AWS Open-Sources Two Tools for Self-Hosted Regional Availability Intelligence
Cloud Platform EngineeringMulti-region AWS architecture requires a clear answer to one question before any design decision: is the service, feature, API, or CloudFormation resource I need actually available in the target region? The AWS console has a regional availability tool, but for teams with compliance requirements, governance policies, or air-gapped environments, “look it up on the console” isn’t an acceptable operational dependency.
AWS published two open-source tools that bring this capability inside your VPC, on your refresh schedule, under your data ownership policies.
Tool 1: Capability Insights for AWS
A self-hosted dashboard that displays service, feature, API, and CloudFormation resource availability across AWS regions. The dashboard runs inside a private VPC — your network, your data, your refresh cadence.
Architecture:
- Dashboard served via API Gateway VPC endpoint (private, not internet-accessible)
- Lambda functions execute within the VPC; the only external call reads AWS-published availability data from an S3 access point
- EventBridge schedules daily data refresh (24-hour intervals, configurable)
- S3 gateway endpoint for data transfer without NAT charges
What it shows:
- Which services are available in each region
- Which API operations are region-specific
- Which CloudFormation resources have regional gaps
- Feature-level availability (not just service-level)
The feature-level granularity matters. A service being “available” in a region doesn’t mean every feature of that service is available. VPC Lattice is available in many regions but specific routing features may lag. Route 53 Resolver endpoints have region-specific DNS inbound endpoint limitations. Capability Insights tracks these at the feature level.
Tool 2: Workload Analysis
Capability Insights shows all 200+ AWS services. Workload Analysis narrows the catalog to the 20–30 services your account actually uses — significantly reducing the scope of regional gap analysis and producing a personalized availability view.
Architecture:
- Analyzes CloudTrail logs via parallel Athena queries to identify services your workloads call
- Inspects CloudFormation stack templates to identify the resources you’ve deployed
- Produces a filtered availability catalog: only services in your actual footprint
The operational value: A 200-service availability catalog is harder to maintain governance processes around than a 25-service personalized catalog. Workload Analysis produces the latter automatically, refreshing as your CloudTrail logs update.
Why Self-Hosted Matters
The AWS team’s documentation is explicit about the driver: “Teams told us they need this data deployed as infrastructure they own, refreshing on their schedule, inside their network.”
The scenarios where this matters:
- Compliance reporting: Auditors require availability documentation that doesn’t depend on external console access. A self-hosted dashboard produces an exportable artifact.
- Deployment validation: CI/CD pipelines that need to verify regional availability before deploying can query the private VPC endpoint rather than calling an external AWS service.
- Air-gapped or restricted environments: Networks with limited egress can’t use the public console tool. Self-hosted brings the capability inside the perimeter.
- Governance workflows: Teams can build approval processes around regional expansion that require the availability data in an internal system rather than referencing external URLs.
Relationship to Existing AWS Availability Tools
These tools complement but don’t replace:
- AWS Capabilities by Region S3 Access Point: The data source both tools read from; still the authoritative data, now with a self-hosted consumption layer
- AWS Knowledge MCP Server: An alternative consumption path for AI agent workflows
- AWS Capabilities by Region web explorer: The console tool for interactive browsing
The architecture deliberately separates the data (still sourced from AWS) from the serving layer (now deployable in your VPC). Teams that need the data under their own governance controls get that without AWS needing to change how the data is published.
Deployment
Both tools are available as open-source on GitHub with CloudFormation deployment templates. Capability Insights deploys in approximately 15 minutes from the template. Workload Analysis requires IAM permissions to read CloudTrail (via Athena) and describe CloudFormation stacks.
The So What
The gap this fills is a data governance one, not a data accuracy one. AWS’s public availability data has been accessible; the constraint was consuming it in a compliant, self-owned, auditable way. These tools close that gap for the specific teams — regulated industries, government contractors, large enterprises with strict data residency policies — where the console tool wasn’t an option.
For teams without those constraints: the tools are still useful for building availability validation into CI/CD pipelines, but the public console tool and the Knowledge MCP Server cover the interactive use case without additional infrastructure.
Content created with AI assistance and reviewed for accuracy.
Join the conversation
Stack Insiders is our free community for readers who want to go deeper — share resources, ask questions, and connect with others across every vertical we cover.
Join Stack Insiders →