🐢
ShellShift
Contact Sign in
Live sandbox · us-east-1

Migrate supported AWS workloads.
With evidence, not guesswork.

Connect a supported AWS source account. ShellShift scans the environment, reconstructs key service relationships, and prepares a controlled target migration flow with validation evidence at every step.

24 resources migrated
12 smoke checks passed
0 issues flagged
Current proof points Live sandbox demo Scan to validation workflow Cross-account role model Migration artifacts
Source inventory
Dependency remap
Target rebuild
Validation evidence
AWS Lambda
ECS clusters
DynamoDB tables
SQS queues

Three steps. Controlled migration flow.

Connect your AWS org and move from source discovery to validated target deployment for supported scenarios.

01
Connect your source account

Create a read-only IAM role and paste the ARN. ShellShift assumes the role and scans supported resources such as Lambda, SQS, DynamoDB, and ECS. No write permissions needed on the source.

02
We remap supported dependencies

ShellShift builds a dependency map, identifying supported resource relationships, environment variables, IAM bindings, and network context before touching the target.

03
Target rebuilt with evidence

Supported resources are recreated on the target in the correct order. Every action generates a deployment manifest and validation report for review and handoff.

Real migration data.
From our sandbox.

This is sandbox migration evidence from the current backend. It shows the shape of the workflow and the validation artifacts we generate.

  • Source inventory read in real-time via boto3
  • Dependency graph built from discovered resources
  • Clone manifest generated for target account
  • Validation report with smoke checks and issue flags
ShellShift: sandbox migration run
Resources
--
Smoke checks
--
Issues
--
λ
Lambda functions
Cloned
SQS queues
Cloned
DynamoDB tables
Cloned
ECS cluster
Cloned
Validation report
Generated

What the product already does well.

Full source inventory

Discover every Lambda, SQS queue, DynamoDB table, ECS cluster, VPC, subnet, and IAM role in your source account.

Dependency graph

Build a dependency graph for supported resources before migration so target planning is grounded in actual discovery data.

Automated rebuild

Supported resources recreated in the correct order on the target account, reducing manual rebuild work.

Deployment manifest

Every migration generates a machine-readable manifest of all created resources, mappings, and configuration.

Validation evidence

Smoke checks run automatically post-migration. Results are exportable as a validation report for audits.

Read-only access

ShellShift only needs read permissions on the source. The target side can be kept behind a separate controlled role.

Start with a controlled AWS assessment.
Scale into migration after proof.

Share your source environment and we scope supported migration paths, timeline, and validation outputs before rollout.

✓ Read-only IAM access ✓ Read-only source scan ✓ Full validation evidence