# MWAA ワークフロー アーティファクト作成・デプロイ Amazon Managed Workflows for Apache Airflow(MWAA)のワークフロー成果物を作成・デプロイします。プロビジョニング環境向けの Python Airflow DAG(有向非環状グラフ)またはサーバーレス環境向けの YAML ワークフローファイルに対応しています。 ## 対応範囲 オペレーター(処理実行モジュール)の選択、タイムアウト設計、リトライ戦略、スケジューリング設定、失敗通知、べき等性(同じ操作を何度実行しても結果が変わらない性質)、MWAA サーバーレス スキーマへの適合性をカバーします。 アーティファクトのデプロイ(S3 への DAG アップロードまたはサーバーレスの CreateWorkflow/UpdateWorkflow API)、承認後のインライン環境作成、修正の再デプロイに対応し、オプションでテスト用プラグイン(testing-mwaa-workflow)へ引き継ぎます。 ## 次のような場合に使用 DAG を作成する、パイプラインを書く、ワークフローを構築する、タスクをオーケストレーション(統合管理)する、Airflow DAG を使う、データパイプラインを構築する、ジョブをスケジュール設定する、DAG をデプロイする、ワークフローをデプロイする、YAML ワークフローを使う ## 非対応 既存 DAG のプロビジョニング環境とサーバーレス環境間の変換・移行、デプロイ済みワークフローの実行・動作確認テスト(testing-mwaa-workflow で対応)、失敗実行の診断(debugging-mwaa-workflow で対応)
Authors and deploys MWAA workflow artifacts: Python Airflow DAGs for provisioned environments or YAML workflow files for Serverless. Covers operator selection, timeout design, retry strategy, scheduling, failure notifications, idempotency, and MWAA Serverless schema compliance. Deploys the artifact (S3 DAG upload or Serverless CreateWorkflow/UpdateWorkflow), creates an environment inline when approved, and redeploys fixes, then optionally hands off to testing-mwaa-workflow. Triggers on: create a DAG, write a pipeline, build a workflow, orchestrate tasks, Airflow DAG, data pipeline, schedule a job, deploy a DAG, deploy a workflow, YAML workflow. Not applicable to converting or migrating existing DAGs between provisioned and serverless (conversion is out of scope), running or smoke-testing a deployed workflow (handled by testing-mwaa-workflow) or diagnosing a failed run (handled by debugging-mwaa-workflow).
AWS MCP サーバー(オプション、ただし推奨): このスキルのAWS CLIコマンドをAWS MCPサーバーで実行すると、隔離された実行環境と監査ログが得られます。ここに記載されたすべてのコマンドは、通常のAWS CLIでも動作するため、このスキルはMCPサーバーやMCP専用ツールを必須とはしていません。
Amazon MWAAの本番環境対応ワークフロー成果物を作成します。2つのいずれかのパスへ振り分けます:Python DAG(専有環境版)またはYAMLワークフロー(サーバーレス版)。
実行上の注意 — 段階的に状態確認: AWSの操作が終了状態や準備完了状態に到達するのを待つときは、呼び出しごとに1回だけ状態確認を行い、独自のループで再確認するかどうかを決定してください。操作時間がどれだけかかっても、単一のコマンドやスクリプトを待機状態でブロックしないでください(
while+sleepのように完了まで待たない)。
このスキルは2つの方法で読み込むことができ、スキル内蔵ファイルの参照元が異なります。参照を読む前にスキルの読み込み方法を確認してください:
retrieve_skillツールで読み込まれた場合: スキルはローカルファイルシステムにインストールされていません。retrieve_skillをfileパラメータで呼び出し(例:file="references/authoring-provisioned-dag.md")、返されたコンテンツを読む必要があります。これらのパスをfile_readでローカル読みしないでください — ディスク上に存在しません。.kiro/skills/authoring-mwaa-workflow/または~/.claude/skills/authoring-mwaa-workflow/):相対パスを使ってローカルスキルディレクトリからファイルを読んでください。この区別はスキル内蔵ファイルにのみ適用されます。ユーザーデータとセッション成果物は常にユーザーの作業ディレクトリとの間で読み書きされます。retrieve_skillを使ってカスタマーデータを取得・書き込みしないでください。
この順序で評価してください:
解決可能な対象が指定されている? 対象参照は、他のキーワードに関わらず確定的な振り分け信号です:
arn:aws:airflow:<region>:<account>:environment/<name>のようなARN、またはaws mwaa get-environmentで解決可能な名前)→ パスAへ。arn:aws:airflow-serverless:<region>:<account>:workflow/<name>)→ パスBへ。両方のパスのキーワードが含まれている? リクエストに両方のパスのキーワードが含まれており、解決可能な対象がない場合は、意図で曖昧性を解消してください:
PythonOperatorはサーバーレスでもサポートされているため、演算子レベルのpythonヒント(PythonOperator、python_callable、「Python関数/タスク」)がパスB信号(yaml、serverless、ワークフローARN)と並行してある場合、曖昧ではありません → パスBへ。Python DAG、provisioned)とサーバーレスヒントが対象なしで並行している → 確認質問をしてください。ちょうど1つのパスキーワード? デプロイ対象項のみをパスA信号と見なしてください:provisioned、Python DAG、または「環境向けの.py」→ パスAへ。yamlまたはserverless→ パスBへ。演算子レベルのPythonについては、パスA信号ではありません。
振り分け信号がない? 「DAG」または「Workflow」のみでは曖昧です — パスを示しません。確認してください:対象は MWAA専有環境(Python DAG) ですか、それとも MWAAサーバーレス(YAML) ですか?
