Reference: Node-to-Next Migration
Do not run deploy commands during discovery.
Avoid serverless deploy dev or serverless deploy prod.
Do not update Lambda configs or environment variables during analysis.
# Serverless configs
rg --files -g" serverless*.yml"
# Lambda functions and handlers
rg " handler|exports\\ .handler|lambda" .
# API Gateway routes or swagger/openapi
rg " openapi|swagger|x-amazon-apigateway|/v1|/api" .
# Auth and role checks
rg " useSession|useAuth|requireAuth|withAuth|jwt|roles|permissions" .
# RDS/DB usage
rg " postgres|pg|knex|prisma|sequelize|mysql|rds" .
# SQS usage
rg " sqs|SendMessage|ReceiveMessage|QueueUrl" .
# S3 usage
rg " s3|getSignedUrl|PutObject|GetObject|Bucket" .
# OpenAI usage
rg " openai|OpenAI|chat\\ .completions|responses" .
Read-only AWS CLI discovery
# List Lambda functions
aws lambda list-functions
# Get runtime and sizing for a specific function
aws lambda get-function-configuration --function-name < function>
# API Gateway routes (REST)
aws apigateway get-rest-apis
aws apigateway get-resources --rest-api-id < api_id>
# API Gateway routes (HTTP API)
aws apigatewayv2 get-apis
aws apigatewayv2 get-routes --api-id < api_id>
# CloudWatch metrics (Lambda invocations)
aws cloudwatch get-metric-statistics \
--namespace AWS/Lambda \
--metric-name Invocations \
--dimensions Name=FunctionName,Value=< function> \
--start-time < start> --end-time < end> --period 3600 \
--statistics Sum
API Gateway routes -> app/api/**/route.ts with method parity.
Lambda auth -> Next middleware or per-route guards.
RDS schema -> Planetscale Postgres with explicit migrations.
SQS jobs -> Workflow Devkit flows with idempotency keys.
Secrets -> Vercel env with environment scopes.
Server-only code under src/server/ or lib/server/.
Shared types under src/types/.
No server-only imports in client components.
Route parity (paths, methods, status codes, JSON shape).
Auth parity (same redirects and role gates).
Data parity (row counts, key constraints, query outputs).
Job parity (retries and idempotency verified).
Observability parity (errors logged and alerts firing).
Validate input schemas in every Route Handler.
Rate limit public endpoints and AI routes.
Keep secrets out of client bundles.
Enforce CORS/CSRF where applicable.