect essential capacity from churn"
          ]
        },
        {
          "title": "EMR Serverless applications",
          "bullets": [
            "An application selects an EMR release and engine, such as Spark or Hive, before jobs are submitted",
            "Each job run uses a runtime IAM role for access to its input data, output locations and other resources",
            "Workers scale with job demand; maximum application capacity bounds how many resources may be used",
            "Pre-initialized workers reduce startup delay but incur charges while that capacity remains running",
            "Use separate applications for teams or environments that need independent versions and cost controls"
          ]
        },
        {
          "title": "EMR on EKS virtual clusters",
          "bullets": [
            "A virtual cluster registers one Kubernetes namespace on an existing Amazon EKS cluster",
            "Submit a Spark JAR, PySpark script or Spark SQL job with an execution role and EMR release",
            "EMR supplies analytics containers while Kubernetes schedules their driver and executor pods",
            "Your team still manages EKS capacity, networking and namespace access for shared workloads",
            "Different virtual clusters can share an EKS cluster; registering one does not provision new compute"
          ]
        },
        {
          "title": "Releases and dependencies",
          "bullets": [
            "An EMR release label selects a tested bundle of engine and dependency versions",
            "Select the applications you need on EC2; Serverless applications choose a single engine type",
            "Pin Python packages, JARs and connectors to compatible Spark, Scala and runtime versions",
            "Use bootstrap actions for EC2 node setup; supported Serverless and EKS custom images package dependencies",
            "Test jobs and table formats against a new release before replacing production environments"
          ]
        },
        {
          "title": "S3, HDFS and local storage",
          "bullets": [
            "Keep durable inputs and outputs in S3 so they survive an EC2 cluster being terminated",
            "HDFS uses cluster storage and provides data locality; its data does not survive cluster termination",
            "S3A is the default S3 connector in newer releases; older releases may use EMRFS",
            "Local shuffle and spill files can fill worker disks; size or select storage for the workload",
            "Use columnar formats and useful partitioning to reduce data scanned by analytics jobs"
          ]
        },
        {
          "title": "Tables and catalogs",
          "bullets": [
            "A catalog stores table metadata; the underlying rows may live in S3 independently of that catalog",
            "Configure AWS Glue Data Catalog as a persistent Hive metastore or a supported Iceberg catalog",
            "Iceberg, Hudi and Delta Lake capabilities depend on the EMR release, engine and deployment option",
            "Keep table data in an explicit S3 location when multiple clusters or query engines need it",
            "Lake Formation integrations can govern lake data; verify the supported access mode and release"
          ]
        },
        {
          "title": "Spark sizing and performance",
          "bullets": [
            "The driver coordinates a Spark application; executors run its distributed tasks",
            "Size driver and executor memory separately, including runtime overhead in worker memory requirements",
            "Joins and aggregations can shuffle data across workers, consuming network, memory and disk",
            "Skewed keys create slow tasks; inspect partitions and use suitable join and adaptive-query settings",
            "Avoid collecting a large distributed dataset into the driver; write results or sample them instead"
          ]
        },
        {
          "title": "Jobs and pipeline orchestration",
          "bullets": [
            "On EC2, submit processing steps to a cluster; configure concurrency and failure actions deliberately",
            "Serverless and EMR on EKS expose job-run APIs with entry points, arguments and job configuration",
            "Step Functions or Airflow can coordinate dependent jobs, retries and cleanup around your pipeline",
            "Store versioned job code and explicit input and output paths so a run can be reproduced",
            "Retries should use safe output and commit logic; replaying a job must not silently duplicate data"
          ]
        },
        {
          "title": "Security and networking",
          "bullets": [
            "EC2 service roles manage infrastructure; instance profiles and supported runtime roles grant data access",
            "Serverless and EKS job execution roles need scoped permissions for S3, catalogs and any KMS keys",
            "On EC2, a security configuration can enable encryption for local data and traffic between services",
            "Private deployments need routes or endpoints to their data sources and required AWS APIs",
            "Restrict cluster and notebook access; keep credentials out of bootstrap scripts and job arguments"
          ]
        },
        {
          "title": "Logs and troubleshooting",
          "bullets": [
            "Use Spark UI or history views to inspect stages, task timings, executor failures and shuffle spill",
            "Driver and executor logs answer different questions; retain both when investigating job failures",
            "Serverless supports managed log storage, S3 and CloudWatch; choose logging options before a run",
            "CloudWatch metrics expose workload and resource usage; alert on failed jobs and prolonged queues",
            "Preserve useful logs and event history before terminating an EC2 cluster or deleting test resources"
          ]
        },
        {
          "title": "Costs and operational pitfalls",
          "bullets": [
            "EMR on EC2 adds an EMR charge to EC2 and any EBS costs; idle clusters still consume resources",
            "Serverless charges for worker vCPU, memory and applicable storage while workers are running",
            "EMR on EKS adds an EMR charge to EKS and its underlying compute and storage costs",
            "S3 requests, logs, catalogs, networking and other connected services can add separate charges",
            "On EC2, use suitable Spot task nodes and auto-termination; plan for interruptions and startup delay"
          ]
        }
      ],
      "guide": "services/emr.html"
    },
    {
      "id": "end-user-messaging",
      "name": "AWS End User Messaging Push",
      "shortName": "End User Messaging Push",
      "category": "business",
      "summary": "Managed push delivery for mobile and web apps through APNs, FCM, and other supported push networks.",
      "details": "AWS End User Messaging Push sends notifications to registered device endpoints and forwards them to the platform that owns each token. Developers configure an app, provider credentials, and push payloads; SMS, voice, and WhatsApp use separate End User Messaging APIs.",
      "useCases": [
        "transactional order and delivery alerts",
        "time-sensitive mobile app notifications",
        "re-engagement and in-app event prompts"
      ],
      "concepts": [
        "APNs and FCM channels use provider credentials to authorize delivery",
        "A device token identifies each registered application endpoint",
        "The `SendMessages` operation routes payloads through the matching push provider",
        "ADM and Baidu channels are also supported"
      ],
      "considerations": [
        "Refresh device tokens and provider credentials to avoid rejected deliveries.",
        "Payload formats, delivery feedback, and reach depend on each platform provider."
      ],
      "docs": "https://docs.aws.amazon.com/end-user-messaging/latest/userguide/nx-push.html",
      "sources": [
        {
          "title": "AWS End User Messaging Push setup and channels",
          "url": "https://docs.aws.amazon.com/end-user-messaging/latest/userguide/nx-push.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "sms-voice",
      "name": "AWS End User Messaging SMS",
      "shortName": "End User Messaging SMS",
      "category": "business",
      "summary": "AWS messaging channel for application SMS and voice delivery.",
      "details": "The service exposes APIs for text messages and voice calls, with two-way SMS in eligible destinations. Teams configure origination identities and country-specific registrations; carriers influence final delivery.",
      "useCases": [
        "one-time passcodes",
        "delivery status texts",
        "automated voice alerts"
      ],
      "concepts": [
        "Origination identities identify the sender by country",
        "Two-way messaging needs supported numbers and inbound routing",
        "Protect configurations limit destinations and risky traffic"
      ],
      "considerations": [
        "Carrier filtering, registration, consent, and local law affect delivery",
        "Sender types, throughput, and rates vary by destination."
      ],
      "docs": "https://docs.aws.amazon.com/sms-voice/",
      "sources": [
        {
          "title": "AWS End User Messaging SMS documentation",
          "url": "https://docs.aws.amazon.com/sms-voice/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "social-messaging",
      "name": "AWS End User Messaging Social",
      "shortName": "End User Messaging Social",
      "category": "business",
      "summary": "AWS End User Messaging Social provides WhatsApp messaging APIs for applications. It supports outbound and inbound messages, reusable templates, and interactive WhatsApp experiences.",
      "details": "Link a WhatsApp Business Account (WABA) and its phone numbers, then use the Social Messaging API to send messages and receive customer responses. The service publishes message events to Amazon SNS or an Amazon Connect Customer instance when configured.",
      "useCases": [
        "order and delivery updates over WhatsApp",
        "customer support conversations with inbound replies",
        "interactive forms and appointment booking in WhatsApp"
      ],
      "concepts": [
        "A WABA and its phone numbers provide the WhatsApp business identity",
        "Approved templates can initiate business messages",
        "Event destinations publish message and inbound communication events"
      ],
      "considerations": [
        "Meta business verification, template approval, and messaging policies affect use",
        "Availability and message charges vary by Region, message type, and Meta pricing."
      ],
      "docs": "https://docs.aws.amazon.com/social-messaging/latest/userguide/what-is-service.html",
      "sources": [
        {
          "title": "What is AWS End User Messaging Social?",
          "url": "https://docs.aws.amazon.com/social-messaging/latest/userguide/what-is-service.html"
        },
        {
          "title": "Message and event destinations in AWS End User Messaging Social",
          "url": "https://docs.aws.amazon.com/social-messaging/latest/userguide/managing-event-destinations.html"
        }
      ],
      "status": "active",
      "statusNote": "Active; the Social Messaging API is a distinct channel API from AWS End User Messaging Push.",
      "kind": "service"
    },
    {
      "id": "entity-resolution",
      "name": "AWS Entity Resolution",
      "shortName": "Entity Resolution",
      "category": "analytics",
      "summary": "Matches records that refer to the same real-world entity across datasets.",
      "details": "Users configure schemas and matching workflows using rule-based or ML-assisted techniques, then inspect match groups and outputs. Data preparation and match thresholds affect false matches and missed links.",
      "useCases": [
        "resolve customer records across CRM exports",
        "deduplicate supplier profiles",
        "link campaign records across sources"
      ],
      "concepts": [
        "schemas",
        "matching workflows",
        "rule-based matching",
        "ML matching"
      ],
      "considerations": [
        "Review match quality and sensitive-data handling",
        "entity links are probabilistic or rule-derived depending on method."
      ],
      "docs": "https://docs.aws.amazon.com/entityresolution/latest/userguide/what-is-service.html",
      "sources": [
        {
          "title": "AWS Entity Resolution documentation",
          "url": "https://docs.aws.amazon.com/entityresolution/latest/userguide/what-is-service.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "eventbridge",
      "name": "Amazon EventBridge",
      "shortName": "EventBridge",
      "category": "integration",
      "summary": "Routes events between AWS services, applications, and SaaS sources.",
      "details": "EventBridge event buses match events against rules and send them to supported targets; Pipes connect a source to a target with optional filtering and enrichment. Scheduler handles time-based invocation separately from event matching.",
      "useCases": [
        "Event-driven service integration",
        "SaaS event ingestion",
        "Scheduled target invocation"
      ],
      "concepts": [
        "Event buses and rules",
        "Pipes and Scheduler",
        "Event patterns and targets",
        "Archive and replay"
      ],
      "considerations": [
        "Delivery is asynchronous and consumers should handle retries and duplicates.",
        "Targets require permissions and supported event formats."
      ],
      "docs": "https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-what-is.html",
      "sources": [
        {
          "title": "Amazon EventBridge documentation",
          "url": "https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-what-is.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "fargate",
      "name": "AWS Fargate",
      "shortName": "Fargate",
      "category": "containers",
      "summary": "Serverless compute capacity for supported ECS tasks and EKS Pods.",
      "details": "Fargate provisions isolated compute for containers selected through ECS task configuration or EKS Fargate profiles. It removes host provisioning but still uses customer-defined task or Pod resources, IAM permissions, and networking.",
      "useCases": [
        "Container services without server fleets",
        "Isolated task execution",
        "Kubernetes Pods with supported requirements"
      ],
      "concepts": [
        "ECS launch type or capacity provider",
        "EKS Fargate profiles",
        "Task/Pod execution roles",
        "Per-task or per-Pod isolation"
      ],
      "considerations": [
        "Not every ECS or Kubernetes feature is supported on Fargate.",
        "AWS Batch supports Fargate with ECS orchestration; not Batch on EKS."
      ],
      "docs": "https://docs.aws.amazon.com/AmazonECS/latest/userguide/what-is-fargate.html",
      "sources": [
        {
          "title": "Fargate with ECS",
          "url": "https://docs.aws.amazon.com/AmazonECS/latest/userguide/what-is-fargate.html"
        },
        {
          "title": "Fargate with EKS",
          "url": "https://docs.aws.amazon.com/eks/latest/userguide/fargate.html"
        },
        {
          "title": "Fargate task definition requirements for ECS",
          "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/fargate-tasks-services.html"
        },
        {
          "title": "Fargate networking for ECS",
          "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/fargate-task-networking.html"
        },
        {
          "title": "EKS Fargate Pod resource configuration",
          "url": "https://docs.aws.amazon.com/eks/latest/userguide/fargate-pod-configuration.html"
        },
        {
          "title": "ECS Fargate and Spot capacity providers",
          "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/fargate-capacity-providers.html"
        },
        {
          "title": "AWS Fargate pricing",
          "url": "https://aws.amazon.com/fargate/pricing/"
        }
      ],
      "status": "active",
      "kind": "service",
      "topics": [
        {
          "title": "Compute engine and isolation",
          "bullets": [
            "Fargate provides serverless compute for containers scheduled by Amazon ECS or Amazon EKS",
            "AWS provisions, patches and manages the underlying hosts; you select application resource needs",
            "Each ECS task or EKS Pod has its own virtualization boundary and does not share its kernel with others",
            "Containers inside the same task or Pod share that workload's resources and can run as sidecars",
            "You still maintain container images, application security, IAM permissions and network configuration"
          ]
        },
        {
          "title": "Running ECS workloads",
          "bullets": [
            "Register a Fargate-compatible task definition with images, task CPU, memory and awsvpc networking",
            "An ECS task launches one or more containers together; its definition also sets roles, logs and volumes",
            "Use an ECS service for applications that need a desired replica count and replacement of stopped tasks",
            "Run standalone tasks for finite jobs; an external scheduler or workflow handles recurring runs and retries",
            "Deploy a new service revision to change application settings; running containers do not update themselves"
          ]
        },
        {
          "title": "Running EKS workloads",
          "bullets": [
            "An EKS Fargate profile selects Pods by namespace and optional labels, with subnets and an execution role",
            "A Pod must match a profile when scheduled; unmatched Pods intended for Fargate can remain Pending",
            "EKS Fargate uses private subnets and does not assign public IPs to Pods",
            "Profiles are immutable; create a replacement profile before retiring the old configuration",
            "DaemonSets, privileged Pods, HostNetwork and HostPort are unsupported; use compatible sidecar patterns"
          ]
        },
        {
          "title": "CPU, memory and architecture",
          "bullets": [
            "ECS requires task-level CPU and memory from supported pairs; not every CPU-to-memory ratio is valid",
            "ECS supports Linux on x86_64 or ARM64 and supported Windows versions on x86_64",
            "EKS Fargate supports Linux x86_64; do not assume the ECS Windows or Arm options apply to EKS",
            "EKS combines container requests, accounts for init containers and system overhead, then rounds to a size",
            "Inspect an EKS Pod's CapacityProvisioned annotation for its actual allocated and billed compute size"
          ]
        },
        {
          "title": "Images and startup flow",
          "bullets": [
            "Build an image for the selected OS and CPU architecture and publish it to a reachable container registry",
            "On launch, Fargate obtains registry access, pulls the image and starts the workload's containers",
            "Private ECR pulls on ECS Linux platform 1.4 need ECR API, registry and S3 endpoints when using PrivateLink",
            "Small images reduce download and unpack work; image layers also consume ephemeral disk space",
            "SOCI lazy loading can speed supported Linux ECS tasks with indexed ECR images; measure the benefit"
          ]
        },
        {
          "title": "Networking and ingress",
          "bullets": [
            "ECS Fargate uses awsvpc: each task gets a dedicated ENI with security groups and a private IP",
            "Containers in the same ECS task can communicate through localhost without an external load balancer",
            "An ECS task in a public subnet can receive a public IP; internet access also needs the correct VPC route",
            "Private IPv4 workloads reach external services through NAT, or supported AWS services through endpoints",
            "Use IP targets with ALB or NLB for Fargate workloads; allow ingress only from intended sources"
          ]
        },
        {
          "title": "Startup and application permissions",
          "bullets": [
            "The ECS execution role lets Fargate pull images, send configured logs and retrieve startup secrets",
            "The ECS task role grants application code its AWS permissions through temporary credentials",
            "The EKS Pod execution role serves platform components and image pulls; containers cannot use it as an app role",
            "Use IAM roles for service accounts for AWS access from applications in EKS Fargate Pods",
            "ECS secrets injected as environment variables are read at startup; replace tasks after secret rotation"
          ]
        },
        {
          "title": "Temporary and durable storage",
          "bullets": [
            "Ephemeral storage is erased when a task or Pod stops; use it for caches and scratch files",
            "Modern ECS platforms include ephemeral storage; compressed and unpacked images reduce usable space",
            "Supported Linux ECS tasks can mount EFS; EKS Fargate uses EFS with static volume provisioning",
            "Supported Linux ECS tasks can use task-managed EBS; EKS Fargate Pods cannot mount EBS volumes",
            "ECS service-managed EBS is deleted on task termination, so plan snapshots or another durable data store"
          ]
        },
        {
          "title": "Scaling and availability",
          "bullets": [
            "ECS Service Auto Scaling changes the number of tasks; Fargate supplies compute for each new task",
            "EKS Horizontal Pod Autoscaler changes replicas; resource requests determine each Pod's Fargate size",
            "Run replicas across AZs and check their placement; one task or Pod is still a single failure boundary",
            "New capacity takes time to provision and start; leave headroom when traffic rises faster than startup",
            "AWS maintenance can replace workloads; ECS services recover replicas, while standalone jobs need handling"
          ]
        },
        {
          "title": "Fargate Spot",
          "bullets": [
            "Fargate Spot supplies discounted spare capacity for interruption-tolerant Linux ECS tasks",
            "EKS Fargate and ECS Windows tasks do not support Fargate Spot",
            "An ECS capacity provider strategy can mix FARGATE and FARGATE_SPOT using a base and weights",
            "Reclaimed Spot tasks receive a two-minute warning; handle termination, save progress and retry safely",
            "Spot shortages delay task launches; Fargate does not automatically replace Spot with regular capacity"
          ]
        },
        {
          "title": "Logs, metrics and troubleshooting",
          "bullets": [
            "ECS awslogs sends stdout and stderr to CloudWatch; FireLens can route logs to other destinations",
            "EKS Fargate has a managed Fluent Bit router configured with aws-logging in aws-observability",
            "Container Insights and application telemetry help track resource use, errors and startup behavior",
            "ECS Exec provides container access through Systems Manager when enabled with suitable IAM permissions",
            "For failed starts, inspect ECS stopped reasons or EKS events, then check images, IAM, routing and subnet IPs"
          ]
        },
        {
          "title": "Costs and practical limits",
          "bullets": [
            "Billing uses provisioned vCPU, memory and additional ephemeral storage, rather than actual CPU utilization",
            "Compute billing starts with image download and lasts until termination; minimum durations depend on OS",
            "Include EKS cluster fees, load balancers, NAT, public IPv4, persistent storage, transfer and logs separately",
            "Right-size tasks and Pods; compare Compute Savings Plans and Spot for eligible workloads",
            "GPU access and privileged containers are unsupported; check regional availability, quotas and platform features"
          ]
        }
      ],
      "guide": "services/fargate.html"
    },
    {
      "id": "fault-injection-service",
      "name": "AWS Fault Injection Service",
      "shortName": "Fault Injection Service",
      "category": "management",
      "summary": "Runs controlled experiments to test workload response to faults.",
      "details": "FIS executes experiments from templates with actions, targets, stop conditions, and IAM roles. It integrates with CloudWatch alarms and resilience workflows to test hypotheses such as recovery behavior under resource or network stress.",
      "useCases": [
        "Test failover and recovery procedures",
        "Validate throttling or latency handling",
        "Exercise resilience game days"
      ],
      "concepts": [
        "experiments run defined actions against targets",
        "stop conditions halt unsafe experiments",
        "CloudWatch alarms provide abort signals",
        "supported actions are service-specific"
      ],
      "considerations": [
        "Start with controlled environments and narrow scope",
        "Verify stop conditions and permissions before execution"
      ],
      "docs": "https://docs.aws.amazon.com/fis/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "AWS Fault Injection Service documentation",
          "url": "https://docs.aws.amazon.com/fis/latest/userguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "finspace",
      "name": "Amazon FinSpace",
      "shortName": "FinSpace",
      "category": "analytics",
      "summary": "Managed environment for storing and analyzing financial time-series and reference data.",
      "details": "FinSpace for capital markets provided a specialized financial data and managed kdb analytics environment. AWS ended support October 7, 2026 after closing new customer access a year earlier; this entry is for migration context.",
      "useCases": [
        "explore market data",
        "curate financial reference datasets",
        "analyze time-series research"
      ],
      "concepts": [
        "datasets",
        "entitlements",
        "notebooks",
        "time-series"
      ],
      "considerations": [
        "Specialized service availability and onboarding may be restricted",
        "verify AWS lifecycle guidance before planning."
      ],
      "docs": "https://docs.aws.amazon.com/finspace/latest/userguide/amazon-finspace-end-of-support.html",
      "sources": [
        {
          "title": "Amazon FinSpace documentation",
          "url": "https://docs.aws.amazon.com/finspace/latest/userguide/amazon-finspace-end-of-support.html"
        }
      ],
      "status": "retired",
      "statusNote": "AWS ended support October 7, 2026; new customer access had already closed October 7, 2025.",
      "kind": "service"
    },
    {
      "id": "firewall-manager",
      "name": "AWS Firewall Manager",
      "shortName": "Firewall Manager",
      "category": "security",
      "summary": "Centrally applies and audits supported security policies across accounts in AWS Organizations.",
      "details": "A security administrator defines policies for supported protections such as AWS WAF, AWS Shield Advanced, VPC security groups, Network Firewall, and DNS Firewall. Firewall Manager can identify in-scope resources and help maintain consistent policy coverage as accounts and resources change.",
      "useCases": [
        "enforce WAF protections across web applications",
        "audit security group rules across an organization",
        "centrally manage Network Firewall or Shield policies"
      ],
      "concepts": [
        "policies specify protections, scope, and remediation behavior",
        "administrators delegate policy management through Organizations",
        "policy compliance reports show resources that need attention",
        "automatic remediation can apply supported changes"
      ],
      "considerations": [
        "requires an AWS Organizations setup and delegated administration",
        "review remediation scope because automatic policy changes affect member resources"
      ],
      "docs": "https://docs.aws.amazon.com/waf/latest/developerguide/fms-chapter.html",
      "sources": [
        {
          "title": "What is AWS Firewall Manager?",
          "url": "https://docs.aws.amazon.com/waf/latest/developerguide/fms-chapter.html"
        },
        {
          "title": "Firewall Manager policies",
          "url": "https://docs.aws.amazon.com/waf/latest/developerguide/working-with-policies.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "pricingplanmanager",
      "name": "AWS Flat-Rate Plans",
      "shortName": "Flat-Rate Plans",
      "category": "cost",
      "summary": "A subscription offering for simplified pricing across participating AWS services.",
      "details": "AWS Flat-Rate Plans let eligible customers select a defined plan that bundles included usage or service benefits under plan terms. They sit alongside standard pay-as-you-go pricing; the covered services, eligibility, commitment, and overage treatment must be checked in the current plan details.",
      "useCases": [
        "compare a bundled plan with metered service charges",
        "select a plan for a predictable eligible workload",
        "review plan coverage before onboarding a team"
      ],
      "concepts": [
        "plan enrollment is managed through Pricing Plan Manager",
        "plan terms define covered service usage and limits",
        "charges outside plan coverage can remain standard metered charges"
      ],
      "considerations": [
        "availability and eligibility can be limited and can change",
        "estimate actual usage against plan boundaries before committing"
      ],
      "docs": "https://docs.aws.amazon.com/PricingPlanManager/latest/UserGuide/overview.html",
      "sources": [
        {
          "title": "AWS Pricing Plan Manager overview",
          "url": "https://docs.aws.amazon.com/PricingPlanManager/latest/UserGuide/overview.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "forecast",
      "name": "Amazon Forecast",
      "shortName": "Forecast",
      "category": "ai",
      "summary": "Time-series forecasting service that trains forecasts from historical target series and related data.",
      "details": "Forecast workflows prepare datasets, train predictors, and produce quantile forecasts for future periods. AWS lifecycle notices should be checked before planning new deployments.",
      "useCases": [
        "forecast item-level retail demand",
        "estimate inventory needs",
        "model staffing demand"
      ],
      "concepts": [
        "target time series",
        "predictors",
        "quantiles",
        "forecast exports"
      ],
      "considerations": [
        "Forecasting depends on data quality and appropriate evaluation windows",
        "verify current onboarding availability before selecting it."
      ],
      "docs": "https://docs.aws.amazon.com/forecast/latest/dg/what-is-forecast.html",
      "sources": [
        {
          "title": "Amazon Forecast documentation",
          "url": "https://docs.aws.amazon.com/forecast/latest/dg/what-is-forecast.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS closed new customer access effective July 29, 2024; existing customers can continue to use it.",
      "kind": "service"
    },
    {
      "id": "fraud-detector",
      "name": "Amazon Fraud Detector",
      "shortName": "Fraud Detector",
      "category": "ai",
      "summary": "Builds fraud detection models and rules from event data for online activity.",
      "details": "Existing users can define event schemas, train models, and apply rules to score events. AWS closed new-customer access in November 2025 and documents migration and alternatives.",
      "useCases": [
        "score account sign-up risk",
        "flag suspicious payment events",
        "combine model scores with rules"
      ],
      "concepts": [
        "event types",
        "variables",
        "models",
        "detector versions"
      ],
      "considerations": [
        "Restricted to existing customers",
        "validate migration options and do not assume the service accepts new accounts."
      ],
      "docs": "https://docs.aws.amazon.com/frauddetector/latest/ug/what-is-frauddetector.html",
      "sources": [
        {
          "title": "Amazon Fraud Detector documentation",
          "url": "https://docs.aws.amazon.com/frauddetector/latest/ug/what-is-frauddetector.html"
        }
      ],
      "status": "restricted",
      "statusNote": "No longer accepts new customers as of November 7, 2025.",
      "kind": "service"
    },
    {
      "id": "freertos",
      "name": "FreeRTOS",
      "shortName": "FreeRTOS",
      "category": "iot",
      "summary": "Open-source real-time operating system for resource-constrained microcontrollers.",
      "details": "FreeRTOS supplies a kernel and libraries for embedded software, including AWS IoT libraries for cloud connectivity. Developers build for target hardware and maintain the device security and update process.",
      "useCases": [
        "sensor firmware",
        "industrial controllers",
        "battery-powered connected devices"
      ],
      "concepts": [
        "The kernel schedules tasks for real-time behavior",
        "Libraries provide reusable networking functions",
        "Board support adapts code to a microcontroller"
      ],
      "considerations": [
        "Customers own firmware maintenance and secure-update design",
        "Memory, CPU, and connectivity vary by hardware."
      ],
      "docs": "https://docs.aws.amazon.com/freertos/",
      "sources": [
        {
          "title": "FreeRTOS documentation",
          "url": "https://docs.aws.amazon.com/freertos/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "fsx",
      "name": "Amazon FSx",
      "shortName": "FSx",
      "category": "storage",
      "summary": "Managed file systems built on familiar file system technologies.",
      "details": "Amazon FSx offers managed file systems including Windows File Server, Lustre, NetApp ONTAP, and OpenZFS. Each system has distinct protocols, performance properties, administration models, and integration options.",
      "useCases": [
        "Windows SMB file shares",
        "HPC scratch and persistent storage",
        "Enterprise NAS migration"
      ],
      "concepts": [
        "FSx file system families",
        "SMB, NFS, and Lustre protocols",
        "Backup and replication options",
        "VPC connectivity"
      ],
      "considerations": [
        "Choose a file system family based on protocol, performance, and operational requirements.",
        "Availability and features differ between FSx families."
      ],
      "docs": "https://docs.aws.amazon.com/fsx/latest/WindowsGuide/what-is.html",
      "sources": [
        {
          "title": "Amazon FSx overview",
          "url": "https://docs.aws.amazon.com/fsx/latest/WindowsGuide/what-is.html"
        },
        {
          "title": "FSx for Lustre overview",
          "url": "https://docs.aws.amazon.com/fsx/latest/LustreGuide/what-is.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "gamelift",
      "name": "Amazon GameLift Servers",
      "shortName": "GameLift Servers",
      "category": "games",
      "summary": "Managed tools and hosting for deploying and scaling multiplayer game servers.",
      "details": "GameLift Servers manages session placement and fleets running customer server builds on managed EC2 or container options. Games integrate the server SDK and choose suitable matchmaking and placement workflows.",
      "useCases": [
        "multiplayer match servers",
        "scale dedicated server fleets",
        "place players into game sessions"
      ],
      "concepts": [
        "Builds and scripts define server software",
        "Fleets provide capacity in selected locations",
        "Queues and FlexMatch place players into sessions"
      ],
      "considerations": [
        "Integration, scaling, and location shape latency and cost",
        "Test scaling and matchmaking under realistic traffic."
      ],
      "docs": "https://docs.aws.amazon.com/gameliftservers/",
      "sources": [
        {
          "title": "Amazon GameLift Servers documentation",
          "url": "https://docs.aws.amazon.com/gameliftservers/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "gamelift-streams",
      "name": "Amazon GameLift Streams",
      "shortName": "GameLift Streams",
      "category": "games",
      "summary": "Streams interactive games from managed GPU instances to player devices.",
      "details": "GameLift Streams provisions capacity for remotely played games through an application client. Developers integrate the streaming SDK and manage game assets and session orchestration; device and Region support changes over time.",
      "useCases": [
        "stream PC games to mobile",
        "browser-based interactive demos",
        "remote game trials"
      ],
      "concepts": [
        "Applications request a session for a game",
        "GPU capacity renders and encodes the video",
        "Client SDK handles input and stream interaction"
      ],
      "considerations": [
        "Network quality and startup time shape experience",
        "Check GPU, Region, and usage pricing before launch."
      ],
      "docs": "https://docs.aws.amazon.com/gameliftstreams/",
      "sources": [
        {
          "title": "Amazon GameLift Streams documentation",
          "url": "https://docs.aws.amazon.com/gameliftstreams/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "global-accelerator",
      "name": "AWS Global Accelerator",
      "shortName": "Global Accelerator",
      "category": "network",
      "summary": "Uses AWS global network entry points to improve access to regional endpoints.",
      "details": "Global Accelerator provides static anycast IP addresses and routes client traffic to endpoints such as load balancers, EC2 instances, or Elastic IPs. Endpoint groups, health checks, and traffic dials shape regional routing.",
      "useCases": [
        "Global application entry points",
        "Multi-Region failover",
        "TCP/UDP traffic acceleration"
      ],
      "concepts": [
        "Static anycast IPs",
        "Listeners and endpoint groups",
        "Health-based routing",
        "Traffic dials"
      ],
      "considerations": [
        "It complements rather than replaces DNS and application-level failover decisions.",
        "Endpoint types and supported Regions should be checked for a deployment."
      ],
      "docs": "https://docs.aws.amazon.com/global-accelerator/latest/dg/what-is-global-accelerator.html",
      "sources": [
        {
          "title": "AWS Global Accelerator documentation",
          "url": "https://docs.aws.amazon.com/global-accelerator/latest/dg/what-is-global-accelerator.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "glue",
      "name": "AWS Glue",
      "shortName": "Glue",
      "category": "analytics",
      "summary": "Serverless data integration for discovering, preparing, transforming, and moving data.",
      "details": "Glue includes Data Catalog metadata, crawlers, ETL jobs, and interactive or streaming capabilities. Teams choose the components needed for their pipelines rather than adopting one fixed architecture.",
      "useCases": [
        "catalog S3 datasets",
        "transform source records into analytics tables",
        "orchestrate scheduled ETL"
      ],
      "concepts": [
        "The Data Catalog stores metadata about data locations and schemas.",
        "Crawlers inspect selected data sources and create or update catalog tables.",
        "ETL jobs run managed scripts that transform and move data.",
        "Connections store configuration for supported data stores and connectors."
      ],
      "considerations": [
        "Generated schemas can need correction",
        "job configuration and data volume drive runtime and cost."
      ],
      "docs": "https://docs.aws.amazon.com/glue/latest/dg/what-is-glue.html",
      "sources": [
        {
          "title": "AWS Glue documentation",
          "url": "https://docs.aws.amazon.com/glue/latest/dg/what-is-glue.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "govcloud-us",
      "name": "AWS GovCloud (US)",
      "shortName": "GovCloud (US)",
      "category": "security",
      "summary": "Isolated AWS Regions designed for workloads subject to specific US government and regulated-workload requirements.",
      "details": "GovCloud Regions have separate account, identity, and operational considerations from commercial Regions and are designed to support eligible US entities and workloads. Services, features, and integrations can differ from commercial AWS, so architecture and compliance scope must be evaluated against the current GovCloud documentation.",
      "useCases": [
        "host eligible US government workloads",
        "separate regulated workloads from commercial AWS environments",
        "use AWS services in a US-based isolated Region partition"
      ],
      "concepts": [
        "GovCloud has separate Regions and account partition",
        "US persons operate and support the environment under defined controls",
        "service availability differs from commercial Regions",
        "cross-partition access and data transfer require deliberate design"
      ],
      "considerations": [
        "eligibility and workload requirements apply",
        "not every commercial AWS service or feature is available in GovCloud"
      ],
      "docs": "https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/whatis.html",
      "sources": [
        {
          "title": "What is AWS GovCloud (US)?",
          "url": "https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/whatis.html"
        },
        {
          "title": "AWS GovCloud (US) service availability",
          "url": "https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-differences.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "ground-station",
      "name": "AWS Ground Station",
      "shortName": "Ground Station",
      "category": "specialist",
      "summary": "Schedules satellite communications through AWS ground-station antennas.",
      "details": "Ground Station reserves satellite contacts and delivers data to AWS services or customer endpoints. Mission planning, licensing, encryption, and processing remain customer responsibilities.",
      "useCases": [
        "downlink Earth-observation data",
        "command satellite payloads",
        "schedule mission contacts"
      ],
      "concepts": [
        "Contacts reserve antenna time for satellite passes",
        "Dataflow endpoints connect antenna output to destinations",
        "Mission profiles define antenna and signal settings"
      ],
      "considerations": [
        "Antenna schedules and satellite visibility limit contacts",
        "Spectrum, approvals, and link budgets need planning."
      ],
      "docs": "https://docs.aws.amazon.com/ground-station/",
      "sources": [
        {
          "title": "AWS Ground Station documentation",
          "url": "https://docs.aws.amazon.com/ground-station/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "guardduty",
      "name": "Amazon GuardDuty",
      "shortName": "GuardDuty",
      "category": "security",
      "summary": "Detects threats using account, workload, and network activity signals.",
      "details": "GuardDuty analyzes supported telemetry such as CloudTrail events, VPC flow data, DNS, and workload-specific sources to produce findings. Findings can be aggregated across accounts and routed to response workflows through EventBridge.",
      "useCases": [
        "Detect suspicious account activity",
        "Identify compromised compute workloads",
        "Monitor S3 or EKS threats"
      ],
      "concepts": [
        "detectors are regional",
        "delegated administrator supports organization-wide management",
        "findings have severity and resource context",
        "optional protection plans add data sources"
      ],
      "considerations": [
        "Enable in relevant accounts and Regions",
        "Findings require triage and response ownership"
      ],
      "docs": "https://docs.aws.amazon.com/guardduty/latest/ug/what-is-guardduty.html",
      "sources": [
        {
          "title": "Amazon GuardDuty documentation",
          "url": "https://docs.aws.amazon.com/guardduty/latest/ug/what-is-guardduty.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "health",
      "name": "AWS Health",
      "shortName": "Health",
      "category": "management",
      "summary": "Reports account-specific and broad AWS service events.",
      "details": "AWS Health provides personalized operational notifications such as service events and scheduled changes. The Health Dashboard shows account-relevant events; the Health API and EventBridge can support organization-wide automation subject to access setup.",
      "useCases": [
        "Monitor events affecting account resources",
        "Notify teams about scheduled maintenance",
        "Aggregate health events across accounts"
      ],
      "concepts": [
        "account-specific events include affected entities",
        "public events report service-wide issues",
        "EventBridge supports event routing",
        "Organizations access requires configuration"
      ],
      "considerations": [
        "Distinguish service health from account workload health",
        "Set event ownership and notification routing"
      ],
      "docs": "https://docs.aws.amazon.com/health/latest/ug/what-is-aws-health.html",
      "sources": [
        {
          "title": "AWS Health documentation",
          "url": "https://docs.aws.amazon.com/health/latest/ug/what-is-aws-health.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "healthimaging",
      "name": "AWS HealthImaging",
      "shortName": "HealthImaging",
      "category": "ai",
      "summary": "Stores, transforms, and provides access to medical imaging data at cloud scale.",
      "details": "It supports DICOM imaging data import and retrieval through purpose-built data stores and APIs, for imaging applications and clinical workflows. It complements rather than replaces clinical image viewers.",
      "useCases": [
        "centralize radiology imaging",
        "retrieve DICOM studies for an application",
        "build imaging research data access"
      ],
      "concepts": [
        "DICOM",
        "data stores",
        "image sets",
        "import jobs"
      ],
      "considerations": [
        "Plan DICOM compatibility, access controls, and clinical application integration",
        "assess regional availability."
      ],
      "docs": "https://docs.aws.amazon.com/healthimaging/latest/devguide/what-is.html",
      "sources": [
        {
          "title": "AWS HealthImaging documentation",
          "url": "https://docs.aws.amazon.com/healthimaging/latest/devguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "healthlake",
      "name": "AWS HealthLake",
      "shortName": "HealthLake",
      "category": "ai",
      "summary": "Stores and analyzes health data using FHIR resources and healthcare-oriented services.",
      "details": "HealthLake provides FHIR-compatible data stores and supports importing and exporting health records; related analytics or NLP tools are separate choices. It targets healthcare data workflows and access control requirements.",
      "useCases": [
        "centralize FHIR clinical records",
        "query longitudinal patient data",
        "exchange healthcare datasets"
      ],
      "concepts": [
        "FHIR",
        "data stores",
        "import and export",
        "healthcare access control"
      ],
      "considerations": [
        "Healthcare data requires strong governance and compliance controls",
        "validate supported FHIR features and Region availability."
      ],
      "docs": "https://docs.aws.amazon.com/healthlake/latest/devguide/what-is.html",
      "sources": [
        {
          "title": "AWS HealthLake documentation",
          "url": "https://docs.aws.amazon.com/healthlake/latest/devguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "healthomics",
      "name": "AWS HealthOmics",
      "shortName": "HealthOmics",
      "category": "ai",
      "summary": "Managed services for bioinformatics workflows, sequence data, and reference genomics.",
      "details": "It provides workflow execution and purpose-built sequence and reference stores, with data movement and compute managed around scientific pipelines. Storage and workflow components can be selected independently.",
      "useCases": [
        "run variant-calling pipelines",
        "manage reference genomes",
        "share sequence datasets for research"
      ],
      "concepts": [
        "sequence stores",
        "reference stores",
        "workflows",
        "workflow runs"
      ],
      "considerations": [
        "Large scientific datasets need deliberate retention and access design",
        "workflow portability and tool containers require validation."
      ],
      "docs": "https://docs.aws.amazon.com/omics/latest/dev/what-is-healthomics.html",
      "sources": [
        {
          "title": "AWS HealthOmics documentation",
          "url": "https://docs.aws.amazon.com/omics/latest/dev/what-is-healthomics.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "iam-identity-center",
      "name": "AWS IAM Identity Center",
      "shortName": "IAM Identity Center",
      "category": "security",
      "summary": "Centralizes workforce sign-in and permission assignment across AWS accounts and applications.",
      "details": "IAM Identity Center connects an identity source to permission sets and account assignments. It provisions federated access so people can use a central portal without creating separate IAM users in every account.",
      "useCases": [
        "Provide workforce account access",
        "Map identity groups to permission sets",
        "Enable SSO to supported business apps"
      ],
      "concepts": [
        "identity source can be its directory or external IdP",
        "permission sets define account permissions",
        "AWS accounts can be organized through Organizations",
        "supports SAML 2.0 application access"
      ],
      "considerations": [
        "Plan identity source and group lifecycle first",
        "Use MFA and least-privilege permission sets"
      ],
      "docs": "https://docs.aws.amazon.com/singlesignon/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "AWS IAM Identity Center documentation",
          "url": "https://docs.aws.amazon.com/singlesignon/latest/userguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "iam",
      "name": "AWS Identity and Access Management",
      "shortName": "Identity and Access Management",
      "category": "security",
      "summary": "Controls authentication and authorization for AWS accounts and resources.",
      "details": "IAM defines identities, roles, policies, and trust relationships used to grant scoped access. Prefer temporary role credentials for people and workloads, and evaluate permissions with policy tools before rollout.",
      "useCases": [
        "Grant application roles access to APIs",
        "Federate workforce access",
        "Constrain cross-account operations"
      ],
      "concepts": [
        "users, groups, roles, policies",
        "identity-based and resource-based policies",
        "STS issues temporary credentials",
        "Access Analyzer checks policies"
      ],
      "considerations": [
        "Avoid long-lived access keys where roles work",
        "Review wildcard permissions and trust policies"
      ],
      "docs": "https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction.html",
      "sources": [
        {
          "title": "AWS Identity and Access Management documentation",
          "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/introduction.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "support",
      "name": "AWS Incident Detection and Response",
      "shortName": "Incident Detection and Response",
      "category": "business",
      "summary": "AWS incident-response offering that monitors eligible production workloads and coordinates response.",
      "details": "Incident Detection and Response is a Support offering with onboarding, workload monitoring, and incident-management processes. It supplements an organization’s operations; it is not a general-purpose monitoring service by itself.",
      "useCases": [
        "coordinate production incident response",
        "add AWS expertise to critical workloads",
        "prepare incident runbooks"
      ],
      "concepts": [
        "Onboarding captures architecture and escalation contacts",
        "Monitoring follows agreed response processes",
        "AWS Support and customer responders coordinate during incidents"
      ],
      "considerations": [
        "Eligibility and workload coverage depend on support arrangements",
        "Customers own application runbooks and business decisions."
      ],
      "docs": "https://docs.aws.amazon.com/IDR/latest/userguide/getting-started-idr.html",
      "sources": [
        {
          "title": "AWS Incident Detection and Response documentation",
          "url": "https://docs.aws.amazon.com/IDR/latest/userguide/getting-started-idr.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "infrastructure-composer",
      "name": "AWS Infrastructure Composer",
      "shortName": "Infrastructure Composer",
      "category": "developer",
      "summary": "Visual tool for designing and editing serverless application infrastructure.",
      "details": "AWS Infrastructure Composer provides a visual canvas and code view for modeling application resources, including SAM and CloudFormation templates. It helps explore resource relationships and generate infrastructure definitions; deployed resources are created and billed through AWS CloudFormation and their services.",
      "useCases": [
        "visualizing a serverless architecture",
        "editing an existing SAM template",
        "collaborative infrastructure design"
      ],
      "concepts": [
        "The canvas represents application resources and their connections while exposing the underlying template.",
        "Composer works with AWS SAM and CloudFormation infrastructure definitions.",
        "The design tool generates infrastructure code; CloudFormation and the referenced services create and bill deployed resources."
      ],
      "considerations": [
        "Generated templates still need review for permissions and configuration",
        "Supported resource types and editor behavior may evolve"
      ],
      "docs": "https://docs.aws.amazon.com/infrastructure-composer/",
      "sources": [
        {
          "title": "AWS Infrastructure Composer documentation",
          "url": "https://docs.aws.amazon.com/infrastructure-composer/"
        }
      ],
      "status": "active",
      "statusNote": "The standalone console ends December 7, 2026; the full experience remains available through the AWS Toolkit for Visual Studio Code and embedded console experiences.",
      "kind": "service"
    },
    {
      "id": "inspector",
      "name": "Amazon Inspector",
      "shortName": "Inspector",
      "category": "security",
      "summary": "Continuously assesses supported compute workloads for software vulnerabilities and exposure.",
      "details": "Inspector discovers eligible EC2 instances, container images, and Lambda functions and matches software inventory to vulnerabilities and network exposure. Organizations can centrally manage coverage and send findings to Security Hub.",
      "useCases": [
        "Prioritize vulnerable EC2 hosts",
        "Scan container images in ECR",
        "Assess Lambda package vulnerabilities"
      ],
      "concepts": [
        "automated discovery drives coverage",
        "findings include CVE and package details",
        "ECR scanning integrates with image lifecycle",
        "delegated administration supports organizations"
      ],
      "considerations": [
        "Coverage depends on supported resource and Region",
        "Remediate based on exploitability and workload context"
      ],
      "docs": "https://docs.aws.amazon.com/inspector/latest/user/what-is-inspector.html",
      "sources": [
        {
          "title": "Amazon Inspector documentation",
          "url": "https://docs.aws.amazon.com/inspector/latest/user/what-is-inspector.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "ivs",
      "name": "Amazon Interactive Video Service",
      "shortName": "Interactive Video Service",
      "category": "media",
      "summary": "Managed live streaming with APIs and SDKs for interactive applications.",
      "details": "IVS provides low-latency or real-time channels and playback components for web and mobile apps. Stages add multi-host workflows; chat and recording have their own setup and limits.",
      "useCases": [
        "creator live streams",
        "interactive shopping",
        "live events with chat"
      ],
      "concepts": [
        "Channels ingest live video and return playback endpoints",
        "Player SDKs integrate into clients",
        "Stages enable real-time multi-host video"
      ],
      "considerations": [
        "Latency tier, Region, and bitrate affect cost",
        "Moderation, identity, and viewer experience remain application tasks."
      ],
      "docs": "https://docs.aws.amazon.com/ivs/",
      "sources": [
        {
          "title": "Amazon Interactive Video Service documentation",
          "url": "https://docs.aws.amazon.com/ivs/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "interconnect",
      "name": "AWS Interconnect",
      "shortName": "Interconnect",
      "category": "network",
      "summary": "Private network connectivity between AWS and other cloud service providers.",
      "details": "AWS Interconnect is a service for configuring private, high-bandwidth connections between AWS and supported third-party cloud providers. Availability, partner onboarding, network locations, and connectivity options depend on the supported provider and Region; it complements rather than replaces network routing design.",
      "useCases": [
        "private multi-cloud connectivity",
        "data transfer between cloud providers",
        "hybrid application networking"
      ],
      "concepts": [
        "The service targets private connectivity between AWS and supported third-party cloud providers.",
        "Connectivity depends on eligible providers, supported locations, and account onboarding arrangements.",
        "A private link supplies a network path, while customers still configure routes and application network policy."
      ],
      "considerations": [
        "Confirm provider, Region, and location availability",
        "Plan addressing, routing, redundancy, and data-transfer charges"
      ],
      "docs": "https://docs.aws.amazon.com/interconnect/",
      "sources": [
        {
          "title": "AWS Interconnect documentation",
          "url": "https://docs.aws.amazon.com/interconnect/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "iot-1-click",
      "name": "AWS IoT 1-Click",
      "shortName": "IoT 1-Click",
      "category": "iot",
      "summary": "AWS IoT 1-Click linked supported buttons to predefined AWS actions such as invoking a Lambda function. AWS discontinued the service and its APIs on December 16, 2024.",
      "details": "The retired service let customers claim devices, group them into projects, and associate button events with placements and actions. AWS recommended building replacement button workflows with AWS IoT Core.",
      "useCases": [
        "one-touch incident or support requests",
        "simple device-triggered Lambda actions",
        "button-based operational workflows"
      ],
      "concepts": [
        "Claimed buttons were associated with projects and placements",
        "Device events invoked configured actions",
        "The service depended on AWS-managed device connectivity and APIs"
      ],
      "considerations": [
        "AWS ended support and shut down the APIs on December 16, 2024",
        "Existing buttons no longer trigger their associated Lambda actions after shutdown."
      ],
      "docs": "https://docs.aws.amazon.com/general/latest/gr/full_shutdown_services.html",
      "sources": [
        {
          "title": "Services in Full Shutdown - AWS General Reference",
          "url": "https://docs.aws.amazon.com/general/latest/gr/full_shutdown_services.html"
        },
        {
          "title": "AWS IoT 1-Click Developer Guide",
          "url": "https://docs.aws.amazon.com/iot-1-click/latest/developerguide/iot-1-click-dg.pdf"
        }
      ],
      "status": "retired",
      "statusNote": "AWS IoT 1-Click is fully shut down; AWS lists 2025-01-29 as its end-of-support date.",
      "kind": "service"
    },
    {
      "id": "iot-analytics",
      "name": "AWS IoT Analytics",
      "shortName": "IoT Analytics",
      "category": "iot",
      "summary": "AWS IoT Analytics collected, processed, stored, and queried IoT device data for analytics workflows. The service is retired and its console and resources became inaccessible after December 15, 2025.",
      "details": "Its historical workflow used channels, pipelines, data stores, and data sets to prepare device data for analysis. AWS IoT Analytics is included here for lifecycle coverage; AWS directs customers to use current data and analytics services for replacement designs.",
      "useCases": [
        "historical IoT telemetry analysis",
        "device data filtering and enrichment",
        "scheduled data set queries"
      ],
      "concepts": [
        "Channels received messages from IoT Core",
        "Pipelines processed messages into data stores",
        "Data sets represented queryable analysis results"
      ],
      "considerations": [
        "The service ended support on December 15, 2025 and resources are no longer accessible",
        "Existing architectures require migration to supported data ingestion and analytics services."