振り分けたパスの参照に従ってください(他方のパスの参照は不要です):
振り分けたパスの作成ステップの後、下記のデプロイとテストに進んでください。
作成スキルはすべてのデプロイと再デプロイを担当します。詳細はreferences/deploying-mwaa.mdを参照してください。
提示 — 成果物がスケジュールを持つかどうかに基づいてオプションを提示します。パスに適した表現で質問を組み立ててください:
DAG/ワークフローがスケジュールを持つ場合:
DAG/ワークフローがスケジュールを持たない場合(手動トリガーのみ):
ユーザーはすべてのオプションを辞退することもできます。
デプロイ:
SourceBucketArn/DagS3Pathにアップロードします。デプロイ後の確認を実行(deploying-mwaa.mdを参照)して、スケジューラーが新しいファイルをインポートエラーやdag_id競合なく解析したことを確認します。環境が存在せずユーザーが承認した場合、インラインで環境を作成(計画-検証-実行 + 明示的確認)し、CREATING → AVAILABLEをポーリングします(約20~40分)。ユーザーは既存環境を提供することもできます。CreateWorkflow(新規)またはUpdateWorkflow(再デプロイ)。YAMLはここで同期的に検証されます。ワークフローがPythonOperator/BashOperatorを使う場合は、最初にコードパッケージをS3にビルド・アップロードし、--code経由で渡してください(references/serverless-code-packaging.mdとreferences/deploying-mwaa.mdを参照)。ユーザーは既存ARNを提供することもできます。UpdateWorkflowパスを、testing-mwaa-workflowが成果物または環境の修正を委譲するときに再利用します。「デプロイして一時停止を解除」が選択された場合 — ステップ2に従ってデプロイし、一時停止を解除します。実行トリガーやtesting-mwaa-workflowの呼び出しはしないでください。
「デプロイしてテストする」が選択された場合 — ステップ2に従ってデプロイ、必要に応じて一時停止を解除し、解決された対象(環境名 + dag_id、またはワークフローARN)を使ってtesting-mwaa-workflowを呼び出します。その委譲はtestingの委譲呼び出しモードです。
ハード制限: テストが要求された場合 — 最初から(「デプロイしてテスト」)か会話の後で(「テストして」「実行して」「試して」)かに関わらず、testing-mwaa-workflowを必ず呼び出す必要があります。DAG実行を手動でトリガー、監視、確認しないでください。「デプロイして一時停止を解除」はテスト要求ではなく、デプロイのみのアクションです。
create-environment、update-environment、create-workflow、update-workflowは状態を変更するため、各々の影響を明示して確認してください。本番名の対象について警告してください。| エラー | 原因 | 修正 |
|---|---|---|
| dagrun_timeout が DAG を早期に終了 | 呼び出されたサービス内のタイムアウト設定が短すぎる | dagrun_timeout を上げるか、サービスタイムアウトを下げる |
| YAML検証がワークフローを拒否 | 型またはパラメータが誤り | timedelta形式を使用、許可リストを確認 |
| サーバーレスでオペレータが見つからない | 許可リストに登録されていない | サポートされたオペレータ、PythonOperator/BashOperator、またはLambdaを使用 |
| サーバーレス実行:コード抽出不可 / 環境破損 | 不正なコードパッケージ | zipルートにファイル、__pycache__なし、≤250 MB、再パッケージ化 |
| サーバーレス Python タスク ImportError | 依存関係なし、またはプラットフォームが合わないwhl | manylinux2014_x86_64 / Py3.12 whlとしてバンドル、事前インストール済みパッケージをバンドルしない |
| テンプレート変数未定義 | バージョン不一致 | 変数がAirflowバージョンと一致するか確認 |
create/update-environment、create/update-workflow、S3 DAGアップロード)は、影響を明示した明示的確認が必要です。本番名の対象について警告してください(デプロイのハード制限を参照)。Action/Resourceペアのみを追加します — *FullAccessやservice:*は使用しません。AWS MCP server (optional but recommended): running the AWS CLI commands in this skill through the AWS MCP server gives sandboxed execution and audit logging. Every command here also works with the plain AWS CLI, so the skill does not require the MCP server or any MCP-only tools.
