<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <link href="http://pubsubhubbub.appspot.com/" rel="hub"/>
  <link href="https://f43.me/aws-blogs.xml" rel="self"/>
  <title>AWS Blogs</title>
  <subtitle>AWS Blog</subtitle>
  <link href="http://aws.amazon.com"/>
  <updated>2026-08-13T01:20:03+02:00</updated>
  <id>http://aws.amazon.com/</id>
  <author>
    <name>AWS Blogs</name>
  </author>
  <generator>f43.me</generator>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-heroes-summit-web-search-on-amazon-bedrock-dogwood-kiro-crew-and-more-august-10-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: AWS Heroes Summit, Web Search on Amazon Bedrock, Dogwood, Kiro Crew, and more (August 10, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Last week, we brought together <a href="https://builder.aws.com/community/heroes/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Heroes</a> from around the world to connect, collaborate, and celebrate the builders who go above and beyond for the AWS community.</p><p><img class="aligncenter size-full wp-image-105229" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/08/07/1785879027542.jpg" alt="" width="1280" height="833" /></p><p>The AWS Heroes Summit, an invite-only annual gathering, brings global experts specializing in fields like AI, serverless, and containers together for direct collaboration, technical deep-dives, and feedback sessions with internal AWS product and service teams.</p><p>Day 1 started with an inspiring fireside chat from AWS CEO Matt Garman. From an insightful AMA with James Hamilton on Day 2 to breakout sessions from various product teams that sparked new ideas, our AWS Heroes excelled at sharing knowledge, lifting each other up, and turning conversations into collaborations. To learn more, read the <a href="https://www.linkedin.com/search/results/content/?keywords=%23awsheroessummit&amp;origin=FACETED_SEARCH&amp;sortBy=%5B%22relevance%22%5D">attendee feedback on LinkedIn</a>.</p><p><strong class="c7">Last week’s launches</strong><br />Here are some launches that got my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-bedrock-web/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Web Search on Amazon Bedrock</a>: Amazon Bedrock now enables OpenAI models (GPT-5.4, GPT-5.5, and GPT-5.6 Sol/Terra/Luna) to browse and retrieve information from the internet, allowing AI applications to access up-to-date information beyond their training data. This capability opens new possibilities for building AI agents and applications that can answer questions using real-time web content while maintaining data residency within your secured AWS environment with zero data egress. To get started, visit the <a href="https://aws.amazon.com/blogs/machine-learning/introducing-web-search-on-amazon-bedrock-for-foundation-model-grounding/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AI blog post</a> and the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/web-search.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock User Guide</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/08/aws-bedrock-agentcore-runtime-instances-generally-available/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Runtime Instances on Amazon Bedrock AgentCore</a>: You can now deploy and run AI agents on dedicated runtime instances through Amazon Bedrock AgentCore, providing more control over agent execution environments with predictable performance and cost. To get started, visit <a href="https://aws.amazon.com/blogs/aws/runtime-instances-persistent-compute-for-production-ai-agents-on-amazon-bedrock-agentcore/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Sébastien’s blog post</a> and <a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-instances-how-it-works.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AgentCore documentation</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/08/amazon-dynamodb-vector-search?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Vector search for Amazon DynamoDB</a>: You can store and query vector embeddings alongside your existing data in DynamoDB without managing a separate vector database. DynamoDB already supports storing memory for AI agents, and with vector search you can now add semantic retrieval over that memory for agentic grounding, with predictable performance. To learn more, visit <a href="https://aws.amazon.com/blogs/aws/amazon-dynamodb-now-supports-real-time-vector-search-at-any-scale?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Esra’s blog post</a> and <a href="https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/VectorSearch.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon DynamoDB Developer Guide</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/7/aws-transform-continuous-general-available?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS Transform continuous modernization now generally available</a>: This capability helps engineering teams analyze and remediate technical debt across source code repositories at scale. You can modernize mainframe and legacy workloads with an ongoing, automated approach rather than a one-time migration event. To learn more, visit <a href="https://aws.amazon.com/blogs/aws/proactively-reduce-tech-debt-autonomously-with-aws-transform-continuous-modernization-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Micah’s preview blog post</a>. You can also try the <a href="https://docs.aws.amazon.com/transform/latest/userguide/ct-developer-tools.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS Transform Kiro Power and agent plugins</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/08/aws-lambda-network-bandwidth/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Up to 3,000 Mbps for AWS Lambda function bandwidth</a>: AWS Lambda functions now support increased network bandwidth, enabling data-intensive workloads and faster communication between Lambda functions and other AWS services. This feature enables functions outside a VPC that are configured with 2 GB of memory or more to access network bandwidth that scales proportionally, from 625 Mbps at 2 GB up to 3,000 Mbps at 10 GB.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">What’s New with AWS</a> page.</p><p><strong class="c7">Other AWS news</strong><br />Here are some additional projects and news items that you may find interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/opensource/introducing-dogwood-runtime-verification-for-ai-agents/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Introducing Dogwood: Runtime Verification for AI Agents</a>: AWS open-sourced Dogwood, a purpose-built governance language for AI agents to support Cedar policies and add temporal conditions. Powering Dogwood, Amazon Bedrock AgentCore introduced <a href="https://aws.amazon.com/about-aws/whats-new/2026/08/temporal-policies-agentcore/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">temporal policies</a> whose decisions depend on the history of an agent’s actions within a session, not on the current request alone.</li>
<li><a href="https://aws.amazon.com/blogs/opensource/aws-supports-agent-plugins-an-open-standard-for-portable-agent-extensions/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS supports Agent Plugins: An Open Standard for Portable Agent Extensions</a>: AWS announced support for Agent Plugins, an open source, vendor-neutral specification that gives AI agent extensions a common packaging format so you can package an extension once and ship it to any client, including Kiro, VS Code, Cursor, or any tool that implements the spec.</li>
<li><a href="https://kiro.dev/blog/introducing-kiro-crew/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Introducing Kiro Crew</a>: Kiro Crew is a persistent, self-evolving workspace that keeps work moving, online or off, enabling collaborative multi-agent development workflows within the Kiro IDE. It’s built for engineering work that goes beyond a single chat session, and spans repos, tools, and days. You can run several efforts in parallel or hand work to subagents that report back, so nothing waits in line.</li>
</ul><p>For a full list of AWS blog posts, be sure to keep an eye on the <a href="https://aws.amazon.com/blogs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Blogs</a> page.</p><p>Learn more about AWS, browse and join upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS-led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?tab=upcoming?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused events</a> including <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summits</a> and <a href="https://aws.amazon.com/events/community-day/">AWS Community Days</a>. Join the <a href="https://builder.aws.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development.</p><p>That is all for this week. Check back next Monday for another Weekly Roundup!</p><p>— <a href="https://www.linkedin.com/in/channy">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="bf051b5f-f898-4cdb-92bf-d93c750a6376" data-title="AWS Weekly Roundup: AWS Heroes Summit, Web Search on Amazon Bedrock, Dogwood, Kiro Crew, and more (August 10, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-heroes-summit-web-search-on-amazon-bedrock-dogwood-kiro-crew-and-more-august-10-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-heroes-summit-web-search-on-amazon-bedrock-dogwood-kiro-crew-and-more-august-10-2026/"/>
    <updated>2026-08-10T17:45:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/runtime-instances-persistent-compute-for-production-ai-agents-on-amazon-bedrock-agentcore/</id>
    <title><![CDATA[Runtime instances: persistent compute for production AI agents on Amazon Bedrock AgentCore]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>When you move AI agents from prototype to production, the infrastructure challenges multiply. Your agents need to persist state across multi-step workflows that run for hours or days. They need to coordinate with other agents, share context, and sometimes access GPUs for specialized tasks. Amazon Bedrock AgentCore runtime microVMs provide a fully managed environment for invocations that can run for up to 8 hours and support stateful workflows through managed session storage. Some workloads also benefit from dedicated, larger-capacity environments — for example, when agents need to run continuously for multiple days, access GPUs or the underlying OS, or run multiple collaborating agents on the same host.</p><p>Today, I’m happy to announce runtime instances, a new complementary compute option in <a href="https://aws.amazon.com/bedrock/agentcore/">Amazon Bedrock AgentCore Runtime</a> that gives your agents persistent, managed infrastructure purpose-built for complex agent workloads.</p><p><strong>What you get</strong><br />Runtime instances provides AWS-managed EC2 infrastructure where you deploy multiple agents in a single runtime, each with their own dependencies and artifact types. Your agents can collaborate on the same host within shared sessions that persist for up to 14 days. The service supports GPU acceleration for compute-intensive tasks, session stop/restart to save costs during idle periods, and containerized deployments for teams that want to ship independently. For knowledge that needs to survive beyond a session, runtime instances pairs naturally with <a href="https://aws.amazon.com/ebs/">Amazon Elastic Block Store (Amazon EBS)</a> and AgentCore Memory, which gives your agents long-term recall across sessions and environments.</p><p>Before today, if you wanted to keep your agents running for days or they needed GPU access, or multi-agent coordination, you had to build and manage that infrastructure yourself. You provisioned EC2 instances, configured networking, set up session management, handled scaling, and stitched together monitoring. Runtime instances handles all of that for you while integrating with the same AgentCore APIs, identity controls, and observability you already use with AgentCore Runtime microVMs.</p><p>A few things that should make agent developers smile: your agents can call each other as tools within a shared session, iterating autonomously until the job is done. You bring any framework (<a href="https://crewai.com/">CrewAI</a>, <a href="https://www.langchain.com/langgraph">LangGraph</a>, <a href="https://www.llamaindex.ai/">LlamaIndex</a>, Strands) and any model. Packaging is minimal, a <code>@app.entrypoint</code> decorator and a zip file or container image. And if your workflow spans days, hibernate Monday night and resume Wednesday morning with everything intact.</p><p>Runtime microVMs and runtime instances are complementary compute options that you can use independently or together through the same AgentCore runtime APIs. A lightweight orchestrator agent on runtime microVM can coordinate and dispatch work to specialized worker agents running on instances. The orchestrator handles API calls, task routing, and result aggregation using runtime microVM’s fast scaling, while workers on Instances perform compute-intensive tasks like code compilation, security scanning, or GUI automation that require persistent state and direct OS access.</p><p><strong>Let me show you how it works<br /></strong> I built two agents for this demo: a code writer agent that generates Python code from natural language descriptions, and a code reviewer agent that analyzes the generated code for bugs, security issues, and style improvements. Both agents share the same file system, so the reviewer can read whatever the writer produces without any data transfer or API calls between them.</p><p>Here is the code writer (simplified, no error handling):</p><pre class="lang-python">writer = Agent(
    model="us.anthropic.claude-sonnet-4-5-20250929-v1:0",
    system_prompt=(
        "You are a senior Python engineer. "
        "Given a task, return ONLY a single Python code block — no prose."
    ),
)
@app.entrypoint
def handler(event, context):
    task = event.get("task") or event.get("prompt")
    session_id = getattr(context, "session_id", None) or event.get("session_id")
    session_dir = SHARED_DIR / session_id
    session_dir.mkdir(parents=True, exist_ok=True)
    code = str(writer(task))
    (session_dir / "code.py").write_text(code)
    return {"agent": "writer", "wrote": str(session_dir / "code.py"), "code": code}</pre><p>Here is the code reviewer agent (simplified, no error handling):</p><pre class="lang-python">reviewer = Agent(
    model="us.anthropic.claude-sonnet-4-5-20250929-v1:0",
    system_prompt=(
        "You are a strict Python code reviewer. "
        "Given code, return 3 bullet points: bugs, style, suggestions."
    ),
)
@app.entrypoint
def handler(event, context):
    session_id = getattr(context, "session_id", None) or event.get("session_id")
    code_path = SHARED_DIR / session_id / "code.py"
    code = code_path.read_text()
    review = str(reviewer(f"Review this code:\n\n{code}"))
    return {"agent": "reviewer", "read": str(code_path), "review": review}
</pre><p>Each agent is a Python application using <a href="https://strandsagents.com/">Strands Agents</a> with an <code>@app.entrypoint</code> decorator and a model of its choice. I package each one as a zip file. For this demo, I use the <a href="https://console.aws.amazon.com">AWS Management Console</a>. You can also use the <a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-get-started-cli.html">AgentCore CLI</a>, the <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a> or infrastructure as code.</p><p><strong>Step 1: Create a capacity provider.</strong></p><p>A capacity provider defines the EC2 infrastructure your agents run on. In the AgentCore console, I select <strong>Runtime</strong> in the left navigation, then select the <strong>Capacity providers</strong> tab and <strong>Create capacity provider</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-18_12-25-58.png"><img class="aligncenter size-large wp-image-104781" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-18_12-25-58-1024x769.png" alt="ACI Create Capcity Provider 1" width="1024" height="769" /></a></p><p>I give it a <strong>Name</strong>, select Linux (64-bit ARM) as the <strong>Operating system</strong>, and choose <code>c7g.2xlarge</code> as the <strong>Allowed instance types</strong>. This gives me 8 vCPUs and 16 GiB of memory, enough for both agents to run comfortably side by side.</p><p>Further down, I configure the <strong>VPC</strong>, <strong>subnets</strong>, and <strong>security groups</strong> for network access. Under <strong>Storage configuration</strong>, I keep the default gp3 volume. Under <strong>Service access</strong>, I select <strong>Create a new service role</strong> and let the console create the infrastructure role that manages EC2 instances on my behalf.</p><p>I select <strong>Create capacity</strong> provider and wait a few seconds. The status moves to <strong>Active</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-18_12-31-53.png"><img class="aligncenter size-large wp-image-104783" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-18_12-31-53-1024x834.png" alt="ACI Create Capacity Provider 2" width="1024" height="834" /></a></p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-18_12-32-39.png"><img class="aligncenter size-full wp-image-104784" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-18_12-32-39.png" alt="ACI Create Capacity Provider 3" width="934" height="712" /></a></p><p>Note the capacity provider configuration summary: operating system, instance type, subnets, security group, instance profile, and infrastructure role. Once created, only the description can be edited, so verify your settings before you proceed.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-18_12-35-42.png"><img class="aligncenter size-large wp-image-104782" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-18_12-35-42-1024x860.png" alt="ACI Create Capcity Provider 2" width="1024" height="860" /></a></p><p><strong>Step 2: Create a runtime and deploy the first agent.</strong></p><p>Back on the <strong>Runtime</strong> page, I select <strong>Create runtime</strong>. I give it a <strong>Name</strong>, select Instances as the <strong>Compute type</strong>, and choose the <strong>Capacity provider</strong> I created in the previous step.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-19_11-34-29.png"><img class="aligncenter size-large wp-image-104785" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-19_11-34-29-1024x444.png" alt="ACI Create Runtime 1" width="1024" height="444" /></a></p><p>Under <strong>Agent source</strong>, I select <strong>S3 Source</strong>, then <strong>Upload to S3</strong>. I choose my agent zip file (<code>ACIDemoWriter.zip</code>), set the <strong>Language runtime</strong> to <code>Python 3.13,</code> and specify <code>agent.py</code> as the <strong>Agent entry point</strong>. This is the file that contains my <code>@app.entrypoint</code> decorated function. Under <strong>Permissions</strong>, I select <strong>Create default role</strong> to let the console provision the IAM role my agent needs.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-19_11-34-45.png"><img class="aligncenter size-large wp-image-104786" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-19_11-34-45-1024x986.png" alt="ACI Create Runtime 2" width="1024" height="986" /></a></p><p>I select <strong>Create runtime</strong> and wait for the status to become <strong>Ready</strong>.</p><p>I repeat the same process for my code reviewer agent. I create a second runtime, select the same capacity provider, upload my reviewer agent zip file, and wait for it to become <strong>Ready</strong>. Both agents now share the same underlying EC2 infrastructure.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/30/2026-06-19_16-19-53.png"><img class="aligncenter size-large wp-image-104926" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/30/2026-06-19_16-19-53-1024x646.png" alt="AgentCore Runtime Instances - Agent Ready" width="1024" height="646" /></a>The console shows me a <strong>View invocation code</strong> section with ready-to-use Python, TypeScript, and JavaScript snippets to invoke my agent programmatically. But for this demo, I use the built-in test feature. I select <strong>Test</strong> on the writer agent’s page.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/30/2026-06-19_16-21-30.png"><img class="aligncenter size-large wp-image-104927" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/30/2026-06-19_16-21-30-1024x679.png" alt="AgentCore Runtime Instances - Show invocation code" width="1024" height="679" /></a><strong>Step 3: Invoke agents and observe collaboration.</strong></p><p>The <strong>Runtime playground</strong> opens. At the top, I see three fields: <strong>Runtime agent</strong>, <strong>Endpoint</strong>, and <strong>Session ID</strong>. The console generates a session ID automatically. I take note of it because I will reuse it with the reviewer agent.</p><p>In the <strong>Input</strong> field, I type a JSON payload asking the writer agent to generate code:</p><pre class="lang-json">{"prompt": "write a fibonacci suite"}</pre><p>I select <strong>Run</strong>. After a few seconds, the <strong>Output</strong> panel shows the agent’s response. The writer agent generated a Python module with two implementations of a Fibonacci sequence (a list-based function and a generator) and wrote it to <code>/tmp/agentcore-session/ca5ec24d-07f5-4eeb-add1-5ba416bf9eb2/code.py</code>. Notice the session ID in the file path. That directory is the shared file system for this session.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/30/2026-06-30_06-45-53.png"><img class="aligncenter size-large wp-image-104928" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/30/2026-06-30_06-45-53-1024x722.png" alt="AgentCore Runtime Instances - Invoke code writer agent" width="1024" height="722" /></a></p><p><strong>Step 4: Invoke the reviewer agent in the same session.</strong></p><p>Now I switch the <strong>Runtime agent</strong> dropdown to <strong>ACIDemoReviewer</strong>. The important part: I paste the same session ID (<code>ca5ec24d-07f5-4eeb-add1-5ba416bf9eb2)</code> in the <strong>Session ID</strong> field. This is what connects the two agents.</p><p>I type a simple prompt:</p><pre class="lang-json">{"prompt": "review the code"}</pre><p>I select <strong>Run</strong>. The reviewer agent reads the file the writer produced from the shared session directory and returns a detailed code review. It finds no critical bugs but suggests adding type hints, input validation, and simplifying the edge case handling.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/30/2026-06-30_06-49-53.png"><img class="aligncenter size-large wp-image-104929" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/30/2026-06-30_06-49-53-1024x740.png" alt="AgentCore Runtime Instances - Invoke code reviewer agent" width="1024" height="740" /></a>The two agents never exchanged messages or called each other’s APIs. They collaborated through the shared file system that runtime instances provide within a session. You can extend this pattern to any number of agents: a test agent that runs the code, a documentation agent that generates README files, a security agent that scans for vulnerabilities, all sharing the same working directory.</p><p><strong>Key details<br /></strong> Here are a few things to know as you get started:</p><ul><li><strong>Supported OS</strong>: Linux (ARM64 and x86_64) at launch.</li>
<li><strong>Session persistence</strong>: Sessions persist for up to 14 days.</li>
<li><strong>Runtimes</strong>: Python 3.11-14 with native code support. Container images also supported.</li>
<li><strong>GPU</strong>: Support for GPU-accelerated instance types.</li>
<li><strong>Integration</strong>: Uses the same AgentCore APIs, identity, observability, and policy controls as AgentCore Runtime.</li>
<li><strong>Pricing</strong>: Standard EC2 pricing plus a management fee for AgentCore orchestration.</li>
<li><strong>Regions</strong>: US East (Ohio, N. Virginia), US West (Oregon), Asia Pacific (Mumbai, Singapore, Sydney, Tokyo), and Europe (Frankfurt, Ireland)</li>
</ul><p>To get started, visit the runtime instance in <a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-instances-how-it-works.html">Amazon Bedrock AgentCore documentation</a>and create your first capacity provider.</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="6d655467-e1d4-431f-9b57-353d0c2a9e5e" data-title="Runtime instances: persistent compute for production AI agents on Amazon Bedrock AgentCore" data-url="https://aws.amazon.com/blogs/aws/runtime-instances-persistent-compute-for-production-ai-agents-on-amazon-bedrock-agentcore/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/runtime-instances-persistent-compute-for-production-ai-agents-on-amazon-bedrock-agentcore/"/>
    <updated>2026-08-07T00:58:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-dynamodb-now-supports-real-time-vector-search-at-any-scale/</id>
    <title><![CDATA[Amazon DynamoDB now supports real-time vector search at any scale]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the general availability of vector search in <a href="https://aws.amazon.com/dynamodb/">Amazon DynamoDB</a>. You can now store vector embeddings alongside your operational data in DynamoDB and run similarity searches directly against that data, without replicating it to a separate vector store.</p><p>DynamoDB supports native vector search with single-digit millisecond latency at 99%+ recall, and is designed for any scale, even trillions of vectors. There are no servers to provision, patch, or manage, and no software to install, maintain, or operate. The service has no versions, no maintenance windows, and zero downtime maintenance.</p><p>Vector indexes have no storage limits and scale horizontally as your data grows. You can now build applications that require semantic retrieval on agentic memory, retrieval augmented generation, recommendation engines, personalized experiences, anomaly detection, and more using DynamoDB and its native vector search.</p><p>If your application already uses DynamoDB, adding vector search previously required copying data into a dedicated vector database while maintaining a synchronization pipeline between the two services. This added operational overhead, data movement costs, licensing costs, and the challenge of maintaining predictable low latency at scale. With vector search built into DynamoDB, your vectors and operational data share the same serverless infrastructure and the same pay-per-request pricing model.</p><p>Vector search in DynamoDB introduces a new index type that you create on an attribute storing vector embeddings. You generate embeddings using a model of your choice, such as Amazon Bedrock Titan Text Embeddings, Cohere Embed, or OpenAI text embedding models, and store them as a list of floats in your table using a standard <code>PutItem</code> call. You then create a vector index on that attribute and specify the number of dimensions, the distance function, and any non-vector attributes you want to use as filters to narrow search results at query time. The <code>SearchVectors</code> API accepts a query vector, the number of results to return (up to 100), and optional filter conditions. It returns results ranked by similarity.</p><p>Use vector search in DynamoDB when your operational data already lives in DynamoDB and you want to add similarity search without provisioning a separate database or managing a synchronization pipeline. DynamoDB is fully serverless, so vector search scales automatically with no infrastructure to manage. It supports up to 4096 dimensions, Euclidean, Cosine, and Dot product distance functions, and inline filtering.</p><p><strong>Getting started with vector search in DynamoDB<br /></strong> This walkthrough shows how to add vector search to an existing DynamoDB table using the <a href="https://console.aws.amazon.com/dynamodbv2/home">DynamoDB console</a>. The scenario contains an online sporting goods store with a product catalog table. Each item has standard operational attributes such as <code>productId</code>, <code>category</code>, <code>description</code>, <code>marketplace</code>, <code>name</code>, and <code>price</code>. The goal is to add semantic search so shoppers can find products using natural language queries rather than exact keyword matches.</p><p><strong>1. Prepare DynamoDB table</strong><br />To enable semantic search, I first generate vector embeddings for the product descriptions already in my table. Embeddings are numerical representations of text generated by a machine learning model that capture the meaning of the content. Two items with similar descriptions will have embeddings that are close to each other in vector space, which is what makes similarity search possible.</p><p><img class="aligncenter wp-image-105171 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/07/29/1212634454659342-0a-1.png" alt="" width="1405" height="599" /></p><p>I can generate embeddings using <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/titan-embedding-models.html">Amazon Bedrock Titan Text Embeddings</a> or another embedding model, then add them to my table using the <a href="http://console.aws.amazon.com">AWS Management Console</a>, <a href="https://aws.amazon.com/cli">AWS Command Line Interface (AWS CLI)</a>, <a href="https://docs.aws.amazon.com/sdkref/latest/guide/overview.html">AWS SDKs</a>, <a href="https://aws.amazon.com/cloudformation/">AWS CloudFormation</a>, or other infrastructure-as-code (IaC) tools.</p><p>For an existing table like <code>ProductCatalog</code>, I add the embeddings to each item as a new attribute named <code>descriptionEmbedding</code> using an <code>UpdateItem</code> call. DynamoDB stores vector embeddings using its existing <code>List</code> data type. Each element in the list is a <code>Number</code> that represents a single float value of the embedding vector. This means I do not need a new data type or schema change to start storing vectors alongside my existing operational attributes.</p><p><strong>2. Create vector index<br /></strong> In the <a href="https://console.aws.amazon.com/dynamodbv2/home">DynamoDB console</a>, open the <code>ProductCatalog</code> table and choose the <strong>Indexes</strong> tab. I choose <strong>Create vector index</strong>. On the <strong>Create vector index</strong> page, I fill in the index details as follows. I enter <code>ProductDescriptionIndex</code> as the <strong>Index name</strong> and <code>descriptionEmbedding</code> as the <strong>Vector attribute</strong>.</p><p><img class="aligncenter size-full wp-image-105107" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/07/22/1212634454659342-1c.png" alt="" width="1924" height="2341" /></p><p>I enter the number of <strong>Dimensions</strong> that matches my embedding model’s output and select <strong>Cosine</strong> as the <strong>Distance function</strong>. Cosine measures the angle between vectors rather than their magnitude, which makes it effective for comparing semantic similarity of text embeddings. Vector search in DynamoDB also supports <strong>Euclidean</strong> and <strong>Dot product</strong> distance functions.</p><ul><li><strong>Euclidean</strong>: Use when the magnitude of the vectors is meaningful, such as clustering items by a numeric value like purchase count.</li>
<li><strong>Dot product</strong>: Use when both direction and magnitude matter, such as in recommendation systems that weight interest alignment and frequency together. As a general rule, match the distance function to the one used to train your embedding model for the best accuracy.</li>
</ul><p>I enter <code class="inline-code">marketplace</code> as the <strong>Partition key</strong>. The vector index partition key controls how DynamoDB distributes vectors across partitions, allowing the index to scale out while maintaining predictable latencies. Each search is scoped to a single partition key value, so a product catalog serving multiple marketplaces can search within one marketplace’s inventory without scanning the entire index. The partition key is optional, but recommended for large datasets with high query throughput.</p><p>I expand <strong>Inline filter attributes</strong> and add <strong>category</strong> as a filter attribute. This helps me narrow search results to a specific product category at query time. Filter conditions support exact-match values only; range conditions such as <code class="inline-code">BETWEEN</code> or <code class="inline-code">BEGINS_WITH</code> are not supported. I leave <strong>Attribute projections</strong> set to <strong>All</strong> so that all table attributes are returned with my search results. Choose <strong>Create vector index</strong> and wait for the index status to change to <strong>Active</strong>.</p><p><strong>3. Run vector search</strong><br />I generate a query vector from a natural language search term such as “<em>lightweight running shoes for summer</em>” using the same embedding model I used for the product descriptions. In the DynamoDB console, I choose <strong>Explore items</strong> in the left navigation pane and select the <code>ProductCatalog</code> table.</p><p>Choose <strong>Search</strong> to switch to vector search mode. I select <strong>ProductDescriptionIndex</strong> from the <strong>Select a vector index</strong> dropdown, paste the query vector into the <strong>Search vector</strong> field, and set <strong>Number of results (Top K) </strong>to 5. I enter <strong>US</strong> as the <strong>Partition key value</strong> to scope the search to the US marketplace. I expand <strong>Inline filter attributes</strong> and set <strong>category</strong> equal to <strong>footwear</strong> to narrow the search to footwear products only. Now, choose <strong>Run</strong>.</p><p><img class="aligncenter size-full wp-image-105110" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/07/22/1212634454659342-2b.png" alt="" width="1913" height="1472" /></p><p>DynamoDB returns the five most semantically similar products in the footwear category, ranked by similarity score, alongside the standard operational attributes such as name and price in the same response. The similarity score’s meaning depends on the distance function selected for the index. For Cosine and Euclidean distance functions, lower similarity score values indicate higher similarity, with a score of 0 indicating identical vectors. For the dot product distance function, higher similarity score values indicate higher similarity.</p><p>To interact with vector search programmatically, including calling APIs and searching documentation, try the <a href="https://docs.aws.amazon.com/agent-toolkit/latest/userguide/getting-started-aws-mcp-server.html">AWS MCP Server</a> and <a href="https://docs.aws.amazon.com/agent-toolkit/latest/userguide/plugins.html">plugins</a> with your preferred AI coding tool. To learn more, visit the <a href="https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/VectorSearch.html">Amazon DynamoDB Developer Guide</a>.</p><p><strong>Get started today<br /></strong> Vector search in <a href="https://aws.amazon.com/dynamodb/">Amazon DynamoDB</a> is generally available in all commercial AWS Regions, including the AWS GovCloud (US) Regions. For Regional availability and a future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>. For pricing details, visit the <a href="https://aws.amazon.com/dynamodb/pricing/">Amazon DynamoDB pricing page</a>.</p><p>Start exploring vector search in DynamoDB today and send feedback to <a href="https://repost.aws/tags/knowledge-center/TAljkKQ0MDQJCjDdxSeDQBJw">AWS re:Post for Amazon DynamoDB</a> or through your usual AWS Support contacts.</p><a href="https://www.linkedin.com/in/esrakayabali/">— Esra</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="b4b7b651-35e7-446c-9fc3-be41961bc974" data-title="Amazon DynamoDB now supports real-time vector search at any scale" data-url="https://aws.amazon.com/blogs/aws/amazon-dynamodb-now-supports-real-time-vector-search-at-any-scale/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-dynamodb-now-supports-real-time-vector-search-at-any-scale/"/>
    <updated>2026-08-05T16:45:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-price-reduction-of-gpt-models-in-bedrock-cloudwatch-managed-collectors-for-prometheus-metrics-and-more-august-3-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Price reduction of GPT models in Bedrock, CloudWatch managed collectors for Prometheus metrics, and more (August 3, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p><img class="alignright size-medium wp-image-105197" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/08/03/IMG_2179-225x300.jpg" alt="" width="225" height="300" />Last week I had the joy of participating in Amazon’s “Bring Your Kids to Work Day” with my 7 year old son. We commuted together into the New York City office, his first real rush hour train ride, and spent the day exploring how Amazon uses AI, machine learning, and robotics to deliver packages to customers all over the world. Watching his eyes light up as he saw robots navigating a fulfillment center reminded me why so many of us got into technology in the first place. There’s nothing quite like seeing that sense of wonder when something complex clicks.</p><p>That same energy carried into the week’s launches. We’ve got updates across AI pricing, observability, multicloud networking, and data management. Let’s dive in.</p><p><strong>Headlines</strong></p><p><strong>Amazon Bedrock announces up to 80% lower prices for OpenAI GPT‑5.6 models</strong> – If you’re using OpenAI’s GPT‑5.6 family through Amazon Bedrock, your costs just dropped significantly. Effective July 30, on-demand inference prices for GPT‑5.6 Luna are reduced by 80%, while GPT‑5.6 Terra prices are reduced by 20%. Luna now costs $0.20 per million input tokens and $1.20 per million output tokens, making it one of the most affordable frontier-class models available. These price reductions apply automatically — no action required on your part. <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/openai-gpt-terra-luna-pricing-bedrock/">Read more</a></p><p><strong>Last week’s launches</strong></p><p>Here are some launches and updates from this past week that caught my attention:</p><ul><li><strong>Amazon CloudWatch announces managed Prometheus collectors</strong> – Amazon CloudWatch now supports collecting Prometheus metrics from your AWS infrastructure using fully managed collectors, enabling you to monitor Amazon EKS, Amazon EC2, Amazon ECS, Amazon MSK, and Amazon OpenSearch Service workloads without deploying or managing any agents. If you’ve been maintaining your own Prometheus scraping infrastructure, this removes a significant operational burden. <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/cloudwatch-managed-collectors/">Read more</a></li>
<li><strong>AWS Interconnect — multicloud connectivity with Oracle Cloud Infrastructure is now generally available</strong> – AWS Interconnect is the first purpose-built multicloud connectivity product of its kind, allowing you to quickly provision resilient, scalable private connections between AWS and other cloud providers. With this GA launch for Oracle Cloud Infrastructure (OCI), you can establish private cross-cloud networking without traversing the public internet, making it easier to run multicloud architectures with the security and performance your workloads demand. <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-announces-AWS-interconnect-multicloud-OCI-GA/">Read more</a></li>
<li><strong>AWS IAM Identity Center extends multi-Region support to Identity Center directory</strong> – You can now replicate IAM Identity Center from your primary AWS Region to additional Regions when using the Identity Center directory as your identity source. If IAM Identity Center is affected by a disruption in the primary Region, your users continue to have access to their AWS accounts using provisioned entitlements in additional Regions. This feature was previously available only for instances connected to external identity providers. <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-iam-identity-center-extends-multi-region-support-to-identity-center-directory/">Read more</a></li>
<li><strong>Amazon S3 Tables now supports the Variant data type for Apache Iceberg V3</strong> – Amazon S3 Tables adds support for the Variant data type, introduced in the Apache Iceberg V3 table format specification. Variant provides a high-performance, native solution for managing semi-structured data within your data lake — think IoT sensor data, application logs, and other schema-flexible payloads — without resorting to JSON blobs. <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-s3-tables-variant-iceberg-v3/">Read more</a></li>
</ul><p><strong>Other AWS news</strong></p><p>Here are some additional posts and resources that you might find interesting:</p><ul><li><strong><a href="https://aws.amazon.com/blogs/developer/installing-and-updating-the-aws-cli-with-single-line-commands/">Installing and updating the AWS CLI with single-line commands</a></strong> – A new blog post from the Developer Tools team that simplifies AWS CLI installation and updates across platforms with single-line commands. If you manage CLI versions across teams or in CI pipelines, this is a nice quality-of-life improvement.</li>
<li><a href="https://aws.amazon.com/blogs/machine-learning/deploying-kimi-k3-on-amazon-sagemaker-hyperpod-and-amazon-eks/"><strong>Deploying Kimi K3 on Amazon SageMaker HyperPod and Amazon EKS</strong></a> – A step-by-step guide for deploying Moonshot AI’s Kimi K3 model on AWS infrastructure using SageMaker HyperPod and Amazon EKS. If you’re evaluating large-scale model deployment options, this walks through the full workflow.</li>
<li><a href="https://aws.amazon.com/blogs/big-data/deliver-apache-kafka-data-to-streaming-tables-for-apache-iceberg-with-amazon-msk-express-brokers/"><strong>Deliver Apache Kafka data to streaming tables for Apache Iceberg with Amazon MSK Express brokers</strong></a> – Learn how to stream data from Apache Kafka into Apache Iceberg tables using Amazon MSK Express brokers, with throughput support of up to 10 GB/s for delivery to Apache Iceberg on Amazon S3 Tables.</li>
</ul><p><strong>Upcoming AWS events</strong></p><p>Check your calendar and sign up for upcoming AWS events:</p><ul><li><strong><a href="https://aws.amazon.com/events/summits/">AWS Summits</a></strong> – AWS Summits are free events that bring the cloud and AI community together to connect, learn, and explore the latest technologies. Browse the full calendar to find a Summit near you in the second half of 2026.</li>
<li><strong><a href="https://aws.amazon.com/developer/community/communitydays/">AWS Community Days</a></strong> – Community-led conferences where content is planned, sourced, and delivered by community leaders.</li>
</ul><p>Join the <a href="https://community.aws/">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development. Browse <a href="https://aws.amazon.com/events/">here</a> for upcoming AWS-led in-person and virtual events and developer-focused events.</p><hr /><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="ffb4abfa-c7ae-482e-ae4c-81c5155e59aa" data-title="AWS Weekly Roundup: Price reduction of GPT models in Bedrock, CloudWatch managed collectors for Prometheus metrics, and more (August 3, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-price-reduction-of-gpt-models-in-bedrock-cloudwatch-managed-collectors-for-prometheus-metrics-and-more-august-3-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-price-reduction-of-gpt-models-in-bedrock-cloudwatch-managed-collectors-for-prometheus-metrics-and-more-august-3-2026/"/>
    <updated>2026-08-03T18:12:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-july-27-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Local Zone in Athens, Claude Opus 5 on AWS, Lambda durable execution for .NET, and more (July 27, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><p>Last week I had the privilege of spending three days in São Paulo with technical builders from across Latin America, brought together for a regional tech event full of deep-dive sessions, hands-on workshops, and conversations with customers and partners. What struck me most wasn’t any single session, it was the energy of a technical community that so rarely gets to be in the same room. People traded architecture ideas over coffee, sketched out solutions on whiteboards, and left with a longer list of things to try than they arrived with. It’s a good reminder that, for all the tooling we build, the community around it is what makes the technology stick.</p><p>That community spirit connects nicely to the week’s biggest infrastructure news, which is all about bringing AWS closer to where builders actually are.</p><p><img class="aligncenter size-full wp-image-105128" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/07/24/eamm-summit-latam.jpg" alt="" width="1800" height="801" /></p><p>Now, let’s get into this week’s AWS news…</p><p><strong>Headlines</strong><br /><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-local-zone-athens-greece/">AWS Local Zone in Athens, Greece</a>: AWS has opened a new Local Zone in Athens, Greece, the second Local Zone in EMEA with support for Amazon S3 and Amazon EBS Local Snapshots, so you can store and process data within Greece to help meet local data residency requirements. The Athens Local Zone supports Amazon EC2 (C7i, M7i, and R7i instances), Amazon S3 with the One Zone-Infrequent Access storage class, Amazon EBS, and Amazon ECS.</p><p><img class="aligncenter size-full wp-image-613" src="https://d2908q01vomqb2.cloudfront.net/b74f5ee9461495ba5ca4c72a7108a23904c27a05/2026/07/16/AdobeStock_294008910-11-scaled.jpg" alt="Athens, Greece skyline" width="2560" height="846" /></p><p>AWS Local Zones place AWS infrastructure much closer to large population and industry hubs, enabling applications that require single-digit millisecond latency, such as real-time gaming, media production, and financial services, to run where end users actually are. For builders in Greece, you can now run latency-sensitive workloads locally while connecting seamlessly to the nearest AWS Region for services that don’t require low latency, giving you the flexibility to architect hybrid, latency-optimized applications without managing your own data center infrastructure. To learn more, visit <a href="https://aws.amazon.com/blogs/infrastructure-sustainability/now-open-aws-local-zones-in-athens-greece/">AWS Global Infrastructure and Sustainability Blog post</a>.</p><p><strong>Last week’s launches</strong><br />Here are some launches and updates from this past week that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/claude-opus-5-aws/">Claude Opus 5 on AWS</a>: You can use Anthropic’s Claude Opus 5, the most advanced Opus model yet, matching Claude Fable 5’s top-tier intelligence in many domains at Opus-tier pricing. Amazon Bedrock offers Claude Opus 5 with zero data retention (ZDR) enabled by default, giving you Opus’ top-tier intelligence while meeting your data governance requirements unlike Claude Fable 5. You have two ways to access Claude Opus 5: Amazon Bedrock and Claude Platform on AWS. To learn more, visit the <a href="https://aws.amazon.com/blogs/machine-learning/introducing-claude-opus-5-on-aws-anthropics-most-capable-opus-model/">deep dive blog post</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/lambdadf-dotnet/">AWS Lambda durable execution SDK for .NET is now generally available</a>: You can now build resilient, long-running workflows in C# using Lambda durable functions, without implementing custom progress tracking or integrating an external orchestration service. The SDK is a natural fit for multi-step applications like payment processing pipelines, AI agent orchestration, and human-in-the-loop approvals, it checkpoints progress automatically and can pause execution for up to a year. If you’re a .NET developer building serverless workflows, this removes a lot of the plumbing you used to write by hand.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-bedrock-agentcore-unified-observability-single-log-group/">Amazon Bedrock AgentCore now delivers unified observability with traces and logs in a single log group</a>: Amazon Bedrock AgentCore now delivers agent traces and prompts to the same Amazon CloudWatch log group as your agent’s logs. Previously, telemetry was split across destinations, trace spans went to a shared log group while prompts, inputs, and outputs went to a separate one, so debugging a single agent invocation meant searching in multiple places. You can now debug an invocation in one place, and apply fine-grained access control and customer-managed key (CMK) encryption at the individual agent level.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-connect-agentic-voice/">Amazon Connect delivers more natural agentic voice experiences</a>: Amazon Connect now supports more natural, human-sounding agentic voice experiences across 50+ languages, including Portuguese, Spanish, French, Italian, Japanese, Korean, and Thai, with over 100 new voice options and conversational improvements that make AI interactions sound more fluid. Connect’s agentic self-service lets AI agents understand, reason, and take action across voice and digital channels, adapting to a customer’s tone and sentiment. You can now build contact center experiences that feel natural to callers in far more of the languages your customers actually speak.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-sagemaker-unified/">Amazon SageMaker Unified Studio now supports Amazon OpenSearch</a>: You can now query and analyze your search and log analytics data from Amazon OpenSearch directly alongside other data assets in Amazon SageMaker Unified Studio. With this connection, you can combine operational search data in OpenSearch with data from sources like Amazon Redshift, Amazon S3, and relational databases, all within a single, governed environment. It’s especially useful when you need to correlate analytical and operational workloads, such as joining application logs with transactional data to uncover insights.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/cloudwatch-coding-agent-insights/">Amazon CloudWatch announces coding agent insights</a>: Amazon CloudWatch now gives engineering leaders visibility into how AI coding tools are driving value across their organization. Coding agent insights integrates with the Claude apps gateway for AWS to collect telemetry from Claude Code without additional instrumentation, and also supports agents like Codex and GitHub Copilot. As teams scale AI coding adoption, you can now measure the return on that investment with metrics built on OpenTelemetry, no custom instrumentation required.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong>Other AWS news</strong><br />Here are some additional posts and resources that you might find interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/machine-learning/evaluating-ai-agents-a-production-blueprint-with-strands-and-agentcore/">Evaluating AI Agents: A production blueprint with Strands and AgentCore</a>: A practical guide to evaluating AI agents before and after they reach production, using Strands Agents and Amazon Bedrock AgentCore. If you’re moving agents from prototype to production, this post is a great companion to the AgentCore observability update above, it walks through how to measure agent quality systematically rather than by gut feel.</li>
<li><a href="https://aws.amazon.com/blogs/architecture/building-multi-region-resiliency-for-aws-cloudformation-custom-resource-deployment/">Building multi-region resiliency for AWS CloudFormation custom resource deployment</a>: Learn how to architect CloudFormation custom resources for multi-region resiliency, so your infrastructure-as-code deployments stay reliable even when a single Region has issues.</li>
<li><a href="https://aws.amazon.com/blogs/messaging-and-targeting/introducing-amazon-simple-email-service-ses-pricing-plans/">Introducing Amazon Simple Email Service (SES) pricing plans</a>: Amazon SES now offers pricing plans that give you more predictable costs as your email volume grows. If you send at scale, this could simplify your billing significantly.</li>
</ul><p><strong>Upcoming AWS events</strong><br />Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/summits/">AWS Summits</a>: AWS Summits are free events that bring the cloud and AI community together to connect, learn, and explore the latest technologies. Browse the full calendar to find a Summit near you in the second half of 2026.</li>
<li><a href="https://aws.amazon.com/events/community-day/">AWS Community Days</a>: Community-led conferences where content is planned, sourced, and delivered by community leaders. If you’re in Latin America, don’t miss AWS Community Day Belo Horizonte on August 22, registration is open at <a href="https://awscommunityday.com.br/">awscommunityday.com.br</a>.</li>
</ul><p>Join the <a href="https://builder.aws.com/">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development. Browse <a href="https://aws.amazon.com/events/">here</a> for upcoming AWS-led in-person and virtual events and developer-focused events.</p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="64cc6fbd-f5da-4402-9cb1-d9482b0018ce" data-title="AWS Weekly Roundup: Local Zone in Athens, Claude Opus 5 on AWS, Lambda durable execution for .NET, and more (July 27, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-july-27-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-july-27-2026/"/>
    <updated>2026-07-27T16:54:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: One-click Lambda setup prompt, OpenAI GPT-5.6 models on Bedrock, and more (July 20, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Last week, my team visited Seoul to meet <a href="https://www.meetup.com/awskrug/">AWS Korea User Group (AWSKRUG)</a> leaders. AWSKRUG is the largest cloud developer community in Korea, with 20 meetup groups organized by topic and area that collectively host over 100 events each year, primarily in Seoul.</p><p>My team regularly visits countries across the Asia-Pacific region, listens to feedback from user group leaders, and works to support their communities. At this meeting, leaders honestly shared what they did well in the first half of the year, what needs improvement, and what they asked of AWS Developer Experience team. We also enjoyed a pleasant conversation during our <a href="https://en.wikipedia.org/wiki/Chimaek">Chimaek</a> time together.</p><p><img class="aligncenter size-full wp-image-105075" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/07/17/2026-aws-devex-awskrug.jpg" alt="" width="1800" height="991" /></p><p>Now, let’s take a closer look at key launches of last week.</p><p>A <a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-lambda-prompt-coding-agents/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">one-click Lambda setup prompt for coding agents</a> caught my eye most last week. This prompt configures your agent with AWS Serverless skills and the Serverless Model Context Protocol (MCP) server, embedding serverless best practices from the start. This prompt references the Lambda agent setup guide, which includes installation commands for Claude Code, Kiro, Cursor, GitHub Copilot, Codex, Devin Desktop, and OpenCode.</p><p>To get started, choose the <strong>Copy agent prompt</strong> button on the Lambda console screen or copy <code>fetch https://docs.aws.amazon.com/lambda/latest/dg/samples/aws-lambda-agent-setup.md</code> directly, and paste this URL in your preferred AI agent.</p><p><img class="aligncenter size-full wp-image-105071 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/07/17/2026-aws-lambda-oneclick.jpg" alt="" width="1800" height="1124" /></p><p>You can also use <a href="https://aws.amazon.com/products/developer-tools/agent-toolkit-for-aws/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Agent Toolkit for AWS</a> to give your coding agent current AWS knowledge and safe resource access. Use <code>fetch https://raw.githubusercontent.com/aws/agent-toolkit-for-aws/refs/heads/main/setup-instructions/setup.md</code> for installing AWS MCP Server.</p><p><strong>Last week’s launches</strong><br />Here are last week’s launches that caught my attention:</p><ul><li><a href="https://aws.amazon.com/blogs/machine-learning/openai-gpt-5-6-sol-terra-and-luna-are-now-generally-available-on-amazon-bedrock/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">OpenAI GPT-5.6 Sol, Terra, and Luna on Amazon Bedrock</a>: You can use the smartest family of models from OpenAI yet on Bedrock’s next-generation inference engine built for high performance, security, and reliability. The three models span capability tiers from flagship reasoning (Sol) to balanced performance (Terra) to fast, cost-efficient inference (Luna), all accessible through the Responses API on Amazon Bedrock.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/s3-removes-30-day-transitions-standard-ia-one-zone-ia/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Same-day transitions to Amazon S3 Standard-IA and S3 One Zone-IA</a>: You can now transition objects to S3 Standard-Infrequent Access (S3 Standard-IA) and S3 One Zone-Infrequent Access (S3 One Zone-IA) as soon as the day they are created, without the previous 30-day minimum retention period in S3 Standard. These storage classes offer up to 40% lower storage costs than S3 Standard while still providing millisecond access when needed, making them ideal for backups, log analytics, and compliance workloads where data becomes cold within hours or days.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/lambda-self-managed-code-storage/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Self-managed code storage on AWS Lambda</a>: With self-managed Amazon S3 buckets for code storage, you can reference source code directly from your own S3 buckets without Lambda creating intermediate copies. This eliminates code storage limits and reduces function activation time after function creates and updates by removing the copy step.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-cognito-password-hash-import/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Importing users with password hashes on Amazon Cognito</a>: You can now import users with password hashes in CSV user imports. Previously, imported users had to reset their passwords on first sign-in. Now, you can include password hashes in the CSV import, enabling users to sign in immediately with their existing credentials. When creating a CSV import, you specify the password hashing algorithm used by your source system.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">What’s New with AWS</a> page.</p><p><strong>Additional updates</strong><br />Here are some additional news items that you might find interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/aws/amazon-sqs-turns-20-two-decades-of-reliable-messaging-at-scale/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon SQS turns 20: Two decades of reliable messaging at scale</a>: When Amazon SQS launched publicly in July 2006, it made this pattern available to every AWS customer. Twenty years later, that core function, decoupling producers from consumers, remains the reason customers use SQS. Let’s look back important milestones after <a href="https://aws.amazon.com/blogs/aws/amazon-sqs-15-years-and-still-queueing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Jeff’s 15th anniversary post</a>.</li>
