Skip to content

SYSTEM Cited by 1 source

Capability Insights for AWS

Capability Insights for AWS is an AWS open-source solution (github.com/aws/capability-insights-for-aws) that deploys a searchable AWS Regional-availability dashboard into the customer's own AWS account and VPC, auto-refreshing every 24 hours. Its purpose is to let teams own the Regional availability dataset as infrastructure under their own governance — their account, their network, their refresh cadence — rather than consuming it only via the public explorer, S3 access point, or MCP server. (Source: sources/2026-10-02-aws-deploy-open-source-regional-availability-tools-in-your-vpc)

What it covers

  • Services and features — availability status, expected launch dates, expansion plans per Region.
  • API operations — individual API-action availability per Region per service.
  • CloudFormation resource types — which resource types each Region supports.

Summary counts span services/features, API operations, CloudFormation resources, and Regions. Dashboard controls: search/filter by name across Regions, expandable per-service feature detail, status indicators (Available / Planning / Not Expanding / projected date e.g. "2026 Q3"), JSON/CSV export, and a Settings page showing last sync time + manual refresh trigger.

Architecture

Served as an S3-hosted static website backed by Amazon API Gateway, Lambda, and EventBridge, all inside the customer account:

  • An EventBridge schedule invokes a data-fetch Lambda every 24h. That Lambda runs outside the VPC so it can read the AWS-published Capabilities by Region S3 access point over the AWS network, then writes the dataset to the in-account website bucket. This is the only call that leaves the account during normal operation — a deliberate egress-minimizing placement.
  • A client in a public subnet reaches the dashboard through an S3 gateway endpoint and the private API through an API Gateway VPC endpoint. The API Lambda can invoke data-fetch on demand via a Lambda VPC endpoint.
  • A deployment-assets bucket supplies the Lambda code during deployment only.
  • The dashboard is reachable only from within the VPC (http://capability-insights-website-<ACCOUNT_ID>-<REGION>.s3-website-<REGION>.amazonaws.com); viewers connect via existing VPN/Direct Connect, AWS Client VPN, or an EC2 SOCKS proxy.

You supply your own VPC, subnets (one public routed to an IGW, one private with no internet route, both with an S3 gateway VPC endpoint), and an S3 deployment-assets bucket, so it integrates with existing infrastructure and security controls. Runtime IAM roles created by the CloudFormation stack use scoped permissions (S3 object r/w, CloudFormation read, Athena, Glue + Lake Formation catalog, Lambda invoke, Step Functions execute).

Deployment

  • Automated: npm run deploy (prompts for VPC/subnet/bucket/source-access-point/source-folders; builds assets, deploys the stack, uploads the website, triggers an initial data sync). SourceFolders defaults to public.
  • Manual: download build-assets.zip from the latest release, aws cloudformation deploy the capability-insights.template.json, aws s3 sync website/, and aws lambda invoke the data-fetch function for the initial sync.
  • Pairs with Workload Analysis (Part 2) via --enable-usage-analysis, deployed as an additive stack.

Seen in

Last updated · 771 distilled / 2,233 read