      ],
      "docs": "https://docs.aws.amazon.com/general/latest/gr/full_shutdown_services.html",
      "sources": [
        {
          "title": "Services in Full Shutdown - AWS General Reference",
          "url": "https://docs.aws.amazon.com/general/latest/gr/full_shutdown_services.html"
        },
        {
          "title": "AWS IoT Analytics storage and dataset guidance",
          "url": "https://docs.aws.amazon.com/iot-sitewise/latest/userguide/configure-storage.html"
        }
      ],
      "status": "retired",
      "statusNote": "AWS ended support for AWS IoT Analytics on 2025-12-15; console and resource access ended.",
      "kind": "service"
    },
    {
      "id": "iot",
      "name": "AWS IoT Core",
      "shortName": "IoT Core",
      "category": "iot",
      "summary": "Managed cloud connectivity and messaging for connected-device fleets.",
      "details": "IoT Core authenticates devices and brokers MQTT or HTTPS messages between devices and cloud applications. Rules route selected messages to other AWS services; registries, policies, and certificates define access.",
      "useCases": [
        "telemetry ingestion",
        "device command and control",
        "connected-product backends"
      ],
      "concepts": [
        "Thing identities and certificates associate device credentials",
        "MQTT topics route authorized messages",
        "Rules process messages and invoke configured destinations"
      ],
      "considerations": [
        "Certificate lifecycle and least-privilege policies matter",
        "Message rates, sizes, and Region coverage affect design."
      ],
      "docs": "https://docs.aws.amazon.com/iot/",
      "sources": [
        {
          "title": "AWS IoT Core documentation",
          "url": "https://docs.aws.amazon.com/iot/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "iot-device-defender",
      "name": "AWS IoT Device Defender",
      "shortName": "IoT Device Defender",
      "category": "iot",
      "summary": "Audits IoT configurations and detects unusual behavior across device fleets.",
      "details": "Device Defender audits against security practices and can detect anomalies from device or cloud metrics. Customers tune thresholds, investigate findings, and remediate affected devices.",
      "useCases": [
        "audit policies and certificates",
        "detect unusual device traffic",
        "monitor fleet security posture"
      ],
      "concepts": [
        "Audits evaluate configuration against checks",
        "Detect metrics compare activity with configured baselines",
        "Mitigations can invoke selected responses"
      ],
      "considerations": [
        "Thresholds need tuning to control false alarms",
        "Findings do not automatically remediate every device."
      ],
      "docs": "https://docs.aws.amazon.com/iot-device-defender/",
      "sources": [
        {
          "title": "AWS IoT Device Defender documentation",
          "url": "https://docs.aws.amazon.com/iot-device-defender/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "iot-device-management",
      "name": "AWS IoT Device Management",
      "shortName": "IoT Device Management",
      "category": "iot",
      "summary": "Tools to register, group, monitor, and remotely manage IoT fleets.",
      "details": "Device Management supports fleet indexing, jobs, and secure tunneling for remote operations. Devices commonly connect through IoT Core; the Fleet Hub web app is a separate feature that shut down in 2025.",
      "useCases": [
        "organize devices by attributes",
        "roll out firmware jobs",
        "troubleshoot devices remotely"
      ],
      "concepts": [
        "Fleet indexing searches registered device attributes",
        "Jobs distribute updates to selected groups",
        "Secure tunneling creates remote access paths"
      ],
      "considerations": [
        "Fleet Hub is retired while other management functions continue",
        "Plan rollout, reconnection, and authorization."
      ],
      "docs": "https://docs.aws.amazon.com/iot-device-management/",
      "sources": [
        {
          "title": "AWS IoT Device Management documentation",
          "url": "https://docs.aws.amazon.com/iot-device-management/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "iot-expresslink",
      "name": "AWS IoT ExpressLink",
      "shortName": "IoT ExpressLink",
      "category": "iot",
      "summary": "Qualified connectivity modules simplify secure networking for IoT devices.",
      "details": "ExpressLink modules let a host microcontroller use cloud connectivity without implementing every network detail. Product makers choose supported modules and use a command interface while owning application behavior and physical security.",
      "useCases": [
        "connect sensors to IoT Core",
        "prototype connected products",
        "reduce networking code on microcontrollers"
      ],
      "concepts": [
        "Qualified modules handle connectivity functions",
        "The host uses a documented command interface",
        "Configured modules connect to AWS IoT services"
      ],
      "considerations": [
        "Module and network support depend on hardware suppliers",
        "Plan credentials, updates, and device lifecycle."
      ],
      "docs": "https://docs.aws.amazon.com/iot-expresslink/",
      "sources": [
        {
          "title": "AWS IoT ExpressLink documentation",
          "url": "https://docs.aws.amazon.com/iot-expresslink/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "iot-fleetwise",
      "name": "AWS IoT FleetWise",
      "shortName": "IoT FleetWise",
      "category": "iot",
      "summary": "Models and transfers selected vehicle data to AWS; closed to new customers since April 30, 2026.",
      "details": "FleetWise standardizes vehicle signals with models and collection schemes that filter cloud-bound data. Existing customers can continue, but AWS no longer accepts new users and points to connected-mobility guidance for modular alternatives.",
      "useCases": [
        "collect selected telemetry",
        "analyze fleet performance",
        "send high-value vehicle signals to cloud"
      ],
      "concepts": [
        "Vehicle models describe signals across vehicle architectures",
        "Collection schemes select signals by conditions",
        "Edge agents transfer selected data"
      ],
      "considerations": [
        "Restricted to existing customers since April 30, 2026",
        "Validate vehicle integration, governance, and Region support."
      ],
      "docs": "https://docs.aws.amazon.com/iot-fleetwise/latest/developerguide/doc-history.html",
      "sources": [
        {
          "title": "AWS IoT FleetWise documentation",
          "url": "https://docs.aws.amazon.com/iot-fleetwise/latest/developerguide/doc-history.html"
        }
      ],
      "status": "restricted",
      "statusNote": "Restricted to existing customers; AWS stopped new-customer access April 30, 2026. Verified 2026-10-08.",
      "kind": "service"
    },
    {
      "id": "greengrass",
      "name": "AWS IoT Greengrass",
      "shortName": "IoT Greengrass",
      "category": "iot",
      "summary": "Runs software components on edge devices and connects them with AWS IoT.",
      "details": "Greengrass runs Lambda functions, containers, and custom components locally, even with intermittent cloud connectivity. Core devices synchronize deployments and messages when connected; customers manage edge hardware and software.",
      "useCases": [
        "edge data filtering",
        "local automation during outages",
        "deploy apps across device groups"
      ],
      "concepts": [
        "Greengrass Core hosts local components",
        "Components package software and lifecycle metadata",
        "Deployments distribute versioned configuration"
      ],
      "considerations": [
        "Hardware, operating system, and connectivity constrain deployments",
        "Customers maintain edge security, patches, and recovery."
      ],
      "docs": "https://docs.aws.amazon.com/greengrass/",
      "sources": [
        {
          "title": "AWS IoT Greengrass documentation",
          "url": "https://docs.aws.amazon.com/greengrass/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "iot-sitewise",
      "name": "AWS IoT SiteWise",
      "shortName": "IoT SiteWise",
      "category": "iot",
      "summary": "Collects and contextualizes industrial equipment data for monitoring and analysis.",
      "details": "SiteWise models assets, ingests measurements from gateways or cloud sources, and exposes data to applications. SiteWise Edge can collect locally; storage and retention choices affect latency and cost.",
      "useCases": [
        "monitor factory equipment",
        "calculate performance metrics",
        "share asset data with dashboards"
      ],
      "concepts": [
        "Asset models represent equipment and relationships",
        "Gateways collect industrial protocol data",
        "Metrics and transforms contextualize measurements"
      ],
      "considerations": [
        "Protocol mapping and asset models affect analytics quality",
        "Connectivity, retention, and ingestion drive cost."
      ],
      "docs": "https://docs.aws.amazon.com/iot-sitewise/",
      "sources": [
        {
          "title": "AWS IoT SiteWise documentation",
          "url": "https://docs.aws.amazon.com/iot-sitewise/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "iot-twinmaker",
      "name": "AWS IoT TwinMaker",
      "shortName": "IoT TwinMaker",
      "category": "iot",
      "summary": "Builds digital twins by linking 3D scenes with equipment data and applications.",
      "details": "TwinMaker organizes entities, components, and connectors into a graph for real-world systems. Visualization integrations can display the model, but the service does not automatically discover or validate physical systems.",
      "useCases": [
        "factory digital twin",
        "building operations visualization",
        "link machine data to 3D scenes"
      ],
      "concepts": [
        "Entities and components model real assets",
        "Connectors query time-series or relationship data",
        "Scene composition links 3D assets to entities"
      ],
      "considerations": [
        "Source data quality determines twin accuracy",
        "Connectors and visualization services add operating dependencies."
      ],
      "docs": "https://docs.aws.amazon.com/iot-twinmaker/",
      "sources": [
        {
          "title": "AWS IoT TwinMaker documentation",
          "url": "https://docs.aws.amazon.com/iot-twinmaker/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "iot-wireless",
      "name": "AWS IoT Wireless",
      "shortName": "IoT Wireless",
      "category": "iot",
      "summary": "Connects LoRaWAN and Amazon Sidewalk devices to AWS IoT applications.",
      "details": "IoT Wireless manages gateways, devices, and network-server functions for supported protocols. Rules can route wireless uplinks into AWS workflows; radio coverage and regional spectrum rules constrain deployments.",
      "useCases": [
        "low-power sensor networks",
        "remote asset tracking",
        "building telemetry over LoRaWAN"
      ],
      "concepts": [
        "Devices join using registered credentials",
        "Gateways forward LoRaWAN traffic to the managed server",
        "Destination rules route messages to applications"
      ],
      "considerations": [
        "Coverage, gateways, and spectrum rules matter",
        "Supported protocol and Region features vary."
      ],
      "docs": "https://docs.aws.amazon.com/iot-wireless/",
      "sources": [
        {
          "title": "AWS IoT Wireless documentation",
          "url": "https://docs.aws.amazon.com/iot-wireless/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "kendra",
      "name": "Amazon Kendra",
      "shortName": "Kendra",
      "category": "ai",
      "summary": "Enterprise search service for finding relevant answers in connected document collections.",
      "details": "Indexes ingest content through connectors or APIs and return ranked passages and documents. Access control and connector choices shape which content is searchable.",
      "useCases": [
        "search technical manuals",
        "retrieve policy passages",
        "power a document portal"
      ],
      "concepts": [
        "indexes",
        "data sources",
        "query results",
        "access control"
      ],
      "considerations": [
        "Index freshness and connector support matter",
        "evaluate whether current Amazon Quick or another search approach better fits new projects."
      ],
      "docs": "https://docs.aws.amazon.com/kendra/latest/dg/what-is-kendra.html",
      "sources": [
        {
          "title": "Amazon Kendra documentation",
          "url": "https://docs.aws.amazon.com/kendra/latest/dg/what-is-kendra.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "kms",
      "name": "AWS Key Management Service",
      "shortName": "Key Management Service",
      "category": "security",
      "summary": "Creates and controls cryptographic keys used by AWS services and applications.",
      "details": "KMS manages key policies, grants, and cryptographic operations, with AWS-managed or customer-managed keys. Many AWS services can use KMS keys for envelope encryption; key-region scope and permissions affect access to encrypted data.",
      "useCases": [
        "Encrypt S3 or database data",
        "Sign or verify application payloads",
        "Control access to encrypted backups"
      ],
      "concepts": [
        "customer-managed keys support lifecycle controls",
        "key policies are primary access control",
        "grants delegate scoped use",
        "envelope encryption protects data keys"
      ],
      "considerations": [
        "Loss or disablement of a key can make data unavailable",
        "Separate key administrators from key users"
      ],
      "docs": "https://docs.aws.amazon.com/kms/latest/developerguide/overview.html",
      "sources": [
        {
          "title": "AWS Key Management Service documentation",
          "url": "https://docs.aws.amazon.com/kms/latest/developerguide/overview.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "keyspaces",
      "name": "Amazon Keyspaces",
      "shortName": "Keyspaces",
      "category": "database",
      "summary": "Managed Apache Cassandra-compatible wide-column database service.",
      "details": "Applications connect using Cassandra query language drivers while AWS manages the service infrastructure. Table design still needs partition-aware access patterns and workload planning.",
      "useCases": [
        "IoT time-series lookups",
        "high-volume event records",
        "Cassandra application migration"
      ],
      "concepts": [
        "keyspaces",
        "tables",
        "partition keys",
        "Cassandra drivers"
      ],
      "considerations": [
        "Cassandra compatibility has service-specific limits",
        "design partitions to avoid uneven access and validate migration queries."
      ],
      "docs": "https://docs.aws.amazon.com/keyspaces/latest/devguide/what-is-keyspaces.html",
      "sources": [
        {
          "title": "Amazon Keyspaces documentation",
          "url": "https://docs.aws.amazon.com/keyspaces/latest/devguide/what-is-keyspaces.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "kinesis",
      "name": "Amazon Kinesis Data Streams",
      "shortName": "Kinesis Data Streams",
      "category": "analytics",
      "summary": "Captures and distributes ordered records for real-time streaming applications.",
      "details": "Producers write records to streams and consumer applications process shards or enhanced fan-out subscriptions. Retention and scaling settings shape replay and throughput behavior.",
      "useCases": [
        "capture clickstream events",
        "stream application telemetry",
        "feed real-time fraud features"
      ],
      "concepts": [
        "streams",
        "shards",
        "partition keys",
        "consumers"
      ],
      "considerations": [
        "Ordering is scoped to partition keys and throughput capacity must be planned",
        "downstream processing needs idempotency strategies."
      ],
      "docs": "https://docs.aws.amazon.com/streams/latest/dev/introduction.html",
      "sources": [
        {
          "title": "Amazon Kinesis Data Streams documentation",
          "url": "https://docs.aws.amazon.com/streams/latest/dev/introduction.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "kiro",
      "name": "Kiro",
      "shortName": "Kiro",
      "category": "developer",
      "summary": "AI-powered development environment for spec-driven software work.",
      "details": "Kiro is an IDE and agentic development tool that can turn prompts into requirements, design documents, and implementation tasks, then help build and validate code. It is a developer product rather than an AWS runtime service; AWS account, plan, and feature availability can vary.",
      "useCases": [
        "specification-led feature work",
        "code generation and refactoring",
        "automated development tasks"
      ],
      "concepts": [
        "A prompt can be expanded into requirements, a design, and implementation tasks through spec-driven workflows.",
        "The IDE helps turn those tasks into code and supports validation during development.",
        "Kiro is a developer environment; access to features depends on the product plan and account."
      ],
      "considerations": [
        "Review generated code and commands before applying them",
        "Check current plan, data handling, and model availability"
      ],
      "docs": "https://kiro.dev/docs/",
      "sources": [
        {
          "title": "Kiro documentation",
          "url": "https://kiro.dev/docs/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "lake-formation",
      "name": "AWS Lake Formation",
      "shortName": "Lake Formation",
      "category": "analytics",
      "summary": "Centralizes fine-grained data access management for data lakes.",
      "details": "It layers permissions and governance over registered data locations and catalog resources, often alongside Glue Data Catalog and analytics consumers. Registration and permission modes determine how controls are enforced.",
      "useCases": [
        "grant analysts column-level access",
        "govern shared lake tables",
        "centralize data lake permissions"
      ],
      "concepts": [
        "registered locations",
        "LF permissions",
        "catalogs",
        "data filters"
      ],
      "considerations": [
        "Existing IAM and resource policies can interact with Lake Formation grants",
        "validate the chosen permission model end to end."
      ],
      "docs": "https://docs.aws.amazon.com/lake-formation/latest/dg/what-is-lake-formation.html",
      "sources": [
        {
          "title": "AWS Lake Formation documentation",
          "url": "https://docs.aws.amazon.com/lake-formation/latest/dg/what-is-lake-formation.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "lambda",
      "name": "AWS Lambda",
      "shortName": "Lambda",
      "category": "compute",
      "summary": "Runs functions in response to events without customers managing servers.",
      "details": "Lambda supports event-driven invocation and managed runtimes as well as container images. Functions can connect to VPC resources, and integrations with services such as S3, SQS, EventBridge, and API Gateway are configured through service-specific permissions and event sources.",
      "useCases": [
        "API backends",
        "File and stream processing",
        "Scheduled or event-triggered automation"
      ],
      "concepts": [
        "Functions and versions",
        "Event source mappings",
        "Execution role",
        "Concurrency and timeouts"
      ],
      "considerations": [
        "Execution duration and resource limits shape suitable workloads.",
        "A VPC attachment changes networking behavior and requires subnet and security-group planning."
      ],
      "docs": "https://docs.aws.amazon.com/lambda/latest/dg/welcome.html",
      "sources": [
        {
          "title": "AWS Lambda documentation",
          "url": "https://docs.aws.amazon.com/lambda/latest/dg/welcome.html"
        },
        {
          "title": "Lambda quotas",
          "url": "https://docs.aws.amazon.com/lambda/latest/dg/gettingstarted-limits.html"
        },
        {
          "title": "Lambda execution environment",
          "url": "https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtime-environment.html"
        },
        {
          "title": "Lambda Managed Instances execution environment",
          "url": "https://docs.aws.amazon.com/lambda/latest/dg/lambda-managed-instances-execution-environment.html"
        },
        {
          "title": "Lambda SnapStart",
          "url": "https://docs.aws.amazon.com/lambda/latest/dg/snapstart.html"
        }
      ],
      "status": "active",
      "kind": "service",
      "topics": [
        {
          "title": "Invocation models",
          "bullets": [
            "Synchronous: the caller waits for the result and receives errors directly",
            "Asynchronous: Lambda queues the event, returns at once and retries on error",
            "Event source mappings: Lambda polls queues and streams and invokes in batches",
            "Synchronous requests and buffered responses are capped at 6 MB; streamed responses at 200 MB",
            "Asynchronous event payloads are capped at 1 MB; pass larger data by reference"
          ]
        },
        {
          "title": "Environment and cold starts",
          "bullets": [
            "Default Lambda runs one invocation per environment; Managed Instances can run several",
            "Warm environments are reused, so module-level globals and /tmp persist between calls",
            "Cold start time covers code download, runtime start and your module imports",
            "Reduce cold starts with smaller packages, lazy imports and fewer dependencies",
            "Provisioned concurrency initializes ahead; SnapStart restores snapshots on supported runtimes"
          ]
        },
        {
          "title": "Concurrency and scaling",
          "bullets": [
            "Concurrency is the number of invocations executing at the same time",
            "Default Lambda scales each function by up to 1,000 environments every 10 seconds",
            "Reserved concurrency caps a function and carves its share from the regional pool",
            "Provisioned concurrency keeps initialized environments ready for a version or alias",
            "Throttled sync calls fail with 429; async and polled invocations are retried"
          ]
        },
        {
          "title": "Event sources",
          "bullets": [
            "S3 and EventBridge invoke asynchronously; deliveries can repeat, so be idempotent",
            "API Gateway and function URLs invoke synchronously; the caller waits for the reply",
            "SQS is polled: set the queue visibility timeout to at least six times the function timeout",
            "DynamoDB and Kinesis streams are polled per shard; a failing record blocks that shard",
            "EventBridge rules and Scheduler can invoke functions on a cron or rate schedule"
          ]
        },
        {
          "title": "Versions and rollouts",
          "bullets": [
            "$LATEST is mutable; a published version is a fixed snapshot of code and config",
            "An alias points at one version; a weighted alias splits traffic between two versions",
            "Roll out by shifting a small weight to the new version, watching errors, then moving on",
            "Point triggers and provisioned concurrency at an alias, not at $LATEST",
            "SAM and CodeDeploy can shift traffic in steps and roll back on failed alarms"
          ]
        },
        {
          "title": "Packages and layers",
          "bullets": [
            "Direct zip upload is capped at 50 MB; code plus layers may total 250 MB unzipped",
            "A function can attach up to five layers to share libraries across functions",
            "Container images can be up to 10 GB and bring their own OS and runtime",
            "Bigger packages mean longer download and unpack time on cold starts",
            "Build dependencies on the target architecture (arm64 or x86_64) and pin versions"
          ]
        },
        {
          "title": "Permissions and VPC access",
          "bullets": [
            "The execution role sets what the function may call in AWS; keep it least-privilege",
            "Resource-based policies control who may invoke the function, such as S3 or another account",
            "VPC attachment places the function's network interfaces in your subnets, with no public IP",
            "VPC IPv4 internet egress uses NAT; supported AWS APIs can use VPC endpoints",
            "Keep secrets in Secrets Manager or Parameter Store, not in plain environment variables"
          ]
        },
        {
          "title": "Retries and failures",
          "bullets": [
            "Async invocations retry failed runs twice by default; the retry count can be changed",
            "Max event age bounds how long an async event may wait before it is discarded",
            "On-failure and on-success destinations receive outcome records for async invocations",
            "Partial batch responses let a stream or queue retry only the items that failed",
            "For SQS sources, use the queue's redrive policy to a dead-letter queue"
          ]
        },
        {
          "title": "Logs, metrics and tracing",
          "bullets": [
            "Stdout and stderr go to CloudWatch Logs, in a log group named /aws/lambda/FUNCTION",
            "Key metrics: Invocations, Errors, Throttles, Duration and ConcurrentExecutions",
            "IteratorAge shows how far a stream consumer lags behind the stream",
            "Enable active X-Ray tracing to see calls to downstream services in a request",
            "Log JSON with a request ID so one invocation's lines can be grouped and searched"
          ]
        },
        {
          "title": "Pricing model",
          "bullets": [
            "Default Lambda bills per request and per GB-second: memory times billed duration",
            "Memory runs from 128 MB to 10,240 MB; CPU scales with memory, so more can cut time",
            "Billed duration rounds up to the nearest millisecond",
            "Provisioned concurrency is billed for as long as it is held, used or not",
            "A free tier covers some monthly requests and compute; check current terms"
          ]
        },
        {
          "title": "When to use it",
          "bullets": [
            "Good fit: event-driven work, spiky traffic, glue code and short tasks",
            "Default timeout limit is 15 minutes; Managed Instances allow 90 for some async/batch sources",
            "For steady load, compare default Lambda costs with Managed Instances or EC2",
            "Weak fit: GPU work and workloads that must hold long-lived client connections",
            "Weak fit: latency-critical paths that cannot absorb cold starts without warm capacity"
          ]
        },
        {
          "title": "Common pitfalls",
          "bullets": [
            "One database connection per call exhausts the database; reuse clients or use RDS Proxy",
            "Timeouts shorter than a downstream call leave half-finished work that gets retried",
            "Background threads may freeze once the handler returns; await work before returning",
            "Unbounded concurrency can overwhelm downstream systems; cap it with reserved concurrency",
            "A function that writes to the source it triggers on can loop and run up cost"
          ]
        }
      ],
      "guide": "services/lambda.html"
    },
    {
      "id": "launchwizard",
      "name": "AWS Launch Wizard",
      "shortName": "Launch Wizard",
      "category": "management",
      "summary": "Guides sizing, configuration, and deployment of supported enterprise applications on AWS.",
      "details": "Launch Wizard gathers application and infrastructure inputs, recommends resources, and can deploy the resulting architecture using AWS infrastructure templates. Supported application scenarios and Regions are specific, and teams can use the generated estimates and deployment artifacts to understand the resulting footprint.",
      "useCases": [
        "size and deploy a supported SAP environment",
        "plan an SQL Server deployment on EC2",
        "generate an estimate and reusable deployment template"
      ],
      "concepts": [
        "application scenario drives required inputs",
        "sizing recommendations map workload needs to AWS resources",
        "CloudFormation templates represent deployment resources",
        "deployment estimates expose projected infrastructure costs"
      ],
      "considerations": [
        "only documented application scenarios are supported",
        "review generated architecture, licensing, and operational ownership before deployment"
      ],
      "docs": "https://docs.aws.amazon.com/launchwizard/",
      "sources": [
        {
          "title": "What is AWS Launch Wizard?",
          "url": "https://docs.aws.amazon.com/launchwizard/"
        },
        {
          "title": "Supported applications in AWS Launch Wizard",
          "url": "https://docs.aws.amazon.com/launchwizard/latest/userguide/how-launch-wizard-sap-works.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "lex",
      "name": "Amazon Lex",
      "shortName": "Lex",
      "category": "ai",
      "summary": "Builds conversational interfaces using speech or text with intent recognition and dialog management.",
      "details": "A bot uses intents, sample utterances, slots, and fulfillment logic to turn user input into structured interactions. It can connect to channels and invoke Lambda for custom fulfillment when configured.",
      "useCases": [
        "self-service appointment booking",
        "voice-enabled contact center menus",
        "conversational order lookup"
      ],
      "concepts": [
        "intents",
        "slots",
        "session state",
        "fulfillment"
      ],
      "considerations": [
        "Design utterances and fallback paths for ambiguity",
        "Lambda fulfillment is an optional integration that needs its own permissions."
      ],
      "docs": "https://docs.aws.amazon.com/lexv2/latest/dg/what-is.html",
      "sources": [
        {
          "title": "Amazon Lex documentation",
          "url": "https://docs.aws.amazon.com/lexv2/latest/dg/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "license-manager",
      "name": "AWS License Manager",
      "shortName": "License Manager",
      "category": "management",
      "summary": "Tracks software licenses and helps apply license controls.",
      "details": "License Manager discovers supported license usage and manages configurations for selected commercial software and AWS license-included scenarios. Rules can help constrain launches, but customers remain responsible for licensing obligations and vendor terms.",
      "useCases": [
        "Track BYOL usage on EC2",
        "Apply license configurations to launches",
        "Inventory software across accounts"
      ],
      "concepts": [
        "license configurations model license rules",
        "cross-account inventory uses Organizations",
        "integrates with Systems Manager inventory",
        "supports selected products and scenarios"
      ],
      "considerations": [
        "Feature coverage varies by vendor and license metric",
        "Validate legal terms with the software publisher"
      ],
      "docs": "https://docs.aws.amazon.com/license-manager/latest/userguide/license-manager.html",
      "sources": [
        {
          "title": "AWS License Manager documentation",
          "url": "https://docs.aws.amazon.com/license-manager/latest/userguide/license-manager.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "lightsail",
      "name": "Amazon Lightsail",
      "shortName": "Lightsail",
      "category": "compute",
      "summary": "Simplified cloud hosting with bundled virtual servers and related resources.",
      "details": "Lightsail offers instances, containers, managed databases, load balancers, and networking through a simplified experience. It is suited to straightforward workloads and can connect to broader AWS services and VPC resources.",
      "useCases": [
        "Small websites and apps",
        "Development sandboxes",
        "Simple packaged cloud deployments"
      ],
      "concepts": [
        "Bundles and blueprints",
        "Static IPs and DNS zones",
        "Managed databases and load balancers",
        "VPC peering"
      ],
      "considerations": [
        "Bundles constrain configuration compared with direct EC2 choices.",
        "Regional availability and bundle options vary."
      ],
      "docs": "https://docs.aws.amazon.com/lightsail/latest/userguide/what-is-amazon-lightsail.html",
      "sources": [
        {
          "title": "Amazon Lightsail documentation",
          "url": "https://docs.aws.amazon.com/lightsail/latest/userguide/what-is-amazon-lightsail.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "linux",
      "name": "Amazon Linux",
      "shortName": "Linux",
      "category": "compute",
      "summary": "AWS Linux operating-system distributions for AWS workloads.",
      "details": "Amazon Linux provides supported Linux images optimized for AWS, including Amazon Linux 2023 and Amazon Linux 2. Customers can use the images on EC2 and in supported container workflows; it is an operating-system distribution, not a separate managed application runtime.",
      "useCases": [
        "EC2 application hosts",
        "container base images",
        "AWS development environments"
      ],
      "concepts": [
        "Amazon Linux 2023 is the current generation, while Amazon Linux 2 remains a distinct supported image with its own lifecycle.",
        "EC2 users select an Amazon Linux AMI when launching an instance and control its updates after launch.",
        "Amazon Linux container images are available for supported workflows, separate from the EC2 AMI format."
      ],
      "considerations": [
        "Choose a supported release and plan its lifecycle",
        "Package availability and behavior can differ from other distributions"
      ],
      "docs": "https://docs.aws.amazon.com/linux/",
      "sources": [
        {
          "title": "Amazon Linux documentation",
          "url": "https://docs.aws.amazon.com/linux/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "local-zones",
      "name": "AWS Local Zones",
      "shortName": "Local Zones",
      "category": "compute",
      "summary": "Places selected AWS compute and storage closer to dense population centers.",
      "details": "A Local Zone is an extension of a parent Region where customers can place supported resources such as EC2, EBS, and selected networking services. VPC subnets in the Local Zone provide low-latency access while remaining connected to the parent Region.",
      "useCases": [
        "Latency-sensitive applications",
        "Media production and rendering",
        "Local data processing"
      ],
      "concepts": [
        "Parent Region and Zone relationship",
        "VPC subnet placement",
        "Supported service and instance catalog",
        "Inter-zone networking"
      ],
      "considerations": [
        "Supported services and capacity differ by Local Zone.",
        "Some operations and services remain Region based."
      ],
      "docs": "https://docs.aws.amazon.com/local-zones/latest/ug/what-is-aws-local-zones.html",
      "sources": [
        {
          "title": "AWS Local Zones documentation",
          "url": "https://docs.aws.amazon.com/local-zones/latest/ug/what-is-aws-local-zones.html"
        }
      ],
      "status": "active",
      "kind": "tool"
    },
    {
      "id": "location",
      "name": "Amazon Location Service",
      "shortName": "Location Service",
      "category": "developer",
      "summary": "Location APIs and map resources for adding geospatial features to applications.",
      "details": "Amazon Location Service provides maps, places search, geocoding, routing, tracking, and geofencing capabilities through APIs and SDKs. Data providers and feature availability differ by capability and Region, and applications can combine location resources with their own identity and storage design.",
      "useCases": [
        "address lookup and place search",
        "route planning",
        "asset tracking and geofences"
      ],
      "concepts": [
        "Maps, places, geocoding, routes, trackers, and geofences are separate resource capabilities exposed by APIs.",
        "Tracker positions can be evaluated against geofences to support entry and exit events.",
        "Available map data providers and features vary by Region, so provider choice is part of resource configuration."
      ],
      "considerations": [
        "Provider coverage and terms vary by Region and feature",
        "Apply authentication and data-retention controls to location information"
      ],
      "docs": "https://docs.aws.amazon.com/location/",
      "sources": [
        {
          "title": "Amazon Location Service documentation",
          "url": "https://docs.aws.amazon.com/location/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "lookout-equipment",
      "name": "Amazon Lookout for Equipment",
      "shortName": "Lookout for Equipment",
      "category": "ai",
      "summary": "Detects abnormal industrial equipment behavior from sensor histories and incoming measurements.",
      "details": "A customer supplied normal-operation sensor data, trained equipment-specific models, and configured inference schedules to identify anomalies. AWS discontinued support October 7, 2026, so this entry is for existing-workload and migration context.",
      "useCases": [
        "identify compressor behavior changes",
        "prioritize generator inspection",
        "alert on abnormal production-line sensors"
      ],
      "concepts": [
        "sensor data",
        "equipment models",
        "inference schedulers",
        "anomaly feedback"
      ],
      "considerations": [
        "Support ends October 7, 2026",
        "plan migration and validate alerts against labeled operational events."
      ],
      "docs": "https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/what-is.html",
      "sources": [
        {
          "title": "Amazon Lookout for Equipment documentation",
          "url": "https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/what-is.html"
        },
        {
          "title": "Amazon Lookout for Equipment end-of-support notice",
          "url": "https://docs.aws.amazon.com/lookout-for-equipment/latest/ug/amazon-lookout-for-equipment-ug.pdf"
        }
      ],
      "status": "retired",
      "statusNote": "AWS discontinued support October 7, 2026; access to the console and resources ended after that date.",
      "kind": "service"
    },
    {
      "id": "lookout-metrics",
      "name": "Amazon Lookout for Metrics",
      "shortName": "Lookout for Metrics",
      "category": "ai",
      "summary": "Finds anomalies and contributing factors in time-series business metrics.",
      "details": "It analyzed a configured dataset and metric dimensions, then surfaced unusual movements and root-cause candidates. AWS ended support on October 10, 2025, so this is a retired service entry for migration context.",
      "useCases": [
        "detect an unexpected conversion-rate drop",
        "monitor shipment delays",
        "identify unusual subscription cancellations"
      ],
      "concepts": [
        "metrics",
        "dimensions",
        "anomaly detectors",
        "root causes"
      ],
      "considerations": [
        "Validate findings against business context and seasonality",
        "confirm current support status before adopting."
      ],
      "docs": "https://docs.aws.amazon.com/general/latest/gr/full_shutdown_services.html",
      "sources": [
        {
          "title": "AWS General Reference: services in full shutdown",
          "url": "https://docs.aws.amazon.com/general/latest/gr/full_shutdown_services.html"
        }
      ],
      "status": "retired",
      "statusNote": "AWS ended support for Amazon Lookout for Metrics on October 10, 2025.",
      "kind": "service"
    },
    {
      "id": "lookout-vision",
      "name": "Amazon Lookout for Vision",
      "shortName": "Lookout for Vision",
      "category": "ai",
      "summary": "Detects visual defects by learning normal and anomalous patterns in images.",
      "details": "Teams trained image-based models with normal and, where available, anomalous examples, then ran image predictions. AWS ended support on October 31, 2025; use this entry to understand existing workloads and migration context.",
      "useCases": [
        "inspect manufactured components",
        "flag packaging defects",
        "compare product images to learned normal appearance"
      ],
      "concepts": [
        "image datasets",
        "projects",
        "models",
        "inference"
      ],
      "considerations": [
        "Lighting, camera setup, and class balance affect results",
        "confirm current availability and migration guidance."
      ],
      "docs": "https://docs.aws.amazon.com/general/latest/gr/full_shutdown_services.html",
      "sources": [
        {
          "title": "AWS General Reference: services in full shutdown",
          "url": "https://docs.aws.amazon.com/general/latest/gr/full_shutdown_services.html"
        }
      ],
      "status": "retired",
      "statusNote": "AWS ended support for Amazon Lookout for Vision on October 31, 2025.",
      "kind": "service"
    },
    {
      "id": "machine-learning",
      "name": "Amazon Machine Learning",
      "shortName": "Machine Learning",
      "category": "ai",
      "summary": "Legacy managed service for building predictive models from tabular data.",
      "details": "Amazon Machine Learning provided model creation and prediction APIs for classification and regression. AWS documentation states it is no longer updated and no longer accepts new users, so this entry is for existing workloads and historical context; new ML work should use current SageMaker capabilities.",
      "useCases": [
        "maintaining existing prediction integrations",
        "understanding legacy model workflows",
        "planning migration from older ML APIs"
      ],
      "concepts": [
        "The legacy service exposed model creation and prediction APIs for classification and regression.",
        "Its documentation remains available to existing users, but AWS no longer updates the service or accepts new users.",
        "AWS directs new machine-learning projects to SageMaker AI; this is a successor choice for new work."
      ],
      "considerations": [
        "No new users and documentation is no longer updated",
        "Plan migration and validate model behavior against a supported alternative"
      ],
      "docs": "https://docs.aws.amazon.com/machine-learning/",
      "sources": [
        {
          "title": "Amazon Machine Learning documentation",
          "url": "https://docs.aws.amazon.com/machine-learning/"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS no longer updates Amazon Machine Learning or accepts new users.",
      "kind": "service"
    },
    {
      "id": "macie",
      "name": "Amazon Macie",
      "shortName": "Macie",
      "category": "security",
      "summary": "Discovers and helps protect sensitive data in Amazon S3.",
      "details": "Macie inventories S3 buckets, evaluates selected security posture signals, and uses managed or custom sensitive-data discovery jobs. Findings identify potentially sensitive data and risky bucket settings for investigation.",
      "useCases": [
        "Find personal data in S3",
        "Audit public or shared buckets",
        "Run targeted classification jobs"
      ],
      "concepts": [
        "managed data identifiers detect common patterns",
        "custom identifiers support organization patterns",
        "discovery jobs can target buckets",
        "findings export to Security Hub or EventBridge"
      ],
      "considerations": [
        "Classification can produce false positives",
        "Scope and schedule jobs to manage data scanning"
      ],
      "docs": "https://docs.aws.amazon.com/macie/latest/user/what-is-macie.html",
      "sources": [
        {
          "title": "Amazon Macie documentation",
          "url": "https://docs.aws.amazon.com/macie/latest/user/what-is-macie.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "mainframe-modernization",
      "name": "AWS Mainframe Modernization",
      "shortName": "Mainframe Modernization",
      "category": "migration",
      "summary": "Tools and managed runtimes for migrating, modernizing, and operating mainframe applications on AWS.",
      "details": "AWS Mainframe Modernization supports refactoring or replatforming paths with runtime environments and migration tooling. AWS Transform for mainframe capabilities are now a distinct modernization route; select tools based on source architecture, target operating model, and required code changes.",
      "useCases": [
        "replatform COBOL workloads to a managed runtime",
        "refactor mainframe applications into distributed services",
        "transfer mainframe datasets for modernization testing"
      ],
      "concepts": [
        "replatforming adapts workloads to a compatible managed runtime",
        "refactoring changes application architecture and code",
        "managed runtime environments provide deployment targets",
        "File Transfer moves data sets to S3 for modernization workflows"
      ],
      "considerations": [
        "tooling and runtime features differ between replatforming and refactoring",
        "validate language, transaction, batch, and data compatibility early"
      ],
      "docs": "https://docs.aws.amazon.com/m2/latest/userguide/what-is-m2.html",
      "sources": [
        {
          "title": "What is AWS Mainframe Modernization?",
          "url": "https://docs.aws.amazon.com/m2/latest/userguide/what-is-m2.html"
        },
        {
          "title": "AWS Mainframe Modernization File Transfer",
          "url": "https://docs.aws.amazon.com/m2/latest/userguide/what-is-filetransfer.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS documentation states the self-managed experience and Managed Runtime Environment experience are no longer open to new customers; existing customers can continue using them.",
      "kind": "service"
    },
    {
      "id": "managed-blockchain",
      "name": "Amazon Managed Blockchain",
      "shortName": "Managed Blockchain",
      "category": "specialist",
      "summary": "Managed blockchain networks using Hyperledger Fabric or Ethereum.",
      "details": "Members create or join a network while AWS provisions its peer nodes and components. Applications still define transaction logic, identity, endorsement, and governance.",
      "useCases": [
        "consortium ledger",
        "auditable intercompany records",
        "tokenized application prototype"
      ],
      "concepts": [
        "Members operate peer nodes that validate transactions",
        "Fabric channels and Ethereum networks have different participation models",
        "Managed provisioning does not decide consortium governance"
      ],
      "considerations": [
        "Network participants must agree on membership and transaction rules",
        "Provisioned nodes and network choices affect recurring cost."
      ],
      "docs": "https://docs.aws.amazon.com/managed-blockchain/",
      "sources": [
        {
          "title": "Amazon Managed Blockchain documentation",
          "url": "https://docs.aws.amazon.com/managed-blockchain/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "managed-blockchain-query",
      "name": "Amazon Managed Blockchain Query",
      "shortName": "Managed Blockchain Query",
      "category": "specialist",
      "summary": "Amazon Managed Blockchain Query provides API access to indexed, normalized data from supported public blockchains. It returns blockchain history and token or transaction information without requiring customers to operate indexing infrastructure.",
      "details": "Applications call Query operations to retrieve real-time and historical blockchain data for supported networks. AWS has announced an end to Managed Blockchain support on September 29, 2027, with new customer onboarding scheduled to stop October 29, 2026.",
      "useCases": [
        "wallet transaction history",
        "token and contract data lookups",
        "blockchain analytics over indexed results"
      ],
      "concepts": [
        "Query returns normalized data through developer-oriented API operations",
        "Supported networks and operations determine available data",
        "Query is distinct from Managed Blockchain Access nodes and network participation"
      ],
      "considerations": [
        "AWS will stop accepting new customers on October 29, 2026 and end service support on September 29, 2027",
        "Applications should plan migration because replacement providers may differ in fields, pagination, and query behavior."
      ],
      "docs": "https://docs.aws.amazon.com/managed-blockchain/latest/ambq-dg/what-is-service.html",
      "sources": [
        {
          "title": "What is Amazon Managed Blockchain Query?",
          "url": "https://docs.aws.amazon.com/managed-blockchain/latest/ambq-dg/what-is-service.html"
        },
        {
          "title": "Amazon Managed Blockchain end of support",
          "url": "https://docs.aws.amazon.com/managed-blockchain/latest/hyperledger-fabric-dev/managed-blockchain-end-of-support.html"
        }
      ],
      "status": "active",
      "statusNote": "Active on 2026-10-08; AWS will stop accepting new customers on 2026-10-29 and end support on 2027-09-29.",
      "kind": "service"
    },
    {
      "id": "managed-flink",
      "name": "Amazon Managed Service for Apache Flink",
      "shortName": "Managed Flink",
      "category": "analytics",
      "summary": "Runs continuously processing applications with Apache Flink on managed infrastructure.",
      "details": "Applications consume streaming sources, maintain state, and emit results to configured destinations. AWS manages the service environment while customers own application logic and checkpoint design.",
      "useCases": [
        "compute rolling transaction metrics",
        "enrich events from streams",
        "detect live operational patterns"
      ],
      "concepts": [
        "Flink applications",
        "state",
        "checkpoints",
        "connectors"
      ],
      "considerations": [
        "State size and checkpoint behavior influence recovery and cost",
        "validate connector compatibility and exactly-once semantics for the full pipeline."
      ],
      "docs": "https://docs.aws.amazon.com/managed-flink/latest/java/what-is.html",
      "sources": [
        {
          "title": "Amazon Managed Service for Apache Flink documentation",
          "url": "https://docs.aws.amazon.com/managed-flink/latest/java/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "grafana",
      "name": "Amazon Managed Grafana",
      "shortName": "Managed Grafana",
      "category": "management",
      "summary": "A managed Grafana service for querying, correlating, and visualizing operational data from multiple sources.",
      "details": "A workspace provides a managed Grafana environment with identity, access control, and configured data sources. It can query AWS sources such as CloudWatch, X-Ray, and Managed Service for Prometheus as well as supported external data sources.",
      "useCases": [
        "build a shared operations dashboard across metrics sources",
        "visualize Prometheus metrics alongside CloudWatch data",
        "give teams role-controlled access to dashboards"
      ],
      "concepts": [
        "workspaces isolate Grafana environments",
        "data sources connect dashboards to metrics, logs, or traces",
        "IAM Identity Center and SAML can authenticate workspace users",
        "AWS data source configuration can simplify access setup"
      ],
      "considerations": [
        "workspace permissions and data-source roles both affect visibility",
        "pricing is based on active users and data source costs remain separate"
      ],
      "docs": "https://docs.aws.amazon.com/grafana/latest/userguide/what-is-Amazon-Managed-Service-Grafana.html",
      "sources": [
        {
          "title": "What is Amazon Managed Grafana?",
          "url": "https://docs.aws.amazon.com/grafana/latest/userguide/what-is-Amazon-Managed-Service-Grafana.html"
        },
        {
          "title": "Connect Managed Grafana to Managed Prometheus",
          "url": "https://docs.aws.amazon.com/grafana/latest/userguide/amazon-prometheus-data-source.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "prometheus",
      "name": "Amazon Managed Service for Prometheus",
      "shortName": "Managed Prometheus",
      "category": "management",
      "summary": "A serverless Prometheus-compatible service for storing, querying, and alerting on container metrics.",
      "details": "Prometheus-compatible agents or collectors send metrics to workspaces, where users query them with PromQL and manage alerting rules. Workspaces scale ingestion and queries, and can feed Grafana dashboards; EKS and self-managed Kubernetes are documented collection environments.",
      "useCases": [
        "monitor EKS or Kubernetes workloads with PromQL",
        "centralize metrics from multiple clusters",
        "alert on service-level metrics and resource saturation"
      ],
      "concepts": [
        "workspaces hold time-series metrics",
        "PromQL queries filter and aggregate series",
        "remote write sends scraped samples to the service",
        "Alertmanager handles alert routing and grouping"
      ],
      "considerations": [
        "cardinality and scrape choices affect ingestion cost",
        "retention, quotas, IAM authorization, and cross-service KMS access need planning"
      ],
      "docs": "https://docs.aws.amazon.com/prometheus/latest/userguide/what-is-Amazon-Managed-Service-Prometheus.html",
      "sources": [
        {
          "title": "What is Amazon Managed Service for Prometheus?",
          "url": "https://docs.aws.amazon.com/prometheus/latest/userguide/what-is-Amazon-Managed-Service-Prometheus.html"
        },
        {
          "title": "Amazon Managed Grafana Prometheus data source",
          "url": "https://docs.aws.amazon.com/grafana/latest/userguide/amazon-prometheus-data-source.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "managedservices",
      "name": "AWS Managed Services",
      "shortName": "Managed Services",
      "category": "business",
      "summary": "AWS infrastructure operations under a defined managed-service model.",
      "details": "AWS Managed Services provides operational processes such as change, incident, and security management. Coverage and controls depend on plan and landing-zone arrangement; it does not own every application task.",
      "useCases": [
        "managed cloud operations",
        "standardized change processes",
        "operations for regulated workloads"
      ],
      "concepts": [
        "A managed landing zone establishes account conventions",
        "Change and incident processes govern covered infrastructure",
        "Automation supports repeatable operations"
      ],
      "considerations": [
        "Scope and supported services vary by plan",
        "Application owners retain responsibility for workload behavior."
      ],
      "docs": "https://docs.aws.amazon.com/managedservices/",
      "sources": [
        {
          "title": "AWS Managed Services documentation",
          "url": "https://docs.aws.amazon.com/managedservices/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "awsconsolehelpdocs",
      "name": "AWS Management Console",
      "shortName": "Management Console",
      "category": "management",
      "summary": "Browser-based interface for accessing and managing AWS services and account settings.",
      "details": "The console organizes service-specific consoles behind a common account and Region selector, with search, notifications, CloudShell, and account tools. Console access is governed by the signed-in identity and its IAM permissions, including any organization-level restrictions.",
      "useCases": [
        "inspect resources and service health",
        "configure an AWS service through its console",
        "review billing, security, and account settings"
      ],
      "concepts": [
        "console sign-in uses root or IAM Identity Center/IAM identities",
        "console sessions can use MFA and session controls",
        "CloudShell offers browser-based command-line access"
      ],
      "considerations": [
        "console features and navigation differ by service and Region",
        "least-privilege IAM policies and MFA are essential for console identities"
      ],
      "docs": "https://docs.aws.amazon.com/awsconsolehelpdocs/latest/gsg/what-is.html",
      "sources": [
        {
          "title": "What is the AWS Management Console?",
          "url": "https://docs.aws.amazon.com/awsconsolehelpdocs/latest/gsg/what-is.html"
        },
        {
          "title": "Signing in to the AWS Management Console",
          "url": "https://docs.aws.amazon.com/signin/latest/userguide/console-sign-in-tutorials.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "marketplace",
      "name": "AWS Marketplace",
      "shortName": "Marketplace",
      "category": "business",
      "summary": "Catalog and commerce channel for third-party software and data products.",
      "details": "AWS Marketplace supports public listings and private offers with AWS account procurement and entitlement workflows. Product operation, licensing, and support remain governed by seller terms and implementation.",
      "useCases": [
        "procure cloud software",
        "publish SaaS offers",
        "subscribe to data products"
      ],
      "concepts": [
        "Listings describe product terms and pricing",
        "Private offers customize buyer terms",
        "Entitlements record subscribed access"
      ],
      "considerations": [
        "Quality, support, and license obligations vary by seller",
        "Some products deploy resources and incur separate AWS usage charges."
      ],
      "docs": "https://docs.aws.amazon.com/marketplace/",
      "sources": [
        {
          "title": "AWS Marketplace documentation",
          "url": "https://docs.aws.amazon.com/marketplace/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "memorydb",
      "name": "Amazon MemoryDB",
      "shortName": "MemoryDB",
      "category": "database",
      "summary": "Durable in-memory database with Redis OSS compatibility for low-latency applications.",
      "details": "MemoryDB is designed to retain data durably across failures while serving in-memory access patterns. It can serve as a primary database for suitable workloads, not simply a disposable cache.",
      "useCases": [
        "low-latency leaderboards",
        "durable session state",
        "real-time application data"
      ],
      "concepts": [
        "Redis OSS compatibility",
        "multi-AZ durability",
        "clusters",
        "snapshots"
      ],
      "considerations": [
        "Validate command compatibility and memory sizing",
        "durability does not remove the need for backup and recovery planning."