<li><a href="https://aws.amazon.com/blogs/opensource/open-protocols-with-the-strands-agents-sdk/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Open Protocols with the Strands Agents SDK</a>: Learn how open AI protocols such as MCP, A2A, UTCP, AG-UI, and x402 work together using Strands Agents SDK for building AI agents as an example implementation, though the patterns apply to any agent framework.</li>
<li><a href="https://aws.amazon.com/blogs/database/introducing-open-source-bulk-executor-for-amazon-dynamodb/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Open source Bulk Executor for Amazon DynamoDB</a>: Performing bulk operations against all items in a DynamoDB table has historically required custom coding. The <a href="https://github.com/awslabs/amazon-dynamodb-tools/tree/main/tools/bulk_executor">Bulk Executor for DynamoDB</a> simplifies bulk tasks like these. You can use this feature to invoke commands like <code>count</code>, <code>find</code>, <code>delete</code>, or <code>update</code>. No coding is required, even when running at large scale.</li>
<li><a href="https://aws.amazon.com/blogs/mt/transform-aws-support-case-workflows-with-kiro-cli/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Transform AWS Support Case Workflows with Kiro CLI</a>: Explore how Kiro CLI’s MCP integration accelerates support case workflows by combining investigation, documentation lookup, and case creation into a single conversational interface across three real-world scenarios: AWS Glue job failures, AWS Lambda cold start investigation, and AWS WAF false positive analysis.</li>
</ul><p>For a full list of AWS blog posts, be sure to keep an eye on the <a href="https://aws.amazon.com/blogs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Blogs</a> page.</p><p>Learn more about AWS, browse and join upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS-led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?tab=upcoming?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused events</a> including <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summits</a>. Join the <a href="https://builder.aws.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development.</p><p>Finally, some customers experienced an issue with <a href="https://health.aws.amazon.com/health/status?eventID=arn:aws:health:global::event/BILLING/AWS_BILLING_OPERATIONAL_ISSUE/AWS_BILLING_OPERATIONAL_ISSUE_47B68_BACBD91434F">Cost Explorer displaying inaccurate estimated billing data</a> in last weekend. They may have received erroneous budget and cost anomaly detection alerts, and observed inflated estimated cost and usage data. The issue has been resolved, and all AWS services are operating normally. We apologize for the concern this incident caused our customers and are conducting a thorough retrospective to prevent events like this from reoccurring, as well as improving our response when billing incidents occur. For more information, visit the <a href="https://health.aws.amazon.com/health/status?eventID=arn:aws:health:global::event/BILLING/AWS_BILLING_OPERATIONAL_ISSUE/AWS_BILLING_OPERATIONAL_ISSUE_47B68_BACBD91434F">AWS Health Dashboard</a>.</p><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Weekly Roundup</a>!</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="813ab749-1aca-4e22-9cfb-3cc53a5a144e" data-title="AWS Weekly Roundup: One-click Lambda setup prompt, OpenAI GPT-5.6 models on Bedrock, and more (July 20, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026/"/>
    <updated>2026-07-20T18:37:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-sqs-turns-20-two-decades-of-reliable-messaging-at-scale/</id>
    <title><![CDATA[Amazon SQS turns 20: Two decades of reliable messaging at scale]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>On July 13, 2006, we <a href="https://aws.amazon.com/blogs/aws/amazon_simple_q/">launched</a> <a href="https://aws.amazon.com/sqs/">Amazon Simple Queue Service (Amazon SQS)</a> as one of the first three services available to customers, alongside <a href="https://aws.amazon.com/blogs/aws/amazon_ec2_beta/">Amazon EC2</a> and <a href="https://aws.amazon.com/blogs/aws/amazon_s3/">Amazon S3</a>. We had learned firsthand that distributed systems need a reliable way to pass messages between components without creating tight dependencies. If one service called another directly and that service was slow or unavailable, failures cascaded through the entire system. Message queuing solved this by letting services communicate asynchronously: a producer could drop a message into a queue and move on, while a consumer picked it up when ready. This approach kept individual service failures from affecting the rest of the system.</p><p>When Amazon SQS launched publicly in July 2006, it made this pattern available to every AWS customer. Twenty years later, that core function, decoupling producers from consumers, remains the reason customers use SQS. The scale, performance, and operational controls around it look very different now though.</p><p><a href="https://aws.amazon.com/blogs/aws/author/jbarr/">Jeff Barr</a> covered the first 15 years of SQS milestones in his <a href="https://aws.amazon.com/blogs/aws/amazon-sqs-15-years-and-still-queueing/">15th anniversary post</a>, from the original 8 KB message limit in 2006 through FIFO queues, server-side encryption, and Lambda integration. Over the last five years, we have continued to scale SQS, added stronger security defaults, and introduced new capabilities that address increasingly complex workload patterns.</p><p><strong>Key milestones between 2021 and 2026</strong><br /><strong>High throughput mode for FIFO queues (2021):</strong> In <a href="https://aws.amazon.com/about-aws/whats-new/2021/05/amazon-sqs-now-supports-a-high-throughput-mode-for-fifo-queues/">May 2021</a>, we launched general availability of high throughput mode for FIFO queues, supporting up to 3,000 transactions per second (TPS) per API action, a tenfold increase over the previous limit. We continued raising this ceiling over the following two years: to 6,000 TPS in <a href="https://aws.amazon.com/about-aws/whats-new/2022/10/amazon-sqs-increased-throughput-quota-fifo-high-throughput-ht-mode-6000-transactions-per-second-tps/">October 2022</a>, to 9,000 TPS in <a href="https://aws.amazon.com/about-aws/whats-new/2023/08/amazon-sqs-increased-throughput-quota-fifo-high-throughput-mode/">August 2023</a>, and to 18,000 TPS in <a href="https://aws.amazon.com/about-aws/whats-new/2023/10/amazon-sqs-increased-throughput-quota-fifo-high-throughput-mode/">October 2023</a>, before reaching 70,000 TPS per API action in select Regions by <a href="https://aws.amazon.com/about-aws/whats-new/2023/11/amazon-sqs-throughput-quota-fifo-high-throughput-mode/">November 2023</a>.</p><p><strong>Server-side encryption with SSE-SQS (2021):</strong> In <a href="https://aws.amazon.com/about-aws/whats-new/2021/11/amazon-sqs-server-side-encryption-keys-sse/">November 2021</a>, we introduced server-side encryption with Amazon SQS-managed encryption keys (SSE-SQS), giving customers an encryption option that required no key management. In <a href="https://aws.amazon.com/about-aws/whats-new/2022/10/amazon-sqs-announces-server-side-encryption-ssq-managed-sse-sqs-default/">October 2022</a>, we made SSE-SQS the default for all newly created queues, so customers no longer needed to explicitly enable it.</p><p><strong>Dead-letter queue redrive enhancements (2021):</strong> We progressively expanded how customers recover unconsumed messages from dead-letter queues. In <a href="https://aws.amazon.com/about-aws/whats-new/2021/12/amazon-sqs-dead-letter-queue-management-experience-queues/">December 2021</a>, we added DLQ redrive to source queue directly in the SQS console. In <a href="https://aws.amazon.com/about-aws/whats-new/2023/06/amazon-sqs-dead-letter-queue-redrive-aws-sdk-cli/">June 2023</a>, we extended this capability to the AWS SDK and CLI through new APIs, including <code>StartMessageMoveTask</code>, <code>CancelMessageMoveTask</code>, and <code>ListMessageMoveTasks</code>. In <a href="https://aws.amazon.com/about-aws/whats-new/2023/11/amazon-sqs-fifo-dead-letter-queue-redrive/">November 2023</a>, we added redrive support for FIFO queues.</p><p><strong>Attribute-based access control, ABAC (2022):</strong> In <a href="https://aws.amazon.com/about-aws/whats-new/2022/11/amazon-sqs-attribute-based-access-control-abac-flexible-scalable-access-permissions/">November 2022</a>, we introduced ABAC, giving customers the ability to configure access permissions based on queue tags rather than maintaining static policies as resources scaled.</p><p><strong>JSON protocol support (2023):</strong> In <a href="https://aws.amazon.com/about-aws/whats-new/2023/11/amazon-sqs-support-json-protocol/">November 2023</a>, we added support for the JSON protocol in the AWS SDK, reducing end-to-end message processing latency by up to 23% for a 5 KB payload and lowering client-side CPU and memory usage.</p><p><strong>Amazon EventBridge Pipes console integration (2023):</strong> We <a href="https://aws.amazon.com/about-aws/whats-new/2023/11/amazon-sqs-eventbridge-pipes-console-integration/">added</a> the ability to connect a queue directly to EventBridge Pipes from the SQS console, routing messages to a broad range of AWS service targets without writing custom integration code.</p><p><strong>Extended Client Library for Python (2024):</strong> We <a href="https://aws.amazon.com/about-aws/whats-new/2024/02/amazon-sqs-extended-client-library-python-payloads/">brought</a> the Extended Client Library, previously available for Java, to Python developers, allowing messages up to 2 GB to be sent through SQS by storing the payload in Amazon S3 and passing a reference through the queue.</p><p><strong>FIFO in-flight message limit increase (2024):</strong> We <a href="https://aws.amazon.com/about-aws/whats-new/2024/11/amazon-sqs-increases-in-flight-limit-fifo-queues/">increased</a> the in-flight message limit for FIFO queues from 20,000 to 120,000 messages, so consumers can process significantly more messages concurrently without being constrained by the previous ceiling.</p><p><strong>Fair queues for multi-tenant workloads (2025):</strong> We <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/amazon-sqs-introduces-fair/">introduced</a> fair queues to mitigate the noisy neighbor problem in multi-tenant standard queues. By including a message group ID when sending messages, customers can prevent a single tenant from delaying message delivery for others, without any changes required on the consumer side.</p><p><strong>1 MiB maximum message payload size (2025):</strong> We <a href="https://aws.amazon.com/about-aws/whats-new/2025/08/amazon-sqs-max-payload-size-1mib/">increased</a> the maximum message payload from 256 KiB to 1 MiB for both standard and FIFO queues, helping customers send larger messages without offloading data to external storage. AWS Lambda event source mapping for SQS was updated in parallel to support the new payload size.</p><p><strong>The constant underneath the change</strong><br />Despite two decades of feature additions, the fundamental use case for SQS has not shifted. Customers use it to decouple services, buffer bursts of traffic, and build systems that stay resilient when individual components fail. That same pattern now extends to AI workloads. Customers use SQS queues to buffer requests to large language models, manage inference throughput, and coordinate communication between autonomous AI agents operating as independent services. For an example of this architecture in practice, read <a href="https://aws.amazon.com/blogs/machine-learning/creating-asynchronous-ai-agents-with-amazon-bedrock/">Creating asynchronous AI agents with Amazon Bedrock</a>.</p><p>To learn more about Amazon SQS, visit the <a href="https://aws.amazon.com/sqs/">Amazon SQS product page</a>, review the <a href="https://docs.aws.amazon.com/AWSSimpleQueueService/latest/SQSDeveloperGuide/welcome.html">developer guide</a>, or explore recent updates on the <a href="https://aws.amazon.com/blogs/compute/category/messaging/amazon-simple-queue-service-sqs/">AWS Blogs</a>.</p><a href="https://www.linkedin.com/in/esrakayabali/">— Esra</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="7e3e9d31-6c85-4093-9537-12ecf7ba201d" data-title="Amazon SQS turns 20: Two decades of reliable messaging at scale" data-url="https://aws.amazon.com/blogs/aws/amazon-sqs-turns-20-two-decades-of-reliable-messaging-at-scale/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-sqs-turns-20-two-decades-of-reliable-messaging-at-scale/"/>
    <updated>2026-07-13T20:13:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-builder-center-at-one-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: AWS Builder Center at 1 year, Network Scanning in Security Hub, Loom for AWS, and more (July 13, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>AWS Builder Center turned one year old last week. Launched on July 9, 2025, the platform has grown from a community hub with Wishlist voting, community profiles, and a toolbox into a full ecosystem with sandbox environments, workshops, Spaces, and a Builders’ Library. To mark the anniversary, Rick Suttles published <a href="https://builder.aws.com/content/3Fvjc3PRHRAbHM4Oa6hT1zogA4t/aws-builder-center-1-year-icymi">a full feature timeline</a> covering everything shipped over the past year: AWS Capabilities by Region (1,500+ services across 37 Regions), Spaces for community-created groups, workshops with category and complexity filters, badges and streaks, article series, view counts, saved items, student status, availability notifications, sign-in with GitHub and Amazon, and sandbox environments.</p><p><img class="alignnone size-full wp-image-105048" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/07/13/1215504668303320.png" alt="" width="1200" height="655" /></p><p>Jeff Barr published <a href="https://builder.aws.com/content/3GFcM59UkfV8HGO8IlMqlkZr8tV/aws-builder-center-the-first-year">a retrospective</a> summarizing Builder Center’s first year. Since launch, 5,548 authors have published 6,448 articles with more than 10.4 million page views combined. Builders have earned 99,226 badges since the badge system launched in March 2026. Community members have submitted 565 wishes, 10 of which have shipped with another 20 on the near-term roadmap.</p><p>The top community article <a href="https://builder.aws.com/content/3EBFSHQD6b0TBD6hJnOM8h5p1B3/building-an-aws-study-buddy-with-mcp-strands-agents-sdk">Building an AWS Study Buddy with MCP + Strands Agents SDK</a> by Dineshraj Dhanapathy reached 50,000+ views. Chris Miller’s <a href="https://builder.aws.com/content/3DrwRkoYtd7StDyVvIOg0ECKXmR/migrating-an-eol-linux-server-to-aws-in-8-hours-with-kiro">Migrating an EOL Linux Server to AWS in 8 Hours with Kiro</a> followed at 45,000+, and Yash Aggarwal’s <a href="https://builder.aws.com/content/39l2TayUzpddaEpCePLFw8Vt7Vl/aideas-neurovoice-multimodal-ai-for-early-screening-of-neurological-diseases">AIdeas: NeuroVoice – Multimodal AI for Early Screening of Neurological Diseases</a> article reached 38,000+.</p><p>The week’s headline addition is <a href="https://builder.aws.com/content/3GCjkXGc1Qrs5jGsWI5fkTLNWzU/introducing-sandbox-environments-on-aws-builder-center">Sandbox Environments</a> by Rick Suttles. Sandboxes give you a free, pre-provisioned AWS account to complete a workshop exercise. Each environment is active for 8 hours, after which the account and all its resources are automatically de-provisioned. You can have one active sandbox at a time and request one per week. No personal AWS account, credit card, or manual cleanup required.</p><p><strong>Last week’s launches<br /></strong> Here’s what else happened this week.</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/aws-security-hub-network-scanning/">AWS Security Hub introduces Network Scanning</a> – Security Hub introduced Network Scanning, a capability that identifies resources in your environment that are reachable from the public internet. Network Scanning probes your resources from the internet to detect actual reachability, complementing the existing network reachability findings in Security Hub that identify configurations that could make a resource reachable. It discovers public IP addresses, virtual machines, and load balancers across your AWS and Azure environments, identifies reachable ports, and determines what services are running behind them. Each reachable port generates a Security Hub finding with evidence of the port and service discovered. Security Hub Exposures then automatically correlates these findings with other findings and resource configurations to determine broader risk. Existing customers can enable Network Scanning in individual accounts and Regions, or across an organization through a configuration policy. For new customers, Network Scanning is on by default. It is included with Security Hub Essentials at no additional cost.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-security-hub-supports-monitoring-microsoft-azure/">Security Hub also extends unified security management to Microsoft Azure</a> – Security Hub now monitors Microsoft Azure resources, providing unified posture management, vulnerability management, and security response across both clouds. It automatically discovers Azure VMs, container images, Function Apps, and identities, and evaluates them for misconfigurations, internet exposure, and software vulnerabilities. AWS and Azure findings appear in the same prioritized view with the same formats and automation workflows.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/sagemaker-studio-hugging-face-integration/">Amazon SageMaker Studio integrates with Hugging Face for one-click model deployment and customization</a> – You can now go from discovering a model on Hugging Face to working with it in SageMaker Studio in a single click. Select any supported model on Hugging Face and choose “Customize on SageMaker AI” or “Deploy on SageMaker AI” to land directly on the corresponding workflow page with the model pre-loaded. New customers receive a Studio environment created in seconds with pre-configured permissions for serverless model customization (including fine-tuning with custom reward functions for reinforcement learning), model evaluation, and deployment to SageMaker or Bedrock endpoints. Verified customers receive default GPU access to G5, G6, and G4dn instances without requesting quota increases, and quota utilization is visible directly inside the Studio environment.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-ecs-managed-instances-gpu-price/">Amazon EKS Auto Mode and Amazon ECS Managed Instances reduce GPU management fees by up to 60%</a> – Beginning July 1, 2026, EKS Auto Mode and ECS Managed Instances reduce management fees for accelerated instance types: G-series fees are down 35%, and P-series and AWS Trainium fees are down 60%. The reductions apply automatically to existing clusters and require no action from customers. Both services include capabilities built for accelerated workloads. EKS Auto Mode provides automatic parallel image pulling on GPU instances with local NVMe storage and accelerator-aware node repair. ECS Managed Instances provides GPU metrics through Amazon CloudWatch Container Insights and automatic health monitoring for GPU hardware failures.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-aurora-dsql-cdc-ga/">Amazon Aurora DSQL change data capture (CDC) is now generally available</a> – Aurora DSQL CDC streams the results of insert, update, and delete operations as change events to Amazon Kinesis Data Streams. You can use it to synchronize data across microservices, trigger Lambda functions, or deliver changes to S3, Redshift, and OpenSearch Service through Amazon Data Firehose. CDC streaming is designed to have zero impact on database workload performance and requires no infrastructure to manage.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong>Other AWS news<br /></strong> Here are some additional posts you may find useful:</p><ul><li><a href="https://aws.amazon.com/blogs/opensource/building-secure-ai-agents-at-scale-introducing-loom-for-aws/">Building secure AI agents at scale: Introducing Loom for AWS</a> – Loom is an open-source enterprise platform for building agents with AWS Strands Agents and deploying them on Amazon Bedrock AgentCore Runtime. It provides a unified management UI and backend API with identity provider integration, scope-based authorization, multi-persona navigation, and full lifecycle management for agents, memory, MCP servers, and agent-to-agent integrations. Loom enforces automated resource tagging for cost attribution, implements RBAC and ABAC for multi-tenant security, uses paved-path blueprints for agent deployments, manages identity propagation through delegated actor chains, integrates with AWS Agent Registry for discovery and governance, and supports human-in-the-loop review before sensitive actions. The project is available in AWS Labs on GitHub.</li>
<li><a href="https://aws.amazon.com/blogs/machine-learning/introducing-claude-apps-gateway-for-aws/">Introducing Claude apps gateway for AWS</a> – The Claude apps gateway is a self-hosted control plane that gives organizations centralized control over access, cost, and policy for Claude Code and Claude Desktop. It connects to any OIDC-compliant identity provider, enforces managed settings on every request, routes inference to Amazon Bedrock or Claude Platform on AWS, and supports per-user and per-group spend caps. The gateway runs as a stateless container in your private network, backed by a PostgreSQL database for short-lived sign-in state. No long-lived secrets are stored on developer machines. Deploy it through Amazon Bedrock to keep data within the AWS security boundary, or through Claude Platform on AWS for the native Claude platform experience.</li>
<li><a href="https://aws.amazon.com/blogs/security/introducing-oauth-support-for-aws-mcp-server/">Introducing OAuth support for AWS MCP Server</a> – You can now connect agents to the AWS MCP Server using browser-based OAuth with the same credentials you use for the AWS Console or CLI. The new sign-in path supports IAM federation, AWS IAM Identity Center, and root or IAM users. AWS Sign-In issues short-lived access tokens and refresh tokens, with automatic token management so developers stay authenticated across restarts. For headless use cases, a non-interactive flow lets applications with existing AWS credentials obtain OAuth access tokens through the <code>create-oauth2-token-with-iam</code> API. New governance controls include OAuth-specific IAM condition keys, token introspection and revocation, dynamic client registration, and CloudTrail audit elements.</li>
</ul><p>For a full list of AWS blog posts, be sure to keep an eye on the <a href="https://aws.amazon.com/blogs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Blogs</a> page.</p><p><strong>Upcoming AWS events</strong><br />Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/summits/">AWS Summits</a> – Free in-person events for builders and innovators to learn, think big, and make new connections. Coming up: <a href="https://aws.amazon.com/tw/events/summits/taipei/">Taipei</a> (July 15), <a href="https://aws.amazon.com/es/events/summits/bogota/">Bogotá</a> (July 30), <a href="https://aws.amazon.com/id/events/summits/jakarta/">Jakarta</a> (August 6), <a href="https://aws.amazon.com/es/events/summits/mexico-city/">Ciudad de México</a> (August 12), <a href="https://aws.amazon.com/events/summits/johannesburg/">Johannesburg</a> (August 19), and <a href="https://aws.amazon.com/events/summits/zurich/">Zurich</a> (September 2).</li>
<li><a href="https://aws.amazon.com/events/community-day/">AWS Community Days</a> – Community-led conferences planned and delivered by community leaders. Upcoming events include <a href="https://communityday.awscmr.com/en">Yaoundé, Cameroon</a> (July 25), <a href="https://awsahmedabad.community/">Ahmedabad, India</a> (July 25), <a href="https://awscommunityday.com.br/">Belo Horizonte, Brazil</a> (August 22), <a href="https://awscommunityday.ca/">Ottawa, Canada</a> (August 22), <a href="https://awsdaytulsa.com/">Tulsa, USA</a> (August 22), and <a href="https://awsday.ca/?city=toronto">Toronto, Canada</a> (August 29).</li>
</ul><p>Visit the <a href="https://builder.aws.com/">AWS Builder Center</a> to meet other builders, contribute solutions, and find resources that help you keep building.</p><p>Wishing everyone a restful and enjoyable summer. Whether you’re building, learning, or recharging, I hope you find time for all three. I’ll be heading to Scandinavia for a few weeks to trade the heat for some cooler weather and longer evenings. Come back next week for more news!</p><a href="https://www.linkedin.com/in/esrakayabali/">— Esra</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="9b59f6b0-ffca-4815-942e-51113d3aa423" data-title="AWS Weekly Roundup: AWS Builder Center at 1 year, Network Scanning in Security Hub, Loom for AWS, and more (July 13, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-builder-center-at-one-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-builder-center-at-one-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/"/>
    <updated>2026-07-13T18:18:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-sonnet-5-on-aws-amazon-workspaces-for-ai-agents-aws-service-availability-updates-and-more-july-6-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Claude Sonnet 5 on AWS, Amazon WorkSpaces for AI agents, AWS service availability updates, and more (July 6, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>A couple of editions ago I wrote about what I find so energizing about working with startups. Last week I got a fresh dose of it: I spent a few days with the AWS Startups team, listening to stories of founders talking about the problems they’re actually solving. One story that stayed with me came from Marco Negreiros, founder of <a href="https://www.eyecarehealth.com.br/">EyeCare Health</a>, a Brazilian healthtech expanding access to eye care. He shared a striking fact: more than 70% of Brazilian municipalities don’t have a single ophthalmologist. His answer was to put a vision test on the one device almost everyone already carries, the smartphone, so a basic eye screening no longer depends on living near a clinic. Watching a founder turn a gap that big into something that concrete is exactly why I love this space.</p><p><img class="aligncenter size-full wp-image-104987 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/07/03/GetTogether_1540.jpg" alt="AWS Startups team get-together with founders in Brazil" width="1540" height="1026" /></p><p>This week, I’ll take a closer look at some key launches, and then cover the quarterly AWS Service Availability updates.</p><p><strong>Last week’s launches</strong><br />Here are some of the launches covered from this past week in the AWS News Blog:</p><ul><li><a href="https://aws.amazon.com/blogs/aws/amazon-ec2-c9g-and-c9gd-instances-powered-by-aws-graviton5-processors-are-now-available/">Amazon EC2 C9g and C9gd instances powered by AWS Graviton5 processors</a>: They deliver up to 25% better compute performance than Graviton4-based instances, 5x larger cache, fastest memory of any processor instances in the cloud, and local NVMe storage options (C9gd).</li>
<li><a href="https://aws.amazon.com/blogs/aws/accelerate-your-infrastructure-deployments-by-up-to-4x-with-aws-cloudformation-express-mode/">A new AWS CloudFormation Express mode</a>: You can speed up infrastructure deployment with AWS CloudFormation Express mode, enabling AI agents and developers to receive deployment confirmation in seconds and iterate faster. Available in all commercial Regions at no additional cost.</li>
<li><a href="https://aws.amazon.com/blogs/aws/upgrade-amazon-eks-clusters-with-confidence-using-kubernetes-version-rollbacks/">Upgrade Amazon EKS clusters with confidence using Kubernetes version rollbacks</a>: Learn how Kubernetes version rollbacks for Amazon EKS let you reverse cluster upgrades within seven days. This new feature provides a safety net for upgrade failures, no cluster rebuilds required, turning Kubernetes version upgrades into a reversible, low-risk operation.</li>
<li><a href="https://aws.amazon.com/blogs/aws/automate-public-tls-certificate-issuance-with-acme-support-in-aws-certificate-manager/">Automate public TLS certificate issuance with ACME support in AWS Certificate Manager</a>: AWS Certificate Manager now supports the ACME protocol, so you can automate the issuance and renewal of public TLS certificates using standard, widely adopted tooling.</li>
</ul><p>Here are some launches and updates that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/claude-sonnet-5-now-available-on-aws">Claude Sonnet 5 is now available on AWS</a> – Anthropic’s most capable Sonnet model brings top-tier intelligence at Sonnet pricing for coding, agents, and everyday professional work at scale. It navigates large codebases, calls tools precisely, and holds state across long agentic tasks. To learn more, visit the <a href="https://aws.amazon.com/blogs/machine-learning/introducing-claude-sonnet-5-on-aws-anthropics-most-capable-sonnet-model/">AI Blog post</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-workspaces-ai/">Amazon WorkSpaces for AI agents is now generally available</a>: AI agents can now securely access and operate desktop applications through managed WorkSpaces environments, without requiring application modernization or custom integrations. To learn more. visit the <a href="https://aws.amazon.com/blogs/desktop-and-application-streaming/amazon-workspaces-now-lets-ai-agents-operate-desktop-applications/">Desktop and Application Streaming Blog post</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-opensearch-service-optimized-log-analytics">Amazon OpenSearch Service is now optimized for log analytics</a>: This release introduces a new engine purpose-built for log analytics workloads that delivers up to 4x better price-performance on internal benchmarks, while keeping the full-text search capabilities OpenSearch is known for. Teams can now get aggregations and precise text search in one place. To learn more, visit the <a href="https://aws.amazon.com/blogs/big-data/run-log-analytics-for-a-fraction-of-the-cost-with-the-new-engine-for-amazon-opensearch-service/">Big Data Blog post</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/sagemakerai-inf-scale-out-time">Amazon SageMaker AI cuts generative AI inference scale-out time by up to half</a>: SageMaker Inference now supports container image caching, enabling up to 2x faster end-to-end scaling for generative AI models during scale-out events. To learn more, visit the <a href="https://aws.amazon.com/blogs/machine-learning/introducing-container-caching-in-amazon-sagemaker-ai-for-faster-model-scaling/?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">AI Blog post</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-cloudwatch-log-alarms/">Amazon CloudWatch supports creating alarms from log queries</a> : You can now create alarms directly on log query results and set thresholds in a single workflow, eliminating the need to first create metric filters or custom metrics as intermediate steps.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong>AWS Service Availability Updates</strong><br />When the availability of an AWS service or feature changes, we provide customers guidance in <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-service-availability/">AWS Product Lifecycle Changes</a> on available alternatives and support for migration so that disruptions to your operations are minimized. The following lifecycle changes were updated on June 30, 2026.</p><p>Services moving to Maintenance (no longer accessible to new customers starting July 30, 2026):</p><ul><li><a href="https://docs.aws.amazon.com/bedrock/latest/userguide/agents-classic-maintenance-mode.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Amazon Bedrock Agents (launched November 2023) is now Amazon Bedrock Agents Classic</a></li>
<li><a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-sync-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Amazon Cognito Sync</a></li>
<li><a href="https://docs.aws.amazon.com/kendra/latest/dg/kendra-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Amazon Kendra</a></li>
<li><a href="https://docs.aws.amazon.com/amazonq/latest/qbusiness-ug/qbusiness-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Amazon Q Business</a></li>
<li><a href="https://docs.aws.amazon.com/directoryservice/latest/admin-guide/simple-ad-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">AWS Directory Service – Simple AD</a></li>
<li><a href="https://docs.aws.amazon.com/iot-device-defender/latest/devguide/dd-detect-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">AWS IoT Device Defender – Detect</a> (feature will no longer be accessible to new customers starting August 31, 2026)</li>
<li><a href="https://docs.aws.amazon.com/managedservices/latest/userguide/SunsetPlan?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">AWS Mainframe Modernization – Self-Managed Experience</a></li>
<li><a href="https://docs.aws.amazon.com/awsconsolehelpdocs/latest/gsg/aws-myApplications-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">AWS Management Console – myApplications</a></li>
<li><a href="https://docs.aws.amazon.com/console/ARG/latest/userguide/resource-groups-gle-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">AWS Resource Groups – Group Lifecycle Events</a></li>
<li><a href="https://docs.aws.amazon.com/servicecatalog/latest/arguide/app-registry-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">AWS Service Catalog – Application Registry</a></li>
<li><a href="https://docs.aws.amazon.com/systems-manager/latest/userguide/application-manager-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">AWS Systems Manager – Application Manager</a></li>
<li>Amazon SageMaker AI features: <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/a2i-use-augmented-ai-a2i-human-review-loops.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">A2I</a>, <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/clarify-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Clarify</a>, <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/model-debugger-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Debugger</a>, <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/geospatial.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">GeoSpatial</a>, <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/sms.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Ground Truth</a>, <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/sms-workforce-management-public.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Mechanical Turk</a>, <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/model-monitor-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Model Monitor</a>, <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/role-manager-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Role Manager</a>, and <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/studio-lab-availability-change.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">Studio Lab</a></li>
</ul><p>Services entering Sunset:</p><p>Services reaching End of Support (as of June 30, 2026):</p><ul><li>Amazon Chime SDK – Carrier Voice Focus</li>
<li>Amazon SageMaker AI – Ground Truth Plus</li>
</ul><p>We understand that changes in availability can impact your operations. For specific guidance, consult the relevant service documentation or contact AWS Support.</p><p><strong>Upcoming AWS events</strong><br />Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/summits/">AWS Summits</a> – AWS Summits are free events that bring the cloud and AI community together to connect, learn, and explore the latest technologies. Browse the full calendar to find a Summit near you in the second half of 2026.</li>
<li><a href="https://builder.aws.com/">AWS Community Days</a> – Community-led conferences where content is planned, sourced, and delivered by community leaders. If you’re in Latin America, don’t miss AWS Community Day Belo Horizonte on August 22. Registration is open at <a href="https://awscommunityday.com.br/">awscommunityday.com.br</a>.</li>
</ul><p>Join the <a href="https://builder.aws.com/">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development. Browse <a href="https://aws.amazon.com/events/">here</a> for upcoming AWS-led in-person and virtual events and developer-focused events.</p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><p>– Daniel Abib</p><p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="e8060a2c-eb98-4c4f-83c9-587086863287" data-title="AWS Weekly Roundup: Claude Sonnet 5 on AWS, Amazon WorkSpaces for AI agents, AWS service availability updates, and more (July 6, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-sonnet-5-on-aws-amazon-workspaces-for-ai-agents-aws-service-availability-updates-and-more-july-6-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-sonnet-5-on-aws-amazon-workspaces-for-ai-agents-aws-service-availability-updates-and-more-july-6-2026/"/>
    <updated>2026-07-06T17:46:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/upgrade-amazon-eks-clusters-with-confidence-using-kubernetes-version-rollbacks/</id>
    <title><![CDATA[Upgrade Amazon EKS clusters with confidence using Kubernetes version rollbacks]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Upgrading a <a href="https://kubernetes.io/">Kubernetes</a> control plane has long been a one way door. Open source Kubernetes doesn’t support control plane rollback, so once you upgrade, there’s no going back. The community is making real progress here, and <a href="https://github.com/kubernetes/enhancements/issues/4330">KEP-4330</a> introduces emulated versions to ease rollback. But in practice this constraint has pushed organizations to build elaborate compensating mechanisms like bake periods, stagger groups, automated sign offs, and months long upgrade cycles. With Kubernetes releasing three minor versions per year, teams managing hundreds of clusters, especially in regulated environments, often delay upgrades entirely because they aren’t confident they can recover if something goes wrong. The result is clusters stuck on older versions, missing security patches, and eventually running up against extended support timelines.</p><p>Today, we’re announcing Kubernetes <a href="https://docs.aws.amazon.com/eks/latest/userguide/rollback-cluster.html">version rollbacks</a> for <a href="https://aws.amazon.com/eks/">Amazon Elastic Kubernetes Service (Amazon EKS)</a>, a new feature that gives cluster administrators a safety net when performing cluster upgrades. With version rollbacks, you can reverse a Kubernetes version upgrade within seven days if you encounter issues after upgrading, returning your cluster to its previous working state.</p><p>Where approaches like emulated versions keep a cluster in a transitional holding state, EKS version rollback returns your cluster to a fully validated previous version that ran in production, not an emulation of it. Now, if you upgrade a cluster from, say, Kubernetes 1.34 to 1.35 and discover a compatibility issue, you can roll back to 1.34 within seven days. There’s no need to rebuild your cluster or scramble to troubleshoot under pressure. Think of it as an undo button for Kubernetes version upgrades.</p><p>The feature supports rolling back one minor version at a time, matching the same incremental approach EKS uses for upgrades. And to help you roll back safely, EKS automatically evaluates your cluster’s rollback readiness through <a href="https://docs.aws.amazon.com/eks/latest/userguide/cluster-insights.html">cluster insights</a>, flagging items like node version compatibility or add-on dependencies before you proceed. If you’ve already assessed the situation and want to move quickly, you can use the <code>--force</code> flag to bypass those checks. The above applies to all EKS clusters, whether you manage your own nodes or let AWS handle them. But for customers who have embraced fully managed infrastructure, rollback goes a step further.</p><p><strong>Rollback for EKS Auto Mode</strong><br /><a href="https://docs.aws.amazon.com/eks/latest/userguide/automode.html">EKS Auto Mode</a> gives you one click deployment of production ready Kubernetes clusters, automating compute, networking, and storage management so you can focus on your applications rather than infrastructure. EKS Auto Mode introduces additional considerations for <a href="https://docs.aws.amazon.com/eks/latest/userguide/rollback-automode.html">version rollbacks</a> because both the control plane and managed nodes need to be rolled back together. Since node rollbacks respect your pod disruption budgets, the process can take time depending on your configuration.</p><p>To give you control over this process, we’ve introduced a <a href="https://docs.aws.amazon.com/eks/latest/userguide/rollback-automode.html#automode-cancel-rollback"><strong>cancel API</strong></a> that lets you stop a node rollback at any point. If you decide the rollback is taking too long or you want to change your approach, you can cancel and adjust your disruption budgets to accelerate things, or choose a different path forward.</p><p>By default, EKS never bypasses your disruption budgets during a rollback because we prioritize workload stability. You can always choose to modify or remove disruption budgets yourself to speed up the process if needed.</p><p><strong>Let’s try it out</strong><br />To try version rollbacks, I navigated to the Amazon EKS console and selected one of my clusters that I had recently upgraded.</p><p><img class="alignnone size-large wp-image-104900" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/27/eks-image-01-1024x382.png" alt="" width="1024" height="382" /></p><p>From the cluster’s configuration page, I can see the option to initiate a version rollback, along with information about my current rollback window.</p><p><img class="alignnone size-large wp-image-104901" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/27/eks-image-02-1024x507.png" alt="" width="1024" height="507" /></p><p>Before initiating the rollback, I reviewed the rollback insights to check for any potential issues. The insights showed me the status of my nodes and flagged anything I should address before proceeding.</p><p><img class="alignnone size-large wp-image-104902" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/27/eks-image-03-1024x718.png" alt="" width="1024" height="718" /></p><p>After confirming, the rollback began. My cluster remained functional throughout the process. The control plane rollback took about 20 minutes, similar to a standard upgrade. For my EKS Auto Mode cluster, the nodes rolled back gracefully according to my disruption budget settings.</p><p><img class="alignnone size-large wp-image-104903" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/27/eks-image-04-1024x557.png" alt="" width="1024" height="557" /></p><p>Once complete, my cluster was back on the previous Kubernetes version, running as expected.</p><p><strong>Now available</strong><br />Kubernetes <a href="https://docs.aws.amazon.com/eks/latest/userguide/rollback-cluster.html">version rollbacks</a> for Amazon EKS are available today at no additional cost in all commercial AWS Regions where Amazon EKS is available. You pay only for the standard EKS and compute costs you would normally incur. There are no extra charges for using the rollback capability.</p><p>Control plane rollbacks are available for all EKS clusters, and node rollbacks are available for clusters running EKS Auto Mode. Version rollbacks support clusters running Kubernetes versions available in EKS standard support and extended support.</p><p>To get started, visit the <a href="https://docs.aws.amazon.com/eks/latest/userguide/">Amazon EKS documentation</a> or try it out directly in the <a href="https://console.aws.amazon.com/eks/">Amazon EKS console</a>.</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="47605433-59bb-4723-bab6-ce5a5498b845" data-title="Upgrade Amazon EKS clusters with confidence using Kubernetes version rollbacks" data-url="https://aws.amazon.com/blogs/aws/upgrade-amazon-eks-clusters-with-confidence-using-kubernetes-version-rollbacks/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/upgrade-amazon-eks-clusters-with-confidence-using-kubernetes-version-rollbacks/"/>
    <updated>2026-07-01T19:20:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/accelerate-your-infrastructure-deployments-by-up-to-4x-with-aws-cloudformation-express-mode/</id>
    <title><![CDATA[Accelerate your infrastructure deployments by up to 4x with AWS CloudFormation Express mode]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing <a href="https://aws.amazon.com/cloudformation/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS CloudFormation</a> Express mode, a new deployment mode that accelerates deployments for developers and AI tools iterating on infrastructure. Express mode accelerates deployments by completing when CloudFormation confirms resource configuration is applied, rather than waiting for extended stabilization checks. This reduces deployment time by up to 4 times for iterative development workflows and production scenarios.</p><p><strong class="c6">How it works</strong><br />Every CloudFormation deployment performs stabilization checks after resource configuration is applied. These checks serve an important purpose when you need to confirm resources can serve traffic before shifting load.</p><p>However, many workflows do not require full stabilization to proceed. Express mode benefits two primary use cases: iterative development workflows and production scenarios where you are comfortable with eventual stabilization. These use cases include iterating on infrastructure configurations during development, testing individual components of your application, and AI-assisted infrastructure development that benefits from sub-minute feedback loops.</p><p>With Express mode, CloudFormation completes deployments when resource configuration is applied, without waiting for stabilization checks. Resources continue becoming operational in the background. CloudFormation automatically retries dependent resources that encounter transient failures during provisioning within the same stack, without requiring any customer intervention. This built-in resilience handles timing issues between resources as they stabilize. Express mode changes <em>when</em> the deployment completes, not <em>how</em> resources are provisioned.</p><p>For example, when I create an <a href="https://aws.amazon.com/sqs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Simple Queue Service (SQS)</a> queue with a dead letter queue (DLQ), Standard mode takes 64 seconds, but Express mode completes in up to 10 seconds. In the case of deleting an <a href="https://aws.amazon.com/lambda/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Lambda</a> function with network interface attachment, Standard mode takes 20–30 minutes, but Express mode completes in up to 10 seconds based on my benchmarking test.</p><p><strong class="c6">Get started with CloudFormation Express mode</strong><br />When you create a CloudFormation stack in the <a href="https://console.aws.amazon.com/cloudformation/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Management Console</a>, choose <strong>Enable</strong> in the <strong>Express mode</strong> under <strong>Stack deployment options</strong>.<img class="aligncenter wp-image-104864 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/25/2026-aws-cloudformation-express-mode-console.jpg" alt="" width="1800" height="1492" /></p><p>You can also use <a href="https://aws.amazon.com/cli/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Command Line Interface (AWS CLI)</a>, <a href="https://builder.aws.com/build/tools#SDKs?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS SDKs</a>, or IaC tools like <a href="https://aws.amazon.com/cdk/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Cloud Development Kit (CDK)</a>, and AI tools such as <a href="https://kido.dev/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Kiro</a>.</p><p>Activate Express mode by setting the <code class="qs:font-mono qs:bg-action-hover qs:rounded qs:px-1 qs:py-0.5 qs:mx-1" data-testid="qbiz-components-markdown-codehighlighter-fallback-container">--deployment-config</code> parameter to <code>EXPRESS</code> when creating, updating, or deleting stacks. No template changes are required. Express mode disables rollback by default for the fastest iteration experience. To re-enable rollback, set <code>disableRollback</code> to <code>false</code> in the <code>deployment-config</code> for production environments, or implement monitoring/cleanup mechanisms for failed deployments.</p><pre class="lang-bash">aws cloudformation create-stack \ 
   --stack-name my-app \ 
   --template-body file://template.yaml \ 
   --deployment-config '{"mode": "EXPRESS", "disableRollback": true}' \</pre><p>For example, use the Express mode when you build infrastructure incrementally, adding resources one at a time. Ensure your IAM role templates follow the principle of least privilege.</p><pre class="lang-bash"># Iteration 1: Deploy IAM role
aws cloudformation create-stack \
--stack-name my-microservice \
--template-body file://iteration1-iam.yaml \
--deployment-config '{"mode": "EXPRESS"}' \
--capabilities CAPABILITY_IAM
--role-arn arn:aws:iam::123456789012:role/CloudFormationDeployRole
# Iteration 2: Add Lambda function
aws cloudformation update-stack \
--stack-name my-microservice \
--template-body file://iteration2-lambda.yaml \
--deployment-config '{"mode": "EXPRESS"}' \
--capabilities CAPABILITY_IAM
--role-arn arn:aws:iam::123456789012:role/CloudFormationDeployRole
# Iteration 3: Add SQS queue and event source mapping
aws cloudformation update-stack \
--stack-name my-microservice \
--template-body file://iteration3-sqs.yaml \
--deployment-config '{"mode": "EXPRESS"}' \
--capabilities CAPABILITY_IAM
--role-arn arn:aws:iam::123456789012:role/CloudFormationDeployRole</pre><p>For AWS CDK, activate Express mode with the <code>cdk deploy --express</code> command when you deploy your CDK stack. This command retrieves your generated CloudFormation template and deploys it through the CloudFormation Express mode, which provisions your resources as part of a CloudFormation stack.</p><p>Express mode works with all existing CloudFormation templates and supports all CloudFormation features including change sets and nested stacks. When you enable Express mode on a parent stack, all nested stacks also use Express mode. If you need resources to be fully operational before proceeding with traffic or testing, continue using the default deployment behavior, which performs stabilization checks before completing.</p><p><strong class="c6">Now available</strong><br />AWS CloudFormation Express mode is available today in all AWS commercial Regions at no additional cost. For Regional availability and a future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>. If you want to call APIs, search documentation, find regional availability, and check troubleshooting about this new feature, try using the <a href="https://docs.aws.amazon.com/agent-toolkit/latest/userguide/getting-started-aws-mcp-server.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS MCP Server</a> and <a href="https://docs.aws.amazon.com/agent-toolkit/latest/userguide/plugins.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">plugins</a> with your preferred AI tool. To learn more, visit the <a href="https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stacks.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">CloudFormation documentation</a>.</p><p>Start accelerating your deployments today, and send feedback to <a href="https://repost.aws/tags/TAm3R3LNU3RfSX9L23YIpo3w/aws-cloudformation?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for AWS CloudFormation</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="af9ee1f3-70e5-4a11-b5d0-10ee275bb0a7" data-title="Accelerate your infrastructure deployments by up to 4x with AWS CloudFormation Express mode" data-url="https://aws.amazon.com/blogs/aws/accelerate-your-infrastructure-deployments-by-up-to-4x-with-aws-cloudformation-express-mode/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/accelerate-your-infrastructure-deployments-by-up-to-4x-with-aws-cloudformation-express-mode/"/>
    <updated>2026-06-30T23:30:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-ec2-c9g-and-c9gd-instances-powered-by-aws-graviton5-processors-are-now-available/</id>
    <title><![CDATA[Amazon EC2 C9g and C9gd instances powered by AWS Graviton5 processors are now available]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>When you run compute-intensive workloads like real-time analytics, batch processing, video encoding, scientific modeling, or CPU-based machine learning inference, every percentage point of performance matters. You need instances that deliver higher throughput per vCPU, faster memory access, and more network bandwidth, all while keeping your costs in check.</p><p>Today I am happy to announce the general availability of <a href="https://aws.amazon.com/ec2/">Amazon Elastic Compute Cloud (Amazon EC2)</a> C9g and C9gd instances, powered by <a href="https://aws.amazon.com/ec2/graviton/">AWS Graviton5</a> processors. C9g instances are compute-optimized and deliver up to 25% higher performance per vCPU compared to previous-generation C8g instances. They feature the fastest memory of any processor instance in the cloud, with DDR5 8800MT/s DIMMs, 5x more L3 cache, and up to 3x higher packet-processing performance compared to Graviton4-based instances. The faster memory and larger caches mean your workloads spend less time waiting on data, translating into higher throughput for in-memory analytics, faster agentic loops, and more responsive real-time applications.</p><p>C9g instances are ideal for batch jobs, video encoding pipelines, or distributed analytics that can utilize <a href="https://aws.amazon.com/ebs/">Amazon Elastic Block Store (Amazon EBS)</a> for storage. It is also a natural fit for agentic AI workloads, where concurrent environments and CPU-bound reasoning steps benefit from Graviton5’s higher core count and larger caches. As AI shifts from answering questions to taking actions, running code, and orchestrating multi-step tasks, the demand for CPU compute is growing, and C9g instances are built for this shift.</p><p>Some workloads also need fast local storage alongside that compute power. Choose C9gd when your application benefits from high-speed, low-latency local NVMe SSD storage, for example scratch space during HPC simulations, temporary caches for ML inference, or local buffers for ad-serving engines.</p><p>Graviton5-based instances with NVMe instance store volumes also <a href="https://aws.amazon.com/blogs/compute/optimize-latency-sensitive-workloads-with-amazon-ec2-detailed-nvme-statistics/">support detailed performance statistics, providing high-resolution I/O metrics, including latency histograms broken down by I/O size, up to 1-second granularity</a> and accessible via <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a> or <a href="https://github.com/linux-nvme/nvme-cli">nvme-cli</a> at no additional cost.</p><p><strong>C9g and C9gd instances at a glance</strong><br />C9g and C9gd instances are available in 11 sizes ranging from medium to 48xlarge, plus a bare metal option. They offer up to 15% higher network bandwidth and 20% higher EBS bandwidth on average across sizes compared to the previous generation, with the largest 48xlarge size delivering up to 100 Gbps of network bandwidth and up to 72 Gbps of EBS bandwidth, a 2x increase.</p><table class="c11" border="0" cellpadding="8" style="border-spacing: 0px;"><tbody><tr class="c7"><th class="c6">C9g</th>
<th class="c6">vCPUs</th>
<th class="c6">Memory<br />(GiB)</th>
<th class="c6">Network Bandwidth<br />(Gbps)</th>
<th class="c6">EBS Bandwidth<br />(Gbps)</th>
</tr><tr class="c9"><td class="c8"><strong>medium</strong></td>
