SYSTEM Cited by 1 source
Capability Insights for AWS¶
Capability Insights for AWS is an AWS open-source solution (github.com/aws/capability-insights-for-aws) that deploys a searchable AWS Regional-availability dashboard into the customer's own AWS account and VPC, auto-refreshing every 24 hours. Its purpose is to let teams own the Regional availability dataset as infrastructure under their own governance — their account, their network, their refresh cadence — rather than consuming it only via the public explorer, S3 access point, or MCP server. (Source: sources/2026-10-02-aws-deploy-open-source-regional-availability-tools-in-your-vpc)
What it covers¶
- Services and features — availability status, expected launch dates, expansion plans per Region.
- API operations — individual API-action availability per Region per service.
- CloudFormation resource types — which resource types each Region supports.
Summary counts span services/features, API operations, CloudFormation resources, and Regions. Dashboard controls: search/filter by name across Regions, expandable per-service feature detail, status indicators (Available / Planning / Not Expanding / projected date e.g. "2026 Q3"), JSON/CSV export, and a Settings page showing last sync time + manual refresh trigger.
Architecture¶
Served as an S3-hosted static website backed by Amazon API Gateway, Lambda, and EventBridge, all inside the customer account:
- An EventBridge schedule invokes a data-fetch Lambda every 24h. That Lambda runs outside the VPC so it can read the AWS-published Capabilities by Region S3 access point over the AWS network, then writes the dataset to the in-account website bucket. This is the only call that leaves the account during normal operation — a deliberate egress-minimizing placement.
- A client in a public subnet reaches the dashboard through an S3 gateway endpoint and the private API through an API Gateway VPC endpoint. The API Lambda can invoke data-fetch on demand via a Lambda VPC endpoint.
- A deployment-assets bucket supplies the Lambda code during deployment only.
- The dashboard is reachable only from within the VPC (
http://capability-insights-website-<ACCOUNT_ID>-<REGION>.s3-website-<REGION>.amazonaws.com); viewers connect via existing VPN/Direct Connect, AWS Client VPN, or an EC2 SOCKS proxy.
You supply your own VPC, subnets (one public routed to an IGW, one private with no internet route, both with an S3 gateway VPC endpoint), and an S3 deployment-assets bucket, so it integrates with existing infrastructure and security controls. Runtime IAM roles created by the CloudFormation stack use scoped permissions (S3 object r/w, CloudFormation read, Athena, Glue + Lake Formation catalog, Lambda invoke, Step Functions execute).
Deployment¶
- Automated:
npm run deploy(prompts for VPC/subnet/bucket/source-access-point/source-folders; builds assets, deploys the stack, uploads the website, triggers an initial data sync).SourceFoldersdefaults topublic. - Manual: download
build-assets.zipfrom the latest release,aws cloudformation deploythecapability-insights.template.json,aws s3 sync website/, andaws lambda invokethe data-fetch function for the initial sync. - Pairs with Workload Analysis (Part 2) via
--enable-usage-analysis, deployed as an additive stack.
Seen in¶
- sources/2026-10-02-aws-deploy-open-source-regional-availability-tools-in-your-vpc — introduces the solution: VPC-local Regional-availability dashboard with 24h EventBridge-driven refresh, S3 static site + private API Gateway, and the out-of-VPC data-fetch Lambda as the single egress point.
Related¶
- systems/aws-capabilities-by-region — the AWS-published dataset it pulls from
- systems/aws-workload-analysis — the additive personalization stack
- concepts/data-residency — the governance motivation
- concepts/control-plane-data-plane-separation — the fetch-outside-VPC egress design