      ],
      "docs": "https://docs.aws.amazon.com/memorydb/latest/devguide/what-is-memorydb.html",
      "sources": [
        {
          "title": "Amazon MemoryDB documentation",
          "url": "https://docs.aws.amazon.com/memorydb/latest/devguide/what-is-memorydb.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "microservice-extractor",
      "name": "AWS Microservice Extractor for .NET",
      "shortName": "Microservice Extractor for .NET",
      "category": "developer",
      "summary": "Assessment and refactoring tool for decomposing monolithic .NET applications.",
      "details": "AWS Microservice Extractor for .NET analyzes application dependencies and helps identify candidate service boundaries, then supports extracting code into microservices. It is a developer tool rather than a hosted runtime, and extracted components need engineering work to become independently deployable services. AWS states that the .NET modernization tools are no longer open to new customers and points to AWS Transform for .NET as an alternative.",
      "useCases": [
        "mapping .NET monolith dependencies",
        "planning service boundaries",
        "accelerating staged modernization"
      ],
      "concepts": [
        "Static analysis maps dependencies between application components to help identify extraction candidates.",
        "Runtime profiling can add observed call information to the dependency view when configured.",
        "The tool can generate an extracted service and communication code, but the resulting service still requires build and deployment work."
      ],
      "considerations": [
        "Automated boundary suggestions need domain review",
        "Confirm supported .NET versions and maintenance status before adoption"
      ],
      "docs": "https://docs.aws.amazon.com/microservice-extractor/",
      "sources": [
        {
          "title": "AWS Microservice Extractor for .NET documentation",
          "url": "https://docs.aws.amazon.com/microservice-extractor/"
        },
        {
          "title": "AWS .NET modernization tool availability",
          "url": "https://docs.aws.amazon.com/microservice-extractor/latest/userguide/"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS .NET modernization tools are no longer open to new customers; AWS names Transform for .NET as the alternative.",
      "kind": "service"
    },
    {
      "id": "migration-hub",
      "name": "AWS Migration Hub",
      "shortName": "Migration Hub",
      "category": "migration",
      "summary": "Tracks application discovery and migration progress in one place.",
      "details": "Migration Hub groups servers into applications and provides a view of migration status reported by connected tools. It stopped accepting new customers on November 7, 2025; existing migration projects can continue, while AWS Transform is the recommended option for new work.",
      "useCases": [
        "Track server migration waves",
        "View application migration status",
        "Coordinate ongoing MGN or DMS migrations"
      ],
      "concepts": [
        "home Region stores tracking data",
        "tools perform migration outside the hub",
        "server grouping associates resources to applications",
        "existing customers may finish active projects"
      ],
      "considerations": [
        "Restricted to existing customers since 2025-11-07",
        "Use AWS Transform for new migration programs"
      ],
      "docs": "https://docs.aws.amazon.com/migrationhub/latest/ug/whatishub.html",
      "sources": [
        {
          "title": "AWS Migration Hub documentation",
          "url": "https://docs.aws.amazon.com/migrationhub/latest/ug/whatishub.html"
        },
        {
          "title": "AWS lifecycle announcement / guidance",
          "url": "https://docs.aws.amazon.com/migrationhub-strategy/latest/userguide/migrationhub-availability-change.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS stopped accepting new customers on 2025-11-07; AWS Transform is recommended for new work.",
      "kind": "service"
    },
    {
      "id": "monitron",
      "name": "Amazon Monitron",
      "shortName": "Monitron",
      "category": "ai",
      "summary": "Industrial condition-monitoring system using wireless sensors and machine learning.",
      "details": "Amazon Monitron combines vibration and temperature sensors, gateways, and cloud analysis to detect equipment conditions and alert maintenance teams. It is closed to new customers as of 2024-10-31, while existing customers may continue to use it; AWS stopped planning new features.",
      "useCases": [
        "monitoring rotating industrial equipment",
        "predictive maintenance alerts",
        "tracking equipment health by site"
      ],
      "concepts": [
        "Wireless vibration and temperature sensors send equipment readings through gateways for cloud analysis.",
        "The service used machine-learning condition monitoring to detect abnormal equipment behavior and alert maintenance teams.",
        "Monitron closed to new customers on October 31, 2024; existing customers may continue under the published lifecycle terms."
      ],
      "considerations": [
        "Existing-customer-only service; confirm hardware supply and support terms",
        "Plan an alternative before making it a dependency for new sites"
      ],
      "docs": "https://docs.aws.amazon.com/Monitron/",
      "sources": [
        {
          "title": "Amazon Monitron documentation",
          "url": "https://docs.aws.amazon.com/Monitron/"
        },
        {
          "title": "Amazon Monitron service details",
          "url": "https://docs.aws.amazon.com/Monitron/latest/user-guide/what-is-monitron.html"
        }
      ],
      "status": "restricted",
      "statusNote": "Closed to new customers since 2024-10-31; existing customers can continue.",
      "kind": "service"
    },
    {
      "id": "msk",
      "name": "Amazon Managed Streaming for Apache Kafka",
      "shortName": "MSK",
      "category": "analytics",
      "summary": "Managed Apache Kafka clusters and serverless Kafka for event streaming.",
      "details": "Applications use Kafka APIs while AWS manages broker or serverless infrastructure. Connectors and integrations can bridge Kafka topics to other systems when configured.",
      "useCases": [
        "event backbone for microservices",
        "stream CDC records",
        "centralize multi-team event topics"
      ],
      "concepts": [
        "clusters",
        "topics",
        "brokers",
        "MSK Serverless"
      ],
      "considerations": [
        "Kafka operations still require partition, retention, and consumer planning",
        "client compatibility and networking matter."
      ],
      "docs": "https://docs.aws.amazon.com/msk/latest/developerguide/what-is-msk.html",
      "sources": [
        {
          "title": "Amazon Managed Streaming for Apache Kafka documentation",
          "url": "https://docs.aws.amazon.com/msk/latest/developerguide/what-is-msk.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "mwaa",
      "name": "Amazon MWAA",
      "shortName": "MWAA",
      "category": "integration",
      "summary": "Managed Apache Airflow environments for orchestrating data workflows on AWS.",
      "details": "Amazon MWAA provisions managed Apache Airflow environments, including schedulers, workers, and web servers, while customers author DAGs and plugins. It can coordinate AWS services through operators and hooks; the environment runs in a customer VPC and has sizing and networking requirements.",
      "useCases": [
        "scheduled ETL orchestration",
        "dependency-managed data workflows",
        "Airflow-based operational jobs"
      ],
      "concepts": [
        "An environment includes managed Airflow schedulers, workers, and a web server; customers provide DAG code.",
        "The required DAG bucket uses versioning and a DAG folder, while plugins and Python requirements are optional additions.",
        "The environment is deployed into a customer VPC, so subnet sizing and outbound access affect Airflow component health."
      ],
      "considerations": [
        "Environment capacity and Airflow version affect cost and compatibility",
        "Private networking, plugins, and dependencies need planning"
      ],
      "docs": "https://docs.aws.amazon.com/mwaa/",
      "sources": [
        {
          "title": "Amazon MWAA documentation",
          "url": "https://docs.aws.amazon.com/mwaa/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "neptune",
      "name": "Amazon Neptune",
      "shortName": "Neptune",
      "category": "database",
      "summary": "Managed graph database for querying connected data with graph models and APIs.",
      "details": "Neptune supports property graph and RDF graph approaches through distinct query languages and interfaces. Choose the graph model based on relationship traversal and semantic query requirements.",
      "useCases": [
        "fraud relationship analysis",
        "knowledge graphs",
        "social graph traversals"
      ],
      "concepts": [
        "property graph",
        "RDF",
        "Gremlin",
        "openCypher",
        "SPARQL"
      ],
      "considerations": [
        "Graph modeling and query patterns strongly affect performance",
        "confirm engine and query-language compatibility."
      ],
      "docs": "https://docs.aws.amazon.com/neptune/latest/userguide/intro.html",
      "sources": [
        {
          "title": "Amazon Neptune documentation",
          "url": "https://docs.aws.amazon.com/neptune/latest/userguide/intro.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "network-firewall",
      "name": "AWS Network Firewall",
      "shortName": "Network Firewall",
      "category": "network",
      "summary": "Managed network firewall for VPC traffic inspection and filtering.",
      "details": "AWS Network Firewall deploys stateful and stateless rule groups into firewall endpoints associated with VPC subnets. Route tables steer selected traffic through those endpoints for inspection.",
      "useCases": [
        "VPC perimeter inspection",
        "Centralized egress filtering",
        "Threat-signature and protocol rules"
      ],
      "concepts": [
        "Firewall endpoints",
        "Stateless and stateful rule groups",
        "Suricata-compatible rules",
        "Route-table steering"
      ],
      "considerations": [
        "Traffic inspection requires deliberate routing and symmetric-path planning.",
        "It does not automatically inspect traffic that does not traverse its endpoints."
      ],
      "docs": "https://docs.aws.amazon.com/network-firewall/latest/developerguide/what-is-aws-network-firewall.html",
      "sources": [
        {
          "title": "AWS Network Firewall documentation",
          "url": "https://docs.aws.amazon.com/network-firewall/latest/developerguide/what-is-aws-network-firewall.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "network-security-manager",
      "name": "AWS Network Security Manager",
      "shortName": "Network Security Manager",
      "category": "security",
      "summary": "Centrally defines and deploys network security protections across organizational AWS accounts.",
      "details": "Teams create reusable rules and templates, assemble them into policies, select accounts and resources through scopes, and deploy consistent protections. AWS documents support for protections including AWS WAF and AWS Shield Advanced; the service manages policy rollout rather than replacing those enforcement services.",
      "useCases": [
        "apply a baseline WAF policy across accounts",
        "standardize Shield Advanced protections for selected resources",
        "roll out network security policy changes centrally"
      ],
      "concepts": [
        "rules and templates encode reusable protection settings",
        "policies bundle rules for deployment",
        "scopes select accounts and target resources",
        "deployments apply and track policy rollout"
      ],
      "considerations": [
        "confirm the supported protection types and resource scope before adoption",
        "permissions and organization structure determine which accounts can be managed"
      ],
      "docs": "https://docs.aws.amazon.com/network-security-manager/latest/devguide/concepts.html",
      "sources": [
        {
          "title": "AWS Network Security Manager Developer Guide",
          "url": "https://docs.aws.amazon.com/network-security-manager/"
        },
        {
          "title": "How AWS Network Security Manager works",
          "url": "https://docs.aws.amazon.com/network-security-manager/latest/devguide/concepts.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "nova",
      "name": "Amazon Nova",
      "shortName": "Nova",
      "category": "ai",
      "summary": "Family of Amazon foundation models available through Amazon Bedrock.",
      "details": "Amazon Nova includes text, multimodal, speech, image, video, and embedding models for use through Bedrock APIs and related capabilities. Nova is a model family, not a separately provisioned inference service; model IDs, APIs, pricing, and Region availability vary by model.",
      "useCases": [
        "multimodal document analysis",
        "text generation and summarization",
        "speech and media generation"
      ],
      "concepts": [
        "Nova is a model family that includes text, multimodal, speech, image, video, and embedding models.",
        "Applications invoke available Nova models through Amazon Bedrock APIs.",
        "Model identifiers, supported modalities, pricing, and Regions differ across the family."
      ],
      "considerations": [
        "Choose a model based on evaluated quality, latency, and cost",
        "Confirm model access, supported API, and Region before deployment"
      ],
      "docs": "https://docs.aws.amazon.com/nova/",
      "sources": [
        {
          "title": "Amazon Nova documentation",
          "url": "https://docs.aws.amazon.com/nova/"
        },
        {
          "title": "Amazon Nova service details",
          "url": "https://docs.aws.amazon.com/nova/latest/userguide/what-is-nova.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "nova-act",
      "name": "Amazon Nova Act",
      "shortName": "Nova Act",
      "category": "ai",
      "summary": "Tools and managed service for building AI agents that automate browser workflows.",
      "details": "Amazon Nova Act supports authoring and deploying workflows that interact with web interfaces, with local development tools and an AWS service for workflow execution and monitoring. It is suited to constrained UI tasks; websites change, so agents need evaluation, bounded permissions, and operational review.",
      "useCases": [
        "automating repetitive browser tasks",
        "web form workflows",
        "managed fleets of UI automation runs"
      ],
      "concepts": [
        "Nova Act workflows are authored with development tools and can be deployed to the managed service for execution.",
        "The agent interacts with web pages through browser actions, so workflows depend on the current page structure and site behavior.",
        "Task boundaries, evaluation, and permissions should be set for the specific web workflow being automated."
      ],
      "considerations": [
        "UI automation can make unintended changes; constrain targets and actions",
        "Playground, API-key, and AWS IAM usage follow different terms and access paths"
      ],
      "docs": "https://docs.aws.amazon.com/nova-act/",
      "sources": [
        {
          "title": "Amazon Nova Act documentation",
          "url": "https://docs.aws.amazon.com/nova-act/"
        },
        {
          "title": "Amazon Nova Act service details",
          "url": "https://docs.aws.amazon.com/nova-act/latest/userguide/getting-started.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "opensearch",
      "name": "Amazon OpenSearch Service",
      "shortName": "OpenSearch Service",
      "category": "analytics",
      "summary": "Managed OpenSearch clusters and serverless collections for search and analytics.",
      "details": "It supports indexing, full-text search, log analytics, and vector search patterns through managed domains or Serverless collections. Data ingestion and access controls are configured separately.",
      "useCases": [
        "search application catalog",
        "explore operational logs",
        "retrieve vector-similar content"
      ],
      "concepts": [
        "domains",
        "collections",
        "indexes",
        "ingestion pipelines"
      ],
      "considerations": [
        "Capacity, shard design, and index lifecycle affect cost and latency",
        "choose OpenSearch versions and features deliberately."
      ],
      "docs": "https://docs.aws.amazon.com/opensearch-service/latest/developerguide/what-is.html",
      "sources": [
        {
          "title": "Amazon OpenSearch Service documentation",
          "url": "https://docs.aws.amazon.com/opensearch-service/latest/developerguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "oracle-database",
      "name": "Oracle Database@AWS",
      "shortName": "Oracle Database@AWS",
      "category": "database",
      "summary": "Oracle Exadata Database Service hosted in AWS data centers through a joint AWS-Oracle offering.",
      "details": "Oracle Database@AWS provides access to Oracle-managed Exadata infrastructure colocated with AWS Regions and integrates with selected AWS services and networking. Oracle operates the database infrastructure under Oracle terms while AWS provides the surrounding cloud integration; availability is limited to announced Regions and configurations.",
      "useCases": [
        "Oracle database migration with low-latency AWS integration",
        "Exadata database workloads",
        "connecting Oracle databases to AWS applications"
      ],
      "concepts": [
        "Oracle Database@AWS provides Oracle Exadata Database Service in AWS Regions through a joint offering.",
        "Oracle operates the database infrastructure while AWS supplies the surrounding network and service integration.",
        "Availability is limited to announced Regions and configurations, and Oracle terms govern database operations."
      ],
      "considerations": [
        "Review both Oracle and AWS contracts, support boundaries, and pricing",
        "Region, capacity, and feature availability may be limited"
      ],
      "docs": "https://docs.aws.amazon.com/odb/",
      "sources": [
        {
          "title": "Oracle Database@AWS documentation",
          "url": "https://docs.aws.amazon.com/odb/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "organizations",
      "name": "AWS Organizations",
      "shortName": "Organizations",
      "category": "management",
      "summary": "Groups AWS accounts and applies organization-wide governance.",
      "details": "Organizations supports account hierarchy, consolidated billing, and policy-based controls. Service control policies limit maximum available permissions rather than granting permissions; delegated administrators operate supported services across member accounts.",
      "useCases": [
        "Organize accounts by environment or business unit",
        "Apply organization-wide service guardrails",
        "Manage accounts centrally"
      ],
      "concepts": [
        "roots, OUs, and accounts form hierarchy",
        "SCPs set permission boundaries",
        "consolidated billing aggregates usage",
        "delegated admin is service-specific"
      ],
      "considerations": [
        "SCPs do not grant IAM permissions",
        "Plan account ownership and recovery access"
      ],
      "docs": "https://docs.aws.amazon.com/organizations/latest/userguide/orgs_introduction.html",
      "sources": [
        {
          "title": "AWS Organizations documentation",
          "url": "https://docs.aws.amazon.com/organizations/latest/userguide/orgs_introduction.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "outposts",
      "name": "AWS Outposts",
      "shortName": "Outposts",
      "category": "compute",
      "summary": "Extends selected AWS infrastructure and services into a customer site.",
      "details": "AWS operates Outposts capacity as part of an AWS Region while customers create local subnets and launch supported resources such as EC2, EBS, ECS, and RDS. Local processing can address latency, data residency, or local data handling requirements.",
      "useCases": [
        "Local low-latency workloads",
        "On-premises data processing",
        "Consistent hybrid deployment patterns"
      ],
      "concepts": [
        "Outpost capacity pools",
        "Outpost subnets in a VPC",
        "Local gateway and service link",
        "Supported services by Outpost type"
      ],
      "considerations": [
        "An Outpost depends on connectivity to its parent Region for service-link operations.",
        "Service availability varies with Outpost configuration and Region."
      ],
      "docs": "https://docs.aws.amazon.com/outposts/latest/userguide/what-is-outposts.html",
      "sources": [
        {
          "title": "AWS Outposts documentation",
          "url": "https://docs.aws.amazon.com/outposts/latest/userguide/what-is-outposts.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "panorama",
      "name": "AWS Panorama",
      "shortName": "Panorama",
      "category": "ai",
      "summary": "Former edge computer-vision service for deploying ML applications to Panorama devices.",
      "details": "AWS Panorama combined appliance hardware, camera ingestion, and cloud management for computer-vision applications at the edge. AWS ended support on 2026-05-31, so it is retired as of this catalog date; its devices and applications no longer function through the discontinued service.",
      "useCases": [
        "historical edge-vision deployments",
        "reviewing migration plans",
        "understanding prior Panorama architectures"
      ],
      "concepts": [
        "Panorama combined edge appliances with camera streams and cloud tools for computer-vision deployment.",
        "Applications ran inference near cameras on the appliance rather than sending every frame to a cloud endpoint.",
        "AWS ended Panorama support on May 31, 2026, so the service and its devices are retired as of this catalog date."
      ],
      "considerations": [
        "Service is retired; do not plan new deployments",
        "AWS recommends migrating to alternatives such as IoT Greengrass and customer-managed edge compute"
      ],
      "docs": "https://docs.aws.amazon.com/panorama/",
      "sources": [
        {
          "title": "AWS Panorama documentation",
          "url": "https://docs.aws.amazon.com/panorama/"
        },
        {
          "title": "AWS Panorama service details",
          "url": "https://docs.aws.amazon.com/panorama/latest/dev/panorama-end-of-support.html"
        }
      ],
      "status": "retired",
      "statusNote": "AWS ended support on 2026-05-31; Panorama devices and applications no longer function.",
      "kind": "service"
    },
    {
      "id": "parallelcluster",
      "name": "AWS ParallelCluster",
      "shortName": "ParallelCluster",
      "category": "compute",
      "summary": "Open-source cluster management tool for HPC clusters on AWS.",
      "details": "AWS ParallelCluster provisions HPC clusters using a configuration file, commonly with a scheduler such as Slurm. It orchestrates AWS resources including EC2 compute, storage, networking, and shared filesystems; it is software customers operate rather than a managed HPC service.",
      "useCases": [
        "HPC simulations",
        "Research clusters",
        "Elastic burst capacity for existing HPC workflows"
      ],
      "concepts": [
        "Cluster configuration",
        "Schedulers and queues",
        "EC2 and storage resources",
        "Shared filesystems"
      ],
      "considerations": [
        "Customers maintain cluster configuration and software environments.",
        "ParallelCluster versions and supported schedulers should be checked against the docs."
      ],
      "docs": "https://docs.aws.amazon.com/parallelcluster/latest/ug/what-is-aws-parallelcluster.html",
      "sources": [
        {
          "title": "AWS ParallelCluster documentation",
          "url": "https://docs.aws.amazon.com/parallelcluster/latest/ug/what-is-aws-parallelcluster.html"
        }
      ],
      "status": "active",
      "kind": "tool"
    },
    {
      "id": "partner-central",
      "name": "AWS Partner Central",
      "shortName": "Partner Central",
      "category": "business",
      "summary": "AWS Partner Network portal for membership, opportunities, and program resources.",
      "details": "Partner Central provides partner workflows for account management, co-selling, training, and program benefits. It is a business portal rather than a service for hosting customer applications.",
      "useCases": [
        "manage partner profiles",
        "track co-sell opportunities",
        "access partner programs"
      ],
      "concepts": [
        "Partner accounts organize membership and users",
        "Opportunity workflows support AWS collaboration",
        "Program benefits depend on tier and validation"
      ],
      "considerations": [
        "Access requires an eligible partner account and roles",
        "Program criteria and portal workflows can change."
      ],
      "docs": "https://docs.aws.amazon.com/partner-central/",
      "sources": [
        {
          "title": "AWS Partner Central documentation",
          "url": "https://docs.aws.amazon.com/partner-central/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "payment-cryptography",
      "name": "AWS Payment Cryptography",
      "shortName": "Payment Cryptography",
      "category": "security",
      "summary": "Managed payment cryptography operations and key management aligned to payment industry standards.",
      "details": "The service provides API operations for payment keys and cryptographic functions used in card authorization, PIN processing, and related payment workflows. It operates within AWS payment security controls and supports payment-specific key types and schemes rather than general-purpose application encryption alone.",
      "useCases": [
        "perform payment cryptograms for authorization flows",
        "manage payment keys for PIN translation workflows",
        "support payment cryptography operations without dedicated HSM operations"
      ],
      "concepts": [
        "payment keys use payment-specific key attributes and usages",
        "cryptographic operations are invoked through service APIs",
        "key import and export workflows follow payment controls",
        "audit and access policy govern sensitive operations"
      ],
      "considerations": [
        "design key ceremonies and permissions to meet applicable payment standards",
        "verify supported algorithms, key usages, and Region availability for the payment network"
      ],
      "docs": "https://docs.aws.amazon.com/payment-cryptography/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "What is AWS Payment Cryptography?",
          "url": "https://docs.aws.amazon.com/payment-cryptography/latest/userguide/what-is.html"
        },
        {
          "title": "AWS Payment Cryptography key concepts",
          "url": "https://docs.aws.amazon.com/payment-cryptography/latest/userguide/cryptographic-details.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "pcs",
      "name": "AWS Parallel Computing Service",
      "shortName": "PCS",
      "category": "compute",
      "summary": "Managed service for creating and operating HPC clusters on AWS.",
      "details": "AWS PCS provides managed cluster control components for HPC scheduling and integrates with Slurm, EC2 compute, networking, and shared storage. Customers create clusters, queues, and compute node groups while managing their scientific software and job workloads.",
      "useCases": [
        "HPC clusters with Slurm",
        "Elastic scientific computing",
        "Managed cluster control plane"
      ],
      "concepts": [
        "Clusters and queues",
        "Slurm scheduler",
        "Compute node groups",
        "Shared storage and VPC"
      ],
      "considerations": [
        "Service availability, supported instance types, and Regions are bounded by current documentation.",
        "Users still install and maintain application software and job environments."
      ],
      "docs": "https://docs.aws.amazon.com/pcs/latest/userguide/what-is-service.html",
      "sources": [
        {
          "title": "AWS Parallel Computing Service documentation",
          "url": "https://docs.aws.amazon.com/pcs/latest/userguide/what-is-service.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "personalize",
      "name": "Amazon Personalize",
      "shortName": "Personalize",
      "category": "ai",
      "summary": "Builds recommendation and user-personalization systems from interaction data.",
      "details": "Teams import interaction and item datasets, train recommenders, and obtain recommendations through campaigns or batch workflows. It is designed for recommendation use cases rather than general-purpose model hosting.",
      "useCases": [
        "rank products for a storefront",
        "recommend videos from viewing history",
        "personalize next-best content"
      ],
      "concepts": [
        "interaction data",
        "recipes",
        "campaigns",
        "batch recommendations"
      ],
      "considerations": [
        "Sparse, biased, or stale interaction history limits results",
        "monitor relevance and privacy expectations."
      ],
      "docs": "https://docs.aws.amazon.com/personalize/latest/dg/what-is-personalize.html",
      "sources": [
        {
          "title": "Amazon Personalize documentation",
          "url": "https://docs.aws.amazon.com/personalize/latest/dg/what-is-personalize.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "pinpoint",
      "name": "Amazon Pinpoint",
      "shortName": "Pinpoint",
      "category": "business",
      "summary": "Legacy engagement service for segments, campaigns, journeys, and analytics; ends October 30, 2026.",
      "details": "Existing accounts may use engagement features until October 30, 2026, but AWS stopped taking new customers May 20, 2025. Messaging APIs moved to AWS End User Messaging; AWS recommends Connect Customer for engagement and Kinesis for event analytics.",
      "useCases": [
        "maintain existing campaigns during transition",
        "inventory segments and journeys",
        "plan analytics and messaging migration"
      ],
      "concepts": [
        "Endpoints and segments define customer audiences",
        "Campaigns and journeys coordinate event-driven messages",
        "Messaging APIs now belong to AWS End User Messaging"
      ],
      "considerations": [
        "New customers cannot sign up and support ends October 30, 2026",
        "Export data and map each feature to its recommended destination."
      ],
      "docs": "https://docs.aws.amazon.com/pinpoint/latest/userguide/migrate.html",
      "sources": [
        {
          "title": "Amazon Pinpoint documentation",
          "url": "https://docs.aws.amazon.com/pinpoint/latest/userguide/migrate.html"
        }
      ],
      "status": "restricted",
      "statusNote": "Restricted to existing customers; AWS ended new-customer access May 20, 2025 and support ends October 30, 2026. Verified 2026-10-08.",
      "kind": "service"
    },
    {
      "id": "polly",
      "name": "Amazon Polly",
      "shortName": "Polly",
      "category": "ai",
      "summary": "Turns text into synthesized speech using selectable voices and speech features.",
      "details": "Applications send text or speech marks to an API and receive audio or synchronized metadata. Voice, language, and synthesis features vary across engines.",
      "useCases": [
        "spoken navigation prompts",
        "narrated accessibility content",
        "dynamic customer notifications"
      ],
      "concepts": [
        "voices",
        "synthesis engines",
        "lexicons",
        "speech marks"
      ],
      "considerations": [
        "Check language and voice support for the selected engine",
        "generated speech should be reviewed for names and specialized terminology."
      ],
      "docs": "https://docs.aws.amazon.com/polly/latest/dg/what-is.html",
      "sources": [
        {
          "title": "Amazon Polly documentation",
          "url": "https://docs.aws.amazon.com/polly/latest/dg/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "portingassistant",
      "name": "Porting Assistant for .NET",
      "shortName": "Porting Assistant for .NET",
      "category": "developer",
      "summary": "Tool that analyzes .NET Framework code and assists porting to modern .NET.",
      "details": "Porting Assistant for .NET scans source projects for compatibility issues and suggests replacements when moving from .NET Framework to .NET. It is a migration aid; compatibility results are advisory and application testing remains necessary.",
      "useCases": [
        "estimating porting effort",
        "updating legacy .NET applications",
        "identifying incompatible APIs"
      ],
      "concepts": [
        "Assessment reports identify incompatible APIs and packages in .NET Framework projects.",
        "Where known, the tool suggests compatible replacements and can update project references during porting.",
        "Porting changes are a starting point; unsupported APIs and build issues can still require manual code changes."
      ],
      "considerations": [
        "Recommendations may require manual changes and regression testing",
        "Check the current tool distribution and supported versions"
      ],
      "docs": "https://docs.aws.amazon.com/portingassistant/",
      "sources": [
        {
          "title": "Porting Assistant for .NET documentation",
          "url": "https://docs.aws.amazon.com/portingassistant/"
        },
        {
          "title": "AWS .NET modernization tool availability",
          "url": "https://docs.aws.amazon.com/portingassistant/latest/userguide/porting-assistant-port.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS .NET modernization tools are no longer open to new customers; AWS names Transform for .NET as the alternative.",
      "kind": "tool"
    },
    {
      "id": "pricing-calculator",
      "name": "AWS Pricing Calculator",
      "shortName": "Pricing Calculator",
      "category": "cost",
      "summary": "Creates scenario-based estimates for AWS architectures before or during deployment.",
      "details": "You add services, configure assumptions such as Region and usage, and organize estimates into groups for comparison and sharing. The result is an estimate based on published pricing inputs rather than a quote or a guarantee of the final bill.",
      "useCases": [
        "estimate a proposed multi-tier application",
        "compare Regions or instance families",
        "share a cost scenario with finance and engineering"
      ],
      "concepts": [
        "service selections build line-item estimates",
        "groups organize components into architecture sections",
        "saved estimates can be exported or shared"
      ],
      "considerations": [
        "actual charges depend on usage, discounts, data transfer, and configuration",
        "revisit estimates when AWS prices or workload assumptions change"
      ],
      "docs": "https://docs.aws.amazon.com/pricing-calculator/latest/userguide/what-is-pricing-calculator.html",
      "sources": [
        {
          "title": "What is AWS Pricing Calculator?",
          "url": "https://docs.aws.amazon.com/pricing-calculator/latest/userguide/what-is-pricing-calculator.html"
        },
        {
          "title": "AWS Pricing Calculator user guide",
          "url": "https://docs.aws.amazon.com/pricing-calculator/latest/userguide/what-is-pricing-calculator.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "private-ca",
      "name": "AWS Private Certificate Authority",
      "shortName": "Private Certificate Authority",
      "category": "security",
      "summary": "Operates private certificate authorities for internal PKI.",
      "details": "Private CA issues X.509 certificates for users, devices, and services under a customer-defined hierarchy. It integrates with ACM for certificate issuance and renewal workflows and supports direct API issuance for custom clients.",
      "useCases": [
        "Issue internal service TLS certificates",
        "Enroll device or workload certificates",
        "Build subordinate CA hierarchy"
      ],
      "concepts": [
        "root and subordinate CAs define trust",
        "ACM can request private certificates",
        "CRL and OCSP can support revocation checking",
        "CA lifecycle and templates govern issuance"
      ],
      "considerations": [
        "Protect CA signing authority and plan revocation",
        "Private trust must be distributed to clients"
      ],
      "docs": "https://docs.aws.amazon.com/privateca/latest/userguide/PcaWelcome.html",
      "sources": [
        {
          "title": "AWS Private Certificate Authority documentation",
          "url": "https://docs.aws.amazon.com/privateca/latest/userguide/PcaWelcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "privatelink",
      "name": "AWS PrivateLink",
      "shortName": "PrivateLink",
      "category": "network",
      "summary": "Private connectivity to supported AWS services and endpoint services.",
      "details": "PrivateLink uses VPC endpoints to access AWS services, partner services, resources, or endpoint services without public IPs or an internet gateway. Endpoint direction is client-initiated, and service providers control allowed principals for endpoint services.",
      "useCases": [
        "Private AWS API access",
        "Private SaaS consumption",
        "Cross-account service exposure"
      ],
      "concepts": [
        "Interface and resource endpoints",
        "Endpoint services",
        "Allowed principals and acceptance",
        "Private DNS"
      ],
      "considerations": [
        "Only supported service integrations can be accessed through managed endpoints.",
        "Interface endpoints have per-AZ and data processing charges."
      ],
      "docs": "https://docs.aws.amazon.com/vpc/latest/privatelink/what-is-privatelink.html",
      "sources": [
        {
          "title": "What is AWS PrivateLink?",
          "url": "https://docs.aws.amazon.com/vpc/latest/privatelink/what-is-privatelink.html"
        },
        {
          "title": "Services integrating with PrivateLink",
          "url": "https://docs.aws.amazon.com/vpc/latest/privatelink/aws-services-privatelink-support.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "professional-services",
      "name": "AWS Professional Services",
      "shortName": "Professional Services",
      "category": "business",
      "summary": "AWS consulting teams that help plan and deliver cloud initiatives.",
      "details": "Engagements provide advisory or implementation assistance for defined business and technical goals. This is a project-based professional service rather than a self-service runtime; deliverables depend on scope.",
      "useCases": [
        "cloud migration planning",
        "data platform implementation",
        "operating-model design"
      ],
      "concepts": [
        "Engagements begin with agreed objectives and scope",
        "Specialists support architecture and modernization work",
        "Knowledge transfer helps customer teams operate outcomes"
      ],
      "considerations": [
        "Availability and terms depend on engagement scope",
        "Customers own production decisions and access."
      ],
      "docs": "https://aws.amazon.com/professional-services/",
      "sources": [
        {
          "title": "AWS Professional Services documentation",
          "url": "https://aws.amazon.com/professional-services/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "proton",
      "name": "AWS Proton",
      "shortName": "Proton",
      "category": "management",
      "summary": "Former platform engineering service for templated delivery of container and serverless infrastructure.",
      "details": "AWS ended Proton support on October 7, 2026; the Proton console and resources are no longer accessible after that date. AWS states that deployed CloudFormation stacks and their resources remain intact, while Proton delivery pipelines and service data require migration or replacement.",
      "useCases": [
        "historically standardize application environments with platform templates",
        "historically provision services from approved infrastructure templates",
        "migrate former Proton delivery workflows to a supported pipeline"
      ],
      "concepts": [
        "environment templates encoded platform infrastructure",
        "service templates let developers provision approved patterns",
        "CloudFormation stacks and Proton delivery management have separate lifecycles"
      ],
      "considerations": [
        "service access and Proton-managed pipeline operations ended October 7, 2026",
        "deployed infrastructure persists but should be adopted into a replacement workflow"
      ],
      "docs": "https://docs.aws.amazon.com/proton/latest/userguide/proton-end-of-support.html",
      "sources": [
        {
          "title": "AWS Proton Service Deprecation and Migration Guide",
          "url": "https://docs.aws.amazon.com/proton/latest/userguide/proton-end-of-support.html"
        },
        {
          "title": "AWS Proton end-of-support notice",
          "url": "https://docs.aws.amazon.com/proton/latest/userguide/Welcome.html"
        }
      ],
      "status": "retired",
      "statusNote": "AWS ended support on October 7, 2026. Proton console/resources are inaccessible after that date; deployed CloudFormation stacks and resources remain intact.",
      "kind": "service"
    },
    {
      "id": "q-business",
      "name": "Amazon Q Business",
      "shortName": "Q Business",
      "category": "ai",
      "summary": "Enterprise assistant that answers questions and performs supported tasks using connected organizational content.",
      "details": "Administrators connect data sources and identity controls; answers can cite retrieved documents and respect configured access. AWS says the service is no longer open to new customers, so this entry describes an existing-customer product.",
      "useCases": [
        "search internal policies with citations",
        "draft answers from approved project documents",
        "summarize connected enterprise content"
      ],
      "concepts": [
        "applications",
        "retrievers",
        "data source connectors",
        "identity-aware access"
      ],
      "considerations": [
        "Existing customers can continue using it, but new customers should evaluate Amazon Quick",
        "connector permissions and indexing freshness affect results."
      ],
      "docs": "https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/what-is.html",
      "sources": [
        {
          "title": "Amazon Q Business documentation",
          "url": "https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/what-is.html"
        }
      ],
      "status": "restricted",
      "statusNote": "No longer open to new customers; AWS points new customers to Amazon Quick.",
      "kind": "service"
    },
    {
      "id": "q-developer",
      "name": "Amazon Q Developer",
      "shortName": "Q Developer",
      "category": "ai",
      "summary": "Generative AI assistant for coding, AWS architecture questions, and operating AWS workloads.",
      "details": "It offers IDE chat and code suggestions plus AWS-focused assistance in supported consoles and workflows. AWS documents it as powered by Amazon Bedrock, with context and capabilities varying by surface.",
      "useCases": [
        "explain an unfamiliar codebase",
        "suggest code and tests in an IDE",
        "investigate AWS configuration questions"
      ],
      "concepts": [
        "IDE assistance",
        "AWS guidance",
        "code transformation",
        "security scanning"
      ],
      "considerations": [
        "Review generated code and permissions",
        "availability and functionality differ among IDE, console, and service integrations."
      ],
      "docs": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/what-is.html",
      "sources": [
        {
          "title": "Amazon Q Developer documentation",
          "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "quick",
      "name": "Amazon Quick",
      "shortName": "Quick",
      "category": "analytics",
      "summary": "Business intelligence, research, and automation workspace, with Quick Sight as its BI component.",
      "details": "Amazon Quick is the current family name following the 2025 QuickSight rebrand; Quick Sight retains dashboards, analyses, and SPICE capabilities within the broader Quick Suite experience. Newly introduced Quick Suite capabilities have separate regional availability.",
      "useCases": [
        "publish governed dashboards",
        "analyze datasets with BI visuals",
        "research across connected business sources"
      ],
      "concepts": [
        "Quick Suite",
        "Quick Sight",
        "dashboards",
        "SPICE"
      ],
      "considerations": [
        "Legacy QuickSight naming remains in older integrations and APIs",
        "regional availability varies by capability."
      ],
      "docs": "https://docs.aws.amazon.com/quick/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "Amazon Quick documentation",
          "url": "https://docs.aws.amazon.com/quick/latest/userguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "Amazon QuickSight was rebranded to Amazon Quick in October 2025; Quick Sight remains its BI component.",
      "kind": "service"
    },
    {
      "id": "rds",
      "name": "Amazon Relational Database Service",
      "shortName": "RDS",
      "category": "database",
      "summary": "Managed relational databases with AWS-operated provisioning, backups, patching options, and monitoring.",
      "details": "RDS supports multiple database engines; engine-specific features and operational controls differ. Customers choose instance or serverless options where supported, and remain responsible for schema and workload design.",
      "useCases": [
        "host a transactional application database",
        "run a managed PostgreSQL workload",
        "maintain a multi-AZ relational database"
      ],
      "concepts": [
        "DB instances run a selected supported relational database engine.",
        "Amazon RDS supports multiple database engines with service-specific features.",
        "Automated backups support point-in-time recovery within the configured retention period.",
        "Multi-AZ deployments maintain a standby in another Availability Zone for supported engines and configurations."
      ],
      "considerations": [
        "Engine versions and extensions vary",
        "tune capacity, backup retention, and high-availability needs for the workload."
      ],
      "docs": "https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Welcome.html",
      "sources": [
        {
          "title": "Amazon Relational Database Service documentation",
          "url": "https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "repostprivate",
      "name": "AWS re:Post Private",
      "shortName": "re:Post Private",
      "category": "business",
      "summary": "Private knowledge community for organization-specific cloud questions and answers.",
      "details": "re:Post Private gives an organization a controlled space for technical discussions and reusable knowledge. Administrators manage membership and content; it complements rather than replaces AWS Support cases.",
      "useCases": [
        "internal cloud help community",
        "share architecture guidance",
        "retain resolved technical questions"
      ],
      "concepts": [
        "Private spaces restrict participation to invited members",
        "Questions and answers can become reusable knowledge",
        "Administrators manage members and configuration"
      ],
      "considerations": [
        "Content quality and access controls depend on administrators",
        "Review subscription and Region availability."
      ],
      "docs": "https://docs.aws.amazon.com/repostprivate/",
      "sources": [
        {
          "title": "AWS re:Post Private documentation",
          "url": "https://docs.aws.amazon.com/repostprivate/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "rosa",
      "name": "Red Hat OpenShift Service on AWS",
      "shortName": "Red Hat OpenShift Service on AWS",
      "category": "containers",
      "summary": "Managed Red Hat OpenShift service operated jointly by AWS and Red Hat.",
      "details": "Red Hat OpenShift Service on AWS (ROSA) provides OpenShift clusters on AWS infrastructure, with AWS and Red Hat sharing service responsibilities. Customers use OpenShift APIs and tools while selecting deployment, identity, networking, and worker-capacity options.",
      "useCases": [
        "enterprise Kubernetes with OpenShift",
        "hybrid OpenShift operations",
        "containerized application platforms"
      ],
      "concepts": [
        "ROSA runs OpenShift clusters on AWS infrastructure with service responsibilities shared by AWS and Red Hat.",
        "Customers manage worker capacity through machine pools while Red Hat SREs manage the control plane and infrastructure nodes.",
        "Cluster setup uses customer-selected VPC subnets, IAM roles, and identity-provider configuration."
      ],
      "considerations": [
        "Review ROSA deployment models, prerequisites, and support responsibilities",
        "Worker capacity, networking, and licensing affect total cost"
      ],
      "docs": "https://docs.aws.amazon.com/rosa/",
      "sources": [
        {
          "title": "Red Hat OpenShift Service on AWS documentation",
          "url": "https://docs.aws.amazon.com/rosa/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "redshift",
      "name": "Amazon Redshift",
      "shortName": "Redshift",
      "category": "analytics",
      "summary": "Cloud data warehouse for SQL analytics across warehouse and lake data.",
      "details": "Provisioned clusters and Serverless namespaces offer different capacity management choices; Redshift can query data in S3 and integrate with AWS lake governance. Workload design and data layout influence performance.",
      "useCases": [
        "enterprise reporting warehouse",
        "interactive analytics on curated facts",
        "join warehouse and lake datasets"
      ],
      "concepts": [
        "Provisioned clusters run warehouse workloads on managed node capacity.",
        "Redshift Serverless provisions and scales warehouse capacity for workloads.",
        "Redshift Spectrum uses Redshift SQL to query data in Amazon S3.",
        "Workload management controls query priorities and concurrency."
      ],
      "considerations": [
        "Plan concurrency, data distribution, and governance",
        "evaluate loading versus federated access for each dataset."
      ],
      "docs": "https://docs.aws.amazon.com/redshift/latest/mgmt/welcome.html",
      "sources": [
        {
          "title": "Amazon Redshift documentation",
          "url": "https://docs.aws.amazon.com/redshift/latest/mgmt/welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "rekognition",
      "name": "Amazon Rekognition",
      "shortName": "Rekognition",
      "category": "ai",
      "summary": "Analyzes images and videos for visual labels, faces, text, and selected specialized tasks.",
      "details": "Developers can analyze stored media or process supported streaming video workflows. Results are API detections with confidence values, not a substitute for human review in consequential decisions.",
      "useCases": [
        "index image libraries by objects",
        "detect text in video frames",
        "moderate user-submitted images"
      ],
      "concepts": [
        "image analysis",
        "video analysis",
        "face comparison",
        "moderation"
      ],
      "considerations": [
        "Assess demographic performance and error impact",
        "face analysis has distinct privacy and consent implications."
      ],
      "docs": "https://docs.aws.amazon.com/rekognition/latest/dg/what-is.html",
      "sources": [
        {
          "title": "Amazon Rekognition documentation",
          "url": "https://docs.aws.amazon.com/rekognition/latest/dg/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "res",
      "name": "Research and Engineering Studio on AWS",
      "shortName": "Research and Engineering Studio on AWS",
      "category": "compute",
      "summary": "Web portal solution for provisioning and managing research computing environments on AWS.",
      "details": "Research and Engineering Studio on AWS is an open-source solution that deploys a web portal for researchers to request virtual desktops and compute resources. It uses AWS infrastructure such as VPC, identity, and compute services; the solution itself is not a single managed AWS service.",
      "useCases": [
        "shared research workspaces",
        "self-service virtual desktops",
        "centralized research project access"
      ],
      "concepts": [
        "Researchers request virtual desktops and compute through a web portal deployed by the solution.",
        "The deployment uses customer AWS resources, including network, identity, and desktop compute components.",
        "Research and Engineering Studio is open source solution software, so operators maintain the deployed stack."
      ],
      "considerations": [
        "Deployment creates billable AWS resources that operators must maintain",
        "Identity, network, storage, and quota design are customer responsibilities"
      ],
      "docs": "https://docs.aws.amazon.com/res/",
      "sources": [
        {
          "title": "Research and Engineering Studio on AWS documentation",
          "url": "https://docs.aws.amazon.com/res/"
        },
        {
          "title": "Research and Engineering Studio end of support",
          "url": "https://docs.aws.amazon.com/res/latest/ug/res-end-of-support.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS stopped new adoption September 29, 2026. Existing deployments continue; the final release is supported through September 30, 2027.",
      "kind": "service"
    },
    {
      "id": "resilience-hub",
      "name": "AWS Resilience Hub",
      "shortName": "Resilience Hub",
      "category": "management",
      "summary": "Assesses application resilience and recommends recovery improvements.",
      "details": "Resilience Hub models application resources, assesses them against resilience policies, and can integrate with fault injection and recovery testing tools. Results estimate recovery objectives and identify gaps; workload owners must implement and validate recommendations.",
      "useCases": [
        "Assess RTO and RPO readiness",
        "Track resilience changes across releases",
        "Plan recovery testing"
      ],
      "concepts": [
        "applications aggregate resources",
        "resilience policies define targets",
        "AWS FIS can run experiments",
        "CloudWatch alarms can support assessment"
      ],
      "considerations": [
        "Assessments depend on accurate application resources",
        "Recommendations do not prove actual recovery success"
      ],
      "docs": "https://docs.aws.amazon.com/resilience-hub/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "AWS Resilience Hub documentation",
          "url": "https://docs.aws.amazon.com/resilience-hub/latest/userguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "resource-access-manager",
      "name": "AWS Resource Access Manager",
      "shortName": "Resource Access Manager",
      "category": "security",
      "summary": "Shares supported resources across accounts and organizational units.",
      "details": "RAM creates resource shares with principals and selected resource types, reducing duplicate infrastructure for supported services. Organizations integration can simplify sharing within an organization, but each service defines its own shareable resources and behavior.",
      "useCases": [
        "Share subnets across accounts",
        "Share Transit Gateway attachments or prefixes",
        "Centralize supported resource administration"
      ],
      "concepts": [
        "resource shares specify principals and resources",
        "Organizations can govern sharing",
        "some shares are external-account invitations",
        "resource type controls supported operations"
      ],
      "considerations": [
        "Confirm service-specific sharing semantics",
        "Cross-account recipients still need their own IAM access"
      ],
      "docs": "https://docs.aws.amazon.com/ram/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "AWS Resource Access Manager documentation",
          "url": "https://docs.aws.amazon.com/ram/latest/userguide/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "resource-explorer",
      "name": "AWS Resource Explorer",
      "shortName": "Resource Explorer",
      "category": "management",
      "summary": "Searches for AWS resources across accounts and Regions.",
      "details": "Resource Explorer indexes resource metadata for search and becomes available automatically when first accessed, with results shaped by IAM permissions. Users can optionally configure cross-Region search through an aggregator Region or multi-account search through AWS Organizations. Results describe resources and link to their owning service; they do not expose resource data.",
      "useCases": [
        "Locate resources by tag or name",
        "Inventory resources across Regions",
        "Find resources for incident response"
      ],
      "concepts": [
        "Indexes collect metadata that Resource Explorer can search.",
        "Views define which indexed resources a user can search.",
        "An aggregator Region enables optional cross-Region search.",
        "Organizations integration enables optional multi-account search."
      ],
      "considerations": [
        "Indexing is asynchronous and resource coverage varies",
        "Limit view access to appropriate users"
      ],
      "docs": "https://docs.aws.amazon.com/resource-explorer/latest/userguide/welcome.html",
      "sources": [
        {
          "title": "AWS Resource Explorer documentation",
          "url": "https://docs.aws.amazon.com/resource-explorer/latest/userguide/welcome.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "resource-groups",
      "name": "AWS Resource Groups",
      "shortName": "Resource Groups",
      "category": "management",
      "summary": "Groups AWS resources using tags or supported resource queries so teams can manage related assets together.",
      "details": "A resource group defines membership criteria and can expose member resources to integrated tools such as Systems Manager. Resource Groups provides grouping and cross-service views; AWS Resource Explorer is the separate service for searching resources across Regions.",
      "useCases": [
        "group all resources tagged to an application",
        "organize resources by environment or owner",
        "launch supported Systems Manager operations against a group"
      ],
      "concepts": [
        "tag-based groups match resource tags",
        "some groups can use supported query criteria",
        "group membership can be consumed by integrated AWS tools"
      ],
      "considerations": [
        "resources must support the chosen grouping query",
        "grouping does not itself grant access or change resource configuration"
      ],
      "docs": "https://docs.aws.amazon.com/ARG/latest/userguide/gettingstarted.html",
      "sources": [
        {
          "title": "What are AWS Resource Groups?",
          "url": "https://docs.aws.amazon.com/ARG/latest/userguide/gettingstarted.html"
        },
        {
          "title": "Tag Editor and Resource Groups",
          "url": "https://docs.aws.amazon.com/tag-editor/latest/userguide/tagging-resources-add.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "route53",
      "name": "Amazon Route 53",
      "shortName": "Route 53",
      "category": "network",
      "summary": "Scalable DNS, domain registration, and health-based routing service.",
      "details": "Route 53 hosts public and private DNS zones and can route queries using policies such as latency, weighted, failover, and geolocation. Resolver rules support DNS forwarding between VPCs and on-premises networks.",
      "useCases": [
        "Public domain DNS",
        "Private VPC name resolution",
        "Health-based traffic routing"
      ],
      "concepts": [
        "Hosted zones and records",
        "Routing policies",
        "Health checks",
        "Route 53 Resolver"
      ],
      "considerations": [
        "DNS caching means changes do not take effect instantly everywhere.",
        "Health checks and routing policies require accurate endpoint and failover design."