<td class="c8">1</td>
<td class="c8">2</td>
<td class="c8">Up to 15</td>
<td class="c8">Up to 12</td>
</tr><tr class="c10"><td class="c8"><strong>large</strong></td>
<td class="c8">2</td>
<td class="c8">4</td>
<td class="c8">Up to 15</td>
<td class="c8">Up to 12</td>
</tr><tr class="c9"><td class="c8"><strong>xlarge</strong></td>
<td class="c8">4</td>
<td class="c8">8</td>
<td class="c8">Up to 15</td>
<td class="c8">Up to 12</td>
</tr><tr class="c10"><td class="c8"><strong>2xlarge</strong></td>
<td class="c8">8</td>
<td class="c8">16</td>
<td class="c8">Up to 17</td>
<td class="c8">Up to 12</td>
</tr><tr class="c9"><td class="c8"><strong>4xlarge</strong></td>
<td class="c8">16</td>
<td class="c8">32</td>
<td class="c8">Up to 17</td>
<td class="c8">Up to 12</td>
</tr><tr class="c10"><td class="c8"><strong>8xlarge</strong></td>
<td class="c8">32</td>
<td class="c8">64</td>
<td class="c8">17</td>
<td class="c8">12</td>
</tr><tr class="c9"><td class="c8"><strong>12xlarge</strong></td>
<td class="c8">48</td>
<td class="c8">96</td>
<td class="c8">25</td>
<td class="c8">18</td>
</tr><tr class="c10"><td class="c8"><strong>16xlarge</strong></td>
<td class="c8">64</td>
<td class="c8">128</td>
<td class="c8">34</td>
<td class="c8">24</td>
</tr><tr class="c9"><td class="c8"><strong>24xlarge</strong></td>
<td class="c8">96</td>
<td class="c8">192</td>
<td class="c8">50</td>
<td class="c8">36</td>
</tr><tr class="c10"><td class="c8"><strong>48xlarge</strong></td>
<td class="c8">192</td>
<td class="c8">384</td>
<td class="c8">100</td>
<td class="c8">72</td>
</tr><tr class="c9"><td class="c8"><strong>metal-48xl</strong></td>
<td class="c8">192</td>
<td class="c8">384</td>
<td class="c8">100</td>
<td class="c8">72</td>
</tr></tbody></table><p>C9gd instances add local NVMe SSD storage with up to 30% higher storage performance compared to previous-generation local storage instances.</p><table class="c11" border="0" cellpadding="8" style="border-spacing: 0px;"><tbody><tr class="c7"><th class="c6">C9gd</th>
<th class="c6">vCPUs</th>
<th class="c6">Memory<br />(GiB)</th>
<th class="c6">Instance Storage<br />(GB)</th>
<th class="c6">Network Bandwidth<br />(Gbps)</th>
<th class="c6">EBS Bandwidth<br />(Gbps)</th>
</tr><tr class="c9"><td class="c8"><strong>medium</strong></td>
<td class="c8">1</td>
<td class="c8">2</td>
<td class="c8">1 x 59</td>
<td class="c8">Up to 15</td>
<td class="c8">Up to 12</td>
</tr><tr class="c10"><td class="c8"><strong>large</strong></td>
<td class="c8">2</td>
<td class="c8">4</td>
<td class="c8">1 x 118</td>
<td class="c8">Up to 15</td>
<td class="c8">Up to 12</td>
</tr><tr class="c9"><td class="c8"><strong>xlarge</strong></td>
<td class="c8">4</td>
<td class="c8">8</td>
<td class="c8">1 x 237</td>
<td class="c8">Up to 15</td>
<td class="c8">Up to 12</td>
</tr><tr class="c10"><td class="c8"><strong>2xlarge</strong></td>
<td class="c8">8</td>
<td class="c8">16</td>
<td class="c8">1 x 474</td>
<td class="c8">Up to 17</td>
<td class="c8">Up to 12</td>
</tr><tr class="c9"><td class="c8"><strong>4xlarge</strong></td>
<td class="c8">16</td>
<td class="c8">32</td>
<td class="c8">1 x 950</td>
<td class="c8">Up to 17</td>
<td class="c8">Up to 12</td>
</tr><tr class="c10"><td class="c8"><strong>8xlarge</strong></td>
<td class="c8">32</td>
<td class="c8">64</td>
<td class="c8">1 x 1900</td>
<td class="c8">17</td>
<td class="c8">12</td>
</tr><tr class="c9"><td class="c8"><strong>12xlarge</strong></td>
<td class="c8">48</td>
<td class="c8">96</td>
<td class="c8">3 x 950</td>
<td class="c8">25</td>
<td class="c8">18</td>
</tr><tr class="c10"><td class="c8"><strong>16xlarge</strong></td>
<td class="c8">64</td>
<td class="c8">128</td>
<td class="c8">1 x 3800</td>
<td class="c8">34</td>
<td class="c8">24</td>
</tr><tr class="c9"><td class="c8"><strong>24xlarge</strong></td>
<td class="c8">96</td>
<td class="c8">192</td>
<td class="c8">3 x 1900</td>
<td class="c8">50</td>
<td class="c8">36</td>
</tr><tr class="c10"><td class="c8"><strong>48xlarge</strong></td>
<td class="c8">192</td>
<td class="c8">384</td>
<td class="c8">3 x 3800</td>
<td class="c8">100</td>
<td class="c8">72</td>
</tr><tr class="c9"><td class="c8"><strong>metal-48xl</strong></td>
<td class="c8">192</td>
<td class="c8">384</td>
<td class="c8">3 x 3800</td>
<td class="c8">100</td>
<td class="c8">72</td>
</tr></tbody></table><p>Both families are well-suited for high-performance computing (HPC), batch processing, gaming, video encoding, scientific modeling, distributed analytics, CPU-based machine learning inference, and ad serving.</p><p>Here are some additional capabilities:</p><ul><li>Instance Bandwidth Configuration (IBC) lets you adjust the allocation of bandwidth between Amazon EBS and Amazon VPC networking by up to 25%, helping you optimize performance for workloads with specific bandwidth requirements such as databases and caching.</li>
<li>ENA Express support for enhanced networking.</li>
<li>Up to 128 EBS volumes can be attached to virtual instances.</li>
<li>Support for Savings Plans, On-Demand, Spot Instances, Dedicated Instances, and Dedicated Hosts.</li>
</ul><p><strong>Nitro Isolation Engine</strong><br />C9g and C9gd instances are the first compute optimized Amazon EC2 instances to feature the <a href="https://aws.amazon.com/blogs/compute/aws-nitro-isolation-engine-formally-verifying-the-hypervisor-in-the-aws-nitro-system/" target="_blank" rel="noopener noreferrer">AWS Nitro Isolation Engine</a>, a new capability of the <a href="https://aws.amazon.com/ec2/nitro/" target="_blank" rel="noopener noreferrer">AWS Nitro System</a>. The Nitro Isolation Engine is a purpose-built component of the Nitro Hypervisor, implemented in Rust, that enforces isolation between virtual machines. It mediates all access to VM memory, CPU register state, and I/O devices through a minimal set of APIs.</p><p>To learn more about the Nitro Isolation Engine, visit the <a href="https://aws.amazon.com/blogs/compute/aws-nitro-isolation-engine-formally-verifying-the-hypervisor-in-the-aws-nitro-system/" target="_blank" rel="noopener noreferrer">blog post</a>. For details on the formal verification results, including scope and assumptions, see our <a href="https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/whitepapers/compliance/nitro-isolation-engine-whitepaper.pdf" target="_blank" rel="noopener noreferrer">technical white paper</a>.</p><p><strong>Now available</strong><br />Amazon EC2 C9g and C9gd instances are now available in US East (Ohio, N. Virginia), US West (Oregon), and Europe (Frankfurt). Additional regions will follow.</p><p>You can launch C9g and C9gd instances today using the <a href="https://console.aws.amazon.com">AWS Management Console</a>, <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a>, or <a href="https://aws.amazon.com/tools/">AWS SDKs</a>. For pricing information, visit the <a href="https://aws.amazon.com/ec2/pricing/">Amazon EC2 Pricing page</a>.</p><p>To learn more, visit the Amazon EC2 C9g and C9gd instances page and send feedback to AWS re:Post for EC2 or through your usual AWS Support contacts.</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="35f13845-cdf4-4ce7-bdb5-f71d942efed7" data-title="Amazon EC2 C9g and C9gd instances powered by AWS Graviton5 processors are now available" data-url="https://aws.amazon.com/blogs/aws/amazon-ec2-c9g-and-c9gd-instances-powered-by-aws-graviton5-processors-are-now-available/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-ec2-c9g-and-c9gd-instances-powered-by-aws-graviton5-processors-are-now-available/"/>
    <updated>2026-06-30T22:56:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/automate-public-tls-certificate-issuance-with-acme-support-in-aws-certificate-manager/</id>
    <title><![CDATA[Automate public TLS certificate issuance with ACME support in AWS Certificate Manager]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>If you manage TLS certificates for your applications, you know the challenge: certificates expire, and when they do, your customers see errors or your service goes down. As certificate validity periods get shorter (the <a href="https://cabforum.org/">Certification Authority (CA)/Browser Forum</a> mandates reduced maximum validity to 100 days starting March 2027, and to 47 days by 2029), manual renewal processes become untenable. You need automation.</p><p><a href="https://en.wikipedia.org/wiki/Automatic_Certificate_Management_Environment">Automatic Certificate Management Environment (ACME)</a> is an open protocol for requesting, renewing, and revoking TLS certificates without human intervention. It’s the same protocol behind Let’s Encrypt, and it’s supported by dozens of clients across every platform.</p><p>Today we’re announcing ACME support for public certificates in <a href="https://aws.amazon.com/certificate-manager/">AWS Certificate Manager (ACM)</a>. ACM now provides a fully managed ACME server endpoint that works with any ACMEv2-compatible client, such as <a href="https://certbot.eff.org/">Certbot</a>, <a href="https://cert-manager.io/">cert-manager for Kubernetes</a>, <a href="https://github.com/acmesh-official/acme.sh">acme.sh</a>, or any other client you already use. You can issue public TLS certificates from <a href="https://www.amazontrust.com/?lang=en">Amazon Trust Services</a> through the standard ACME protocol.</p><p>Before today, if you wanted automated certificate management using the ACME protocol, you relied on external certificate authorities alongside ACM, leading to a fragmented visibility experience. Some certificates lived in ACM, others were managed externally with no central dashboard. PKI administrators had limited ability to control who could request certificates or which domains were allowed.</p><p>With ACME support in ACM, you can now set up one or more managed ACME endpoint that allows you to centrally manage and monitor ACME certificate usage across your organization.</p><p>As a PKI administrator, you get centralized controls that go beyond basic certificate issuance. You can bind IAM roles to ACME accounts for fine-grained access control over which domains each client can request. You can define domain scopes at the endpoint level to enforce organization-wide policies. And you get centralized monitoring and visibility in the same place: <a href="https://aws.amazon.com/cloudtrail/">AWS CloudTrail</a> logs every certificate request for auditability, <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a> tracks operational metrics, and ACM sends expiry notifications when certificates are approaching renewal. Using ACM, your PKI team can search all certificates, whether issued through the ACM console, an API call, or ACME.</p><p><strong>How it works<br /></strong> To get started, you first set up a dedicated ACME endpoint, configure authorization controls using External Account Binding (EAB), validate which domains the endpoint can issue certificates for, and point your existing ACME clients to the new endpoint.</p><p>The domain validation step is important: it separates who can set up certificate issuance from who can request certificates. The PKI administrator validates domains once at the endpoint level, using DNS credentials that stay with the admin. Application owners who need certificates never touch DNS. They register with an EAB credential, and the endpoint enforces which domains and scopes they’re allowed to request. This means you can distribute certificate automation broadly across your organization without distributing DNS keys along with it.</p><p>I start this demo from the <strong>ACME certificates</strong> page in the AWS Certificate Manager console.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/09/2026-06-09_15-35-37.png"><img class="aligncenter wp-image-104397 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/09/2026-06-09_15-35-37-1024x877.png" alt="ACME Console" width="1024" height="877" /></a></p><p>I already have a few endpoints and certificates in this account, I walk you through creating a new one from scratch. First, I select <strong>Create ACME endpoint</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/09/2026-06-09_15-37-35.png"><img class="aligncenter wp-image-104398 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/09/2026-06-09_15-37-35-1024x650.png" alt="ACME - Ceeate endpoint 1" width="1024" height="650" /></a></p><p>I give my endpoint a name. The <strong>Endpoint type</strong> is <strong>Public</strong>. ACME clients will connect over the public internet. The <strong>Certificate type</strong> is <strong>Public</strong>. The certificate will be issued by Amazon Trust Services and trusted by browsers and operating systems by default. For the certificate key type, I keep the default <strong>ECDSA P-256</strong>. RSA 2048 and ECDSA P-384 are also available if your clients require them.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/08/2026-06-05_17-27-21.png"><img class="aligncenter size-large wp-image-104324" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/08/2026-06-05_17-27-21-1024x832.png" alt="ACME - Ceeate endpoint 2" width="1024" height="832" /></a></p><p>Scrolling down, I configure the domain. I enter my domain name and select the domain scope. The scope controls exactly what certificate patterns your ACME clients are allowed to request for this domain. If I check only <strong>Exact domain</strong>, clients can only request certificates for that specific domain name. Adding <strong>Subdomains</strong> allows certificates for any subdomain (for example, api.example.com or dev.example.com). Adding <strong>Wildcards</strong> allows wildcard certificates (*.example.com). By leaving a scope unchecked, you prevent any client using this endpoint from requesting that type of certificate, even if their ACME request is otherwise valid. For a production endpoint, you might enable only <strong>Exact domain</strong> and <strong>Subdomains</strong> while leaving <strong>Wildcards</strong> unchecked to enforce a stricter security posture.</p><p>I also select my <a href="https://aws.amazon.com/route53/">Amazon Route 53</a> hosted zone from the drop down menu. ACM then automatically creates the DNS CNAME records needed for domain validation, so I don’t have to do it manually. When my domain is hosted outside of Route 53, I manually create the provided CNAME record at my DNS provider instead. This is a meaningful difference from typical ACME setups where each client handles its own domain verification independently.</p><p>These centralized controls give PKI administrators a single place to authenticate domains, restrict which certificate types (ECDSA or RSA) clients can request, and further limit wildcard issuance. Having these governance capabilities built in means you don’t need to purchase a separate certificate lifecycle management product or invest in building a custom policy layer yourself, both of which come at significant cost and operational overhead.</p><p>I select <strong>Create ACME endpoint</strong></p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-09_15-46-50-v2.png"><img class="aligncenter wp-image-104797 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-09_15-46-50-v2-1024x801.png" alt="ACME - DNS configuration" width="1024" height="801" /></a></p><p>After a few seconds, the endpoint is created. The console shows a <strong>Setup progress</strong> tracker with the next steps. My domain shows a “Validating” status. The validation method is DNS validation, where ACM verifies that you control the domain by checking for a specific CNAME record. Because I selected my Route 53 hosted zone during creation, I select <strong>Create records in Route 53</strong> to let ACM handle the DNS validation automatically.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/08/2026-06-05_17-30-08.png"><img class="aligncenter size-large wp-image-104326" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/08/2026-06-05_17-30-08-1024x255.png" alt="ACME - DNS success" width="1024" height="255" /></a>The validation completes in a few seconds and the status changes to <strong>Success</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/09/2026-06-09_15-50-53.png"><img class="aligncenter wp-image-104400 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/09/2026-06-09_15-50-53-1024x810.png" alt="ACME - External Account Binding 1" width="1024" height="810" /></a></p><p>Now I need to create External Account Binding (EAB) credentials. EAB credentials are a key identifier and HMAC key pair that lets your ACME client register an account with the ACME server. Once registered, the client generates its own asymmetric key pair, which is then used to authenticate all subsequent certificate requests. On the endpoint details page, I select the <strong>External account binding</strong> tab, then select <strong>Create EAB</strong>. I give the credential a name and optionally set an expiration time, ideally no longer than needed to complete client registration.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/08/2026-06-05_17-46-42.png"><img class="aligncenter size-large wp-image-104329" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/08/2026-06-05_17-46-42-1024x569.png" alt="ACME - External Account Binding 2" width="1024" height="569" /></a></p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/09/2026-06-09_15-53-37.png"><img class="aligncenter wp-image-104401 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/09/2026-06-09_15-53-37-1024x251.png" alt="ACME - end of configuration - show key" width="1024" height="251" /></a></p><p>After I select <strong>Create EAB credential</strong>, the console shows the <strong>Key ID</strong> and <strong>HMAC Key</strong>. I note these values because I need them to configure my ACME client. The setup progress now shows four green checkmarks.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/08/2026-06-05_17-48-17.png"><img class="aligncenter size-large wp-image-104330" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/08/2026-06-05_17-48-17-1024x227.png" alt="ACME - end of configuration - success" width="1024" height="227" /></a></p><p>I’m ready to request a certificate. On the endpoint details page, I expand the <strong>CLI reference</strong> section. The console provides ready-to-use command examples for both <a href="https://certbot.eff.org/">Certbot</a> and <a href="https://github.com/acmesh-official/acme.sh">acme.sh</a>. I copy the Certbot command and run it inside a container using the <code>certbot/certbot</code> image.</p><pre>certbot certonly --standalone --non-interactive --agree-tos \
    --email &lt;EMAIL&gt; \
    --server https://acm-acme-enroll.us-east-1.api.aws/&lt;ENDPOINT_ID&gt;/directory \
    --eab-kid &lt;EAB_KID&gt; \
    --eab-hmac-key &lt;EAB_HMAC_KEY&gt; \
    --issuance-timeout &lt;ISSUANCE_TIMEOUT&gt; \
    -d &lt;DOMAIN&gt;</pre><p>I replace the placeholders with my endpoint URL, EAB credentials, and domain name. The <code>--eab-kid</code> and <code>--eab-hmac-key</code> arguments are how Certbot registers with your ACME endpoint using the External Account Binding credentials I generated earlier. Each ACME client has its own syntax for this step, so check your client’s documentation for the exact flags.</p><p>Certbot contacts the ACME endpoint and returns a valid certificate signed by Amazon Trust Services.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-10_15-16-12-v3.png"><img class="aligncenter wp-image-104798 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-10_15-16-12-v3-1024x378.png" alt="Certbot to obtain a certificate through ACME" width="1024" height="378" /></a></p><p>I use <code>openssl</code> to view the certificate before installing it.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-10_15-21-23-v2.png"><img class="aligncenter wp-image-104799 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/2026-06-10_15-21-23-v2.png" alt="openssl to view the certificate" width="938" height="752" /></a></p><p>The certificate is now visible in the ACM console under the <strong>ACME certificates</strong> tab, alongside any certificates issued through the console or API.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/10/2026-06-10_15-18-04.png"><img class="aligncenter size-large wp-image-104442" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/10/2026-06-10_15-18-04-1024x280.png" alt="Certoficate view in the ACME console" width="1024" height="280" /></a></p><p><strong>Availability and pricing<br /></strong> ACME support in AWS Certificate Manager is available today in all commercial AWS Regions and will be available in AWS GovCloud (US), the China Regions, and the <a href="https://aws.eu/">AWS European Sovereign Cloud</a> <a href="https://docs.aws.amazon.com/whitepapers/latest/aws-fault-isolation-boundaries/partitions.html">partitions</a> at a later date.</p><p>Pricing is per domain included in each certificate at the time of issuance, with a different price for fully qualified domain names and wildcards. Volume tiers are calculated based on total domain occurrences across all certificates issued per month in your AWS account. For details, see <a href="https://aws.amazon.com/certificate-manager/pricing/">the ACM pricing page</a>.</p><p>To get started, visit the <a href="https://console.aws.amazon.com/acm/">ACM section on the AWS console</a> or read the <a href="https://docs.aws.amazon.com/acm/latest/userguide/">documentation</a>.</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="e8b79af7-6e07-4e63-92a9-6f4b2f61eb07" data-title="Automate public TLS certificate issuance with ACME support in AWS Certificate Manager" data-url="https://aws.amazon.com/blogs/aws/automate-public-tls-certificate-issuance-with-acme-support-in-aws-certificate-manager/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/automate-public-tls-certificate-issuance-with-acme-support-in-aws-certificate-manager/"/>
    <updated>2026-06-30T22:15:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-agentic-cx-designer-for-amazon-connect-customer-ec2-ami-watermarks-open-governance-for-mysql-and-more-june-29-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Agentic CX designer for Amazon Connect Customer, EC2 AMI Watermarks, Open Governance for MySQL, and more (June 29, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p><img class="alignright size-medium wp-image-104911" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/28/IMG_5013-225x300.jpg" alt="" width="225" height="300" />It has been a busy stretch on the AWS Summit circuit. At the <a href="https://aws.amazon.com/events/summits/new-york/">New York City Summit,</a> I delivered a workshop called Building AI architectures with AWS Serverless, and it was a lot of fun watching builders wire up agents and serverless services to solve real problems in a single afternoon. This week I am heading down to the <a href="https://aws.amazon.com/events/summits/washington-dc/">Washington, DC Summit</a>, which always puts a spotlight on innovation in the public sector. If you are going to be there, come say hello.</p><p>A question I hear a lot at these events is how teams can put AI to work without waiting on a long engineering backlog, and this week’s biggest launch speaks directly to that, with Amazon Connect Customer introducing a no-code way for business teams to design AI powered customer experiences themselves. Now, let’s get into this week’s AWS news.</p><p><strong><ins>Headlines<br /></ins></strong> Amazon Connect Customer launched the <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-connect-customer-agentic-cx-preview/">Agentic CX designer (NLX) in preview</a>, a no-code canvas for designing and deploying AI powered self service experiences. Business teams can build and launch voice and digital experiences that bring agentic and deterministic AI together in one governed flow, going from design to testing and simulation to production ready experiences in weeks rather than months. The launch also includes Live Sync in preview, a patented technology that drives a customer’s web or mobile experience in real time as they speak or type. A caller can complete a form or pull up the right product page without ever leaving the conversation. To see how this reshapes who designs customer experience, read the blog post on how the <a href="https://aws.amazon.com/blogs/contact-center/business-user-is-the-new-architect-of-customer-experience/">business user is the new architect of customer experience</a>.</p><p><strong><ins>Last week’s launches<br /></ins></strong> Here are some launches and updates from this past week that caught my attention:</p><ul><li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-lambda-microvms/">AWS Lambda MicroVMs</a></strong> – A new serverless compute primitive that gives each user or job VM level isolation with near instant launch and resume speeds, plus the ability to suspend and resume execution for up to 8 hours. Built on Firecracker, it is made for running user or AI generated code in multi-tenant applications without managing virtualization infrastructure or trading off isolation, speed, and state.</li>
<li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/ec2-image-watermarks-allowed-images/">Amazon EC2 AMI Watermarks</a></strong> – Lets you embed custom identifiers in your private AMIs that automatically carry forward to every derived AMI across copies, Regions, and account shares. You can combine watermarks with Allowed AMIs and Declarative Policies to restrict launches to approved images, available at no additional cost in all AWS Regions.</li>
<li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-outposts-self-service-lifecycle-management">AWS Outposts self-service lifecycle management</a></strong> – Adds self service configuration, quoting, ordering, subscription management, renewal, and decommissioning directly from the console, CLI, and API. A new quoting tool generates real time cost estimates in seconds and surfaces account and regional constraints before you submit an order.</li>
<li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-msk-ai-agent-skills">Amazon MSK AI Agent Skills</a></strong> – Gives AI coding assistants like Kiro, Claude Code, and Cursor expert, up-to-date guidance for operating Amazon MSK, covering troubleshooting, sizing, configuring, monitoring, and migrating external Kafka clusters to MSK Express. Tasks that once required specialized knowledge become a guided experience developers can complete on their own.</li>
<li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-opensearch-service-ai-migrations">Amazon OpenSearch Service AI-assisted migrations</a></strong> – Migration Assistant now includes an agent guided experience that helps you move self managed Apache Solr, Elasticsearch, or OpenSearch deployments to OpenSearch Serverless or Managed Clusters using tools like Kiro and Claude Code, with new live traffic capture and replay support for Solr.</li>
<li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-guardduty/">Amazon GuardDuty AI-powered investigations (preview)</a></strong> – Automatically analyzes findings and accounts to help you separate true threats from benign activity, examining context and related activity from the last 90 days with knowledge graphs and threat intelligence. Each investigation returns a disposition assessment with confidence scoring, MITRE ATT&amp;CK classification, and actionable recommendations in minutes.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong><ins>Other AWS news<br /></ins></strong> Here are some additional posts and resources that you might find interesting:</p><ul><li><strong><a href="https://aws.amazon.com/blogs/opensource/open-governance-for-mysql-a-step-forward-for-the-community/">Open Governance for MySQL</a></strong> – Oracle announced a community governance model for MySQL that gives organizations outside Oracle a defined role in the project, including four non Oracle seats on a new Steering Committee and a public GitHub presence. AWS holds a seat and shares why it supports the move and how it already contributes fixes upstream for everyone running MySQL.</li>
<li><strong><a href="https://aws.amazon.com/blogs/training-and-certification/a-new-way-to-keep-your-aws-certification-current/">A new way to keep your AWS Certification current</a></strong> -You can now maintain an eligible AWS Certification for an additional year by completing curated training and hands on labs on AWS Skill Builder instead of retaking a full exam. The option is available today in open beta for several Associate and Professional certifications, with more coming later this year.</li>
<li><strong><a href="https://builder.aws.com/content/3FGF2bDqKm6xKGmyJqJMrcwRhE8/the-aws-all-builders-welcome-grant-an-insiders-guide-for-2026-applicants">The All Builders Welcome Grant insider’s guide for 2026 applicants</a></strong> – A community guide on AWS Builder Center that walks early career builders through applying for the grant, which covers a full conference pass, airfare, and hotel for AWS re:Invent 2026. Applications are open now and close on July 14.</li>
</ul><p>For a full list of AWS blog posts, be sure to keep an eye on the <a href="https://aws.amazon.com/blogs/">AWS Blogs</a> page.</p><p>Looking for ways to connect with builders in person? Check out the <a href="https://aws.amazon.com/events/summits/">AWS Summits</a> coming to a city near you, find a local <a href="https://aws.amazon.com/developer/community/community-days/">AWS Community Day</a> led by user groups around the world, and explore tutorials, community content, and ways to grow your skills over at the <a href="https://builder.aws.com/">AWS Builder Center</a>.</p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><p>-Micah</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="2f9a42c4-1906-4027-8219-05778a66844a" data-title="AWS Weekly Roundup: Agentic CX designer for Amazon Connect Customer, EC2 AMI Watermarks, Open Governance for MySQL, and more (June 29, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-agentic-cx-designer-for-amazon-connect-customer-ec2-ami-watermarks-open-governance-for-mysql-and-more-june-29-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-agentic-cx-designer-for-amazon-connect-customer-ec2-ami-watermarks-open-governance-for-mysql-and-more-june-29-2026/"/>
    <updated>2026-06-29T18:30:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/run-isolated-sandboxes-with-full-lifecycle-control-aws-lambda-introduces-microvms/</id>
    <title><![CDATA[Run isolated sandboxes with full lifecycle control: AWS Lambda introduces MicroVMs]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we are announcing AWS Lambda MicroVMs, a new serverless compute primitive within <a href="https://aws.amazon.com/lambda/">AWS Lambda</a> that lets you run code generated by users or AI in isolated, stateful execution environments. You get virtual machine level isolation, near-instant launch and resume, and direct control over environment lifecycle and state, all without managing infrastructure or building expertise in complex virtualization technologies. Lambda MicroVMs are powered by <a href="https://firecracker-microvm.github.io/">Firecracker</a>, the same lightweight virtualization technology that has powered over 15 trillions of monthly Lambda function invocations.</p><p><strong>Why customers need this<br /></strong> Over the past few years a new class of multi-tenant applications has emerged that all share the need to hand each end user their own dedicated execution environment in which to safely run code that the application developer did not write. AI coding assistants, interactive code environments, data analytics platforms, vulnerability scanners, and game servers that run user-supplied scripts all fit this pattern. Building that capability today means making a difficult choice. Virtual machines deliver strong isolation but take minutes to start. Containers launch in seconds, yet their shared-kernel architecture requires significant custom hardening to safely contain untrusted code. Functions as a service are optimized for event-driven, request-response workloads, but are not designed for long-running interactive sessions that need to retain environment state across user interactions. That leaves developers either accepting tradeoffs between performance and isolation, or investing significant engineering resources to build and operate custom virtualization infrastructure to achieve isolated execution while delivering low-latency experiences to end-users. This presents an effort that demands deep expertise and pulls engineering time away from the product they are actually trying to build.</p><p>Lambda MicroVMs is purpose-built for exactly this gap. Each MicroVM gives a single end user or session its own isolated environment that launches rapidly, retains memory and disk state for the length of the session, and pauses to a low idle cost when the user steps away. Because the same Firecracker technology already underpins AWS Lambda Functions, you inherit the operational maturity of a service that has been running this stack at scale.</p><p><strong>Let’s try it out<br /></strong> To get started, I navigated to the AWS Lambda console, where Lambda MicroVMs now appears in the left-hand navigation menu. I first need to create a MicroVM Image.</p><p>I packaged a Flask web app and its Dockerfile into a zip file, uploaded it to an <a href="https://aws.amazon.com/s3/">Amazon Simple Storage Service (Amazon S3)</a> bucket.</p><p>My Flask API – app.py</p><pre class="lang-python">import logging
from flask import Flask, jsonify
app = Flask(__name__)
logging.basicConfig(level=logging.INFO)
@app.route("/")
def hello():
    app.logger.info("Received request to hello world endpoint")
    return jsonify(message="Hello, World!")
if __name__ == "__main__":
    app.run(host="0.0.0.0", port=5000)
</pre><p>My Dockerfile</p><pre>
FROM public.ecr.aws/lambda/microvms:al2023-minimal
RUN dnf install -y python3 python3-pip &amp;&amp; dnf clean all
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY app.py .
EXPOSE 5000
CMD ["gunicorn", "--bind", "0.0.0.0:5000", "app:app"]
</pre><p>I used the following command to create my MicroVM Image.</p><pre class="lang-bash">aws lambda-microvms create-microvm-image \
--code-artifact uri=&lt;path/to/s3/artifact.zip&gt; --name &lt;VM_image_name&gt; \
--base-image-arn arn:aws:lambda:us-east-1:aws:microvm-image:al2023-1 \
--build-role-arn &lt;IAM role ARN&gt;</pre><p><img class="alignnone wp-image-104847 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/22/Screenshot-2026-06-22-at-10.49.45%E2%80%AFAM-1024x577.png" alt="" width="1024" height="577" /></p><p>You can also create the MicroVM Image in the AWS Console as in the image above. Once I ran the command, Lambda retrieved the zip, ran the Dockerfile, initialized the application, and took a Firecracker snapshot of the running disk and memory state. Build logs streamed in real time to <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a> under <code>/aws/lambda/microvms/&lt;image-name&gt;</code>, and when the image was ready it appeared in the console with its <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference-arns.html">Amazon Resource Name (ARN)</a> and version number.</p><pre class="lang-bash">aws lambda-microvms run-microvm \
--image-identifier arn:aws:lambda:&lt;region&gt;:&lt;acct&gt;:microvm-image:my-image \
--execution-role-arn arn:aws:iam::&lt;acct&gt;:role/MicroVMExecutionRole \
--idle-policy '{"maxIdleDurationSeconds":900,"suspendedDurationSeconds":300,"autoResumeEnabled":true}'
</pre><p>Launching can also be done via the AWS Console or the CLI. I passed the image ARN and an idle policy configured to auto-suspend after 15 minutes of inactivity and auto-resume on the next incoming request. No networking setup was required. Lambda assigned the MicroVM a unique ID, returned a dedicated endpoint URL, and started a new MicroVM with my Flask app already running, since it was resumed from a snapshot. My Flask app was already running the moment the launch completed. One API call to get a fully initialized, bootstrapped compute environment.</p><p><img class="alignnone size-large wp-image-104756" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/image-04-1024x729.png" alt="" width="1024" height="729" /></p><p>To send traffic, I generated a short-lived auth token with the CLI and attached it to a plain HTTPS request using the <code>X-aws-proxy-auth</code> header. The request landed on my Flask app immediately. I then let the MicroVM sit idle past the suspend threshold, at which point the MicroVM was suspended, with its memory and disk state snapshotted and stored. I then sent another request, and it resumed with the application state fully intact. From the client side, the pause never happened.</p><p><img class="alignnone size-large wp-image-104757" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/19/image-05-1024x229.png" alt="" width="1024" height="229" /></p><p><strong>How it works<br /></strong> Under the covers, Lambda MicroVMs delivers three capabilities that, until today, no single AWS compute service offered together. The first is virtual machine level isolation, which comes from Firecracker. Each session runs in its own dedicated MicroVM with no shared kernel and no shared resources between users, so untrusted code supplied by one user is contained to their execution environment, without access to other environments or the underlying system. The second is rapid launch and resume. The model is image-then-launch: you create a MicroVM Image by supplying a Dockerfile and code packaged as a zip artifact in Amazon S3, and Lambda runs your Dockerfile, initializes your application, and takes a Firecracker snapshot of the running environment’s memory and disk state. Every subsequent MicroVM launched from that image resumes from the pre-initialized snapshot rather than booting cold, which means launches and idle resumes both achieve near-instant startup latency. Even a multi-gigabyte interactive session comes back online quickly enough to feel responsive to the end user. The third is stateful execution. A running MicroVM retains memory, disk, and running processes across the user’s session. During idle periods, a MicroVM can be suspended – with memory and disk state intact – and resumed when traffic arrives. Installed packages, loaded models, and working ﬁlesets are readily available when the user resumes their session. MicroVMs support up to 8 hours of total runtime and can be suspended automatically after a configurable idle window, which makes it straightforward to build products as varied as software vulnerability scans that complete in minutes, data analytics applications that run for hours, and interactive coding sessions with extended idle periods. As Lambda MicroVMs are started from pre-initialized snapshots, applications generating unique content, establishing network connections, or loading ephemeral data during initialization may need to integrate with service-provided hooks for compatibility.</p><p>Lambda MicroVMs is a new resource within AWS Lambda, with a distinct API surface. Lambda Functions remain the right choice for event-driven, request-response workloads, and Lambda MicroVMs is purpose-built for multi-tenant applications that need to hand each end user or session their own isolated environment to execute user- or AI-generated code. The two complement each other. An application using Lambda Functions for its event-driven backbone can call into Lambda MicroVMs for the steps that need to run untrusted code in isolation. You bring the application, and the service delivers the execution environment.</p><p><strong>Now available<br /></strong> AWS Lambda MicroVMs is available today in the US East (N. Virginia, Ohio), US West (Oregon), Europe (Ireland) and Asia Pacific (Tokyo) <a href="https://aws.amazon.com/about-aws/global-infrastructure/regions_az/">Regions</a>, on the ARM64 architecture, with up to 16 vCPUs, 32 GB of memory, and 32 GB of disk per MicroVM. Idle MicroVMs can be suspended explicitly through an API call or automatically through a lifecycle policy, which reduces the running cost while preserving full state for fast resume. Pricing details can be found on the <a href="https://aws.amazon.com/lambda/pricing/">AWS Lambda pricing page</a>.</p><p>To get started, visit the <a href="https://console.aws.amazon.com/lambda/">AWS Lambda console</a>, or learn more on the <a href="https://aws.amazon.com/lambda/lambda-microvms">Lambda MicroVMs product page</a>. For documentation, see the <a href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-microvms-guide.html">Lambda MicroVMs Developer Guide</a>.</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="3ad0fa18-93e9-439a-8a31-3087b2a38702" data-title="Run isolated sandboxes with full lifecycle control: AWS Lambda introduces MicroVMs" data-url="https://aws.amazon.com/blogs/aws/run-isolated-sandboxes-with-full-lifecycle-control-aws-lambda-introduces-microvms/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/run-isolated-sandboxes-with-full-lifecycle-control-aws-lambda-introduces-microvms/"/>
    <updated>2026-06-23T00:40:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-ny-summit-recap-local-zone-in-hanoi-grok-4-3-in-bedrock-price-reductions-and-more-june-22-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: NY Summit recap, Local Zone in Hanoi, Grok 4.3 in Bedrock, price reductions, and more (June 22, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Last week <a href="https://aws.amazon.com/events/summits/new-york/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summit New York City</a> brought together thousands of customers, partners, and builders for a free, one-day event showcasing the latest in cloud and AI innovation. Dr. Swami Sivasubramanian, VP of Agentic AI at AWS unveiled a stack of AI launches in <a href="https://www.youtube.com/watch?v=T25Fn3FvF6I">his keynote</a>, all built around one thesis: agents that compound value over time.</p><p><img class="aligncenter size-full wp-image-104713" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/17/2026-aws-ny-summit-keynote.jpg" alt="" width="1600" height="905" /></p><ul><li><strong>Agents for working</strong> – You can launch autonomous agents and access a smarter activity feed with <a href="https://aws.amazon.com/blogs/machine-learning/get-back-hours-every-day-with-autonomous-agents-in-amazon-quick/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">new Amazon Quick features</a>, which now let you create and run multi-step agents directly in the desktop app and consolidates email, Slack, calendar, and tasks into a single prioritized view with personalized rules.</li>
<li><strong>Agents for securing</strong> – You can shift from reactive to proactive security with AWS Continuum, a new AI-native security service that reasons, validates, and acts at machine speed across the <a href="https://aws.amazon.com/blogs/security/introducing-aws-continuum-security-at-machine-speed/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">full code vulnerability lifecycle</a>. AWS Security Agent (now part of AWS Continuum) adds <a href="https://aws.amazon.com/blogs/aws/aws-security-agent-adds-threat-modeling-kiro-power-and-claude-code-plugin-and-more?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">new features</a>: threat modeling; pull request code scanning with remediation across major Git platforms; and IDE integrations via Kiro power, Claude Code plugin, and MCP.</li>
<li><strong>Agents for building</strong> – You can write, ship, and modernize code in one continuous loop with Kiro, AWS DevOps Agent, and AWS Transform. Kiro introduces a <a href="https://kiro.dev/blog/introducing-kiro-for-ios/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">native iOS app</a>; AWS DevOps Agent adds <a href="https://aws.amazon.com/blogs/aws/aws-devops-agent-adds-release-management-capabilities-to-assess-code-changes-before-production-preview?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">release management capabilities</a> to assess code changes before production; and <a href="https://aws.amazon.com/blogs/aws/proactively-reduce-tech-debt-autonomously-with-aws-transform-continuous-modernization-preview?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Transform continuous modernization</a> reduces tech debt autonomously.</li>
<li><strong>Agents customers create</strong> – You can go from agent idea to production in minutes with Amazon Bedrock AgentCore, which now includes a <a href="https://aws.amazon.com/blogs/machine-learning/amazon-bedrock-agentcore-harness-is-now-generally-available-go-from-idea-to-production-grade-agent-in-minutes/">GA harness</a> for infrastructure and orchestration, <a href="https://aws.amazon.com/blogs/aws/announcing-web-search-on-amazon-bedrock-agentcore-ground-your-ai-agents-in-current-accurate-web-knowledge?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Web Search</a>, <a href="https://aws.amazon.com/blogs/aws/introducing-amazon-bedrock-managed-knowledge-base-for-faster-more-accurate-enterprise-ai-applications?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Managed Knowledge Base</a>, <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-bedrock-agentcore-policy-guardrails-generally-available?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">policy integrations with Guardrails</a>, and the new <a href="https://aws.amazon.com/blogs/machine-learning/context-intelligence-for-your-data-and-ai-agents-at-scale/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Context service</a> for mapping organizational data relationships.</li>
</ul><p>To learn more, visit the Summit recap from our <a href="https://aws.amazon.com/blogs/aws/top-announcements-of-the-aws-summit-in-new-york-2026/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">top announcements blog post</a> and <a href="https://www.aboutamazon.com/news/aws/aws-summit-nyc-2026-ai-agents?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon News post</a>.</p><p><strong>Last week’s launches</strong><br />Here are last week’s launches that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-local-zones-hanoi-vietnam/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Local Zone in Hanoi, Vietnam</a>  —This new Local Zone is one of the first AWS Local Zones in the Asia Pacific with support for Amazon S3 and Amazon EBS Local Snapshots, enabling customers to meet data residency requirements by storing and backing up data locally. To get started, enable the Hanoi Local Zone (<code>ap-southeast-1-han-1a</code>) from the Regions and Zones tab in the AWS Global View or by using the ModifyAvailabilityZoneGroup API.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-blocks-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Blocks, an open-source TypeScript framework for application developers (preview)</a> — AWS Blocks runs a fully functional local environment with Postgres, authentication, and real-time messaging, no AWS account required. When you’re ready to deploy, the same application code runs on production AWS services with zero changes, and you can drop into AWS CDK at any point for direct resource configuration.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/grok-amazon-bedrock/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Grok 4.3 from xAI in Amazon Bedrock</a> —You can use the Grok 4.3 model on Amazon Bedrock, giving you even more choice as you build generative AI applications across reasoning, agentic, and enterprise workflows. Grok 4.3 runs on a new inference engine in Bedrock designed for price performance, with support for tool calling, structured output, and response streaming.</li>
<li><a href="https://aws.amazon.com/blogs/aws/amazon-s3-annotations-attach-rich-queryable-context-directly-to-your-objects/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon S3 annotations: attach rich, queryable context directly to your objects</a> — Amazon S3 now lets you attach up to 1 GB of rich, mutable, and queryable context directly to your objects using annotations, purpose-built for AI agents and autonomous workflows that need to discover, understand, and act on data at scale without maintaining separate metadata systems.</li>
<li><a href="https://aws.amazon.com/blogs/aws/amazon-ecs-introduces-new-high-resolution-metrics-for-faster-service-auto-scaling/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon ECS announces faster service auto scaling</a> — Amazon ECS service auto scaling now detects and responds to load changes faster with support for high resolution (20-second) metrics and metric publishing optimizations. In AWS benchmarking tests, time to trigger scale-out improved from 363 seconds to 86 seconds (76% faster), and total time to scale and provision new tasks improved from 386 seconds to 109 seconds (72% faster).</li>
<li><a href="https://aws.amazon.com/blogs/aws/announcing-amazon-ec2-g7-instances-accelerated-by-nvidia-rtx-pro-4500-blackwell-server-edition-gpus/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 G7 instances accelerated by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs</a> — AWS is the first major cloud provider to support NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs. G7 instances are accelerated by these GPUs with custom sixth-generation Intel Xeon Scalable processors, delivering up to 4.6x AI inference performance and up to 2.1x graphics performance compared to G6 instances.</li>
<li><a href="https://strandsagents.com/blog/reduced-cost-better-isolation-more-resilience/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Strands Agents introduces new capabilities</a> — Strands is an open source toolkit for building production agents. You can now use better context management in Harness SDK, a new isolated execution environment with Strands Shell, and chaos testing and red teaming in Strands Evals.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-management-console-private/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Management Console Private Access</a> – You can access the AWS Console from VPCs without internet connectivity, allowing enterprises to manage their AWS infrastructure through the console while maintaining strict network security controls in air-gapped environments.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-marketplace-storefront/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Marketplace Storefront is now generally available</a> – AWS Partners can create and deploy their own branded catalog of solutions and services on their website or application in hours. Channel Partners and Independent Software Vendors can now simplify how they manage their cloud marketplace business and make it easier for customers to discover and purchase their solutions from AWS Marketplace.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-route-53-resolver-dns/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Palo Alto Networks (PANW) Advanced DNS Security on Amazon Route 53 Resolver DNS Firewall (preview)</a> – You can now enforce DNS threat protections from Palo Alto Networks directly on Route 53 DNS Firewall rules, without deploying separate firewalls or modifying VPC configurations — by subscribing to PANW from the DNS Firewall console through the embedded AWS Marketplace widget.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">What’s New with AWS</a> page.</p><p><strong>Price reductions </strong><br />AWS continues to look for ways to increase performance and lower prices for our customers. I noticed a few such efforts last week, so I’d like to share them:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/s3-vectors-reduces-query-charges-80-percent-large-indexes/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon S3 Vectors reduces query charges by up to 80% for large vector indexes</a> — This reduction lowers costs for customers running similarity search across large-scale AI, RAG, and semantic search workloads. The new pricing applies automatically with no application changes required.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-gamelift-servers-free-network-bandwidth/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon GameLift Servers introduces free network bandwidth</a> — Amazon GameLift Servers provides network bandwidth in and out of AWS at no additional charge for all instance types from generation 6 and later, including On-Demand and Spot, with no commitment required. You now pay only for your Amazon GameLift Servers instance hours; all network bandwidth is free.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/reduce-listing-fee-professional-services-aws-marketplace/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Marketplace reduces listing fee for professional services to 0.5% from 2.5%</a> — This reduction makes it more cost-effective for consulting partners, systems integrators, managed services providers and independent software vendors to transact their services through AWS Marketplace, while retaining the procurement and billing benefits that come with it.</li>
</ul><p>Learn more about AWS, browse and join upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS-led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?tab=upcoming?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused events</a> as well as <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summits</a> and <a href="https://aws.amazon.com/events/community-day/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Community Days</a>. Join the <a href="https://builder.aws.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development.</p><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Weekly Roundup</a>!</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="0c2c52cc-0bb5-418d-81d2-4832e452edfc" data-title="AWS Weekly Roundup: NY Summit recap, Local Zone in Hanoi, Grok 4.3 in Bedrock, price reductions, and more (June 22, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-ny-summit-recap-local-zone-in-hanoi-grok-4-3-in-bedrock-price-reductions-and-more-june-22-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-ny-summit-recap-local-zone-in-hanoi-grok-4-3-in-bedrock-price-reductions-and-more-june-22-2026/"/>
    <updated>2026-06-22T16:46:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/announcing-amazon-ec2-g7-instances-accelerated-by-nvidia-rtx-pro-4500-blackwell-server-edition-gpus/</id>
    <title><![CDATA[Announcing Amazon EC2 G7 instances accelerated by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the general availability of <a href="https://aws.amazon.com/ec2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Compute Cloud (Amazon EC2)</a> G7 instances, delivering high performance GPU acceleration for AI inference, graphics, and data analytics workloads.</p><p>AWS is the first major cloud provider to support NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs. G7 instances are accelerated by these GPUs with custom sixth-generation Intel Xeon Scalable processors, delivering up to 4.6x AI inference performance and up to 2.1x graphics performance compared to <a href="https://aws.amazon.com/ec2/instance-types/g6/">G6 instances</a>. G7 instances also deliver faster performance for GPU-accelerated analytics on <a href="https://aws.amazon.com/emr/">Amazon EMR</a> on <a href="https://aws.amazon.com/eks/">Amazon Elastic Kubernetes Service (Amazon EKS)</a>. G7 instances are well suited for a broad range of GPU-enabled workloads including AI inference, graphics rendering, video transcoding and analytics, spatial computing, virtual desktop infrastructure (VDI), and data analytics.</p><p>Here are improvements of G7 instances compared to previous generation:</p><ul><li><strong>Faster GPU memory</strong> – NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs offer 1.33 times the GPU memory capacity and 2.45 times the GPU memory bandwidth compared to G6 instances. With 32 GB of GPU memory per GPU, 5th Gen Tensor Cores, and 4th Gen RT Cores, G7 instances deliver enhanced AI inference and graphics performance.</li>
<li><strong>High performance networking and storage</strong> – G7 instances come with 700 Gbps of EFA-enabled networking throughput (7x compared to G6) enabling the low-latency, high-bandwidth connectivity that AI inference, graphics-intensive applications, and GPU-accelerated data analytics workloads need to perform at their best. G7 instances support up to 7.6 TB local NVMe SSD storage, enabling you to keep large models and datasets close to compute, reduce data transfer overhead, and improve throughput.</li>
<li><strong>Advanced video encoding and decoding engines</strong> – Ninth-generation NVENC and sixth-generation NVDEC engines support 4:2:2 encoding and decoding for high-resolution video workflows, delivering 1.5x concurrent video streams compared to previous-generation G6 instances.</li>
</ul><p><strong>EC2 G7 instance specifications</strong><br />G7 instances feature up to 8 NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs with up to 256 GB of total GPU memory (32 GB of memory per GPU) and custom Intel Xeon Scalable processors. They also are available in 7 sizes and support up to 192 vCPUs, up to 700 Gbps of network bandwidth, up to 768 GiB of system memory, and up to 7.6 TB of local NVMe SSD storage.</p><p>Here are the specs:</p><table class="c9"><tbody><tr class="c7"><td class="c6"><strong>Instance name</strong></td>
<td class="c6"><strong>GPUs</strong></td>
<td class="c6"><strong>GPU memory (GB)</strong></td>
<td class="c6"><strong>vCPUs</strong></td>
<td class="c6"><strong>Memory (GiB)</strong></td>
<td class="c6"><strong>Storage</strong></td>
<td class="c6"><strong>EBS bandwidth (Gbps)</strong></td>
<td class="c6"><strong>Network bandwidth (Gbps)</strong></td>
</tr><tr class="c8"><td class="c6"><strong>g7.2xlarge</strong></td>
<td class="c6">1</td>
<td class="c6">32</td>
<td class="c6">8</td>
<td class="c6">32</td>
<td class="c6">1 x 600</td>
<td class="c6">Up to 8</td>
<td class="c6">Up to 60</td>
</tr><tr class="c8"><td class="c6"><strong>g7.4xlarge</strong></td>
<td class="c6">1</td>
<td class="c6">32</td>
<td class="c6">16</td>
<td class="c6">64</td>
<td class="c6">1 x 600</td>