Author production-grade workflow artifacts for Amazon MWAA. Routes to one of two paths: Python DAG (provisioned) or YAML workflow (Serverless).
Execution note — poll in discrete steps: whenever you wait for an AWS operation to reach a terminal or ready state, issue one status check per call and decide in your own loop whether to check again. Never block a single command or script on the wait (no
while+sleepuntil done), regardless of the operation or how long it takes.
This skill can be loaded two ways, and they resolve the skill's own bundled files from different places. Determine how the skill was loaded before reading a reference:
retrieve_skill tool: The skill is not
installed on the local filesystem. You MUST fetch each reference via
retrieve_skill with the file parameter (e.g.
file="references/authoring-provisioned-dag.md") and read the returned
content. Do NOT file_read these paths locally — they do not exist on disk..kiro/skills/authoring-mwaa-workflow/ or
~/.claude/skills/authoring-mwaa-workflow/): Read the files from the local
skill directory using relative paths.This distinction applies only to the skill's own packaged files. User data and
session artifacts are always read from and written to the user's working
directory. Never fetch or write customer data through retrieve_skill.
Evaluate in this order:
arn:aws:airflow:<region>:<account>:environment/<name>, or a name
resolvable via aws mwaa get-environment) → go to Path A.arn:aws:airflow-serverless:<region>:<account>:workflow/<name>) → go to
Path B.PythonOperator is supported on Serverless, so an operator-level
python cue (PythonOperator, python_callable, "Python function/task")
alongside a Path B signal (yaml, serverless, workflow ARN) is NOT
ambiguous → go to Path B.Python DAG, provisioned) alongside a
Serverless cue with no target → ask the clarifying question.provisioned, Python DAG, or "a .py for my environment" → go
to Path A. yaml or serverless → go to Path B. Operator-level
Python mentions are not Path A signals.Follow the reference for the path you routed to (you do not need the other path's reference):
After the routed path's Write step, continue with Deploy & Test below.
Authoring owns all deployment and redeployment. Detail in references/deploying-mwaa.md.
Ask — present options based on whether the artifact has a schedule. Frame the question using path-appropriate language:
If the DAG/workflow has a schedule:
If the DAG/workflow has no schedule (manual-trigger only):
The user may also decline all options.
Deploy:
SourceBucketArn/
DagS3Path. Run post-deploy verification (see deploying-mwaa.md) to
confirm the scheduler parsed the new file without import errors or
dag_id conflicts. If no environment exists and the user approves,
create one inline (plan-validate-execute + explicit confirmation),
then poll CREATING -> AVAILABLE (~20-40 min). The user may instead
supply an existing environment.CreateWorkflow (new) or UpdateWorkflow (redeploy);
the YAML is validated synchronously here. If the workflow uses
PythonOperator/BashOperator, first build and upload the code package
to S3 and pass it via --code (see
references/serverless-code-packaging.md
and references/deploying-mwaa.md). The user
may instead supply an existing ARN.UpdateWorkflow path,
reused when testing-mwaa-workflow delegates an ARTIFACT or ENVIRONMENT
fix.If "Deploy and unpause" selected — deploy per step 2, then unpause. Do not trigger a run or invoke testing-mwaa-workflow.
If "Deploy and test" selected — deploy per step 2, unpause if
applicable, then invoke testing-mwaa-workflow with the resolved target
(env name + dag_id, or workflow ARN). That hand-off is testing's
delegated invocation mode.
HARD GATE: If testing is requested — whether upfront ("deploy and test") or later in the conversation ("test it", "run it", "try it") — you MUST invoke testing-mwaa-workflow. Do NOT trigger, monitor, or verify DAG runs manually. "Deploy and unpause" is NOT a test request — it is a deploy-only action.
create-environment, update-environment,
create-workflow, and update-workflow mutate state — confirm each with
its impact stated. Warn on prod-named targets.| Error | Cause | Fix |
|---|---|---|
| dagrun_timeout kills DAG early | < timeout set in service called | Raise dagrun_timeout or lower service timeout |
| YAML validation rejects workflow | Wrong type or param | Use timedelta format; check allowlist |
| Operator not found in Serverless | Not allowlisted | Use a supported operator, PythonOperator/BashOperator, or Lambda |
| Serverless run: cannot extract code / corrupt env | Bad code package | Files at zip root, no __pycache__, ≤250 MB; repackage |
| Serverless Python task ImportError | Missing dep or wrong-platform wheel | Bundle as manylinux2014_x86_64 / Py3.12 wheel; don't bundle pre-installed packages |
| Template variable undefined | Version mismatch | Check vars for exact Airflow version |
create/update-environment,
create/update-workflow, S3 DAG upload) require explicit confirmation with
impact stated; warn on prod-named targets (see the Deploy HARD-GATE).Action/Resource
pairs the artifact needs — never *FullAccess or service:*.原文・著作権は Anthropic および各プラグイン作者に帰属します。日本語訳は Claude API による自動翻訳です。