      ],
      "docs": "https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/Welcome.html",
      "sources": [
        {
          "title": "Amazon Route 53 documentation",
          "url": "https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/Welcome.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "rtb-fabric",
      "name": "AWS RTB Fabric",
      "shortName": "RTB Fabric",
      "category": "network",
      "summary": "Network service for co-locating real-time bidding applications on AWS.",
      "details": "AWS RTB Fabric provides a managed networking environment for advertising technology workloads that need low-latency communication among participating applications. It is designed for supported real-time bidding use cases and deployment arrangements, not as a general-purpose VPC replacement.",
      "useCases": [
        "real-time ad bidding",
        "low-latency partner application exchange",
        "ad-tech workload co-location"
      ],
      "concepts": [
        "The service places participating real-time bidding applications in a managed low-latency network environment.",
        "Its design targets ad-tech workloads that exchange bid requests and responses under strict latency needs.",
        "Eligibility and deployment arrangements are specialized, so RTB Fabric is not a general VPC connectivity option."
      ],
      "considerations": [
        "Eligibility, supported Regions, and onboarding constraints apply",
        "Measure end-to-end latency and account for application and transfer costs"
      ],
      "docs": "https://docs.aws.amazon.com/rtb-fabric/",
      "sources": [
        {
          "title": "AWS RTB Fabric documentation",
          "url": "https://docs.aws.amazon.com/rtb-fabric/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "s3",
      "name": "Amazon S3",
      "shortName": "S3",
      "category": "storage",
      "summary": "Object storage with multiple storage classes and data management features.",
      "details": "S3 stores objects in buckets and supports lifecycle, replication, access controls, event notifications, and query integrations. It commonly serves as a data lake and application storage layer, while access is governed through IAM, bucket policies, and encryption settings.",
      "useCases": [
        "Backups and archives",
        "Data lakes and analytics",
        "Static assets and application uploads"
      ],
      "concepts": [
        "Buckets, objects, and keys",
        "Storage classes and lifecycle",
        "Versioning and Object Lock",
        "Events, replication, and access policies"
      ],
      "considerations": [
        "S3 is object storage with API and consistency semantics distinct from a mounted file system.",
        "Cross-service triggers require appropriate Region, policy, and event configuration."
      ],
      "docs": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/Welcome.html",
      "sources": [
        {
          "title": "Amazon S3 User Guide",
          "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/Welcome.html"
        },
        {
          "title": "S3 event destinations",
          "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/notification-how-to-event-types-and-destinations.html"
        },
        {
          "title": "S3 multipart upload limits",
          "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/qfacts.html"
        },
        {
          "title": "General-purpose bucket namespaces",
          "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/gpbucketnamespaces.html"
        },
        {
          "title": "SSE-C defaults for new buckets",
          "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/default-s3-c-encryption-setting-faq.html"
        },
        {
          "title": "Restrict access to an S3 origin with CloudFront",
          "url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-restricting-access-to-s3.html"
        }
      ],
      "status": "active",
      "kind": "service",
      "topics": [
        {
          "title": "Objects, keys and uploads",
          "bullets": [
            "General-purpose bucket names are unique within an AWS partition; buckets are regional",
            "A PUT to an existing key replaces the whole object; bytes are never edited in place",
            "Maximum object size is 48.8 TiB; a single PUT request accepts up to 5 GiB",
            "Above 5 GiB use multipart: up to 10,000 parts, 5 MiB to 5 GiB; the last may be smaller",
            "Changing user metadata means copying the object onto itself; tags update in place"
          ]
        },
        {
          "title": "Prefixes and request rates",
          "bullets": [
            "The namespace is flat; console folders are key prefixes, not real directories",
            "Per prefix: at least 3,500 PUT/COPY/POST/DELETE and 5,500 GET/HEAD per second",
            "Request capacity is per prefix, so spreading keys over prefixes raises throughput",
            "ListObjectsV2 returns at most 1,000 keys per call; follow the continuation token",
            "Reads after PUT, overwrite or DELETE are strongly consistent, with no stale-read window"
          ]
        },
        {
          "title": "Storage classes",
          "bullets": [
            "Standard is the default: frequent access, multi-AZ, no minimum duration or retrieval fee",
            "Intelligent-Tiering suits unknown access patterns; it charges a per-object monitoring fee",
            "Standard-IA: infrequent reads; 30-day minimum, 128 KB minimum billed size, retrieval fee",
            "Glacier Instant and Flexible Retrieval have 90-day minimums; Deep Archive has 180 days",
            "One Zone classes keep data in one AZ, so suit re-creatable data; all target 11 nines"
          ]
        },
        {
          "title": "Lifecycle and versioning",
          "bullets": [
            "Versioning keeps overwritten and deleted data; a plain DELETE adds a delete marker",
            "Versioning can be suspended but never removed; noncurrent versions are billed",
            "MFA Delete is enabled by the root user and needs MFA to permanently delete versions",
            "Lifecycle rules move objects to other storage classes or expire them after set days",
            "Lifecycle can expire noncurrent versions and abort stale incomplete multipart uploads"
          ]
        },
        {
          "title": "Replication",
          "bullets": [
            "CRR copies to a bucket in another Region; SRR copies within the same Region",
            "Source and destination both need versioning, and an IAM role grants S3 access",
            "Only objects written after the rule exists replicate; use Batch Replication for old ones",
            "Permanent deletes of versions do not replicate; delete markers can be replicated",
            "Replication Time Control adds a 15-minute target and metrics for an extra charge"
          ]
        },
        {
          "title": "Encryption",
          "bullets": [
            "All new objects are encrypted at rest with SSE-S3 by default; no setup is needed",
            "SSE-KMS uses a KMS key you choose; each KMS request is billed and quota-limited",
            "S3 Bucket Keys cut the number of KMS requests for SSE-KMS objects",
            "SSE-C needs your key on each request; new buckets generally block SSE-C writes by default",
            "Deny requests where aws:SecureTransport is false to enforce TLS in transit"
          ]
        },
        {
          "title": "Access control",
          "bullets": [
            "Block Public Access is on by default for new buckets; account settings override buckets",
            "ACLs are disabled by default; grant access with IAM and bucket policies instead",
            "Cross-account access needs an allow in the caller's IAM policy and the bucket policy",
            "An explicit deny in any applicable policy overrides every allow",
            "Presigned URLs carry the signer's access and expire; SigV4 allows up to 7 days"
          ]
        },
        {
          "title": "Static website hosting",
          "bullets": [
            "Enabled per bucket; S3 serves an index document and an error document",
            "The website endpoint is HTTP only; HTTPS needs CloudFront in front of the bucket",
            "Website endpoints require public reads; private CloudFront OAC uses the S3 REST endpoint",
            "Routing rules can redirect paths or hosts; the index document serves folder-style paths"
          ]
        },
        {
          "title": "Event notifications",
          "bullets": [
            "Object events can go to SNS, SQS, Lambda or Amazon EventBridge",
            "EventBridge supports richer filters, multiple targets, archive and replay",
            "Legacy notifications filter only on key prefix and suffix",
            "Delivery is at least once; consumers must tolerate duplicates",
            "Events may arrive out of order; compare the sequencer field per key"
          ]
        },
        {
          "title": "Logs, metrics and analytics",
          "bullets": [
            "Server access logs are best-effort and written to a separate target bucket",
            "CloudTrail data events record object-level API calls and are billed per event",
            "Daily storage metrics are free; request metrics are opt-in and billed per metric",
            "S3 Inventory writes scheduled object lists with metadata as CSV, ORC or Parquet",
            "Storage Lens reports usage and activity across accounts, Regions and buckets"
          ]
        },
        {
          "title": "Pricing model",
          "bullets": [
            "Storage is billed per GB-month, with the rate set by storage class",
            "Requests are billed by type; PUT, COPY, POST and LIST cost more than GET",
            "IA and Glacier classes add a per-GB retrieval charge on read",
            "Data transfer out to the internet is billed per GB; transfer in is free",
            "Minimum-duration charges, lifecycle transitions and KMS requests are billed separately"
          ]
        },
        {
          "title": "Common pitfalls",
          "bullets": [
            "Incomplete multipart uploads keep their parts billed until aborted; add a rule",
            "Noncurrent versions stay billed until a lifecycle rule expires them",
            "11 nines covers hardware loss, not accidental deletes or overwrites; keep versions",
            "Bucket names with dots cause TLS certificate errors on virtual-hosted HTTPS; avoid dots",
            "Deleting a bucket needs it empty, including every version of every object"
          ]
        }
      ],
      "guide": "services/s3.html"
    },
    {
      "id": "s3-glacier",
      "name": "S3 Glacier storage classes",
      "shortName": "S3 Glacier",
      "category": "storage",
      "summary": "Archive storage classes within Amazon S3 for infrequently accessed data.",
      "details": "S3 Glacier Flexible Retrieval and Deep Archive are S3 storage classes managed through normal buckets and object APIs, with restore workflows before archived objects can be read. S3 Glacier Instant Retrieval is an archive class that supports millisecond retrieval for rarely accessed data.",
      "useCases": [
        "Long-term records retention",
        "Compliance archives",
        "Low-cost disaster recovery copies"
      ],
      "concepts": [
        "Flexible Retrieval and Deep Archive",
        "Restore requests and retrieval tiers",
        "Lifecycle transitions",
        "S3 object and bucket controls"
      ],
      "considerations": [
        "Archived objects may require restore time and incur retrieval charges.",
        "S3 Glacier is a family of S3 storage classes, not a separate bucket service."
      ],
      "docs": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/storage-class-intro.html",
      "sources": [
        {
          "title": "S3 Glacier storage classes documentation",
          "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/storage-class-intro.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "sagemaker-platform",
      "name": "Amazon SageMaker",
      "shortName": "SageMaker",
      "category": "analytics",
      "summary": "Unified data, analytics, and AI platform centered on Amazon SageMaker.",
      "details": "The next-generation Amazon SageMaker experience brings together data, analytics, and AI capabilities, including lakehouse access, governance, model development, and generative AI tools. It is a broad platform spanning integrated services and components; distinguish this platform entry from the separate Amazon SageMaker AI service and verify feature and Region availability.",
      "useCases": [
        "governed data and AI environments",
        "collaborative analytics and model development",
        "building generative AI applications"
      ],
      "concepts": [
        "The next-generation experience brings data, analytics, and AI capabilities together under the SageMaker platform.",
        "The platform includes a lakehouse experience for working with data across supported AWS stores.",
        "SageMaker platform and SageMaker AI are distinct catalog entries; component availability and regional support vary."
      ],
      "considerations": [
        "Capabilities can be delivered by distinct services with separate billing",
        "Feature availability, permissions, and data access vary by Region and component"
      ],
      "docs": "https://docs.aws.amazon.com/next-generation-sagemaker/latest/userguide/what-is-sagemaker.html",
      "sources": [
        {
          "title": "Amazon SageMaker documentation",
          "url": "https://docs.aws.amazon.com/next-generation-sagemaker/latest/userguide/what-is-sagemaker.html"
        },
        {
          "title": "Amazon SageMaker service details",
          "url": "https://docs.aws.amazon.com/next-generation-sagemaker/latest/userguide/what-is-sagemaker.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "sagemaker",
      "name": "Amazon SageMaker AI",
      "shortName": "SageMaker AI",
      "category": "ai",
      "summary": "Managed environment for preparing data, building, training, deploying, and governing machine-learning models.",
      "details": "The current SageMaker brand includes SageMaker AI for the model lifecycle alongside broader SageMaker data and analytics experiences. Teams can use managed development environments and hosted endpoints or bring their own training containers and deployment patterns.",
      "useCases": [
        "train a fraud classifier",
        "deploy a demand model endpoint",
        "manage model quality and bias reviews"
      ],
      "concepts": [
        "Prepare datasets with managed tools before training or deployment.",
        "Training jobs run supplied code or algorithms on managed compute.",
        "Deploy models through real-time endpoints and other inference options.",
        "Governance tools document models, manage access, and track model activity."
      ],
      "considerations": [
        "Compute and storage choices affect cost and operational control",
        "model monitoring and responsible-use checks remain customer responsibilities."
      ],
      "docs": "https://docs.aws.amazon.com/sagemaker/latest/dg/whatis.html",
      "sources": [
        {
          "title": "Amazon SageMaker AI documentation",
          "url": "https://docs.aws.amazon.com/sagemaker/latest/dg/whatis.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "savings-plans",
      "name": "AWS Savings Plans",
      "shortName": "Savings Plans",
      "category": "cost",
      "summary": "Offers discounted compute rates in exchange for a usage commitment.",
      "details": "Savings Plans apply eligible discounted rates to matching usage up to a committed hourly spend, with plan types varying in flexibility. Cost Explorer recommendations and utilization reports can inform purchases; unused commitment can reduce realized savings.",
      "useCases": [
        "Reduce steady compute costs",
        "Cover eligible EC2, Fargate, or Lambda usage",
        "Compare commitment scenarios"
      ],
      "concepts": [
        "Compute and EC2 Instance plan types differ",
        "commitment is hourly and term-based",
        "discount applies automatically to eligible usage",
        "utilization and coverage track value"
      ],
      "considerations": [
        "Commitment continues regardless of workload demand",
        "Model eligible usage before purchasing"
      ],
      "docs": "https://docs.aws.amazon.com/savingsplans/latest/userguide/what-is-savings-plans.html",
      "sources": [
        {
          "title": "AWS Savings Plans documentation",
          "url": "https://docs.aws.amazon.com/savingsplans/latest/userguide/what-is-savings-plans.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "schemaconversiontool",
      "name": "AWS Schema Conversion Tool",
      "shortName": "Schema Conversion Tool",
      "category": "migration",
      "summary": "Desktop migration tool that converts database schemas and code objects between supported source and target engines.",
      "details": "AWS SCT assesses source schemas, identifies incompatibilities, and converts supported objects into a target-compatible form. It can also support data extraction workflows; AWS DMS is commonly used separately to migrate ongoing database data.",
      "useCases": [
        "assess an Oracle schema for migration to PostgreSQL",
        "convert database code objects before a migration",
        "identify manual conversion work before cutover"
      ],
      "concepts": [
        "assessment reports classify conversion issues",
        "conversion rules map source constructs to target constructs",
        "extension packs can emulate selected source behaviors",
        "DMS can move data after schema preparation"
      ],
      "considerations": [
        "not every database object or semantic behavior converts automatically",
        "test converted SQL and application behavior against representative data"
      ],
      "docs": "https://docs.aws.amazon.com/SchemaConversionTool/latest/userguide/CHAP_Welcome.html",
      "sources": [
        {
          "title": "What is AWS Schema Conversion Tool?",
          "url": "https://docs.aws.amazon.com/SchemaConversionTool/latest/userguide/CHAP_Welcome.html"
        },
        {
          "title": "Using AWS SCT assessment reports",
          "url": "https://docs.aws.amazon.com/SchemaConversionTool/latest/userguide/CHAP_AssessmentReport.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "secrets-manager",
      "name": "AWS Secrets Manager",
      "shortName": "Secrets Manager",
      "category": "security",
      "summary": "Stores, retrieves, and rotates application secrets.",
      "details": "Secrets Manager encrypts secret values and integrates with KMS and supported database rotation workflows. Applications retrieve secrets through API or SDK calls; caching can reduce latency and API calls but requires refresh handling.",
      "useCases": [
        "Rotate database credentials",
        "Store third-party API tokens",
        "Share secrets across accounts with controlled policies"
      ],
      "concepts": [
        "secret versions track rotations",
        "rotation uses Lambda for supported patterns",
        "resource policies enable cross-account access",
        "KMS encrypts secret values"
      ],
      "considerations": [
        "Prevent secrets from leaking into logs or source code",
        "Rotation must be compatible with the consuming application"
      ],
      "docs": "https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html",
      "sources": [
        {
          "title": "AWS Secrets Manager documentation",
          "url": "https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "securityagent",
      "name": "AWS Security Agent",
      "shortName": "Security Agent",
      "category": "security",
      "summary": "AI-assisted application security reviews, threat modeling, code analysis, and on-demand penetration testing, now documented as part of AWS Continuum.",
      "details": "Teams provide design documents, repositories, or test scopes so the agent can assess an application against organizational requirements and identify security weaknesses. AWS describes code reviews, threat models, and authorized penetration tests that can generate actionable findings and proposed fixes; operators remain responsible for validating findings and test scope.",
      "useCases": [
        "review pull requests against security requirements",
        "model threats from an application design and codebase",
        "run an authorized penetration test against a scoped application"
      ],
      "concepts": [
        "organization requirements encode security expectations",
        "threat models map trust boundaries and STRIDE threat classes",
        "repository integrations support code review workflows",
        "test scope defines the targets and access used for penetration testing"
      ],
      "considerations": [
        "review any generated code changes and validate findings before action",
        "penetration testing requires explicit authorized targets and carefully bounded scope"
      ],
      "docs": "https://docs.aws.amazon.com/securityagent/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "What is AWS Security Agent (now part of AWS Continuum)?",
          "url": "https://docs.aws.amazon.com/securityagent/latest/userguide/what-is.html"
        },
        {
          "title": "AWS Security Agent infrastructure security",
          "url": "https://docs.aws.amazon.com/securityagent/latest/userguide/infrastructure-security.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "security-hub",
      "name": "AWS Security Hub",
      "shortName": "Security Hub",
      "category": "security",
      "summary": "Aggregates security findings and evaluates security posture across AWS accounts.",
      "details": "Security Hub normalizes findings from AWS services and partner products and supports standards-based controls. Central configuration and delegated administration help manage multi-account coverage; integrations can route findings to response tools.",
      "useCases": [
        "Centralize security findings",
        "Track security controls against standards",
        "Prioritize findings across accounts"
      ],
      "concepts": [
        "ASFF is the normalized finding format",
        "standards have control checks",
        "Organizations supports central administration",
        "EventBridge can trigger response automation"
      ],
      "considerations": [
        "Finding volume needs ownership and triage",
        "Controls are signals and do not certify compliance"
      ],
      "docs": "https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub.html",
      "sources": [
        {
          "title": "AWS Security Hub documentation",
          "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "security-ir",
      "name": "AWS Security Incident Response",
      "shortName": "Security Incident Response",
      "category": "security",
      "summary": "Managed service that triages threat findings and provides AWS security engineering support for confirmed incidents.",
      "details": "It ingests findings from configured detection services such as GuardDuty and Security Hub CSPM, deduplicates and investigates them, then escalates cases requiring customer action. During authorized incidents, responders can help contain supported resources; the service does not generate findings or perform full forensic disk analysis.",
      "useCases": [
        "triage GuardDuty threat findings across an organization",
        "coordinate an AWS-assisted response to a suspected compromise",
        "route case events to existing incident workflows through EventBridge"
      ],
      "concepts": [
        "memberships connect monitored accounts",
        "proactive cases originate from configured detection sources",
        "case workflows include investigation, containment, and recovery guidance",
        "EventBridge can route case and membership events"
      ],
      "considerations": [
        "detection sources must be configured separately",
        "containment requires authorization and supported actions; recovery remains customer-led"
      ],
      "docs": "https://docs.aws.amazon.com/security-ir/latest/userguide/what-is.html",
      "sources": [
        {
          "title": "What is AWS Security Incident Response?",
          "url": "https://docs.aws.amazon.com/security-ir/latest/userguide/what-is.html"
        },
        {
          "title": "Security Incident Response and Amazon EventBridge",
          "url": "https://docs.aws.amazon.com/security-ir/latest/userguide/eventbridge.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "security-lake",
      "name": "Amazon Security Lake",
      "shortName": "Security Lake",
      "category": "security",
      "summary": "Centralizes security data in an account-owned data lake.",
      "details": "Security Lake collects supported AWS and third-party security logs into an S3-backed lake using the Open Cybersecurity Schema Framework. Consumers can query or access data through supported analytics integrations; the lake is not itself a SIEM investigation UI.",
      "useCases": [
        "Build cross-source security analytics",
        "Retain normalized logs for investigations",
        "Share security data with analytics tools"
      ],
      "concepts": [
        "OCSF normalizes supported sources",
        "S3 and Lake Formation underpin access",
        "subscribers consume data",
        "multi-account collection uses Organizations"
      ],
      "considerations": [
        "Plan retention, access, and query costs",
        "Not every source or consumer is supported in every Region"
      ],
      "docs": "https://docs.aws.amazon.com/security-lake/latest/userguide/what-is-security-lake.html",
      "sources": [
        {
          "title": "Amazon Security Lake documentation",
          "url": "https://docs.aws.amazon.com/security-lake/latest/userguide/what-is-security-lake.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "serverless-application-model",
      "name": "AWS Serverless Application Model",
      "shortName": "Serverless Application Model",
      "category": "compute",
      "summary": "Open-source framework for defining and deploying serverless applications on AWS.",
      "details": "AWS SAM provides a shorthand template syntax and command-line tooling for packaging and deploying serverless applications, translating SAM resources into AWS CloudFormation resources. It is a framework and toolchain; deployed Lambda, API Gateway, and other resources are billed by their underlying services.",
      "useCases": [
        "Lambda APIs and event handlers",
        "local serverless development",
        "repeatable infrastructure deployment"
      ],
      "concepts": [
        "SAM templates add concise resource types that transform into CloudFormation resources.",
        "The SAM CLI can build and package application artifacts before deployment.",
        "SAM is an authoring and deployment framework; runtime charges come from the resources it deploys."
      ],
      "considerations": [
        "Runtime and service limits still apply to deployed resources",
        "Review generated CloudFormation changes before deployment"
      ],
      "docs": "https://docs.aws.amazon.com/serverless-application-model/",
      "sources": [
        {
          "title": "AWS Serverless Application Model documentation",
          "url": "https://docs.aws.amazon.com/serverless-application-model/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "serverlessrepo",
      "name": "AWS Serverless Application Repository",
      "shortName": "Serverless Application Repository",
      "category": "compute",
      "summary": "Catalog for discovering, publishing, and deploying serverless applications.",
      "details": "The AWS Serverless Application Repository distributes applications packaged with AWS SAM and CloudFormation templates. Applications can be shared publicly or privately and deployed into an account, where the underlying AWS resources run and incur their normal charges.",
      "useCases": [
        "deploying reusable serverless apps",
        "sharing internal application templates",
        "publishing serverless components"
      ],
      "concepts": [
        "Published applications are packaged from AWS SAM or CloudFormation templates.",
        "Publishers can share an application publicly or restrict it to specified AWS accounts.",
        "Deploying an application creates resources in the subscriber's account, where those resources follow their service pricing."
      ],
      "considerations": [
        "Inspect source, permissions, and resources before deployment",
        "Repository availability does not remove charges for deployed resources"
      ],
      "docs": "https://docs.aws.amazon.com/serverlessrepo/",
      "sources": [
        {
          "title": "AWS Serverless Application Repository documentation",
          "url": "https://docs.aws.amazon.com/serverlessrepo/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "service-catalog",
      "name": "AWS Service Catalog",
      "shortName": "Service Catalog",
      "category": "management",
      "summary": "Publishes approved infrastructure products for governed self-service.",
      "details": "Service Catalog portfolios expose versioned products and constraints to selected users or groups. Products can be CloudFormation-based; launch roles and constraints let platform teams standardize how consumers provision approved resources.",
      "useCases": [
        "Offer approved environment templates",
        "Constrain self-service infrastructure choices",
        "Manage product versions and access"
      ],
      "concepts": [
        "products can use CloudFormation templates",
        "portfolios grant access",
        "launch constraints control provisioning role",
        "provisioned products have lifecycle records"
      ],
      "considerations": [
        "Template changes can affect existing products",
        "Set clear ownership for product updates"
      ],
      "docs": "https://docs.aws.amazon.com/servicecatalog/latest/adminguide/introduction.html",
      "sources": [
        {
          "title": "AWS Service Catalog documentation",
          "url": "https://docs.aws.amazon.com/servicecatalog/latest/adminguide/introduction.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "smc",
      "name": "AWS Service Management Connector",
      "shortName": "Service Management Connector",
      "category": "management",
      "summary": "Integrates AWS service management workflows into supported ITSM platforms such as ServiceNow and Atlassian.",
      "details": "Administrators configure the connector and its integrations to expose AWS capabilities inside an organization’s existing service-management tools. AWS stopped accepting new customers on March 31, 2026 and will end support on March 31, 2027; existing users should plan migration to partner solutions or direct API integrations.",
      "useCases": [
        "request AWS products through an ITSM catalog",
        "surface AWS operational events in an ITSM system",
        "connect service workflows to AWS Service Catalog"
      ],
      "concepts": [
        "connector modules map AWS capabilities into ITSM interfaces",
        "Service Catalog products can be exposed as requestable items",
        "integration roles authorize AWS actions",
        "supported modules vary by connector release"
      ],
      "considerations": [
        "the connector does not replace the ITSM platform or AWS service permissions",
        "compatibility and supported modules depend on platform and version"
      ],
      "docs": "https://docs.aws.amazon.com/smc/latest/ag/overview.html",
      "sources": [
        {
          "title": "What is AWS Service Management Connector?",
          "url": "https://docs.aws.amazon.com/smc/latest/ag/overview.html"
        },
        {
          "title": "AWS Service Management Connector end of support",
          "url": "https://docs.aws.amazon.com/smc/latest/ag/smc-end-of-support.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS stopped accepting new customers on March 31, 2026. Existing customers can use the connector until March 31, 2027, when service access ends.",
      "kind": "service"
    },
    {
      "id": "servicequotas",
      "name": "Service Quotas",
      "shortName": "Service Quotas",
      "category": "management",
      "summary": "Shows and manages adjustable quotas for many AWS services and supports quota increase requests.",
      "details": "The console and API expose default and applied quota values, usage where available, and increase-request workflows. Quotas are service- and Region-specific; some are adjustable while others are fixed or not exposed for automated tracking.",
      "useCases": [
        "check a quota before a production launch",
        "request a higher regional service limit",
        "monitor quota utilization with supported integrations"
      ],
      "concepts": [
        "applied quotas reflect account-specific values",
        "adjustable quotas can be increased through requests",
        "CloudWatch integration can track selected usage and quotas"
      ],
      "considerations": [
        "not every quota is adjustable or has usage metrics",
        "approved increases may take time and do not guarantee resource capacity"
      ],
      "docs": "https://docs.aws.amazon.com/servicequotas/latest/userguide/intro.html",
      "sources": [
        {
          "title": "What is Service Quotas?",
          "url": "https://docs.aws.amazon.com/servicequotas/latest/userguide/intro.html"
        },
        {
          "title": "Requesting a quota increase",
          "url": "https://docs.aws.amazon.com/servicequotas/latest/userguide/request-quota-increase.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "shield",
      "name": "AWS Shield",
      "shortName": "Shield",
      "category": "security",
      "summary": "Provides managed DDoS protection for AWS workloads.",
      "details": "Shield Standard is automatically available for AWS customers, while Shield Advanced adds enhanced detection, response support, and protections for supported resources. Shield Advanced can coordinate with WAF and uses service-linked roles to configure protections.",
      "useCases": [
        "Protect public web applications from DDoS",
        "Get response support for attack events",
        "Apply protections across eligible resources"
      ],
      "concepts": [
        "Standard protections are automatic",
        "Advanced is subscription-based",
        "works with WAF for application-layer defenses",
        "resource coverage depends on service"
      ],
      "considerations": [
        "Shield does not replace application security controls",
        "Advanced onboarding and cost commitments require planning"
      ],
      "docs": "https://docs.aws.amazon.com/waf/latest/developerguide/shield-chapter.html",
      "sources": [
        {
          "title": "AWS Shield documentation",
          "url": "https://docs.aws.amazon.com/waf/latest/developerguide/shield-chapter.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "signer",
      "name": "AWS Signer",
      "shortName": "Signer",
      "category": "security",
      "summary": "Managed code signing that lets publishers sign software artifacts and consumers verify their origin and integrity.",
      "details": "A signing profile defines the signing job and platform configuration; Signer manages the signing keys and produces signed artifacts or signatures for supported platforms. Integrations include Lambda deployment-package validation and supported IoT/device workflows.",
      "useCases": [
        "require signed Lambda deployment packages",
        "sign IoT device software releases",
        "centralize publisher authorization for artifacts"
      ],
      "concepts": [
        "signing profiles establish allowed signers and platform",
        "signing jobs create signed artifacts or signature metadata",
        "Lambda code-signing configuration can block untrusted packages"
      ],
      "considerations": [
        "Signer only helps when the deployment or device workflow verifies signatures",
        "supported platform and artifact constraints vary by integration"
      ],
      "docs": "https://docs.aws.amazon.com/signer/latest/developerguide/Welcome.html",
      "sources": [
        {
          "title": "What is AWS Signer?",
          "url": "https://docs.aws.amazon.com/signer/latest/developerguide/Welcome.html"
        },
        {
          "title": "AWS Signer and AWS Lambda",
          "url": "https://docs.aws.amazon.com/lambda/latest/dg/configuration-codesigning.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "ses",
      "name": "Amazon Simple Email Service",
      "shortName": "Simple Email Service",
      "category": "business",
      "summary": "Managed email service for application sending and inbound email processing.",
      "details": "SES offers APIs and SMTP for outbound mail plus receipt rules that store or route inbound messages. Domains must be verified, and senders manage reputation, bounces, complaints, and suppression.",
      "useCases": [
        "transactional receipts",
        "opted-in newsletters",
        "route inbound support email"
      ],
      "concepts": [
        "Verified identities establish sending domains or addresses",
        "Configuration sets attach controls and events to messages",
        "Receipt rules route inbound mail to configured actions"
      ],
      "considerations": [
        "Sandbox restrictions and quotas apply until raised",
        "Sender reputation, consent, and deliverability need ongoing care."
      ],
      "docs": "https://docs.aws.amazon.com/ses/",
      "sources": [
        {
          "title": "Amazon Simple Email Service documentation",
          "url": "https://docs.aws.amazon.com/ses/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "site-to-site-vpn",
      "name": "AWS Site-to-Site VPN",
      "shortName": "Site-to-Site VPN",
      "category": "network",
      "summary": "Encrypted IPsec tunnels connect customer networks with AWS.",
      "details": "Site-to-Site VPN connects a customer gateway device to a virtual private gateway or Transit Gateway. Each connection normally uses two tunnels for availability and supports static or dynamic routing.",
      "useCases": [
        "Branch-office to VPC connectivity",
        "Hybrid cloud networks",
        "Backup path for Direct Connect"
      ],
      "concepts": [
        "Customer and virtual private gateways",
        "IPsec tunnels",
        "BGP or static routing",
        "Transit Gateway attachment"
      ],
      "considerations": [
        "Customer edge device configuration and routing must match AWS settings.",
        "VPN is internet-based and performance can vary with path conditions."
      ],
      "docs": "https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html",
      "sources": [
        {
          "title": "AWS Site-to-Site VPN documentation",
          "url": "https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "snowball",
      "name": "AWS Snowball Edge",
      "shortName": "Snowball",
      "category": "storage",
      "summary": "Physical edge device for offline data transfer and selected local compute workloads.",
      "details": "Snowball Edge devices support import/export jobs and selected local compute and storage features. AWS documentation says the device is no longer available to new customers; existing customers can continue using it, with DataSync, Data Transfer Terminal, or Outposts suggested for new needs.",
      "useCases": [
        "Offline large data transfer for existing customers",
        "Disconnected edge processing",
        "Local S3-compatible data staging"
      ],
      "concepts": [
        "Import and export jobs",
        "Local compatible compute and storage",
        "Job tracking and shipping",
        "Existing-customer availability restriction"
      ],
      "considerations": [
        "No longer offered to new customers according to the current service notice.",
        "Device and feature availability depends on account and Region."
      ],
      "docs": "https://docs.aws.amazon.com/snowball/latest/developer-guide/snowball-edge-availability-change.html",
      "sources": [
        {
          "title": "Snowball Edge availability change",
          "url": "https://docs.aws.amazon.com/snowball/latest/developer-guide/snowball-edge-availability-change.html"
        },
        {
          "title": "How Snowball Edge works",
          "url": "https://docs.aws.amazon.com/snowball/latest/developer-guide/how-it-works.html"
        }
      ],
      "status": "restricted",
      "statusNote": "AWS says Snowball Edge is no longer available to new customers; existing customers may continue using it.",
      "kind": "service"
    },
    {
      "id": "snowcone",
      "name": "AWS Snowcone",
      "shortName": "Snowcone",
      "category": "storage",
      "summary": "AWS Snowcone was a compact rugged device for offline data transfer and edge computing in constrained locations. AWS discontinued the service on November 12, 2024 and ended support for existing devices on November 12, 2025.",
      "details": "Snowcone SSD and HDD devices could be shipped to a site, connected locally, and returned for transfer into AWS. AWS recommends DataSync for most online migration workloads and Outposts for edge computing alternatives.",
      "useCases": [
        "historical offline transfer from remote sites",
        "historical edge compute where connectivity was limited",
        "shipping data when network transfer was impractical"
      ],
      "concepts": [
        "Snowcone devices were ordered for specific jobs",
        "Local devices supported data movement and edge workloads",
        "Returned devices were processed for transfer into AWS"
      ],
      "considerations": [
        "AWS no longer accepts Snowcone orders or supports existing devices",
        "Replacement choices depend on connectivity, transfer volume, and whether workloads need local compute."
      ],
      "docs": "https://aws.amazon.com/blogs/storage/aws-snow-device-updates/",
      "sources": [
        {
          "title": "AWS Snow device updates",
          "url": "https://aws.amazon.com/blogs/storage/aws-snow-device-updates/"
        }
      ],
      "status": "retired",
      "statusNote": "AWS discontinued Snowcone on 2024-11-12 and support for existing devices ended 2025-11-12.",
      "kind": "service"
    },
    {
      "id": "snowmobile",
      "name": "AWS Snowmobile",
      "shortName": "Snowmobile",
      "category": "storage",
      "summary": "A historical exabyte-scale truck-based data transfer option for very large migrations.",
      "details": "AWS introduced Snowmobile in 2016 as a truck-based service for moving up to 100 PB per container into AWS. AWS now lists Snowmobile in its full-shutdown services with an end-of-support date of March 14, 2024.",
      "useCases": [
        "Historical exabyte-scale offline migration",
        "Data-center exit planning in historical AWS guidance",
        "Legacy migration references"
      ],
      "concepts": [
        "A ruggedized, truck-hauled data container",
        "Historical Amazon S3 and Glacier import destination",
        "Historical chain-of-custody and security controls"
      ],
      "considerations": [
        "Retired; AWS lists end of support as March 14, 2024.",
        "Do not present Snowmobile as an available transfer option."
      ],
      "docs": "https://docs.aws.amazon.com/general/latest/gr/full_shutdown_services.html",
      "sources": [
        {
          "title": "AWS services in full shutdown",
          "url": "https://docs.aws.amazon.com/general/latest/gr/full_shutdown_services.html"
        },
        {
          "title": "AWS Snowmobile launch announcement",
          "url": "https://aws.amazon.com/blogs/aws/aws-snowmobile-move-exabytes-of-data-to-the-cloud-in-weeks/"
        }
      ],
      "status": "retired",
      "statusNote": "AWS lists Snowmobile end of support as March 14, 2024.",
      "kind": "service"
    },
    {
      "id": "sns",
      "name": "Amazon SNS",
      "shortName": "SNS",
      "category": "integration",
      "summary": "Managed pub/sub messaging for fan-out delivery to subscribers.",
      "details": "SNS topics publish messages to subscriptions such as SQS queues, Lambda functions, HTTP endpoints, and mobile push destinations. Topic and subscription policies control who can publish and receive messages.",
      "useCases": [
        "Fan-out notifications",
        "Application alerts",
        "Event delivery to multiple consumers"
      ],
      "concepts": [
        "Topics and subscriptions",
        "Message filtering",
        "Delivery policies",
        "SNS-to-SQS fan-out"
      ],
      "considerations": [
        "Subscriber delivery and retry behavior vary by protocol.",
        "SQS fan-out subscriptions need queue policies that allow the topic to publish."
      ],
      "docs": "https://docs.aws.amazon.com/sns/latest/dg/welcome.html",
      "sources": [
        {
          "title": "Amazon SNS documentation",
          "url": "https://docs.aws.amazon.com/sns/latest/dg/welcome.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "sqs",
      "name": "Amazon SQS",
      "shortName": "SQS",
      "category": "integration",
      "summary": "Managed message queues that decouple distributed application components.",
      "details": "SQS provides standard and FIFO queues with visibility timeouts, retention, dead-letter queues, and long polling. Lambda event source mappings can poll SQS and invoke functions to process messages.",
      "useCases": [
        "Work queues and task buffering",
        "Service decoupling",
        "Retryable asynchronous processing"
      ],
      "concepts": [
        "Standard and FIFO queues",
        "Visibility timeout and redrive",
        "Long polling",
        "Lambda event source mapping"
      ],
      "considerations": [
        "Consumers should be idempotent because messages can be delivered more than once.",
        "Queue retention, visibility timeout, and throughput limits affect processing behavior."
      ],
      "docs": "https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/welcome.html",
      "sources": [
        {
          "title": "Amazon SQS documentation",
          "url": "https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/welcome.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "step-functions",
      "name": "AWS Step Functions",
      "shortName": "Step Functions",
      "category": "integration",
      "summary": "Orchestrates application workflows using state machines.",
      "details": "Step Functions coordinates tasks, retries, branches, waits, and error handling across AWS services and application code. Standard and Express workflows have different execution and duration characteristics.",
      "useCases": [
        "Multi-step business processes",
        "Data and ML workflow orchestration",
        "Service coordination with retries"
      ],
      "concepts": [
        "State machines and states",
        "Standard and Express workflows",
        "Service integrations",
        "Execution history and retries"
      ],
      "considerations": [
        "Workflow type affects duration, throughput, and execution-history behavior.",
        "Payload size and service integration quotas shape workflow design."
      ],
      "docs": "https://docs.aws.amazon.com/step-functions/latest/dg/welcome.html",
      "sources": [
        {
          "title": "AWS Step Functions documentation",
          "url": "https://docs.aws.amazon.com/step-functions/latest/dg/welcome.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "storage-gateway",
      "name": "AWS Storage Gateway",
      "shortName": "Storage Gateway",
      "category": "storage",
      "summary": "Hybrid storage service that connects on-premises applications to AWS storage.",
      "details": "Storage Gateway offers file, volume, and tape gateway modes delivered as a virtual appliance or hardware appliance. Depending on gateway type, data is cached locally or stored locally and backed up to AWS services such as S3 and EBS snapshots.",
      "useCases": [
        "Cloud-backed file shares",
        "On-premises volume backup",
        "Virtual tape migration"
      ],
      "concepts": [
        "File, volume, and tape gateways",
        "Local cache and upload buffer",
        "S3 and EBS snapshot backing",
        "AWS Backup integration"
      ],
      "considerations": [
        "Gateway deployments require local host, network, and cache capacity planning.",
        "Some data exposed through gateway abstractions is not directly browsable through S3 APIs."
      ],
      "docs": "https://docs.aws.amazon.com/storagegateway/latest/tgw/WhatIsStorageGateway.html",
      "sources": [
        {
          "title": "AWS Storage Gateway documentation",
          "url": "https://docs.aws.amazon.com/storagegateway/latest/tgw/WhatIsStorageGateway.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "sts",
      "name": "AWS Security Token Service",
      "shortName": "STS",
      "category": "security",
      "summary": "Issues temporary security credentials for role sessions and federated access to AWS.",
      "details": "STS returns time-limited access credentials for supported operations such as AssumeRole and AssumeRoleWithWebIdentity. IAM policies and role trust determine what a caller may request and what the resulting session may access.",
      "useCases": [
        "Cross-account access through an IAM role",
        "Federated access using an external identity provider",
        "Short-lived workload credentials instead of long-lived access keys"
      ],
      "concepts": [
        "Temporary credentials include an access key, secret key, session token, and expiration.",
        "A role trust policy controls who may assume the role; permission policies control the resulting access.",
        "Session policies can narrow a session’s permissions but cannot grant beyond the role’s permissions."
      ],
      "considerations": [
        "Refresh credentials before expiration and include the session token when signing requests.",
        "Choose endpoint and session-duration settings appropriate to the identity flow."
      ],
      "docs": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html",
      "sources": [
        {
          "title": "Temporary security credentials in IAM",
          "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html"
        },
        {
          "title": "Permissions for temporary security credentials",
          "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_control-access.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "supply-chain",
      "name": "AWS Supply Chain",
      "shortName": "Supply Chain",
      "category": "business",
      "summary": "Legacy planning product documented beside the newer Amazon Connect Decisions service.",
      "details": "AWS documents AWS Supply Chain in a legacy section under Connect Decisions documentation. Treat this entry as a migration reference and verify which product experience and account eligibility apply.",
      "useCases": [
        "identify existing integrations",
        "review historical planning workflows",
        "map users to Connect Decisions docs"
      ],
      "concepts": [
        "Legacy guides remain under Connect Decisions docs",
        "Planning material includes source data and forecasts",
        "Connect Decisions is the current product name in docs"
      ],
      "considerations": [
        "Do not assume legacy onboarding remains open",
        "Confirm migration and feature access with AWS."
      ],
      "docs": "https://docs.aws.amazon.com/connect-decisions/",
      "sources": [
        {
          "title": "AWS Supply Chain documentation",
          "url": "https://docs.aws.amazon.com/connect-decisions/"
        }
      ],
      "status": "restricted",
      "statusNote": "Legacy product documentation; current Connect Decisions docs retain a legacy section. Verified 2026-10-08.",
      "kind": "service"
    },
    {
      "id": "sustainability",
      "name": "AWS Sustainability",
      "shortName": "Sustainability",
      "category": "management",
      "summary": "A set of AWS tools and guidance that helps customers understand and reduce the environmental impact of cloud workloads.",
      "details": "The sustainability documentation points to architecture practices, customer carbon footprint information, and workload-level optimization approaches. These resources help teams evaluate infrastructure choices and usage trends; they do not replace organization-wide emissions accounting or supplier data.",
      "useCases": [
        "review estimated AWS-related carbon footprint trends",
        "identify architecture changes that may reduce resource use",
        "apply sustainability practices during workload reviews"
      ],
      "concepts": [
        "Customer Carbon Footprint Tool estimates emissions associated with AWS usage",
        "Well-Architected sustainability guidance addresses workload design",
        "utilization and managed-service choices influence resource efficiency"
      ],
      "considerations": [
        "estimates use AWS methodology and boundaries that may differ from corporate reporting",
        "measure workload outcomes and consider data retention and transfer as well as compute"
      ],
      "docs": "https://docs.aws.amazon.com/sustainability/latest/userguide/what-is-sustainability.html",
      "sources": [
        {
          "title": "What is AWS Sustainability?",
          "url": "https://docs.aws.amazon.com/sustainability/latest/userguide/what-is-sustainability.html"
        },
        {
          "title": "Sustainability Pillar of the AWS Well-Architected Framework",
          "url": "https://docs.aws.amazon.com/wellarchitected/latest/sustainability-pillar/sustainability-pillar.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "swf",
      "name": "Amazon Simple Workflow Service",
      "shortName": "SWF",
      "category": "integration",
      "summary": "Coordinates distributed tasks using workflow and activity workers.",
      "details": "Amazon SWF provides a durable workflow execution history and task lists so application workers can coordinate long-running business processes. AWS recommends evaluating Step Functions for many new workflow use cases, while SWF remains relevant to existing deployments.",
      "useCases": [
        "Long-running business workflows",
        "Legacy workflow applications",
        "Worker-driven task coordination"
      ],
      "concepts": [
        "Workflow and activity types",
        "Decision and activity workers",
        "Task lists and history",
        "External signal and timer patterns"
      ],
      "considerations": [
        "It requires workers and application code to drive decisions and activities.",
        "Step Functions offers a managed visual state-machine model for many new designs."
      ],
      "docs": "https://docs.aws.amazon.com/amazonswf/latest/developerguide/swf-welcome.html",
      "sources": [
        {
          "title": "Amazon Simple Workflow Service documentation",
          "url": "https://docs.aws.amazon.com/amazonswf/latest/developerguide/swf-welcome.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "systems-manager",
      "name": "AWS Systems Manager",
      "shortName": "Systems Manager",
      "category": "management",
      "summary": "Provides fleet operations, patching, automation, and parameter management.",
      "details": "Systems Manager uses managed nodes and documents to run operational tasks across supported servers and AWS resources. Capabilities include Session Manager, Run Command, Automation, Patch Manager, and Parameter Store; permissions and agent readiness determine coverage.",
      "useCases": [
        "Run commands across EC2 fleets",
        "Patch managed servers",
        "Open audited shell sessions without inbound SSH"
      ],
      "concepts": [
        "SSM Agent registers managed nodes",
        "documents define actions",
        "Session Manager can log sessions",
        "Parameter Store holds configuration values"
      ],
      "considerations": [
        "Configure instance profiles and network endpoints",
        "Test patch baselines and automation scope"
      ],
      "docs": "https://docs.aws.amazon.com/systems-manager/latest/userguide/what-is-systems-manager.html",
      "sources": [
        {
          "title": "AWS Systems Manager documentation",
          "url": "https://docs.aws.amazon.com/systems-manager/latest/userguide/what-is-systems-manager.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "tnb",
      "name": "AWS Telco Network Builder",
      "shortName": "Telco Network Builder",
      "category": "management",
      "summary": "Automates deployment and lifecycle management of 5G network functions and supporting AWS infrastructure.",
      "details": "Communication service providers describe network services using service and function descriptors, then AWS TNB provisions infrastructure and deploys containerized network functions. It integrates with ETSI-compliant orchestrators and AWS services such as EC2, EKS, and VPC.",
      "useCases": [
        "deploy a 5G core network function stack",
        "upgrade network functions using versioned descriptors",
        "inspect the AWS resources underlying a telecom service"
      ],
      "concepts": [
        "network service descriptors describe deployment topology",
        "network function packages include software artifacts and Helm charts",
        "orchestrators can use ETSI SOL interfaces",
        "TNB tracks deployment changes as service lifecycle operations"
      ],
      "considerations": [
        "requires telecom-specific artifacts and partner software images",
        "charges include managed network-function hours and API requests plus underlying AWS resources"
      ],
      "docs": "https://docs.aws.amazon.com/tnb/latest/ug/what-is-tnb.html",
      "sources": [
        {
          "title": "What is AWS Telco Network Builder?",
          "url": "https://docs.aws.amazon.com/tnb/latest/ug/what-is-tnb.html"
        },
        {
          "title": "AWS TNB integrations and service orchestration",
          "url": "https://docs.aws.amazon.com/tnb/latest/ug/how-tnb-works.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "textract",
      "name": "Amazon Textract",
      "shortName": "Textract",
      "category": "ai",
      "summary": "Extracts printed text, forms, tables, and structured fields from documents.",
      "details": "Document APIs return blocks and relationships, while specialized analysis features target forms, invoices, identity documents, and lending workflows. Human review can be added for uncertain results.",
      "useCases": [
        "digitize invoices",
        "extract form fields from applications",
        "process tables in scanned reports"
      ],
      "concepts": [
        "text detection",
        "document analysis",
        "forms",
        "tables"
      ],
      "considerations": [
        "Scans, handwriting, and document layout affect extraction",
        "validate extracted fields before business decisions."
      ],
      "docs": "https://docs.aws.amazon.com/textract/latest/dg/what-is.html",
      "sources": [
        {
          "title": "Amazon Textract documentation",
          "url": "https://docs.aws.amazon.com/textract/latest/dg/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "timestream",
      "name": "Amazon Timestream for LiveAnalytics",
      "shortName": "Timestream",
      "category": "database",
      "summary": "Purpose-built time-series database for ingesting and querying timestamped measurements.",
      "details": "LiveAnalytics organizes measurements into memory and magnetic storage tiers with SQL query access and retention controls. AWS closed access to new customers in June 2025 and recommends evaluating Timestream for InfluxDB for new customers.",
      "useCases": [
        "monitor device telemetry",
        "analyze application metrics",
        "query industrial sensor history"
      ],
      "concepts": [
        "time-series records",
        "memory and magnetic stores",
        "retention",
        "scheduled queries"
      ],
      "considerations": [
        "Restricted for new customers since June 20, 2025",
        "evaluate the recommended alternative and migration path."
      ],
      "docs": "https://docs.aws.amazon.com/timestream/latest/developerguide/what-is-timestream.html",
      "sources": [
        {
          "title": "Amazon Timestream for LiveAnalytics documentation",
          "url": "https://docs.aws.amazon.com/timestream/latest/developerguide/what-is-timestream.html"
        }
      ],
      "status": "restricted",
      "statusNote": "New customer access closed June 20, 2025; existing payer accounts can continue using the service.",
      "kind": "service"
    },
    {
      "id": "training",
      "name": "AWS Training and Certification",
      "shortName": "Training and Certification",
      "category": "business",
      "summary": "AWS learning and certification programs for building cloud skills.",
      "details": "Training and Certification includes digital courses, instructor-led learning, exam preparation, and credentials. These are educational programs rather than infrastructure resources; availability varies by language and location.",
      "useCases": [
        "onboard cloud engineers",
        "prepare for AWS certifications",
        "build role-based cloud skills"
      ],
      "concepts": [
        "Digital courses support self-paced study",
        "Instructor-led courses provide scheduled expert teaching",
        "Certification exams assess knowledge against defined objectives"
      ],
      "considerations": [
        "Course and exam availability varies by geography",
        "Certification does not itself provide production access or experience."