<td class="c6">8</td>
<td class="c6">Up to 100</td>
</tr><tr class="c8"><td class="c6"><strong>g7.8xlarge</strong></td>
<td class="c6">1</td>
<td class="c6">32</td>
<td class="c6">32</td>
<td class="c6">128</td>
<td class="c6">1 x 950</td>
<td class="c6">16</td>
<td class="c6">Up to 100</td>
</tr><tr class="c8"><td class="c6"><strong>g7.12xlarge</strong></td>
<td class="c6">2</td>
<td class="c6">64</td>
<td class="c6">48</td>
<td class="c6">192</td>
<td class="c6">1 x 1900</td>
<td class="c6">20</td>
<td class="c6">175</td>
</tr><tr class="c8"><td class="c6"><strong>g7.24xlarge</strong></td>
<td class="c6">4</td>
<td class="c6">128</td>
<td class="c6">96</td>
<td class="c6">384</td>
<td class="c6">1 x 3800</td>
<td class="c6">40</td>
<td class="c6">350</td>
</tr><tr class="c8"><td class="c6"><strong>g7.48xlarge</strong></td>
<td class="c6">8</td>
<td class="c6">256</td>
<td class="c6">192</td>
<td class="c6">768</td>
<td class="c6">2 x 3800</td>
<td class="c6">80</td>
<td class="c6">700</td>
</tr><tr class="c8"><td class="c6"><strong>g7.metal*</strong></td>
<td class="c6">8</td>
<td class="c6">256</td>
<td class="c6">192</td>
<td class="c6">768</td>
<td class="c6">2 x 3800</td>
<td class="c6">80</td>
<td class="c6">700</td>
</tr></tbody></table><p>* Coming soon</p><p>G7 instances support NVIDIA GPUDirect P2P for multi-GPU sizes, NVIDIA GPUDirect RDMA with EFA, and GPUDirect RDMA with EFA for <a href="https://aws.amazon.com/fsx/lustre/">Amazon FSx for Lustre</a>, enabling low-latency GPU-to-GPU communication for multi-GPU and multi-node workloads.</p><p>To get started with G7 instances, you can use the <a href="https://aws.amazon.com/ai/machine-learning/amis/">AWS Deep Learning AMIs (DLAMI)</a> or <a href="https://aws.amazon.com/marketplace/pp/prodview-z4aq5h62z2nv6">NVIDIA Workstation AMIs</a> with prepackaged GPU drivers for your AI inference and graphics workloads. To use G7 instances with Amazon EKS, build EKS AMIs with NVIDIA driver version R595 with <a href="https://docs.aws.amazon.com/eks/latest/userguide/eks-ami-build-scripts.html">EKS-provided automation</a><strong>.</strong> G7 instances support multiple operating systems including Amazon Linux, Ubuntu, RHEL, and Windows Server, with comprehensive NVIDIA driver integration providing compatibility with industry-standard graphics libraries including DirectX, Vulkan, and OpenGL.</p><p><strong>Get started today</strong><br />You can start using Amazon EC2 G7 instances today in two AWS regions: US East (Ohio) and US West (Oregon). To check future Regional expansion plans, look up the instance type in the <a href="https://aws.amazon.com/pt/cloudformation/"><strong>CloudFormation</strong></a> resources tab on the <a href="https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/">AWS Capabilities by Region</a> page.</p><p>G7 instances are offered through multiple purchasing options, including <a href="https://aws.amazon.com/ec2/pricing/on-demand/">On-Demand</a>, <a href="https://aws.amazon.com/savingsplans/compute-pricing/">Savings Plans</a>, and <a href="https://aws.amazon.com/ec2/spot/pricing/">Spot Instances</a>. <a href="https://aws.amazon.com/ec2/pricing/dedicated-instances/">Dedicated Instances</a> are also supported for the <code>12xlarge</code>, <code>24xlarge</code>, and <code>48xlarge</code> sizes. For detailed pricing, visit the <a href="https://aws.amazon.com/ec2/pricing/">Amazon EC2 Pricing</a> page.</p><p>Ready to get started? Launch G7 instances from the <a href="https://console.aws.amazon.com/ec2/">Amazon EC2 console</a>. For more details, head over to the <a href="https://aws.amazon.com/ec2/instance-types/g7/">Amazon EC2 G7 instances</a> page. We’d love to hear your feedback. Share it on <a href="https://repost.aws/tags/TAO-wqN9fYRoyrpdULLa5y7g/amazon-ec-2?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for EC2</a> or reach out through your usual AWS Support contacts.</p><p>– Daniel Abib</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="f5b19410-9974-48bd-877f-f1dbdd401b98" data-title="Announcing Amazon EC2 G7 instances accelerated by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs" data-url="https://aws.amazon.com/blogs/aws/announcing-amazon-ec2-g7-instances-accelerated-by-nvidia-rtx-pro-4500-blackwell-server-edition-gpus/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/announcing-amazon-ec2-g7-instances-accelerated-by-nvidia-rtx-pro-4500-blackwell-server-edition-gpus/"/>
    <updated>2026-06-18T23:22:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-ecs-introduces-new-high-resolution-metrics-for-faster-service-auto-scaling/</id>
    <title><![CDATA[Amazon ECS introduces new high-resolution metrics for faster service auto scaling]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p><a href="https://docs.aws.amazon.com/AmazonECS/latest/developerguide/service-auto-scaling.html">Amazon Elastic Container Service (Amazon ECS) service auto scaling</a> automatically adjusts task counts to meet workload demand with comprehensive scaling policies, including predictive scaling for recurring traffic patterns, scheduled scaling for planned events, and target tracking to scale dynamically on real-time metrics.</p><p>You can choose proactive scaling by using <a href="https://docs.aws.amazon.com/AmazonECS/latest/developerguide/predictive-auto-scaling.html">predictive scaling</a> (automatic) and <a href="https://docs.aws.amazon.com/AmazonECS/latest/developerguide/service-autoscaling-schedulescaling.html">scheduled scaling</a> (customer-defined), or reactive scaling by using <a href="https://docs.aws.amazon.com/AmazonECS/latest/developerguide/service-autoscaling-targettracking.html">target tracking</a> with just a target to scale on. Amazon ECS service auto scaling adjusts the number of tasks in an ECS service based on <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a> metrics, such as average CPU/Memory usage, request count per target, a custom metric such as queue depth, or demand surges by using advanced machine learning (ML) algorithms.</p><p>With today’s launch, Amazon ECS service auto scaling now detects and responds to load changes faster with support for high resolution (20-second) metrics and metric publishing optimizations. In AWS benchmarking tests, time to trigger scale-out improved from 363 seconds to 86 seconds (76% faster, 4.2x), and total time to scale and provision new tasks improved from 386 seconds to 109 seconds (72% faster, 3.5x)</p><p>This launch delivers three key benefits for your applications:</p><ul><li><strong>Improved performance and reliability</strong>: Faster scaling means, your application responds faster to demand surges, reducing latencies or failures for end users during demand surges.</li>
<li><strong>Right-size without compromise</strong>: Depending on the workload, you can reduce baseline task counts because scale-out now happens fast enough to handle traffic spikes without preemptive capacity padding. This directly reduces compute costs while maintaining application performance and availability.</li>
<li><strong>Simpler scaling configuration</strong>: Target tracking with high-resolution metrics delivers the aggressive scaling behavior that previously required custom scaling configurations, such as usage of step-scaling policies. One configuration change replaces custom engineering work.</li>
</ul><p><strong class="c6">How it works</strong><br />To use ECS faster service auto scaling, first enable high-resolution metrics for your ECS service, and then configure a target tracking scaling policy which uses high-resolution metrics. ECS faster service autoscaling works across all compute options on ECS: <a href="https://aws.amazon.com/fargate/">AWS Fargate</a>, <a href="https://aws.amazon.com/ecs/managed-instances/">ECS Managed Instances</a>, and <a href="https://aws.amazon.com/ec2">Amazon Elastic Compute Cloud (Amazon EC2)</a>. You can enable these metrics when you create or update your ECS service in the <a href="https://console.aws.amazon.com/ecs">Amazon ECS console</a>, or using <a href="https://docs.aws.amazon.com/sdkref/latest/guide/version-support-matrix.html">AWS SDKs and tools</a>, and <a href="https://aws.amazon.com/cloudformation/">AWS CloudFormation</a>.</p><p>When you create a service in the console, add 20-seconds resolution metrics in the <strong>Monitoring configuration</strong> section. These metrics incur additional CloudWatch costs while the standard resolution (60-seconds) is free.</p><p><img class="aligncenter wp-image-104695 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/17/2026-ecs-fast-autoscaling-metrics-create-service-1.jpg" alt="" width="1661" height="2560" /></p><p>In the <strong>Service auto scaling</strong> section, check <strong>Use service auto scaling</strong> and choose <strong>Target Tracking</strong> for the scaling policy type to use real-time data to scale the number of tasks that your service runs based on demand.</p><p>Then, choose a <strong>Scaling policy type</strong> for the target tracking. You can select <code>ECSServiceAverageCPUUtilizationHighResolution</code> or <code>ECSServiceAverageMemoryUtilizationHighResolution</code> as new metrics.</p><p><img class="aligncenter wp-image-104696 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/17/2026-ecs-fast-autoscaling-metrics-create-service-2.jpg" alt="" width="1800" height="2380" /></p><p>That’s it – your ECS service will use high resolution metrics for auto scaling.</p><p>To update an existing ECS service to use faster auto scaling, you first need to configure high resolution metrics via <strong>Update Service</strong>. Once deployment completes, your service will generate high-resolution metrics. You can then go to the <strong>Service and auto scaling</strong> tab from your service details to update scaling policy to use higher resolution metrics.</p><p><img class="aligncenter wp-image-104200 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/03/2026-ecs-fast-autoscaling-metrics-1.png" alt="" width="2007" height="1685" /></p><p>That’s all you need. Your ECS service now evaluates scaling decisions at 20-second intervals.</p><p>You can also use the <a href="https://aws.amazon.com/cli">AWS Command Line Interface (AWS CLI)</a> to enable new metrics in your ECS service through Application Auto Scaling. To learn more, visit the <a href="https://docs.aws.amazon.com/AmazonECS/latest/developerguide/target-tracking-faster-auto-scaling.html">faster auto scaling documentation</a>.</p><p><strong class="c6">Now available</strong><br />Faster service autoscaling with high-resolution metrics for Amazon ECS is available today. The feature itself has no additional cost, but high-resolution CloudWatch metrics introduce a new pricing dimension. For details, see the <a href="https://aws.amazon.com/cloudwatch/pricing/">CloudWatch pricing</a> page.</p><p>Give it a try today and send feedback to <a href="https://repost.aws/tags/TAefn4YSprR-uCBYmbofOpHw/amazon-elastic-container-service?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for ECS</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="22138c9e-f689-4e35-bf6b-52d1ebb0b65b" data-title="Amazon ECS introduces new high-resolution metrics for faster service auto scaling" data-url="https://aws.amazon.com/blogs/aws/amazon-ecs-introduces-new-high-resolution-metrics-for-faster-service-auto-scaling/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-ecs-introduces-new-high-resolution-metrics-for-faster-service-auto-scaling/"/>
    <updated>2026-06-18T23:06:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/top-announcements-of-the-aws-summit-in-new-york-2026/</id>
    <title><![CDATA[Top announcements of the AWS Summit in New York, 2026]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p class="c6">Today at the <a href="https://aws.amazon.com/events/summits/new-york/">AWS Summit in New York City</a>, Swami Sivasubramanian, AWS VP of Agentic AI, provided the day’s keynote. Here’s our roundup of the biggest announcements from the event:</p><p><strong>New in Amazon Bedrock AgentCore<br /></strong> We’re introducing new capabilities on Amazon Bedrock AgentCore: connecting AI agents to organizational, web, and paid knowledge, helping teams find and fix what’s going wrong in production, and enforcing controls that scale as agents grow more capable.</p><p><img class="alignnone wp-image-133707 size-full" src="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/06/16/knowledge-layers.png" alt="" width="3200" height="1800" /></p><p>Together, these capabilities help you build more capable agents faster, govern those agents with controls that scale, and improve them continuously. To learn more, read our <a href="https://aws.amazon.com/blogs/machine-learning/new-in-amazon-bedrock-agentcore-build-agents-with-broader-knowledge-and-continuous-learning/">blog post</a> covering all the new features.</p><ul><li><a href="https://aws.amazon.com/blogs/aws/introducing-amazon-bedrock-managed-knowledge-base-for-faster-more-accurate-enterprise-ai-applications">Introducing Amazon Bedrock Managed Knowledge Base for faster, more accurate enterprise AI applications</a> — You can build enterprise RAG pipelines with the managed Knowledge Base on Bedrock. It provides native data connectors, Smart Parsing for automatic multi-format data preparation, and an Agentic Retriever for complex multi-step queries—all integrated with AgentCore Gateway so developers can focus on business outcomes rather than infrastructure management.</li>
<li><a href="https://aws.amazon.com/blogs/aws/announcing-web-search-on-amazon-bedrock-agentcore-ground-your-ai-agents-in-current-accurate-web-knowledge">Announcing Web Search on Amazon Bedrock AgentCore: Ground your AI agents in current, accurate web knowledge</a> — You can use a fully managed web search tool that enables agents to ground responses in current, cited web knowledge with zero data egress from customer’ secured AWS environment. You can focus on building agents instead of manually adding web search to agents on Bedrock AgentCore and managing its infrastructure.</li>
<li><a href="https://aws.amazon.com/blogs/aws/aws-waf-adds-ai-traffic-monetization-capability-to-help-content-owners-charge-ai-bots-for-content-access/" rel="bookmark">AWS WAF adds AI traffic monetization capability to help content owners charge AI bots for content access</a> — You can use a new Bot Control capability that enables content providers and publishers price, meter, and collect payment from AI bots and agents accessing their content and APIs. AWS WAF now lets you set a price for that access, accept payment through third-party providers, and grant scoped access directly at the edge.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-bedrock-agentcore-harness-generally-available/">Amazon Bedrock AgentCore harness in now generally available</a> — You can do building and running production-grade AI agents in minutes—without coding orchestration loops—by defining your agent’s model, tools, skills, and instructions in configuration, with Bedrock AgentCore harness.</li>
</ul><p><strong>New in AI-based security tools</strong></p><ul><li><a href="https://aws.amazon.com/blogs/security/introducing-aws-continuum-security-at-machine-speed/">Introducing AWS Continuum: Security at machine speed</a> — AWS Continuum for code vulnerabilities, available in a gated preview, takes findings from across your environment, prioritizes by business impact, proves which are exploitable, and drives a fix through your own process.</li>
<li><a href="https://aws.amazon.com/blogs/aws/aws-security-agent-adds-threat-modeling-kiro-power-and-claude-code-plugin-and-more">AWS Security Agent (now part of AWS Continuum) adds threat modeling, Kiro power and Claude Code plugin, and more</a> — You can generate the new threat modeling (preview) to understand the full context of your application and identify threats with recommended mitigations using the STRIDE framework. You can also use pull request code scanning with remediation across major Git platforms, and IDE integrations via Kiro power, Claude Code plugin, and MCP — letting developers run security reviews and fix issues without context switching.</li>
</ul><p><strong>New in building AI-based applications </strong></p><ul><li><a href="https://kiro.dev/blog/introducing-kiro-for-ios/">Introducing Kiro for iOS</a> — Kiro introduces a native iOS app, available in a gated preview, built for real engineering work that gives developers a new surface to kick off, monitor, steer, and interact with their Kiro sessions directly from their phone. That means you can now start sessions, check back when they’re done, review diffs, and approve changes all while staying connected to your work with no laptop running.</li>
<li><a href="https://aws.amazon.com/blogs/aws/aws-devops-agent-adds-release-management-capabilities-to-assess-code-changes-before-production-preview">AWS DevOps Agent adds release management capabilities to assess code changes before production</a> — You can use a new release readiness review of code changes and autonomous release testing. These new features verify every change against the natural language standards you give to the DevOps Agent and run change-specific tests in production-like environments.</li>
<li><a href="https://aws.amazon.com/blogs/aws/proactively-reduce-tech-debt-autonomously-with-aws-transform-continuous-modernization-preview">Proactively reduce tech debt autonomously with AWS Transform – continuous modernization</a> — You can use continuous analysis (preview) to automatically scan your code repositories against configurable baselines and generates findings in hours, not weeks. Once you’ve identified and prioritized findings, you can configure autonomous remediations that generate pull requests for affected repositories automatically.</li>
</ul><p>In addition to the keynote announcements, we have other important launches this week:</p><ul><li><a href="https://aws.amazon.com/blogs/aws/amazon-s3-annotations-attach-rich-queryable-context-directly-to-your-objects/">Amazon S3 annotations: attach rich, queryable context directly to your objects</a> — Amazon S3 now lets you attach up to 1 GB of rich, mutable, and queryable context directly to your objects using annotations, purpose-built for AI agents and autonomous workflows that need to discover, understand, and act on data at scale without maintaining separate metadata systems.</li>
</ul></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="bd12acc0-5492-4676-adeb-5f6d18ff16b1" data-title="Top announcements of the AWS Summit in New York, 2026" data-url="https://aws.amazon.com/blogs/aws/top-announcements-of-the-aws-summit-in-new-york-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/top-announcements-of-the-aws-summit-in-new-york-2026/"/>
    <updated>2026-06-17T18:36:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-devops-agent-adds-release-management-capabilities-to-assess-code-changes-before-production-preview/</id>
    <title><![CDATA[AWS DevOps Agent adds release management capabilities to assess code changes before production (preview)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing a new release management capability in <a href="https://aws.amazon.com/devops-agent/">AWS DevOps Agent</a> that is now available in preview. AWS DevOps Agent is your always-available teammate that spans software changes and operations across AWS, multicloud, and on-premises environments. The practice of DevOps aims to make software change and operations smooth and increasingly autonomous, and AWS DevOps Agent delivers on both by leveraging its deep understanding of your environment, your services, their dependencies, and how they behave in production. Already generally available for post-deployment operations, it autonomously investigates incidents, provides root cause analysis and mitigation steps, and delivers targeted recommendations to prevent recurring issues. With today’s preview, AWS DevOps Agent adds release readiness review of code changes and autonomous release testing. These new features verify every change against the natural language standards you give to the DevOps Agent and run change-specific tests in production-like environments. AWS DevOps Agent now supports teams from code creation to production, helping reviewers and testers keep pace with the volume of AI-generated code.</p><p>As development teams adopt AI coding tools, the volume of pull requests moving through delivery pipelines has increased faster than review and testing processes can handle. When teams are under pressure to keep up, reviews are approved without thorough examination, and test environments drift from production. The value that coding agents generate sits waiting in review queues instead of reaching end users. At the same time, AI models are increasingly capable of catching functional and security issues that human reviewers might miss under time pressure, making speedy and safe delivery a requirement rather than a tradeoff.</p><p>The release readiness review feature evaluates every code change against production requirements, dependency safety, and the standards and best practices you provide to the DevOps Agent. The agent checks cross-repository dependency risks that could affect other services, access control changes against AWS Well-Architected Framework best practices, and compliance with any standards you have defined. When no standards are provided, the agent applies general best practices. As part of the review, the agent also runs your software in an AWS-managed isolated environment, executing lightweight user journey tests to verify the software builds, runs, and passes basic functional checks before the change enters the pipeline. Findings appear in the AWS DevOps Agent console and as comments on pull requests in GitHub or GitLab. You can also invoke reviews directly from your IDE through the Kiro power or Claude Code plugin, so developers can identify and fix dependency risks, standards violations, and access control issues before the change is committed to version control.</p><p>The autonomous release testing feature goes further, generating and running change-specific test plans for web and API-based applications in customer-provisioned, production-like environments before the change merges. Rather than running a static test suite, the agent reasons about what the change does and constructs tests tailored to it, covering functional correctness, behavioral regressions, and integration scenarios that a manually maintained test plan might not anticipate. Every test run produces structured artifacts including metrics, logs, traces, and an execution summary, giving reviewers a consistent record of what was tested and what the results were.</p><p><strong>Getting started with AWS DevOps Agent release management<br /></strong> This walkthrough shows how to run an on-demand release readiness review using the AWS DevOps Agent web app. Before you begin, confirm that you have at least one <a href="https://docs.aws.amazon.com/devopsagent/latest/userguide/connecting-to-cicd-pipelines-connecting-github.html">GitHub</a> or <a href="https://docs.aws.amazon.com/devopsagent/latest/userguide/connecting-to-cicd-pipelines-connecting-gitlab.html">GitLab</a> repository connected to your Agent Space. Once your repositories are connected, AWS DevOps Agent will index your code and build a knowledge graph of cross-repository and cloud dependencies.</p><p>To open the web app, navigate to the <a href="https://console.aws.amazon.com/aidevops/">AWS DevOps Agent console</a>, select your <strong>Agent Space</strong>, and choose the <strong>Web app</strong> tab. Choose <strong>Operator access</strong> to open the web app.</p><p>Without standards configured, the agent applies general best practices. To tailor reviews to your internal standards, navigate to <strong>Knowledge</strong>, then choose the <strong>Instructions</strong> tab. You will see a list of instruction sets, each scoped to a specific agent or task. Choose <strong>View</strong> next to <strong>Release readiness review</strong> to edit the instructions for production-readiness change review. Write your internal standards in plain English. For example, you can define infrastructure and data standards on encryption or network access rules, best practices that warn without blocking such as logging and observability requirements, and sensitive data classification best practices that identify applications or resources requiring higher security measures. To apply instructions across all agents in your space, choose <strong>View</strong> next to <strong>All agents</strong>.</p><p><img class="alignnone wp-image-104568 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/14/1214659328598974-4.png" alt="" width="1924" height="967" /></p><p>You can trigger a release readiness review in two ways: by submitting a pull request to a connected repository, or by entering an on-demand query in the chat interface. To run an on-demand review from chat, choose <strong>New chat</strong> and enter a request such as:</p><p><code>Perform a production risk analysis on my repository branch</code></p><p>The agent will ask for the repository and branch you want to analyze. You can provide a branch name, a pull request number, or a commit SHA. Once you confirm your selection, the agent queues the review and analyzes the change for production risks, including infrastructure impacts, configuration changes, and potential issues.</p><p>After the review completes, you can ask follow-up questions directly in the chat to explore the findings in more detail. For example, you can ask which downstream consumers a change affects, and the agent will return a structured breakdown of in-repository and cross-repository consumers that will break, the specific files and line numbers affected, and the recommended steps to resolve the issue before deployment.</p><p><img class="alignnone wp-image-104569 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/14/1214659328598974-5.png" alt="" width="1168" height="968" /></p><p>After submitting a review request, navigate to <strong>Changes</strong> in the left navigation pane. The <strong>Proposed changes</strong> table shows each review that has run, including the proposed change description, its source, category, status, and when it was created. You can filter by category or status to find specific reviews, or search by name using the search bar. Choose any entry to open the full execution detail.</p><p><img class="alignnone wp-image-104571 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/14/1214659328598974-6.png" alt="" width="1641" height="516" /></p><p>The <strong>Timeline</strong> tab shows the agent’s step-by-step reasoning process, including the tools it called, the dependencies it consulted, and the observations it made at each step. Each entry is timestamped, giving you a complete record of how the agent built its understanding of the change and reached its conclusion.</p><p><img class="alignnone wp-image-104572 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/14/1214659328598974-8.png" alt="" width="1283" height="901" /></p><p>Choose the <strong>Report</strong> tab to see the final recommendation. The report opens with a summary header showing the recommended action, the number of critical issues found, the commit revision, and the number of files changed. The recommended action is either <strong>BLOCK</strong>, <strong>Proceed with Caution</strong>, or <strong>Safe to Release</strong>.</p><p>Below the summary header, the <strong>Analysis</strong> section explains why the recommendation was made, citing specific risks and the evidence the agent found to support its conclusion. The <strong>Issues</strong> section lists each finding by severity, giving you a prioritized view of what needs to be addressed before the change can proceed. The <strong>Recommendations</strong> section provides specific, actionable steps the developer can take to resolve each issue. Finally, the <strong>Changes</strong> section lists each file that was modified, with the type of change, the category it falls under, and a description of what was changed, so reviewers have a complete picture of what the change does before it merges.</p><p><img class="alignnone wp-image-104573 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/14/1214659328598974-7.png" alt="" width="1289" height="1072" /></p><p>You can also invoke the autonomous release testing feature directly from the chat interface. To run an autonomous release test on a web or API-based application, choose <strong>New chat</strong> and enter a query such as:</p><p><code>Run a release test on my application deployed at [application URL]</code></p><p>The agent generates a change-specific test plan and executes it in your provisioned environment. Results appear in <strong>Changes</strong>, where you can review the execution steps and a structured summary of what was tested.</p><p><strong>Get started today</strong><br />The release readiness review and autonomous release testing features for AWS DevOps Agent are available in preview. These features are available at no additional cost during preview in the US East (N. Virginia) Region. For pricing information on other AWS DevOps Agent features, visit the <a href="https://aws.amazon.com/devops-agent/pricing/">AWS DevOps Agent pricing</a> page.</p><p>For configuration details, visit the <a href="https://docs.aws.amazon.com/devopsagent/latest/userguide/getting-started-with-aws-devops-agent.html">AWS DevOps Agent user guide</a>.</p><a href="https://www.linkedin.com/in/esrakayabali/">— Esra</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="c44f7fc9-8ce8-4758-a5c9-4ea307738900" data-title="AWS DevOps Agent adds release management capabilities to assess code changes before production (preview)" data-url="https://aws.amazon.com/blogs/aws/aws-devops-agent-adds-release-management-capabilities-to-assess-code-changes-before-production-preview/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-devops-agent-adds-release-management-capabilities-to-assess-code-changes-before-production-preview/"/>
    <updated>2026-06-17T16:57:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-security-agent-adds-threat-modeling-kiro-power-and-claude-code-plugin-and-more/</id>
    <title><![CDATA[AWS Security Agent adds threat modeling, Kiro power and Claude Code plugin, and more]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>At re:Invent 2025, we <a href="https://aws.amazon.com/blogs/aws/new-aws-security-agent-secures-applications-proactively-from-design-to-deployment-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">previewed</a> <a href="https://aws.amazon.com/security-agent/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Agent</a> (now part of <a href="http://aws.amazon.com/continuum/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Continuum</a>), a frontier agent that proactively secures your applications throughout the development lifecycle across all your environments. You can perform on-demand penetration testing customized to your application, discovering and reporting security risks verified through exploitability testing.</p><p>Since the preview, we announced general availability for <a href="https://aws.amazon.com/about-aws/whats-new/2026/03/aws-security-agent-ondemand-penetration/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">on-demand penetration testing</a> and the preview of <a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-security-agent-full-repository-code-review/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">full repository code review</a> that performs deep, context-aware security analysis of your entire codebase.</p><p>Today, we’re introducing more features based on customer feedback:</p><ul><li><strong>Code review updates (Preview)</strong> — You can now use pull request scanning with remediation, security requirements packs, and simulated validation. New integrations support GitHub, GitLab, Bitbucket, and Confluence.</li>
<li><strong>Threat modeling (Preview)</strong> — AWS Security Agent analyzes your design documents or application source code, understands the full context of your application architecture and identifies threats with recommended mitigations using the STRIDE framework.</li>
<li><strong>Kiro power, Claude Code plugin, and MCP integration</strong> — You can run code reviews, generate threat models, and remediate findings directly from your IDE, CLI, or any AI-powered IDE through an open MCP integration, with results surfacing inline without any context switching.</li>
</ul><p>Let’s take a closer look at each launch!</p><p><img class="aligncenter size-full wp-image-104509 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/11/2026-security-agent-updates-home.jpg" alt="" width="1800" height="994" /></p><p><strong>Code review updates</strong><br />You can now connect to GitLab and Bitbucket in addition to GitHub— supporting both SaaS and self-hosted versions, so you can trigger scans regardless of where code lives. You can also integrate Confluence to reference your existing documentation as context for reviews.</p><p>To get started, choose <strong>Enable code review</strong> or update your code review setting in the <a href="https://console.aws.amazon.com/securityagent/agents/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Security Agent console</a>.</p><p><img class="aligncenter size-full wp-image-104510 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/11/2026-security-agent-updates-1-codereivew-repo.jpg" alt="" width="1800" height="1018" /></p><p>AWS Security Agent introduces deep, reasoning-based analysis on every pull request as well as full repository to identify complex vulnerabilities that go beyond pattern-matching. It checks against your organizational security requirements and common security risks to catch what other tools can’t. To get started, access the Security Agent web application and run your code review.</p><p><img class="aligncenter size-full wp-image-104511 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/11/2026-security-agent-updates-1-codereivew-results.jpg" alt="" width="1800" height="1025" /></p><p>You’ll receive fix commits and remediation guidance directly in your GitHub, GitLab, or Bitbucket workflow, while your security teams configure the repositories to be monitored and intervene on critical issues. AWS Security Agent validates findings in simulated environments to demonstrate proof of exploitability. This embeds security expertise across all repositories, reducing security-related delays in the development pipeline.</p><p>To learn more about new code review features, visit <a href="https://docs.aws.amazon.com/securityagent/latest/userguide/perform-code-review-scan.html">Create a code review</a> in the AWS Security Agent User Guide.</p><p><strong>Design review updates<br /></strong> You can continuously validate your security requirements across every design and code review with managed compliance packs: <a href="https://aws.amazon.com/waf/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS WAF</a>, <a href="https://docs.aws.amazon.com/config/latest/developerguide/operational-best-practices-for-nist-csf.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">NIST CSF</a>, <a href="https://aws.amazon.com/compliance/pci-faqs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">PCI DSS</a>, and AWS best practices, or import your own organizational requirements directly from internal documents or Confluence. Every finding maps back to your compliance posture, so teams stay audit-ready as they build.</p><p class="jss491" data-pm-slice="1 1 []">To learn more, visit the <a href="https://docs.aws.amazon.com/securityagent/latest/userguide/perform-design-review.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">design review documentation</a>.</p><p><strong>Threat modeling</strong><br />AWS Security Agent generates threat models based on your design documentation or code repository, creates and build context about the application, including data flows, architecture, and trust boundaries. It maps out all components of your application, identifies potential threat actors and attack vectors, determines where weaknesses may exist, and prioritizes threats so you know what to address first.</p><p>To get started, choose <strong>Enable threat model</strong> and Connect source code repository in the <a href="https://console.aws.amazon.com/securityagent/agents/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Security Agent console</a>.</p><p><img class="aligncenter wp-image-104640 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/16/2026-security-agent-updates-2-thread-model.png" alt="" width="1275" height="827" /></p><p>To learn more, visit the <a href="https://docs.aws.amazon.com/securityagent/latest/userguide/perform-threat-model.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">threat modeling documentation</a>.</p><p><strong>Kiro power and Claude Code plugin for Security Agent</strong><br />AWS Security Agent introduces a new <a href="https://github.com/kirodotdev/powers/tree/main/aws-security-agent">Kiro power</a> and Claude Code plugin (coming soon) and can be integrated with any AI IDE through an open MCP integration to secure your applications. You can trigger threat models and code reviews directly from your IDE, with results surfacing inline without any context switching.</p><p>To get started, install the <a href="https://github.com/kirodotdev/powers/tree/main/aws-security-agent">Kiro power</a>, and run your prompts. The Kiro power uses the <a class="Hyperlink SCXW112479336 BCX2" href="https://github.com/awslabs/mcp/tree/main/src/aws-security-agent-server" target="_blank" rel="noreferrer noopener">AWS Security Agent MCP</a> server. You can get started with the power by asking “<code>Set up AWS Security Agent</code>“. Kiro will check if you have an Agent Space and ask if you would like to use the existing one or create a new one.</p><p><img class="aligncenter wp-image-104642 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/16/2026-security-agent-updates-3-kiro-power-1.jpg" alt="" width="1700" height="1057" /></p><p>With the Kiro power for Security Agent, you can catch vulnerabilities on every pull request as you build and scan an entire repository to surface accumulated risk by asking “<code>Run a full security scan on this repo</code>“. The Security Agent power includes an Agent hook to evaluate if a code review diff scan should be started after the Kiro agent has completed its turn. Before deploying to production, you can run a penetration test from your CLI to find what most scanners miss. Security Agent closes the loop by validating every finding and generating ready-to-implement code fixes.</p><p class="jss491" data-pm-slice="1 1 []">You can pull the findings back into your development environment by asking “<code>help me remediate my findings</code>“. The Kiro power for AWS Security Agent will download findings to your local workspace, prioritize the most critical finding, and offer to start a bugfix spec session. You can iterate on fixing the findings using their familiar IDE with their existing tooling, steering, powers, and MCP servers.</p><p><img class="aligncenter wp-image-104643 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/16/2026-security-agent-updates-3-kiro-power-code-review.jpg" alt="" width="1700" height="1056" /></p><p>You can also run threat models through the Kiro power in the IDE by asking “<code>Build a threat model for this application</code>“. The generated threat model is saved to <code>.security-agent/threat_model.md</code>. </p><p>To learn more, visit the <a href="https://github.com/kirodotdev/powers/tree/main/aws-security-agent">Kiro power for Security Agent</a>.</p><p><strong class="c7">Now available</strong><br />AWS Security Agent understands the full security context across your software development lifecycle by covering design-time security (design reviews and threat modeling in preview), development-time security (code review in preview), and deployment-time security (penetration testing in GA), in a single, unified agentic offering. To learn more, visit the <a href="https://aws.amazon.com/security-agent/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Agent product page</a> and the <a href="https://docs.aws.amazon.com/securityagent/latest/userguide/what-is.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">technical documentation</a>.</p><p>These features are now available in AWS commercial Regions where AWS Security Agent is available. For Regional availability and the future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>. For detailed pricing information and to access our 2-month free trial offer, please visit the <a id="link-self:r8l:" class="awsui_link_4c84z_1hknd_145 awsui_variant-primary_4c84z_1hknd_280 awsui_font-size-body-m_4c84z_1hknd_478" href="https://aws.amazon.com/security-agent/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-analytics-type="eventDetail" data-analytics="link-ga-pricing-page" data-awsui-analytics="{&quot;action&quot;:&quot;click&quot;,&quot;detail&quot;:{&quot;label&quot;:{&quot;root&quot;:&quot;self&quot;},&quot;external&quot;:&quot;true&quot;,&quot;href&quot;:&quot;https://aws.amazon.com/security-agent/pricing/&quot;},&quot;component&quot;:{&quot;name&quot;:&quot;awsui.Link&quot;,&quot;label&quot;:{&quot;root&quot;:&quot;self&quot;},&quot;properties&quot;:{&quot;variant&quot;:&quot;primary&quot;}}}" aria-label="AWS Security Agent pricing page (Opens in a new tab)" data-analytics-funnel-value="link:r8k:">AWS Security Agent pricing page</a>.</p><p>Give it a try in the <a href="https://console.aws.amazon.com/securityagent/agents/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Security Agent console</a> and send feedback to <a href="https://repost.aws/tags/TAujmCOJj0TSykKSuMsqRwZQ/aws-security-agent?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Security Agent</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy">Channy</a></p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="225cd790-3f4d-4b52-9525-bddd1a725c1e" data-title="AWS Security Agent adds threat modeling, Kiro power and Claude Code plugin, and more" data-url="https://aws.amazon.com/blogs/aws/aws-security-agent-adds-threat-modeling-kiro-power-and-claude-code-plugin-and-more/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-security-agent-adds-threat-modeling-kiro-power-and-claude-code-plugin-and-more/"/>
    <updated>2026-06-17T16:54:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-s3-annotations-attach-rich-queryable-context-directly-to-your-objects/</id>
    <title><![CDATA[Amazon S3 annotations: attach rich, queryable context directly to your objects]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing a new metadata capability for <a href="https://aws.amazon.com/s3/">Amazon Simple Storage Service (Amazon S3)</a> called annotations, enabling you to attach rich, large-scale business context directly to your objects. You can store up to 1,000 named annotations per object, each up to 1 MB in size, totaling up to 1 GB per object, in flexible formats like JSON, XML, YAML, or plain text. You can modify or delete an annotation at any time, without re-writing your objects, making it easy to keep your object context current.</p><p>Organizations are building AI agents and autonomous workflows that need to find, understand, and act on data without human intervention. To support these agentic workflows, you need metadata that can evolve alongside the data, scale to petabytes of objects, and remain queryable without expensive retrieval.</p><p>With S3 annotations, you can store context such as AI-generated transcripts, content ratings, or technical specifications directly alongside your objects. Your context moves automatically with the object during copy, replication, and cross-region transfers, and S3 removes it when you delete the object. When you enable <a href="https://aws.amazon.com/s3/features/metadata/">S3 Metadata</a>, annotations automatically flow into fully managed annotation tables that you can query with <a href="https://aws.amazon.com/athena/">Amazon Athena</a> and other analytics engines.</p><p><strong>Common use cases</strong><br />Annotations solve complex metadata challenges across industries:</p><ul><li><strong>Media &amp; Entertainment</strong>: Track transcripts, content moderation results, subtitle files, and licensing metadata as separate annotations on video assets, eliminating the need to synchronize metadata across multiple media asset management systems.</li>
<li><strong>Financial Services</strong>: Attach AI-generated investment summaries and sentiment analysis to research documents, enabling autonomous research agents to discover relevant datasets through natural-language queries without maintaining separate metadata databases.</li>
<li><strong>Life Sciences</strong>: Annotate clinical trial data with regulatory status, patient cohort details, and approval chains, making compliance audits faster while keeping full context accessible for archived data in Amazon S3 Glacier storage classes without retrieval charges.</li>
</ul><p><strong>How annotations address metadata challenges</strong><br />Amazon S3 already supports several ways to describe your objects. System-defined metadata captures properties like size and storage class. Object tags support operational tasks like access control and lifecycle management. User-defined metadata lets you add small amounts of custom information at upload time.</p><p>While these capabilities work well for their intended purposes, they have limitations when you need to attach much richer context without building and maintaining separate metadata systems. Annotations address these needs by providing metadata capabilities at a fundamentally different scale and flexibility, offering mutable, queryable context per object compared to 10 immutable tags or 2 KB of headers.</p><table class="c10"><tbody><tr class="c8"><td class="c6"><strong>Capability</strong></td>
<td class="c6"><strong>Max size</strong></td>
<td class="c6"><strong>Mutable?</strong></td>
<td class="c7"><strong>Best for</strong></td>
</tr><tr class="c9"><td class="c6">System-defined metadata</td>
<td class="c6">Fixed</td>
<td class="c6">No</td>
<td class="c7">Object properties (size, storage class, creation time)</td>
</tr><tr class="c9"><td class="c6">User-defined metadata</td>
<td class="c6">2 KB</td>
<td class="c6">No (set at upload)</td>
<td class="c7">Small custom key-value pairs</td>
</tr><tr class="c9"><td class="c6">Object tags</td>
<td class="c6">10 tags, 128/256 characters per key/value</td>
<td class="c6">Yes</td>
<td class="c7">Access control, lifecycle rules, cost allocation</td>
</tr><tr><td class="c6"><strong>Annotations</strong></td>
<td class="c6"><strong>1 GB (1,000 × 1 MB)</strong></td>
<td class="c6"><strong>Yes</strong></td>
<td class="c7"><strong>Rich business context (JSON, XML, YAML, plain text)</strong></td>
</tr></tbody></table><p>Today, metadata describing S3 objects often lives in separate databases or sidecar files, requiring complex synchronization workflows that can exceed data storage costs. When you enable S3 Metadata annotation tables, this context becomes queryable at scale through Amazon Athena. AI agents can discover your data through natural language with the <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/storage-lens-s3-tables-ai-tools.html">S3 Tables MCP server</a>, which provides a standardized interface for AI models to query your annotations. You can query annotations for objects in any storage class, without restoring the objects or paying retrieval charges.</p><p><strong>Getting started with annotations</strong><br />To start using annotations, make sure your <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (IAM)</a> policy or bucket policy grants permissions for the <code>s3:PutObjectAnnotation</code> and <code>s3:GetObjectAnnotation</code> actions. You can then add annotations to any existing or new S3 object using the <code>PutObjectAnnotation</code> API.</p><p><img class="aligncenter wp-image-104564 size-full c11" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/13/2026-s3-annotations-add.png" alt="" width="1244" height="650" /></p><p>For example, a media company can attach technical specifications and AI-produced summaries to a video asset using the <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a>:</p><pre class="lang-bash"># Create a JSON file with technical metadata
cat &gt; mediainfo.json &lt;&lt; 'EOF'
{"codec":"H.265","resolution":"3840x2160","audio_tracks":8,"frame_rate":29.97}
EOF
# Attach it as an annotation
aws s3api put-object-annotation \
  --bucket my-media-bucket \
  --key videos/documentary-2026.mp4 \
  --annotation-name mediainfo \
  --annotation-payload ./mediainfo.json
</pre><pre class="lang-bash"># Attach a plain-text AI-generated summary as a separate annotation
echo "A 90-minute nature documentary covering wildlife migration patterns across three continents, featuring aerial footage and underwater sequences. Languages: English, Spanish, Portuguese." &gt; ai_summary.txt
aws s3api put-object-annotation \
  --bucket my-media-bucket \
  --key videos/documentary-2026.mp4 \
  --annotation-name ai_summary \
  --annotation-payload ./ai_summary.txt
</pre><p>These commands attach two separate annotations to the same video object. The <code>mediainfo</code> annotation stores structured technical specifications as JSON, while the <code>ai_summary</code> annotation stores a text description. Each annotation is identified by a unique name, and you can read and modify each one independently. With unique names for each annotation, you can use different annotations to support multiple concurrent enrichment workflows, for example, one team adding technical metadata while another team adds content classifications, without interfering with each other.</p><p><img class="aligncenter wp-image-104565 size-full c11" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/13/2026-s3-annotations-list.png" alt="" width="1169" height="604" /></p><p>Retrieve a specific annotation using the <code>GetObjectAnnotation</code> API:</p><pre class="lang-bash">aws s3api get-object-annotation \
  --bucket my-media-bucket \
  --key videos/documentary-2026.mp4 \
  --annotation-name mediainfo \
  ./mediainfo-output.json
</pre><p>To see all annotations attached to an object, use the <code>ListObjectAnnotations</code> API:</p><pre class="lang-bash">aws s3api list-object-annotations \
  --bucket my-media-bucket \
  --key videos/documentary-2026.mp4
</pre><p>When you no longer need a specific annotation, remove it using the <code>DeleteObjectAnnotation</code> API:</p><pre class="lang-bash">aws s3api delete-object-annotation \
  --bucket my-media-bucket \
  --key videos/documentary-2026.mp4 \
  --annotation-name mediainfo
</pre><p>You can update an existing annotation at any time by calling <code>PutObjectAnnotation</code> again with the same annotation name. For large objects uploaded using multipart upload, attach annotations after completing the multipart upload using the <code>PutObjectAnnotation</code> API.</p><p><strong>Querying annotations at scale with S3 Metadata tables</strong><br />Attaching annotations to individual objects is useful, but the real power comes when you query across all your annotations at scale. When you enable S3 Metadata annotation tables on your bucket, S3 automatically indexes your annotations into a fully managed <a href="https://iceberg.apache.org/">Apache Iceberg</a> table, called an annotation table. You can query annotation tables with Amazon Athena or any Iceberg-compatible engine.</p><p>To enable annotation tables, use the S3 console or the <code>CreateBucketMetadataConfiguration</code> API. The following example creates a new metadata configuration with annotation tables enabled while keeping journal tables for change tracking and disabling the live inventory table:</p><pre class="lang-json">{
  "JournalTableConfiguration": {
    "RecordExpiration": { "Expiration": "DISABLED" }
  },
  "InventoryTableConfiguration": { "ConfigurationState": "DISABLED" },
  "AnnotationTableConfiguration": {
    "ConfigurationState": "ENABLED",
    "Role": "arn:aws:iam::123456789012:role/S3MetadataAnnotationRole"
  }
}
</pre><p>This configuration tells S3 to automatically capture all your annotations in a queryable table. Once applied, any annotation you attach to objects in this bucket will appear in the table within approximately one hour.</p><p>If the bucket already has a metadata configuration, use the <code>UpdateBucketMetadataAnnotationTableConfiguration</code> API:</p><pre class="lang-bash">aws s3api update-bucket-metadata-annotation-table-configuration \
  --bucket my-media-bucket \
  --annotation-table-configuration '{"ConfigurationState":"ENABLED","Role":"arn:aws:iam::123456789012:role/S3MetadataAnnotationRole"}'
</pre><p>Once enabled, your annotations automatically flow into the annotation table. Journal tables update in near real time, while annotation tables refresh within an hour. Unlike traditional metadata tables that require predefined schemas, annotation tables automatically adapt to any JSON, XML, or YAML structure you write. Each annotation becomes a row in the table with its content stored in a <code>text_value</code> column, letting you query across all annotations without schema migrations.</p><p>If you enable annotation tables on a bucket that already has annotated objects, S3 automatically backfills existing annotations into the table. The backfill process runs in the background and can take several hours to days depending on the number of objects.</p><p>For example, to find all video assets with more than 8 audio tracks across your entire bucket using Amazon Athena:</p><pre class="lang-sql">SELECT DISTINCT bucket, object_key
FROM "s3tablescatalog/aws-s3"."b_my_media_bucket"."annotation"
WHERE name = 'mediainfo'
AND CAST(json_extract_scalar(text_value, '$.audio_tracks') AS INTEGER) &gt; 8
</pre><p>This query scans the annotation table for all annotations named <code>mediainfo</code>, extracts the <code>audio_tracks</code> field from the JSON content, and returns objects where the count exceeds 8.</p><p>Or to find all objects that received new annotations in the last 24 hours through the journal table:</p><pre class="lang-sql">SELECT bucket, key, version_id, record_timestamp, annotation.name
FROM "s3tablescatalog/aws-s3"."b_my_media_bucket"."journal"
WHERE record_timestamp &gt;= (current_date - interval '1' day)
AND annotation.name IS NOT NULL
AND record_type IN ('CREATE_ANNOTATION', 'DELETE_ANNOTATION')
</pre><p>This query uses the journal table to track annotation changes in near real time, which is ideal for building event-driven workflows that respond to new or deleted annotations.</p><p>You can also use natural language to search objects by their annotations using agents in <a href="https://aws.amazon.com/sagemaker/unified-studio/">Amazon SageMaker Unified Studio</a> or any IDE with the S3 Tables MCP server. For example, asking “find all PG-rated movies with Spanish subtitles from 2023” returns results in seconds instead of the hours it would take querying multiple disconnected systems.</p><p><strong class="c12">Get started today</strong><br />You can start using Amazon S3 annotations today in all AWS Regions, including the AWS China Regions. Annotation tables are available in all AWS Regions where S3 Metadata is available.</p><p>Whether you’re building AI agents that need to discover data autonomously, managing petabytes of media assets with complex metadata, or tracking compliance context for archived datasets, annotations give you the scale and flexibility to attach rich metadata directly to your objects without managing separate systems.</p><p>Annotation storage is always billed at S3 Standard rates, even if the parent object is in S3 Glacier or another storage class. For full pricing details, visit the <a href="https://aws.amazon.com/s3/pricing/">Amazon S3 pricing page</a>.</p><p>To learn more and get started, visit the <a href="https://aws.amazon.com/s3/features/metadata/">Amazon S3 Metadata overview page</a> and the <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/annotations.html">Amazon S3 documentation</a>. Send feedback to <a href="https://repost.aws/tags/TADSTjraA0Q4-a1dxk6eUYaw/amazon-simple-storage-service">AWS re:Post for S3</a> or through your usual AWS Support contacts.</p><p>Daniel Abib</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="a0aecdb6-ec22-4137-b7bd-e58708d44a16" data-title="Amazon S3 annotations: attach rich, queryable context directly to your objects" data-url="https://aws.amazon.com/blogs/aws/amazon-s3-annotations-attach-rich-queryable-context-directly-to-your-objects/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-s3-annotations-attach-rich-queryable-context-directly-to-your-objects/"/>
    <updated>2026-06-17T01:13:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/announcing-web-search-on-amazon-bedrock-agentcore-ground-your-ai-agents-in-current-accurate-web-knowledge/</id>
