← Files SugerARCHIVED FILE

SKILL.md

7.88 KB · Oct 2, 2026 · 00:17 UTC

↓ Download file

---
name: aws-integration-verify
description: "Verify AWS Marketplace integration end to end by reading expected values from the Suger Console UI and then checking the corresponding AWS Console pages with browser tools."
---

# Verify AWS Marketplace Integration

Use browser frontend tools only. Read the expected values from the Suger Console UI first, then compare those values against AWS Console pages in one continuous flow.

During this verification flow, read-only browser actions are pre-approved. You should directly navigate, switch tabs, open details, and inspect pages without stopping for confirmation. Only pause if you are about to change a configuration value or perform a clearly state-changing action in AWS or Suger.

Do not stop when one step fails. Keep going and finish the full verification so you can give the user a complete diagnosis.

## Core Rules

- Start each major step with `get_ui_context` or `list_tabs` so you know which page and tab you are operating on.
- Use `extract_page` before direct page actions such as `click`, `fill`, or `select`.
- After each important transition, call `extract_page` again:
  - page navigation
  - opening `Details`
  - opening a drawer or modal
  - switching AWS sections
  - landing on a role, bucket, SNS, KMS, or EventBridge page
- Use `navigate` only for trusted destinations such as Suger Console, AWS Console, or approved custom domains.
- Use the Suger integration card's `Console` button to enter AWS when possible instead of inventing the initial AWS Marketplace URL.
- For the AWS Marketplace entry flow, keep the AWS Marketplace console region at `us-west-2` unless an ARN or other expected integration value explicitly points to a different AWS region. If an ARN includes a specific region, treat that ARN region as the source of truth for the related AWS resource page.

## Step 0: Read Expected Values From Suger Console

Always start from Suger Console and treat the Suger UI as the source of truth for the expected integration values. Do not rely on backend database tools for this skill.

1. Use `get_ui_context` to confirm the current organization and page.
2. If you are not already on the AWS Marketplace integrations page for the current organization, use `navigate_to_page`, `navigate_to_entity`, visible UI navigation, or `navigate` to reach it.
3. Call `extract_page` to read the integrations list.
4. Identify the AWS Marketplace integration row that should be verified.
5. If the row is collapsed, use `click` on the row's `Details` button.
6. Call `extract_page` again after the details view opens.
7. Read and carry forward these expected values from the Suger UI:
   - `partnerID`
   - `iamRoleArn`
   - `mcasS3Bucket`
   - `mcasSnsTopic`
   - `mcasIamRoleArn`
   - `mdfsS3BucketArn`
   - `mdfsKmsKeyArn`
   - `eventBridgeRuleName`
   - `mcasFullSyncDone`
   - `mdfsFullSyncDone`
   - `revenueRecordFullSyncDone`
   - `mdfsEnrollmentPassed`
   - `agreementEventBridgeEnrolled`
8. Keep these values in working memory and use them as the expected values for the AWS checks below.

## Step 1: Confirm Suger Status And Open AWS Console

1. Call `extract_page` again if needed so you are working from the latest Suger details view.
2. Verify that the AWS Marketplace integration appears connected, verified, or otherwise healthy in Suger Console.
3. If the Suger details already show a mismatch or an incomplete value, record it, but do not stop.
4. Use `click` on the same AWS Marketplace card's `Console` button to enter AWS Marketplace.
5. After the AWS page loads, use `get_ui_context` and `extract_page`.
6. Confirm that the initial AWS Marketplace console flow is in region `us-west-2`.

## Step 2: Verify The Main IAM Role And Required Policies

The main marketplace role should match `iamRoleArn`.