      ],
      "docs": "https://aws.amazon.com/training/",
      "sources": [
        {
          "title": "AWS Training and Certification documentation",
          "url": "https://aws.amazon.com/training/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "tool"
    },
    {
      "id": "transcribe",
      "name": "Amazon Transcribe",
      "shortName": "Transcribe",
      "category": "ai",
      "summary": "Converts audio into text for batch or streaming speech recognition.",
      "details": "It can produce timestamps and speaker-related output, with separate workflows for general transcription and call analytics. Audio format, language, and selected options affect recognition quality.",
      "useCases": [
        "meeting transcription",
        "live captions",
        "call-center conversation analytics"
      ],
      "concepts": [
        "batch jobs",
        "streaming",
        "speaker labels",
        "vocabulary"
      ],
      "considerations": [
        "Noisy audio and domain vocabulary can reduce accuracy",
        "treat transcripts as probabilistic output and validate consequential records."
      ],
      "docs": "https://docs.aws.amazon.com/transcribe/latest/dg/what-is.html",
      "sources": [
        {
          "title": "Amazon Transcribe documentation",
          "url": "https://docs.aws.amazon.com/transcribe/latest/dg/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "transfer-family",
      "name": "AWS Transfer Family",
      "shortName": "Transfer Family",
      "category": "storage",
      "summary": "Managed file transfer endpoints that deliver files into AWS storage.",
      "details": "Transfer Family provides managed SFTP, FTPS, FTP, and AS2 capabilities for supported workflows, with storage backed by S3 or EFS. It can use custom identity providers and VPC-hosted endpoint options for partner access patterns.",
      "useCases": [
        "Partner SFTP exchange",
        "Legacy FTP workflow migration",
        "Managed B2B file transfer"
      ],
      "concepts": [
        "Protocols and servers",
        "S3 or EFS storage domains",
        "Identity provider options",
        "Workflow automation"
      ],
      "considerations": [
        "Protocol choice and endpoint type affect reachability and security controls.",
        "S3 and EFS access still depends on role permissions and file-system policies."
      ],
      "docs": "https://docs.aws.amazon.com/transfer/latest/userguide/what-is-aws-transfer-family.html",
      "sources": [
        {
          "title": "AWS Transfer Family documentation",
          "url": "https://docs.aws.amazon.com/transfer/latest/userguide/what-is-aws-transfer-family.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "transform",
      "name": "AWS Transform",
      "shortName": "Transform",
      "category": "migration",
      "summary": "Accelerates infrastructure, application, and code transformation with agentic workflows.",
      "details": "AWS Transform provides specialized workflows for migration discovery, planning, landing zones, network migration, and modernization. AWS describes it as the successor path for capabilities from Migration Hub and Application Discovery Service, with new projects started directly in Transform.",
      "useCases": [
        "Discover and plan server migration waves",
        "Modernize mainframe or VMware workloads",
        "Create landing-zone and network migration plans"
      ],
      "concepts": [
        "specialized transformation workflows",
        "application grouping and dependency analysis",
        "migration execution can coordinate AWS MGN",
        "AI-assisted workflow needs human validation"
      ],
      "considerations": [
        "Review generated plans before execution",
        "Service capabilities and supported source platforms vary by workflow"
      ],
      "docs": "https://docs.aws.amazon.com/transform/latest/userguide/",
      "sources": [
        {
          "title": "AWS Transform documentation",
          "url": "https://docs.aws.amazon.com/transform/latest/userguide/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "transit-gateway",
      "name": "AWS Transit Gateway",
      "shortName": "Transit Gateway",
      "category": "network",
      "summary": "Central network hub for connecting VPCs and on-premises networks.",
      "details": "Transit Gateway attaches VPCs, VPNs, and Direct Connect gateways to a regional routing hub. Route tables segment traffic and can be shared across accounts through AWS Resource Access Manager.",
      "useCases": [
        "Many-VPC hub networking",
        "Hybrid network routing",
        "Centralized network segmentation"
      ],
      "concepts": [
        "Attachments and route tables",
        "Association and propagation",
        "Cross-account sharing",
        "VPN and Direct Connect paths"
      ],
      "considerations": [
        "It is a routing hub, not an application proxy or firewall by itself.",
        "Route propagation and segmentation must be explicitly designed."
      ],
      "docs": "https://docs.aws.amazon.com/vpc/latest/tgw/what-is-transit-gateway.html",
      "sources": [
        {
          "title": "AWS Transit Gateway documentation",
          "url": "https://docs.aws.amazon.com/vpc/latest/tgw/what-is-transit-gateway.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "translate",
      "name": "Amazon Translate",
      "shortName": "Translate",
      "category": "ai",
      "summary": "Neural machine translation for text and supported document workflows.",
      "details": "The service translates between supported languages through synchronous APIs or asynchronous batch jobs, with terminology and custom parallel data options for some workflows. Language-pair and feature availability varies.",
      "useCases": [
        "localize product descriptions",
        "translate support case batches",
        "translate chat content in an application"
      ],
      "concepts": [
        "source and target language",
        "terminology",
        "batch translation",
        "parallel data"
      ],
      "considerations": [
        "Review regulated or high-impact translations with qualified people",
        "language features differ by pair."
      ],
      "docs": "https://docs.aws.amazon.com/translate/latest/dg/what-is.html",
      "sources": [
        {
          "title": "Amazon Translate documentation",
          "url": "https://docs.aws.amazon.com/translate/latest/dg/what-is.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "trusted-advisor",
      "name": "AWS Trusted Advisor",
      "shortName": "Trusted Advisor",
      "category": "management",
      "summary": "Surfaces recommendations across AWS cost, security, fault tolerance, and service limits.",
      "details": "Trusted Advisor checks account configurations against AWS best practices, with check availability depending on support plan and service evolution. Organizations can aggregate recommendations through supported integrations and use them to prioritize account review.",
      "useCases": [
        "Find exposed resources or security gaps",
        "Identify cost optimization opportunities",
        "Review service quotas and resiliency checks"
      ],
      "concepts": [
        "checks span multiple optimization categories",
        "check availability depends on plan",
        "Organizations view can aggregate results",
        "Service Quotas handles quota management workflows"
      ],
      "considerations": [
        "Check status and eligibility for each recommendation",
        "Recommendations need workload owner validation"
      ],
      "docs": "https://docs.aws.amazon.com/awssupport/latest/user/trusted-advisor.html",
      "sources": [
        {
          "title": "AWS Trusted Advisor documentation",
          "url": "https://docs.aws.amazon.com/awssupport/latest/user/trusted-advisor.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "notifications",
      "name": "AWS User Notifications",
      "shortName": "User Notifications",
      "category": "management",
      "summary": "Centralizes supported AWS service notifications and lets users configure delivery to selected channels.",
      "details": "Notification configurations define which events matter, how they are filtered, and where they are delivered, such as the console notification center or supported email/chat channels. AWS Health, security, and service events can be routed through the service where supported.",
      "useCases": [
        "send selected AWS Health events to an operations team",
        "filter service notifications by account, Region, or event type",
        "review alerts centrally in the console"
      ],
      "concepts": [
        "notification configurations define event filters and channels",
        "aggregation can combine related notifications",
        "AWS Chatbot integrations deliver selected notifications to chat channels"
      ],
      "considerations": [
        "only supported event sources and destinations are available",
        "notification delivery does not replace incident ownership or event retention controls"
      ],
      "docs": "https://docs.aws.amazon.com/notifications/latest/userguide/what-is-service.html",
      "sources": [
        {
          "title": "What is AWS User Notifications?",
          "url": "https://docs.aws.amazon.com/notifications/latest/userguide/what-is-service.html"
        },
        {
          "title": "AWS User Notifications and AWS Health",
          "url": "https://docs.aws.amazon.com/notifications/latest/userguide/managed-notifications-health.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "verified-access",
      "name": "AWS Verified Access",
      "shortName": "Verified Access",
      "category": "network",
      "summary": "Provides application access based on identity and device context without a VPN.",
      "details": "Verified Access evaluates access requests against trust providers and access policies, then proxies approved access to configured application endpoints. It can integrate with identity providers, device trust, and CloudWatch logging.",
      "useCases": [
        "Private web application access",
        "Zero-trust workforce access",
        "Context-aware authorization"
      ],
      "concepts": [
        "Verified Access instances and groups",
        "Trust providers",
        "Access policies",
        "Application endpoints"
      ],
      "considerations": [
        "The service evaluates access; application authorization remains a separate responsibility.",
        "Trust providers, supported protocols, and endpoint types constrain designs."
      ],
      "docs": "https://docs.aws.amazon.com/verified-access/latest/ug/what-is-verified-access.html",
      "sources": [
        {
          "title": "AWS Verified Access documentation",
          "url": "https://docs.aws.amazon.com/verified-access/latest/ug/what-is-verified-access.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "verified-permissions",
      "name": "Amazon Verified Permissions",
      "shortName": "Verified Permissions",
      "category": "security",
      "summary": "Evaluates fine-grained application authorization using Cedar policies.",
      "details": "Verified Permissions stores Cedar policies and schemas and evaluates application authorization requests. Applications call the service at decision points; identity authentication remains in the application or an identity provider such as Cognito.",
      "useCases": [
        "Authorize multi-tenant app actions",
        "Manage policy-based access rules",
        "Centralize authorization decisions"
      ],
      "concepts": [
        "Cedar is the policy language",
        "policy stores hold schema and policies",
        "IsAuthorized evaluates principal/action/resource context",
        "Cognito identities can inform requests"
      ],
      "considerations": [
        "Application must enforce returned decisions",
        "Design schemas and policy administration carefully"
      ],
      "docs": "https://docs.aws.amazon.com/verifiedpermissions/latest/userguide/what-is-avp.html",
      "sources": [
        {
          "title": "Amazon Verified Permissions documentation",
          "url": "https://docs.aws.amazon.com/verifiedpermissions/latest/userguide/what-is-avp.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "vpc",
      "name": "Amazon VPC",
      "shortName": "VPC",
      "category": "network",
      "summary": "A logically isolated virtual network for AWS resources.",
      "details": "A VPC defines IP ranges, subnets, route tables, and network boundaries in a Region. It supports public, private, and isolated subnet designs and connects to gateways, endpoints, VPNs, and other AWS network services.",
      "useCases": [
        "Workload network foundations",
        "Multi-tier application networks",
        "Private and hybrid connectivity"
      ],
      "concepts": [
        "CIDR blocks and subnets",
        "Route tables and gateways",
        "Security groups and network ACLs",
        "VPC endpoints"
      ],
      "considerations": [
        "VPCs are regional and subnet placements are Availability Zone scoped.",
        "Overlapping IP ranges can complicate routing and connectivity."
      ],
      "docs": "https://docs.aws.amazon.com/vpc/latest/userguide/what-is-amazon-vpc.html",
      "sources": [
        {
          "title": "Amazon VPC documentation",
          "url": "https://docs.aws.amazon.com/vpc/latest/userguide/what-is-amazon-vpc.html"
        },
        {
          "title": "VPC subnet types and routing",
          "url": "https://docs.aws.amazon.com/vpc/latest/userguide/configure-subnets.html"
        },
        {
          "title": "NAT gateway connectivity types",
          "url": "https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html"
        },
        {
          "title": "Regional NAT gateways",
          "url": "https://docs.aws.amazon.com/vpc/latest/userguide/nat-gateways-regional.html"
        },
        {
          "title": "NAT gateway basics",
          "url": "https://docs.aws.amazon.com/vpc/latest/userguide/nat-gateway-basics.html"
        }
      ],
      "status": "active",
      "kind": "service",
      "topics": [
        {
          "title": "CIDR blocks and subnets",
          "bullets": [
            "VPC IPv4 CIDR block sizes range from /16 (largest) to /28 (smallest).",
            "Use RFC 1918 private ranges and keep them unique across all accounts and Regions.",
            "The primary CIDR block cannot be changed after creation; secondary blocks can be added.",
            "Each subnet reserves five addresses, so a /28 has 11 usable for ENIs and endpoints.",
            "A subnet sits in one Availability Zone; spread each tier across at least two."
          ]
        },
        {
          "title": "Public and private subnets",
          "bullets": [
            "A subnet is public when its route table has a direct route to an internet gateway.",
            "The gateway alone is not enough: the instance also needs a public IPv4 or IPv6 address.",
            "Private subnets have no direct IGW route; outbound IPv4 internet traffic can use NAT.",
            "Egress-only internet gateways allow outbound IPv6 and block internet-initiated inbound.",
            "Three tiers: public for internet-facing load balancers, private for apps, isolated for data."
          ]
        },
        {
          "title": "Route tables",
          "bullets": [
            "Every subnet is associated with exactly one route table; a table can serve many subnets.",
            "Subnets without an explicit association use the VPC's main route table.",
            "The local route for the VPC CIDR is always present and cannot be deleted.",
            "Routes match by longest prefix; a /24 route wins over a /16 for the same packet.",
            "Keep the main route table free of custom routes; create named tables per tier."
          ]
        },
        {
          "title": "NAT gateways",
          "bullets": [
            "A zonal public NAT gateway needs a public subnet and Elastic IP; private NAT uses no EIP.",
            "Private subnets send 0.0.0.0/0 to the NAT gateway ID in their route table.",
            "Use one zonal NAT per AZ, or a regional NAT gateway that expands across workload AZs.",
            "NAT charges cover AZ-hours and GB processed; cross-AZ traffic can add transfer charges.",
            "Idle TCP flows are dropped after a fixed timeout; use keepalives on long connections."
          ]
        },
        {
          "title": "Security groups",
          "bullets": [
            "Security groups are stateful; return traffic of an allowed connection is automatic.",
            "Allow rules only; anything not allowed is denied. There are no deny rules.",
            "They attach to network interfaces, not subnets; one instance can carry several groups.",
            "A rule can name another security group as its source, so membership follows instances.",
            "New groups allow no inbound traffic. The default group allows only its own members."
          ]
        },
        {
          "title": "Network ACLs",
          "bullets": [
            "Network ACLs are stateless: inbound and outbound rules are checked separately.",
            "Return traffic must match an explicit rule, so allow the peer's ephemeral port range.",
            "Rules are evaluated by number, lowest first; the first match decides.",
            "Each subnet has exactly one network ACL; the default ACL allows all traffic.",
            "A custom network ACL denies everything until you add rules; leave gaps in rule numbers."
          ]
        },
        {
          "title": "VPC endpoints",
          "bullets": [
            "Gateway endpoints cover S3 and DynamoDB only; they are a route table target, not an ENI.",
            "Gateway endpoints have no hourly charge and are not reachable from on-premises networks.",
            "Interface endpoints (AWS PrivateLink) place an ENI with a private IP in your subnets.",
            "Interface endpoints are billed per hour per AZ and per GB; they use security groups.",
            "Private DNS on interface endpoints makes standard service hostnames resolve to them."
          ]
        },
        {
          "title": "Peering and Transit Gateway",
          "bullets": [
            "VPC peering connects two VPCs only; it is not transitive through a third VPC.",
            "Peering needs non-overlapping CIDR blocks and routes added in both VPCs' route tables.",
            "Transit Gateway is a regional hub; route tables control which attachments can talk.",
            "Transit Gateway routes between attachments transitively, avoiding a full peering mesh.",
            "Peering: per GB across AZs or Regions. Transit Gateway: per attachment-hour and per GB."
          ]
        },
        {
          "title": "VPN and Direct Connect",
          "bullets": [
            "Site-to-Site VPN gives two IPsec tunnels per connection; configure both for redundancy.",
            "Attach VPNs to a virtual private gateway or Transit Gateway; pick static or BGP.",
            "Direct Connect is a private link to AWS; traffic is not encrypted by default.",
            "A Direct Connect gateway links virtual interfaces to VGWs or Transit Gateways.",
            "Overlapping on-premises and VPC ranges break routing; plan address space early."
          ]
        },
        {
          "title": "DNS and Route 53 Resolver",
          "bullets": [
            "Amazon DNS server listens at the VPC base address plus two (10.0.0.2 in 10.0.0.0/16).",
            "DNS support and DNS hostnames are separate settings; private endpoint DNS needs both.",
            "Route 53 Resolver inbound endpoints let on-premises DNS query private zones in the VPC.",
            "Outbound endpoints plus forwarding rules send chosen domains to on-premises DNS.",
            "Resolver endpoints use subnet ENIs; billing covers endpoint hours and queries."
          ]
        },
        {
          "title": "Flow logs and monitoring",
          "bullets": [
            "Flow logs capture IP traffic metadata for a VPC, a subnet, or one network interface.",
            "Send logs to CloudWatch Logs, S3 or Firehose; each record shows accept or reject.",
            "Some AWS-internal traffic, such as instance metadata and Amazon DNS, is not logged.",
            "Flow logs do not affect traffic but publish in batches on an aggregation interval.",
            "Reachability Analyzer checks a path and names the component that blocks it."
          ]
        },
        {
          "title": "Common pitfalls",
          "bullets": [
            "Direct internet access needs an IGW route and public address; private IPv4 egress can use NAT.",
            "Missing ephemeral return ports in a network ACL cause timeouts that look like bugs.",
            "Overlapping CIDRs block peering and hybrid routing; fix ranges before building.",
            "A single zonal NAT is an AZ outage risk; use per-AZ gateways or regional NAT.",
            "Admin ports open to 0.0.0.0/0 expose hosts; limit sources to SGs or known ranges."
          ]
        }
      ],
      "guide": "services/vpc.html"
    },
    {
      "id": "vpc-lattice",
      "name": "Amazon VPC Lattice",
      "shortName": "VPC Lattice",
      "category": "network",
      "summary": "Application networking across services, resources, VPCs, and accounts.",
      "details": "VPC Lattice creates service networks with connectivity, service discovery, access policies, and observability for supported service targets. VPCs associate to service networks, and PrivateLink-powered service-network endpoints can extend access from unassociated VPCs or on-premises paths.",
      "useCases": [
        "Cross-VPC service communication",
        "Multi-account microservice networks",
        "Service-level access policy"
      ],
      "concepts": [
        "Services and target groups",
        "Service networks and VPC associations",
        "Auth policies",
        "Service-network endpoints"
      ],
      "considerations": [
        "Lattice is an application networking layer with policy and routing behavior to configure.",
        "PrivateLink endpoints are an optional connection mechanism for a service network."
      ],
      "docs": "https://docs.aws.amazon.com/vpc-lattice/latest/ug/what-is-vpc-lattice.html",
      "sources": [
        {
          "title": "What is VPC Lattice?",
          "url": "https://docs.aws.amazon.com/vpc-lattice/latest/ug/what-is-vpc-lattice.html"
        },
        {
          "title": "PrivateLink service-network endpoint",
          "url": "https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-service-networks.html"
        }
      ],
      "status": "active",
      "kind": "service"
    },
    {
      "id": "waf",
      "name": "AWS WAF",
      "shortName": "WAF",
      "category": "security",
      "summary": "Filters HTTP and HTTPS requests to supported application resources.",
      "details": "WAF protection packs (web ACLs) combine managed or custom rules, rate limits, and request inspection. WAF integrates with services such as CloudFront, Application Load Balancers, API Gateway, and AppSync; tuning is needed to avoid blocking legitimate traffic.",
      "useCases": [
        "Block common web exploits",
        "Rate-limit abusive endpoints",
        "Apply geographic or IP-based rules"
      ],
      "concepts": [
        "web ACL associates with protected resource",
        "managed rule groups provide maintained detections",
        "rules can inspect request components",
        "logs can flow to supported destinations"
      ],
      "considerations": [
        "Test rules in count mode before blocking",
        "Rule limits and inspection scope vary by integration"
      ],
      "docs": "https://docs.aws.amazon.com/waf/latest/developerguide/what-is-aws-waf.html",
      "sources": [
        {
          "title": "AWS WAF documentation",
          "url": "https://docs.aws.amazon.com/waf/latest/developerguide/what-is-aws-waf.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "wavelength",
      "name": "AWS Wavelength",
      "shortName": "Wavelength",
      "category": "compute",
      "summary": "Places AWS compute and storage in participating telecom networks for mobile edge applications.",
      "details": "Wavelength Zones are AWS infrastructure embedded in carrier networks and accessed through a parent Region. Applications use VPC subnets in a Wavelength Zone and can interact with AWS services through the associated Region.",
      "useCases": [
        "Low-latency 5G applications",
        "Interactive media and gaming",
        "Connected-device processing near users"
      ],
      "concepts": [
        "Wavelength Zones",
        "Carrier network integration",
        "VPC subnets and carrier gateways",
        "Regional service relationship"
      ],
      "considerations": [
        "Availability depends on carrier, location, account, and supported instance types.",
        "It is a specialized deployment location, not a general-purpose Region replacement."
      ],
      "docs": "https://docs.aws.amazon.com/wavelength/latest/developerguide/what-is-wavelength.html",
      "sources": [
        {
          "title": "AWS Wavelength documentation",
          "url": "https://docs.aws.amazon.com/wavelength/latest/developerguide/what-is-wavelength.html"
        }
      ],
      "status": "active",
      "kind": "tool"
    },
    {
      "id": "well-architected-agent",
      "name": "AWS Well-Architected Agent",
      "shortName": "Well-Architected Agent",
      "category": "management",
      "summary": "Preview service that continuously analyzes configured AWS workloads and generates prioritized optimization recommendations.",
      "details": "Agent profiles define accounts, Regions, business goals, and optimization pillars; cross-account roles grant resource discovery access. The agent produces resource, application, and infrastructure-as-code architecture recommendations, with updates refreshed on a weekly cadence.",
      "useCases": [
        "prioritize cost, security, resilience, and performance work",
        "review IaC before deploying a workload",
        "correlate resource recommendations into application-level improvements"
      ],
      "concepts": [
        "profiles scope accounts, Regions, and business goals",
        "execution and access roles enable cross-account analysis",
        "recommendations can target resources, applications, or IaC",
        "four pillars cover cost, security, resilience, and performance"
      ],
      "considerations": [
        "public preview and support-plan eligibility apply",
        "recommendations and generated IaC need human review before implementation"
      ],
      "docs": "https://docs.aws.amazon.com/wellarchitected/latest/userguide/agent.html",
      "sources": [
        {
          "title": "What is AWS Well-Architected Agent (preview)?",
          "url": "https://docs.aws.amazon.com/wellarchitected/latest/userguide/agent.html"
        },
        {
          "title": "AWS Well-Architected Agent concepts",
          "url": "https://docs.aws.amazon.com/wellarchitected/latest/userguide/agent-concepts.html"
        }
      ],
      "status": "restricted",
      "statusNote": "Public preview; AWS documents availability for Business+ support plans and higher, with profiles hosted in three US Regions.",
      "kind": "service"
    },
    {
      "id": "well-architected",
      "name": "AWS Well-Architected Tool",
      "shortName": "Well-Architected Tool",
      "category": "management",
      "summary": "Reviews workloads against AWS architectural best practices.",
      "details": "The tool organizes a workload review around the Well-Architected Framework pillars and records answers, risks, and improvement plans. It facilitates review and tracking; it does not automatically inspect every architecture decision or guarantee workload outcomes.",
      "useCases": [
        "Run a workload architecture review",
        "Track high-risk issues and improvement actions",
        "Compare workload milestones over time"
      ],
      "concepts": [
        "workloads contain review milestones",
        "lenses add question sets",
        "risks map to pillar best practices",
        "improvement plan records actions"
      ],
      "considerations": [
        "Answers depend on accurate workload context",
        "Revisit reviews as architectures change"
      ],
      "docs": "https://docs.aws.amazon.com/wellarchitected/latest/userguide/well-architected.html",
      "sources": [
        {
          "title": "AWS Well-Architected Tool documentation",
          "url": "https://docs.aws.amazon.com/wellarchitected/latest/userguide/well-architected.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "wickr",
      "name": "AWS Wickr",
      "shortName": "Wickr",
      "category": "business",
      "summary": "Secure messaging and collaboration service for controlled organizational communication.",
      "details": "Wickr provides encrypted messages, calls, and file sharing through managed organizational networks. Administrators set access and retention controls; federation and deployment options depend on plan and configuration.",
      "useCases": [
        "secure team messaging",
        "regulated collaboration",
        "controlled external communication"
      ],
      "concepts": [
        "Wickr networks define administrative boundaries",
        "Messages and calls use end-to-end encryption features",
        "Network administrators manage provisioning and policies"
      ],
      "considerations": [
        "Encryption does not replace endpoint and identity controls",
        "Check plan, Region, and federation features."
      ],
      "docs": "https://docs.aws.amazon.com/wickr/",
      "sources": [
        {
          "title": "AWS Wickr documentation",
          "url": "https://docs.aws.amazon.com/wickr/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "workmail",
      "name": "Amazon WorkMail",
      "shortName": "WorkMail",
      "category": "business",
      "summary": "Managed business email and calendars for existing customers; AWS support ends March 31, 2027.",
      "details": "WorkMail provides hosted mailboxes and calendaring with common email clients and protocols. AWS stopped accepting customers April 30, 2026 and will end service support March 31, 2027; existing users should plan export and migration.",
      "useCases": [
        "operate legacy mailboxes",
        "inventory calendar dependencies",
        "prepare mailbox export"
      ],
      "concepts": [
        "Organizations configure domains, users, and mailboxes",
        "Clients connect through supported protocols",
        "Mailbox export is part of migration planning"
      ],
      "considerations": [
        "No new customers after April 30, 2026; support ends March 31, 2027",
        "Plan data export and cutover ahead of the end date."
      ],
      "docs": "https://docs.aws.amazon.com/workmail/latest/adminguide/workmail-end-of-support.html",
      "sources": [
        {
          "title": "Amazon WorkMail documentation",
          "url": "https://docs.aws.amazon.com/workmail/latest/adminguide/workmail-end-of-support.html"
        }
      ],
      "status": "restricted",
      "statusNote": "Restricted to existing customers; AWS stopped new-customer sign-ups April 30, 2026 and support ends March 31, 2027. Verified 2026-10-08.",
      "kind": "service"
    },
    {
      "id": "workspaces",
      "name": "Amazon WorkSpaces",
      "shortName": "WorkSpaces",
      "category": "enduser",
      "summary": "Managed virtual desktops delivered from AWS infrastructure.",
      "details": "WorkSpaces offers personal persistent desktops and pooled application desktops through managed client access. Administrators choose bundles, directories, protocols, and running modes; options differ across WorkSpaces products.",
      "useCases": [
        "employee virtual desktops",
        "contractor desktop access",
        "remote application workspaces"
      ],
      "concepts": [
        "Directory configuration connects users to desktops",
        "Bundles define compute, memory, storage, and OS choices",
        "Protocols stream display and input to clients"
      ],
      "considerations": [
        "Region, protocol, and bundle support varies",
        "Always-on and auto-stop choices affect responsiveness and cost."
      ],
      "docs": "https://docs.aws.amazon.com/workspaces/",
      "sources": [
        {
          "title": "Amazon WorkSpaces documentation",
          "url": "https://docs.aws.amazon.com/workspaces/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "workspaces-applications",
      "name": "Amazon WorkSpaces Applications",
      "shortName": "WorkSpaces Applications",
      "category": "enduser",
      "summary": "Streams desktop applications to users without local installation.",
      "details": "WorkSpaces Applications packages apps into images and streams sessions from managed fleets. Users connect through a browser or client while administrators control fleet size, identity, and image updates.",
      "useCases": [
        "graphics apps for students",
        "temporary contractor software",
        "central access to legacy Windows apps"
      ],
      "concepts": [
        "Application images define installed software",
        "Fleets provide compute for streaming sessions",
        "Configured storage can preserve user files and settings"
      ],
      "considerations": [
        "Image maintenance and fleet sizing need planning",
        "Capacity model and session duration affect cost."
      ],
      "docs": "https://docs.aws.amazon.com/appstream2/",
      "sources": [
        {
          "title": "Amazon WorkSpaces Applications documentation",
          "url": "https://docs.aws.amazon.com/appstream2/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "workspaces-core",
      "name": "Amazon WorkSpaces Core",
      "shortName": "WorkSpaces Core",
      "category": "enduser",
      "summary": "Infrastructure and APIs for partner virtual desktop platforms on AWS.",
      "details": "WorkSpaces Core enables qualified VDI partners to build services on AWS infrastructure. The partner remains responsible for its control plane and user experience while AWS supplies supported desktop resources.",
      "useCases": [
        "extend partner VDI to AWS",
        "add cloud desktop capacity",
        "support hybrid desktop operations"
      ],
      "concepts": [
        "Partner software integrates with Core APIs",
        "AWS infrastructure hosts desktop resources",
        "Partner determines brokering and user experience"
      ],
      "considerations": [
        "Supported partners and Regions constrain choices",
        "Coordinate responsibility boundaries and licensing."
      ],
      "docs": "https://docs.aws.amazon.com/workspaces-core/",
      "sources": [
        {
          "title": "Amazon WorkSpaces Core documentation",
          "url": "https://docs.aws.amazon.com/workspaces-core/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "workspaces-secure-browser",
      "name": "Amazon WorkSpaces Secure Browser",
      "shortName": "WorkSpaces Secure Browser",
      "category": "enduser",
      "summary": "Managed isolated browser access to approved websites and SaaS applications.",
      "details": "Secure Browser launches sessions in an AWS-managed environment so users can reach approved web apps without directly exposing local endpoints. Administrators configure identity, network access, and browser policies; it does not provide a general desktop.",
      "useCases": [
        "private admin portal access",
        "contractor access to internal web apps",
        "isolated SaaS sessions"
      ],
      "concepts": [
        "Portals define user-facing access points",
        "Network settings control reachable websites",
        "Browser policies govern session behavior and data transfer"
      ],
      "considerations": [
        "Identity and network setup require care",
        "Session capacity and duration drive cost."
      ],
      "docs": "https://docs.aws.amazon.com/workspaces-web/",
      "sources": [
        {
          "title": "Amazon WorkSpaces Secure Browser documentation",
          "url": "https://docs.aws.amazon.com/workspaces-web/"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    },
    {
      "id": "workspaces-thin-client",
      "name": "Amazon WorkSpaces Thin Client",
      "shortName": "WorkSpaces Thin Client",
      "category": "enduser",
      "summary": "Purpose-built endpoint for WorkSpaces desktops; AWS support ends March 31, 2027.",
      "details": "Devices are registered to managed environments with activation codes to access supported desktops. AWS stopped new-customer onboarding April 20, 2026 and ends support March 31, 2027; current customers may continue during transition.",
      "useCases": [
        "shared desk desktop access",
        "standardized cloud desktop endpoint",
        "inventory endpoints for migration"
      ],
      "concepts": [
        "Environments hold device and software-set configuration",
        "Activation codes register devices",
        "Software sets deliver OS and application updates"
      ],
      "considerations": [
        "AWS support ends March 31, 2027; existing users should plan alternatives",
        "Peripheral compatibility and updates affect experience."
      ],
      "docs": "https://docs.aws.amazon.com/workspaces-thin-client/latest/ag/what-is-thin-client.html",
      "sources": [
        {
          "title": "Amazon WorkSpaces Thin Client documentation",
          "url": "https://docs.aws.amazon.com/workspaces-thin-client/latest/ag/what-is-thin-client.html"
        }
      ],
      "status": "restricted",
      "statusNote": "Restricted to existing customers; AWS stopped onboarding April 20, 2026 and support ends March 31, 2027. Verified 2026-10-08.",
      "kind": "service"
    },
    {
      "id": "x-ray",
      "name": "AWS X-Ray",
      "shortName": "X-Ray",
      "category": "developer",
      "summary": "Traces requests across distributed applications and services.",
      "details": "X-Ray collects trace segments and subsegments to show request paths, timing, and errors across instrumented applications. Service maps help identify dependencies; OpenTelemetry-based instrumentation is also supported in AWS observability workflows.",
      "useCases": [
        "Trace latency across microservices",
        "Find failing downstream calls",
        "Inspect request-level service maps"
      ],
      "concepts": [
        "traces are composed of segments",
        "sampling controls captured requests",
        "annotations and metadata aid filtering",
        "service maps derive from trace relationships"
      ],
      "considerations": [
        "Instrument all relevant request paths for useful traces",
        "Sampling can omit individual requests"
      ],
      "docs": "https://docs.aws.amazon.com/xray/latest/devguide/aws-xray.html",
      "sources": [
        {
          "title": "AWS X-Ray documentation",
          "url": "https://docs.aws.amazon.com/xray/latest/devguide/aws-xray.html"
        }
      ],
      "status": "active",
      "statusNote": "",
      "kind": "service"
    }
  ],
  "edges": [
    {
      "source": "agentcore",
      "target": "s3",
      "type": "foundation",
      "label": "AgentCore managed data storage",
      "detail": "AWS documents AgentCore data at rest in DynamoDB and S3 under AWS-owned keys by default. This describes service-managed storage and does not mean each agent must configure an S3 bucket.",
      "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-encryption.html"
    },
    {
      "source": "agentcore",
      "target": "dynamodb",
      "type": "foundation",
      "label": "AgentCore managed data storage",
      "detail": "AWS documents DynamoDB as one of AgentCore’s service-managed data stores. Customers do not provision a DynamoDB table as a universal prerequisite for Runtime or Gateway.",
      "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-encryption.html"
    },
    {
      "source": "agentcore",
      "target": "lambda",
      "type": "integration",
      "label": "Gateway invokes Lambda tools",
      "detail": "A Gateway can expose a Lambda function as a tool when configured; its execution role needs permission to invoke the selected function. This target is optional.",
      "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-prerequisites-permissions.html"
    },
    {
      "source": "agentcore",
      "target": "iam",
      "type": "foundation",
      "label": "Roles authorize selected features",
      "detail": "AgentCore components assume IAM roles to reach configured targets and resources. Required permissions depend on the component and target rather than a single broad role.",
      "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-prerequisites-permissions.html"
    },
    {
      "source": "agentcore",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Optional logs and telemetry",
      "detail": "AgentCore components can publish logs and observability signals to CloudWatch; VPC-connected runtimes need the documented Logs endpoint when they lack internet access.",
      "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-vpc.html"
    },
    {
      "source": "agentcore",
      "target": "kms",
      "type": "integration",
      "label": "Customer-managed encryption keys",
      "detail": "AgentCore encrypts data by default with AWS-owned keys; customer-managed KMS keys are supported for selected resources such as Memory and Gateway.",
      "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-encryption.html"
    },
    {
      "source": "agentcore",
      "target": "vpc",
      "type": "integration",
      "label": "Optional private resource access",
      "detail": "Runtime and built-in tools can attach to a VPC to reach private resources. This is an explicit network configuration and changes internet reachability.",
      "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-vpc.html"
    },
    {
      "source": "agentcore",
      "target": "ecr",
      "type": "integration",
      "label": "Container image source for runtime",
      "detail": "Container-based runtime deployments can use images in ECR. In VPC mode, AWS documents ECR and S3 endpoints for retrieving image layers; code deployment is another option.",
      "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-vpc.html"
    },
    {
      "source": "agentcore",
      "target": "bedrock",
      "type": "integration",
      "label": "Invoke foundation models in an agent",
      "detail": "Agent applications may call foundation models through Amazon Bedrock. AgentCore Runtime itself is not a requirement to use Bedrock model APIs.",
      "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/what-is-bedrock-agentcore.html"
    },
    {
      "source": "athena",
      "target": "s3",
      "type": "pattern",
      "label": "Query data stored in S3",
      "detail": "Athena commonly runs SQL against data in S3, using selected table metadata and formats. S3 is the storage location for this pattern; Athena does not require every query to use only S3.",
      "url": "https://docs.aws.amazon.com/athena/latest/ug/what-is.html"
    },
    {
      "source": "athena",
      "target": "glue",
      "type": "integration",
      "label": "Use the Glue Data Catalog",
      "detail": "Athena can use Glue Data Catalog metadata to discover databases and tables. Other catalogs and federated sources are also supported.",
      "url": "https://docs.aws.amazon.com/athena/latest/ug/what-is.html"
    },
    {
      "source": "glue",
      "target": "s3",
      "type": "pattern",
      "label": "Catalog and transform lake data",
      "detail": "Glue crawlers and ETL jobs can discover and process S3 data into analytics-ready datasets. S3 is a common source and destination, not a universal prerequisite for every Glue feature.",
      "url": "https://docs.aws.amazon.com/glue/latest/dg/what-is-glue.html"
    },
    {
      "source": "lake-formation",
      "target": "glue",
      "type": "integration",
      "label": "Govern catalog resources",
      "detail": "Lake Formation permissions can govern Data Catalog databases and tables used by analytics services. This integration is configured; Glue jobs do not inherently require Lake Formation.",
      "url": "https://docs.aws.amazon.com/lake-formation/latest/dg/what-is-lake-formation.html"
    },
    {
      "source": "emr",
      "target": "s3",
      "type": "pattern",
      "label": "Process lake data",
      "detail": "EMR applications commonly read and write datasets in S3, while some deployments also use HDFS or other storage. S3 is an architecture choice, not a hard dependency.",
      "url": "https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-what-is-emr.html"
    },
    {
      "source": "redshift",
      "target": "s3",
      "type": "integration",
      "label": "Query lake data with Spectrum",
      "detail": "Redshift Spectrum can query selected data in S3 from Redshift SQL workflows. Configure external schemas and access; it is optional to the warehouse.",
      "url": "https://docs.aws.amazon.com/redshift/latest/dg/c-using-spectrum.html"
    },
    {
      "source": "kinesis",
      "target": "firehose",
      "type": "integration",
      "label": "Deliver stream records",
      "detail": "Data Firehose can be configured as a consumer path for Kinesis Data Streams and deliver records to supported destinations. This is an optional managed delivery path.",
      "url": "https://docs.aws.amazon.com/firehose/latest/dev/what-is-this-service.html"
    },
    {
      "source": "managed-flink",
      "target": "kinesis",
      "type": "integration",
      "label": "Process a Kinesis stream",
      "detail": "Managed Flink applications can consume Kinesis Data Streams as a streaming source when configured. Kafka and other connectors are alternative sources.",
      "url": "https://docs.aws.amazon.com/managed-flink/latest/java/what-is.html"
    },
    {
      "source": "msk",
      "target": "s3",
      "type": "pattern",
      "label": "Archive or stage Kafka data",
      "detail": "Kafka Connect or a configured delivery integration can move topic data to S3 for downstream analysis. This is a selected data pipeline, not a required MSK dependency.",
      "url": "https://docs.aws.amazon.com/msk/latest/developerguide/what-is-msk.html"
    },
    {
      "source": "quick",
      "target": "redshift",
      "type": "integration",
      "label": "Visualize warehouse data",
      "detail": "Quick Sight, within Amazon Quick, can connect to Redshift datasets for analyses and dashboards. The BI service also supports other data sources.",
      "url": "https://docs.aws.amazon.com/quick/latest/userguide/what-is.html"
    },
    {
      "source": "datazone",
      "target": "glue",
      "type": "integration",
      "label": "Publish cataloged data assets",
      "detail": "DataZone can use Glue cataloged assets in data publishing and discovery workflows. Catalog integration and project permissions require setup.",
      "url": "https://docs.aws.amazon.com/datazone/latest/userguide/what-is-datazone.html"
    },
    {
      "source": "clean-rooms",
      "target": "s3",
      "type": "integration",
      "label": "Configure collaboration data",
      "detail": "Clean Rooms supports configured data sources and tables, including S3-backed workflows through documented integrations. Data must be explicitly onboarded and governed.",
      "url": "https://docs.aws.amazon.com/clean-rooms/latest/userguide/what-is.html"
    },
    {
      "source": "dms",
      "target": "s3",
      "type": "integration",
      "label": "Replicate changes to a data lake",
      "detail": "DMS can write full-load and CDC output to S3 when S3 is selected as a target. This is one target option among supported engines and destinations.",
      "url": "https://docs.aws.amazon.com/dms/latest/userguide/CHAP_Target.S3.html"
    },
    {
      "source": "dms",
      "target": "aurora",
      "type": "integration",
      "label": "Migrate into Aurora",
      "detail": "DMS supports migration and replication tasks involving supported Aurora engines. Check the engine-specific source and target matrix before planning cutover.",
      "url": "https://docs.aws.amazon.com/dms/latest/userguide/CHAP_Introduction.Targets.html"
    },
    {
      "source": "aurora",
      "target": "rds",
      "type": "alternative",
      "label": "Compare relational deployment options",
      "detail": "Aurora is an Amazon RDS database engine family with a distributed cluster storage design; compare supported engines and workload requirements.",
      "url": "https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/CHAP_AuroraOverview.html"
    },
    {
      "source": "aurora-dsql",
      "target": "aurora",
      "type": "alternative",
      "label": "Compare distributed SQL needs",
      "detail": "Aurora DSQL and Aurora address distinct relational architectures. Compare transaction, compatibility, multi-Region, and operational requirements before choosing.",
      "url": "https://docs.aws.amazon.com/aurora-dsql/latest/userguide/what-is-aurora-dsql.html"
    },
    {
      "source": "timestream",
      "target": "dms",
      "type": "pattern",
      "label": "Route replicated data for migration",
      "detail": "A migration design may use DMS and application pipelines to move time-series records to an alternative destination. This is a migration pattern, not a direct DMS-to-Timestream dependency.",
      "url": "https://docs.aws.amazon.com/timestream/latest/developerguide/AmazonTimestreamForLiveAnalytics-availability-change.html"
    },
    {
      "source": "q-business",
      "target": "quick",
      "type": "alternative",
      "label": "Evaluate Amazon Quick for new adoption",
      "detail": "AWS points new Q Business customers to Amazon Quick. Q Business remains available to existing customers under its restricted onboarding status.",
      "url": "https://docs.aws.amazon.com/amazonq/latest/api-reference/"
    },
    {
      "source": "forecast",
      "target": "sagemaker",
      "type": "alternative",
      "label": "Assess SageMaker for forecasting workflows",
      "detail": "AWS lifecycle and migration guidance should drive replacement decisions; SageMaker AI can support custom forecasting workflows, but it is not an automatic drop-in replacement for Forecast.",
      "url": "https://docs.aws.amazon.com/sagemaker/latest/dg/whatis.html"
    },
    {
      "source": "fraud-detector",
      "target": "sagemaker",
      "type": "alternative",
      "label": "Consider custom fraud models",
      "detail": "AWS points users toward alternatives including SageMaker AI deployment of open-source models; this requires building and operating a replacement workflow.",
      "url": "https://docs.aws.amazon.com/frauddetector/latest/ug/frauddetector-availability-change.html"
    },
    {
      "source": "lookout-equipment",
      "target": "iot-sitewise",
      "type": "alternative",
      "label": "Evaluate AWS IoT SiteWise anomaly detection",
      "detail": "AWS recommends AWS IoT SiteWise as an alternative for predictive maintenance and describes migration guidance for existing Lookout for Equipment models. SiteWise is a migration path, not a drop-in replacement.",
      "url": "https://aws.amazon.com/blogs/machine-learning/preserve-access-and-explore-alternatives-for-amazon-lookout-for-equipment/"
    },
    {
      "source": "personalize",
      "target": "s3",
      "type": "integration",
      "label": "Import interaction datasets",
      "detail": "Personalize dataset import jobs can load training data from S3 locations with a configured service role. This is a selected data path for model training.",
      "url": "https://docs.aws.amazon.com/personalize/latest/dg/import-data.html"
    },
    {
      "source": "textract",
      "target": "s3",
      "type": "integration",
      "label": "Analyze documents from S3",
      "detail": "Textract asynchronous document workflows can read input documents from S3 and optionally write output there. Synchronous APIs can use other input forms.",
      "url": "https://docs.aws.amazon.com/textract/latest/dg/async.html"
    },
    {
      "source": "rekognition",
      "target": "s3",
      "type": "integration",
      "label": "Analyze stored images and video",
      "detail": "Rekognition APIs can analyze media stored in S3 for supported workflows. Direct byte input and streaming paths are also available for selected operations.",
      "url": "https://docs.aws.amazon.com/rekognition/latest/dg/images.html"
    },
    {
      "source": "transcribe",
      "target": "s3",
      "type": "integration",
      "label": "Transcribe stored audio",
      "detail": "Batch transcription jobs commonly read audio from S3 and can write transcripts to an S3 output location. Streaming transcription uses a different live input path.",
      "url": "https://docs.aws.amazon.com/transcribe/latest/dg/how-input.html"
    },
    {
      "source": "lex",
      "target": "lambda",
      "type": "integration",
      "label": "Run custom fulfillment",
      "detail": "Lex can invoke a Lambda function for configured dialog or fulfillment hooks. Bots can also use other integration patterns.",
      "url": "https://docs.aws.amazon.com/lexv2/latest/dg/lambda.html"
    },
    {
      "source": "healthlake",
      "target": "s3",
      "type": "integration",
      "label": "Import and export health records",
      "detail": "HealthLake supports import and export workflows involving S3 locations. Configure access and encryption around protected health information.",
      "url": "https://docs.aws.amazon.com/healthlake/latest/devguide/importing-fhir-data.html"
    },
    {
      "source": "healthomics",
      "target": "s3",
      "type": "integration",
      "label": "Stage scientific input data",
      "detail": "HealthOmics workflows can use S3 data sources and outputs through supported workflow definitions. Keep access scoped to the required research datasets.",
      "url": "https://docs.aws.amazon.com/omics/latest/dev/what-is-healthomics.html"
    },
    {
      "source": "kendra",
      "target": "s3",
      "type": "integration",
      "label": "Index S3 document collections",
      "detail": "Kendra provides an S3 data source connector for importing documents into an index. Connector configuration and access policy determine searchable content.",
      "url": "https://docs.aws.amazon.com/kendra/latest/dg/data-source-s3.html"
    },
    {
      "source": "comprehend",
      "target": "s3",
      "type": "integration",
      "label": "Run batch text analysis",
      "detail": "Comprehend batch jobs can read text documents from S3 and write results to configured output locations. Synchronous analysis has different request limits and input forms.",
      "url": "https://docs.aws.amazon.com/comprehend/latest/dg/concepts-processing-modes.html"
    },
    {
      "source": "augmented-ai",
      "target": "sagemaker",
      "type": "integration",
      "label": "Review selected ML predictions",
      "detail": "A2I provides human review workflows for supported SageMaker inference and document analysis integrations. It is an optional human review step.",
      "url": "https://docs.aws.amazon.com/sagemaker/latest/dg/a2i.html"
    },
    {
      "source": "bedrock",
      "target": "s3",
      "type": "pattern",
      "label": "Use S3 as an optional data source",
      "detail": "An application can use S3 with Bedrock to stage or exchange data when its API workflow supports that pattern; no bucket is universally required.",
      "url": "https://docs.aws.amazon.com/bedrock/latest/userguide/what-is-bedrock.html"
    },
    {
      "source": "bedrock",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Bedrock APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/bedrock/latest/userguide/what-is-bedrock.html"
    },
    {
      "source": "sagemaker",
      "target": "s3",
      "type": "pattern",
      "label": "Use S3 as an optional data source",
      "detail": "An application can use S3 with SageMaker AI to stage or exchange data when its API workflow supports that pattern; no bucket is universally required.",
      "url": "https://docs.aws.amazon.com/sagemaker/latest/dg/whatis.html"
    },
    {
      "source": "sagemaker",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call SageMaker AI APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/sagemaker/latest/dg/whatis.html"
    },
    {
      "source": "q-business",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Q Business APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/what-is.html"
    },
    {
      "source": "q-developer",
      "target": "s3",
      "type": "pattern",
      "label": "Use S3 as an optional data source",
      "detail": "An application can use S3 with Q Developer to stage or exchange data when its API workflow supports that pattern; no bucket is universally required.",
      "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/what-is.html"
    },
    {
      "source": "q-developer",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Q Developer APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/amazonq/latest/qdeveloper-ug/what-is.html"
    },
    {
      "source": "lex",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Lex APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/lexv2/latest/dg/what-is.html"
    },
    {
      "source": "polly",
      "target": "s3",
      "type": "pattern",
      "label": "Use S3 as an optional data source",
      "detail": "An application can use S3 with Polly to stage or exchange data when its API workflow supports that pattern; no bucket is universally required.",
      "url": "https://docs.aws.amazon.com/polly/latest/dg/what-is.html"
    },
    {
      "source": "polly",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Polly APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/polly/latest/dg/what-is.html"
    },
    {
      "source": "transcribe",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Transcribe APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/transcribe/latest/dg/what-is.html"
    },
    {
      "source": "translate",
      "target": "s3",
      "type": "pattern",
      "label": "Use S3 as an optional data source",
      "detail": "An application can use S3 with Translate to stage or exchange data when its API workflow supports that pattern; no bucket is universally required.",
      "url": "https://docs.aws.amazon.com/translate/latest/dg/what-is.html"
    },
    {
      "source": "translate",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Translate APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/translate/latest/dg/what-is.html"
    },
    {
      "source": "comprehend",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Comprehend APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/comprehend/latest/dg/what-is.html"
    },
    {
      "source": "rekognition",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Rekognition APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/rekognition/latest/dg/what-is.html"
    },
    {
      "source": "textract",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Textract APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/textract/latest/dg/what-is.html"
    },
    {
      "source": "personalize",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Personalize APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/personalize/latest/dg/what-is-personalize.html"
    },
    {
      "source": "kendra",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Kendra APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/kendra/latest/dg/what-is-kendra.html"
    },
    {
      "source": "forecast",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Forecast APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/forecast/latest/dg/what-is-forecast.html"