    <title><![CDATA[Announcing Web Search on Amazon Bedrock AgentCore: Ground your AI agents in current, accurate web knowledge]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the general availability of Web Search on <a href="https://aws.amazon.com/bedrock/agentcore/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock AgentCore</a>, a fully managed tool that enables agents to ground responses in current, cited web knowledge with zero data egress from customer’s secured AWS environment.</p><p>Web Search uses a built-in connector target on Bedrock AgentCore Gateway using the Model Context Protocol (MCP). Your agent sends a natural-language query, and Web Search returns most relevant snippets, source URLs, titles, and publication dates that the model can reason over to produce a grounded response.</p><p><img class="aligncenter wp-image-104652 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/16/2026-agentcore-websearch-diagram-3.jpg" alt="" width="2532" height="604" /></p><p>It is built on Amazon’s search infrastructure, informed by years of experience powering agentic search experiences across <a href="https://www.amazon.com/alexaplus/dp/B0CXRRF584?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Alexa+</a>, <a href="https://aws.amazon.com/quick/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Quick</a>, and <a href="https://kiro.dev/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Kiro</a>. It uses a multi-source grounding approach that combines Amazon’s web index with structured knowledge graph data. Beyond standard web results, this gives agents access to Amazon Knowledge Graph with verified facts, helping them retrieve more relevant and accurate responses than traditional web search alone.</p><p>With this launch, you can focus on building agents instead of manually adding web search to agents on Bedrock AgentCore and managing its infrastructure. Your AI agent looks at user question, retrieves the latest facts, and then takes any necessary action grounded in current developments beyond a model’s training data. You can also meet enterprise governance policies without sending user prompts and retrieval queries to external search API providers outside of AWS.</p><p><strong class="c6">Web Search on Bedrock AgentCore in action</strong><br />To get started, create the Bedrock AgentCore Gateway with Web Search tool target in the <a href="https://console.aws.amazon.com/bedrock-agentcore/home?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Bedrock AgentCore console</a>. When the Gateway URL is created, you can interact with API call, Command Line Interface (CLI), or MCP Inspector.</p><p>To add Web Search tool target when creating the Gateway, choose <strong>MCP target</strong> as a target protocol and <strong>Connectors</strong> as a target type. You can select the <strong>Web Search tool</strong> as a preconfigured target to retrieve most relevant web search results including links, snippets, and metadata.</p><p><img class="aligncenter wp-image-104633 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/15/2026-agentcore-websearch-add-gateway-target.jpg" alt="" width="1800" height="1970" /></p><p>After creating your gateway, you can find the Web Search tool target on the detail page of your gateway. You can also add a new Web Search tool target to an existing gateway.</p><p><img class="aligncenter size-full wp-image-104274 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/2026-agentcore-websearch-add-gateway-detail.png" alt="" width="2406" height="2618" /></p><p>To interact with Web Search tool, use the sample invocation code in the <strong>View invocation code</strong> section. You can use code snippets through Python codes with API requests, MCP Python SDK, Strands MCP Client, and MCP Inspector.</p><p>For example, you can interact with the <a href="https://modelcontextprotocol.io/docs/tools/inspector">MCP Inspector</a>, an interactive developer tool for testing and debugging MCP servers. When you connect to the MCP server through the <strong>Gateway resource URL</strong>, you will find a Web Search tool for each connector target on the Gateway. Enter input the web search query and choose <strong>Run Tool</strong> to get the results.</p><p><img class="aligncenter wp-image-104703 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/17/2026-agentcore-websearch-mcp-inspector-1.jpg" alt="" width="1800" height="1258" /></p><p>To learn more about how to use Web Search on Bedrock AgentCore, visit the <a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Bedrock AgentCore Gateway documentation</a>.</p><p><strong class="c6">Customer voices</strong><br />Some of our customers had early access to this new feature. This is what they shared with us:</p><p><a href="https://aws.amazon.com/marketplace/seller-profile?id=seller-2xeeqw6omnqeq&amp;trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Benchling</a> helps scientists accelerate R&amp;D, making it easy to centralize scientific data, collaborate across teams, and access insights. Nicholas Larus-Stone, Head of AI Agents at Benchling shared “Scientists using Benchling AI can now ask about a target they’re actively working on and get answers grounded in both their institutional data in Benchling and published literature. The result is more complete science, and hypothesis generation done right. Because we’re using the Web Search tool on Amazon Bedrock AgentCore, customers have a secure, governed environment to bring that high quality published data into their workflows without compromising how they manage their data.”</p><p><a href="https://aws.amazon.com/solutions/case-studies/gen-digital-video-case-study/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Gen Digital</a> leads consumer and small business cyber safety, offering antivirus, antimalware, identity and privacy protection, virtual private networks, and cloud backup. Iskander Sanchez-Rola, Senior Director of AI &amp; Innovation, Gen Digital shared “With the Web Search tool on Amazon Bedrock AgentCore, Norton Revamp helps professionals build their online reputation with current, grounded content ideas shaped by what’s actually happening in the world today. What we value most is that AWS uses its own search index and keep queries within our trusted AWS environment.”</p><p>To read more customer stories, visit the <a href="https://aws.amazon.com/bedrock/customers/" target="_blank" rel="noopener noreferrer">Amazon Bedrock Customers</a>.</p><p><strong class="c6">Now available</strong><br />Web Search on Amazon Bedrock AgentCore is generally available today in the US East (N. Virginia) Region. For Regional availability and a future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>.</p><p>You can get started with Web Search on Bedrock AgentCore at no additional cost. You pay only for the data transfer charges you use for the Gateway. New AWS customers also receive up to $200 in Free Tier credits. To learn more, visit the <a href="https://aws.amazon.com/bedrock/agentcore/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock AgentCore pricing</a> page.</p><p>Try it in the <a href="https://console.aws.amazon.com/bedrock-agentcore/home?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock AgentCore console</a> and send feedback to <a href="https://repost.aws/tags/TAaysfWwGaS3SNb1O0i1GkOg/amazon-bedrock-agentcore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Amazon Bedrock AgentCore</a> or through your usual AWS Support contacts.</p><p>— <a href="https://twitter.com/channyun">Channy</a></p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="3df25607-19a0-400f-8267-43f17a15f6c3" data-title="Announcing Web Search on Amazon Bedrock AgentCore: Ground your AI agents in current, accurate web knowledge" data-url="https://aws.amazon.com/blogs/aws/announcing-web-search-on-amazon-bedrock-agentcore-ground-your-ai-agents-in-current-accurate-web-knowledge/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/announcing-web-search-on-amazon-bedrock-agentcore-ground-your-ai-agents-in-current-accurate-web-knowledge/"/>
    <updated>2026-06-16T09:56:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-waf-adds-ai-traffic-monetization-capability-to-help-content-owners-charge-ai-bots-for-content-access/</id>
    <title><![CDATA[AWS WAF adds AI traffic monetization capability to help content owners charge AI bots for content access]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>AWS WAF now includes AI traffic monetization capability that gives digital content owners and publishers a way to charge AI bots and agents for access to protected web content directly at the network edge. The capability helps content owners and publishers set per-request pricing by content path, bot category, or verification tier without modifying their origin infrastructure or writing application code. Content owners can define granular access policies per agent type, collect payments in stablecoins to their preferred wallet, and monitor revenue and bot activity from a single dashboard.</p><p>AI bot traffic now accounts for more than 50% of web traffic for many content providers, with AI-specific crawlers growing more than 300% year-over-year. Unlike traditional search engine crawlers, which index content and return measurable referral traffic back to publisher websites, AI bots consume the same content to generate summaries and responses in AI interfaces, with little to no traffic sent back to the original source. Publishers bear the infrastructure costs of serving that traffic without the page views, ad impressions, or subscription conversions that typically offset those costs. <a href="https://docs.aws.amazon.com/waf/latest/developerguide/waf-bot-control.html">AWS WAF Bot Control</a> already gives customers visibility into bot activity and the ability to block or rate-limit traffic, but setting pricing and collecting payment from AI agents has not been possible until now. AI traffic monetization is a new Bot Control capability that closes that gap, giving content owners and publishers a way to configure pricing rules directly through the AWS WAF console and collect payments from AI agents through third-party payment integrations, without building custom payment infrastructure or negotiating individual licensing agreements. Payment settlement and verification flows are provided by Coinbase’s x402 Facilitator. Integration with Stripe for direct account payments and Machine Payments Protocol (MPP) support is coming soon.</p><p><strong>Getting Started with AI Traffic Monetization<br /></strong> Before configuring monetization, confirm that AWS WAF Bot Control is enabled at Common or Targeted level on the web ACL associated with your CloudFront distribution. Bot Control provides the agent classification that monetization rules depend on. If you have not set this up yet, visit <a href="https://docs.aws.amazon.com/waf/latest/developerguide/waf-bot-control-rg-using.html">Adding the AWS WAF Bot Control managed rule group to your web ACL</a> documentation. In the AWS Management Console, go to <strong>WAF &amp; Shield</strong> and choose <strong>Protection packs (web ACLs)</strong> in the left navigation pane to get started.</p><p>A protection pack is the core configuration unit for AI traffic monetization. It defines which content paths are monetized, what each agent verification tier is charged, which payment methods you accept, and what license terms apply. To create one, choose <strong>Create protection pack (web ACL)</strong>.</p><p><img class="alignnone wp-image-104464 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/10/1213987938308918-0e.png" alt="" width="1924" height="2626" /></p><p>In <strong>Tell us about your app</strong>, select one or more app categories that describe your content (for example, Content &amp; publishing systems, E-commerce &amp; transaction platforms, or Enterprise &amp; business applications), and choose an <strong>App focus</strong>. AWS WAF uses these selections to recommend suitable security protections for your configuration.</p><p>In <strong>Select resources to protect</strong>, choose <strong>Add resources</strong> to associate regional or global resources such as CloudFront distributions with this protection pack. You can skip this step and add resources later.</p><p>In <strong>Choose initial protections</strong>, select from AWS WAF managed rule packages based on your app category and resource selections. You can also choose individual rules instead of packages.</p><p>In <strong>Name and describe</strong>, provide a name and optional description for the protection pack.</p><p>Optionally, expand <strong>Customize protection pack (web ACL) </strong>to configure additional settings including pricing tiers, payment methods, content scope, and license terms.</p><p>When finished, choose <strong>Create protection pack (web ACL)</strong>.</p><p>Once your protection pack is in place, review the AI traffic analysis dashboard to understand the impact of AI bot traffic on your content before setting your pricing strategy. In the WAF &amp; Shield console, go to <strong>AI traffic analysis</strong> in the left navigation pane. Select your protection pack (web ACL) from the dropdown to populate the dashboard.</p><p><img class="alignnone wp-image-104466 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/10/1213987938308918-1a.png" alt="" width="1928" height="1787" /></p><p>The AI traffic analysis dashboard breaks down traffic into four categories visible in the bot traffic overview panel: <strong>All bot requests</strong>, <strong>AI bot requests</strong>, <strong>Verified AI bot traffic</strong>, and <strong>Unverified AI bot traffic</strong>. The dashboard surfaces infrastructure impact metrics including bandwidth consumed, estimated monthly cost, and peak request rates. A per-path heatmap shows which content paths receive the most AI bot activity by hour, giving you the data you need to make informed pricing decisions.</p><p>AWS WAF Bot Control classifies over 650 distinct AI bot and agent types including GPTBot, Claude-Web, and Perplexity-Bot, and assigns each a verification tier:</p><ul><li><strong>Verified</strong> — Agent identity confirmed through Web Bot Auth (WBA) Ed25519 cryptographic signature, or sourced from a documented IP range with a known set of user-agents and domain names.</li>
<li><strong>Unverified</strong> — Agent recognized through user-agent matching, behavioral fingerprinting, and IP reputation, but identity not cryptographically confirmed.</li>
</ul><p>Once you have reviewed your traffic patterns, return to <strong>Protection packs (web ACLs)</strong>, select your protection pack from the list, and choose <strong>Configure AI monetization</strong> from the right panel to set pricing and access policies. Each protection pack defines the pricing, agent policies, accepted payment methods, and license terms that apply to a defined set of content paths. You can create multiple protection packs and apply different pricing to different content zones within the same distribution. Once created, associate the protection pack with your web ACL by opening the web ACL and choosing <strong>Add protection pack</strong>.</p><p>For each agent verification tier within the pack, you can assign one of six actions: <strong>Monetize</strong> (return a 402 with pricing), <strong>Allow</strong> (grant free access), <strong>Block</strong> (deny access entirely), <strong>Count</strong> (log without charging), <strong>CAPTCHA</strong> (present a puzzle to verify a human sender), or <strong>Challenge</strong> (run a silent check to verify the client is a browser, not a bot).</p><p><img class="alignnone wp-image-104528 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/12/1213987938308918-3a.png" alt="" width="1279" height="1531" /></p><p>In the <strong>Edit monetization configuration</strong> page, configure the following:</p><p>Under<strong> Payment settlement</strong>, select one or more blockchain networks for stablecoin payments. Any wallet address on the supported networks is accepted, whether self-managed or hosted by a wallet provider such as Coinbase. For each network, provide your wallet address and set a <strong>Base price per page</strong> in USDC. You can add multiple networks using <strong>Add network</strong>. AWS does not process payments or take a fee on content revenue; disbursement is self-managed or managed by your wallet provider.</p><p>When a <strong>Monetize</strong> rule matches an incoming request, AWS WAF returns an HTTP 402 Payment Required response. The response body contains a machine-readable price manifest in JSON format using the x402 open protocol for machine-to-machine payments. The manifest includes the content price in USDC, accepted blockchain networks such as Base and Solana, the destination wallet address, the maximum payment timeout, and the payment scheme.</p><p>Any x402-compatible agent runtime can complete this flow autonomously. The client submits a signed payment authorization on their payment network of choice. AWS WAF verifies it, fetches the content, integrates with third-party facilitator services for settling the payment on-chain, and serves the response.</p><p>Note that the <strong>Monetize</strong> action is supported exclusively for web ACLs associated with Amazon CloudFront distributions. Adding a <strong>Monetize</strong> rule to a regional web ACL is not supported.</p><p>Since the <strong>Currency mode</strong> toggle is available directly in the monetization configuration page, you can switch between <strong>Real</strong> and <strong>Test</strong> mode at any time. Before going live, use test mode on non-production traffic to validate pricing, wallet configuration, and x402 payment flows. Note that test mode still enforces x402 payments, but those payments can be made on testnets such as Base Sepolia or Solana Devnet using test funds obtained from faucets such as faucet.circle.com. To activate test mode, toggle <strong>Currency mode</strong> to <strong>Test</strong> in your protection pack configuration. AWS WAF returns real price manifests and runs the full payment flow identically to production on the configured test chain. All events are logged with <code>CurrencyMode: TEST</code>. When satisfied with the configuration, toggle Currency mode back to Real to begin processing real payments.</p><p>Once you have switched <strong>Currency mode</strong> to <strong>Real</strong>, navigate to <strong>AI access monetization</strong> in the left navigation pane to track monetization outcomes in real time. Note that the <strong>AI access monetization</strong> dashboard only reflects activity from real currency mode and does not display test transactions.</p><p><img class="alignnone wp-image-104468 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/10/1213987938308918-2b.png" alt="" width="1924" height="1906" /></p><p>The Revenue dashboard shows <strong>Total revenue</strong>, revenue broken down by <strong>Verified bots</strong> and <strong>Unverified bots</strong>, and <strong>Avg. per request.</strong> The<strong> Top revenue sources</strong> panel groups earnings by bot category, and the AI access patterns panel ranks content paths by revenue generated. Use the <strong>Settlements</strong> tab to reconcile payments by provider and review payment method distribution and failed payment attempts.</p><p><strong>Now Available</strong><br />AI traffic monetization is available now for Amazon CloudFront customers at no additional charge beyond standard AWS WAF pricing. The capability is available in all edge locations where AWS WAF web ACLs are associated with Amazon CloudFront distributions.</p><p>To learn more about AI traffic monetization, see the <a href="https://docs.aws.amazon.com/waf/latest/developerguide/waf-ai-traffic-monetization.html">AWS WAF Developer Guide</a>.</p><a href="https://www.linkedin.com/in/esrakayabali/">— Esra</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="fe03144e-4057-4c1f-99d7-94159b58204f" data-title="AWS WAF adds AI traffic monetization capability to help content owners charge AI bots for content access" data-url="https://aws.amazon.com/blogs/aws/aws-waf-adds-ai-traffic-monetization-capability-to-help-content-owners-charge-ai-bots-for-content-access/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-waf-adds-ai-traffic-monetization-capability-to-help-content-owners-charge-ai-bots-for-content-access/"/>
    <updated>2026-06-15T22:42:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-finops-agent-in-preview-gemma-4-on-bedrock-kiro-pro-max-and-more-june-15-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: AWS FinOps Agent in preview, Gemma 4 on Bedrock, Kiro Pro Max, and more (June 15, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>This week, New York City is hosting <a href="https://aws.amazon.com/events/summits/new-york/">AWS Summit</a>, bringing together builders, customers, and AWS teams for a full day of announcements, demos, and technical sessions at the Javits Center. I wrote blog posts for some of the Summit launches, so I am excited to see them go live this week. I just won’t be watching from the Javits Center. I’ll be at a four-day music festival, following the launches on my phone while trying to figure out how to put up a tent. If you weren’t able to attend in person like me, the keynote <a href="https://pages.awscloud.com/aws-summit-nyc-livestream-2026-registration.html">livestream</a> is available on June 17, with Dr. Swami Sivasubramanian, VP of Agentic AI, and Chet Kapoor, VP of Security Services and Observability, covering new capabilities across developer tools, AI infrastructure, and security.</p><p><img class="alignnone wp-image-104579 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/14/WIR-Why1.5d9838d88ff23b99b4fe14be6598b68ef4493215.png" alt="" width="800" height="533" /></p><p>Here’s what happened this week.</p><p><strong>Headlines</strong><br /><a href="https://aws.amazon.com/blogs/machine-learning/how-frontier-teams-are-reinventing-ai-native-development/">How frontier teams are reinventing AI-native development</a> — Swami published a detailed post this week drawing on data from experiments across hundreds of Amazon engineering teams. The findings are worth reading carefully if you are thinking about how to structure AI adoption on your own team.</p><p>A six-engineer team rebuilt the Amazon Bedrock inference engine in 76 days, a project originally scoped for 30 developers over 12 to 18 months. The median productivity gain across structured pilots with Amazon Stores teams was 4.5x in normalized deployment velocity, with some teams exceeding 10x. Perfect Order Experience went from a two-week feature cycle to shipping in an afternoon. WW Grocery cut design document creation from five days to a few hours.</p><p>The post distills these results into five practices for becoming a frontier team. First, invest in agent context: build steering files, coding standards, and structured repositories before writing production code. Second, expect an initial slowdown while workflows are restructured, and push through it. Third, maintain a steady backlog of well-scoped tasks so agents can run in parallel without constant supervision. Fourth, make intent explicit through structured specifications before code generation begins. Fifth, shift testing left so agents can self-correct before code reaches the pipeline.</p><p>The post closes with a note that commit velocity is only part of the picture, and that a follow-up will cover release management, operations, security operations, and EOL upgrades.</p><p><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-finops-agent-preview/">AWS FinOps Agent is now available in preview</a> — AWS FinOps Agent is a new agent for FinOps practitioners and engineering teams that answers cost questions, surfaces optimization opportunities, investigates cost anomalies, and runs recurring FinOps workflows on a defined schedule. You can use it to query your AWS costs, generate cost reports for finance and engineering teams, and surface rightsizing, idle resource, and Savings Plans recommendations from AWS Cost Optimization Hub and AWS Compute Optimizer. The agent can open Jira tickets on your behalf based on those recommendations. When a cost anomaly is detected, FinOps Agent can automatically investigate the root cause and post findings to a Slack channel.</p><p><strong>Last week’s launches</strong><br />I’ll start with one I wrote this week, then cover the other launches that caught my attention:</p><ul><li><a href="https://aws.amazon.com/blogs/aws/now-available-amazon-ec2-m9g-and-m9gd-instances-powered-by-new-aws-graviton5-processors/">Amazon EC2 M9g and M9gd instances are now generally available</a> — Powered by AWS Graviton5 processors and built on the sixth-generation AWS Nitro System, M9g instances deliver up to 25% better compute performance compared to Graviton4-based instances, with up to 35% faster performance for web applications, up to 35% for machine learning inference, and up to 30% for databases. Graviton5 is the first processor in the AWS fleet to support PCIe Gen6 and DDR5-8800 memory, and includes a 5x larger L3 cache compared to the previous generation. M9g and M9gd instances offer up to 15% higher network bandwidth and 20% higher Amazon EBS bandwidth on average across sizes compared to M8g. This release also introduces the Nitro Isolation Engine, an enhancement to the Nitro System that uses formal verification to provide mathematically proven isolation between virtual machines — establishing Nitro as the first formally verified cloud hypervisor. M9gd instances add up to 11.4 TB of NVMe SSD local storage with 30% higher IOPS compared to M8gd. Both instance types support Instance Bandwidth Configuration (IBC) for adjusting bandwidth allocation between EBS and VPC networking by up to 25%.</li>
<li><a href="https://aws.amazon.com/blogs/aws/anthropic-claude-fable-5-on-aws-mythos-class-capabilities-with-built-in-safeguards-now-available/">Anthropic Claude Fable 5 on Amazon Bedrock</a> — Claude Fable 5 launched on Amazon Bedrock on June 9, bringing extended asynchronous task execution, advanced vision capabilities across diagrams, charts, and PDFs, and proactive self-verification. Access requires opting into data sharing via the Data Retention API before invoking the model; Anthropic requires 30-day retention of inputs and outputs for Mythos-class models. <strong>Important note on availability:</strong> On June 12, Anthropic asked AWS to revoke access to Claude Fable 5 and Claude Mythos 5 for all users to support compliance with a US Government export control directive. All other models, including Opus 4.8, are unaffected. Read the <a href="https://www.anthropic.com/news/fable-mythos-access">Anthropic statement</a> for details. AWS will share further updates as they become available.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/gemma-4-amazon-bedrock/">Gemma 4 models are now available on Amazon Bedrock</a> — The Gemma 4 family from Google DeepMind is now available on Amazon Bedrock across three variants: Gemma 4 31B (dense, 256K-token context window, suited for reasoning and coding workloads), Gemma 4 26B-A4B (mixture-of-experts architecture, targeting cost- and latency-sensitive workloads), and Gemma 4 E2B (smallest variant, designed for low-latency interactive use cases). All three support native function calling, structured output, reasoning, response streaming, multimodal input across text, image, video, and audio, and more than 35 languages.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/opensearch-agentic-observability-mcp-app/">Amazon OpenSearch Service launches MCP Apps for agentic observability</a> — Amazon OpenSearch Service now supports MCP Apps, enabling observability workflows inside compatible agentic IDEs including Claude Desktop and VS Code. An AI agent in your local environment can investigate incidents using logs, traces, metrics, and alerts stored in OpenSearch domains, collections, and Amazon Managed Service for Prometheus. Each MCP App tool call returns a dual response: a text summary for the agent to reason over and an interactive visualization rendered in the same conversation thread. Available MCP App tools cover log, metrics, and trace investigation; service performance; topology; dynamic visualizations; agent health; cluster health; and instrumentation scoring.</li>
</ul><p><strong>Other AWS news</strong><br />Here are some additional posts and updates you may find useful:</p><ul><li><a href="https://aws.amazon.com/blogs/developer/aws-cli-v1-maintenance-mode-announcing-changes-to-dependency-updates/">AWS CLI v1 enters maintenance mode</a> — When CLI v1 enters maintenance mode, the botocore and s3transfer dependencies will be vendored directly into the CLI v1 codebase rather than installed as separate packages. This means upgrading CLI v1 will no longer update the standalone botocore or s3transfer packages, and installing those packages independently will have no effect on the versions used by CLI v1. Environments with both CLI v1 and boto3 installed will contain separate copies of these libraries. New CLI v1 releases will be limited to critical bug fixes and security issues. The recommended path is to migrate to AWS CLI v2.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-workload-credentials-provider/">AWS Workload Credentials Provider is now available</a> — AWS has launched a new Workload Credentials Provider that enables workloads to obtain short-term AWS credentials without requiring long-term access keys. This supports credential management for applications running outside of AWS, giving teams a way to follow least-privilege access patterns for workloads in third-party or on-premises environments.</li>
<li><a href="https://kiro.dev/blog/kiro-pro-max/">Kiro Pro Max is now available</a> — Kiro has introduced a new Pro Max tier, adding higher usage limits, access to the latest frontier models, and additional agentic capabilities for development teams. Kiro Pro Max is designed for professional developers who need sustained, high-volume use across coding, specification generation, and agent-driven tasks.</li>
</ul><p><strong>Upcoming AWS events<br /></strong> Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/summits/">AWS Summits</a> — AWS Summits are free in-person events covering cloud and AI. Coming up: <a href="https://aws.amazon.com/events/summits/new-york/">New York City</a> (June 17), <a href="https://aws.amazon.com/events/summits/hongkong/">Hong Kong</a> (June 17), <a href="https://aws.amazon.com/events/summits/shanghai/">Shanghai</a> (June 23-24), <a href="https://aws.amazon.com/jp/events/summits/japan/">Japan</a> (June 25), <a href="https://aws.amazon.com/events/summits/washington-dc/">Washington, D.C.</a> (June 30 – July 1), <a href="https://aws.amazon.com/tw/events/summits/taipei/">Taipei</a> (July 15), and <a href="https://aws.amazon.com/es/events/summits/bogota/">Bogotá</a> (July 30).</li>
<li><a href="https://aws.amazon.com/events/community-day/">AWS Community Days</a> — Community-led conferences planned and delivered by community leaders. Upcoming events include <a href="https://awscommunitydayeast.ca/">Montreal, Canada</a> (June 20), <a href="https://www.midwestcommunityday.com/">Indianapolis, USA</a> (June 24), <a href="https://2026-summer.awscommunityday.cn/">Hangzhou, China</a> (June 28), <a href="https://acd.awsugblr.in/">Bengaluru, India</a> (July 11), and <a href="https://communityday.awscmr.com/en">Yaoundé, Cameroon</a> (July 25).</li>
</ul><p>Visit the <a href="https://builder.aws.com/?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">AWS Builder Center</a> to meet other builders, contribute solutions, and find resources that help you keep building. You can also browse upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS-led in-person and virtual events</a>, plus <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused sessions</a>.</p><a href="https://www.linkedin.com/in/esrakayabali/">— Esra</a><p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="354033c3-8df3-486d-955c-96095d4b888f" data-title="AWS Weekly Roundup: AWS FinOps Agent in preview, Gemma 4 on Bedrock, Kiro Pro Max, and more (June 15, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-finops-agent-in-preview-gemma-4-on-bedrock-kiro-pro-max-and-more-june-15-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-finops-agent-in-preview-gemma-4-on-bedrock-kiro-pro-max-and-more-june-15-2026/"/>
    <updated>2026-06-15T13:41:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/proactively-reduce-tech-debt-autonomously-with-aws-transform-continuous-modernization-preview/</id>
    <title><![CDATA[Proactively reduce tech debt autonomously with AWS Transform – continuous modernization (preview)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing <a href="http://aws.amazon.com/transform/continuous-modernization">AWS Transform – continuous modernization (preview)</a>, a new capability of <a href="https://aws.amazon.com/transform/">AWS Transform</a> for continuous, autonomous tech debt analysis and remediation at scale. AWS Transform already helps enterprises migrate out of data centers, modernize mainframe and Windows applications, and handle the undifferentiated work of software maintenance: upgrading Java versions, swapping deprecated frameworks, and updating <a href="https://aws.amazon.com/lambda/">AWS Lambda</a> runtimes before they reach end of life. This new experience builds on this. Customers get full visibility into the state of their codebase across thousands of repositories, prioritized findings, and the pull requests that make the fixes.</p><p>Engineering organizations typically consume up to 30% of IT budgets. Customers stitch together point tools: one to detect dependency issues, another to flag vulnerabilities, another for code quality. But no existing tool detects, prioritizes, and remediates tech debt continuously and at scale. The result is a manual, app-by-app cycle that drains engineering capacity. Leaders fall back on self-reported team status that lags reality and hides regressions. AI-assisted development makes this worse: as coding agents accelerate the pace of change, tech debt accumulates faster than developers can keep up. Customers need a capability that detects, prioritizes, and remediates tech debt continuously, autonomously, and at scale.</p><p><strong>Continuous analysis<br /></strong> To address the visibility challenge, this new capability within AWS Transform automatically scans your code repositories against configurable baselines and generates findings in hours, not weeks. Out of the box, AWS Transform – continuous modernization includes policies for detecting end of life dependencies, deprecated frameworks, and other common sources of technical debt. You can also extend these with your own remediation patterns specific to your organization, including approved libraries, internal coding standards, or tech debt policies your platform team already enforces. For example, if your team has deprecated an internal library or prefers a particular logging pattern, you can codify that as a policy and run it across all your repositories continuously.</p><p>Unlike periodic manual efforts, continuous analysis provides ground truth directly from your code. When a repository falls behind your baseline, you know immediately, showing which components are behind and by how much, regardless of how the team chooses to address it. This eliminates the need for status check-ins and manual compliance tracking, giving platform teams an always current view of their technical debt landscape.</p><p><strong>Autonomous remediation at scale<br /></strong> Once you’ve identified and prioritized findings, you can configure autonomous remediations that generate pull requests for affected repositories automatically. This new AWS Transform capability provides out-of-the-box remediation transformations for common scenarios such as Java version upgrades, SDK migrations, and library updates. You can also create custom transformations for organization-specific patterns.</p><p>When you launch a remediation, the continuous modernization capability creates pull requests for each affected repository, notifying the owning team with a message like: “This repository is behind on your organization’s baseline for this dependency. Here’s a PR that resolves it.” Teams can review and merge the PR, or choose to remediate using their own approach. Either way, continuous analysis detects when the fix is in place, providing ground truth without requiring manual confirmation.</p><p>AWS Transform – continuous modernization integrates with <a href="https://aws.amazon.com/security-agent">AWS Security Agent</a> to detect and remediate security vulnerabilities at the source-code level, so security findings flow into the same prioritized list and pull-request workflow as other tech debt.</p><p><strong>Let’s try it out<br /></strong> To get started with, I navigated to the AWS Transform web application. From the dashboard, I can see an overview of my organization’s repositories and their current status against my configured baselines.</p><p>First, I connected my source control system and initiated an analysis against my specified policies. Within hours, the analysis returned findings across my repositories, showing which ones were behind the baseline and by how much. I could see the severity, the number of affected files, and the specific tech debt patterns detected.</p><p>From here, I selected a group of high-priority findings and launched a remediation campaign. AWS Transform – continuous modernization generated pull requests for each affected repository. I could monitor the campaign’s progress in real time, seeing which PRs were created, which were merged, and which repositories returned to compliance.</p><p><img class="alignnone wp-image-104654 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/16/image-01-1024x557.png" alt="" width="1024" height="557" /></p><p>Image 1: AWS Transform – continuous modernization dashboard showing a portfolio overview of your technical debt findings across all connected repositories.</p><p><img class="alignnone wp-image-104655 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/16/image-02-1024x572.png" alt="" width="1024" height="572" /></p><p>Image 2: The detailed findings view listing individual tech debt items by severity, category, and repository with their available remediation options.</p><p><img class="alignnone wp-image-104656 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/16/image-03-1024x573.png" alt="" width="1024" height="573" /></p><p>Image 3: The sources view showing connected repositories from GitHub and local environments that continuous modernization is tracking for analysis.</p><p><strong>Faster ways to modernize<br /></strong> These capabilities support two distinct approaches to code modernization. In continuous mode, you can use continuous modernization to keep your codebases current as baselines evolve. Think of this as the day-to-day work of upgrading libraries, applying security patches, and enforcing coding standards across your organization.</p><p>For larger modernization projects, such as migrating from one framework to another or upgrading a major runtime version across hundreds of applications, you can use campaign mode for targeted, project-based modernization. AWS Transform custom continues to provide the flexible primitive for these larger efforts. AWS Transform – continuous modernization is purpose-built for the recurring, high-volume work that platform teams manage every day.</p><p><strong>Now available<br /></strong> AWS Transform – continuous modernization (preview) is available today. You can get started through the AWS Transform web application, via the AWS Transform Kiro Power, or through MCP and skills for integration with your existing coding agents. To learn more, visit the <a href="https://docs.aws.amazon.com/transform/">AWS Transform documentation</a>.</p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="a8cf771c-32c3-439a-a368-c27822d2fc92" data-title="Proactively reduce tech debt autonomously with AWS Transform – continuous modernization (preview)" data-url="https://aws.amazon.com/blogs/aws/proactively-reduce-tech-debt-autonomously-with-aws-transform-continuous-modernization-preview/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/proactively-reduce-tech-debt-autonomously-with-aws-transform-continuous-modernization-preview/"/>
    <updated>2026-06-11T20:02:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/introducing-amazon-bedrock-managed-knowledge-base-for-faster-more-accurate-enterprise-ai-applications/</id>
    <title><![CDATA[Introducing Amazon Bedrock Managed Knowledge Base for faster, more accurate enterprise AI applications]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing <a href="https://aws.amazon.com/bedrock/knowledge-bases/">Amazon Bedrock Managed Knowledge Base</a>, a new set of capabilities that enables developers to build enterprise-grade generative AI applications with their proprietary data in minutes. Organizations building agentic AI applications need secure, reliable, and up-to-date access to enterprise-wide data to deliver accurate, fast, and trusted outcomes. Managed Knowledge Base abstracts away the complexity of building and managing retrieval-augmented generation (RAG) pipelines, allowing developers to focus on business outcomes rather than infrastructure management.</p><p>Developers building knowledge bases for their agents face three key challenges today:</p><ul><li><strong>Connecting to enterprise data</strong> – Enterprise knowledge lives across disparate systems with different content types, access control lists, and document formats. Building and maintaining custom connectors for each source adds complexity that slows down development.</li>
<li><strong>Optimizing RAG accuracy</strong> – Best practices for retrieval-augmented generation keep evolving. Developers need to experiment with different parsing strategies, chunking approaches, embedding models, and agentic retrieval behaviors to get accurate answers from their data.</li>
<li><strong>Managing infrastructure at scale</strong> – Organizations need to serve large knowledge bases with millions of documents, or manage thousands of smaller knowledge bases across teams. Both patterns require reliable infrastructure, security enforcement, and cost control.</li>
</ul><p>These challenges require developers to repeatedly perform undifferentiated work instead of focusing on their applications.</p><p>Amazon Bedrock Managed Knowledge Base addresses these challenges by abstracting away the multiple infrastructure components developers traditionally have to assemble and maintain themselves (storage, retrieval, embeddings, re-ranking, and foundation model selection) into a single managed primitive. By default, the service automatically selects and manages a default embeddings model, re-ranker model, and foundational model on your behalf, so you can get up to speed quickly without needing to pick or maintain one yourself. On top of this managed foundation, three core innovations further improve ease of use and accuracy:</p><ul><li><strong>Native data connectors</strong> – Six pre-built ingestion connectors that natively pull enterprise data and permissions from SaaS applications, eliminating the overhead developers face in managing application-specific requirements. At launch, we support Amazon S3, SharePoint, Confluence, Web Crawler, Google Drive, and OneDrive.</li>
<li><strong>Smart Parsing</strong> – Different content types and sources require different approaches to achieve accurate retrieval. Smart Parsing handles this complexity automatically, selecting the right parsing strategy for each data type and connector to provide the highest accuracy for your agents.</li>
<li><strong>Agentic Retriever</strong> – Optimized for complex queries that require multiturn, multihop retrieval within a single knowledge base or across multiple knowledge bases. Agentic Retriever automatically infers end-user intent and draws relevant context from institutional knowledge spread across data sources and modalities.</li>
</ul><p>With just a few lines of code, Amazon Bedrock Managed Knowledge Base automatically manages and scales the end-to-end RAG pipeline that powers your enterprise knowledge agents. For agent builders, it’s available as a pre-built target type in <a href="https://aws.amazon.com/bedrock/agentcore/">Amazon Bedrock AgentCore Gateway</a>, reducing integration to a few lines of code, auto-generating role-based permissions, and providing observability and evaluation metrics in the AgentCore Observability dashboard.</p><p><strong class="c6">Getting started with Amazon Bedrock Managed Knowledge Base</strong><br />Creating a Managed Knowledge Base is straightforward. Navigate to the <a href="https://console.aws.amazon.com/bedrock-agentcore/">Amazon Bedrock AgentCore console</a> or the <a href="https://console.aws.amazon.com/bedrock/">Amazon Bedrock console</a>, open the <strong>Knowledge Bases</strong> page, and choose <strong>Create Managed KB</strong>. The experience is the same in both consoles. You will see that <strong>Unstructured Vector Store KB</strong> is now available as the recommended option, alongside the other knowledge base types you may already be familiar with:</p><div id="attachment_104601" class="wp-caption aligncenter c8"><img aria-describedby="caption-attachment-104601" class="wp-image-104601 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/15/2026-bedrock-fmkb-1.jpg" alt="" width="1800" height="1141" /><p id="caption-attachment-104601" class="wp-caption-text">Picture 1 – Knowledge Bases list page in the Amazon Bedrock AgentCore console showing the Type column with different KB types and the Create Managed KB button</p></div><p>When creating a new Knowledge Bases, you can connect to your enterprise data sources by choosing from the list of supported connectors directly from a dropdown. <a href="https://aws.amazon.com/iam">AWS Identity and Access Management (IAM)</a> roles are automatically created, and you can choose to edit these permissions if needed:</p><div id="attachment_104602" class="wp-caption aligncenter c8"><img aria-describedby="caption-attachment-104602" class="wp-image-104602 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/15/2026-bedrock-fmkb-2.jpg" alt="" width="1800" height="1846" /><p id="caption-attachment-104602" class="wp-caption-text">Picture 2 – Create Knowledge Base page showing the Data source dropdown expanded with all supported connectors: Amazon S3, Confluence, Custom, Google Drive, One Drive, SharePoint, and Web Crawler</p></div><p>An optimized set of defaults will be presented, allowing you to create your knowledge base in just a few clicks. Once the data is synced, you can integrate the knowledge base with your agent or provide it as a tool for your foundation model and start querying.</p><p><strong>Smart Parsing for accurate data ingestion</strong><br />One of the key challenges in building knowledge bases is preparing diverse data types for accurate retrieval. Once you point Managed Knowledge Base at your data sources, Smart Parsing automatically determines the optimal parsing strategy for each data type and connector, no extra configuration is required.</p><p>Smart Parsing combines multiple techniques:</p><ul><li><strong>Connector-specific data models</strong> – Optimized handling for each data source. For example, the Web Crawler connector preserves HTML structure including embedded images and tables, ensuring rich content is not dropped during ingestion. SharePoint connectors maintain document hierarchy and relationships between files.</li>
<li><strong>Multimodal processing</strong> – Automatic detection and processing of different content types within documents. The system identifies bounding boxes in documents, then sends them to foundation models for data extraction, captioning, and scene description in video files.</li>
<li><strong>Optimized chunking</strong> – Smart Parsing leverages foundation models to understand document structure and extract meaningful content, ensuring that complex documents with mixed formats are properly indexed. Intelligent defaults balance retrieval accuracy with performance based on document type and content structure, while advanced users can customize chunking strategies when needed.</li>
</ul><p>This automated approach eliminates weeks of experimentation typically required to achieve production-quality retrieval accuracy, while still preserving the flexibility to customize when needed.</p><p><strong>Using Agentic Retriever for complex queries</strong><br />After your data is ingested, you can start querying your knowledge base. Generative AI applications often struggle with complex user queries that require reasoning, recursive multi-step retrieval, and intermediate evaluations of results. Consider a user asking two related questions: “What is the cloud infrastructure budget for the ML platform team?” and “Does our expense policy allow prepaying annual commitments?” A single retrieval step might surface documents about the ML platform team but fail to connect the budget information with the expense policy needed to fully answer the question.</p><div id="attachment_104253" class="wp-caption aligncenter c9"><img aria-describedby="caption-attachment-104253" class="wp-image-104253 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/Infographics.png" alt="" width="3107" height="1081" /><p id="caption-attachment-104253" class="wp-caption-text">Picture 3 – Agentic Retriever decomposes complex user queries into a step-by-step plan, performing multi-hop retrieval across multiple knowledge bases and combining results to deliver accurate, grounded responses</p></div><p>Agentic Retriever solves this by creating a step-by-step query plan: 1. Which team owns the ML platform, and what is their cloud infrastructure budget? 2. What does the expense policy say about prepaying annual commitments? 3. Does the policy allow the ML platform team to prepay against this budget?</p><p>The system performs multi-hop retrieval and reasoning at each step, and once it has gathered sufficient relevant passages, it stops the search process and returns the top results. By abstracting away the complexity of building a separate multi-hop reasoning pipeline, this approach dramatically improves accuracy for complex queries while letting developers focus on their agentic search applications instead of orchestration logic.</p><p>You can try Agentic Retriever directly from the test panel of your knowledge base in the Amazon Bedrock AgentCore console. Select <strong>Agentic retrieval only</strong> as the retrieval type to let the system automatically plan and execute multi-step queries across your knowledge bases:</p><div id="attachment_104603" class="wp-caption aligncenter c8"><img aria-describedby="caption-attachment-104603" class="wp-image-104603 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/15/2026-bedrock-fmkb-3.jpg" alt="" width="1800" height="991" /><p id="caption-attachment-104603" class="wp-caption-text">Picture 4 – Test Knowledge Base panel showing Agentic retrieval with answer generation selected as the retrieval type, with model selection and maximum agentic iterations options</p></div><p><strong>Enabling MCP with Bedrock AgentCore</strong><br />Amazon Bedrock Managed Knowledge Base seamlessly integrates with AgentCore Gateway as a native target type. This integration eliminates the need for manual integration and provides built-in observability, policy enforcement, and automatic permission management.</p><p>You can navigate to the Amazon Bedrock AgentCore console or SDK and create an AgentCore Gateway or select an existing one. When adding targets to your gateway, you will find <strong>Knowledge Base</strong> as a new pre-built target type alongside other options such as MCP server, Lambda ARN, REST API, and other integrations. Simply select your knowledge base ID to expose it through the gateway:</p><div id="attachment_104604" class="wp-caption aligncenter c8"><img aria-describedby="caption-attachment-104604" class="wp-image-104604 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/15/2026-bedrock-fmkb-4.jpg" alt="" width="1800" height="1365" /><p id="caption-attachment-104604" class="wp-caption-text">Picture 5 – Add targets page in AgentCore Gateway showing Knowledge Base as a new pre-built target type, with the knowledge base ID selector and runtime retrieval mode options</p></div><p>Add targets page in AgentCore Gateway showing Knowledge Base as a new pre-built target type, with the knowledge base ID selector and runtime retrieval mode options</p><p>Gateway exposes the standard Model Context Protocol (MCP), so the knowledge base tools are automatically discovered by clients from any MCP-compatible framework, including <a href="https://strandsagents.com/">Strands Agents</a>, <a href="https://github.com/langchain-ai/langchain">LangChain</a>, <a href="https://crewai.com/">CrewAI</a>, <a href="https://www.llamaindex.ai/">LlamaIndex</a>, and <a href="https://github.com/langchain-ai/langgraph">LangGraph</a>. No custom integration code is required.</p><p><strong>Model choice and flexibility</strong><br />Amazon Bedrock Managed Knowledge Base preserves the flexibility developers expect from Amazon Bedrock. Every foundation model available on Bedrock can power the generation step, and developers can select from different embedding and re-ranking models to optimize retrieval for their specific use case, enabling teams to fine-tune accuracy and cost-performance without changing infrastructure.</p><p>Unlike managed solutions that lock you into specific model providers, Amazon Bedrock Managed Knowledge Base separates the infrastructure management (connectors, parsing, storage, retrieval orchestration) from model selection. This means you can:</p><ul><li><strong>Take advantage of the latest models</strong> – Adopt the latest embedding, re-ranking, and foundation models as they become available to improve accuracy, latency, and cost for your application without rebuilding your RAG pipeline.</li>
<li><strong>Optimize for price-performance</strong> – Choose smaller, faster models for simple queries and more capable models for complex reasoning tasks, all using the same knowledge base infrastructure.</li>
<li><strong>Use Bedrock embedding models</strong> – While Smart Parsing provides optimized defaults, you can configure Bedrock embedding models when your domain requires specialized semantic understanding.</li>
<li><strong>Maintain consistency with existing applications</strong> – If you’re already using Bedrock Knowledge Bases APIs (<code>Retrieve</code>, <code>StartIngest</code>, <code>StopIngest</code>, <code>IngestKnowledgeBaseDocuments</code>), Managed Knowledge Base uses the same APIs, so migration requires no code changes, just point to the new knowledge base ID.</li>
</ul><p>This approach ensures you can spend time on your generative AI application without losing the ability to change models based on evolving requirements or new model capabilities.</p><p><strong class="c6">Get started today</strong><br />Amazon Bedrock Managed Knowledge Base is available today in the US East (N. Virginia), US West (Oregon), Asia Pacific (Sydney, Tokyo), Europe (Dublin, Frankfurt, London), and AWS GovCloud (US-West) Regions. For Regional availability and future roadmap, visit <a href="https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/">AWS Capabilities by Region</a>.</p><p>With Bedrock Managed Knowledge Base, you pay for what you use with no upfront commitments. Pricing is based on two dimensions: the size of indexed data stored and the number of retrievals performed (on-demand). For detailed pricing information, visit the <a href="https://aws.amazon.com/bedrock/pricing/">Amazon Bedrock pricing page</a>. Bedrock is also a part of the <a href="https://aws.amazon.com/free/">AWS Free Tier</a> that new AWS customers can use to get started at no cost and explore key AWS services.</p><p>These capabilities work with any open source framework such as CrewAI, LangGraph, LlamaIndex, and Strands Agents, and with any foundation model. Bedrock services can be used together or independently, and you can get started using your favorite AI-assisted development environment with the <a href="https://awslabs.github.io/mcp/servers/amazon-bedrock-agentcore-mcp-server">AgentCore open source MCP server</a>.</p><p>To learn more and get started quickly, visit the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/knowledge-base.html">Bedrock Knowledge Bases Developer Guide</a>.</p><p>Daniel Abib</p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="e001ee23-de52-4ccb-ab3b-0f93ae8cc066" data-title="Introducing Amazon Bedrock Managed Knowledge Base for faster, more accurate enterprise AI applications" data-url="https://aws.amazon.com/blogs/aws/introducing-amazon-bedrock-managed-knowledge-base-for-faster-more-accurate-enterprise-ai-applications/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/introducing-amazon-bedrock-managed-knowledge-base-for-faster-more-accurate-enterprise-ai-applications/"/>
    <updated>2026-06-10T19:09:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/now-available-amazon-ec2-m9g-and-m9gd-instances-powered-by-new-aws-graviton5-processors/</id>