1. Parse `iamRoleArn`. It should follow this shape:
   - `arn:aws:iam::<partnerID>:role/<role-name>`
2. Derive the expected IAM role details URL in `us-west-2`:
   - `<aws-console>/iam/home?region=us-west-2#/roles/details/<role-name>`
3. Use `navigate` to open that IAM role details page directly when needed.
4. Call `extract_page`.
5. If the page does not exist, the role is missing, or the page clearly indicates the role cannot be found:
   - report that `iamRoleArn` is incorrect or the role does not exist
   - mark this check as failed
   - continue to the next steps
6. If the role page exists, verify that the role matches the expected `iamRoleArn`.
7. Verify that the role includes these attached policies:
   - `AWSMarketplaceFullAccess`
   - `AWSMarketplaceSellerFullAccess`
   - `SugerAccessMarketplacePolicy`
8. Report issues with clear operational meaning:
   - if `AWSMarketplaceFullAccess` is missing, explain that Suger cannot properly access AWS Marketplace and related services
   - if `AWSMarketplaceSellerFullAccess` is missing, explain that Suger cannot access seller-related workflows such as products, plans, and offers
   - if `SugerAccessMarketplacePolicy` is missing, explain that Suger cannot complete required data extraction, analysis, or notifications
9. Continue even if any IAM policy check fails.

## Step 3: Verify MCAS

Use the values from Suger Console and confirm that the MCAS-related configuration is internally consistent.

1. Check that `mcasS3Bucket` follows this expected pattern:
   - `suger-mcas-s3-bucket-{partnerID}`
2. Check that `mcasSnsTopic` follows this expected pattern:
   - `arn:aws:sns:<region>:<partnerID>:suger-mcas-sns-topic`
3. Parse `mcasIamRoleArn`. It should follow this shape:
   - `arn:aws:iam::<partnerID>:role/<role-name>`
4. Derive the IAM role details URL:
   - `<aws-console>/iam/home?region=us-west-2#/roles/details/<role-name>`
5. Use `navigate` to open the `mcasIamRoleArn` role page.
6. Call `extract_page`.
7. Confirm that the MCAS IAM role exists.
8. Verify the status flag from the Suger details:
   - `mcasFullSyncDone` should be `true`
9. If any MCAS issue exists, report it and continue. Examples:
   - bucket name does not match expected pattern
   - SNS topic format is wrong
   - MCAS IAM role does not exist
   - `mcasFullSyncDone` is not `true`

## Step 4: Verify MDFS

Use the values from Suger Console and validate that the MDFS-related configuration looks correct.

1. Check that `mdfsS3BucketArn` follows this expected pattern:
   - `arn:aws:s3:::suger-mdfs-s3-bucket-{partnerID}`
2. Parse `mdfsKmsKeyArn`. It should follow this shape:
   - `arn:aws:kms:<region>:<partnerID>:key/<key-id>`
3. Derive the KMS key details URL:
   - `<aws-console>/kms/home?region=<region>#/kms/keys/<key-id>`
4. Use `navigate` to open that KMS key details page.
5. Call `extract_page`.
6. Confirm that the KMS key exists and is enabled.
7. Verify the status flags from the Suger details:
   - `mdfsFullSyncDone` should be `true`
   - `mdfsEnrollmentPassed` should be `true`
   - `agreementEventBridgeEnrolled` should be `true`
8. Verify that `eventBridgeRuleName` is not empty.
9. If any MDFS issue exists, report it and continue. Examples:
   - MDFS bucket ARN format is wrong
   - KMS key is missing
   - KMS key is disabled
   - any of the Suger status flags is not `true`
   - `eventBridgeRuleName` is empty

## Reporting Format

After the full flow ends, provide a compact verification summary.

- List each check with `pass`, `fail`, or `skipped`.
- For each failure, include:
  - expected value
  - actual value
  - why it matters
  - recommended corrective action
- Continue to include operational recommendations, for example:
  - if MCAS role, bucket, or SNS topic is missing or misconfigured, explain that MCAS analytics and downstream analysis will not work correctly
  - if MDFS bucket or KMS setup is missing, explain that Suger will not receive full structured billing, buyer, and revenue data
  - if required IAM policies are missing, explain which capabilities are blocked
- For skipped checks, explain why they were skipped.
- Offer to re-run one failed section or the full verification flow.
- If everything passed, say the AWS Marketplace integration appears correctly configured.

SHA-256: 05a477e894ab5a6e3ec28bcef8a9ab08d51afa9c43628bb763ebb151fa6f14c2