    },
    {
      "source": "fraud-detector",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call Fraud Detector APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/frauddetector/latest/ug/what-is-frauddetector.html"
    },
    {
      "source": "augmented-ai",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call A2I APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/sagemaker/latest/dg/a2i.html"
    },
    {
      "source": "healthomics",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call HealthOmics APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/omics/latest/dev/what-is-healthomics.html"
    },
    {
      "source": "healthimaging",
      "target": "s3",
      "type": "pattern",
      "label": "Use S3 as an optional data source",
      "detail": "An application can use S3 with HealthImaging to stage or exchange data when its API workflow supports that pattern; no bucket is universally required.",
      "url": "https://docs.aws.amazon.com/healthimaging/latest/devguide/what-is.html"
    },
    {
      "source": "healthimaging",
      "target": "lambda",
      "type": "pattern",
      "label": "Call the service from application logic",
      "detail": "An application can call HealthImaging APIs from Lambda using the AWS SDK and scoped IAM permissions; this is an optional application pattern.",
      "url": "https://docs.aws.amazon.com/healthimaging/latest/devguide/what-is.html"
    },
    {
      "source": "glue",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use Glue resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/glue/latest/dg/what-is-glue.html"
    },
    {
      "source": "lake-formation",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use Lake Formation resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/lake-formation/latest/dg/what-is-lake-formation.html"
    },
    {
      "source": "emr",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use EMR resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-what-is-emr.html"
    },
    {
      "source": "redshift",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use Redshift resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/redshift/latest/mgmt/welcome.html"
    },
    {
      "source": "opensearch",
      "target": "s3",
      "type": "pattern",
      "label": "Use S3 in a data pipeline",
      "detail": "A common OpenSearch Service architecture reads or writes selected data in S3 when that integration is configured; it is not a universal prerequisite.",
      "url": "https://docs.aws.amazon.com/opensearch-service/latest/developerguide/what-is.html"
    },
    {
      "source": "opensearch",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use OpenSearch Service resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/opensearch-service/latest/developerguide/what-is.html"
    },
    {
      "source": "kinesis",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use Kinesis Data Streams resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/streams/latest/dev/introduction.html"
    },
    {
      "source": "firehose",
      "target": "s3",
      "type": "pattern",
      "label": "Use S3 in a data pipeline",
      "detail": "A common Data Firehose architecture reads or writes selected data in S3 when that integration is configured; it is not a universal prerequisite.",
      "url": "https://docs.aws.amazon.com/firehose/latest/dev/what-is-this-service.html"
    },
    {
      "source": "firehose",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use Data Firehose resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/firehose/latest/dev/what-is-this-service.html"
    },
    {
      "source": "managed-flink",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use Managed Flink resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/managed-flink/latest/java/what-is.html"
    },
    {
      "source": "msk",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use MSK resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/msk/latest/developerguide/what-is-msk.html"
    },
    {
      "source": "quick",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use Quick resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/quick/latest/userguide/what-is.html"
    },
    {
      "source": "datazone",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use DataZone resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/datazone/latest/userguide/what-is-datazone.html"
    },
    {
      "source": "clean-rooms",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use Clean Rooms resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/clean-rooms/latest/userguide/what-is.html"
    },
    {
      "source": "entity-resolution",
      "target": "s3",
      "type": "pattern",
      "label": "Use S3 in a data pipeline",
      "detail": "A common Entity Resolution architecture reads or writes selected data in S3 when that integration is configured; it is not a universal prerequisite.",
      "url": "https://docs.aws.amazon.com/entityresolution/latest/userguide/what-is-service.html"
    },
    {
      "source": "entity-resolution",
      "target": "iam",
      "type": "integration",
      "label": "Scope access with IAM",
      "detail": "IAM policies can scope which principals administer or use Entity Resolution resources; grant only the actions required by the selected workflow.",
      "url": "https://docs.aws.amazon.com/entityresolution/latest/userguide/what-is-service.html"
    },
    {
      "source": "rds",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor database health",
      "detail": "RDS can be monitored with CloudWatch metrics and alarms when configured; select relevant signals for the workload.",
      "url": "https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Welcome.html"
    },
    {
      "source": "rds",
      "target": "kms",
      "type": "integration",
      "label": "Protect stored data with encryption",
      "detail": "AWS documents encryption and key-management controls for RDS; choose service-supported encryption settings and key policies for the deployment.",
      "url": "https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Welcome.html"
    },
    {
      "source": "aurora",
      "target": "kms",
      "type": "integration",
      "label": "Protect stored data with encryption",
      "detail": "Aurora encrypts cluster data at rest with AWS KMS keys; deployments can use an AWS-owned, AWS-managed, or customer-managed key.",
      "url": "https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/Overview.Encryption.html"
    },
    {
      "source": "aurora-dsql",
      "target": "kms",
      "type": "integration",
      "label": "Protect stored data with encryption",
      "detail": "AWS documents encryption and key-management controls for Aurora DSQL; choose service-supported encryption settings and key policies for the deployment.",
      "url": "https://docs.aws.amazon.com/aurora-dsql/latest/userguide/what-is-aurora-dsql.html"
    },
    {
      "source": "dynamodb",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor database health",
      "detail": "DynamoDB can be monitored with CloudWatch metrics and alarms when configured; select relevant signals for the workload.",
      "url": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/Introduction.html"
    },
    {
      "source": "dynamodb",
      "target": "kms",
      "type": "integration",
      "label": "Protect stored data with encryption",
      "detail": "AWS documents encryption and key-management controls for DynamoDB; choose service-supported encryption settings and key policies for the deployment.",
      "url": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/Introduction.html"
    },
    {
      "source": "elasticache",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor database health",
      "detail": "ElastiCache can be monitored with CloudWatch metrics and alarms when configured; select relevant signals for the workload.",
      "url": "https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/WhatIs.html"
    },
    {
      "source": "elasticache",
      "target": "kms",
      "type": "integration",
      "label": "Protect stored data with encryption",
      "detail": "AWS documents encryption and key-management controls for ElastiCache; choose service-supported encryption settings and key policies for the deployment.",
      "url": "https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/WhatIs.html"
    },
    {
      "source": "memorydb",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor database health",
      "detail": "MemoryDB can be monitored with CloudWatch metrics and alarms when configured; select relevant signals for the workload.",
      "url": "https://docs.aws.amazon.com/memorydb/latest/devguide/what-is-memorydb.html"
    },
    {
      "source": "memorydb",
      "target": "kms",
      "type": "integration",
      "label": "Protect stored data with encryption",
      "detail": "AWS documents encryption and key-management controls for MemoryDB; choose service-supported encryption settings and key policies for the deployment.",
      "url": "https://docs.aws.amazon.com/memorydb/latest/devguide/what-is-memorydb.html"
    },
    {
      "source": "neptune",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor database health",
      "detail": "Neptune can be monitored with CloudWatch metrics and alarms when configured; select relevant signals for the workload.",
      "url": "https://docs.aws.amazon.com/neptune/latest/userguide/intro.html"
    },
    {
      "source": "neptune",
      "target": "kms",
      "type": "integration",
      "label": "Protect stored data with encryption",
      "detail": "AWS documents encryption and key-management controls for Neptune; choose service-supported encryption settings and key policies for the deployment.",
      "url": "https://docs.aws.amazon.com/neptune/latest/userguide/intro.html"
    },
    {
      "source": "documentdb",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor database health",
      "detail": "DocumentDB can be monitored with CloudWatch metrics and alarms when configured; select relevant signals for the workload.",
      "url": "https://docs.aws.amazon.com/documentdb/latest/developerguide/what-is.html"
    },
    {
      "source": "documentdb",
      "target": "kms",
      "type": "integration",
      "label": "Protect stored data with encryption",
      "detail": "AWS documents encryption and key-management controls for DocumentDB; choose service-supported encryption settings and key policies for the deployment.",
      "url": "https://docs.aws.amazon.com/documentdb/latest/developerguide/what-is.html"
    },
    {
      "source": "keyspaces",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor database health",
      "detail": "Keyspaces can be monitored with CloudWatch metrics and alarms when configured; select relevant signals for the workload.",
      "url": "https://docs.aws.amazon.com/keyspaces/latest/devguide/monitoring-cloudwatch.html"
    },
    {
      "source": "keyspaces",
      "target": "kms",
      "type": "integration",
      "label": "Protect stored data with encryption",
      "detail": "AWS documents encryption and key-management controls for Keyspaces; choose service-supported encryption settings and key policies for the deployment.",
      "url": "https://docs.aws.amazon.com/keyspaces/latest/devguide/EncryptionAtRest.html"
    },
    {
      "source": "timestream",
      "target": "kms",
      "type": "integration",
      "label": "Protect stored data with encryption",
      "detail": "AWS documents encryption and key-management controls for Timestream; choose service-supported encryption settings and key policies for the deployment.",
      "url": "https://docs.aws.amazon.com/timestream/latest/developerguide/what-is-timestream.html"
    },
    {
      "source": "finspace",
      "target": "s3",
      "type": "alternative",
      "label": "Export data during retirement",
      "detail": "Historical migration guidance for existing FinSpace Managed kdb Insights customers says to export database contents and application code to Amazon S3 before setting up self-managed kdb on AWS. FinSpace support ended October 7, 2026; this edge describes migration, not a current FinSpace integration.",
      "url": "https://docs.aws.amazon.com/finspace/latest/userguide/amazon-finspace-end-of-support.html"
    },
    {
      "source": "lookout-metrics",
      "target": "managed-flink",
      "type": "alternative",
      "label": "Historical time-series anomaly path",
      "detail": "Lookout for Metrics shut down on October 10, 2025. In its sunset guidance, AWS described a CloudFormation-based early-access anomaly-detection solution using Managed Service for Apache Flink; treat this as historical transition guidance and verify current availability before adopting it.",
      "url": "https://aws.amazon.com/blogs/machine-learning/transitioning-off-amazon-lookout-for-metrics/"
    },
    {
      "source": "lookout-vision",
      "target": "sagemaker",
      "type": "alternative",
      "label": "Migrate defect detection workloads",
      "detail": "Lookout for Vision shut down on October 31, 2025. AWS migration guidance describes exporting the dataset and manifest to S3, then using SageMaker to build a replacement model; this is a migration path, not a current Lookout integration.",
      "url": "https://aws.amazon.com/blogs/machine-learning/exploring-alternatives-and-seamlessly-migrating-data-from-amazon-lookout-for-vision/"
    },
    {
      "source": "ec2",
      "target": "vpc",
      "type": "foundation",
      "label": "Launches into",
      "detail": "EC2 instances are launched in a VPC subnet and use VPC security groups and routes.",
      "url": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-networking.html"
    },
    {
      "source": "ec2",
      "target": "ebs",
      "type": "foundation",
      "label": "Attaches block volumes",
      "detail": "EBS volumes provide persistent block storage for EC2 instances.",
      "url": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-volumes.html"
    },
    {
      "source": "ec2",
      "target": "iam",
      "type": "integration",
      "label": "Uses instance roles",
      "detail": "An instance profile can provide temporary IAM role credentials to software on an EC2 instance.",
      "url": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-roles-for-amazon-ec2.html"
    },
    {
      "source": "ec2",
      "target": "elastic-load-balancing",
      "type": "integration",
      "label": "Registers targets",
      "detail": "Load balancers can route traffic to EC2 instances in target groups.",
      "url": "https://docs.aws.amazon.com/elasticloadbalancing/latest/application/load-balancer-target-groups.html"
    },
    {
      "source": "ec2",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Publishes metrics",
      "detail": "EC2 provides instance metrics to CloudWatch; detailed monitoring is an instance option.",
      "url": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/monitoring_ec2.html"
    },
    {
      "source": "lambda",
      "target": "s3",
      "type": "integration",
      "label": "Invokes on object events",
      "detail": "S3 can invoke Lambda for configured object events; bucket and function must meet regional and permission requirements.",
      "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/notification-how-to-event-types-and-destinations.html"
    },
    {
      "source": "lambda",
      "target": "sqs",
      "type": "integration",
      "label": "Consumes queue messages",
      "detail": "Lambda event source mappings poll SQS queues and invoke functions with batches of messages.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/with-sqs.html"
    },
    {
      "source": "lambda",
      "target": "eventbridge",
      "type": "integration",
      "label": "Runs from matched events",
      "detail": "EventBridge rules can invoke Lambda targets when event patterns match.",
      "url": "https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-run-lambda-schedule.html"
    },
    {
      "source": "lambda",
      "target": "api-gateway",
      "type": "integration",
      "label": "Handles API requests",
      "detail": "API Gateway can route API requests to Lambda integrations.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/services-apigateway.html"
    },
    {
      "source": "lambda",
      "target": "vpc",
      "type": "integration",
      "label": "Connects to VPC resources",
      "detail": "A Lambda function can be configured for VPC access to private resources such as databases.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/configuration-vpc.html"
    },
    {
      "source": "lambda",
      "target": "kms",
      "type": "integration",
      "label": "Encrypts environment variables",
      "detail": "Lambda can use a customer managed KMS key to encrypt environment variables.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/configuration-envvars-encryption.html"
    },
    {
      "source": "ecs",
      "target": "fargate",
      "type": "integration",
      "label": "Runs tasks on",
      "detail": "Fargate is a compute option for ECS tasks selected in task or service configuration.",
      "url": "https://docs.aws.amazon.com/AmazonECS/latest/userguide/what-is-fargate.html"
    },
    {
      "source": "ecs",
      "target": "ecr",
      "type": "integration",
      "label": "Pulls container images",
      "detail": "ECS task execution roles can authorize image pulls from ECR repositories.",
      "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task_execution_IAM_role.html"
    },
    {
      "source": "ecs",
      "target": "elastic-load-balancing",
      "type": "integration",
      "label": "Routes service traffic",
      "detail": "ECS services can register tasks with load balancer target groups.",
      "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/service-load-balancing.html"
    },
    {
      "source": "ecs",
      "target": "cloud-map",
      "type": "integration",
      "label": "Registers service names",
      "detail": "ECS service discovery can register task endpoints in AWS Cloud Map.",
      "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/service-discovery.html"
    },
    {
      "source": "ecs",
      "target": "vpc-lattice",
      "type": "integration",
      "label": "Connects application services",
      "detail": "ECS services can be associated with VPC Lattice for service connectivity and access controls.",
      "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-vpc-lattice.html"
    },
    {
      "source": "eks",
      "target": "fargate",
      "type": "integration",
      "label": "Schedules selected Pods",
      "detail": "EKS Fargate profiles select Pods that should run on Fargate.",
      "url": "https://docs.aws.amazon.com/eks/latest/userguide/fargate.html"
    },
    {
      "source": "eks",
      "target": "ecr",
      "type": "integration",
      "label": "Pulls container images",
      "detail": "EKS nodes and Pods can pull container images from ECR with suitable authorization.",
      "url": "https://docs.aws.amazon.com/AmazonECR/latest/userguide/ECR_on_EKS.html"
    },
    {
      "source": "eks",
      "target": "vpc",
      "type": "integration",
      "label": "Uses cluster networking",
      "detail": "EKS clusters and their compute resources use VPC networking.",
      "url": "https://docs.aws.amazon.com/eks/latest/userguide/eks-networking.html"
    },
    {
      "source": "batch",
      "target": "ecs",
      "type": "integration",
      "label": "Schedules container jobs",
      "detail": "AWS Batch orchestrates containerized jobs using ECS or EKS compute environments.",
      "url": "https://docs.aws.amazon.com/batch/latest/userguide/what-is-batch.html"
    },
    {
      "source": "batch",
      "target": "fargate",
      "type": "integration",
      "label": "Runs serverless jobs",
      "detail": "Batch can use Fargate capacity in ECS-based compute environments.",
      "url": "https://docs.aws.amazon.com/batch/latest/userguide/fargate.html"
    },
    {
      "source": "batch",
      "target": "ecr",
      "type": "integration",
      "label": "Fetches job images",
      "detail": "Batch job definitions reference container images hosted in a registry such as ECR.",
      "url": "https://docs.aws.amazon.com/batch/latest/userguide/job_definition_parameters.html"
    },
    {
      "source": "ecr",
      "target": "iam",
      "type": "integration",
      "label": "Controls repository access",
      "detail": "ECR private repository access is controlled through IAM and repository policies.",
      "url": "https://docs.aws.amazon.com/AmazonECR/latest/userguide/repository-policies.html"
    },
    {
      "source": "outposts",
      "target": "ec2",
      "type": "integration",
      "label": "Runs local instances",
      "detail": "Outpost subnets can host EC2 instances using local Outposts capacity.",
      "url": "https://docs.aws.amazon.com/outposts/latest/userguide/what-is-outposts.html"
    },
    {
      "source": "local-zones",
      "target": "ec2",
      "type": "integration",
      "label": "Places regional workloads nearby",
      "detail": "Customers can launch supported EC2 instances in Local Zone subnets connected to a parent Region.",
      "url": "https://docs.aws.amazon.com/local-zones/latest/ug/what-is-aws-local-zones.html"
    },
    {
      "source": "wavelength",
      "target": "ec2",
      "type": "integration",
      "label": "Runs edge instances",
      "detail": "EC2 instances can run in Wavelength Zone subnets within participating carrier networks.",
      "url": "https://docs.aws.amazon.com/wavelength/latest/developerguide/what-is-wavelength.html"
    },
    {
      "source": "ebs",
      "target": "ec2",
      "type": "integration",
      "label": "Provides persistent block storage",
      "detail": "EBS volumes attach to EC2 instances in the same Availability Zone.",
      "url": "https://docs.aws.amazon.com/ebs/latest/userguide/ebs-volumes.html"
    },
    {
      "source": "efs",
      "target": "vpc",
      "type": "integration",
      "label": "Mounts through VPC",
      "detail": "EFS mount targets are network endpoints in VPC subnets for NFS clients.",
      "url": "https://docs.aws.amazon.com/efs/latest/ug/accessing-fs.html"
    },
    {
      "source": "fsx",
      "target": "vpc",
      "type": "integration",
      "label": "Connects clients over VPC",
      "detail": "FSx file systems are accessed by clients over configured VPC networking.",
      "url": "https://docs.aws.amazon.com/fsx/latest/WindowsGuide/what-is.html"
    },
    {
      "source": "s3",
      "target": "lambda",
      "type": "integration",
      "label": "Sends object notifications",
      "detail": "S3 event notifications can invoke Lambda for supported bucket events.",
      "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/notification-how-to-event-types-and-destinations.html"
    },
    {
      "source": "s3",
      "target": "eventbridge",
      "type": "integration",
      "label": "Publishes bucket events",
      "detail": "A bucket can enable EventBridge delivery for S3 events, which rules can route to targets.",
      "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/enable-event-notifications-eventbridge.html"
    },
    {
      "source": "s3",
      "target": "sqs",
      "type": "integration",
      "label": "Sends notifications to queues",
      "detail": "S3 event notifications can publish supported events to SQS queues.",
      "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/notification-how-to-event-types-and-destinations.html"
    },
    {
      "source": "s3",
      "target": "sns",
      "type": "integration",
      "label": "Publishes object notifications",
      "detail": "S3 event notifications can publish supported events to SNS topics.",
      "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/notification-how-to-event-types-and-destinations.html"
    },
    {
      "source": "s3",
      "target": "cloudfront",
      "type": "integration",
      "label": "Serves bucket content",
      "detail": "CloudFront can use an S3 bucket as an origin, with Origin Access Control for private bucket access.",
      "url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/DownloadDistS3AndCustomOrigins.html"
    },
    {
      "source": "s3",
      "target": "athena",
      "type": "integration",
      "label": "Queries lake data",
      "detail": "Athena can query data stored in S3 using supported formats and catalog metadata.",
      "url": "https://docs.aws.amazon.com/athena/latest/ug/what-is.html"
    },
    {
      "source": "s3",
      "target": "glue",
      "type": "integration",
      "label": "Catalogs data sets",
      "detail": "AWS Glue Data Catalog can store table metadata for data in S3 used by analytics services.",
      "url": "https://docs.aws.amazon.com/glue/latest/dg/catalog-and-crawler.html"
    },
    {
      "source": "s3",
      "target": "kms",
      "type": "integration",
      "label": "Encrypts objects with KMS keys",
      "detail": "S3 supports SSE-KMS encryption using AWS KMS keys.",
      "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/UsingKMSEncryption.html"
    },
    {
      "source": "s3",
      "target": "iam",
      "type": "integration",
      "label": "Authorizes bucket access",
      "detail": "IAM identity policies and S3 bucket policies jointly govern access to S3 resources.",
      "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html"
    },
    {
      "source": "s3",
      "target": "backup",
      "type": "integration",
      "label": "Protects bucket data",
      "detail": "AWS Backup supports backup and restore workflows for supported S3 buckets and object versions.",
      "url": "https://docs.aws.amazon.com/aws-backup/latest/devguide/s3-backups.html"
    },
    {
      "source": "s3",
      "target": "storage-gateway",
      "type": "integration",
      "label": "Backs file and volume gateways",
      "detail": "Storage Gateway file and volume modes use AWS-managed S3-backed storage; gateway data is accessed through gateway interfaces.",
      "url": "https://docs.aws.amazon.com/storagegateway/latest/tgw/WhatIsStorageGateway.html"
    },
    {
      "source": "s3",
      "target": "transfer-family",
      "type": "integration",
      "label": "Hosts transferred files",
      "detail": "Transfer Family can store uploaded files in S3 buckets.",
      "url": "https://docs.aws.amazon.com/transfer/latest/userguide/what-is-aws-transfer-family.html"
    },
    {
      "source": "s3",
      "target": "datasync",
      "type": "integration",
      "label": "Moves data into or out of",
      "detail": "DataSync supports S3 locations as transfer sources or destinations.",
      "url": "https://docs.aws.amazon.com/datasync/latest/userguide/what-is-datasync.html"
    },
    {
      "source": "s3",
      "target": "ec2",
      "type": "integration",
      "label": "Stores application objects",
      "detail": "Applications on EC2 can use S3 APIs to store and retrieve object data with IAM authorization.",
      "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-overview.html"
    },
    {
      "source": "s3",
      "target": "s3-glacier",
      "type": "integration",
      "label": "Transitions objects to archive",
      "detail": "S3 lifecycle rules can transition objects into S3 Glacier storage classes.",
      "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/lifecycle-transition-general-considerations.html"
    },
    {
      "source": "storage-gateway",
      "target": "ebs",
      "type": "integration",
      "label": "Creates snapshot backups",
      "detail": "Volume Gateway snapshots are stored as EBS snapshots and can be restored to EBS volumes.",
      "url": "https://docs.aws.amazon.com/storagegateway/latest/vgw/backing-up-volumes.html"
    },
    {
      "source": "storage-gateway",
      "target": "backup",
      "type": "integration",
      "label": "Centralizes volume backup",
      "detail": "AWS Backup supports backup and restore for Storage Gateway cached and stored volumes.",
      "url": "https://docs.aws.amazon.com/storagegateway/latest/vgw/backing-up-volumes.html"
    },
    {
      "source": "datasync",
      "target": "efs",
      "type": "integration",
      "label": "Transfers file data",
      "detail": "DataSync can copy between supported source locations and EFS file systems.",
      "url": "https://docs.aws.amazon.com/datasync/latest/userguide/what-is-datasync.html"
    },
    {
      "source": "datasync",
      "target": "fsx",
      "type": "integration",
      "label": "Moves data to file systems",
      "detail": "DataSync supports transfer locations for supported FSx file systems.",
      "url": "https://docs.aws.amazon.com/datasync/latest/userguide/what-is-datasync.html"
    },
    {
      "source": "transfer-family",
      "target": "efs",
      "type": "integration",
      "label": "Stores partner files",
      "detail": "Transfer Family servers can use EFS as a storage domain.",
      "url": "https://docs.aws.amazon.com/transfer/latest/userguide/what-is-aws-transfer-family.html"
    },
    {
      "source": "vpc",
      "target": "ec2",
      "type": "foundation",
      "label": "Provides instance networking",
      "detail": "EC2 instances launch into VPC subnets and use VPC routing and security groups.",
      "url": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-networking.html"
    },
    {
      "source": "vpc",
      "target": "privatelink",
      "type": "integration",
      "label": "Creates private endpoints",
      "detail": "PrivateLink VPC endpoints privately connect VPC clients to supported services and resources.",
      "url": "https://docs.aws.amazon.com/vpc/latest/privatelink/what-is-privatelink.html"
    },
    {
      "source": "vpc",
      "target": "transit-gateway",
      "type": "integration",
      "label": "Attaches to network hub",
      "detail": "VPCs can attach to Transit Gateway for centralized routing among networks.",
      "url": "https://docs.aws.amazon.com/vpc/latest/tgw/what-is-transit-gateway.html"
    },
    {
      "source": "vpc",
      "target": "network-firewall",
      "type": "integration",
      "label": "Routes traffic for inspection",
      "detail": "VPC route tables can steer traffic through Network Firewall endpoints.",
      "url": "https://docs.aws.amazon.com/network-firewall/latest/developerguide/architectures.html"
    },
    {
      "source": "vpc",
      "target": "client-vpn",
      "type": "integration",
      "label": "Provides remote user reachability",
      "detail": "Client VPN can associate target networks in VPCs for authenticated remote access.",
      "url": "https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/what-is.html"
    },
    {
      "source": "vpc",
      "target": "site-to-site-vpn",
      "type": "integration",
      "label": "Connects hybrid networks",
      "detail": "Site-to-Site VPN can terminate on a virtual private gateway or Transit Gateway attached to a VPC.",
      "url": "https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html"
    },
    {
      "source": "vpc",
      "target": "direct-connect",
      "type": "integration",
      "label": "Connects private networks",
      "detail": "Direct Connect private virtual interfaces and gateways can provide private connectivity to VPCs.",
      "url": "https://docs.aws.amazon.com/directconnect/latest/UserGuide/Welcome.html"
    },
    {
      "source": "vpc",
      "target": "vpc-lattice",
      "type": "integration",
      "label": "Associates service networks",
      "detail": "VPCs can associate with a VPC Lattice service network to reach authorized services.",
      "url": "https://docs.aws.amazon.com/vpc-lattice/latest/ug/what-is-vpc-lattice.html"
    },
    {
      "source": "vpc",
      "target": "verified-access",
      "type": "integration",
      "label": "Hosts private endpoints",
      "detail": "Verified Access endpoints can connect users to applications reachable through configured network interfaces.",
      "url": "https://docs.aws.amazon.com/verified-access/latest/ug/what-is-verified-access.html"
    },
    {
      "source": "cloudfront",
      "target": "s3",
      "type": "integration",
      "label": "Uses object bucket origin",
      "detail": "CloudFront distributions can retrieve content from an S3 origin and restrict direct bucket access.",
      "url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/DownloadDistS3AndCustomOrigins.html"
    },
    {
      "source": "route53",
      "target": "cloudfront",
      "type": "integration",
      "label": "Routes DNS to distribution",
      "detail": "Route 53 alias records can route domain names to CloudFront distributions.",
      "url": "https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-to-cloudfront-distribution.html"
    },
    {
      "source": "route53",
      "target": "vpc",
      "type": "integration",
      "label": "Resolves private names",
      "detail": "Route 53 private hosted zones provide DNS names resolvable from associated VPCs.",
      "url": "https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/hosted-zones-private.html"
    },
    {
      "source": "elastic-load-balancing",
      "target": "ecs",
      "type": "integration",
      "label": "Balances service tasks",
      "detail": "ECS services can register tasks with load balancer target groups.",
      "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/service-load-balancing.html"
    },
    {
      "source": "global-accelerator",
      "target": "elastic-load-balancing",
      "type": "integration",
      "label": "Uses load balancer endpoints",
      "detail": "Global Accelerator can route traffic to supported load balancer endpoints.",
      "url": "https://docs.aws.amazon.com/global-accelerator/latest/dg/about-endpoints.html"
    },
    {
      "source": "transit-gateway",
      "target": "direct-connect",
      "type": "integration",
      "label": "Uses gateway attachment",
      "detail": "Transit Gateway can connect to on-premises networks through a Direct Connect gateway.",
      "url": "https://docs.aws.amazon.com/directconnect/latest/UserGuide/direct-connect-transit-gateways.html"
    },
    {
      "source": "privatelink",
      "target": "vpc-lattice",
      "type": "integration",
      "label": "Connects to service networks",
      "detail": "A service-network VPC endpoint uses PrivateLink to privately access a VPC Lattice service network.",
      "url": "https://docs.aws.amazon.com/vpc/latest/privatelink/privatelink-access-service-networks.html"
    },
    {
      "source": "cloud-map",
      "target": "ecs",
      "type": "integration",
      "label": "Discovers service tasks",
      "detail": "ECS service discovery integrates with Cloud Map to register task endpoints.",
      "url": "https://docs.aws.amazon.com/AmazonECS/latest/developerguide/service-discovery.html"
    },
    {
      "source": "api-gateway",
      "target": "lambda",
      "type": "integration",
      "label": "Invokes function integrations",
      "detail": "API Gateway integrates with Lambda to expose function-backed APIs.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/services-apigateway.html"
    },
    {
      "source": "appsync",
      "target": "dynamodb",
      "type": "integration",
      "label": "Resolves GraphQL data",
      "detail": "AppSync supports DynamoDB as a GraphQL data source.",
      "url": "https://docs.aws.amazon.com/appsync/latest/devguide/tutorial-dynamodb-resolvers.html"
    },
    {
      "source": "appsync",
      "target": "lambda",
      "type": "integration",
      "label": "Uses custom resolver logic",
      "detail": "AppSync can invoke Lambda data sources for custom GraphQL resolver behavior.",
      "url": "https://docs.aws.amazon.com/appsync/latest/devguide/tutorial-lambda-resolvers.html"
    },
    {
      "source": "eventbridge",
      "target": "sqs",
      "type": "integration",
      "label": "Routes events to queues",
      "detail": "EventBridge rules can target SQS queues for asynchronous processing.",
      "url": "https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-targets.html"
    },
    {
      "source": "eventbridge",
      "target": "sns",
      "type": "integration",
      "label": "Routes events to topics",
      "detail": "EventBridge rules can publish matching events to SNS topics.",
      "url": "https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-targets.html"
    },
    {
      "source": "eventbridge",
      "target": "step-functions",
      "type": "integration",
      "label": "Starts workflow executions",
      "detail": "EventBridge rules can start Step Functions state machine executions.",
      "url": "https://docs.aws.amazon.com/step-functions/latest/dg/eventbridge-integration.html"
    },
    {
      "source": "sqs",
      "target": "lambda",
      "type": "integration",
      "label": "Triggers message processing",
      "detail": "Lambda polls SQS queues through an event source mapping and invokes a function with message batches.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/with-sqs.html"
    },
    {
      "source": "sns",
      "target": "sqs",
      "type": "integration",
      "label": "Fans out into queues",
      "detail": "SNS can publish a topic message to subscribed SQS queues.",
      "url": "https://docs.aws.amazon.com/sns/latest/dg/sns-sqs-as-subscriber.html"
    },
    {
      "source": "step-functions",
      "target": "lambda",
      "type": "integration",
      "label": "Runs workflow tasks",
      "detail": "Step Functions can invoke Lambda functions as workflow tasks.",
      "url": "https://docs.aws.amazon.com/step-functions/latest/dg/connect-lambda.html"
    },
    {
      "source": "appflow",
      "target": "s3",
      "type": "integration",
      "label": "Transfers records to buckets",
      "detail": "AppFlow supports S3 as a flow source or destination for supported connectors.",
      "url": "https://docs.aws.amazon.com/appflow/latest/userguide/what-is-appflow.html"
    },
    {
      "source": "appflow",
      "target": "redshift",
      "type": "integration",
      "label": "Loads analytics data",
      "detail": "AppFlow supports Amazon Redshift as a destination for supported flows.",
      "url": "https://docs.aws.amazon.com/appflow/latest/userguide/what-is-appflow.html"
    },
    {
      "source": "ec2",
      "target": "lightsail",
      "type": "alternative",
      "label": "Alternative hosting choices",
      "detail": "EC2 offers broad instance control; Lightsail packages common compute and networking choices for simpler deployments.",
      "url": "https://docs.aws.amazon.com/decision-guides/latest/decision-guides/lightsail-elastic-beanstalk-ec2.html"
    },
    {
      "source": "ecs",
      "target": "eks",
      "type": "alternative",
      "label": "Alternative container orchestration",
      "detail": "ECS provides AWS-native orchestration while EKS provides managed Kubernetes; choose based on orchestration and ecosystem needs.",
      "url": "https://docs.aws.amazon.com/decision-guides/latest/decision-guides/choosing-aws-container-service.html"
    },
    {
      "source": "ecs",
      "target": "elastic-beanstalk",
      "type": "alternative",
      "label": "Alternative app deployment path",
      "detail": "Elastic Beanstalk manages application environments; ECS offers direct container task and service orchestration.",
      "url": "https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/create_deploy_docker.html"
    },
    {
      "source": "step-functions",
      "target": "swf",
      "type": "alternative",
      "label": "Modern workflow alternative",
      "detail": "AWS identifies Step Functions as a service to consider for new workflow designs while SWF supports existing worker-driven systems.",
      "url": "https://docs.aws.amazon.com/amazonswf/latest/developerguide/swf-welcome.html"
    },
    {
      "source": "datasync",
      "target": "snowball",
      "type": "alternative",
      "label": "Online migration alternative",
      "detail": "AWS recommends DataSync for online transfers where network bandwidth and reliability meet migration goals; Snowball is an existing-customer offline option.",
      "url": "https://docs.aws.amazon.com/snowball/latest/developer-guide/snowball-edge-availability-change.html"
    },
    {
      "source": "s3",
      "target": "glue",
      "type": "pattern",
      "label": "Catalogs data lake tables",
      "detail": "AWS Glue crawlers and the Data Catalog can describe S3 data for analytics consumers.",
      "url": "https://docs.aws.amazon.com/glue/latest/dg/catalog-and-crawler.html"
    },
    {
      "source": "s3",
      "target": "athena",
      "type": "pattern",
      "label": "Queries data in place",
      "detail": "Athena reads supported data formats from S3 and uses catalog metadata where configured.",
      "url": "https://docs.aws.amazon.com/athena/latest/ug/what-is.html"
    },
    {
      "source": "s3",
      "target": "cloudfront",
      "type": "pattern",
      "label": "Delivers static content",
      "detail": "A common architecture uses S3 as a private CloudFront origin for static assets.",
      "url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/DownloadDistS3AndCustomOrigins.html"
    },
    {
      "source": "s3",
      "target": "eventbridge",
      "type": "pattern",
      "label": "Routes events to workflows",
      "detail": "An S3 event can be matched by EventBridge rules and routed to supported targets such as Step Functions.",
      "url": "https://docs.aws.amazon.com/AmazonS3/latest/userguide/enable-event-notifications-eventbridge.html"
    },
    {
      "source": "s3",
      "target": "snowball",
      "type": "pattern",
      "label": "Imports offline data",
      "detail": "Snowball Edge import jobs transfer on-premises files into S3 for existing eligible customers.",
      "url": "https://docs.aws.amazon.com/snowball/latest/developer-guide/how-it-works.html"
    },
    {
      "source": "elastic-beanstalk",
      "target": "ec2",
      "type": "foundation",
      "label": "Provisions application capacity",
      "detail": "Elastic Beanstalk environments provision EC2 instances for supported web and worker tiers.",
      "url": "https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/using-features-managing-env-tiers.html"
    },
    {
      "source": "elastic-beanstalk",
      "target": "elastic-load-balancing",
      "type": "integration",
      "label": "Adds an environment load balancer",
      "detail": "Load-balanced Elastic Beanstalk environments create and manage an Elastic Load Balancing resource.",
      "url": "https://docs.aws.amazon.com/elasticbeanstalk/latest/dg/using-features.managing.elb.html"
    },
    {
      "source": "lightsail",
      "target": "vpc",
      "type": "integration",
      "label": "Connects to VPC resources",
      "detail": "Lightsail instances can use VPC peering to connect to resources in the AWS account VPC.",
      "url": "https://docs.aws.amazon.com/lightsail/latest/userguide/lightsail-how-to-set-up-vpc-peering-with-aws-resources.html"
    },
    {
      "source": "lightsail",
      "target": "route53",
      "type": "integration",
      "label": "Hosts DNS records",
      "detail": "Lightsail DNS zones can manage domain records for Lightsail resources and other endpoints.",
      "url": "https://docs.aws.amazon.com/lightsail/latest/userguide/lightsail-how-to-create-dns-entry.html"
    },
    {
      "source": "app-runner",
      "target": "ecr",
      "type": "integration",
      "label": "Deploys from images",
      "detail": "App Runner can deploy a service from a private ECR image repository.",
      "url": "https://docs.aws.amazon.com/apprunner/latest/dg/service-source-image.html"
    },
    {
      "source": "app-runner",
      "target": "vpc",
      "type": "integration",
      "label": "Connects to private resources",
      "detail": "An App Runner VPC connector provides outbound access from an application to resources in a VPC.",
      "url": "https://docs.aws.amazon.com/apprunner/latest/dg/network-vpc.html"
    },
    {
      "source": "app-runner",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Publishes application logs",
      "detail": "App Runner streams service and application logs to CloudWatch Logs.",
      "url": "https://docs.aws.amazon.com/apprunner/latest/dg/monitor-cw.html"
    },
    {
      "source": "outposts",
      "target": "ebs",
      "type": "foundation",
      "label": "Provides local block storage",
      "detail": "Outposts supports EBS volumes on compatible Outpost capacity for supported instance types.",
      "url": "https://docs.aws.amazon.com/outposts/latest/userguide/what-is-outposts.html"
    },
    {
      "source": "outposts",
      "target": "vpc",
      "type": "foundation",
      "label": "Uses Outpost subnets",
      "detail": "Outpost subnets are created in a VPC and place supported resources at the customer site.",
      "url": "https://docs.aws.amazon.com/outposts/latest/userguide/what-is-outposts.html"
    },
    {
      "source": "wavelength",
      "target": "vpc",
      "type": "foundation",
      "label": "Uses carrier edge subnets",
      "detail": "Wavelength Zones are represented as subnets in a VPC associated with a parent Region.",
      "url": "https://docs.aws.amazon.com/wavelength/latest/developerguide/what-is-wavelength.html"
    },
    {
      "source": "wavelength",
      "target": "route53",
      "type": "pattern",
      "label": "Routes users to edge workloads",
      "detail": "AWS describes using Route 53 and Global Accelerator with Wavelength for application traffic routing.",
      "url": "https://docs.aws.amazon.com/wavelength/latest/developerguide/how-wavelengths-work.html"
    },
    {
      "source": "local-zones",
      "target": "vpc",
      "type": "foundation",
      "label": "Extends a regional VPC",
      "detail": "A Local Zone subnet belongs to a VPC in its parent Region and connects workloads to that Region.",
      "url": "https://docs.aws.amazon.com/local-zones/latest/ug/what-is-aws-local-zones.html"
    },
    {
      "source": "local-zones",
      "target": "ebs",
      "type": "foundation",
      "label": "Attaches local-zone volumes",
      "detail": "EBS volumes can be created in a Local Zone for instances in that same zone where supported.",
      "url": "https://docs.aws.amazon.com/local-zones/latest/ug/what-is-aws-local-zones.html"
    },
    {
      "source": "parallelcluster",
      "target": "ec2",
      "type": "foundation",
      "label": "Builds HPC compute nodes",
      "detail": "ParallelCluster provisions EC2 instances as cluster head and compute nodes.",
      "url": "https://docs.aws.amazon.com/parallelcluster/latest/ug/what-is-aws-parallelcluster.html"
    },
    {
      "source": "parallelcluster",
      "target": "fsx",
      "type": "integration",
      "label": "Uses shared HPC file systems",
      "detail": "ParallelCluster supports FSx for Lustre and other shared storage integrations for cluster workloads.",
      "url": "https://docs.aws.amazon.com/parallelcluster/latest/ug/shared-storage-quotas-integration-v3.html"
    },
    {
      "source": "parallelcluster",
      "target": "vpc",
      "type": "foundation",
      "label": "Places cluster networking",
      "detail": "ParallelCluster deploys cluster resources into customer-selected VPC subnets.",
      "url": "https://docs.aws.amazon.com/parallelcluster/latest/ug/what-is-aws-parallelcluster.html"
    },
    {
      "source": "pcs",
      "target": "ec2",
      "type": "foundation",
      "label": "Scales compute node groups",
      "detail": "AWS PCS compute node groups use EC2 instances for Slurm cluster capacity.",
      "url": "https://docs.aws.amazon.com/pcs/latest/userguide/working-with_cng.html"
    },
    {
      "source": "pcs",
      "target": "vpc",
      "type": "foundation",
      "label": "Deploys cluster resources into",
      "detail": "AWS PCS clusters are created in a VPC and use subnets and security groups for networking.",
      "url": "https://docs.aws.amazon.com/pcs/latest/userguide/working-with_clusters.html"
    },
    {
      "source": "pcs",
      "target": "fsx",
      "type": "integration",
      "label": "Uses shared HPC storage",
      "detail": "AWS PCS supports shared storage patterns such as Amazon FSx for Lustre for HPC workloads.",
      "url": "https://docs.aws.amazon.com/pcs/latest/userguide/working-with_clusters.html"
    },
    {
      "source": "s3-glacier",
      "target": "backup",
      "type": "integration",
      "label": "Stores long-term recovery points",
      "detail": "AWS Backup can copy supported recovery points to cold storage tiers, subject to resource and vault requirements.",
      "url": "https://docs.aws.amazon.com/aws-backup/latest/devguide/whatisbackup.html"
    },
    {
      "source": "global-accelerator",
      "target": "route53",
      "type": "integration",
      "label": "Maps application names to static IPs",
      "detail": "Route 53 can create alias records that point a domain name to a Global Accelerator.",
      "url": "https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/routing-to-global-accelerator.html"
    },
    {
      "source": "global-accelerator",
      "target": "ec2",
      "type": "integration",
      "label": "Uses instance endpoints",
      "detail": "Global Accelerator can route traffic to EC2 instance endpoints.",
      "url": "https://docs.aws.amazon.com/global-accelerator/latest/dg/about-endpoints.html"
    },
    {
      "source": "network-firewall",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Sends flow and alert logs",
      "detail": "Network Firewall can publish alert and flow logs to CloudWatch Logs, S3, or Kinesis Data Firehose.",
      "url": "https://docs.aws.amazon.com/network-firewall/latest/developerguide/firewall-logging.html"
    },
    {
      "source": "network-firewall",
      "target": "vpc",
      "type": "foundation",
      "label": "Inspects routed VPC traffic",
      "detail": "Firewall endpoints reside in VPC subnets, and route tables direct selected traffic through them.",
      "url": "https://docs.aws.amazon.com/network-firewall/latest/developerguide/architectures.html"
    },
    {
      "source": "verified-access",
      "target": "iam",
      "type": "integration",
      "label": "Evaluates IAM identity context",
      "detail": "Verified Access can use IAM Identity Center as an identity trust provider for application access decisions.",
      "url": "https://docs.aws.amazon.com/verified-access/latest/ug/trust-providers.html"
    },
    {
      "source": "verified-access",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Logs access activity",
      "detail": "Verified Access can send application access logs to CloudWatch Logs, S3, or Kinesis Data Firehose.",
      "url": "https://docs.aws.amazon.com/verified-access/latest/ug/access-logs.html"
    },
    {
      "source": "client-vpn",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Publishes connection logs",
      "detail": "Client VPN connection logs can be delivered to CloudWatch Logs.",
      "url": "https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/connection-logging.html"
    },
    {
      "source": "client-vpn",
      "target": "site-to-site-vpn",
      "type": "pattern",
      "label": "Combines remote and network VPN access",
      "detail": "A VPC can support remote-user Client VPN access alongside Site-to-Site VPN connectivity to customer networks.",
      "url": "https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/what-is.html"
    },
    {
      "source": "site-to-site-vpn",
      "target": "transit-gateway",
      "type": "integration",
      "label": "Terminates VPN at network hub",
      "detail": "A Site-to-Site VPN connection can attach to Transit Gateway for centralized routing.",
      "url": "https://docs.aws.amazon.com/vpc/latest/tgw/tgw-vpn-attachments.html"
    },
    {
      "source": "site-to-site-vpn",
      "target": "direct-connect",
      "type": "pattern",
      "label": "Provides a backup hybrid path",
      "detail": "AWS documents Site-to-Site VPN as a possible backup path alongside Direct Connect.",
      "url": "https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-options/aws-direct-connect.html"
    },
    {
      "source": "mq",
      "target": "vpc",
      "type": "foundation",
      "label": "Hosts brokers in private subnets",
      "detail": "Amazon MQ brokers are deployed into VPC subnets and accessed by clients over configured network paths.",
      "url": "https://docs.aws.amazon.com/amazon-mq/latest/developer-guide/amazon-mq-broker-architecture.html"
    },
    {
      "source": "mq",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitors broker metrics",
      "detail": "Amazon MQ publishes broker metrics to CloudWatch.",
      "url": "https://docs.aws.amazon.com/amazon-mq/latest/developer-guide/amazon-mq-accessing-metrics.html"
    },
    {
      "source": "swf",
      "target": "lambda",
      "type": "pattern",
      "label": "Runs worker code",
      "detail": "SWF activity workers can be implemented as application processes, including code hosted on AWS compute such as Lambda where the workflow design supports it.",
      "url": "https://docs.aws.amazon.com/amazonswf/latest/developerguide/swf-dev-activities.html"
    },
    {
      "source": "swf",
      "target": "step-functions",
      "type": "alternative",
      "label": "Evaluates managed state-machine orchestration",
      "detail": "Step Functions provides a managed state-machine workflow model that AWS recommends evaluating for new orchestration needs.",
      "url": "https://docs.aws.amazon.com/step-functions/latest/dg/welcome.html"
    },
    {
      "source": "snowmobile",
      "target": "s3",
      "type": "pattern",
      "label": "Historical S3 transfer path",
      "detail": "AWS launch material described Snowmobile as moving up to 100 PB of data to AWS storage, including Amazon S3. Snowmobile ended support March 14, 2024 and is retired.",
      "url": "https://aws.amazon.com/blogs/aws/aws-snowmobile-move-exabytes-of-data-to-the-cloud-in-weeks/"
    },
    {
      "source": "iam",
      "target": "organizations",
      "type": "integration",
      "label": "govern account access",
      "detail": "Organizations SCPs bound permissions that IAM policies can grant in member accounts.",
      "url": "https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html"
    },
    {
      "source": "iam-identity-center",
      "target": "organizations",
      "type": "integration",
      "label": "assign access to accounts",
      "detail": "IAM Identity Center provisions permission sets to accounts managed in Organizations.",
      "url": "https://docs.aws.amazon.com/singlesignon/latest/userguide/identity-center-and-orgs.html"
    },
    {
      "source": "cognito",
      "target": "verified-permissions",
      "type": "integration",
      "label": "provide app identity context",
      "detail": "Applications can pass authenticated Cognito principal attributes into Verified Permissions authorization requests.",
      "url": "https://docs.aws.amazon.com/verifiedpermissions/latest/userguide/identity-sources-cognito.html"
    },
    {
      "source": "kms",
      "target": "secrets-manager",
      "type": "foundation",
      "label": "encrypt secret values",
      "detail": "Secrets Manager uses KMS keys to encrypt secret values at rest.",
      "url": "https://docs.aws.amazon.com/secretsmanager/latest/userguide/security-encryption.html"
    },
    {
      "source": "certificate-manager",
      "target": "private-ca",
      "type": "integration",
      "label": "issue private certificates",
      "detail": "ACM can request and renew certificates issued by an ACM Private CA.",
      "url": "https://docs.aws.amazon.com/acm/latest/userguide/private-certificates.title.html"
    },
    {
      "source": "waf",
      "target": "shield",
      "type": "integration",
      "label": "add application-layer protection",
      "detail": "Shield Advanced can coordinate with AWS WAF protections for web applications.",
      "url": "https://docs.aws.amazon.com/waf/latest/developerguide/ddos-app-layer-protections.html"
    },
    {
      "source": "guardduty",
      "target": "security-hub",
      "type": "integration",
      "label": "send threat findings",
      "detail": "GuardDuty findings can be enabled as a Security Hub finding source.",
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-internal-providers.html"
    },
    {
      "source": "inspector",
      "target": "security-hub",
      "type": "integration",
      "label": "centralize vulnerability findings",
      "detail": "Inspector findings can be viewed and prioritized in Security Hub.",
      "url": "https://docs.aws.amazon.com/inspector/latest/user/securityhub-integration.html"
    },
    {
      "source": "macie",
      "target": "security-hub",
      "type": "integration",
      "label": "centralize sensitive-data findings",
      "detail": "Macie findings can be sent to Security Hub for aggregated triage.",
      "url": "https://docs.aws.amazon.com/macie/latest/user/securityhub-integration.html"
    },
    {
      "source": "detective",
      "target": "guardduty",
      "type": "integration",
      "label": "investigate findings",
      "detail": "Detective can link GuardDuty findings to related entities and behavior graph context.",
      "url": "https://docs.aws.amazon.com/detective/latest/userguide/detective-investigation-about.html"
    },
    {
      "source": "audit-manager",
      "target": "organizations",
      "type": "integration",
      "label": "assess across accounts",
      "detail": "Organizations supports delegated administration and multi-account Audit Manager assessments.",
      "url": "https://docs.aws.amazon.com/audit-manager/latest/userguide/add-delegated-admin.html"
    },
    {
      "source": "directory-service",
      "target": "iam-identity-center",
      "type": "integration",
      "label": "use directory identities",
      "detail": "IAM Identity Center can connect to supported external identity sources; Directory Service can support AD identity integration patterns.",
      "url": "https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-identity-source.html"
    },
    {
      "source": "cloudtrail",
      "target": "cloudwatch",
      "type": "integration",
      "label": "route event notifications",
      "detail": "CloudTrail can deliver trail events to CloudWatch Logs for monitoring and alerting.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/send-cloudtrail-events-to-cloudwatch-logs.html"
    },
    {
      "source": "config",
      "target": "security-hub",
      "type": "integration",
      "label": "surface configuration controls",
      "detail": "Security Hub uses AWS Config rules for many security control evaluations.",
      "url": "https://docs.aws.amazon.com/securityhub/latest/userguide/controls-config-resources.html"
    },
    {
      "source": "systems-manager",
      "target": "cloudwatch",
      "type": "integration",
      "label": "monitor managed operations",
      "detail": "Systems Manager Automation can send aws:executeScript action output to CloudWatch Logs when enabled; this is an optional monitoring integration.",
      "url": "https://docs.aws.amazon.com/systems-manager/latest/userguide/automation-action-logging.html"
    },
    {
      "source": "control-tower",
      "target": "organizations",
      "type": "integration",
      "label": "govern account hierarchy",
      "detail": "Control Tower builds and governs an AWS Organizations landing zone.",
      "url": "https://docs.aws.amazon.com/controltower/latest/userguide/how-control-tower-works.html"
    },
    {
      "source": "control-tower",
      "target": "cloudformation",
      "type": "integration",
      "label": "provision governed accounts",
      "detail": "Account Factory provisions accounts using Control Tower governance workflows and CloudFormation-related resources.",