    <title><![CDATA[Now available: Amazon EC2 M9g and M9gd instances powered by new AWS Graviton5 processors]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>AWS Graviton processors have improved steadily across generations, with each iteration delivering advances in compute performance, price-performance, and energy efficiency. At re:Invent 2025, we <a href="https://aws.amazon.com/about-aws/whats-new/2025/12/ec2-m9g-instances-graviton5-processors-preview/">announced</a> Amazon EC2 M9g, the first Graviton5-powered instances, in preview. Since then, customers have tested M9g across a wide range of workloads and shared their results. <a href="https://clickhouse.com/">ClickHouse</a> saw a 36% performance boost compared to M8g, with zero code changes. <a href="https://www.honeycomb.io/">Honeycomb</a> achieved 36% better throughput per core compared to Graviton4, across a 6-month A/B test of production observability workloads. <a href="https://www.hubspot.com/">HubSpot</a> deployed M9g for MySQL databases and saw query duration drop by up to 60%. Today, M9g instances are generally available, alongside the new M9gd instances for customers who need high-speed, low-latency local NVMe SSD storage. Both are powered by <a href="https://aws.amazon.com/ec2/graviton/">Graviton5</a>, the most powerful and most energy efficient processor AWS has ever built.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/10/1213311671976503-0-G5_Angled.jpg"><img class="alignnone size-full wp-image-104435" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/10/1213311671976503-0-G5_Angled.jpg" alt="" width="2560" height="1710" /></a></p><p>While many Arm-based instances have been introduced across the industry, no one comes close to the breadth and depth of the AWS Graviton footprint. After five generations of custom silicon and eight years of continuous investment, Graviton powers over 350 instance types serving more than 120,000 customers, from startups to large enterprises, a robust ISV partner ecosystem, and a broad set of managed services. You can use Graviton for a broad variety of workloads, including web applications, microservices, analytics, databases, machine learning (ML) inference, electronic design automation (EDA), gaming, and video encoding. As workloads grow more compute-intensive and data-driven, many have asked for more processing power, along with greater network and storage bandwidth to move more data and complete workloads faster. We’ve also designed these instances to efficiently package compute, memory, and I/O to maximize energy utilization.</p><p>As AI shifts from answering questions to taking actions, running code, using tools, evaluating results, and orchestrating multi-step tasks, the demand for CPU compute is growing rapidly. Graviton5 is built for this shift. With 192 cores, a 5x larger L3 cache, up to 33% lower inter-core latency, and DDR5 memory delivering high bandwidth, Graviton5 helps agents spend less time waiting on CPU-bound steps, processing more instructions, handling large numbers of concurrent environments, and keeping accelerators moving.</p><p><a href="https://www.aboutamazon.com/news/aws/meta-aws-graviton-ai-partnership">Meta</a> is deploying Graviton at scale starting with tens of millions of cores to support its agentic AI efforts, making Meta one of the largest Graviton customers in the world. Agentic AI workloads, including real-time reasoning, code generation, and the orchestration of multi-step tasks, are CPU-intensive and benefit from the higher compute performance, larger caches, higher memory bandwidth, and core density in Graviton5.</p><p><strong>What’s new in M9g and M9gd<br /></strong> Built on the sixth-generation <a href="https://aws.amazon.com/ec2/nitro/">AWS Nitro System</a>, M9g instances are powered by AWS Graviton5 processors that deliver higher compute performance, larger caches, and improved memory and I/O scalability compared to Graviton4 processors. Graviton5 offers up to 25% better compute performance compared to Graviton4-based instances, with up to 35% faster performance for web applications, up to 35% for machine learning inference, and up to 30% for databases. As the first CPU in the AWS fleet to support the latest generation of PCIe Gen6 and DDR5-8800 memory, AWS Graviton5 instances deliver the fastest memory of any processor instances in the cloud, and 5 times more L3 cache compared to the previous generation. These improvements also come with better energy efficiency, helping you meet sustainability targets without compromising capability.</p><p>Networking and storage bandwidth have been expanded to keep pace with compute growth. M9g and M9gd instances offer up to 15% higher network bandwidth and 20% higher <a href="https://aws.amazon.com/ebs/?nc2=type_a">Amazon Elastic Block Store (Amazon EBS)</a> bandwidth on average across sizes, with up to twice the network bandwidth for the largest instance size. M9g and M9gd instances also support <a href="https://docs.aws.amazon.com/ebs/latest/userguide/instance-bandwidth-configuration.html">Instance Bandwidth Configuration (IBC)</a>, a feature that helps you adjust the allocation of bandwidth between Amazon EBS and <a href="https://aws.amazon.com/vpc/">Amazon Virtual Private Cloud (Amazon VPC)</a> networking for an Amazon EC2 instance by up to 25%. IBC can help optimize performance for workloads with specific bandwidth requirements, such as database read and write performance, query processing, and logging. These enhancements support faster data movement and improved throughput for workloads that rely on high I/O performance.</p><p>Security and isolation are foundational requirements for running workloads in the cloud. Within the Nitro System, the AWS Nitro Hypervisor is designed to isolate instances from each other as well as AWS operators. With M9g and M9gd instances we are raising the bar on security even further with the introduction of Nitro Isolation Engine.Nitro Isolation Engine is an enhancement to the Nitro System, which enforces isolation of instances and harnesses formal verification to provide assurances of isolation with mathematical precision. Nitro Isolation Engine is a purpose-built component that is responsible for enforcing isolation between virtual machines, including mediation of all access to virtual machine memory, CPU register state, and I/O devices through a minimal set of APIs. Nitro Isolation Engine leverages formal verification, a technique to mathematically demonstrate that the hardware or software behaves as intended, and not just in specific test cases. This intensive verification technique establishes Nitro as the first formally verified cloud hypervisor, pioneering a new standard for mathematically proven cloud security.</p><p>M9g instances provide one vCPU for every four GiB of memory and are well suited for a broad range of general-purpose workloads, including application servers, microservices, midsize data stores, gaming servers, caching fleets, containerized applications, large-scale Java applications, code repositories, web applications, and agentic AI.</p><p>For workloads that need high-speed, low-latency local storage, M9gd instances provide up to 11.4 TB of NVMe SSD storage and 30% higher IOPS and storage performance compared to Graviton4-based M8gd instances. M9gd instances are well suited for general-purpose workloads that require a balance of compute and memory with high-speed, low-latency local storage, including application servers, microservices, gaming servers, midsize key-value data stores, caching fleets, data logging, media processing, batch and log processing, and applications that need temporary storage such as caches and scratch files.</p><p>Here are the key specifications across the family:</p><table class="c10"><tbody><tr class="c8"><td class="c6"><strong>M9g</strong></td>
<td class="c7"><strong>vCPUs</strong></td>
<td class="c7"><strong>Memory (GiB)</strong></td>
<td class="c7"><strong>Network bandwidth (Gbps)</strong></td>
<td><strong>EBS bandwidth (Gbps)</strong></td>
</tr><tr class="c9"><td class="c6"><strong>medium</strong></td>
<td class="c6">1</td>
<td class="c6">4</td>
<td class="c6">Up to 15</td>
<td class="c6">Up to 12</td>
</tr><tr class="c9"><td class="c6"><strong>large</strong></td>
<td class="c6">2</td>
<td class="c6">8</td>
<td class="c6">Up to 15</td>
<td class="c6">Up to 12</td>
</tr><tr class="c9"><td class="c6"><strong>xlarge</strong></td>
<td class="c6">4</td>
<td class="c6">16</td>
<td class="c6">Up to 15</td>
<td class="c6">Up to 12</td>
</tr><tr class="c9"><td class="c6"><strong>2xlarge</strong></td>
<td class="c6">8</td>
<td class="c6">32</td>
<td class="c6">Up to 17</td>
<td class="c6">Up to 12</td>
</tr><tr class="c9"><td class="c6"><strong>4xlarge</strong></td>
<td class="c6">16</td>
<td class="c6">64</td>
<td class="c6">Up to 17</td>
<td class="c6">Up to 12</td>
</tr><tr class="c9"><td class="c6"><strong>8xlarge</strong></td>
<td class="c6">32</td>
<td class="c6">128</td>
<td class="c6">17</td>
<td class="c6">12</td>
</tr><tr class="c9"><td class="c6"><strong>12xlarge</strong></td>
<td class="c6">48</td>
<td class="c6">192</td>
<td class="c6">25</td>
<td class="c6">18</td>
</tr><tr class="c9"><td class="c6"><strong>16xlarge</strong></td>
<td class="c6">64</td>
<td class="c6">256</td>
<td class="c6">34</td>
<td class="c6">24</td>
</tr><tr class="c9"><td class="c6"><strong>24xlarge</strong></td>
<td class="c6">96</td>
<td class="c6">384</td>
<td class="c6">50</td>
<td class="c6">36</td>
</tr><tr class="c9"><td class="c6"><strong>48xlarge</strong></td>
<td class="c6">192</td>
<td class="c6">768</td>
<td class="c6">100</td>
<td class="c6">72</td>
</tr><tr class="c9"><td class="c6"><strong>metal-48xl</strong></td>
<td class="c6">192</td>
<td class="c6">768</td>
<td class="c6">100</td>
<td class="c6">72</td>
</tr></tbody></table><p>M9gd instances include local NVMe SSD storage. The table below shows the instance storage for each size. Compute, memory, network, and EBS bandwidth specifications are the same as M9g.</p><table class="c10"><tbody><tr class="c8"><td class="c6"><strong>M9gd</strong></td>
<td class="c7"><strong>vCPUs</strong></td>
<td class="c7"><strong>Memory (GiB)</strong></td>
<td class="c7"><strong>Instance storage (GB)</strong></td>
<td class="c7"><strong>Network bandwidth (Gbps)</strong></td>
<td><strong>EBS bandwidth (Gbps)</strong></td>
</tr><tr class="c9"><td class="c6"><strong>medium</strong></td>
<td class="c6">1</td>
<td class="c6">4</td>
<td class="c6">1 x 59 NVMe SSD</td>
<td class="c6">Up to 15</td>
<td class="c6">Up to 12</td>
</tr><tr class="c9"><td class="c6"><strong>large</strong></td>
<td class="c6">2</td>
<td class="c6">8</td>
<td class="c6">1 x 118 NVMe SSD</td>
<td class="c6">Up to 15</td>
<td class="c6">Up to 12</td>
</tr><tr class="c9"><td class="c6"><strong>xlarge</strong></td>
<td class="c6">4</td>
<td class="c6">16</td>
<td class="c6">1 x 237 NVMe SSD</td>
<td class="c6">Up to 15</td>
<td class="c6">Up to 12</td>
</tr><tr class="c9"><td class="c6"><strong>2xlarge</strong></td>
<td class="c6">8</td>
<td class="c6">32</td>
<td class="c6">1 x 475 NVMe SSD</td>
<td class="c6">Up to 17</td>
<td class="c6">Up to 12</td>
</tr><tr class="c9"><td class="c6"><strong>4xlarge</strong></td>
<td class="c6">16</td>
<td class="c6">64</td>
<td class="c6">1 x 950 NVMe SSD</td>
<td class="c6">Up to 17</td>
<td class="c6">Up to 12</td>
</tr><tr class="c9"><td class="c6"><strong>8xlarge</strong></td>
<td class="c6">32</td>
<td class="c6">128</td>
<td class="c6">1 x 1900 NVMe SSD</td>
<td class="c6">17</td>
<td class="c6">12</td>
</tr><tr class="c9"><td class="c6"><strong>12xlarge</strong></td>
<td class="c6">48</td>
<td class="c6">192</td>
<td class="c6">3 x 950 NVMe SSD</td>
<td class="c6">25</td>
<td class="c6">18</td>
</tr><tr class="c9"><td class="c6"><strong>16xlarge</strong></td>
<td class="c6">64</td>
<td class="c6">256</td>
<td class="c6">1 x 3800 NVMe SSD</td>
<td class="c6">34</td>
<td class="c6">24</td>
</tr><tr class="c9"><td class="c6"><strong>24xlarge</strong></td>
<td class="c6">96</td>
<td class="c6">384</td>
<td class="c6">3 x 1900 NVMe SSD</td>
<td class="c6">50</td>
<td class="c6">36</td>
</tr><tr class="c9"><td class="c6"><strong>48xlarge</strong></td>
<td class="c6">192</td>
<td class="c6">768</td>
<td class="c6">3 x 3800 NVMe SSD</td>
<td class="c6">100</td>
<td class="c6">72</td>
</tr><tr class="c9"><td class="c6"><strong>metal-48xl</strong></td>
<td class="c6">192</td>
<td class="c6">768</td>
<td class="c6">3 x 3800 NVMe SSD</td>
<td class="c6">100</td>
<td class="c6">72</td>
</tr></tbody></table><p><strong>Now available<br /></strong> M9g and M9gd instances are available in the US East (N. Virginia), US East (Ohio), US West (Oregon), and Europe (Frankfurt) Regions. M9g and M9gd instances are available for purchase through <a href="https://aws.amazon.com/savingsplans/">Savings Plans</a>, On-Demand, Spot Instances, Dedicated Instances, or Dedicated Hosts. For more information, visit <a href="https://aws.amazon.com/ec2/pricing/">Amazon EC2 pricing</a>.</p><p>To get started with M9g and M9gd instances, several resources are available. The <a href="https://github.com/aws/aws-graviton-getting-started">AWS Graviton Getting Started Guide</a> is a technical guide covering how to build, run, and optimize workloads on Graviton-based instances. The <a href="https://docs.aws.amazon.com/guidance/latest/cloud-intelligence-dashboards/graviton-savings-dashboard.html">Graviton Savings Dashboard</a> helps you track and measure the cost savings from running workloads on Graviton-based instances. And <a href="https://aws.amazon.com/blogs/compute/migrating-your-java-applications-to-aws-graviton-using-aws-transform-custom/">AWS Transform</a> is an AI-powered service that automates code transformations for migrating Java applications from x86 to Graviton-based Amazon EC2 instances, handling compatibility analysis, automated recompilation, dependency updates, and validation.</p><p>To learn more about Graviton-based instances, visit <a href="https://aws.amazon.com/ec2/graviton/">AWS Graviton Processors</a> or <a href="https://aws.amazon.com/ec2/graviton/level-up-with-graviton/">Level up your compute with AWS Graviton</a>.</p><a href="https://www.linkedin.com/in/esrakayabali/">— Esra</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="4e2df662-7fd9-4334-bb0e-7ddc0be6fcef" data-title="Now available: Amazon EC2 M9g and M9gd instances powered by new AWS Graviton5 processors" data-url="https://aws.amazon.com/blogs/aws/now-available-amazon-ec2-m9g-and-m9gd-instances-powered-by-new-aws-graviton5-processors/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/now-available-amazon-ec2-m9g-and-m9gd-instances-powered-by-new-aws-graviton5-processors/"/>
    <updated>2026-06-10T17:04:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/anthropic-claude-fable-5-on-aws-mythos-class-capabilities-with-built-in-safeguards-now-available/</id>
    <title><![CDATA[Anthropic Claude Fable 5 on AWS: Mythos-class capabilities with built-in safeguards now available]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the availability of <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Claude Fable 5</a> on <a href="https://aws.amazon.com/bedrock/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock</a> and <a href="https://aws.amazon.com/claude-platform/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Claude Platform on AWS</a>. Claude Fable 5 makes Mythos-level capabilities available to all customers, with strong safeguards designed to make it safe for broader use. Fable 5 is state-of-the-art on nearly all tested benchmarks and delivers exceptional performance in software engineering, knowledge work tasks, and vision – built for ambitious, long running work.</p><p>With Claude Fable 5 on Bedrock, you can build within your existing AWS environment and scale inference workloads. You can also use Claude Fable 5 through the Claude Platform on AWS, giving you Anthropic’s native platform experience.</p><p>According to Anthropic, Claude Fable 5 represents a step-change in what you can accomplish with AI models. Here is what makes this model different:</p><ul><li><strong>Long-running, asynchronous execution</strong> — Claude Fable 5 handles complex tasks that previous models could not sustain, executing coding and knowledge work tasks for extended periods without intervention.</li>
<li><strong>Advanced vision capabilities</strong> — Claude Fable 5 understands diagrams, charts, and tables nested in files and PDFs. This opens up research and document-heavy work in finance, legal, analytics, architecture, and gaming. In coding, the model implements designs with high fidelity and uses vision to critique its output against goals.</li>
<li><strong>Proactive self-verification</strong> — The model self-updates skills based on learnings, develops its own harnesses and evaluations.</li>
</ul><p>Claude Fable 5 includes safeguards that limit its performance in specific areas where misuse risk is elevated. Harmful prompts related to cybersecurity, biology, chemistry, and health fall back to receive a response from Opus 4.8 instead. Anthropic is able to expand access to nearly all of Claude Fable 5’s state-of-the-art capabilities by developing more powerful safeguards. The same model without these limits is <a href="https://www.anthropic.com/news/claude-fable-5-mythos-5">Claude Mythos 5</a> and it will only be available to a small group of vetted customers.</p><p><strong class="c6">Claude Fable 5 model in action</strong><br />You can use Claude Fable 5 in both Amazon Bedrock and Claude Platform on AWS. This post will cover guidance on how to access and use on Amazon Bedrock. For guidance on the Claude Platform on AWS, visit the <a href="https://docs.aws.amazon.com/claude-platform/latest/userguide/welcome.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">documentation</a> to learn more.</p><p>To get started with Amazon Bedrock, you can only access the model programmatically now using the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/model-parameters-anthropic-claude-messages.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Anthropic Messages API</a> to call the <code>bedrock-runtime</code> or <code>bedrock-mantle</code> endpoints through Anthropic SDK. You can sole keep using the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/inference-api.html" target="_blank" rel="noopener noreferrer">Invoke</a> and <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/conversation-inference.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Converse API</a> on <code>bedrock-runtime</code> through the <a href="https://aws.amazon.com/cli/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS Command Line Interface (AWS CLI)</a> and <a href="https://aws.amazon.com/developer/tools/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS SDK</a>. The console support is coming soon.</p><p>In order to access Claude Fable 5 model, you must opt into data sharing by using the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Data Retention API</a> and setting <code>provider_data_sharing</code> before you can invoke the models. There is no console user interface for this setting at launch.</p><pre class="lang-bash">curl -X PUT https://bedrock-mantle.us-east-1.api.aws/v1/data_retention \
  -H "x-api-key: &lt;your-bedrock-api-key&gt;" \ 
  -H "Content-Type: application/json" \
  -d '{ "mode": "provider_data_share" }'</pre><p>This mode allows Amazon Bedrock to retain and share your inference data with model providers per their requirements. Anthropic requires 30-day inputs and outputs retention, as well as human review. To learn more, visit the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/abuse-detection.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock abuse detection</a>.</p><p>Let’s start with Anthropic SDK for Python using the Messages API on <code>bedrock-mantle</code> endpoint. Install Anthropic SDK.</p><pre class="lang-bash">pip install anthropic</pre><p>Here is a sample Python code to call Claude Fable 5 model:</p><pre class="lang-python">import anthropic
client = anthropic.Anthropic(
    base_url="https://bedrock-mantle.us-east-1.api.aws/anthropic",
    api_key= &lt;your-bedrock-api-key&gt;
)
message = client.messages.create( 
     model="anthropic.claude-fable-5", 
         max_tokens=4096, 
         messages=[ 
             { "role": "user", 
                   "content": "Design a distributed architecture on AWS in Python that should support 100k requests per second across multiple geographic regions", 
                 }, 
         ], 
)
print(message.content[0].text)</pre><p>To learn more, check out <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/api-inference-examples-claude-messages-code-examples.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Anthropic Messages API code examples</a> and <a href="https://github.com/aws-samples/anthropic-on-aws/tree/main/notebooks">notebook examples</a> for multiple use cases and a variety of programming languages.</p><p>You can also use Claude Fable 5 with the Invoke API and Converse API on <code>bedrock-runtime</code> endpoint. Here’s a example to call Converse API for a unified multi-model experience using the AWS SDK for Python (Boto3):</p><pre class="lang-python">import boto3 
bedrock_runtime = boto3.client("bedrock-runtime", region_name="us-east-1") 
response = bedrock_runtime.converse( 
    modelId="us.anthropic.claude-fable-5", 
    messages=[ 
        { 
            "role": "user", 
            "content": [ 
                { 
                    "text": "Design a distributed architecture on AWS in Python that should support 100k requests per second across multiple geographic regions." 
                } 
            ] 
        } 
    ], 
    inferenceConfig={ 
        "maxTokens": 4096 
    } 
) 
print(response["output"]["message"]["content"][0]["text"]) </pre><p>To learn more, visit <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/service_code_examples_bedrock-runtime_anthropic_claude.html">code examples</a> that show how to use Amazon Bedrock Runtime with AWS SDKs.</p><p><strong>Things to know</strong><br />Let me share some important technical details that I think you’ll find useful.</p><ul><li><strong>Model access</strong> — Claude Fable 5 access is gradually expanding for all AWS accounts. If your account doesn’t have access yet, it will be enabled soon depending on your Bedrock usage. If you want to get access to this model quickly, contact your usual AWS Support.</li>
<li><strong>Pricing</strong> — When a harmful prompt is routed to Opus 4.8 instead of Fable 5, you pay only Opus prices. If a request is blocked mid-conversation, initial tokens are charged at Fable rates and subsequent tokens at Opus rates. To learn more, visit the <a href="https://aws.amazon.com/bedrock/pricing/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon Bedrock pricing</a> page.</li>
<li><strong>Data retention</strong> — For Fable 5, Mythos 5, and future models on Bedrock with similar or higher capability levels, Anthropic will require 30-day retention for all traffic on Mythos-class models. Retaining data for a limited period allows Anthropic to detect patterns of misuse that are not visible from a single exchange. Once you opt into data retention, your data will leave AWS’s data and security boundary.</li>
<li><strong>Claude Mythos 5 on Bedrock (Limited Preview)</strong> – You can also use Anthropic’s most capable model for cybersecurity and life sciences, including vulnerability discovery, drug design, and biodefense screening. Access is currently limited due to the dual-use nature of these domains. To learn more, visit the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/model-card-anthropic-claude-mythos-5.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">model card documentation</a>.</li>
</ul><p><strong class="c6">Now available</strong><br />Anthropic’s Claude Fable 5 model is available today on Amazon Bedrock in the US East (N. Virginia) and Europe (Stockholm) Regions; check the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/model-card-anthropic-claude-fable-5.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">full list of Regions</a> for future updates. Claude Fable 5 is also available on the Claude Platform on AWS in North America, South America, Europe, and Asia Pacific.</p><p>Give Claude Fable 5 a try with the Amazon Bedrock APIs, in the <a href="https://console.aws.amazon.com/claude-platform/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Claude Platform on AWS</a>, and send feedback to <a href="https://repost.aws/tags/TAQeKlaPaNRQ2tWB6P7KrMag/amazon-bedrock?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Amazon Bedrock</a> or through your usual AWS Support contacts.</p><p>— <a href="https://twitter.com/channyun">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="3d8b85a3-48f5-4786-b2bf-6c59931bf8ec" data-title="Anthropic Claude Fable 5 on AWS: Mythos-class capabilities with built-in safeguards now available" data-url="https://aws.amazon.com/blogs/aws/anthropic-claude-fable-5-on-aws-mythos-class-capabilities-with-built-in-safeguards-now-available/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/anthropic-claude-fable-5-on-aws-mythos-class-capabilities-with-built-in-safeguards-now-available/"/>
    <updated>2026-06-09T19:40:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-byom-for-amazon-rds-for-sql-server-aws-iot-device-sdk-for-swift-and-more-june-8-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: BYOM for Amazon RDS for SQL Server, AWS IoT Device SDK for Swift, and more (June 8, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>This week, the <a href="https://aws.amazon.com/blogs/developer/announcing-the-general-availability-of-the-aws-iot-device-sdk-for-swift/">AWS IoT Device SDK for Swift</a> reached general availability. As a member of the <a href="https://swift.org/sswg">Swift Server Workgroup (SSWG)</a>, this one caught my attention. The SDK brings production-ready MQTT 5 connectivity, Device Shadow, Jobs, and fleet provisioning to Swift developers on macOS, iOS, tvOS, and Linux.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/Gemini_Generated_Image_sdi7hqsdi7hqsdi7.jpg"><img class="aligncenter size-large wp-image-104245" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/Gemini_Generated_Image_sdi7hqsdi7hqsdi7-1024x559.jpg" alt="Swift on IoT and Edge devices, an AI generated illustration" width="1024" height="559" /></a></p><p>I’m curious to see what you will build with it. Swift on the server has matured over the past few years, and now it reaches IoT devices too. This connects to a broader trend of running Swift at the edge. <a href="https://wendy.dev/">WendyOS</a>, for example, is an open-source operating system for physical AI that offers first-class Swift support for deploying apps to NVIDIA Jetson and Raspberry Pi hardware. Between server-side Swift, IoT, and edge computing, the language is showing up in places that would have surprised most people a few years ago.</p><p>Now, let’s get into this week’s AWS news.</p><p><strong>Headlines<br /></strong> <strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/rds-sqlserver-supports-bring-your-own-media/">Amazon RDS for SQL Server supports Bring Your Own Media</a></strong> — Customers who migrate SQL Server applications from on-premises environments can now reuse their existing Microsoft SQL Server licenses, including Software Assurance, through Microsoft’s License Mobility program on Amazon RDS. BYOM is integrated with AWS License Manager for tracking license usage and compliance. <a href="https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/sqlserver-byom.html">Read more</a>.</p><p><a href="https://aws.amazon.com/blogs/aws/improve-your-application-resilience-with-amazon-cognito-multi-region-replication/"><strong>Amazon Cognito now supports multi-Region replication</strong></a> — You can now synchronize user and machine identity data, including credentials, user pool configurations, and federation setups, to a secondary user pool in a standby Region in near real-time. In the event of a disruption in the primary Region, signed-in users continue accessing their applications without re-authenticating, and registered users can sign in with their existing credentials. Multi-Region replication is available as an add-on for user pools in Essentials or Plus feature tiers across 16 Regions. <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-cognito-multi-region/">Read more</a>.</p><p><a href="https://aws.amazon.com/blogs/aws/get-started-with-openai-gpt-5-5-gpt-5-4-models-and-codex-on-amazon-bedrock/"><strong>GPT-5.5, GPT-5.4, and Codex from OpenAI are now generally available on Amazon Bedrock</strong></a> — You can now use GPT-5.5 and GPT-5.4 in production workloads on Amazon Bedrock and build with Codex for AI-powered software development, with the same security, governance, and operational controls you already use across AWS. GPT-5.5 is the most capable model from OpenAI, excelling at agentic coding, data analysis, and multi-step autonomous tasks. Codex is available through the Codex App, the Codex CLI, and IDE integrations with Visual Studio Code, JetBrains, and Xcode. Pricing matches OpenAI first-party rates, and usage counts toward existing AWS commitments. <a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-bedrock-openai-models-codex-generally-available/">Read more</a>.</p><p><strong>Last week’s launches<br /></strong> Here are some launches and updates from this past week that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-bedrock-supports-cloudwatch-metrics-bedrock-mantle-endpoint/">Amazon Bedrock adds CloudWatch metrics for OpenAI- and Anthropic-compatible APIs</a> — You can now monitor inference traffic to the bedrock-mantle endpoint with CloudWatch metrics, including inference counts, input and output token totals, and client error counts at account, project, model, and project-and-model granularity.</li>
<li><a href="https://aws.amazon.com/blogs/aws/try-the-new-console-experience-in-amazon-bedrock-optimized-for-anthropic-and-openai-compatible-apis/">Amazon Bedrock launches a redesigned console optimized for OpenAI- and Anthropic-compatible APIs</a> — A refreshed console workflow with a model catalog, side-by-side comparison, project-based organization, and project-aware documentation with pre-filled code snippets.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/agentcore-identity-secrets-manager/">Amazon Bedrock AgentCore Identity now supports bring-your-own secrets with AWS Secrets Manager</a> — Customers can now reference existing AWS Secrets Manager secret ARNs in AgentCore Identity Credential Providers, enabling full ownership of secrets governance including custom CMKs, tagging strategies, and automatic rotation.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-step-functions-agentcore/">AWS Step Functions adds AgentCore-powered agentic reasoning step</a> — You can now add AI agent reasoning steps to your Step Functions workflows through an integration with the managed harness in Amazon Bedrock AgentCore. Run multiple agents in parallel or sequence, add human approval, and trace every agent decision.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-eks-distro-kubernetes-version-1-36/">Amazon EKS and Amazon EKS Distro now support Kubernetes version 1.36</a> — Kubernetes 1.36 promotes User Namespaces to GA, introduces Mutating Admission Policies, In-Place Pod-Level Resources Vertical Scaling, and Resource Health Status reporting. Available in all Regions where EKS is available.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-ecs-managed-instances-neuron/">Amazon ECS Managed Instances now supports AWS Trainium and AWS Inferentia</a> — You can now create an ECS Managed Instances capacity provider with Inferentia2, Trainium1, and Trainium2 instance types and have Amazon ECS automatically allocate all accelerator resources to your workload.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-quick-vpc-mcp/">Amazon Quick now supports VPC connectivity for MCP connections</a> — Enterprise customers can now connect privately hosted Model Context Protocol (MCP) servers to Amazon Quick through VPC, enabling secure access to proprietary applications and internal tools without exposing them to the internet.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/aws-cur2.0-athena-redshift/">AWS Cost and Usage Report 2.0 now supports Athena and Redshift integration</a> — CUR 2.0 exports are automatically delivered in the optimal format for your chosen query engine, with supporting infrastructure templates, table definitions, and data loading instructions.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-location-service/amazon-location-new-public-transit-intermodal-routing/">Amazon Location Service announces public transit and intermodal routing</a> — The Routes API now supports two new travel modes, Transit and Intermodal, to plan journeys combining public transportation with walking, driving, taxi, and rental segments across 13 Regions.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong>Upcoming AWS events<br /></strong> Learn more about AWS, browse and join upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe" target="_blank" rel="noopener noreferrer">AWS-led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?tab=upcoming?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">developer-focused events</a> as well as <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS Summits</a> and <a href="https://aws.amazon.com/events/community-day/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS Community Days</a>. Join the <a href="https://builder.aws.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development. <strong><br /></strong></p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="3a6c7878-3591-42c8-baac-192e4fd7fcda" data-title="AWS Weekly Roundup: BYOM for Amazon RDS for SQL Server, AWS IoT Device SDK for Swift, and more (June 8, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-byom-for-amazon-rds-for-sql-server-aws-iot-device-sdk-for-swift-and-more-june-8-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-byom-for-amazon-rds-for-sql-server-aws-iot-device-sdk-for-swift-and-more-june-8-2026/"/>
    <updated>2026-06-08T23:27:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/try-the-new-console-experience-in-amazon-bedrock-optimized-for-anthropic-and-openai-compatible-apis/</id>
    <title><![CDATA[Try the new console experience in Amazon Bedrock, optimized for Anthropic- and OpenAI-compatible APIs]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing a new console experience in <a href="https://aws.amazon.com/bedrock/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock</a> for you to experiment, iterate, and scale with the latest AI models on Amazon Bedrock’s next-generation inference engine built for high performance, reliability, and security. This console has a refreshed workflow optimized for <code>bedrock-mantle</code> endpoint, which supports the latest GPT, Claude, and open-weight models with the OpenAI Responses API, OpenAI Chat Completions API, and the Anthropic Messages API.</p><p>The new console experience makes it simple to find the right model and move quickly from evaluation to production.</p><ul><li><strong>New model card</strong> – You can browse the full model catalog, compare them side by side on capabilities, modality support, context window, and applicable service quotas in a single view, removing the need to stitch together documentation, and limit calculators.</li>
<li><strong>Project-based work</strong> – You can make a project to run evaluations and review usage insights in one streamlined workflow that mirrors the lifecycle of building a generative AI application.</li>
<li><strong>Live documentation</strong> – You can use project-aware live documentation: code samples, SDK snippets, and API references are automatically prefilled with your project variables. You can copy a snippet straight from the console into your application and run it without modification.</li>
</ul><p><strong class="c6">How to get started</strong><br />You can try new experience by choosing the <strong>Try the Bedrock Mantle Console</strong> from within the <a href="https://console.aws.amazon.com/bedrock/home?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock console</a> or using the <a href="https://console.aws.amazon.com/bedrock-mantle/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">new console link</a>.</p><p><img class="aligncenter wp-image-104227 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/2026-new-bedrock-console-0.jpg" alt="" width="1796" height="779" /></p><p>You can find a project-based dashboard to show inference requests and error by range of recent dates, recently used models, and the project list. You can create a project, assign models, configure API keys, and start making inference requests in minutes.</p><p><img class="aligncenter wp-image-104229 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/2026-new-bedrock-console-1-home.jpg" alt="" width="1800" height="1630" /></p><p>A new model catalog shows the latest GPT, Claude, and open-weight models that are supported on the <code>bedrock-mantle</code> engine. You can see the details of features, tokens, pricing, input/output, pricing information, and Regional availability. You can also compare up to 3 models in a single view.</p><p><img class="aligncenter size-full wp-image-104230 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/2026-new-bedrock-console-1-model-card.jpg" alt="" width="1800" height="972" /></p><p>When you choose the project dashboard, you can see the models used in the project, the distribution of your token usage such as total token usage, token usage per minute, inference requests per minute, and tokens per inference request. This can inform your model selection, prompt optimization, and workload consistency decisions.</p><p><img class="aligncenter size-full wp-image-104231 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/2026-new-bedrock-console-2-project.jpg" alt="" width="1800" height="991" /></p><p>You can select up to 3 models to start evaluating to compare responses side by side with the same prompt.</p><p><img class="aligncenter size-full wp-image-104232 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/2026-new-bedrock-console-2-evaluation.jpg" alt="" width="1800" height="977" /></p><p>To build your application in the project, choose <strong>Getting started</strong>. You can migrate existing code, build a new app with the Anthropic or OpenAI SDK, or connect an AI coding assistant to Bedrock.</p><p>Choose the <strong>API &amp; SDK</strong>, your SDK (either Anthropic or OpenAI), your preferred programming language, and your authentication method. It shows your environment code to run these in your terminal for a quick test, or save to a <code>.env</code> file for your application. You can also send your first request with sample code snippets to verify your setup.</p><p>When you choose <strong>Clients</strong>, you can select the AI coding agent source such as Claude Code, Cline, Codex, Cursor, or OpenCode that you want to connect to the <code>bedrock-mantle</code> engine. It provides instructions on how to install the AI agent, use your AWS IAM credentials or use a Bedrock API key, set environment variables, and route requests from each AI agent through Bedrock.</p><p><img class="aligncenter size-full wp-image-104234 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/2026-new-bedrock-console-3-getstarted.jpg" alt="" width="1800" height="1932" /></p><p>To learn about Anthropic- and OpenAI-compatible APIs, choose <strong>Live API docs</strong>. You can choose <strong>Anthropic API Protocol</strong> for access to Claude model features like the Messages API or <strong>OpenAI API Protocol</strong> for access to features like Responses API.</p><p>For example, when you choose OpenAI Response API, it retrieves a model response with the given model ID. These API references are automatically prefilled with the project’s selected model ID, Region, <code>bedrock-mantle</code> endpoint URL, and API key reference, and they update in place as you change models or settings.</p><p><img class="aligncenter wp-image-104235 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/05/2026-new-bedrock-console-3-livedoc.jpg" alt="" width="1800" height="1929" /></p><p>You can also choose the existing Bedrock console to manage fully-managed features such as Agents, Knowledge Bases, Guardrails, fine-tuning, or the InvokeModel and Converse APIs to run on the <code>bedrock-runtime</code> endpoint.</p><p><strong class="c6">Now available</strong><br />The new console experience is available in all AWS Regions where the <code>bedrock-mantle</code> endpoint is offered: US East (N. Virginia, Ohio), US West (Oregon), Asia Pacific (Jakarta, Mumbai, Sydney, Tokyo), Europe (Frankfurt, Ireland, London, Milan, Stockholm), and South America (São Paulo). Check the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/models-region-compatibility.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">full list of Regions</a> for future updates.</p><p>Give the new console experience a try in the <a href="https://console.aws.amazon.com/bedrock-mantle/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">new Amazon Bedrock console</a> and send feedback to <a href="https://repost.aws/tags/TAQeKlaPaNRQ2tWB6P7KrMag/amazon-bedrock?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Amazon Bedrock</a> or through your usual AWS Support contacts.</p><p>— <a href="https://twitter.com/channyun">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="05aafed5-cf82-41b3-b8da-36d94361c8a8" data-title="Try the new console experience in Amazon Bedrock, optimized for Anthropic- and OpenAI-compatible APIs" data-url="https://aws.amazon.com/blogs/aws/try-the-new-console-experience-in-amazon-bedrock-optimized-for-anthropic-and-openai-compatible-apis/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/try-the-new-console-experience-in-amazon-bedrock-optimized-for-anthropic-and-openai-compatible-apis/"/>
    <updated>2026-06-05T21:15:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/improve-your-application-resilience-with-amazon-cognito-multi-region-replication/</id>
    <title><![CDATA[Improve your application resilience with Amazon Cognito multi-Region replication]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>As a developer advocate working with web and mobile application developers, I’ve often heard about the need to maintain consistent user authentication in the unlikely event of a regional service interruption. The increasing use of agentic AI, microservices, automation, and service accounts has sparked a similar need for machine-to-machine authentication. Today, I’m excited to share two important updates to Amazon Cognito: <strong>multi-Region replication</strong> for improved resilience, and support for <strong>customer managed keys</strong> for more control encryption control.</p><p>Many applications rely on Amazon Cognito to handle user and machine-to-machine authentication, and to manage user profiles. When building for high availability, having consistent data across different AWS Regions is a key approach, and until now, achieving that consistency came with significant challenges. Engineering teams spent significant time building and maintaining custom replication solutions to synchronize configurations across Regions. Manual export and import of user data between Regions created security risks from potential data exposure and introduced opportunities for data inconsistencies. During regional transitions, end users experienced disruptions like forced password resets and re-authentication. For machine-to-machine communications, teams had to create new app clients in the secondary region, which meant reconfiguring their applications and updating OAuth-protected resources to accept access tokens issued by the new regional issuer. These challenges made it difficult to maintain uninterrupted operations across Regions.</p><p>With multi-Region replication, Amazon Cognito automatically maintains a synchronized copy of your user data and machine secrets in a secondary AWS Region of your choice. The replication flows in one direction, from your primary Region to the secondary Region. This includes user profiles, credentials, and pool configurations. The secondary Region operates in read-only mode, focusing on maintaining authentication capabilities. Existing sessions continue uninterrupted.</p><p>When you need to direct traffic to the secondary Region, your existing users can continue signing in with their existing credentials without disruption, and currently signed-in users remain authenticated because both regions recognize access tokens issued by either region. Multi-Region replication supports all authentication methods, including federated sign-in through social providers (Amazon, Google, Apple, Facebook), Security Assertion Markup Language (SAML) and OpenID Connect (OIDC) integrations, and API authorization flows. This approach maintains availability for both customer-facing applications and machine-to-machine communications in your backend services. While authentication continues without interruption, operations like new user registration or profile updates are not available during failover.</p><p>Before configuring multi-Region replication, you must configure a multi-Region customer managed key stored in <a href="https://aws.amazon.com/kms/">AWS Key Management Service (AWS KMS)</a> to encrypt your user data at rest. These keys provide consistent encryption across Regions while giving you control over your encryption strategy.</p><p><strong>How this works in practice<br /></strong> I start this demo with an existing Cognito user pool in the <code>us-west-2</code> (Oregon) Region. I want to configure replication to <code>us-east-1</code> (Northern Virginia). I also have a customer managed key replicated in these two Regions.</p><p>Configuring multi-Region replication is just three steps. The <a href="https://console.aws.amazon.com">AWS Management Console</a> guides me through the steps: set up a custom key for encryption, configure multi-region OIDC endpoints, and configure the replication itself.</p><p>First, I set up a custom AWS KMS key to encrypt the data at rest.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/22/Screenshot-2026-04-21-at-1.27.34%E2%80%AFPM.png"><img class="aligncenter size-large wp-image-103762" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/22/Screenshot-2026-04-21-at-1.27.34%E2%80%AFPM-1024x538.png" alt="Cognito Multi-Region replication - initial state" width="1024" height="538" data-wp-editing="1" /></a></p><p>I select the custom key I created. I also update the key policy to allow Amazon Cognito to access and use the key. The console shows the correct IAM policy statements to add to my key policy.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/2025-11-13_14-12-57.png"><img class="aligncenter size-large wp-image-100881" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/2025-11-13_14-12-57-1024x754.png" alt="Cognito Multi-Region replication - select CMK" width="1024" height="754" /></a></p><p>The console confirms when the custom key is selected and correctly configured.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/2025-11-13_14-13-25.png"><img class="aligncenter size-large wp-image-100882" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/2025-11-13_14-13-25-1024x471.png" alt="Cognito Multi-Region replication - confirm CMK" width="1024" height="471" /></a></p><p>Second, I follow the console instructions to configure the OIDC issuer type. On <strong>Step 2 – optional</strong>, I choose <strong>Configure</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/24/Screenshot-2026-04-24-at-8.48.56%E2%80%AFAM.png"><img class="aligncenter wp-image-103804 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/24/Screenshot-2026-04-24-at-8.48.56%E2%80%AFAM-1024x442.png" alt="Cognito Multi-Region replication - configure multi region OIDC 1" width="1024" height="442" /></a></p><p>I make sure to update my client applications with these new endpoints. This is a required change that will need a redeployment of server-side applications and an update submission for mobile apps on the App Store and Google Play. If I don’t update the endpoints, my users will experience disruptions because requests to the old endpoints will no longer be routed correctly.</p><p>On the next screen, I select <strong>Updated</strong>. I take note of the new URLs. I confirm the changes and choose <strong>Change issuer type</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/24/Screenshot-2026-04-24-at-8.49.32%E2%80%AFAM.png"><img class="aligncenter wp-image-103805 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/24/Screenshot-2026-04-24-at-8.49.32%E2%80%AFAM-1024x532.png" alt="Cognito Multi-Region replication - configure multi region OIDC 2" width="1024" height="532" /></a>Finally, I select the target Region for replication. Only Regions where the custom encryption key is replicated are available for selection. After having chosen the target Region, I choose <strong>Create</strong>.<a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/27/Screenshot-2026-04-24-at-12.30.41%E2%80%AFPM.png"><img class="aligncenter wp-image-103808 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/27/Screenshot-2026-04-24-at-12.30.41%E2%80%AFPM-1024x463.png" alt="Cognito Multi-Region replication - start the replication process" width="1024" height="463" /></a>.</p><p>The service prepares the replication. The time needed depends on the amount of data in the user pool.</p><p>When the replicated user pool is ready, I manually <strong>Activate</strong> it.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/2025-11-13_16-38-40.png"><img class="aligncenter wp-image-100888 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/2025-11-13_16-38-40-e1763048830128-1024x184.png" alt="Cognito Multi-Region replication - replication process is complete" width="1024" height="184" /></a></p><p>The replication status becomes <strong>Active</strong>. It is ready to direct traffic to the replica.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/2025-11-13_16-44-19.png"><img class="aligncenter size-large wp-image-100889" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/2025-11-13_16-44-19-1024x113.png" alt="Cognito Multi-Region replication - active" width="1024" height="113" /></a></p><p><strong>Additional configurations<br /></strong> The console helps me to keep track of additional configurations I have to plan. When I’m using <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-working-with-lambda-triggers.html">Lambda functions</a> for <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/amazon-cognito-user-pools-authentication-flow-methods.html">custom authentication flows</a> or SMS or email notifications, I must also deploy and configure these resources in the new Region.</p><p>Similarly, log streaming or <a href="https://aws.amazon.com/waf">AWS WAF</a> configuration must be manually configured in the target Region before I start directing authentication traffic to it.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/2025-11-13_16-43-11-copy.png"><img class="aligncenter size-large wp-image-100890" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/2025-11-13_16-43-11-copy-1024x443.png" alt="Cognito Multi-Region replication - task list" width="1024" height="443" /></a></p><p><strong>Health checks and failover<br /></strong> Both primary and secondary regional endpoints remain active and ready to serve your traffic at all times. To monitor system health and manage failovers, you design a strategy that aligns with your application’s specific requirements and security posture. You can implement health checks to monitor the status of authentication services in your primary Region and define criteria for when to initiate failover. These checks might look for error rates, latency patterns, or specific service alerts.</p><p>When your monitoring system detects issues meeting your failover criteria, you can redirect traffic to the secondary Region through DNS updates. This approach gives you control over the failover process while maintaining security. Consider testing your failover strategy during off-peak hours by redirecting a small portion of traffic to verify that authentication continues working as expected in the secondary Region.</p><p>When using managed login and federation with custom domains, you can also use the built-in traffic routing feature by providing an <a href="https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/welcome-health-checks.html">Amazon Route 53 health check ID</a>.</p><p><strong>Pricing and availability<br /></strong> Multi-Region replication is available today as an add-on feature for Amazon Cognito customers using Essentials and Plus tier. For user authentication, the add-on costs $0.0045 per monthly active user per replica Region for Essentials tier customers and $0.006 per monthly active user per replica region for Plus tier customers. For machine-to-machine (M2M) authentication, the add-on is a 30% charge on top of the standard volume-based pricing for successful tokens issued. For detailed pricing information, <a href="https://aws.amazon.com/cognito/pricing/">see Amazon Cognito pricing</a>.</p><p>Multi-Region replication is available in the following Regions: US East (Ohio, N. Virginia), US West (N. California, Oregon), Asia Pacific (Mumbai, Seoul, Singapore, Sydney, Tokyo), Canada (Central), Europe (Frankfurt, Ireland, London, Paris, Stockholm), and South America (São Paulo).</p><p>Any of these Regions can be used as the source or the destination for the replication.</p><p>Support for customer managed keys is available for the Essentials and Plus tiers. It is available in the following Regions: US East (Ohio, N. Virginia), US West (N. California, Oregon), Africa (Cape Town), Asia Pacific (Hong Kong, Hyderabad, Jakarta, Malaysia, Melbourne, Mumbai, New Zealand, Osaka, Seoul, Singapore, Sydney, Thailand, Tokyo), Canada (Central), Canada West (Calgary), Europe (Frankfurt, Ireland, London, Milan, Paris, Spain, Stockholm, Zurich), Israel (Tel Aviv), Mexico (Central), South America (São Paulo), and AWS GovCloud (US-East, US-West)</p><p>From my conversations with customers, maintaining business continuity during regional incidents while meeting security requirements is a high priority. Multi-Region replication provides the capability to build more resilient applications without managing complex replication logic yourself. The automatic synchronization of user data and configurations reduces operational overhead while maintaining security.</p><p>For customers in regulated industries, the new support for customer managed keys provides additional control over data encryption. You can now use your own encryption keys to protect user data at rest, helping you meet regulatory requirements in industries like healthcare and financial services.</p><p>To get started with multi-Region replication and customer managed key encryption, visit t<a href="https://console.aws.amazon.com/cognito">he Amazon Cognito console</a> or see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/user-pool-multi-region.html">the documentation</a> for detailed setup instructions. I look forward to hearing how you use this feature to strengthen your application architecture.</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="def77851-bbf6-455d-84a9-b0397ad26dd2" data-title="Improve your application resilience with Amazon Cognito multi-Region replication" data-url="https://aws.amazon.com/blogs/aws/improve-your-application-resilience-with-amazon-cognito-multi-region-replication/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/improve-your-application-resilience-with-amazon-cognito-multi-region-replication/"/>
    <updated>2026-06-04T00:37:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/get-started-with-openai-gpt-5-5-gpt-5-4-models-and-codex-on-amazon-bedrock/</id>
    <title><![CDATA[Get started with OpenAI GPT-5.5, GPT-5.4 models, and Codex on Amazon Bedrock]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>As we <a href="https://www.aboutamazon.com/news/aws/bedrock-openai-models?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">previewed in What’s Next with AWS 2026</a>, we’re announcing the general availability of OpenAI GPT-5.5, GPT-5.4 models, and Codex on <a href="https://aws.amazon.com/bedrock/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock</a>, giving you access to frontier models and a coding agent for software development.</p><p>According to OpenAI, GPT-5.5 and GPT-5.4 models are excellent for coding, reasoning, agentic workflows, and complex professional work. You can use GPT-5.5 for the hardest customer workloads and GPT-5.4 for the best price-performance. You can call them through <code>Responses</code> API on Amazon Bedrock’s next-generation inference engine built for high performance, reliability, and security.</p><p>Codex is the OpenAI coding agent for AI-powered software development. According to OpenAI, more than 4 million developers use Codex every week to write, refactor, debug, test, and validate code across large codebases. With GPT-5.5 powering inference, Codex introduces a new class of intelligence optimized for complex, long-horizon developer workflows. You can use the Codex App, the Codex CLI, and IDE integrations with Visual Studio Code, JetBrains, and Xcode, with all model inference routed through the <code>Responses</code> API on Amazon Bedrock.</p><p>For customers with data residency requirements, all processing stays within the Bedrock Region you select. You pay per token with no seat licenses and no per-developer commitments.</p><p><strong class="c6">GPT-5.5 and GPT-5.4 models on Bedrock in action</strong><br />You can access the model programmatically using the OpenAI <code>Responses</code> API to call the <code>bedrock-mantle</code> endpoints through the OpenAI SDK, command-line tools such as <code>curl</code>.</p><p>Let’s start with OpenAI SDK for Python. Install OpenAI SDK.</p><pre class="lang-bash">pip install -U openai</pre><p>Set the environment variables for authentication.</p><pre class="lang-bash">export OPENAI_BASE_URL="https://bedrock-mantle.us-east-2.api.aws/openai/v1"
export OPENAI_API_KEY="&lt;BEDROCK_API_KEY&gt;"
export BEDROCK_OPENAI_MODEL_ID="openai.gpt-5.5"
</pre><p>Here is a sample Python code to call GPT-5.5 model on Bedrock:</p><pre class="lang-python">import os
from openai import OpenAI
client = OpenAI(
    base_url=os.environ["OPENAI_BASE_URL"],
    api_key=os.environ["OPENAI_API_KEY"],
)
response = client.responses.create(
    model=os.environ["BEDROCK_OPENAI_MODEL_ID"],
    input=[
        {
            "role": "developer",
            "content": "You are a software engineer with excellent AWS cloud knowledge. Be concise and practical.",
        },
        {
            "role": "user",
            "content": "Design a distributed architecture on AWS in Python that should support 100k requests per second across multiple geographic regions.",
        },
    ],
    reasoning={"effort": "medium"},
    text={"verbosity": "low"},
)
print(response.output_text)</pre><p>You can call directly the model endpoint using <code>curl</code>.</p><pre class="lang-bash">curl "$OPENAI_BASE_URL/responses" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $OPENAI_API_KEY" \
  -d '{
    "model": "openai.gpt-5.5",
    "input": [
      {
        "role": "developer",
        "content": "You are a software engineer with excellent AWS cloud knowledge."
