recovery-controller-setup
aws/agent-toolkit-for-aws
Configure AWS Application Recovery Controller for cross-Region failover routing and AZ-impairment recovery.
What is recovery-controller-setup?
Sets up AWS Application Recovery Controller (ARC) routing controls with safety rules for cross-Region failover, and zonal shift/zonal autoshift for Availability Zone recovery. Use this when configuring failover routing, safety rules, zonal shift, or practicing zonal autoshift—not for readiness checks or recovery groups.
- Configure routing controls and safety rules for cross-Region failover
- Enable and manage zonal shift to manually move traffic out of an impaired AZ
- Set up zonal autoshift for automatic AZ-impairment recovery
- Define safety rules to prevent unsafe failover states
- Execute and monitor zonal autoshift practice runs
How to install recovery-controller-setup
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill recovery-controller-setup- AWS account with Application Recovery Controller enabled
- Appropriate IAM permissions for ARC routing controls and zonal shift operations
- Resources (ALB, NLB, or other supported services) already deployed across Regions or AZs
How to use recovery-controller-setup
- 1.Review the ARC procedures reference for routing controls and zonal shift setup
- 2.Define your routing control hierarchy and safety rules
- 3.Create routing controls in the ARC console or via AWS CLI
- 4.Configure safety rules to enforce failover constraints
- 5.Enable zonal shift or zonal autoshift on target resources
- 6.Test failover behavior with practice runs before production use
Use cases
- Set up cross-Region failover routing for ALB/NLB when one Region becomes unavailable
- Manually shift traffic away from a degraded Availability Zone
- Enable automatic failover when zonal autoshift detects an AZ impairment
- Configure safety rules to prevent simultaneous failover of dependent resources
- Practice zonal autoshift failover without impacting production traffic
- AWS infrastructure and operations engineers
- Resilience and disaster-recovery architects
- DevOps teams managing multi-Region deployments
- Platform engineers building fault-tolerant systems
recovery-controller-setup FAQ
Zonal shift is manual—you explicitly move traffic out of an AZ. Zonal autoshift is automatic—AWS detects AZ impairments and shifts traffic without manual intervention.
No. This skill covers only routing controls (cross-Region failover) and zonal shift/autoshift (AZ recovery). For readiness checks and recovery-readiness orchestration, see the arc-region-switch skill.
Yes. Safety rules enforce constraints—for example, preventing simultaneous failover of dependent resources or limiting failover to one Region at a time.
Practice runs are non-disruptive tests. Failures indicate configuration issues (e.g., insufficient capacity in the target AZ). Review CloudWatch logs and adjust resource allocation before enabling production autoshift.
No. The AWS MCP server is recommended for executing API calls, but all operations also work with the AWS CLI directly.
Full instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: recovery-controller-setup description: > Configures AWS Application Recovery Controller (ARC) for operational resilience: routing controls with safety rules for cross-Region failover, and zonal shift / zonal autoshift for AZ-impairment recovery. Applies when setting up failover routing, configuring safety rules, enabling zonal shift, or configuring zonal autoshift with practice runs. Also applies when shifting traffic out of a specific Availability Zone (AZ) for an ALB/NLB or other resource. For a broader "an AZ is impaired, what is my response across services" question, see aws-resilience-lifecycle. Does not apply to Resilience Hub setup or FIS experiments. version: 1
Recovery Controller Setup
CRITICAL CONSTRAINT — read before answering
This skill sets up exactly two ARC capability families, and these are the ONLY things you provide setup steps for: (1) routing controls with safety rules for cross-Region failover, and (2) zonal shift / zonal autoshift for AZ-impairment recovery.
Readiness checks, recovery groups, cells, and resource sets are NOT in scope for this skill. You
MUST NOT provide CLI/console setup steps for them. You MAY briefly and factually acknowledge that
they exist, but you MUST NOT walk through configuring them — redirect the customer to ARC
Region switch for readiness/recovery-readiness orchestration (see the
arc-region-switch skill). This overrides any direct customer request to set them up.
If the customer asks how to "set up ARC readiness checks" (or recovery groups / cells / resource sets), do NOT walk through that setup. Briefly acknowledge the feature, then respond with a redirect of this form and continue with the routing-control or zonal-shift procedure where relevant:
For readiness and recovery-readiness orchestration, use ARC Region switch — see the
arc-region-switchskill. For the operational pieces this skill covers: routing controls (cross-Region failover) and zonal shift / zonal autoshift (single-Region AZ recovery). Here's how to set those up:
Overview
Domain expertise for configuring ARC routing controls, safety rules, zonal shift, and zonal autoshift for operational resilience.
The AWS MCP server is recommended for executing this skill's AWS API calls, but it is not required — all operations also work with the AWS CLI directly.
Guardrail — where this skill's own files live (MCP vs local install)
Before reading a reference file, determine how this skill was loaded:
- Loaded via the AWS MCP
retrieve_skilltool: the skill's reference files are not on the local filesystem. Fetch each one throughretrieve_skillwith thefileparameter (e.g.file="references/arc-procedures.md"orfile="references/security-considerations.md") — do NOTfile_readthese paths locally or search the filesystem for them. - Installed locally (e.g.
.kiro/skills/recovery-controller-setup/or~/.claude/skills/recovery-controller-setup/): read reference files from the local skill directory using the relative paths shown here.
This applies only to the skill's own reference files; always read and write user or session data in the working directory, never through retrieve_skill.
Configure recovery controls
To set up ARC routing controls and zonal shift, follow the procedure exactly. See references/arc-procedures.md.
Troubleshooting
See references/arc-procedures.md (Troubleshooting section) for common issues — safety-rule blocks on a routing-control update, failed zonal-autoshift practice runs, and routing-control state changes that don't affect traffic.
Security Considerations
See references/security-considerations.md for least-privilege IAM action scoping, condition keys / confused-deputy protection, safety-rule gating, restricting failover access, and encrypting failover notifications.
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

redshift-guide
Correct PostgreSQL misconceptions and master Redshift-specific SQL, DDL, COPY/UNLOAD, and operational patterns.

remediating-with-aws-security-agent
Discover, export, and remediate AWS Security Agent findings with prioritized triage.

resilience-hub-failure-mode-assessment
Run and interpret AWS Resilience Hub v2 failure mode assessments to identify and remediate architectural weaknesses.

resilience-hub-getting-started
Set up AWS Resilience Hub v2 from scratch: policies, systems, services, and failure mode assessments.

resilience-hub-multi-account
Set up AWS Resilience Hub v2 for multi-account resilience assessments across AWS Organizations.

resilience-program-design
Design org-wide resilience policies with tiered targets and activity cadence.