      "url": "https://docs.aws.amazon.com/controltower/latest/userguide/account-factory.html"
    },
    {
      "source": "cdk",
      "target": "cloudformation",
      "type": "integration",
      "label": "synthesize infrastructure templates",
      "detail": "CDK synthesizes infrastructure into CloudFormation templates that CloudFormation deploys.",
      "url": "https://docs.aws.amazon.com/cdk/v2/guide/ref-cli-cmd-synth.html"
    },
    {
      "source": "resource-explorer",
      "target": "organizations",
      "type": "integration",
      "label": "search member accounts",
      "detail": "Resource Explorer supports multi-account resource search through organization configuration.",
      "url": "https://docs.aws.amazon.com/resource-explorer/latest/userguide/manage-service-multi-account.html"
    },
    {
      "source": "fault-injection-service",
      "target": "cloudwatch",
      "type": "integration",
      "label": "stop experiments on alarm",
      "detail": "FIS experiment templates can use CloudWatch alarms as stop conditions.",
      "url": "https://docs.aws.amazon.com/fis/latest/userguide/stop-conditions.html"
    },
    {
      "source": "resilience-hub",
      "target": "fault-injection-service",
      "type": "integration",
      "label": "validate resilience assumptions",
      "detail": "Resilience Hub can recommend FIS experiments to validate application resilience.",
      "url": "https://docs.aws.amazon.com/resilience-hub/latest/userguide/what-is.html"
    },
    {
      "source": "cost-explorer",
      "target": "budgets",
      "type": "integration",
      "label": "investigate budget alerts",
      "detail": "Cost Explorer can analyze the spending dimensions that contributed to a Budgets threshold alert.",
      "url": "https://docs.aws.amazon.com/cost-management/latest/userguide/ce-what-is.html"
    },
    {
      "source": "cost-and-usage-report",
      "target": "cost-explorer",
      "type": "integration",
      "label": "analyze detailed billing data",
      "detail": "Cost and Usage Reports provide detailed S3 line items that can be queried alongside Cost Explorer summaries.",
      "url": "https://docs.aws.amazon.com/cur/latest/userguide/what-is-cur.html"
    },
    {
      "source": "compute-optimizer",
      "target": "cost-explorer",
      "type": "integration",
      "label": "review optimization recommendations",
      "detail": "Compute Optimizer recommendations can be used with Cost Explorer analysis to assess potential cost impact.",
      "url": "https://docs.aws.amazon.com/cost-management/latest/userguide/ce-rightsizing.html"
    },
    {
      "source": "savings-plans",
      "target": "cost-explorer",
      "type": "integration",
      "label": "model commitment purchases",
      "detail": "Cost Explorer provides Savings Plans purchase recommendations and utilization views.",
      "url": "https://docs.aws.amazon.com/savingsplans/latest/userguide/ce-sp-usingPR.html"
    },
    {
      "source": "license-manager",
      "target": "systems-manager",
      "type": "integration",
      "label": "collect software inventory",
      "detail": "License Manager can use Systems Manager inventory data to discover software installations.",
      "url": "https://docs.aws.amazon.com/license-manager/latest/userguide/inventory.html"
    },
    {
      "source": "codepipeline",
      "target": "codebuild",
      "type": "integration",
      "label": "run build actions",
      "detail": "CodePipeline invokes CodeBuild actions as stages in a delivery pipeline.",
      "url": "https://docs.aws.amazon.com/codepipeline/latest/userguide/action-reference-CodeBuild.html"
    },
    {
      "source": "codepipeline",
      "target": "codedeploy",
      "type": "integration",
      "label": "run deployment actions",
      "detail": "CodePipeline can invoke CodeDeploy actions to deploy application revisions.",
      "url": "https://docs.aws.amazon.com/codepipeline/latest/userguide/action-reference-CodeDeploy.html"
    },
    {
      "source": "codecommit",
      "target": "codepipeline",
      "type": "integration",
      "label": "trigger from repository changes",
      "detail": "CodePipeline can use CodeCommit repositories as a pipeline source.",
      "url": "https://docs.aws.amazon.com/codepipeline/latest/userguide/action-reference-CodeCommit.html"
    },
    {
      "source": "x-ray",
      "target": "cloudwatch",
      "type": "integration",
      "label": "view traces and service telemetry",
      "detail": "CloudWatch application monitoring can present X-Ray traces alongside metrics and logs.",
      "url": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/Services.html"
    },
    {
      "source": "amplify",
      "target": "cognito",
      "type": "integration",
      "label": "add application authentication",
      "detail": "Amplify applications can integrate Cognito user pools for sign-in and identity management.",
      "url": "https://docs.amplify.aws/react/build-a-backend/auth/set-up-auth/"
    },
    {
      "source": "app-studio",
      "target": "iam-identity-center",
      "type": "integration",
      "label": "control builder and user access",
      "detail": "App Studio uses workforce identity and permissions to govern access to applications and data connections.",
      "url": "https://docs.aws.amazon.com/appstudio/latest/userguide/security.html"
    },
    {
      "source": "application-discovery-service",
      "target": "migration-hub",
      "type": "integration",
      "label": "import discovered inventory",
      "detail": "Discovery Service inventory can be viewed and grouped in Migration Hub for migration tracking.",
      "url": "https://docs.aws.amazon.com/application-discovery/latest/userguide/discovery-agent.html"
    },
    {
      "source": "application-migration-service",
      "target": "migration-hub",
      "type": "integration",
      "label": "report migration progress",
      "detail": "Application Migration Service can report server migration status to Migration Hub.",
      "url": "https://docs.aws.amazon.com/migrationhub/latest/ug/whatishub.html"
    },
    {
      "source": "transform",
      "target": "application-migration-service",
      "type": "integration",
      "label": "coordinate server rehosting",
      "detail": "AWS Transform migration workflows can orchestrate server migration activities that use AWS MGN.",
      "url": "https://docs.aws.amazon.com/transform/latest/userguide/"
    },
    {
      "source": "migration-hub",
      "target": "transform",
      "type": "alternative",
      "label": "successor for new migration programs",
      "detail": "AWS Transform is AWS’s recommended destination for new projects after Migration Hub closed to new customers in November 2025.",
      "url": "https://docs.aws.amazon.com/migrationhub-strategy/latest/userguide/migrationhub-availability-change.html"
    },
    {
      "source": "application-discovery-service",
      "target": "transform",
      "type": "alternative",
      "label": "successor for new discovery",
      "detail": "AWS Transform includes discovery and assessment capabilities and is recommended for new discovery projects.",
      "url": "https://docs.aws.amazon.com/application-discovery/latest/userguide/application-discovery-service-availability-change.html"
    },
    {
      "source": "cloud9",
      "target": "systems-manager",
      "type": "alternative",
      "label": "different remote operations approach",
      "detail": "Cloud9 is an IDE; Systems Manager Session Manager provides managed shell access to instances, not an equivalent development environment.",
      "url": "https://aws.amazon.com/blogs/devops/how-to-migrate-from-aws-cloud9-to-aws-ide-toolkits-or-aws-cloudshell/"
    },
    {
      "source": "guardduty",
      "target": "eventbridge",
      "type": "pattern",
      "label": "automate finding response",
      "detail": "A common response pattern routes GuardDuty findings through EventBridge to a Lambda or ticketing workflow.",
      "url": "https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_findings_eventbridge.html"
    },
    {
      "source": "security-lake",
      "target": "resource-explorer",
      "type": "pattern",
      "label": "query security inventory with context",
      "detail": "A security analytics workflow can correlate normalized security logs with resource metadata discovered across accounts.",
      "url": "https://docs.aws.amazon.com/security-lake/latest/userguide/what-is-security-lake.html"
    },
    {
      "source": "cloudtrail",
      "target": "security-lake",
      "type": "pattern",
      "label": "centralize audit telemetry",
      "detail": "CloudTrail logs are a supported source for centralized security analysis in Security Lake.",
      "url": "https://docs.aws.amazon.com/security-lake/latest/userguide/cloudtrail-event-logs.html"
    },
    {
      "source": "cloudformation",
      "target": "organizations",
      "type": "pattern",
      "label": "deploy organization-wide stacks",
      "detail": "StackSets can deploy CloudFormation templates across target accounts and Regions.",
      "url": "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/what-is-cfnstacksets.html"
    },
    {
      "source": "budgets",
      "target": "sns",
      "type": "pattern",
      "label": "notify cost owners",
      "detail": "Budgets can notify subscribers through SNS when actual or forecast thresholds are reached.",
      "url": "https://docs.aws.amazon.com/cost-management/latest/userguide/budgets-sns-policy.html"
    },
    {
      "source": "resilience-hub",
      "target": "cloudwatch",
      "type": "pattern",
      "label": "assess telemetry-backed recovery",
      "detail": "CloudWatch alarms and operational data can support resilience assessment and recovery signals.",
      "url": "https://docs.aws.amazon.com/resilience-hub/latest/userguide/what-is.html"
    },
    {
      "source": "iam",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Identity and Access Management operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "iam-identity-center",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS IAM Identity Center APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "iam-identity-center",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS IAM Identity Center operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "cognito",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call Amazon Cognito APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "cognito",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported Amazon Cognito operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "kms",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Key Management Service APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "kms",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Key Management Service operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "cloudhsm",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS CloudHSM APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "cloudhsm",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS CloudHSM operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "secrets-manager",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Secrets Manager APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "secrets-manager",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Secrets Manager operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "certificate-manager",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Certificate Manager APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "certificate-manager",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Certificate Manager operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "private-ca",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Private Certificate Authority APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "private-ca",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Private Certificate Authority operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "waf",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS WAF APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "waf",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS WAF operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "shield",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Shield APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "shield",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Shield operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "guardduty",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call Amazon GuardDuty APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "guardduty",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported Amazon GuardDuty operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "inspector",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call Amazon Inspector APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "inspector",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported Amazon Inspector operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "macie",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call Amazon Macie APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "macie",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported Amazon Macie operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "security-hub",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Security Hub APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "security-hub",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Security Hub operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "detective",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call Amazon Detective APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "detective",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported Amazon Detective operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "security-lake",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call Amazon Security Lake APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "iam",
      "target": "audit-manager",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Audit Manager APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "audit-manager",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Audit Manager operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "artifact",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Artifact APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "artifact",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Artifact operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "resource-access-manager",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Resource Access Manager APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "resource-access-manager",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Resource Access Manager operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "directory-service",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Directory Service APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "directory-service",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Directory Service operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "verified-permissions",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call Amazon Verified Permissions APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "verified-permissions",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported Amazon Verified Permissions operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "cloudwatch",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call Amazon CloudWatch APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "iam",
      "target": "cloudtrail",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS CloudTrail APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "iam",
      "target": "config",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Config APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "config",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Config operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "systems-manager",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Systems Manager APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "systems-manager",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Systems Manager operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "organizations",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Organizations operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "control-tower",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Control Tower APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "control-tower",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Control Tower operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "cloudformation",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS CloudFormation APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "cloudformation",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS CloudFormation operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "cdk",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Cloud Development Kit (AWS CDK) APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "cdk",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Cloud Development Kit (AWS CDK) operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "compute-optimizer",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Compute Optimizer APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "compute-optimizer",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Compute Optimizer operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "trusted-advisor",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Trusted Advisor APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "trusted-advisor",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Trusted Advisor operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "service-catalog",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Service Catalog APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "service-catalog",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Service Catalog operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "health",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Health APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "health",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Health operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "well-architected",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Well-Architected Tool APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "well-architected",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Well-Architected Tool operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "resource-explorer",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Resource Explorer APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "resource-explorer",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Resource Explorer operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "cost-explorer",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Cost Explorer APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "cost-explorer",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Cost Explorer operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "budgets",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Budgets APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "budgets",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Budgets operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "cost-and-usage-report",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Data Exports (Cost and Usage Reports) APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "cost-and-usage-report",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Data Exports (Cost and Usage Reports) operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "savings-plans",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Savings Plans APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "savings-plans",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Savings Plans operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "license-manager",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS License Manager APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "license-manager",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS License Manager operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "codebuild",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS CodeBuild APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "codebuild",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS CodeBuild operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "codepipeline",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS CodePipeline APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "codepipeline",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS CodePipeline operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "codedeploy",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS CodeDeploy APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "codedeploy",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS CodeDeploy operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "codecommit",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS CodeCommit APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "codecommit",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS CodeCommit operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "codecatalyst",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call Amazon CodeCatalyst APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "codecatalyst",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported Amazon CodeCatalyst operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "cloud9",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Cloud9 APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "cloud9",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Cloud9 operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "x-ray",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS X-Ray APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "x-ray",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS X-Ray operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "amplify",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Amplify APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "amplify",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Amplify operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "app-studio",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS App Studio APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "app-studio",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS App Studio operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "application-migration-service",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Application Migration Service (AWS MGN) APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "application-migration-service",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Application Migration Service (AWS MGN) operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "application-discovery-service",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Application Discovery Service APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "application-discovery-service",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Application Discovery Service operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "migration-hub",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Migration Hub APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "migration-hub",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Migration Hub operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "transform",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Transform APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "transform",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Transform operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "resilience-hub",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Resilience Hub APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "resilience-hub",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Resilience Hub operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "iam",
      "target": "fault-injection-service",
      "type": "foundation",
      "label": "authorize service API access",
      "detail": "IAM identities and policies define who can call AWS Fault Injection Service APIs; service-specific actions and resource support are documented in AWS’s IAM service reference.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html"
    },
    {
      "source": "fault-injection-service",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit supported API activity",
      "detail": "CloudTrail records management API events for supported AWS Fault Injection Service operations, giving account administrators an audit trail of control-plane activity.",
      "url": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-aws-service-specific-topics.html"
    },
    {
      "source": "cloudtrail",
      "target": "iam",
      "type": "integration",
      "label": "audit identity changes",
      "detail": "CloudTrail records IAM management events such as identity and policy changes for investigation and governance.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html"
    },
    {
      "source": "managed-blockchain",
      "target": "kms",
      "type": "integration",
      "label": "Encrypt network data with managed keys",
      "detail": "For supported network resources, AWS KMS encrypts data at rest; a customer-managed key can be selected during creation where the network type supports it. Key policy and member access remain part of the configuration.",
      "url": "https://docs.aws.amazon.com/managed-blockchain/latest/hyperledger-fabric-dev/managed-blockchain-encryption-at-rest.html"
    },
    {
      "source": "managed-blockchain",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor network resources with CloudWatch metrics",
      "detail": "Managed Blockchain publishes network and node metrics to CloudWatch, where operators can graph them or configure alarms for supported signals.",
      "url": "https://docs.aws.amazon.com/managed-blockchain/latest/hyperledger-fabric-dev/managed-blockchain-peer-node-metrics.html"
    },
    {
      "source": "connect",
      "target": "lex",
      "type": "integration",
      "label": "Use Amazon Lex bots in contact flows",
      "detail": "A contact flow can invoke a configured Amazon Lex bot block to collect intent and slot values, then branch on the bot response.",
      "url": "https://docs.aws.amazon.com/connect/latest/adminguide/amazon-lex.html"
    },
    {
      "source": "connect",
      "target": "s3",
      "type": "integration",
      "label": "Record and store contact recordings in S3",
      "detail": "Contact recording settings store voice recordings and chat transcripts in an S3 bucket associated with the Connect instance; KMS and bucket permissions govern access.",
      "url": "https://docs.aws.amazon.com/connect/latest/adminguide/about-recording-behavior.html"
    },
    {
      "source": "appfabric",
      "target": "security-lake",
      "type": "integration",
      "label": "Send normalized audit data to security analytics",
      "detail": "AppFabric normalizes SaaS audit records to OCSF JSON and sends them through an Amazon Data Firehose delivery stream to the S3 custom-source location that Security Lake ingests. Configure the Glue table, Firehose stream, and Security Lake custom source.",
      "url": "https://docs.aws.amazon.com/appfabric/latest/adminguide/security-lake.html"
    },
    {
      "source": "appfabric",
      "target": "s3",
      "type": "integration",
      "label": "Deliver audit logs to an S3 destination",
      "detail": "An AppFabric ingestion can choose an S3 bucket as its output location and write raw JSON or normalized OCSF audit records there, subject to bucket permissions and format settings.",
      "url": "https://docs.aws.amazon.com/appfabric/latest/adminguide/prerequisites.html"
    },
    {
      "source": "chime",
      "target": "chime-sdk",
      "type": "pattern",
      "label": "Historical distinction: Chime SDK remains separately available",
      "detail": "AWS retirement guidance states that the Chime SDK remains available after the Chime application service ended on February 20, 2026. The SDK is a separate developer toolkit for embedding communications, not a continuation of hosted Chime meetings.",
      "url": "https://docs.aws.amazon.com/chime/latest/ag/amazon-chime-transition-features.html"
    },
    {
      "source": "chime",
      "target": "wickr",
      "type": "alternative",
      "label": "Historical transition alternative: Wickr",
      "detail": "AWS lists Wickr as an AWS-provided collaboration alternative for organizations transitioning from Chime. The services have different capabilities, so users and message history require a separate migration plan.",
      "url": "https://docs.aws.amazon.com/chime/latest/ag/amazon-chime-transition-features.html"
    },
    {
      "source": "chime-sdk",
      "target": "eventbridge",
      "type": "integration",
      "label": "Route meeting lifecycle events through EventBridge",
      "detail": "Meeting lifecycle events can be published to EventBridge; an EventBridge rule can then invoke a Lambda target for application-specific follow-up. This is optional event handling, not a meeting dependency.",
      "url": "https://docs.aws.amazon.com/chime-sdk/latest/dg/meeting-events.html"
    },
    {
      "source": "chime-sdk",
      "target": "s3",
      "type": "integration",
      "label": "Store meeting recordings in S3",
      "detail": "The SDK supports media capture pipelines that write meeting audio/video artifacts to S3 when recording is enabled and configured.",
      "url": "https://docs.aws.amazon.com/chime-sdk/latest/dg/capture-pipe-config.html"
    },
    {
      "source": "connect-decisions",
      "target": "s3",
      "type": "integration",
      "label": "Connect supply-chain data sources for planning",
      "detail": "Connect Decisions accepts CSV source files and stores uploaded source flows in the S3 bucket associated with the instance; mappings transform them into its common data model.",
      "url": "https://docs.aws.amazon.com/connect-decisions/latest/adminguide/connecting-your-data.html"
    },
    {
      "source": "connect-decisions",
      "target": "bedrock",
      "type": "foundation",
      "label": "Uses Bedrock cross-Region inference for supported AI features",
      "detail": "Amazon Connect Decisions uses Amazon Bedrock cross-Region inference for supported LLM features; the traffic-routing behavior depends on the Region where the Decisions instance is created.",
      "url": "https://docs.aws.amazon.com/connect-decisions/latest/adminguide/cross-region-processing.html"
    },
    {
      "source": "talent",
      "target": "connect",
      "type": "integration",
      "label": "Provisions Connect services for the hiring solution",
      "detail": "Creating a Talent instance provisions resources across Amazon Connect, Lex, Cases, Customer Profiles, Q in Connect, and SES; these components support the hiring application rather than a contact-center workflow.",
      "url": "https://docs.aws.amazon.com/talent/latest/adminguide/prerequisites.html"
    },
    {
      "source": "talent",
      "target": "ses",
      "type": "integration",
      "label": "Sends candidate evaluation invitations through SES",
      "detail": "Amazon Connect Talent uses SES to email candidates evaluation invitations. Accounts still in the SES sandbox can send only to verified addresses until production access is granted.",
      "url": "https://docs.aws.amazon.com/talent/latest/adminguide/prerequisites.html"
    },
    {
      "source": "end-user-messaging",
      "target": "pinpoint",
      "type": "alternative",
      "label": "Retains the Pinpoint mobiletargeting API namespace",
      "detail": "Push uses the Pinpoint `mobiletargeting` API namespace and `SendMessages` operation for registered endpoints. This API compatibility does not mean the retired Pinpoint engagement console or journeys are required.",
      "url": "https://docs.aws.amazon.com/end-user-messaging/latest/userguide/nx-push.html"
    },
    {
      "source": "sms-voice",
      "target": "sns",
      "type": "alternative",
      "label": "SNS provides a separate publish/subscribe path for SMS",
      "detail": "For high-volume SMS in a publish/subscribe workflow, SNS can publish the message and manage queued delivery; use the SMS and Voice v2 API when direct number and channel controls are needed.",
      "url": "https://docs.aws.amazon.com/end-user-messaging/latest/userguide/nx-overview-choosing.html"
    },
    {
      "source": "sms-voice",
      "target": "connect",
      "type": "integration",
      "label": "Connect uses messaging for customer conversations",
      "detail": "Amazon Connect customer conversations can use End User Messaging for SMS transport; Connect retains conversation routing and contact-center controls while the messaging service handles delivery.",
      "url": "https://docs.aws.amazon.com/end-user-messaging/latest/userguide/nx-overview-choosing.html"
    },
    {
      "source": "pinpoint",
      "target": "end-user-messaging",
      "type": "alternative",
      "label": "Move messaging channels while Pinpoint engagement ends",
      "detail": "Pinpoint push, SMS, and voice channel APIs continue under AWS End User Messaging, while endpoints, segments, campaigns, journeys, and engagement analytics leave Pinpoint on October 30, 2026. Select the replacement by capability.",
      "url": "https://docs.aws.amazon.com/pinpoint/latest/userguide/migrate.html"
    },
    {
      "source": "pinpoint",
      "target": "kinesis",
      "type": "alternative",
      "label": "AWS recommends Kinesis for events collection and mobile analytics",
      "detail": "AWS recommends Kinesis for event collection and mobile analytics migration; export or forward application events into a stream and rebuild downstream analytics there.",
      "url": "https://docs.aws.amazon.com/pinpoint/latest/userguide/migrate.html"
    },
    {
      "source": "ses",
      "target": "s3",
      "type": "integration",
      "label": "Store inbound email with receipt-rule actions",
      "detail": "An SES receipt rule can invoke the S3 action to store the raw inbound email and attachments in a selected bucket, with an IAM role granting SES write access.",
      "url": "https://docs.aws.amazon.com/ses/latest/dg/receiving-email-action-s3.html"
    },
    {
      "source": "ses",
      "target": "lambda",
      "type": "integration",
      "label": "Invoke Lambda from an inbound receipt rule",
      "detail": "An SES receipt rule can invoke a Lambda function with message metadata or a reference to stored mail, enabling custom inbound processing.",
      "url": "https://docs.aws.amazon.com/ses/latest/dg/receiving-email-action-lambda.html"
    },
    {
      "source": "wickr",
      "target": "kms",
      "type": "integration",
      "label": "Use customer-managed keys for supported encryption configurations",
      "detail": "Wickr supports customer-managed KMS keys for data-at-rest encryption in supported deployments; the Wickr service role needs key permissions and key availability.",
      "url": "https://docs.aws.amazon.com/wickr/latest/adminguide/what-is-wickr.html"
    },
    {
      "source": "wickr",
      "target": "iam-identity-center",
      "type": "integration",
      "label": "Federate user access where supported",
      "detail": "Wickr user sign-in can federate through a configured identity provider; use the documented SAML/SCIM setup where supported to map users and groups.",
      "url": "https://docs.aws.amazon.com/wickr/latest/adminguide/what-is-wickr.html"
    },
    {
      "source": "workmail",
      "target": "ses",
      "type": "alternative",
      "label": "AWS recommends SES for email sending migration",
      "detail": "AWS recommends SES for sending-email workloads after WorkMail; SES is an email API/SMTP service and does not replace mailbox or calendar hosting.",
      "url": "https://docs.aws.amazon.com/workmail/latest/adminguide/workmail-end-of-support.html"
    },
    {
      "source": "workmail",
      "target": "s3",
      "type": "integration",
      "label": "Export mailbox data to S3 for migration workflows",
      "detail": "WorkMail mailbox export produces migration data that can be staged in S3 for transfer to another mail platform; preserve mailbox ownership and export permissions.",
      "url": "https://docs.aws.amazon.com/workmail/latest/adminguide/workmail-end-of-support.html"
    },
    {
      "source": "support",
      "target": "cloudwatch",
      "type": "pattern",
      "label": "Use workload monitoring signals in incident response",
      "detail": "Incident Detection and Response consumes selected CloudWatch alarms through EventBridge rules during workload onboarding; alarms are mapped to an application and response runbook.",
      "url": "https://docs.aws.amazon.com/IDR/latest/userguide/observe-idr.html"
    },
    {
      "source": "support",
      "target": "eventbridge",
      "type": "integration",
      "label": "Send selected workload alarms through EventBridge",
      "detail": "Incident Detection and Response ingests selected CloudWatch alarms through AWS-managed EventBridge rules, then associates each alarm with a workload and response runbook.",
      "url": "https://docs.aws.amazon.com/IDR/latest/userguide/idr-arch.html"
    },
    {
      "source": "managedservices",
      "target": "cloudformation",
      "type": "integration",
      "label": "Use approved CloudFormation templates in managed environments",
      "detail": "AMS Accelerate supports customer change workflows and CloudFormation templates; AMS Advanced uses approved change types for managed resource changes, so the plan determines the mechanism.",
      "url": "https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/what-is-acc.html"
    },
    {
      "source": "managedservices",
      "target": "systems-manager",
      "type": "integration",
      "label": "Use Systems Manager capabilities in operations workflows",
      "detail": "AMS uses Systems Manager capabilities such as managed instances and automation documents in supported operations; enrolled account and plan configuration govern access.",
      "url": "https://docs.aws.amazon.com/managedservices/latest/accelerate-guide/what-is-acc.html"
    },
    {
      "source": "professional-services",
      "target": "well-architected",
      "type": "pattern",
      "label": "AWS engagements can apply Well-Architected guidance",
      "detail": "Professional Services engagements can use the AWS Well-Architected Framework to review workloads and turn identified risks into a remediation plan.",
      "url": "https://aws.amazon.com/professional-services/"
    },
    {
      "source": "professional-services",
      "target": "migration-hub",
      "type": "pattern",
      "label": "Migration projects can use AWS migration tooling",
      "detail": "For migration engagements, AWS Migration Hub can inventory and track application migration progress; consultants can use it as a project tool when the engagement selects it.",
      "url": "https://aws.amazon.com/professional-services/"
    },
    {
      "source": "repostprivate",
      "target": "support",
      "type": "alternative",
      "label": "Use AWS Support cases for account-specific technical assistance",
      "detail": "A re:Post Private answer can link to AWS Support, but account-specific troubleshooting and service requests still go through an AWS Support case.",
      "url": "https://docs.aws.amazon.com/repostprivate/"
    },
    {
      "source": "repostprivate",
      "target": "iam-identity-center",
      "type": "integration",
      "label": "Manage organization access through supported federation",
      "detail": "re:Post Private uses an organization instance of IAM Identity Center for workforce sign-in; identity sources can be its directory, Active Directory, or an external IdP.",
      "url": "https://docs.aws.amazon.com/repostprivate/latest/caguide/onboard-iam-identity-center.html"
    },
    {
      "source": "training",
      "target": "iam",
      "type": "pattern",
      "label": "Use IAM learning paths to build cloud security skills",
      "detail": "AWS Training offers learning paths and courses covering IAM concepts; this is a learning-topic connection, not an IAM runtime integration.",
      "url": "https://aws.amazon.com/training/"
    },
    {
      "source": "workspaces",
      "target": "directory-service",
      "type": "integration",
      "label": "Connect WorkSpaces to a supported directory",
      "detail": "WorkSpaces registers users against supported directory configurations, including AWS Managed Microsoft AD or AD Connector, to authenticate desktop sessions.",
      "url": "https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces.html"
    },
    {
      "source": "workspaces",
      "target": "kms",
      "type": "integration",
      "label": "Encrypt WorkSpaces volumes with KMS keys",
      "detail": "WorkSpaces can encrypt root and user volumes with KMS; customer-managed key policies must permit the service to create and use encrypted volumes.",
      "url": "https://docs.aws.amazon.com/workspaces/latest/adminguide/encrypt-workspaces.html"
    },
    {
      "source": "workspaces-applications",
      "target": "s3",
      "type": "integration",
      "label": "Store application image assets and user data",
      "detail": "WorkSpaces Applications home folders store user files in S3; administrators enable persistent storage for a stack and configure access for users.",
      "url": "https://docs.aws.amazon.com/appstream2/latest/developerguide/what-is-appstream.html"
    },
    {
      "source": "workspaces-applications",
      "target": "directory-service",
      "type": "integration",
      "label": "Integrate user access with directory services",
      "detail": "Windows Always-On and On-Demand fleets can join a Microsoft AD domain through a Directory Config, allowing streamed apps to use domain credentials and resources.",
      "url": "https://docs.aws.amazon.com/appstream2/latest/developerguide/what-is-appstream.html"
    },
    {
      "source": "workspaces-core",
      "target": "workspaces",
      "type": "foundation",
      "label": "WorkSpaces Core underpins partner-built desktop services",
      "detail": "WorkSpaces Core exposes managed desktop infrastructure that approved VDI partners use to build their own desktop service; it is a partner platform, not a WorkSpaces Personal dependency.",
      "url": "https://docs.aws.amazon.com/workspaces-core/latest/pg/intro.html"
    },
    {
      "source": "workspaces-core",
      "target": "ec2",
      "type": "foundation",
      "label": "Desktop sessions use AWS compute infrastructure",
      "detail": "Core provisions supported virtual desktop resources on EC2 and EBS behind partner VDI management, with AWS managing the underlying infrastructure for supported bundles.",
      "url": "https://docs.aws.amazon.com/workspaces-core/latest/pg/intro.html"
    },
    {
      "source": "workspaces-thin-client",
      "target": "workspaces",
      "type": "integration",
      "label": "Thin Client accesses supported WorkSpaces desktops",
      "detail": "A registered Thin Client environment can launch supported WorkSpaces Personal desktops after the user supplies the environment activation code.",
      "url": "https://docs.aws.amazon.com/workspaces-thin-client/latest/ug/what-is-thin-client.html"
    },
    {
      "source": "workspaces-thin-client",
      "target": "workspaces-applications",
      "type": "integration",
      "label": "Thin Client can access WorkSpaces Applications",
      "detail": "Thin Client can be configured to start a WorkSpaces Applications session; the environment stores the service connection and activation settings.",
      "url": "https://docs.aws.amazon.com/workspaces-thin-client/latest/ug/what-is-thin-client.html"
    },
    {
      "source": "dcv",
      "target": "ec2",
      "type": "integration",
      "label": "Run DCV servers on EC2 instances",
      "detail": "A DCV server can run on an EC2 instance with GPU or CPU capacity chosen for the remote application; clients connect to the host over the configured network path.",
      "url": "https://docs.aws.amazon.com/dcv/latest/adminguide/what-is-dcv.html"
    },
    {
      "source": "dcv",
      "target": "workspaces",
      "type": "integration",
      "label": "Customize supported DCV-based WorkSpaces sessions",
      "detail": "WorkSpaces supports the DCV Extension SDK for customizing supported DCV-based desktop sessions, including hardware and application extensions. Client and protocol versions determine support.",
      "url": "https://docs.aws.amazon.com/workspaces/latest/adminguide/extension-sdk.html"
    },
    {
      "source": "workspaces-secure-browser",
      "target": "iam-identity-center",
      "type": "integration",
      "label": "Use supported identity federation for portal access",
      "detail": "Secure Browser portals can use IAM Identity Center as an identity provider through supported SAML 2.0 federation settings.",
      "url": "https://docs.aws.amazon.com/workspaces-web/latest/adminguide/identity-settings.html"
    },
    {
      "source": "workspaces-secure-browser",
      "target": "vpc",
      "type": "integration",
      "label": "Configure network access to private destinations",
      "detail": "A Secure Browser portal can attach to a VPC and route sessions to private websites through configured subnets, security groups, and network paths.",
      "url": "https://docs.aws.amazon.com/workspaces-web/latest/adminguide/network-settings.html"
    },
    {
      "source": "gamelift",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor fleet and game-session metrics",
      "detail": "GameLift Servers emits fleet, session, and matchmaking metrics to CloudWatch; alarms can trigger scaling or operational notifications.",
      "url": "https://docs.aws.amazon.com/gameliftservers/latest/developerguide/monitoring-cloudwatch.html"
    },
    {
      "source": "gamelift",
      "target": "s3",
      "type": "integration",
      "label": "Store build assets and game-server content",
      "detail": "GameLift build resources are uploaded from an S3 location or local build package and then deployed to fleet compute for server launches.",
      "url": "https://docs.aws.amazon.com/gameliftservers/latest/developerguide/gamelift-build-cli-uploading-create-build.html"
    },
    {
      "source": "gamelift-streams",
      "target": "s3",
      "type": "integration",
      "label": "Store application and game build files",
      "detail": "GameLift Streams application content is uploaded to an S3 bucket and referenced by its S3 URI when the application is created.",
      "url": "https://docs.aws.amazon.com/gameliftstreams/latest/developerguide/applications.html"
    },
    {
      "source": "gamelift-streams",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor streaming sessions and service metrics",
      "detail": "GameLift Streams publishes CloudWatch metrics for stream capacity, performance, resource use, and session status.",
      "url": "https://docs.aws.amazon.com/gameliftstreams/latest/developerguide/monitoring-cloudwatch.html"
    },
    {
      "source": "freertos",
      "target": "iot",
      "type": "integration",
      "label": "Connect devices to AWS IoT Core using embedded libraries",
      "detail": "FreeRTOS libraries implement MQTT/TLS device connections to AWS IoT Core using device certificates and IoT policies.",
      "url": "https://docs.aws.amazon.com/freertos/latest/userguide/mqtt-demo-ma.html"
    },
    {
      "source": "freertos",
      "target": "iot-device-management",
      "type": "integration",
      "label": "Provision and manage connected device fleets",
      "detail": "Devices built with FreeRTOS can register with IoT Device Management and receive fleet jobs through the AWS IoT job agent/library integration.",
      "url": "https://docs.aws.amazon.com/freertos/latest/userguide/freertos-lib-jobs.html"
    },
    {
      "source": "iot",
      "target": "iot-device-defender",
      "type": "integration",
      "label": "Audit device security and detect unusual behavior",
      "detail": "Device Defender audits IoT account configuration and can ingest device-side metrics reported through IoT Device Management APIs for anomaly detection.",
      "url": "https://docs.aws.amazon.com/iot/latest/developerguide/iot-security.html"
    },
    {
      "source": "iot",
      "target": "greengrass",
      "type": "integration",
      "label": "Extend IoT Core connectivity to edge devices",
      "detail": "Greengrass Core devices authenticate with AWS IoT Core and use its registry, credentials, and cloud messaging for deployments and synchronization.",
      "url": "https://docs.aws.amazon.com/greengrass/v2/developerguide/what-is-iot-greengrass.html"
    },
    {
      "source": "iot-device-defender",
      "target": "iot",
      "type": "foundation",
      "label": "Device Defender protects connected AWS IoT fleets",
      "detail": "Device Defender evaluates IoT Core thing, certificate, and policy configurations and reports audit findings against those registered resources.",
      "url": "https://docs.aws.amazon.com/iot-device-defender/latest/devguide/what-is-device-defender.html"
    },
    {
      "source": "iot-device-defender",
      "target": "sns",
      "type": "integration",
      "label": "Publish Device Defender findings to SNS",
      "detail": "Device Defender can publish audit findings and detected violations to an SNS topic through configured mitigation or alert actions, allowing subscribers to receive the notification.",
      "url": "https://docs.aws.amazon.com/iot-device-defender/latest/devguide/what-is-device-defender.html"
    },
    {
      "source": "iot-device-management",
      "target": "iot",
      "type": "foundation",
      "label": "Manage devices registered and connected through IoT Core",
      "detail": "Device Management operates on IoT Core thing registries, fleet indexing, jobs, and secure tunnels; IoT Core provides device identity and connectivity.",
      "url": "https://docs.aws.amazon.com/iot/latest/developerguide/iot-indexing.html"
    },
    {
      "source": "iot-expresslink",
      "target": "iot",
      "type": "integration",
      "label": "Connect qualified modules to AWS IoT Core",
      "detail": "ExpressLink modules provision credentials and connect to AWS IoT Core, exposing device cloud messaging to the host microcontroller through the module command interface.",
      "url": "https://docs.aws.amazon.com/iot-expresslink/latest/gettingstartedguide/elgsg.html"
    },
    {
      "source": "iot-fleetwise",
      "target": "iot",
      "type": "integration",
      "label": "Transfer selected vehicle data into AWS IoT workflows",
      "detail": "FleetWise edge software uses AWS IoT credentials and service connectivity to transfer campaign-selected vehicle signals to the FleetWise cloud service.",
      "url": "https://docs.aws.amazon.com/iot-fleetwise/latest/developerguide/what-is-iotfleetwise.html"
    },
    {
      "source": "iot-fleetwise",
      "target": "s3",
      "type": "integration",
      "label": "Export vehicle data for storage and analytics",
      "detail": "Vehicle data can be routed from FleetWise into customer analytics/storage workflows, including S3, through configured service integrations and data-export pipelines.",
      "url": "https://docs.aws.amazon.com/iot-fleetwise/latest/developerguide/what-is-iotfleetwise.html"
    },
    {
      "source": "greengrass",
      "target": "iot",
      "type": "integration",
      "label": "Synchronize edge devices with AWS IoT Core",
      "detail": "Greengrass uses IoT Core connectivity and device identity to synchronize deployments, certificates, and cloud-to-device messages when a core device is online.",
      "url": "https://docs.aws.amazon.com/greengrass/v2/developerguide/what-is-iot-greengrass.html"
    },
    {
      "source": "greengrass",
      "target": "lambda",
      "type": "integration",
      "label": "Run Lambda functions as Greengrass components",
      "detail": "A Lambda function can be packaged as a Greengrass component and deployed to core devices; the component recipe defines the function version and lifecycle.",
      "url": "https://docs.aws.amazon.com/greengrass/v2/developerguide/run-lambda-functions.html"
    },
    {
      "source": "iot-sitewise",
      "target": "greengrass",
      "type": "integration",
      "label": "Use SiteWise Edge gateways to collect industrial data",
      "detail": "SiteWise Edge runs on a Greengrass core and uses Greengrass components to collect industrial protocol data locally before forwarding it to SiteWise.",
      "url": "https://docs.aws.amazon.com/iot-sitewise/latest/userguide/gateways.html"
    },
    {
      "source": "iot-sitewise",
      "target": "s3",
      "type": "integration",
      "label": "Store cold-tier SiteWise data in S3",
      "detail": "SiteWise cold storage uses an S3 bucket for data retained beyond the hot or warm tier; this is a configured storage tier for less frequently accessed time-series data.",
      "url": "https://docs.aws.amazon.com/iot-sitewise/latest/userguide/manage-data-storage.html"
    },
    {
      "source": "iot-twinmaker",
      "target": "grafana",
      "type": "integration",
      "label": "Visualize twin data in Grafana dashboards",
      "detail": "The TwinMaker Grafana data source plugin queries workspace entities and time-series connectors so dashboards can render twin properties and scenes.",
      "url": "https://docs.aws.amazon.com/iot-twinmaker/latest/guide/grafana-integration.html"
    },
    {
      "source": "iot-twinmaker",
      "target": "iot-sitewise",
      "type": "integration",
      "label": "Use SiteWise industrial data in digital-twin models",
      "detail": "A TwinMaker entity component can use the SiteWise data connector to read asset properties and time-series measurements into a twin model.",
      "url": "https://docs.aws.amazon.com/iot-twinmaker/latest/guide/what-is-twinmaker.html"
    },
    {
      "source": "iot-wireless",
      "target": "iot",
      "type": "integration",
      "label": "Route wireless device messages into AWS IoT Core workflows",
      "detail": "Wireless device profiles and destination rules can send decoded uplink payloads to IoT Core rules for topic-based application routing.",
      "url": "https://docs.aws.amazon.com/iot-wireless/latest/developerguide/what-is-iot-wireless.html"
    },
    {
      "source": "iot-wireless",
      "target": "lambda",
      "type": "integration",
      "label": "Invoke Lambda from wireless device rules",
      "detail": "An IoT Wireless destination can invoke Lambda with decoded LoRaWAN uplink data for application processing.",
      "url": "https://docs.aws.amazon.com/iot-wireless/latest/developerguide/what-is-iot-wireless.html"
    },
    {
      "source": "marketplace",
      "target": "iam",
      "type": "integration",
      "label": "Control procurement and subscription access with AWS account permissions",
      "detail": "Marketplace procurement is authorized through AWS account and organization permissions; IAM policies govern who can subscribe, accept offers, and manage agreements.",
      "url": "https://docs.aws.amazon.com/marketplace/latest/buyerguide/what-is-marketplace.html"
    },
    {
      "source": "marketplace",
      "target": "s3",
      "type": "integration",
      "label": "Deploy or consume eligible data products through AWS services",
      "detail": "Marketplace data products can grant access to datasets shared through AWS Data Exchange, including entitled S3 data sets where the seller publishes that delivery option.",
      "url": "https://docs.aws.amazon.com/marketplace/latest/buyerguide/what-is-marketplace.html"
    },
    {
      "source": "deadline-cloud",
      "target": "s3",
      "type": "integration",
      "label": "Use S3 for job attachments and render assets",
      "detail": "Deadline Cloud job attachments stage input assets and return output files through configured S3 buckets and storage profiles.",
      "url": "https://docs.aws.amazon.com/deadline-cloud/latest/userguide/what-is-deadline-cloud.html"
    },
    {
      "source": "deadline-cloud",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor render jobs and workers",
      "detail": "Deadline Cloud publishes service and worker metrics to CloudWatch; use the job and fleet dimensions to monitor queue health and render capacity.",
      "url": "https://docs.aws.amazon.com/deadline-cloud/latest/userguide/monitoring-overview.html"
    },
    {
      "source": "elemental-inference",
      "target": "eventbridge",
      "type": "integration",
      "label": "Route detected-event metadata through EventBridge",
      "detail": "For supported event-clipping channels, inference emits event metadata to EventBridge with event start and end times; a consumer can use that event to create a clip.",
      "url": "https://docs.aws.amazon.com/medialive/latest/ug/elemental-inference-event-clip.html"
    },
    {
      "source": "elemental-inference",
      "target": "mediatailor",
      "type": "integration",
      "label": "Use contextual metadata in downstream ad decisioning",
      "detail": "Contextual metadata can be inserted into SCTE-35 markers so MediaTailor or another downstream ad-decision system can query metadata at ad decision time.",
      "url": "https://docs.aws.amazon.com/medialive/latest/ug/elemental-inference.html"
    },
    {
      "source": "mediaconnect",
      "target": "cloudwatch",
      "type": "integration",
      "label": "Monitor MediaConnect flows with CloudWatch",
      "detail": "MediaConnect publishes flow and entitlement metrics to CloudWatch; operators can graph source health and output throughput or alarm on them.",
      "url": "https://docs.aws.amazon.com/mediaconnect/latest/ug/monitor-with-cloudwatch.html"
    },
    {
      "source": "mediaconnect",
      "target": "mediapackage",
      "type": "integration",
      "label": "Deliver MediaConnect flow sources to packaging workflows",
      "detail": "MediaPackage can ingest a MediaConnect flow as a live input, allowing the flow to transport the contribution feed and MediaPackage to create playback manifests.",
      "url": "https://docs.aws.amazon.com/mediaconnect/latest/ug/what-is.html"
    },
    {
      "source": "mediaconvert",
      "target": "s3",
      "type": "integration",
      "label": "Read input files and write transcoded outputs in S3",
      "detail": "MediaConvert job inputs and output groups can reference S3 objects; the service role needs read access to source objects and write access to destinations.",
      "url": "https://docs.aws.amazon.com/mediaconvert/latest/ug/what-is.html"
    },
    {
      "source": "mediaconvert",
      "target": "lambda",
      "type": "integration",
      "label": "Trigger transcoding jobs from application events",
      "detail": "An S3 object-created event can invoke Lambda to submit a MediaConvert job using a preset job template; configure event filtering to avoid processing outputs again.",
      "url": "https://docs.aws.amazon.com/mediaconvert/latest/ug/what-is.html"
    },
    {
      "source": "mediapackage",
      "target": "mediatailor",
      "type": "integration",
      "label": "Use MediaPackage as a MediaTailor origin",
      "detail": "MediaTailor can use a MediaPackage endpoint as its origin URL, then personalize the manifest for each playback session.",
      "url": "https://docs.aws.amazon.com/mediatailor/latest/ug/what-is.html"