      },
      {
        "role": "user",
        "content": "Design a distributed architecture on AWS in Python that should support 100k requests per second across multiple geographic regions."
      }
    ],
    "reasoning": {"effort": "medium"},
    "text": {"verbosity": "low"}
  }'</pre><p>You can use the <code>Responses</code> API when you want to use model-managed multi-turn state, need hosted tools, function tools, or richer tool orchestration, and run background or long-running work. To learn more, visit the <a href="https://github.com/openai/openai-cookbook/tree/main/examples">OpenAI Cookbook Responses examples</a>.</p><p><strong class="c6">Using OpenAI Codex with GPT-5.5 on Amazon Bedrock</strong><br />You can download Codex CLI, Codex App or Codex VS Code extension and get started with the Bedrock for model inference. Codex supports two Bedrock authentication pathways: <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/api-keys.html">Amazon Bedrock API key</a> or AWS SDK credential chain. If you set <code>AWS_BEARER_TOKEN_BEDROCK</code>, Codex uses it first; otherwise Codex falls back to AWS SDK credential chain.</p><p>Set <code>AWS_BEARER_TOKEN_BEDROCK</code> in the environment that Codex will read:</p><pre class="lang-bash">export AWS_BEARER_TOKEN_BEDROCK=&lt;your-bedrock-api-key&gt;</pre><p>Then, configure your preferred Region and set the model ID to <code>openai.gpt-5.5</code> in <code>~/.codex/config.toml</code>, which is required for Bedrock API-key authentication. You can also choose <code>openai.gpt-5.4</code>, <code>openai.gpt-oss-120b</code>, or <code>openai.gpt-oss-20b</code>. For the desktop app or VS Code extension, put any environment variables the app needs in <code>~/.codex/.env</code>.</p><pre class="lang-json">model = "openai.gpt-5.5"
model_provider = "amazon-bedrock"
[model_providers.amazon-bedrock.aws]
region = "us-east-2"</pre><p>Restart the desktop app or VS Code extension after changing <code>~/.codex/config.toml</code> or <code>~/.codex/.env</code>. In Codex CLI, you should see a <code>/status</code> tab that looks like this:</p><p><img class="aligncenter wp-image-104157 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/06/01/2026-codex-on-bedrock.png" alt="" width="1656" height="656" /></p><p>In Codex App, you can use GPT-5.5 model through Amazon Bedrock inference.</p><p><img class="aligncenter wp-image-104068 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/26/2026-codex-on-bedrock-desktop-1.jpg" alt="" width="2228" height="1214" /></p><p><strong>Things to know</strong><br />Let me share some important technical details that I think you’ll find useful.</p><ul><li><strong>Model latency</strong>: OpenAI model information positions GPT-5.5 as fast and GPT-5.4 as medium speed, but customer-perceived latency depends on reasoning effort, output length, tool calls, background mode, Region, quotas, throttling, prompt size, and cache hits. Start GPT-5.5 at <code>medium</code> effort. Start GPT-5.4 with effort set explicitly rather than relying on its <code>none</code> default.</li>
<li><strong>Scaling and capacity</strong>: Bedrock’s new inference engine is designed to rapidly provision and serve capacity across many different models. When accepting requests, we prioritize keeping steady state workloads running, and ramp usage and capacity rapidly in response to changes in demand. During periods of high demand, requests are queued, rather than rejected.</li>
</ul><p><strong class="c6">Now available</strong><br />OpenAI GPT models and Codex on Amazon Bedrock are available today: GPT-5.5 model in the US East (Ohio) Region, GPT-5.4 model in the US East (Ohio) and US West (Oregon) Regions. Check the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/models-region-compatibility.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">full list of Regions</a> for future updates. To learn more, visit the <a href="https://aws.amazon.com/bedrock/openai/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">OpenAI on Amazon Bedrock</a> page and the <a href="https://aws.amazon.com/bedrock/pricing/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon Bedrock pricing</a> page.</p><p>Give GPT-5.5, GPT-5.4 models, and Codex on Amazon Bedrock a try today and send feedback to <a href="https://repost.aws/tags/TAQeKlaPaNRQ2tWB6P7KrMag/amazon-bedrock?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Amazon Bedrock</a> or through your usual AWS Support contacts.</p><p>— <a href="https://twitter.com/channyun">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="c732e3ca-84e7-44f8-aee0-1d6459163390" data-title="Get started with OpenAI GPT-5.5, GPT-5.4 models, and Codex on Amazon Bedrock" data-url="https://aws.amazon.com/blogs/aws/get-started-with-openai-gpt-5-5-gpt-5-4-models-and-codex-on-amazon-bedrock/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/get-started-with-openai-gpt-5-5-gpt-5-4-models-and-codex-on-amazon-bedrock/"/>
    <updated>2026-06-01T23:33:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-opus-4-8-on-aws-aurora-mysql-with-kiro-powers-and-more-june-1-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Claude Opus 4.8 on AWS, Aurora MySQL with Kiro Powers, and more (June 1, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>In my last <a href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-mythos-preview-in-amazon-bedrock-aws-agent-registry-and-more-april-13-2026/">Week in Review post</a>, I shared what I’d been hearing from customers in the <a href="https://aws.amazon.com/blogs/devops/ai-driven-development-life-cycle/">AI-Driven Development Lifecycle (AI-DLC)</a> workshops I’ve been delivering. Last week I was back at it, this time in Denver for a two-day AI-DLC workshop, where I helped facilitate 17 teams to deliver nearly 20 separate use cases in just two days. The pace of acceleration that AI-DLC unlocks—especially when paired with tools like <a href="https://aws.amazon.com/bedrock/claude-code/">Claude Code on Amazon Bedrock</a>—is fundamentally changing how businesses operate. Traditional roles within software development teams are collapsing into smaller, AI-augmented squads, and the paradigm shift is beginning to take place right in front of us. To learn more about how to utilize various AI tools, visit the <a href="https://github.com/awslabs/aidlc-workflows">GitHub repository of AI-DLC workflow</a>.</p><p>This shift is also reshaping how AWS account teams (solutions architects, customer solutions managers, and technical account managers) collaborate with customers. It’s becoming less about handing off advisory design documents and more about building alongside them in real time. It’s a genuinely exciting moment to be in the middle of the change, and this week’s headline launch — Anthropic’s most capable model yet, now on AWS — is going to push that pace even further.</p><p>Now, let’s get into this week’s AWS news…</p><p><strong>Headlines<br /></strong> <strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/claude-opus-4.8-aws/">Claude Opus 4.8 on AWS</a></strong> — Anthropic’s most capable generally available model is now accessible through both Amazon Bedrock and the Claude Platform on AWS. Opus 4.8 is built for agentic coding, knowledge work, and extended autonomous task execution — it sustains longer autonomous sessions with deeper reasoning, recovers from errors, and synthesizes information across lengthy documents. For coding workloads, it reads codebases like an engineer, plans before it edits, and holds context across long sessions. On Amazon Bedrock, you get AWS-managed features like Guardrails, Knowledge Bases, and data residency; on the Claude Platform on AWS, you get Anthropic’s native APIs unified with AWS billing. To learn more, visit the <a href="https://aws.amazon.com/blogs/machine-learning/claude-opus-4-8-is-now-available-on-aws/">deep-dive blog post</a>.</p><p><strong>Last week’s launches</strong><br />Here are some launches and updates from this past week that caught my attention:</p><ul><li><a href="https://aws.amazon.com/blogs/aws/introducing-the-next-generation-of-aws-resilience-hub-for-generative-ai-based-sre-resilience-journey/">Introducing the next generation of AWS Resilience Hub</a> — A reimagined Resilience Hub gives SREs and developers a unified framework to define resilience standards, evaluate applications against them, and demonstrate compliance across an entire portfolio. It introduces modular resilience policies (covering service-level objectives (SLOs), multi-AZ/Region DR, and data recovery), business-oriented application modeling, generative AI-powered assessments aligned with the Well-Architected and Resilience Analysis Frameworks, and automatic dependency discovery via DNS query log analysis. Integration with AWS Organizations enables organization-wide resilience management from a single delegated administrator account.</li>
<li><a href="https://aws.amazon.com/blogs/aws/introducing-the-next-generation-of-amazon-opensearch-serverless-for-building-your-agentic-ai-applications/">Introducing the next generation of Amazon OpenSearch Serverless for building agentic AI applications</a> — Amazon OpenSearch Serverless is now a fully managed search and vector engine purpose-built for agentic AI applications. It scales from zero to thousands of requests per second—roughly 20x faster than the prior generation—delivers up to 60% cost savings versus peak-provisioned clusters, and adds GPU acceleration plus new SEARCH and VECTORSEARCH collection types. Native integrations with Vercel, Kiro, Claude Code, and Cursor through OpenSearch Agent Skills make it straightforward to plug into your agent stack.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/assessment-capabilities-transform">New assessment capabilities in AWS Transform</a> — AWS Transform expands with new tools to help you build migration business cases and evaluate TCO before moving workloads to AWS. You can ingest data from RVTools exports, CMDB data, the AWS Transform discovery tool, and third-party discovery tools, then run what-if scenarios across region, utilization, and service mapping for EC2, FSx, S3, SQL Server on EC2, and virtual desktops. The release also adds <a href="https://aws.amazon.com/blogs/migration-and-modernization/new-in-aws-transform-analyze-your-code-for-modernization-and-agentic-readiness/">Agentic Readiness Analysis (ARA) and Modernization Analysis (MODA)</a>, which scan code repositories in 5 to 30 minutes per repo to surface severity-tagged findings with file-level evidence and AWS-mapped remediation guidance.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-aurora-mysql-kiro-powers/">Amazon Aurora MySQL with Kiro Powers</a> — Aurora MySQL now integrates with Kiro Powers, drawing from a curated repository of pre-packaged MCP servers, steering files, and hooks validated by Kiro partners. Developers can execute both data plane tasks (queries, schema management) and control plane tasks (cluster management) in natural language, with dynamic guidance for Aurora MySQL Serverless scaling, RDS-to-Aurora migration, and replication setup. The companion <a href="https://aws.amazon.com/blogs/database/guide-your-amazon-aurora-mysql-migration-with-kiro-powers/">Database Blog post</a> explains how the agent produces the API calls, SQL, and configuration for you to review and run — available via one-click install from the Kiro IDE or webpage.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-workspaces-applications-windows-desktop-OS/">Amazon WorkSpaces Applications now supports Windows Desktop OS</a> — You can now bring your own Windows Desktop licenses to Amazon WorkSpaces Applications and stream full Windows desktops and applications from AWS-hosted dedicated hardware. BYOL eliminates OS fees (you pay only for compute and streaming infrastructure), supports eligible Microsoft 365 Apps for enterprise, and gives users a matching experience between local and remote environments — same workflows, shortcuts, and navigation in both.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong>Other AWS news</strong><br />Here are some additional posts and resources that you might find interesting:</p><ul><li><a href="https://builder.aws.com/content/3EJcio15l8cEfd5gzrCatbq9UNX/meet-our-newest-aws-heroes-may-2026">Meet our newest AWS Heroes — May 2026</a> — An AWS Builder Center post introducing the latest cohort of AWS Heroes recognized for their contributions to the global AWS community.</li>
<li><a href="https://aws.amazon.com/blogs/database/ai-native-full-stack-web-apps-with-vercel-and-aws-databases/">AI-native, full-stack web apps with Vercel and AWS databases</a> — Database blog post on the new Vercel and AWS Databases integration, which lets you provision Aurora PostgreSQL, DynamoDB, or Aurora DSQL directly from the Vercel dashboard or via v0. The post also highlights the <a href="https://h01.devpost.com/">H0 hackathon</a> with $160,000 in prizes for building full-stack apps on this stack.</li>
<li><a href="https://aws.amazon.com/blogs/publicsector/introducing-us-based-us-citizen-24-7-technical-support-for-aws-govcloud-us-customers-your-mission-never-sleeps-neither-do-we/">Introducing US-based, US citizen 24/7 technical support for AWS GovCloud (US) customers: Your mission never sleeps. Neither do we.</a> — Public Sector blog post announcing that all AWS GovCloud (US) technical support cases are now automatically routed to US-based, US citizen engineers around the clock — no opt-in required — for government agencies, contractors, nonprofits, and academic institutions running mission-critical workloads.</li>
</ul><p>For a full list of AWS blog posts, be sure to keep an eye on the <a href="https://aws.amazon.com/blogs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Blogs</a> page.</p><p>Learn more about AWS, browse and join upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS-led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?tab=upcoming?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused events</a> as well as <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summits</a> and <a href="https://aws.amazon.com/events/community-day/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Community Days</a>. Join the <a href="https://builder.aws.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development.</p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><p>-Micah</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="33e2c876-8e08-4ebc-b52b-2ce171c77f14" data-title="AWS Weekly Roundup: Claude Opus 4.8 on AWS, Aurora MySQL with Kiro Powers, and more (June 1, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-opus-4-8-on-aws-aurora-mysql-with-kiro-powers-and-more-june-1-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-opus-4-8-on-aws-aurora-mysql-with-kiro-powers-and-more-june-1-2026/"/>
    <updated>2026-06-01T16:25:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/introducing-the-next-generation-of-aws-resilience-hub-for-generative-ai-based-sre-resilience-journey/</id>
    <title><![CDATA[Introducing the next generation of AWS Resilience Hub for generative AI-based SRE resilience journey]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the next generation of <a href="https://aws.amazon.com/resilience-hub/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Resilience Hub</a> with a significantly expanded experience that brings together a new application model, dependency discovery assessment, generative AI-powered failure mode analysis, modular resilience policies, and organization-wide reporting.</p><p>Organizations running hundreds of applications share a common challenge: availability is a top concern, yet there is no consistent way to set resilience goals, measure progress, or prove compliance across a portfolio. Teams set different standards, use different tools, and struggle to exchange information about whether applications actually meet expectations.</p><p>The next generation of AWS Resilience Hub changes this by giving Site Reliability Engineers (SREs) and development teams a structured way to align on resilience policy expectations, help application teams achieve them, and demonstrate compliance through testing. With integration into A<a href="https://aws.amazon.com/organizations/">WS Organizations</a>, teams can now evaluate resilience at scale, identify failure modes, discover hidden dependencies, and report on progress across the enterprise.</p><p>The next generation of Resilience Hub walks you through your resilience journey and to help you there are the following concepts built into it.</p><ul><li><strong>Resilience policy</strong>: You can define your resilience expectations through modular, composable requirements. Rather than choosing a single rigid policy type, you construct policies by selecting the requirements that matter to your application, such as service level objective (SLO), multi-AZ and multi-Region disaster recovery, and data recovery requirements.</li>
<li><strong>Business-level understanding</strong>: You can use new application modeling through critical end-user paths that map directly to business outcomes. Systems represent a business application, user journeys describe critical business paths, and services are the deployable units comprising AWS resources, code, and observability. Resilience Hub automatically discovers and maps them into a topology showing how resources connect.</li>
<li><strong>AI failure mode assessments</strong>: You can run generative AI-powered assessments that analyze your services against your defined resilience policies, <a href="https://aws.amazon.com/architecture/well-architected/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Well-Architected</a> best practices, and the <a href="https://docs.aws.amazon.com/prescriptive-guidance/latest/resilience-analysis-framework/introduction.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Resilience Analysis Framework</a>. These assessments identify potential failure modes and provide actionable recommendations.</li>
<li><strong>Dependency discovery assessment</strong>: You can automatically discover AWS services, internal endpoints, and third-party endpoints that your services depend on. This dependency assessment uses DNS query log analysis to identify dependencies you may not know about—including unexpected cross-region calls or critical third-party dependencies.</li>
</ul><p><strong class="c6">The next generation of AWS Resilience Hub in action</strong><br />To get started, you configure a resilience policy, set up your first system and service, run a failure mode assessment, review the results, and implement the findings.</p><p>Before you begin, you should set up the invoker IAM role, which grants Resilience Hub read-only access to your AWS resources, cross-account roles (if not using AWS Organizations), or service-linked roles (SLRs) with AWS Organizations. Resilience Hub also integrates with AWS Organizations to enable organization-wide resilience management from a single delegated administrator account. This eliminates the need to log in to individual accounts to assess resilience posture across your enterprise. To learn more, visit For <a href="https://docs.aws.amazon.com/resilience-hub/latest/userguide/next-gen-prerequisites.html">prerequisite details</a> in the AWS Resilience Hub User Guide.</p><p>To configure a resilience policy, choose <strong>Create policy</strong> in the <strong>Policies</strong> menu through the <a href="https://console.aws.amazon.com/resiliencehub/v2/home/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Resilience Hub console</a>. Enter a policy name, description, and choose resilience requirements. For example, you can create a reusable policy for multi-Region disaster recovery used in financial applications—including 99.95% availability SLO, 15-minutes RTO, 5-minutes RPO for multi-Region disaster recovery, and disaster recovery approach that aligns with your RTO and RPO requirements.</p><p>If you choose data recovery requirements, you can define the data recovery time objective for restoring from backups for each service associated with this policy.</p><p><img class="aligncenter wp-image-104062 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/26/2026-ngrh-create-policy.png" alt="" width="2078" height="4083" /></p><p>To create your first system representing your business application, choose <strong>Create a system</strong> in the <strong>Systems</strong> menu. Optionally, you can enable AWS Organizations account access for this system.</p><p><img class="aligncenter size-full wp-image-104042 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/24/2026-ngrh-create-systems.png" alt="" width="2048" height="1522" /></p><p>Now you can create a service that represents a deployable unit, like one of your microservices, and associate it with your system, and tell Resilience Hub where to find your resources. Enter a service name, for example, <code>stock-exchange-service</code>, choose your resilience policy and invoker AWS IAM role name. You can choose service Regions, service resources such as your resource tags, AWS CloudFormation stack, Terraform state file location, or Amazon EKS cluster and namespace.</p><p>When you enable dependency discovery for this service, AWS examines your VPC query logs for the VPCs associated with the resources in your service. You can disable this feature anytime from the dependency discovery settings in the service details page.</p><p><img class="aligncenter wp-image-104064 size-full c8" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/26/2026-ngrh-create-service-2.png" alt="" width="1868" height="4002" /></p><p>Now, you can run your first assessment with the service creation complete and a policy applied. Choose <strong>Run failure mode assessment</strong> in your service page and wait for the assessment to complete.</p><p><img class="aligncenter wp-image-104045 size-full c8" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/24/2026-ngrh-failure-mode-assessment.png" alt="" width="2170" height="1835" /></p><p>During the assessment, Resilience Hub assumes your invoker role, reads resources from your configured input sources, identifies parent-child relationships, queries the application topology service to map connections between resources, and builds a topology showing data flow, containment, and permissions.</p><p>By choosing <strong>Service topology</strong>, you can see service resources grouped by service functions in the graph, table, or JSON format.</p><p><img class="aligncenter wp-image-104048 size-full c8" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/24/2026-ngrh-topology-1.png" alt="" width="2156" height="1172" /></p><p>By choosing <strong>Failure mode guidance</strong>, you can add assertions used to guide the agents while performing the failure mode assessment. Assertions are either generated by the agent or added by users. You can update them to improve assessment accuracy.</p><p><img class="aligncenter wp-image-104077 size-full c8" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/27/2026-ngrh-failure-mode-guidance.png" alt="" width="2076" height="1136" /></p><p>Once the assessment is complete, you can review findings and recommendations in the <strong>Assessment</strong> tab of your service page. Each finding tells you what the failure mode is, why it matters for your architecture, how to fix it, and which policy requirement it relates to.</p><p><img class="aligncenter wp-image-104063 size-full c8" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/26/2026-ngrh-failure-mode-assessment-result.png" alt="" width="2456" height="1944" /></p><p>You can choose <strong>Mark as resolved</strong> to implement the recommendation or <strong>Mark as irrelevant</strong> if the finding doesn’t apply to your use case.</p><p>If you’re an existing Resilience Hub customer, Resilience Hub provides migration APIs to simplify the transition of your previous applications. These APIs convert your previous assessment policies to new resilience policies, map your previous applications to the new model, such as multiple related applications to one system with multiple services.</p><p>For more information about new features, visit the <a href="https://docs.aws.amazon.com/resilience-hub/latest/userguide/next-gen-what-is.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Resilience Hub User Guide</a>.</p><p><strong class="c6">Now available</strong><br />The next generation of AWS Resilience Hub is now generally available in AWS commercial Regions where Resilience Hub is available. For Regional availability and the future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>.</p><p>Resilience Hub uses a new service-based pricing model. Pricing includes two failure mode assessments per month for services, and optionally automated dependency assessment. You can try AWS Resilience Hub free. For pricing details, visit the <a href="https://aws.amazon.com/resilience-hub/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Resilience Hub pricing page</a>.</p><p>Give the new AWS Resilience Hub a try in the <a href="https://console.aws.amazon.com/resiliencehub/v2/home/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Resilience Hub console</a> and send feedback to <a href="https://repost.aws/selections/KPhiJicDpwTY-J-On9dNlhMg/aws-resilience-hub?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Resilience Hub</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="9bd8c4c8-84e4-463d-bde6-7d0efc167820" data-title="Introducing the next generation of AWS Resilience Hub for generative AI-based SRE resilience journey" data-url="https://aws.amazon.com/blogs/aws/introducing-the-next-generation-of-aws-resilience-hub-for-generative-ai-based-sre-resilience-journey/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/introducing-the-next-generation-of-aws-resilience-hub-for-generative-ai-based-sre-resilience-journey/"/>
    <updated>2026-05-28T21:29:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/introducing-the-next-generation-of-amazon-opensearch-serverless-for-building-your-agentic-ai-applications/</id>
    <title><![CDATA[Introducing the next generation of Amazon OpenSearch Serverless for building your agentic AI applications]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the next generation of <a href="https://aws.amazon.com/opensearch-service/features/serverless/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon OpenSearch Serverless</a>, a fully managed search and vector engine designed for customers building AI agents. The next generation of OpenSearch Serverless scales from zero to thousands of requests per second and back to zero when idle, offering up to 60% cost savings compared to the cost of OpenSearch Service clusters provisioned for peak capacity.</p><p>The next generation of OpenSearch Serverless creates resources in seconds and scales capacity up to 20 times faster than the previous generation. With instant resource creation and native integrations with AI development platforms like <a href="https://vercel.com/">Vercel</a> and <a href="https://kiro.dev/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Kiro</a>, you can deploy production-ready search and vector backends for your AI agents in minutes without managing infrastructure.</p><p><strong class="c6">The next generation of OpenSearch Serverless in action</strong><br />To get started with the next generation of OpenSearch Serverless, choose <strong>Create collection</strong> in the <strong>Serverless</strong> menu in the <a href="https://console.aws.amazon.com/aos/home?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon OpenSearch Service console</a>.</p><p><img class="aligncenter wp-image-104058 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/26/2026-opensearch-serverless-nextgen-1-dashboard-1.jpg" alt="" width="1800" height="715" /></p><p>Create NextGen collection with instant auto scaling and scale-to-zero for cost optimization. At launch, we support full-text search and vector search only for the collection type. If you want to use the existing OpenSearch Serverless infrastructure, choose <strong>Switch to Classic</strong>.</p><p>Choose <strong>Express create</strong>, the fastest way to create collection. No configuration is required—the default settings and matching security policies are applied automatically. Some configuration options can be changed later.</p><p><img class="aligncenter wp-image-104059 size-full c8" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/26/2026-opensearch-serverless-nextgen-2-create.png" alt="" width="1868" height="3950" /></p><p>When you choose <strong>Create collection</strong>, OpenSearch Serverless will provision resources in seconds.</p><p>You can also create a collection of OpenSearch Serverless with <a href="https://aws.amazon.com/cli/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Command Line Interface (AWS CLI)</a> or AWS SDKs. Here is a sample CLI command to create a collection group.</p><pre class="lang-bash">aws opensearchserverless create-collection-group \
    --name channy-nextgen-group \
    --standby-replicas ENABLED \
    --generation NEXTGEN \
    --description "My NextGen collection group" \
    --capacity-limits '{
        "maxIndexingCapacityInOCU": 10,
        "maxSearchCapacityInOCU": 10,
        "minIndexingCapacityInOCU": 0,
        "minSearchCapacityInOCU": 0
    }' \
    --region "us-east-1"</pre><p>Now, you can create a collection that inherits the generation from its parent collection group. Supported collection types: <code>SEARCH</code> and <code>VECTORSEARCH</code>.</p><pre class="lang-bash">aws opensearchserverless create-collection \
    --name channy-nextgen-collection \
    --type SEARCH \
    --collection-group-name channy-nextgen-group \
    --standby-replicas ENABLED \
    --description "My collection in NextGen group" \
    --region "us-east-1"</pre><p>To learn more about managing the next generation of OpenSearch Serverless, visit the <a href="https://docs.aws.amazon.com/opensearch-service/latest/developerguide/serverless.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon OpenSearch Serverless documentation</a>.</p><p><strong>Building your agents faster with OpenSearch Serverless<br /></strong> To support building production-ready agent applications in Vercel, you can now create a new OpenSearch collection or connect your existing OpenSearch Serverless collection within the Vercel console. Create a search backend in seconds and add features on-demand as your application grows. To learn more, visit <a href="https://vercel.com/marketplace/aws">AWS for Vercel</a>.</p><p><img class="aligncenter size-full wp-image-104083" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/28/2026-opensearch-serverless-nextgen-vercel-integration.png" alt="" width="1800" height="979" /></p><p>You can go from idea to working prototype in minutes using Claude Code, Cursor, and Kiro. <a href="https://github.com/opensearch-project/opensearch-agent-skills">OpenSearch Agent Skills</a> provide a repository of skills that bring OpenSearch intelligence directly into your agent. Each skill encapsulates domain knowledge, best practices, and multi-step execution logic for a specific workflow–so your agent not only gets results, but understands how they were achieved. You can also use the <a href="https://github.com/opensearch-project/opensearch-launchpad/tree/main/kiro/opensearch-launchpad">OpenSearch Launchpad</a> in <a href="https://kiro.dev/powers/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Kiro Powers</a> to accelerate search applications with guided, end-to-end architecture planning.</p><p><img class="aligncenter size-full wp-image-104084" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/28/2026-opensearch-serverless-nextgen-kiro-powers.jpg" alt="" width="1400" height="777" /></p><p><strong class="c6">Now available</strong><br />The next generation of Amazon OpenSearch Serverless is generally available today and is available in all AWS commercial Regions where Amazon OpenSearch Serverless is currently available.</p><p class="jss356" data-pm-slice="1 1 []">The next generation of OpenSearch Serverless charges for the compute you use in OpenSearch Compute Units (OCUs) for indexing, search, and <a href="https://docs.aws.amazon.com/opensearch-service/latest/developerguide/gpu-acceleration-vector-index.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">GPU acceleration</a>. You are charged separately for storage in GB-month. For more information, see <a href="https://aws.amazon.com/opensearch-service/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon OpenSearch Service Pricing</a>.</p><p>Give it a try and send feedback to the <a href="https://repost.aws/tags/TA6VFzFFY6QQa_KlHRKR-WsA/amazon-opensearch-service?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Amazon OpenSearch Service</a> or through your usual AWS Support contacts.</p><p>— <a href="https://twitter.com/channyun">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="9b1106ba-2859-402d-8331-8bb89210c0bf" data-title="Introducing the next generation of Amazon OpenSearch Serverless for building your agentic AI applications" data-url="https://aws.amazon.com/blogs/aws/introducing-the-next-generation-of-amazon-opensearch-serverless-for-building-your-agentic-ai-applications/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/introducing-the-next-generation-of-amazon-opensearch-serverless-for-building-your-agentic-ai-applications/"/>
    <updated>2026-05-28T20:26:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/meet-our-newest-aws-heroes-may-2026/</id>
    <title><![CDATA[Meet Our Newest AWS Heroes – May 2026]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>We’re excited to welcome four outstanding community leaders as our newest AWS Heroes. These individuals embody the spirit of collaboration and knowledge sharing that makes the AWS community thrive. From building AI-powered tools that help fellow builders navigate AWS re:Invent, to leading some of the largest AWS communities in Latin America, to sharing deep cloud architecture expertise across blogs and events. Their dedication to lifting others up through education, mentorship, and community organizing inspires builders around the world.</p><h2 class="c6">Damiano Giorgi – Pavia, Italy</h2><p><a href="https://builder.aws.com/community/@rayg" target="_blank" rel="noopener noreferrer"><img class="alignleft" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/22/damiano_175x263.png" width="175" height="263" alt="image" /></a> Artificial Intelligence Hero <a href="https://builder.aws.com/community/damiano" target="_blank" rel="noopener noreferrer">Damiano Giorgi</a> is a Cloud Solutions Architect focused on AI and its evolution, who transitioned from on-premises (on-prem) systems engineering to AWS and never looked back. He helps organize AWS User Group Pavia and AWS User Group Milan, and shares content on his personal blog, “Bass and Bytes.” Damiano developed the “Unofficial post:Invent Session Suggester,” powered by Amazon Bedrock and Amazon Nova, to help builders find AWS re:Invent sessions matching their interests. He speaks at conferences across Europe including AWS Summit Milan, AWS Community Day Italy, Adria, Greece, and the Netherlands.</p><h2 class="c6">Darryl Ruggles – Ottawa, Canada</h2><p><a href="https://builder.aws.com/community/@margoneto81" target="_blank" rel="noopener noreferrer"><img class="alignleft" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/22/Darryl-profile_175x263.jpg" width="175" height="263" alt="image" /></a> Serverless Hero <a href="https://builder.aws.com/community/darrylr" target="_blank" rel="noopener noreferrer">Darryl Ruggles</a> is a Cloud Solutions Architect who spent many years as a software developer before focusing on AWS application and AI/ML architectures. He shares knowledge across serverless, containers, AI/ML, and FinOps through his blog, LinkedIn, and published projects. Darryl is an active member of many online AWS communities including “Believe In Serverless” and loves interacting with the community at events both online and in person.</p><h2 class="c6">Ricardo Daniel Ceci – Buenos Aires, Argentina</h2><p><a href="https://builder.aws.com/community/@sheyla" target="_blank" rel="noopener noreferrer"><img class="alignleft" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/22/Ricardo-Daniel-Ceci_175x263.jpg" width="175" height="263" alt="image" /></a> Artificial Intelligence Hero <a href="https://builder.aws.com/community/ricardoceci" target="_blank" rel="noopener noreferrer">Ricardo Daniel Ceci</a> leads the AWS User Group Buenos Aires, which is the largest AWS community in Argentina with nearly 2,400 members. He is also the principal organizer of the AWS Community Day Argentina and was recognized as the AWS Community Leader of the Year 2025 for LATAM. Ricardo hosts a podcast featuring conversations with cloud experts, AWS Heroes, and developer advocates across Latin America. He has over fifteen years of experience in cloud and web development, and is passionate about empowering Spanish-speaking builders and lowering the barrier to cloud and AI across LATAM.</p><h2 class="c6">Matias Kreder – Buenos Aires, Argentina</h2><p><a href="https://builder.aws.com/community/@sheyla" target="_blank" rel="noopener noreferrer"><img class="alignleft" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/22/Matias-Kreder_175x263.png" width="175" height="263" alt="image" /></a> Artificial Intelligence Hero <a href="https://builder.aws.com/community/mkreder" target="_blank" rel="noopener noreferrer">Matias Kreder</a> is an AWS Certification Subject Matter Expert (SME) who contributed to multiple AI/ML certifications, including the AWS Certified AI Practitioner exam. His journey began with AWS DeepRacer where he qualified three times as a finalist, which sparked his community work organizing racing events and ML talks across the region. As an AWS User Group Leader for Buenos Aires, he organized the AWS Community Day Argentina 2025 and speaks at community events throughout LATAM.</p><h2 class="c6">Learn More</h2><p>Visit the <a href="https://builder.aws.com/connect/community/heroes" target="_blank" rel="noopener">AWS Heroes webpage</a> if you’d like to learn more about the AWS Heroes program, or to connect with a Hero near you.</p><p>— <a href="https://twitter.com/taylorjacobsen" target="_blank" rel="noopener noreferrer">Taylor</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="e55912f6-3bb0-46f0-8c11-e4c86087e3f1" data-title="Meet Our Newest AWS Heroes – May 2026" data-url="https://aws.amazon.com/blogs/aws/meet-our-newest-aws-heroes-may-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/meet-our-newest-aws-heroes-may-2026/"/>
    <updated>2026-05-27T18:15:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-local-zones-in-istanbul-open-source-extenddb-kiro-web-and-more-may-25-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: AWS Local Zones in Istanbul, open-source ExtendDB, Kiro Web, and more (May 25, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p><img class="alignright wp-image-104002 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/22/aws_startups.png" alt="" width="318" height="159" />There’s something genuinely energizing about working with startups — something I’ve been doing intensely for more than two years now. Startups operate at a different frequency: the urgency is real, the constraints are tight, and the stakes are personal. Helping them navigate the challenge of proving their business model requires not just technical depth but a willingness to move fast, challenge assumptions, and make bets on the right architecture before the perfect data exists.</p><p>What I love most is that the work is never abstract: every decision I help a startup make has a direct impact on whether they ship on time, stay within budget, and earn the next round of confidence from their investors.</p><p>Let’s dive into this week’s AWS news.</p><p><strong class="c7">Headlines</strong><br /><img class="wp-image-364 size-large alignright c6" src="https://d2908q01vomqb2.cloudfront.net/b74f5ee9461495ba5ca4c72a7108a23904c27a05/2026/05/17/AdobeStock_281852927_resized-1024x602.jpeg" alt="" width="1024" height="602" /><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-local-zones-istanbul-turkiye/">Now Open — AWS Local Zones in Istanbul, Türkiye</a> — AWS has opened a new Local Zone in Istanbul, Türkiye, bringing AWS compute, storage, and networking services to one of Europe’s largest metropolitan areas. For organizations with data residency requirements in Türkiye, this Local Zone enables you to keep data within the country while still leveraging the full breadth of AWS services. The Local Zone also benefits applications that require single-digit millisecond latency — such as real-time gaming, media production, live video streaming, and financial services — by running closer to where end users actually are.</p><p>A Local Zone is a significant infrastructure investment: it requires the same level of commitment as a Region in terms of hardware, power, networking, and operational excellence. It also reflects AWS’s continued expansion into underserved markets.</p><p>For builders in Türkiye, this opens up a new set of architectural possibilities. You can now store and back up data within Turkish borders to help meet data residency requirements, and run latency-sensitive workloads in the Istanbul Local Zone while connecting seamlessly to the AWS Region — giving you the flexibility to architect hybrid applications without managing your own data center infrastructure. To learn more about our decade-long commitment, available services, customers and partners in Türkiye, visit the <a href="https://aws.amazon.com/blogs/infrastructure-sustainability/now-open-aws-local-zones-in-istanbul-turkiye/">launch blog post</a>.</p><p><strong class="c7">Last week’s launches</strong><br />Here are some launches and updates that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-security-hub-extended/">Security Hub Extended expands to 21 curated partner solutions across 9 categories</a> — AWS Security Hub Extended now integrates with 21 curated partner security solutions spanning 9 categories, including endpoint protection, cloud security posture management, threat intelligence, and more. You can now get consolidated, prioritized security findings from a broader ecosystem of tools directly within Security Hub, without requiring custom integrations. This is particularly valuable for enterprise security teams that want a unified view of their security posture across AWS and third-party tooling.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-sagemaker-ai-openai-apis/">Amazon SageMaker AI now supports OpenAI-compatible APIs for inference endpoints</a> — You can now call Amazon SageMaker AI inference endpoints using OpenAI-compatible APIs, making it significantly easier to migrate AI workloads from OpenAI to SageMaker — or to build applications that work across multiple providers — with no SDK changes required. This lowers the migration barrier for teams that started prototyping with OpenAI and are now looking to move to a more scalable, cost-controlled infrastructure on AWS. Your existing application code works as-is; you simply point it at your SageMaker endpoint.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/secrets-manager-agent-prefetch-and-role-assumption/">Introducing pre-fetching and IAM role assumption for AWS Secrets Manager Agent</a> — The AWS Secrets Manager Agent can now pre-fetch secrets at startup and assume IAM roles to retrieve them, eliminating the cold-start latency associated with on-demand secret retrieval in latency-sensitive applications. You can configure the agent to preload the secrets your application needs before it starts serving traffic, reducing the risk of secrets-related latency spikes in production. IAM role assumption support also makes it easier to share the agent across workloads with different permission boundaries.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-extenddb-dynamodb/">AWS announces ExtendDB, an open-source DynamoDB-compatible adapter</a> — AWS has open-sourced ExtendDB, a DynamoDB-compatible adapter that allows you to use the DynamoDB API and data model on top of alternative backend storage systems. This is particularly useful for local development and testing workflows — you can write against the DynamoDB API without requiring a live AWS connection. It’s also valuable for scenarios where you need DynamoDB-compatible semantics with more control over the underlying storage layer. It’s a practical tool for teams that want to build portability into their data access layer.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-sam-cli-cloudformation/">AWS SAM CLI adds AWS CloudFormation Language Extensions support to accelerate local serverless development</a> — The AWS SAM CLI now supports AWS CloudFormation Language Extensions locally, meaning you can use transforms, dynamic references, and other CloudFormation language features directly in your local development and testing workflows. This closes a long-standing gap between what you can test locally and what runs in production, making local serverless development faster and more reliable. If you build serverless applications with SAM and encounter edge cases in local testing, this update will meaningfully improve your experience.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong class="c7">Other AWS news</strong><br />Here are some additional posts and resources that you might find interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/aws/amazon-bedrock-introduces-new-advanced-prompt-optimization-and-migration-tool/">Amazon Bedrock introduces new advanced prompt optimization and migration tool</a> — This post covers the newly launched Advanced Prompt Optimization and Migration Tool in Amazon Bedrock, which helps you automatically tune your prompts for better model performance and assists you in migrating prompts across different foundation models. It’s a must-read if you’re iterating on prompt quality for production AI workloads.</li>
<li><a href="https://kiro.dev/blog/introducing-kiro-web/" data-agent-id="137">Introducing Kiro Web</a> — Kiro, AWS’s AI-powered development environment, now has a web-based interface. Kiro Web lets you access Kiro’s spec-driven development, AI chat, and agent capabilities directly from your browser, without needing to install the desktop IDE. This is a great step toward making AI-assisted development more accessible — whether you’re doing a quick review, prototyping from a new machine, or introducing your team to the Kiro workflow.</li>
<li><a href="https://aws.amazon.com/blogs/developer/announcing-updated-retry-behavior-for-aws-sdks-and-tools/">Announcing updated retry behavior for AWS SDKs and Tools</a> — AWS has updated the default retry behavior across its SDKs and CLI tools, improving resilience for transient errors without requiring configuration changes from developers. The updated behavior includes smarter backoff strategies and better handling of throttling responses. If you’re running production workloads that occasionally hit API rate limits or transient failures, this update improves reliability out of the box. It’s worth reading to understand what changed and how it affects your applications.</li>
<li><a href="https://aws.amazon.com/blogs/containers/bitnami-image-removal-from-ecr-public/">Bitnami image removal from ECR Public</a> — AWS has announced that Bitnami container images will be removed from Amazon ECR Public. If your workloads pull Bitnami images from ECR Public, you should review this post to understand the timeline and migration path. The Bitnami images remain available directly from Bitnami’s own registry, and this post explains how to update your image references to continue pulling them without interruption.</li>
</ul><p><strong class="c7">Upcoming AWS events</strong><br />Check your calendar and sign up for these events:</p><ul><li><a href="https://aws.amazon.com/events/summits/amsterdam/">AWS Summit Amsterdam</a> — Join us in Amsterdam on May 27 for a full day of cloud and AI sessions, hands-on labs, and networking with builders and AWS experts from across Europe. Registration is free.</li>
<li><a href="https://aws.amazon.com/events/summits/bangkok/">AWS Summit Bangkok</a> — AWS Summit Bangkok takes place on May 28. It’s a fantastic opportunity for builders and customers across Southeast Asia to connect and explore the latest in cloud innovation.</li>
<li><a href="https://aws.amazon.com/it/events/summits/milano/">AWS Summit Milan</a> — Also on May 28, AWS Summit Milan brings the AWS community together in Italy. If you’re in Southern Europe, this is your event.</li>
<li><a href="https://aws.amazon.com/events/summits/mumbai/">AWS Summit Mumbai</a> — Also on May 28, AWS Summit Mumbai brings cloud and AI content to builders across India. Check the link for the full agenda and registration.</li>
<li><a href="https://aws.amazon.com/events/summits/los-angeles/">AWS Summit Los Angeles</a> — Mark your calendar for June 10 in Los Angeles. The AWS Summit LA is coming up and it’s a great opportunity to connect with the West Coast builder community.</li>
<li><a href="https://builder.aws.com/">AWS Community Days</a> — Community-led conferences where content is planned, sourced, and delivered by community leaders. If you’re in Latin America, don’t miss AWS Community Day Belo Horizonte on August 22 — registration is open at <a href="https://awscommunityday.com.br/">awscommunityday.com.br</a>.</li>
</ul><p>Join the <a href="https://builder.aws.com/">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development. Browse <a href="https://aws.amazon.com/events/">here</a> for upcoming AWS-led in-person and virtual events and developer-focused events.</p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><p>— Daniel Abib</p><p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="d3a9e5e2-6a4a-460f-ad42-2f0ab3f0c81a" data-title="AWS Weekly Roundup: AWS Local Zones in Istanbul, open-source ExtendDB, Kiro Web, and more (May 25, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-local-zones-in-istanbul-open-source-extenddb-kiro-web-and-more-may-25-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-local-zones-in-istanbul-open-source-extenddb-kiro-web-and-more-may-25-2026/"/>
    <updated>2026-05-25T22:11:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-transform-at-1-year-claude-platform-on-aws-ec2-m3-ultra-mac-instances-and-more-may-18-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: AWS Transform at 1 year, Claude Platform on AWS, EC2 M3 Ultra Mac instances, and more (May 18, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p><img class="wp-image-103968 size-full alignright c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/18/AWS-Transform-1-year.jpg" alt="" width="250" height="250" />Just a year ago, we launched <a href="https://aws.amazon.com/transform/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Transform</a> for <a href="https://aws.amazon.com/blogs/aws/aws-transform-for-net-the-first-agentic-ai-service-for-modernizing-net-applications-at-scale/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">.NET</a>, <a href="https://aws.amazon.com/blogs/aws/accelerate-the-modernization-of-mainframe-and-vmware-workloads-with-aws-transform/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Mainframe and VMware workloads</a>, the first agentic AI service purpose-built for modernizing enterprise applications at scale. At re:Invent 2025, we introduced <a href="https://aws.amazon.com/transform/custom?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Transform custom</a>, which enables organizations to modernize and transform code at scale using AWS-managed and custom transformations. You can upgrade language versions, migrate frameworks, optimize performance, and analyze code bases using transformations that are ready to use or can be customized to meet your organization’s specific requirements. We also introduced <a href="https://aws.amazon.com/blogs/aws/aws-transform-announces-full-stack-windows-modernization-capabilities/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">full-stack Windows modernization capabilities</a> and <a href="https://aws.amazon.com/blogs/aws/aws-transform-for-mainframe-introduces-reimagine-capabilities-and-automated-testing-functionality/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Reimagine capabilities and automated testing functionality for mainframe</a>.</p><p>In 12 months, thousands of customers migrated hundreds of thousands of servers, saved 1.6+ million hours, and processed 4.5+ billion lines of code with AWS Transform. Celebrating its 1-year anniversary, AWS Transform agents now available in <a href="https://aws.amazon.com/about-aws/whats-new/2026/04/aws-transform-developer-tools/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Kiro, Claude, Cursor, and Codex</a>, including <a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-transform-agent-builder-toolkit/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">the agent builder toolkit Kiro power</a> for building customized transformation agents.</p><p>To learn what happened in 12 months, the four things we learned, and how that evolved our roadmap, visit the <a href="https://aws.amazon.com/blogs/migration-and-modernization/aws-transform-one-year-milestone/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">one-year anniversary blog post</a>.</p><p><strong>Last week’s launches</strong><br />Here are last week’s launches that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/claude-platform-aws/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">The general availability of Claude Platform on AWS</a> – You can get direct access to Anthropic’s native Claude Platform experience, including APIs, console, and early-access beta features, directly through your existing AWS account, without managing separate accounts, billing, or tracking. Claude Platform on AWS is operated by Anthropic, and customer data is processed outside the AWS security boundary. To learn more, visit the <a href="https://aws.amazon.com/blogs/machine-learning/introducing-claude-platform-on-aws-anthropics-native-platform-through-your-aws-account/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">deep dive blog post</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-ec2-m3-ultra-mac-instances-generally-available/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 M3 Ultra Mac instances</a> – These instances are built on Apple M3 Ultra Mac Studio computers featuring a 28-core CPU, 60-core GPU, 32-core Neural Engine, and 256GB of unified memory. Compared to EC2 M4 Max Mac instances, M3 Ultra Mac instances provide 2x the unified memory, 1.75x the CPU cores, 1.5x the GPU cores, and 2x the Neural Engine cores, giving Apple developers the headroom to run significantly more Xcode simulators in parallel and accelerate on-device ML workflows to improve product time to market.</li>
<li><a href="https://aws.amazon.com/blogs/aws/amazon-redshift-introduces-aws-graviton-based-rg-instances-with-an-integrated-data-lake-query-engine/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Redshift RG instances powered by AWS Graviton</a> – These instances deliver better performance, running data warehouse and data lake workloads up to 2.4x as fast as previous generation RA3 instances, at 30% lower price per vCPU. RG instances include Redshift’s custom-built vectorized data lake query engine that processes Apache Iceberg and Parquet data on your cluster nodes.</li>
<li><a href="https://aws.amazon.com/blogs/aws/amazon-bedrock-introduces-new-advanced-prompt-optimization-and-migration-tool/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock Advanced Prompt Optimization</a> – You can optimize your prompts for any model on Bedrock, while comparing your original prompts to your optimized prompts across up to 5 models simultaneously. You can also use this if you are migrating to a new model or just want to get better performance on your current model.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-security-agent-full-repository-code-review/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Agent full repository code scanning (preview)</a> – You can use a new capability in AWS Security Agent that performs deep, context-aware security analysis of your entire codebase. When vulnerabilities are found, the scanner generates code remediation—specific fixes tied to the exact file and line—enabling teams to remediate security vulnerabilities faster than ever before. This capability is available at no additional charge for existing AWS Security Agent customers during the preview.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-announces-AWS-interconnect-multicloud-oci-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Interconnect – multicloud connectivity with Oracle Cloud Infrastructure (preview)</a> – You can quickly provision resilient, scalable private connections to other cloud providers using AWS Interconnect – multicloud connectivity. OCI is the latest CSP to adopt the open specification that powers AWS Interconnect. This allows AWS to provide a consistent, simple experience to our customers on OCI (preview), Google Cloud (generally available), and Microsoft Azure (coming later in 2026).</li>
</ul><p><strong>Additional updates</strong><br />Here are some additional news items that you might find interesting:</p><ul><li><a href="https://www.aboutamazon.com/news/aws/amazon-trainium-investment-university-ai-research?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Accelerate AI research and education with Build on Trainium program</a> – Read how the next generation of AI researchers is using Amazon chips to accelerate discovery. AWS invested $110 million to give university researchers access to purpose-built AI chips. AWS Trainium is speeding up AI research at UC Berkeley, MIT, Carnegie Mellon, and more. All research is open source, meaning improvements flow back to the broader developer community.</li>
<li><a href="https://builder.aws.com/content/3Dj1piMsfZG5aSDK1q6bHfzPOqs/aws-community-days-where-builders-learn-together?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">A full list of AWS Community Days 2026</a> – There’s something different about an event where the speakers are your peers, the organizers are volunteers who do this out of passion, and the agenda was shaped by the community itself. That’s exactly what AWS Community Days are, and they’re happening in cities across every continent, every year.</li>
<li><a href="https://kiro.dev/blog/bringing-back-startup-credits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">The Kiro Startups Credit program is back</a> – Thousands of founders applied in the first round, and now applications are open again. Apply to receive up to one year of Kiro Pro+ credits automatically applied to your organization’s AWS account.</li>
</ul><p>For a full list of AWS blog posts, be sure to keep an eye on the <a href="https://aws.amazon.com/blogs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Blogs</a> page.</p><p>Learn more about AWS, browse and join upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS-led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?tab=upcoming?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused events</a> including <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summits</a>. Join the <a href="https://builder.aws.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development.</p><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Weekly Roundup</a>!</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="6127e5d7-efd2-45b2-8e60-1f65cb04d3d6" data-title="AWS Weekly Roundup: AWS Transform at 1 year, Claude Platform on AWS, EC2 M3 Ultra Mac instances, and more (May 18, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-transform-at-1-year-claude-platform-on-aws-ec2-m3-ultra-mac-instances-and-more-may-18-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-transform-at-1-year-claude-platform-on-aws-ec2-m3-ultra-mac-instances-and-more-may-18-2026/"/>
    <updated>2026-05-18T21:13:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-bedrock-introduces-new-advanced-prompt-optimization-and-migration-tool/</id>
    <title><![CDATA[Amazon Bedrock introduces new advanced prompt optimization and migration tool]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing <strong>Amazon Bedrock Advanced Prompt Optimization</strong>, a new tool that you can use to optimize your prompts for any model on <a href="https://aws.amazon.com/bedrock">Amazon Bedrock</a>, while comparing your original prompts to optimized prompts across up to 5 models simultaneously. With the new prompt optimization, you can migrate to a new model or improve performance from your current model. You can test them to make sure they see no regressions on known use cases and also improve on underperforming tasks.</p><p><img class="aligncenter wp-image-103964 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/14/2026-bedrock-advanced-prompt-optimization-process-3.png" alt="" width="1740" height="410" /></p><p>The new prompt optimizer takes in your prompt template, example user inputs for the variable values, ground truth answers, and an evaluation metric to use as a guide. You can even use this with multimodal user inputs – it supports <code>png</code>, <code>jpg</code>, and <code>pdf</code> as inputs to your prompt templates so you can optimize prompts for tasks like document and image analysis.</p><p>You can also provide an <a href="https://aws.amazon.com/lambda/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Lambda</a> function, LLM-as-a-judge rubric, or a short natural language description to guide the optimization. The prompt optimizer works in a metric-driven feedback loop to optimize the prompt and resulting model responses for the evaluation metric, and outputs the original and final prompt templates with evaluation scores, cost estimates, and latency.</p><p><strong class="c6">Bedrock Advanced Prompt Optimization in action</strong><br />To get started with the new prompt optimization, choose <strong>Create prompt optimization</strong> on the <strong>Advanced Prompt Optimization</strong> page of <a href="https://console.aws.amazon.com/bedrock/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock console</a>.</p><p><img class="aligncenter wp-image-103951 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/13/2026-bedrock-advanced-prompt-optimization-1-console.jpg" alt="" width="2560" height="1506" /></p><p>Pick up to 5 inference models for which to optimize your prompts. You can use this if you are migrating to a new model or just want to get better performance on their current model. If you’re changing models, you can select your current model as a baseline and up to 4 other models. If you aren’t changing models, then just select your current model to see before and after optimization.</p><p><img class="aligncenter wp-image-103952 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/13/2026-bedrock-advanced-prompt-optimization-2-create.png" alt="" width="2245" height="2373" /></p><p>You should prepare your prompt templates in JSONL format with example user data, ground truth answers, and an evaluation metric or rewriting guidance. For <code>.jsonl</code> files, each JSON object must be on a single line.</p><pre class="lang-json">{
    "version": "bedrock-2026-05-14",           // required; Fixed value
    "templateId": "string",                    // required
    "promptTemplate": "string",                // required
    "steeringCriteria": ["string"],            // optional
    "customEvaluationMetricLabel": "string",   // required if customLLMJConfig or evaluationMetricLambdaArn is used
    "customLLMJConfig": {                      // optional
        "customLLMJPrompt": "string",          // required if customLLMJConfig present
        "customLLMJModelId": "string"          // required if customLLMJConfig present
    },
    "evaluationMetricLambdaArn": "string",     // optional
    "evaluationSamples": [                     // required
        {
            "inputVariables": [                // required
                {
                    "variableName1": "string",
                    "variableName2": "string"
                }
            ],
            "referenceResponse": "string"      // optional
            "inputVariablesMultimodal": [      // optional
                {
                "Arbitrary_Name": {            // required for your multimodal variable.