    },
    {
      "source": "mediapackage",
      "target": "cloudfront",
      "type": "integration",
      "label": "Deliver packaged streams through CloudFront",
      "detail": "CloudFront can use a MediaPackage endpoint as an origin and cache eligible manifests and segments for viewer delivery.",
      "url": "https://docs.aws.amazon.com/mediapackage/latest/ug/what-is.html"
    },
    {
      "source": "mediatailor",
      "target": "mediapackage",
      "type": "integration",
      "label": "Personalize streams from MediaPackage origins",
      "detail": "A MediaTailor playback configuration points to a MediaPackage origin endpoint; MediaTailor returns the personalized manifest to the player.",
      "url": "https://docs.aws.amazon.com/mediatailor/latest/ug/what-is.html"
    },
    {
      "source": "mediatailor",
      "target": "cloudfront",
      "type": "integration",
      "label": "Deliver personalized manifests through a CDN",
      "detail": "CloudFront can sit in front of MediaTailor playback URLs; cache policies must preserve session parameters needed for personalization.",
      "url": "https://docs.aws.amazon.com/mediatailor/latest/ug/what-is.html"
    },
    {
      "source": "elemental-on-premises",
      "target": "mediaconnect",
      "type": "integration",
      "label": "Connect on-premises media sources to cloud flows",
      "detail": "Elemental on-premises encoders can contribute a live stream to MediaConnect using a supported protocol and configured flow source.",
      "url": "https://docs.aws.amazon.com/elemental-on-premises/"
    },
    {
      "source": "elemental-on-premises",
      "target": "s3",
      "type": "integration",
      "label": "Move processed media into AWS storage workflows",
      "detail": "On-premises Elemental workflows can transfer completed media files to S3 using the configured file destination or a separate ingest workflow.",
      "url": "https://docs.aws.amazon.com/elemental-on-premises/"
    },
    {
      "source": "ivs",
      "target": "s3",
      "type": "integration",
      "label": "Store recordings with configured recording destinations",
      "detail": "IVS recording configuration stores channel recordings in an S3 bucket; the recording configuration and service permissions must be set before streaming.",
      "url": "https://docs.aws.amazon.com/ivs/latest/LowLatencyUserGuide/record-to-s3.html"
    },
    {
      "source": "ivs",
      "target": "cloudfront",
      "type": "integration",
      "label": "Distribute playback using IVS playback endpoints and CDN options",
      "detail": "IVS provides managed playback endpoints backed by its delivery network; CloudFront is a separate CDN choice for custom origin and cache workflows, not a required IVS layer.",
      "url": "https://docs.aws.amazon.com/ivs/latest/LowLatencyUserGuide/what-is.html"
    },
    {
      "source": "partner-central",
      "target": "marketplace",
      "type": "integration",
      "label": "Manage eligible AWS Marketplace partner offerings",
      "detail": "Partner Central includes workflows for managing eligible Marketplace products and offers; listing publication still follows Marketplace seller requirements.",
      "url": "https://docs.aws.amazon.com/partner-central/latest/getting-started/what-is-partner-central.html"
    },
    {
      "source": "partner-central",
      "target": "training",
      "type": "integration",
      "label": "Access partner training and certification resources",
      "detail": "Partner Central exposes partner-specific training and certification resources to eligible users; access is based on the partner account and role.",
      "url": "https://docs.aws.amazon.com/partner-central/latest/getting-started/what-is-partner-central.html"
    },
    {
      "source": "braket",
      "target": "s3",
      "type": "integration",
      "label": "Store quantum task inputs and results",
      "detail": "Braket notebook and quantum-task workflows use an S3 bucket for input data, output artifacts, and result locations configured for the task.",
      "url": "https://docs.aws.amazon.com/braket/latest/developerguide/braket-get-started.html"
    },
    {
      "source": "braket",
      "target": "iam",
      "type": "integration",
      "label": "Authorize notebook and quantum-task access",
      "detail": "IAM roles authorize Braket notebooks and quantum tasks to call service APIs and access the configured S3 results bucket.",
      "url": "https://docs.aws.amazon.com/braket/latest/developerguide/braket-manage-access.html"
    },
    {
      "source": "ground-station",
      "target": "s3",
      "type": "integration",
      "label": "Deliver satellite downlink data to S3",
      "detail": "A Ground Station dataflow endpoint can deliver downlink data to S3 through the configured dataflow path and destination role.",
      "url": "https://docs.aws.amazon.com/ground-station/latest/ug/what-is.html"
    },
    {
      "source": "ground-station",
      "target": "ec2",
      "type": "integration",
      "label": "Route satellite data to EC2 endpoints",
      "detail": "Ground Station can route downlink data through a dataflow endpoint to an EC2 receiver in the selected Region and VPC network.",
      "url": "https://docs.aws.amazon.com/ground-station/latest/ug/what-is.html"
    },
    {
      "source": "supply-chain",
      "target": "connect-decisions",
      "type": "alternative",
      "label": "Current documentation presents Amazon Connect Decisions as the planning service",
      "detail": "AWS now places current planning documentation under Amazon Connect Decisions and retains AWS Supply Chain in a legacy section; the product rename is the relevant relationship.",
      "url": "https://docs.aws.amazon.com/connect-decisions/"
    },
    {
      "source": "supply-chain",
      "target": "s3",
      "type": "integration",
      "label": "Legacy workflows can connect source data for planning",
      "detail": "Legacy Supply Chain ingested structured source files through S3 connectors into its data lake; current Connect Decisions likewise creates S3 source-flow folders for uploaded CSV data.",
      "url": "https://docs.aws.amazon.com/connect-decisions/legacy/userguide/data_ingestion.html"
    },
    {
      "source": "end-user-messaging",
      "target": "sns",
      "type": "alternative",
      "label": "Compare SNS platform endpoint delivery",
      "detail": "SNS can publish to platform application endpoints, while AWS End User Messaging Push uses its application and device endpoint resources with the `SendMessages` API. Choose based on whether the application needs SNS publish/subscribe fan-out or direct push-channel controls.",
      "url": "https://docs.aws.amazon.com/end-user-messaging/latest/userguide/nx-overview-choosing.html"
    },
    {
      "source": "consolemobileapp",
      "target": "cloudwatch",
      "type": "integration",
      "label": "review mobile alarms",
      "detail": "The AWS Console Mobile Application displays supported CloudWatch alarms and dashboards for mobile operational checks.",
      "url": "https://docs.aws.amazon.com/consolemobileapp/latest/userguide/what-is-consolemobileapp.html"
    },
    {
      "source": "consolemobileapp",
      "target": "health",
      "type": "integration",
      "label": "check AWS Health events",
      "detail": "The mobile application surfaces AWS Health information so operators can review account and service issues while away from the console.",
      "url": "https://docs.aws.amazon.com/consolemobileapp/latest/userguide/what-is-consolemobileapp.html"
    },
    {
      "source": "awsconsolehelpdocs",
      "target": "cloudshell",
      "type": "integration",
      "label": "open browser shell",
      "detail": "AWS CloudShell is available from the Management Console and uses the active console Region and identity context.",
      "url": "https://docs.aws.amazon.com/cloudshell/latest/userguide/welcome.html"
    },
    {
      "source": "awsconsolehelpdocs",
      "target": "iam-identity-center",
      "type": "foundation",
      "label": "authenticate workforce users",
      "detail": "IAM Identity Center can provide workforce single sign-on into AWS accounts and the Management Console.",
      "url": "https://docs.aws.amazon.com/singlesignon/latest/userguide/what-is.html"
    },
    {
      "source": "account-billing",
      "target": "cost-explorer",
      "type": "integration",
      "label": "analyze historical spend",
      "detail": "Cost Explorer is part of AWS cost management and provides interactive analysis of historical and forecasted costs.",
      "url": "https://docs.aws.amazon.com/cost-management/latest/userguide/ce-what-is.html"
    },
    {
      "source": "account-billing",
      "target": "organizations",
      "type": "integration",
      "label": "consolidate linked account billing",
      "detail": "Consolidated billing combines charges for organization member accounts and exposes linked-account cost views.",
      "url": "https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/consolidated-billing.html"
    },
    {
      "source": "pricingplanmanager",
      "target": "account-billing",
      "type": "integration",
      "label": "review plan charges",
      "detail": "AWS billing surfaces account charges and plan-related billing information for enrolled services.",
      "url": "https://docs.aws.amazon.com/PricingPlanManager/latest/UserGuide/overview.html"
    },
    {
      "source": "pricingplanmanager",
      "target": "pricing-calculator",
      "type": "pattern",
      "label": "compare metered scenarios",
      "detail": "Pricing Calculator can estimate service usage scenarios to compare with the documented flat-rate plan coverage.",
      "url": "https://docs.aws.amazon.com/pricing-calculator/latest/userguide/what-is-pricing-calculator.html"
    },
    {
      "source": "pricing-calculator",
      "target": "ec2",
      "type": "integration",
      "label": "estimate compute scenarios",
      "detail": "Pricing Calculator includes EC2 instance, storage, and usage assumptions in architecture estimates.",
      "url": "https://docs.aws.amazon.com/pricing-calculator/latest/userguide/what-is-pricing-calculator.html"
    },
    {
      "source": "pricing-calculator",
      "target": "s3",
      "type": "integration",
      "label": "estimate storage and requests",
      "detail": "Pricing Calculator estimates S3 storage and request costs from user-provided usage assumptions.",
      "url": "https://docs.aws.amazon.com/pricing-calculator/latest/userguide/what-is-pricing-calculator.html"
    },
    {
      "source": "signer",
      "target": "lambda",
      "type": "integration",
      "label": "verify signed deployment packages",
      "detail": "Lambda code signing can validate deployment packages signed through AWS Signer before allowing function code updates.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/configuration-codesigning.html"
    },
    {
      "source": "signer",
      "target": "iot-device-management",
      "type": "integration",
      "label": "sign device software",
      "detail": "AWS Signer supports signing software packages for supported IoT and device workflows.",
      "url": "https://docs.aws.amazon.com/signer/latest/developerguide/Welcome.html"
    },
    {
      "source": "appconfig",
      "target": "cloudwatch",
      "type": "integration",
      "label": "roll back on alarm",
      "detail": "AppConfig monitors configured CloudWatch alarms during deployment and can roll back a configuration deployment when an alarm triggers.",
      "url": "https://docs.aws.amazon.com/appconfig/latest/userguide/monitoring-deployments.html"
    },
    {
      "source": "appconfig",
      "target": "systems-manager",
      "type": "integration",
      "label": "source parameter configuration",
      "detail": "AppConfig configuration profiles can retrieve configuration data from Systems Manager Parameter Store.",
      "url": "https://docs.aws.amazon.com/appconfig/latest/userguide/appconfig-creating-configuration-profile.html"
    },
    {
      "source": "ec2-auto-scaling",
      "target": "ec2",
      "type": "foundation",
      "label": "manage EC2 fleet capacity",
      "detail": "Auto Scaling groups launch, maintain, and terminate EC2 instances using launch templates and group capacity settings.",
      "url": "https://docs.aws.amazon.com/autoscaling/ec2/userguide/what-is-amazon-ec2-auto-scaling.html"
    },
    {
      "source": "ec2-auto-scaling",
      "target": "cloudwatch",
      "type": "integration",
      "label": "scale from metrics",
      "detail": "Auto Scaling policies can use CloudWatch metrics and alarms to adjust group capacity.",
      "url": "https://docs.aws.amazon.com/autoscaling/ec2/userguide/as-scaling-target-tracking.html"
    },
    {
      "source": "securityagent",
      "target": "codecommit",
      "type": "integration",
      "label": "review connected repositories",
      "detail": "AWS Security Agent documents repository integrations for source review workflows; supported providers include GitHub, GitLab, Bitbucket, and GitHub Enterprise Server.",
      "url": "https://docs.aws.amazon.com/securityagent/latest/userguide/what-is.html"
    },
    {
      "source": "securityagent",
      "target": "iam",
      "type": "foundation",
      "label": "control agent access",
      "detail": "IAM and IAM Identity Center control access to the AWS Security Agent console and APIs.",
      "url": "https://docs.aws.amazon.com/securityagent/latest/userguide/infrastructure-security.html"
    },
    {
      "source": "cli",
      "target": "iam",
      "type": "foundation",
      "label": "sign API requests with credentials",
      "detail": "AWS CLI requests use configured credentials and IAM permissions to authorize AWS service API calls.",
      "url": "https://docs.aws.amazon.com/cli/latest/userguide/cli-chap-authentication.html"
    },
    {
      "source": "cli",
      "target": "cloudformation",
      "type": "integration",
      "label": "deploy infrastructure stacks",
      "detail": "The AWS CLI exposes CloudFormation commands for creating, updating, and inspecting infrastructure stacks.",
      "url": "https://docs.aws.amazon.com/cli/latest/reference/cloudformation/"
    },
    {
      "source": "data-lifecycle-manager",
      "target": "ebs",
      "type": "foundation",
      "label": "manage EBS snapshots",
      "detail": "Data Lifecycle Manager creates and retains EBS snapshots and EBS-backed AMIs using lifecycle policies.",
      "url": "https://docs.aws.amazon.com/ebs/latest/userguide/snapshot-lifecycle.html"
    },
    {
      "source": "data-lifecycle-manager",
      "target": "kms",
      "type": "integration",
      "label": "encrypt managed snapshots",
      "detail": "EBS snapshots can use EBS encryption and KMS keys according to the source volume and copy configuration.",
      "url": "https://docs.aws.amazon.com/ebs/latest/userguide/ebs-encryption.html"
    },
    {
      "source": "devopsagent",
      "target": "cloudwatch",
      "type": "integration",
      "label": "correlate telemetry",
      "detail": "AWS DevOps Agent connects operational observability data such as metrics, logs, and alarms to incident investigations.",
      "url": "https://docs.aws.amazon.com/devopsagent/latest/userguide/about-aws-devops-agent-what-is-a-devops-agent-topology.html"
    },
    {
      "source": "devopsagent",
      "target": "cloudtrail",
      "type": "integration",
      "label": "use audit context",
      "detail": "AWS DevOps Agent can use AWS operational context and CloudTrail data through configured account access during investigations.",
      "url": "https://docs.aws.amazon.com/devopsagent/latest/userguide/aws-devops-agent-security.html"
    },
    {
      "source": "launchwizard",
      "target": "cloudformation",
      "type": "integration",
      "label": "deploy generated resources",
      "detail": "Launch Wizard uses AWS infrastructure templates to provision resources for supported application deployments.",
      "url": "https://docs.aws.amazon.com/launchwizard/latest/userguide/launch-wizard-sap-launch-artifacts-cloudformation.html"
    },
    {
      "source": "launchwizard",
      "target": "ec2",
      "type": "integration",
      "label": "size application compute",
      "detail": "Launch Wizard recommends and deploys EC2 resources for supported enterprise application scenarios.",
      "url": "https://docs.aws.amazon.com/launchwizard/latest/userguide/how-launch-wizard-sap-works.html"
    },
    {
      "source": "grafana",
      "target": "prometheus",
      "type": "integration",
      "label": "visualize PromQL metrics",
      "detail": "Amazon Managed Grafana can use Amazon Managed Service for Prometheus workspaces as a data source.",
      "url": "https://docs.aws.amazon.com/grafana/latest/userguide/amazon-prometheus-data-source.html"
    },
    {
      "source": "grafana",
      "target": "cloudwatch",
      "type": "integration",
      "label": "visualize AWS metrics",
      "detail": "Amazon Managed Grafana includes an AWS data source integration for CloudWatch metrics and logs.",
      "url": "https://docs.aws.amazon.com/grafana/latest/userguide/AMG-data-sources.html"
    },
    {
      "source": "prometheus",
      "target": "eks",
      "type": "integration",
      "label": "collect Kubernetes metrics",
      "detail": "Amazon Managed Service for Prometheus supports metrics from Amazon EKS and other Kubernetes environments using Prometheus-compatible collection.",
      "url": "https://docs.aws.amazon.com/prometheus/latest/userguide/AMP-onboard-ingest-metrics.html"
    },
    {
      "source": "prometheus",
      "target": "grafana",
      "type": "integration",
      "label": "query workspace dashboards",
      "detail": "Grafana can query Managed Prometheus workspaces through the Prometheus data source and AWS authentication.",
      "url": "https://docs.aws.amazon.com/prometheus/latest/userguide/AMP-onboard-query-standalone-grafana.html"
    },
    {
      "source": "proton",
      "target": "cloudformation",
      "type": "foundation",
      "label": "leave deployed stacks intact",
      "detail": "AWS states that Proton-deployed CloudFormation stacks and managed resources remain after Proton support ends.",
      "url": "https://docs.aws.amazon.com/proton/latest/userguide/proton-end-of-support.html"
    },
    {
      "source": "proton",
      "target": "codepipeline",
      "type": "alternative",
      "label": "replace delivery workflows",
      "detail": "AWS lists CodePipeline and CodeBuild among possible replacements for Proton deployment pipelines.",
      "url": "https://docs.aws.amazon.com/proton/latest/userguide/proton-end-of-support.html"
    },
    {
      "source": "resource-groups",
      "target": "systems-manager",
      "type": "integration",
      "label": "operate selected group members",
      "detail": "Supported Systems Manager tools can target resources organized in AWS Resource Groups.",
      "url": "https://docs.aws.amazon.com/ARG/latest/userguide/integrated-services-list.html"
    },
    {
      "source": "resource-groups",
      "target": "resource-explorer",
      "type": "alternative",
      "label": "search resources across Regions",
      "detail": "Resource Explorer is the AWS service for searching and discovering resources across Regions; Resource Groups organizes selected resources for management.",
      "url": "https://docs.aws.amazon.com/resource-explorer/latest/userguide/welcome.html"
    },
    {
      "source": "smc",
      "target": "service-catalog",
      "type": "integration",
      "label": "expose product requests in ITSM",
      "detail": "Service Management Connector can expose AWS Service Catalog products and provisioning workflows in supported ITSM platforms.",
      "url": "https://docs.aws.amazon.com/smc/latest/ag/sn-configure-sc.html"
    },
    {
      "source": "smc",
      "target": "systems-manager",
      "type": "integration",
      "label": "operate incident workflows in ITSM",
      "detail": "The Service Management Connector can expose Systems Manager Automation, OpsCenter, Change Manager, and Incident Manager workflows through supported ITSM integrations.",
      "url": "https://docs.aws.amazon.com/systems-manager/latest/userguide/integrations-partners-servicenow.html"
    },
    {
      "source": "servicequotas",
      "target": "cloudwatch",
      "type": "integration",
      "label": "monitor quota utilization",
      "detail": "Service Quotas integrates with CloudWatch for monitoring selected quota usage and utilization.",
      "url": "https://docs.aws.amazon.com/servicequotas/latest/userguide/configure-cloudwatch.html"
    },
    {
      "source": "servicequotas",
      "target": "ec2",
      "type": "integration",
      "label": "request compute limit changes",
      "detail": "Service Quotas exposes adjustable EC2 quotas and provides workflows to request increases.",
      "url": "https://docs.aws.amazon.com/servicequotas/latest/userguide/request-quota-increase.html"
    },
    {
      "source": "sustainability",
      "target": "well-architected",
      "type": "pattern",
      "label": "review workload sustainability",
      "detail": "The AWS Well-Architected Sustainability Pillar provides workload design practices for reducing environmental impact.",
      "url": "https://docs.aws.amazon.com/wellarchitected/latest/sustainability-pillar/sustainability-pillar.html"
    },
    {
      "source": "sustainability",
      "target": "cost-explorer",
      "type": "pattern",
      "label": "inspect usage efficiency",
      "detail": "Cost and usage analysis can help teams identify resource utilization changes relevant to workload efficiency assessments.",
      "url": "https://docs.aws.amazon.com/sustainability/latest/userguide/what-is-sustainability.html"
    },
    {
      "source": "tnb",
      "target": "eks",
      "type": "integration",
      "label": "run containerized network functions",
      "detail": "AWS TNB can provision AWS infrastructure and deploy containerized telecom network functions using services such as EKS.",
      "url": "https://docs.aws.amazon.com/tnb/latest/ug/what-is-tnb.html"
    },
    {
      "source": "tnb",
      "target": "vpc",
      "type": "foundation",
      "label": "provision network infrastructure",
      "detail": "AWS TNB provisions and monitors supporting AWS network infrastructure including VPC resources for telecom services.",
      "url": "https://docs.aws.amazon.com/tnb/latest/ug/what-is-tnb.html"
    },
    {
      "source": "notifications",
      "target": "health",
      "type": "integration",
      "label": "deliver Health events",
      "detail": "AWS User Notifications supports AWS Health event notifications with filtering and delivery configurations.",
      "url": "https://docs.aws.amazon.com/notifications/latest/userguide/managed-notifications-health.html"
    },
    {
      "source": "notifications",
      "target": "q-developer",
      "type": "integration",
      "label": "send notifications into chat apps",
      "detail": "AWS User Notifications supports delivery to Amazon Q Developer in chat applications for supported notifications.",
      "url": "https://docs.aws.amazon.com/notifications/latest/userguide/what-is-service.html"
    },
    {
      "source": "well-architected-agent",
      "target": "organizations",
      "type": "integration",
      "label": "analyze multiple accounts",
      "detail": "Well-Architected Agent profiles can include multiple AWS accounts through configured cross-account access roles.",
      "url": "https://docs.aws.amazon.com/wellarchitected/latest/userguide/agent-concepts.html"
    },
    {
      "source": "well-architected-agent",
      "target": "cloudformation",
      "type": "integration",
      "label": "review IaC before deploy",
      "detail": "Architecture reviews analyze CloudFormation and other supported IaC templates and return recommendations with updated templates.",
      "url": "https://docs.aws.amazon.com/wellarchitected/latest/userguide/agent-concepts.html"
    },
    {
      "source": "datatransferterminal",
      "target": "s3",
      "type": "integration",
      "label": "transfer data to AWS storage",
      "detail": "Data Transfer Terminal provides physical transfer connectivity for moving customer data to AWS cloud services such as S3.",
      "url": "https://docs.aws.amazon.com/datatransferterminal/latest/userguide/what-is-dtt.html"
    },
    {
      "source": "datatransferterminal",
      "target": "snowball",
      "type": "alternative",
      "label": "compare offline transfer options",
      "detail": "AWS Snowball is another offline data transfer approach; choose between scheduled terminal access and shipped devices based on distance, scale, and schedule.",
      "url": "https://docs.aws.amazon.com/snowball/latest/developer-guide/whatisedge.html"
    },
    {
      "source": "evs",
      "target": "ec2",
      "type": "foundation",
      "label": "run VCF on EC2 capacity",
      "detail": "Amazon Elastic VMware Service deploys VMware Cloud Foundation components on Amazon EC2 instances inside the customer VPC.",
      "url": "https://docs.aws.amazon.com/evs/latest/userguide/what-is-evs.html"
    },
    {
      "source": "evs",
      "target": "vpc",
      "type": "foundation",
      "label": "place VMware environment in VPC",
      "detail": "EVS environments are deployed within a customer-managed VPC with documented network and subnet prerequisites.",
      "url": "https://docs.aws.amazon.com/evs/latest/userguide/architecture.html"
    },
    {
      "source": "mainframe-modernization",
      "target": "s3",
      "type": "integration",
      "label": "stage modernization datasets",
      "detail": "Mainframe Modernization File Transfer can transfer mainframe data sets to Amazon S3 for migration and modernization workflows.",
      "url": "https://docs.aws.amazon.com/m2/latest/userguide/what-is-filetransfer.html"
    },
    {
      "source": "mainframe-modernization",
      "target": "transform",
      "type": "alternative",
      "label": "assess modernization paths",
      "detail": "AWS Transform for mainframe is a distinct service route for mainframe analysis and modernization; compare its supported transformation path with Mainframe Modernization runtimes.",
      "url": "https://docs.aws.amazon.com/transform/latest/userguide/what-is-service.html"
    },
    {
      "source": "schemaconversiontool",
      "target": "dms",
      "type": "integration",
      "label": "pair schema and data migration",
      "detail": "AWS SCT can prepare target schemas while AWS Database Migration Service migrates database data in a migration project.",
      "url": "https://docs.aws.amazon.com/dms/latest/userguide/CHAP_Tasks.Creating.html"
    },
    {
      "source": "schemaconversiontool",
      "target": "rds",
      "type": "integration",
      "label": "convert toward managed database targets",
      "detail": "AWS SCT supports conversion workflows targeting supported Amazon RDS database engines.",
      "url": "https://docs.aws.amazon.com/SchemaConversionTool/latest/userguide/CHAP_Converting.html"
    },
    {
      "source": "network-security-manager",
      "target": "waf",
      "type": "integration",
      "label": "deploy WAF policies centrally",
      "detail": "Network Security Manager supports centralized AWS WAF rule and policy deployment across scoped accounts and resources.",
      "url": "https://docs.aws.amazon.com/network-security-manager/latest/devguide/concepts.html"
    },
    {
      "source": "network-security-manager",
      "target": "shield",
      "type": "integration",
      "label": "apply Shield protections",
      "detail": "Network Security Manager documents AWS Shield Advanced as a supported protection managed through centralized policies.",
      "url": "https://docs.aws.amazon.com/network-security-manager/latest/devguide/concepts.html"
    },
    {
      "source": "clouddirectory",
      "target": "iam",
      "type": "integration",
      "label": "authorize directory API calls",
      "detail": "IAM policies control access to Cloud Directory API actions and directory resources.",
      "url": "https://docs.aws.amazon.com/clouddirectory/latest/developerguide/iam_auth_access_accesscontrol_identitybased.html"
    },
    {
      "source": "firewall-manager",
      "target": "organizations",
      "type": "foundation",
      "label": "govern member account policies",
      "detail": "Firewall Manager uses AWS Organizations to apply security policies across organization accounts.",
      "url": "https://docs.aws.amazon.com/waf/latest/developerguide/fms-chapter.html"
    },
    {
      "source": "firewall-manager",
      "target": "waf",
      "type": "integration",
      "label": "apply WAF policies across accounts",
      "detail": "Firewall Manager creates and monitors AWS WAF policies for in-scope resources across accounts.",
      "url": "https://docs.aws.amazon.com/waf/latest/developerguide/working-with-policies.html"
    },
    {
      "source": "govcloud-us",
      "target": "iam",
      "type": "foundation",
      "label": "manage isolated account access",
      "detail": "GovCloud account access uses AWS identity and permission controls in the GovCloud partition, with partition-specific operational considerations.",
      "url": "https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/controlling-access.html"
    },
    {
      "source": "govcloud-us",
      "target": "vpc",
      "type": "foundation",
      "label": "build isolated workload networks",
      "detail": "GovCloud workloads use VPC networking within supported GovCloud Regions and service availability boundaries.",
      "url": "https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-differences.html"
    },
    {
      "source": "payment-cryptography",
      "target": "cloudtrail",
      "type": "integration",
      "label": "audit payment key operations",
      "detail": "AWS Payment Cryptography integrates with CloudTrail so API activity can be logged for audit and investigation.",
      "url": "https://docs.aws.amazon.com/payment-cryptography/latest/userguide/monitoring-cloudtrail.html"
    },
    {
      "source": "security-ir",
      "target": "guardduty",
      "type": "integration",
      "label": "triage threat findings",
      "detail": "Security Incident Response ingests and triages threat findings from configured detection sources including GuardDuty.",
      "url": "https://docs.aws.amazon.com/security-ir/latest/userguide/what-is.html"
    },
    {
      "source": "security-ir",
      "target": "eventbridge",
      "type": "integration",
      "label": "route case lifecycle events",
      "detail": "Security Incident Response publishes supported case and membership events that EventBridge rules or Pipes can route to other systems.",
      "url": "https://docs.aws.amazon.com/security-ir/latest/userguide/eventbridge.html"
    },
    {
      "source": "b2b-data-interchange",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke AWS B2B Data Interchange; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/b2bi/"
    },
    {
      "source": "b2b-data-interchange",
      "target": "s3",
      "type": "integration",
      "label": "Stage EDI documents",
      "detail": "B2B Data Interchange supports S3-based document exchange workflows.",
      "url": "https://docs.aws.amazon.com/b2bi/"
    },
    {
      "source": "mwaa",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Amazon MWAA; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/mwaa/"
    },
    {
      "source": "mwaa",
      "target": "s3",
      "type": "foundation",
      "label": "Stores required DAG code",
      "detail": "Every MWAA environment uses an S3 bucket and DAG folder for DAG code; plugins and Python dependencies can also be stored there. The bucket must have public access blocked and versioning enabled.",
      "url": "https://docs.aws.amazon.com/mwaa/latest/userguide/create-environment.html"
    },
    {
      "source": "location",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Amazon Location Service; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/location/"
    },
    {
      "source": "location",
      "target": "lambda",
      "type": "pattern",
      "label": "Call location APIs from application code",
      "detail": "An application can call Amazon Location APIs from Lambda using SDKs and scoped permissions.",
      "url": "https://docs.aws.amazon.com/location/"
    },
    {
      "source": "amazonarc",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Amazon Application Recovery Controller (ARC); grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/amazonarc/"
    },
    {
      "source": "interconnect",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke AWS Interconnect; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/interconnect/"
    },
    {
      "source": "rtb-fabric",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke AWS RTB Fabric; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/rtb-fabric/"
    },
    {
      "source": "elastic-disaster-recovery",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke AWS Elastic Disaster Recovery; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/drs/"
    },
    {
      "source": "sagemaker-platform",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Amazon SageMaker; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/next-generation-sagemaker/"
    },
    {
      "source": "cloudsearch",
      "target": "opensearch",
      "type": "alternative",
      "label": "Alternative for modern search workloads",
      "detail": "Amazon OpenSearch Service is a modern search option referenced in AWS guidance; migration requires schema and query review.",
      "url": "https://docs.aws.amazon.com/cloudsearch/latest/developerguide/what-is-cloudsearch.html"
    },
    {
      "source": "data-exchange",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke AWS Data Exchange; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/data-exchange/"
    },
    {
      "source": "data-exchange",
      "target": "s3",
      "type": "integration",
      "label": "Deliver data assets",
      "detail": "Data Exchange supports product delivery to destinations such as S3 for supported asset types.",
      "url": "https://docs.aws.amazon.com/data-exchange/"
    },
    {
      "source": "data-pipeline",
      "target": "glue",
      "type": "alternative",
      "label": "Migration option: AWS Glue",
      "detail": "AWS documents AWS Glue as one migration option for AWS Data Pipeline workloads; map semantics before migrating.",
      "url": "https://docs.aws.amazon.com/datapipeline/latest/DeveloperGuide/migration.html"
    },
    {
      "source": "connecthealth",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Amazon Connect Health; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/connecthealth/"
    },
    {
      "source": "connecthealth",
      "target": "lambda",
      "type": "pattern",
      "label": "Integrate application workflows",
      "detail": "Connect Health integrates with EHR systems through FHIR R4; Lambda may be used in optional surrounding application workflows.",
      "url": "https://docs.aws.amazon.com/connecthealth/latest/userguide/what-is-service.html"
    },
    {
      "source": "oracle-database",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Oracle Database@AWS; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/odb/"
    },
    {
      "source": "claude-platform",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Claude Platform on AWS; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/claude-platform/"
    },
    {
      "source": "claude-platform",
      "target": "bedrock",
      "type": "alternative",
      "label": "Alternative model access path",
      "detail": "Claude Platform on AWS is a distinct Anthropic-operated path; Bedrock has a separate AWS-operated inference stack.",
      "url": "https://docs.aws.amazon.com/claude-platform/latest/userguide/welcome.html"
    },
    {
      "source": "codeguru",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Amazon CodeGuru; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/codeguru/"
    },
    {
      "source": "codeguru",
      "target": "lambda",
      "type": "pattern",
      "label": "Profile application workloads",
      "detail": "CodeGuru Profiler can profile supported application workloads; instrumentation and setup are required.",
      "url": "https://docs.aws.amazon.com/codeguru/"
    },
    {
      "source": "comprehend-medical",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Amazon Comprehend Medical; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/comprehend-medical/"
    },
    {
      "source": "comprehend-medical",
      "target": "s3",
      "type": "pattern",
      "label": "Stage text for batch processing",
      "detail": "S3 can serve as input or output for supported batch text workflows when configured.",
      "url": "https://docs.aws.amazon.com/comprehend-medical/"
    },
    {
      "source": "dlami",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke AWS Deep Learning AMIs; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/dlami/"
    },
    {
      "source": "deep-learning-containers",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke AWS Deep Learning Containers; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/deep-learning-containers/"
    },
    {
      "source": "devops-guru",
      "target": "cloudwatch",
      "type": "alternative",
      "label": "Migration path for alerting",
      "detail": "AWS recommends CloudWatch for metric anomaly detection and alerting as DevOps Guru support ends.",
      "url": "https://docs.aws.amazon.com/devops-guru/latest/userguide/devops-guru-end-of-support.html"
    },
    {
      "source": "monitron",
      "target": "kinesis",
      "type": "integration",
      "label": "Export condition data",
      "detail": "Existing Monitron workflows can export data to Kinesis or S3; confirm configured export paths.",
      "url": "https://docs.aws.amazon.com/Monitron/latest/user-guide/what-is-monitron.html"
    },
    {
      "source": "nova",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Amazon Nova; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/nova/"
    },
    {
      "source": "nova",
      "target": "bedrock",
      "type": "foundation",
      "label": "Run models through Bedrock",
      "detail": "Amazon Nova models are accessed through Amazon Bedrock inference APIs; availability varies by model and Region.",
      "url": "https://docs.aws.amazon.com/nova/latest/userguide/what-is-nova.html"
    },
    {
      "source": "nova-act",
      "target": "iam",
      "type": "integration",
      "label": "Control access with IAM",
      "detail": "IAM policies scope which principals can configure or invoke Amazon Nova Act; grant only actions required by the selected workflow. This is an access-control integration, not a dependency on IAM-specific application architecture.",
      "url": "https://docs.aws.amazon.com/nova-act/"
    },
    {
      "source": "nova-act",
      "target": "lambda",
      "type": "pattern",
      "label": "Deploy workflow integrations",
      "detail": "Nova Act workflows can be developed locally and deployed to its AWS service using documented tooling.",
      "url": "https://docs.aws.amazon.com/nova-act/latest/userguide/getting-started.html"
    },
    {
      "source": "panorama",
      "target": "sagemaker",
      "type": "alternative",
      "label": "Alternative for computer-vision model workflows",
      "detail": "AWS identifies SageMaker as one option for building computer-vision models during Panorama migration.",
      "url": "https://docs.aws.amazon.com/panorama/latest/dev/panorama-end-of-support.html"
    },
    {
      "source": "kiro",
      "target": "iam-identity-center",
      "type": "integration",
      "label": "Sign in with IAM Identity Center",
      "detail": "Kiro supports AWS IAM Identity Center as a sign-in provider. Enterprise setup requires an Identity Center instance and a supported Region; this is an optional identity path, not a requirement for every Kiro user.",
      "url": "https://kiro.dev/docs/cli/authentication/"
    },
    {
      "source": "kiro",
      "target": "lambda",
      "type": "integration",
      "label": "Run configured Lambda CLI operations",
      "detail": "Kiro CLI’s built-in AWS tool can make AWS CLI calls; its documented configuration example includes Lambda among the services that can be allowed. The user still needs AWS credentials and matching tool permissions.",
      "url": "https://kiro.dev/docs/cli/reference/built-in-tools/"
    },
    {
      "source": "linux",
      "target": "ec2",
      "type": "integration",
      "label": "Launch Amazon Linux AMIs on EC2",
      "detail": "Amazon Linux 2 is available as an AMI that can be launched on EC2; AWS identifies Amazon Linux 2023 as its successor.",
      "url": "https://docs.aws.amazon.com/linux/al2/ug/ec2.html"
    },
    {
      "source": "imagebuilder",
      "target": "ec2",
      "type": "integration",
      "label": "Build AMIs for EC2 instances",
      "detail": "EC2 Image Builder creates AMIs, which are the virtual-machine images used to launch EC2 instances.",
      "url": "https://docs.aws.amazon.com/imagebuilder/latest/userguide/what-is-image-builder.html"
    },
    {
      "source": "serverless-application-model",
      "target": "lambda",
      "type": "integration",
      "label": "Define Lambda functions with SAM",
      "detail": "The AWS SAM `AWS::Serverless::Function` resource creates a Lambda function and its execution role.",
      "url": "https://docs.aws.amazon.com/serverless-application-model/latest/developerguide/sam-resource-function.html"
    },
    {
      "source": "serverlessrepo",
      "target": "lambda",
      "type": "integration",
      "label": "Deploy applications from the Lambda console",
      "detail": "The Serverless Application Repository is integrated with the Lambda console, where users can browse and deploy published serverless applications.",
      "url": "https://docs.aws.amazon.com/serverlessrepo/latest/devguide/serverlessrepo-consuming-applications.html"
    },
    {
      "source": "app2container",
      "target": "ecs",
      "type": "integration",
      "label": "Generate ECS deployment artifacts",
      "detail": "App2Container can containerize supported applications and generate deployment artifacts for Amazon ECS, Amazon EKS, or App Runner.",
      "url": "https://docs.aws.amazon.com/app2container/latest/UserGuide/what-is-a2c.html"
    },
    {
      "source": "infrastructure-composer",
      "target": "lambda",
      "type": "integration",
      "label": "Compose Lambda application templates",
      "detail": "Infrastructure Composer can import Lambda functions and produce AWS SAM or CloudFormation templates for application architectures.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/foundation-iac-getting-started.html"
    },
    {
      "source": "res",
      "target": "ec2",
      "type": "integration",
      "label": "Launch EC2 research desktops",
      "detail": "Research and Engineering Studio launches virtual desktops on EC2. This applies to existing deployments; RES is no longer available for new adoption as of September 29, 2026.",
      "url": "https://docs.aws.amazon.com/res/latest/ug/prerequisites.html"
    },
    {
      "source": "app-mesh",
      "target": "vpc-lattice",
      "type": "alternative",
      "label": "Migration path to VPC Lattice",
      "detail": "AWS provides migration guides from App Mesh to VPC Lattice. App Mesh ended support September 30, 2026, so this is a transition reference rather than an available integration.",
      "url": "https://aws.amazon.com/blogs/containers/migrating-from-aws-app-mesh-to-amazon-vpc-lattice/"
    },
    {
      "source": "cloudcontrolapi",
      "target": "cloudformation",
      "type": "foundation",
      "label": "Operate CloudFormation resource types",
      "detail": "Cloud Control API performs resource operations through supported CloudFormation registry resource types. The registry provides the type schemas and permissions; AWS notes that some listed types do not support Cloud Control API.",
      "url": "https://docs.aws.amazon.com/cloudcontrolapi/latest/userguide/resource-types.html"
    },
    {
      "source": "codeartifact",
      "target": "kms",
      "type": "foundation",
      "label": "Encrypt package assets at rest",
      "detail": "CodeArtifact encrypts all assets in a domain with one KMS key. AWS managed keys are used by default; a customer-managed KMS key can be selected when creating the domain.",
      "url": "https://docs.aws.amazon.com/codeartifact/latest/ug/security-encryption.html"
    },
    {
      "source": "corretto",
      "target": "lambda",
      "type": "integration",
      "label": "Build Java Lambda container images",
      "detail": "AWS Lambda documentation uses Amazon Corretto as a Java base image when building a Lambda container image. This is a build-time choice for container deployments, not a requirement for every Java Lambda function.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/java-image.html"
    },
    {
      "source": "devicefarm",
      "target": "vpc",
      "type": "integration",
      "label": "Test private apps through VPC connectivity",
      "detail": "Device Farm can connect private devices and their host machines to VPC endpoints through an elastic network interface, allowing tests to reach isolated services. The documented VPC-ENI option is limited to private devices in us-west-2.",
      "url": "https://docs.aws.amazon.com/devicefarm/latest/developerguide/vpc-eni.html"
    },
    {
      "source": "machine-learning",
      "target": "sagemaker",
      "type": "alternative",
      "label": "Use the current ML platform",
      "detail": "Amazon Machine Learning is a legacy service that no longer accepts new users and is no longer updated. AWS directs new machine-learning work to SageMaker AI; this is a successor choice, not an integration with the legacy service.",
      "url": "https://docs.aws.amazon.com/machine-learning/latest/dg/what-is-amazon-machine-learning.html"
    },
    {
      "source": "microservice-extractor",
      "target": "transform",
      "type": "alternative",
      "label": "Modernize .NET with AWS Transform",
      "detail": "AWS documentation says Microservice Extractor for .NET is no longer open to new customers and names AWS Transform as the alternative for .NET modernization.",
      "url": "https://docs.aws.amazon.com/portingassistant/latest/userguide/porting-assistant-port.html"
    },
    {
      "source": "portingassistant",
      "target": "transform",
      "type": "alternative",
      "label": "Modernize .NET with AWS Transform",
      "detail": "AWS documentation says Porting Assistant for .NET is no longer open to new customers and names AWS Transform as the alternative for .NET modernization.",
      "url": "https://docs.aws.amazon.com/portingassistant/latest/userguide/porting-assistant-port.html"
    },
    {
      "source": "rosa",
      "target": "ec2",
      "type": "foundation",
      "label": "Use EC2 for cluster compute",
      "detail": "ROSA uses Amazon EC2 for its control-plane, infrastructure, and worker-node compute. AWS documents EC2 as the underlying infrastructure; customers manage worker capacity through ROSA machine pools rather than manually operating the managed control-plane instances.",
      "url": "https://docs.aws.amazon.com/rosa/latest/userguide/rosa-responsibilities.html"
    },
    {
      "source": "rosa",
      "target": "eks",
      "type": "alternative",
      "label": "Compare managed Kubernetes choices",
      "detail": "AWS’s container decision guide lists ROSA and Amazon EKS as separate managed Kubernetes choices. Select between them based on OpenShift requirements, operating model, and service capabilities; this is a comparison, not an integration.",
      "url": "https://docs.aws.amazon.com/decision-guides/latest/decision-guides/choosing-aws-container-service.html"
    },
    {
      "source": "social-messaging",
      "target": "sns",
      "type": "integration",
      "label": "publish WhatsApp events",
      "detail": "AWS End User Messaging Social can publish message and inbound communication events to an Amazon SNS topic configured as the WABA event destination.",
      "url": "https://docs.aws.amazon.com/social-messaging/latest/userguide/managing-event-destinations.html"
    },
    {
      "source": "social-messaging",
      "target": "connect",
      "type": "integration",
      "label": "route WhatsApp events to Connect",
      "detail": "AWS End User Messaging Social supports an Amazon Connect Customer instance as a message and event destination for a WhatsApp Business Account.",
      "url": "https://docs.aws.amazon.com/social-messaging/latest/userguide/managing-event-destinations.html"
    },
    {
      "source": "signin",
      "target": "iam-identity-center",
      "type": "integration",
      "label": "sign in through the access portal",
      "detail": "IAM Identity Center users sign in through their organization's AWS access portal and can select the AWS accounts and applications assigned to them.",
      "url": "https://docs.aws.amazon.com/signin/latest/userguide/iam-id-center-sign-in-tutorial.html"
    },
    {
      "source": "iot-1-click",
      "target": "lambda",
      "type": "integration",
      "label": "historically invoke Lambda actions from buttons",
      "detail": "AWS IoT 1-Click buttons historically triggered configured actions such as Lambda functions. AWS IoT 1-Click is fully shut down; this edge describes the retired workflow, not a current integration.",
      "url": "https://docs.aws.amazon.com/iot-1-click/latest/developerguide/iot-1-click-dg.pdf"
    },
    {
      "source": "snowcone",
      "target": "datasync",
      "type": "alternative",
      "label": "move data over the network",
      "detail": "AWS recommends DataSync for most data migration workloads as an alternative to discontinued Snowcone devices.",
      "url": "https://aws.amazon.com/blogs/storage/aws-snow-device-updates/"
    },
    {
      "source": "snowcone",
      "target": "outposts",
      "type": "alternative",
      "label": "run edge workloads on AWS infrastructure",
      "detail": "AWS identifies Outposts as an alternative for edge computing workloads after discontinuing Snowcone.",
      "url": "https://aws.amazon.com/blogs/storage/aws-snow-device-updates/"
    },
    {
      "source": "medialive",
      "target": "mediapackage",
      "type": "integration",
      "label": "deliver live output for packaging",
      "detail": "A MediaLive channel can send live output to a MediaPackage v1 or v2 output group. The MediaPackage output group configures the destination and managed ingest connection.",
      "url": "https://docs.aws.amazon.com/medialive/latest/ug/delivering-to-mediapackage.html"
    },
    {
      "source": "medialive",
      "target": "mediaconnect",
      "type": "integration",
      "label": "ingest a MediaConnect flow",
      "detail": "MediaLive supports MediaConnect inputs that ingest transport streams from MediaConnect flows; standard channels can use two flows for separate pipelines.",
      "url": "https://docs.aws.amazon.com/medialive/latest/ug/setup-input-emx.html"
    },
    {
      "source": "medialive",
      "target": "cloudwatch",
      "type": "integration",
      "label": "monitor channel state and alerts",
      "detail": "MediaLive emits channel and multiplex state changes and alerts as CloudWatch events, which can be routed to supported targets.",
      "url": "https://docs.aws.amazon.com/medialive/latest/ug/monitoring-via-cloudwatch.html"
    },
    {
      "source": "medialive",
      "target": "s3",
      "type": "integration",
      "label": "use S3 media files as inputs",
      "detail": "MediaLive supports inputs that pull MP4 and transport-stream files from Amazon S3 buckets using a secure connection.",
      "url": "https://docs.aws.amazon.com/medialive/latest/ug/inputs-supported-formats.html"
    },
    {
      "source": "managed-blockchain-query",
      "target": "managed-blockchain",
      "type": "integration",
      "label": "query indexed blockchain data in the AMB family",
      "detail": "AWS describes AMB Query as part of Amazon Managed Blockchain: it exposes indexed, normalized blockchain data through APIs while AMB Access provides separate network-access features. Query does not require customers to operate AMB nodes.",
      "url": "https://docs.aws.amazon.com/managed-blockchain/latest/ambq-dg/what-is-service.html"
    },
    {
      "source": "iot-analytics",
      "target": "iot",
      "type": "integration",
      "label": "historically ingest IoT Core messages",
      "detail": "Historically, an AWS IoT Core rule could send MQTT message data to an AWS IoT Analytics channel. AWS IoT Analytics is retired; this edge describes the former integration, not a current workflow.",
      "url": "https://docs.aws.amazon.com/pdfs/iot/latest/developerguide/iot-dg.pdf"
    },
    {
      "source": "iot-analytics",
      "target": "s3",
      "type": "integration",
      "label": "historically deliver datasets to S3",
      "detail": "Historically, AWS IoT Analytics data stores used Amazon S3 storage, and dataset contents could be delivered to S3 buckets. AWS IoT Analytics is retired, so this is a historical relationship only.",
      "url": "https://docs.aws.amazon.com/iot-sitewise/latest/userguide/configure-storage.html"
    },
    {
      "source": "dynamodb",
      "target": "lambda",
      "type": "integration",
      "label": "Process table changes",
      "detail": "Enable DynamoDB Streams and configure a Lambda event source mapping to process item-change records. This is an optional trigger pipeline; applications should tolerate retries and duplicate processing.",
      "url": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/Streams.Lambda.html"
    },
    {
      "source": "dynamodb",
      "target": "s3",
      "type": "integration",
      "label": "Export table snapshots",
      "detail": "DynamoDB can export point-in-time table data to an S3 bucket for analytics and archival workflows. Export eligibility and the target bucket permissions must be configured.",
      "url": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/S3DataExport.HowItWorks.html"
    },
    {
      "source": "lambda",
      "target": "sqs",
      "type": "integration",
      "label": "Consume queued messages",
      "detail": "A Lambda event source mapping polls an SQS queue and invokes the function with batches. Visibility timeouts, batch failures, retries, and idempotent handlers affect processing reliability.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/with-sqs.html"
    },
    {
      "source": "lambda",
      "target": "efs",
      "type": "integration",
      "label": "Mount a shared file system",
      "detail": "Supported VPC-connected Lambda functions can mount an EFS file system through an access point. Network reachability, execution-role permissions, and POSIX permissions all apply.",
      "url": "https://docs.aws.amazon.com/lambda/latest/dg/configuration-filesystem.html"
    },
    {
      "source": "step-functions",
      "target": "lambda",
      "type": "integration",
      "label": "Run a function in a workflow",
      "detail": "The Lambda service integration invokes a function from a state-machine task. Choose synchronous or supported callback behavior deliberately and handle task errors and retries.",
      "url": "https://docs.aws.amazon.com/step-functions/latest/dg/connect-lambda.html"
    },
    {
      "source": "athena",
      "target": "glue",
      "type": "foundation",
      "label": "Resolve cataloged table metadata",
      "detail": "Athena can use the Glue Data Catalog to find databases, tables, partitions, and schema metadata for queries. The catalog describes data; it does not move S3 objects into a database.",
      "url": "https://docs.aws.amazon.com/athena/latest/ug/data-sources-glue.html"
    },
    {
      "source": "rds",
      "target": "secrets-manager",
      "type": "integration",
      "label": "Manage a master user secret",
      "detail": "For supported RDS configurations, RDS can manage the master user password in Secrets Manager. This is an optional integration with secret lifecycle and rotation behavior, rather than a requirement for every database.",
      "url": "https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/rds-secrets-manager.html"
    },
    {
      "source": "rds",
      "target": "s3",
      "type": "integration",
      "label": "Export snapshot data",
      "detail": "Supported database snapshots can export data into S3 for analysis. An export task uses an IAM role and encryption configuration, and exported data is not an RDS restore image.",
      "url": "https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_ExportSnapshot.html"
    },
    {
      "source": "redshift",
      "target": "s3",
      "type": "integration",
      "label": "Load objects with COPY",
      "detail": "Redshift COPY can load data from S3 into warehouse tables. The role, data format, and load parameters must match the source; this is a configured loading operation.",
      "url": "https://docs.aws.amazon.com/redshift/latest/dg/t_loading-tables-from-s3.html"
    },
    {
      "source": "emr",
      "target": "s3",
      "type": "integration",
      "label": "Read and write a durable data lake",
      "detail": "EMR workloads can use S3 for data and outputs. EMRFS is the EMR-specific S3 file-system connector for applicable releases; connector defaults and feature support depend on the release.",
      "url": "https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-fs.html"
    },
    {
      "source": "bedrock",
      "target": "s3",
      "type": "integration",
      "label": "Ingest a knowledge-base data source",
      "detail": "Bedrock Knowledge Bases can ingest documents from a configured S3 data source for retrieval-augmented generation. This requires a knowledge-base setup and data synchronization; ordinary model inference does not need an S3 bucket.",
      "url": "https://docs.aws.amazon.com/bedrock/latest/userguide/data-source-connectors.html"
    },
    {
      "source": "bedrock",
      "target": "opensearch",
      "type": "integration",
      "label": "Store knowledge-base embeddings",
      "detail": "Supported Bedrock Knowledge Bases can use OpenSearch Serverless or supported OpenSearch managed clusters as a vector store. The selected store, embedding model, and access configuration must satisfy the knowledge-base requirements.",
      "url": "https://docs.aws.amazon.com/bedrock/latest/userguide/kb-how-data.html"
    },
    {
      "source": "bedrock",
      "target": "aurora",
      "type": "integration",
      "label": "Use an Aurora vector store",
      "detail": "Supported Aurora configurations can serve as a Bedrock Knowledge Bases vector store. This is an optional retrieval architecture with database and access prerequisites, independent from direct foundation-model invocation.",
      "url": "https://docs.aws.amazon.com/bedrock/latest/userguide/kb-how-data.html"
    },
    {
      "source": "eks",
      "target": "sts",
      "type": "foundation",
      "label": "Exchange an OIDC token for role credentials",
      "detail": "IAM roles for service accounts use an EKS OIDC identity provider and STS AssumeRoleWithWebIdentity to grant temporary permissions to configured Pods. EKS Pod Identity is a separate supported credential mechanism.",
      "url": "https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts.html"
    },
    {
      "source": "iam",
      "target": "sts",
      "type": "foundation",
      "label": "Issue temporary role credentials",
      "detail": "IAM defines the role trust and permission policies; AWS STS issues temporary credentials for supported role and federation operations. Session policies can further restrict the role permissions.",
      "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html"
    }
  ]
}