                    "type": "string",          // choose from "PDF" or "IMAGE". Acceptable filetypes for IMAGE = png, jpg,  
                    "s3Uri": "string"          // input the S3 path of the file
                }
            ]
        }
    ]
}</pre><p>You can upload files directly or import prompt templates from <a href="https://aws.amazon.com/s3/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Simple Storage Service (Amazon S3)</a> and set an S3 output location where prompt optimization results and evaluation data will be stored. Then, choose <strong>Create optimization</strong>.</p><p>Amazon Bedrock automatically sends your prompt templates and example data with optional ground truth to your inference models, evaluates the responses with your evaluation metric, then rewrites the prompt in a feedback loop to optimize it for your inference models. You’ll see evaluation results based on your provided metric and your final optimized prompts.</p><p><img class="aligncenter wp-image-103953 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/13/2026-bedrock-advanced-prompt-optimization-3-result-1.png" alt="" width="2375" height="1225" /></p><p>As you noted, you can evaluate prompt quality in three ways: a Lambda function with your own Python scoring logic, LLM-as-a-Judge with a custom rubric, or natural-language steering criteria. You can just choose one per prompt template, but can do multiple prompt templates in a job, so they can use a different method for each prompt template if they want.</p><ul><li><strong>Lambda function</strong> — If you have a concrete metric (accuracy, F1, execution accuracy, structured-JSON match, etc.), you can deploy a Lambda function containing your custom scoring logic and configure <code>evaluationMetricS3Uri</code> field of the prompt template. Inside the Lambda, the core is a compute_score implementation that programmatically compares model outputs against reference responses.</li>
<li><strong>LLM-as-a-Judge</strong> — If your task is open-ended (summarization, generation, reasoning explanations) and you want a rubric-based score, you can configure the S3 config file in the <code>customLLMJConfig</code> field of the prompt template to define named metrics with structured instructions and a rating scale. A Bedrock judge model evaluates each prompt-response pair and returns a score with reasoning. The default model is Claude Sonnet 4.6 and you can also select your own from a list of judge models.</li>
<li><strong>Steering criteria</strong> — If you know the qualities you want (brand voice, format, safety constraints) but don’t want to author a full judge prompt, you can define criteria in the input dataset through the <code>steeringCriteria</code> array of the prompt template. Instead of structured metrics with rating scales, you provide free-form natural language criteria that the LLM judge evaluates holistically. If you use this option, then a default LLM-as-a-judge prompt will evaluate the responses and incorporate your steering criteria into the judge prompt. The judge model in this case is Anthropic Claude Sonnet 4.6.</li>
</ul><p>To learn more about how to use the advanced prompt optimization and migration, visit the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/prompt-optimization-migration.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">advanced prompt optimization in Bedrock</a> guide and the <a href="https://github.com/aws-samples/amazon-bedrock-samples/tree/main/advanced-prompt-optimization">sample codes in Github</a>.</p><p><strong class="c6">Now available</strong><br />Amazon Bedrock Advanced Prompt Optimization is available today in US East (N. Virginia, Ohio), US West (Oregon), Asia Pacific (Mumbai, Seoul, Singapore, Sydney, Tokyo), Canada (Central), Europe (Frankfurt, Ireland, London, Zurich), and South America (São Paulo) Regions. You are charged based on the Bedrock model-inference tokens consumed during optimization, at the same per-token rates as regular Bedrock inference. To learn more, visit the <a href="https://aws.amazon.com/bedrock/pricing/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon Bedrock pricing</a> page.</p><p>Give the advanced prompt optimization a try in the <a href="https://console.aws.amazon.com/bedrock?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock console</a> or with <code>CreateAdvancedPromptOptimizationJob</code> API today and send feedback to <a href="https://repost.aws/tags/TAQeKlaPaNRQ2tWB6P7KrMag/amazon-bedrock?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Amazon Bedrock</a> or through your usual AWS Support contacts.</p><p>— <a href="https://twitter.com/channyun">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="f9664403-b18d-4430-b66b-1d88f41213e0" data-title="Amazon Bedrock introduces new advanced prompt optimization and migration tool" data-url="https://aws.amazon.com/blogs/aws/amazon-bedrock-introduces-new-advanced-prompt-optimization-and-migration-tool/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-bedrock-introduces-new-advanced-prompt-optimization-and-migration-tool/"/>
    <updated>2026-05-15T00:03:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-redshift-introduces-aws-graviton-based-rg-instances-with-an-integrated-data-lake-query-engine/</id>
    <title><![CDATA[Amazon Redshift introduces AWS Graviton-based RG instances with an integrated data lake query engine]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Since 2013, <a href="https://aws.amazon.com/redshift/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Redshift</a> has given the full power of a data warehouse in the cloud, at a fraction of the on-premises cost. Every architectural generation—from dense compute to <a href="https://aws.amazon.com/blogs/aws/amazon-redshift-update-next-generation-compute-instances-and-managed-analytics-optimized-storage/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon RA3 instances</a>, from provisioned to <a href="https://aws.amazon.com/blogs/aws/amazon-redshift-serverless-now-generally-available-with-new-capabilities/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Redshift Serverless</a>—has made each query cheaper, faster, and more efficient than the last.</p><p>For over a decade, as data volumes have grown and analytics requirements have evolved, organizations increasingly leverage both data warehouse tables for structured, frequently-accessed data and data lakes for cost-effective storage of diverse datasets. Add AI agents to the mix and they query your data warehouse at a scale that dwarfs typical human usage, leading to spiraling operational costs.</p><p>Amazon Redshift has doubled down on its core strengths to meet the demands of any workload — whether driven by humans or AI agents. For example, in March 2026, Amazon Redshift improved the performance of business intelligence (BI) dashboards and ETL workloads by <a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-redshift-increases-performance-for-new-queries/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">speeding up new queries by up to 7 times</a>. This significantly improves the response times of low-latency SQL queries, such as those used in near-real-time analytics applications, BI dashboards, ETL pipelines, and autonomous, goal-seeking AI agents.</p><p>Today, we’re announcing <a href="https://aws.amazon.com/redshift/features/rg/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Redshift RG instances</a>, a new instance family powered by <a href="https://aws.amazon.com/ec2/graviton/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Graviton</a>. RG instances deliver better performance, running data warehouse workloads up to 2.2x as fast as RA3 instances at 30% lower price per vCPU. Their integrated data lake query engine lets you run SQL analytics across your data warehouse and data lake from a single engine with performance up to 2.4x as fast as RA3 for <a href="https://iceberg.apache.org/">Apache Iceberg</a> and up to 1.5x as fast as RA3 for <a href="https://parquet.apache.org/">Apache Parquet</a>. This blend of speed, cost efficiency, and an integrated data lake query engine makes Redshift RG instances well-suited to handle the high query volumes and low-latency requirements of today’s analytics and agentic AI workloads.</p><p>You can compare new RG instances and current RA3 instances:</p><table class="c9"><tbody><tr class="c7"><td class="c6"><strong>Current RA3 Instance</strong></td>
<td class="c6"><strong>Recommended RG instance</strong></td>
<td class="c6"><strong>vCPU</strong></td>
<td class="c6"><strong>Memory (GB)</strong></td>
<td class="c6"><strong>Primary Use Case</strong></td>
</tr><tr class="c8"><td class="c6"><code>ra3.xlplus</code></td>
<td class="c6"><code>rg.xlarge</code></td>
<td class="c6">4</td>
<td class="c6">32</td>
<td class="c6">Small cluster departmental analytics</td>
</tr><tr class="c8"><td class="c6"><code>ra3.4xlarge</code></td>
<td class="c6"><code>rg.4xlarge</code></td>
<td class="c6">12 → 16 (1.33:1)</td>
<td class="c6">96 GB → 128 GB (1.33:1)</td>
<td class="c6">Standard production workloads, medium data volumes</td>
</tr></tbody></table><p>This approach reduces total analytics costs for customers running combined data warehouse and data lake workloads, while simplifying operations through a single system for querying both warehouse tables and <a href="https://aws.amazon.com/s3/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Simple Storage Service (Amazon S3)</a> data lakes. We recommend using the <a href="https://calculator.aws/#/">AWS Pricing Calculator</a> with your specific workload patterns to estimate savings.</p><p><strong class="c10">Getting started with Amazon Redshift RG instances</strong><br />You can launch new clusters or migrate existing clusters through the <a href="https://console.aws.amazon.com/redshift/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Management Console</a>, <a href="https://aws.amazon.com/cli/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Command Line Interface (AWS CLI),</a> or AWS API. The integrated data lake query engine is enabled by default.</p><p>In the Amazon Redshift console, you can choose new RG instances when you create a cluster.</p><p><img class="aligncenter wp-image-103897 size-full c11" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/06/2026-redshift-rg-instances-1.png" alt="" width="2120" height="1254" /></p><p>You can migrate previous-generation instances to RG instances with optimal paths based on your cluster configuration to estimate costs, validate compatibility, and automate execution.</p><ul><li><strong>Elastic Resize</strong>—in-place migration with 10-15 minutes downtime for compatible configurations</li>
<li><strong>Snapshot and Restore</strong>—create a RG cluster from an RA3 snapshot. This is best for customers who want to make configuration changes during the migration</li>
</ul><p>Your external tables, schemas, and query syntax—including existing Spectrum queries—remain unchanged. There is no need to recreate external tables or modify application code. To learn more, visit the <a href="https://docs.aws.amazon.com/redshift/latest/mgmt/managing-cluster-considerations.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Redshift Management Guide</a>.</p><p>Amazon Redshift now executes data lake queries on cluster nodes—the same compute that processes data warehouse workloads. As a result, <a href="https://docs.aws.amazon.com/redshift/latest/dg/c-using-spectrum.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Redshift Spectrum</a> is no longer required. Data lake queries stay within your VPC boundary, use existing IAM roles, and incur zero per-terabyte scanning charges. This removes the $5/TB Spectrum scanning fees that previously added to total Redshift costs.</p><p><strong class="c10">Now available</strong><br />Amazon Redshift RG instances are now available in the following AWS Regions: US East (N. Virginia, Ohio), US West (N. California, Oregon), Asia Pacific (Hong Kong, Hyderabad, Jakarta, Malaysia, Melbourne, Mumbai, Osaka, Seoul, Singapore, Sydney, Taiwan, Tokyo), Canada (Central), Europe (Frankfurt, Ireland, Milan, London, Paris, Spain, Stockholm), and South America (São Paulo). For Regional availability and a future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>. For Redshift Provisioned, you can select On-Demand Instances with hourly billing and no commitments or choose Reserved Instances for cost savings. To learn more, visit the <a href="https://aws.amazon.com/redshift/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Redshift Pricing page</a>.</p><p>Give RG instances a try in the <a href="https://console.aws.amazon.com/redshift/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Redshift console</a> and send feedback to <a href="https://repost.aws/tags/TAByF7MpfSQUCX_lAeDTvODw/amazon-redshift?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Amazon Redshift</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy">Channy</a></p><p>Updated 5/12/26: Middle East (UAE) removed from available regions.</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="fac5f831-f76c-4c6e-b2c5-ad6cadc4a616" data-title="Amazon Redshift introduces AWS Graviton-based RG instances with an integrated data lake query engine" data-url="https://aws.amazon.com/blogs/aws/amazon-redshift-introduces-aws-graviton-based-rg-instances-with-an-integrated-data-lake-query-engine/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-redshift-introduces-aws-graviton-based-rg-instances-with-an-integrated-data-lake-query-engine/"/>
    <updated>2026-05-12T18:05:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-bedrock-agentcore-payments-agent-toolkit-for-aws-and-more-may-11-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Amazon Bedrock AgentCore payments, Agent Toolkit for AWS, and more (May 11, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>My most exciting news of last week: <a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-bedrock-agentcore-payments-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock AgentCore previewed the first managed payment capabilities</a> enabling AI agents to autonomously access and pay for APIs, MCP servers, web content, and other agents. Built in partnership with Coinbase and Stripe, it removes the undifferentiated heavy lifting of building customized systems for billing, credential management, and compliance.</p><p><img class="aligncenter size-full c6" src="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/05/06/images-ML-20991-1.png.jpg" alt="image" style="text-align: center;" /></p><p>You can connect a Coinbase CDP wallet or Stripe Privy wallet as a payment connection, set session-level spending limits, and your agent transacts autonomously during execution. What excites me most is what AgentCore payments can unlock—like a research agent that can pay for real-time market data on the fly, or a coding agent calling paid APIs mid-task.</p><p>To learn more, visit the <a href="https://aws.amazon.com/blogs/machine-learning/agents-that-transact-introducing-amazon-bedrock-agentcore-payments-built-with-coinbase-and-stripe/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">blog post</a>, dive deeper using the <a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/payments.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">documentation</a>, and get started with the <a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-get-started-cli.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AgentCore CLI.</a></p><p><strong>Last week’s launches</strong><br />Here are last week’s launches that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/agent-toolkit/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Agent Toolkit for AWS</a> – A production-ready suite of tools and guidance, available at no additional charge, that helps AI coding agents build on AWS with fewer errors, lower token costs, and enterprise-grade security controls. The Agent Toolkit for AWS is the successor to the MCP servers, plugins, and skills available on <a href="https://github.com/awslabs">AWS Labs</a>. To get started, visit the <a href="https://docs.aws.amazon.com/agent-toolkit/latest/userguide/quick-start.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">quick start guide</a> or browse the available skills and plugins on <a href="https://github.com/aws/agent-toolkit-for-aws">GitHub</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-mcp-server/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS MCP Server GA</a> – You can use a managed remote Model Context Protocol (MCP) server that gives AI agents and coding assistants secure, authenticated access to all AWS services through a small, fixed set of tools. It is part of the Agent Toolkit for AWS. To learn more, visit <a href="https://aws.amazon.com/blogs/aws/the-aws-mcp-server-is-now-generally-available/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Seb Stormacq’s blog post</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/workspaces-ai-agents/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon WorkSpaces for AI agents (Preview)</a> – You can use AI agents to securely access and operate desktop applications through managed WorkSpaces environments. This capability allows organizations to automate everyday workflows at scale while maintaining full enterprise-grade governance and compliance. To learn more, visit <a href="https://aws.amazon.com/blogs/aws/modernize-your-workflows-amazon-workspaces-now-gives-ai-agents-their-own-desktop-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Micah Walter’s blog post</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-ec2-m8idn-m8idb/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 M8idn/M8idb</a> and <a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-ec2-r8idn-r8idb/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">R8idn/R8idb instances</a> – These instances are powered by custom sixth-generation Intel Xeon Scalable processors available only on AWS and the latest sixth-generation AWS Nitro cards. These instances deliver up to 43% better compute performance per vCPU compared to previous-generation instances. M8idn/R8idn instances offer up to 600 Gbps network bandwidth, and M8idb/R8idb instances deliver up to 300 Gbps EBS bandwidth.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">What’s New with AWS</a> page.</p><p><strong>Additional updates</strong><br />Here are some additional news items that you might find interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/database/valkey-turns-two/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Valkey turns two</a> – Valkey stands as proof that open, community-driven technology innovates faster, scales further, and delivers more value than any single-vendor model. Valkey has surpassed 100 million Docker pulls (up 17x year over year) and attracted more than 225 contributors who have submitted over 1,500 pull requests, roughly double the development pace of Redis over the same period. You can also use the latest <a href="https://aws.amazon.com/blogs/database/announcing-valkey-9-0-for-amazon-elasticache/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Valkey 9.0 in Amazon ElastiCache</a>.</li>
<li><a href="https://aws.amazon.com/blogs/database/query-billion-scale-vectors-with-sql-integrating-amazon-s3-vectors-and-aurora-postgresql/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Query billion-scale vectors with SQL</a> – You can learn how to query Amazon S3 Vectors from Amazon Aurora PostgreSQL-Compatible Edition using standard SQL, and how to combine vector similarity results with relational filters in a single query, for example, finding the most semantically similar products and then filtering by price, stock status, or tenant in one SQL statement.</li>
<li><a href="https://aws.amazon.com/blogs/devops/building-an-end-to-end-agentic-sre-using-aws-devops-agent/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Building an end-to-end agentic SRE using AWS DevOps Agent</a> – Learn how to configure DevOps Agent Spaces that define an investigation scope, integrating seamlessly with Amazon CloudWatch, Splunk, GitHub, and Slack. You can also learn how to trigger automated investigations via webhooks, generate mitigation plans, and hand off agent-ready specs to coding agents like Kiro for implementation.</li>
</ul><p>For a full list of AWS blog posts, be sure to keep an eye on the <a href="https://aws.amazon.com/blogs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Blogs</a> page.</p><p>Learn more about AWS, browse and join upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS-led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?tab=upcoming?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused events</a> as well as <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summits</a> and <a href="https://aws.amazon.com/events/community-day/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Community Days</a>. Join the <a href="https://builder.aws.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development.</p><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Weekly Roundup</a>!</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="d5fae86b-2eaf-42c3-91a9-6aed62c40949" data-title="AWS Weekly Roundup: Amazon Bedrock AgentCore payments, Agent Toolkit for AWS, and more (May 11, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-bedrock-agentcore-payments-agent-toolkit-for-aws-and-more-may-11-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-bedrock-agentcore-payments-agent-toolkit-for-aws-and-more-may-11-2026/"/>
    <updated>2026-05-11T18:08:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/the-aws-mcp-server-is-now-generally-available/</id>
    <title><![CDATA[The AWS MCP Server is now generally available]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>I have been building with AI agents and MCP tools for a while now, and one question kept coming up: how do you give an agent real, authenticated access to AWS without handing it the keys to the kingdom? Today, there is an answer.</p><p>I’m happy to announce the general availability of the <a href="https://docs.aws.amazon.com/aws-mcp/latest/userguide/what-is-mcp-server.html">AWS MCP Server</a>, a managed remote Model Context Protocol (MCP) server that gives AI agents and coding assistants secure, authenticated access to all AWS services through a small, fixed set of tools.</p><p>The AWS MCP Server is part of the <a href="https://aws.amazon.com/products/developer-tools/agent-toolkit-for-aws/">Agent Toolkit for AWS</a>, a suite of tooling that includes the MCP Server, skills, and plugins that help coding agents build more effectively and efficiently on AWS.</p><p>AI coding agents are already useful for many tasks, but they run into real trouble when working with AWS at any meaningful depth. Without access to current <a href="https://docs.aws.amazon.com/">AWS documentation</a>, agents rely on training data that may be months out of date and may not know about services like <a href="https://aws.amazon.com/s3/features/vectors/">Amazon S3 Vectors</a>, <a href="https://aws.amazon.com/rds/aurora/dsql/">Amazon Aurora DSQL</a>, or <a href="https://aws.amazon.com/bedrock/agentcore/">Amazon Bedrock AgentCore</a>. When asked to build infrastructure, they tend to reach for the <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a> rather than <a href="https://aws.amazon.com/cdk/">AWS Cloud Development Kit (AWS CDK)</a> or <a href="https://aws.amazon.com/cloudformation/">AWS CloudFormation</a>, and they produce <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (IAM)</a> policies that are far broader than necessary. The result is infrastructure that works in a demo but is not production-ready.</p><p>The AWS MCP Server addresses this through a compact set of tools that do not consume your model’s context window. The <code>call_aws</code> tool executes any of the 15,000+ AWS API operations using your existing IAM credentials. When we will launch new APIs, they will be supported within days. The <code>search_documentation</code> and <code>read_documentation</code> tools retrieve current AWS documentation and best practices at query time, so the agent always works from up-to-date information.</p><p>With general availability, we are introducing several new capabilities. The AWS MCP Server now supports IAM context keys, so you no longer need a separate IAM permission to use the server and can express fine-grained access in a standard IAM policy. Documentation retrieval no longer requires authentication. We have also reduced the number of tokens required per interaction, which matters for complex, multi-step workflows.</p><p>Also new, the <code>run_script</code> tool lets the agent write a short Python script that runs server-side in a sandboxed environment. The sandbox inherits your IAM permissions but has no network access, so you can give an agent the ability to process data without giving it access to your local file system or a shell. When an agent needs to call multiple APIs and combine the results, making them one at a time is slow and burns context. With <code>run_script</code>, the agent chains API calls, filters responses, and computes results in a single round-trip, which is both faster and more context-efficient.</p><p>The most significant addition is the transition from Agent SOPs to Skills. Skills provide curated guidance and best practices for the tasks where agents most commonly make mistakes. This helps agents complete work faster, using validated best practices, with fewer errors and fewer tokens — all of which saves you time and money. Skills are contributed and maintained by AWS service teams. This keeps the tool list short and predictable, which reduces hallucination and keeps the agent focused.</p><p>For enterprise customers, the AWS MCP Server provides a clear separation between human and agent permissions. You can use IAM policies or Service Control Policies to specify that a given user can perform mutating operations while the MCP server is restricted to read-only actions. Amazon CloudWatch metrics published under the <code>AWS-MCP</code> namespace let you observe MCP server calls separately from direct human calls, giving you the audit trail that compliance teams require. Amazon CloudTrail captures all API calls for a complete record.</p><p><strong>Let’s see it in action<br /></strong> For this demo, I chose to use <a href="https://claude.ai/code">Claude Code</a>, but I can use the AWS MCP Server with any AI agent that supports MCP, which is basically all tools available today: <a href="https://kiro.dev/docs/cli">Kiro CLI</a>, <a href="https://kiro.dev">Kiro</a>, <a href="https://www.cursor.com">Cursor</a>, <a href="https://openai.com/codex">Codex</a>, and more. I configure Claude Code to use the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/model-card-anthropic-claude-opus-4-6.html">Anthropic Opus 4.6 model</a>.</p><p>Opus 4.6 has a <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/model-card-anthropic-claude-opus-4-6.html">knowledge cutoff date in May 2025</a>. It means it doesn’t know anything that happened after May last year. I ask a question about an AWS service that was introduced recently: <a href="https://aws.amazon.com/s3/features/vectors/">Amazon S3 Vectors</a>, launched in <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/amazon-s3-vectors-preview-native-support-storing-querying-vectors/">preview in July 2025</a> and that went <a href="https://aws.amazon.com/blogs/aws/amazon-s3-vectors-now-generally-available-with-increased-scale-and-performance/">GA in December 2025</a>.</p><p>The question is “how to store <a href="https://aws.amazon.com/what-is/embeddings-in-machine-learning/">embedding</a> on S3″. (embedding is a kind of vector)</p><p>It gives me five solutions, all correct, but none using S3 Vectors as I asked. Note that this answer comes from the Opus 4.6 model, not from Claude Code. Any AI tool using the same model will return similar answers because S3 Vectors wasn’t announced at the time the model was trained.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/23/2026-04-23_09-53-22.png"><img class="aligncenter size-large wp-image-103776" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/23/2026-04-23_09-53-22-1024x813.png" alt="Claude Code response about S3 Vectors with Opus 4.6 and no AWS MCP Server" width="1024" height="813" /></a></p><p>Let’s now try with the AWS MCP Server.</p><p>The AWS MCP Server uses <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (IAM)</a> and IAM <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sigv.html">SigV4 authentication</a>. To use my local AWS credentials configuration over MCP, <a href="https://modelcontextprotocol.io/specification/2025-11-25/basic/authorization">which only supports OAuth 2.1</a>, I configure my AI coding agent to call the AWS MCP Server through a proxy. The <a href="https://github.com/aws/mcp-proxy-for-aws">MCP Proxy for AWS</a> is an open source proxy that runs on my machine and bridges the world of IAM authentication to OAuth.</p><p>I add the MCP configuration with this command:</p><pre class="lang-bash">claude mcp add-json aws-mcp --scope user \
   '{"command":"uvx","args":["mcp-proxy-for-aws@latest","https://aws-mcp.us-east-1.api.aws/mcp","--metadata","AWS_REGION=us-west-2"]}'
</pre><p>Let’s analyze the JSON configuration:</p><ul><li>I use the user <a href="https://code.claude.com/docs/en/mcp#mcp-installation-scopes">scope</a> to make the server available to all my projects on my laptop.</li>
<li><code>uvx mcp-proxy-for-aws</code> is the command to launch the proxy; the rest of the arguments are parameters passed to the proxy.</li>
<li><code>https://aws-mcp.us-east-1.api.aws/mcp</code> is one of the two regional endpoints for the AWS MCP Server. The proxy will forward Claude Code’s requests to that endpoint.</li>
<li><code>--metadata</code> are passed to the proxy target. Here, it tells the AWS MCP Server to use the US West (Oregon) Region.</li>
</ul><p>I start Claude Code and I type <code>/mcp</code> to verify the AWS MCP Server is correctly installed and can use my credentials.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/23/2026-04-23_09-29-47.png"><img class="aligncenter size-large wp-image-103775" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/23/2026-04-23_09-29-47-1024x678.png" alt="Verify AWS MCP Server in Claude Code" width="1024" height="678" /></a></p><p>I ask the same question: “how can I store embedding on S3”.</p><p>This time, Claude Code knows it has a tool it can use to answer the question. It asks me permission to invoke the <code>aws___search_documentation</code> tool. After a few seconds, I receive a correct answer: “AWS now has a dedicated service for this: Amazon S3 Vectors …”</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/23/2026-04-23_09-59-16.png"><img class="aligncenter size-large wp-image-103777" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/23/2026-04-23_09-59-16-1024x813.png" alt="Claude Code correct response about S3 Vectors" width="1024" height="813" /></a></p><p><strong>Pricing and availability<br /></strong> The AWS MCP Server is available today in the US East (N. Virginia) and Europe (Frankfurt) AWS Regions and can make API calls to any Region. There is no additional charge for the AWS MCP server itself. You pay only for the AWS resources you create and any applicable data transfer costs.</p><p>The AWS MCP Server works with Claude Code, Kiro, Cursor, and any MCP-compatible client. To get started, see the <a href="https://docs.aws.amazon.com/aws-mcp/latest/userguide/what-is-mcp-server.html">AWS MCP Server User Guide</a>.</p><p>I have been waiting for something like this since I started using MCP tools in my AI agents early last year. The combination of current documentation, authenticated API access, and sandboxed script execution in a single server changes what an agent can actually do on AWS. I am curious what you build with it. Let me know in the comments.</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="a9ac5657-c30a-49ef-b8aa-1290fd62ab2f" data-title="The AWS MCP Server is now generally available" data-url="https://aws.amazon.com/blogs/aws/the-aws-mcp-server-is-now-generally-available/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/the-aws-mcp-server-is-now-generally-available/"/>
    <updated>2026-05-06T17:36:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/modernize-your-workflows-amazon-workspaces-now-gives-ai-agents-their-own-desktop-preview/</id>
    <title><![CDATA[Modernize your workflows: Amazon WorkSpaces now gives AI agents their own desktop (preview)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Enterprises face a significant challenge when deploying AI agents: the desktop and legacy applications that power most business workflows are simply inaccessible to modern AI systems. According to a <a href="https://www.gartner.com/en/documents/5947839">2024 Gartner report</a>, 75% of organizations run legacy applications that lack modern APIs, and 71% of Fortune 500 companies operate critical processes on mainframe systems without adequate programmatic access. For many organizations, this has meant choosing between delaying AI adoption or undertaking expensive and risky modernization projects.</p><p>Today, we are announcing that <a href="https://aws.amazon.com/workspaces/">Amazon WorkSpaces</a> now enables AI agents to securely operate desktop applications without requiring application modernization. The same managed virtual desktops that millions of employees use and trust can now also serve AI agents, turning WorkSpaces into infrastructure for scaling enterprise productivity, not just delivering it. Because agents operate within your existing WorkSpaces environment, there are no APIs to build, no application migrations to plan, and no new infrastructure to manage.</p><p>Some of our customers had an early opportunity to give their agents a WorkSpace. Chris Noon, Director, Nuvens Consulting shared with us, <em>“WorkSpaces lets our clients give AI agents the same secure, governed desktop environment their employees already use — no custom API integrations, full audit trails, and enterprise-grade isolation out of the box. For regulated industries, that’s not a nice-to-have — it’s the baseline.”</em></p><p><strong>Secure cloud desktop access for AI agents<br /></strong> With WorkSpaces, AI agents can securely access and operate desktop applications running inside managed WorkSpaces environments to complete complex business workflows. Agents authenticate through <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (IAM)</a> and connect via Workspaces with complete audit trails available through <a href="https://aws.amazon.com/cloudtrail/">AWS CloudTrail</a> and <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a>. Because agents operate within secure WorkSpaces environments rather than on local machines, your existing security controls and compliance policies remain fully intact.</p><p>Amazon Workspaces supports the industry-standard <a href="https://modelcontextprotocol.io/docs/getting-started/intro">Model Context Protocol (MCP)</a>, which means WorkSpaces works with any agent framework, such as <a href="https://www.langchain.com/">LangChain</a>, <a href="https://crewai.com/">CrewAI</a> and <a href="https://strandsagents.com/">Strands Agents</a>.</p><p><strong>Let’s try it out<br /></strong> To set up a WorkSpaces environment for AI agents, I started in the <a href="https://aws.amazon.com/console/">AWS Management Console</a> by creating a new WorkSpaces Applications stack—the environment definition that controls how agents connect and what they’re allowed to do.</p><p>From the Amazon WorkSpaces console, I chose <strong>Create stack</strong> and configured the basics: name, fleet association, and VPC endpoints. In Step 3 of the stack creation workflow, I noticed the new AI agents section with two options. The first, <strong>No AI agent access</strong>, is the default configuration for standard WorkSpaces designed for people. The second, <strong>Add AI Agents</strong>, allows AI agents to securely access and operate applications using their own identity and permissions. I selected Add AI Agents to enable agent connections on this stack.</p><p><img class="alignnone wp-image-103876 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/04/image.png" alt="Workspaces Screenshot" width="1628" height="1012" /></p><p>Next, I will enable storage before configuring the agent access settings to define how agents interact with the desktop.</p><p><img class="alignnone wp-image-103881 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/05/image-3-1.png" alt="Workspaces screenshot" width="1625" height="461" /></p><p>Under Agent features, I enabled three capabilities. <strong>Computer input</strong> allows the agent to click, type, and scroll within the desktop. <strong>Computer vision</strong> allows the agent to capture screenshots of the desktop, which is how it “sees” the application. Finally, screenshot storage configures where session screenshots are stored for audit and debugging.</p><p><img class="alignnone wp-image-103877 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/04/image-1-1.png" alt="Workspaces Screenshot" width="1618" height="1002" /></p><p>Under <strong>Desktop screen layout</strong>, I set the screen resolution to 1280×720 and image format to PNG. The resolution determines the fidelity of what the agent sees during a session—a complex application with dense UI elements might benefit from higher resolution, while a terminal-style interface works well at 720p.</p><p><img class="alignnone wp-image-103878 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/04/image-2-1.png" alt="Workspaces Screenshot" width="1624" height="1363" /></p><p>With my stack configured, WorkSpaces exposes a managed MCP endpoint. I pointed my agent framework to this endpoint, provided IAM credentials for authentication, and my agent began interacting with the desktop applications installed on the fleet’s image.</p><p>To see this in action, here’s an agent built with the Strands Agent SDK and <a href="https://aws.amazon.com/bedrock/">Amazon Bedrock</a> handling a prescription refill, looking up the patient record, searching for the medication, placing the order, and confirming a successful refill, all inside a sample pharmacy system with no API.</p><p>The application doesn’t know an agent is driving it. Nothing about the software was modified, rebuilt, or integrated. The agent worked with it exactly as it exists today.</p><p><strong>Now available<br /></strong> This feature is available today in public preview at no additional cost in US East (N. Virginia, Ohio), US West (Oregon), Canada (Central), Europe (Frankfurt, Ireland, Paris), and Asia (Tokyo, Mumbai, Sydney, Seoul, Singapore) <a href="https://aws.amazon.com/about-aws/global-infrastructure/regions_az/">Regions</a>.</p><p>Get started building today using our <a href="https://github.com/aws-samples/sample-code-for-workspaces-agent-access">GitHub repo,</a> or visit the <a href="https://aws.amazon.com/workspaces/">WorkSpaces</a> page for more details.</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="d8ac3f55-f52a-4851-b46b-c9f977781f41" data-title="Modernize your workflows: Amazon WorkSpaces now gives AI agents their own desktop (preview)" data-url="https://aws.amazon.com/blogs/aws/modernize-your-workflows-amazon-workspaces-now-gives-ai-agents-their-own-desktop-preview/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/modernize-your-workflows-amazon-workspaces-now-gives-ai-agents-their-own-desktop-preview/"/>
    <updated>2026-05-05T19:23:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-whats-next-with-aws-2026-amazon-quick-openai-partnership-and-more-may-4-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: What’s Next with AWS 2026, Amazon Quick, OpenAI partnership, and more (May 4, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Last week, I took some time off in York, England, often described as the most haunted city in the country. I wandered through the ruins of abbeys that have stood for nearly a thousand years, walked along medieval walls, and spent an evening on a ghost tour hearing stories passed down through centuries. There’s something grounding about standing in a place that has witnessed so much history. Now I’m back at my desk, and the contrast is hard to miss: those abbey stones have stood for a thousand years largely unchanged, while in the span of a single week away, the pace of technological change has moved forward yet again.</p><div id="attachment_103852" class="wp-caption alignnone c6"><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/03/WIR-04-05-2026.jpeg"><img aria-describedby="caption-attachment-103852" class="wp-image-103852 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/05/03/WIR-04-05-2026.jpeg" alt="" width="1600" height="1200" /></a><p id="caption-attachment-103852" class="wp-caption-text">The ruins of Whitby Abbey in North Yorkshire. Stones that have seen a thousand years, while this week alone brought another wave of change.</p></div><p>Now, let’s get into this week’s AWS news.</p><p><strong>Headlines</strong><br />On April 28, Matt Garman, CEO of AWS, Colleen Aubrey, SVP Amazon Applied AI Solutions, Julia White, CMO of AWS, and OpenAI leaders took the stage to share how customers are changing the way businesses operate with agents. The event brought a packed slate of announcements across Amazon Quick, Amazon Connect, and a deeper partnership with OpenAI. Here’s a roundup of the biggest announcements from the event.</p><p><a href="https://www.aboutamazon.com/news/aws/amazon-quick-desktop-ai-assistant">Amazon Quick expands with a desktop app, new pricing plans, and visual asset generation</a> – Amazon Quick is an AI assistant for work that connects to your apps, learns what matters to you, and takes action on your behalf. This week, Quick introduced a new desktop app (Preview) that keeps you connected to your local files, calendar, and communications without opening a browser. You can sign up within minutes using your personal email address or existing Google, Apple, Github, or Amazon credentials—no AWS account required. Quick can now generate polished documents, presentations, infographics, and images directly from the chat interface, and native integrations expand to include Google Workspace, Zoom, Airtable, Dropbox, and Microsoft Teams. A new Build custom apps with Quick capability (Preview) lets you create intelligent apps, dashboards, and web pages connected to the rest of your business using natural language.</p><p><a href="https://www.aboutamazon.com/news/aws/amazon-connect-ai-business-set">Amazon Connect expands into four agentic AI solutions</a> – Amazon Connect is expanding from a single product into a set of four agentic AI solutions designed to work within your existing workflows. Amazon Connect Decisions is a supply chain planning and intelligence solution that shifts teams from crisis management to proactive planning, combining 30 years of Amazon operational science with more than 25 specialized supply chain tools. Amazon Connect Talent (Preview) is an agentic AI hiring solution that delivers AI-led interviews, science-backed assessments, and consistent evaluation for talent acquisition leaders managing scaled hiring. Amazon Connect Customer, previously known as Amazon Connect, delivers personalized customer experiences across voice, chat, and digital channels, with new configuration capabilities that enable organizations to set up conversational AI in weeks rather than months. Amazon Connect Health delivers agentic patient verification, appointment management, patient insights, ambient documentation, and medical coding, giving patients faster access to care and clinicians more time to deliver it.</p><p><a href="https://www.aboutamazon.com/news/aws/bedrock-openai-models">AWS and OpenAI expand their partnership across Amazon Bedrock</a> – AWS and OpenAI are bringing the latest OpenAI models to Amazon Bedrock, launching Codex on Amazon Bedrock, and introducing Amazon Bedrock Managed Agents powered by OpenAI — all in limited preview. OpenAI models on Amazon Bedrock (Limited preview) brings the latest OpenAI models, including GPT-5.5 and GPT-5.4, to the Bedrock APIs you already use, with unified security, governance, and cost controls. No additional infrastructure to configure, no new security model to learn. Codex on Amazon Bedrock (Limited preview) lets you access the OpenAI coding agent within your existing AWS environments, authenticating with your AWS credentials, processing inference through Bedrock, and applying Codex usage toward your AWS cloud commitments. Codex on Bedrock is available through the Bedrock API, starting with the Codex CLI, the Codex desktop app, and a Visual Studio Code extension. Amazon Bedrock Managed Agents, powered by OpenAI (Limited preview) combines OpenAI frontier models with AWS infrastructure to build production-ready OpenAI-powered agents in the cloud, built with the OpenAI harness for faster execution, sharper reasoning, and reliable steering of long-running tasks.</p><p>To learn more, visit <a href="https://aws.amazon.com/blogs/aws/top-announcements-of-the-whats-next-with-aws-2026/">Top announcements of the What’s Next with AWS, 2026</a>.</p><p><strong>Last week’s launches</strong><br />Here are some launches and updates from this past week that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-ec2-m8in-m8ib/">Amazon EC2 M8in and M8ib instances are now generally available</a> – Powered by custom 6th-gen Intel Xeon Scalable processors and 6th-gen AWS Nitro cards, these instances deliver up to 43% higher performance over M6in and M6ib. M8in offers 600 Gbps network bandwidth, while M8ib delivers up to 300 Gbps EBS bandwidth. Available in US East (N. Virginia), US West (Oregon), Asia Pacific (Tokyo), and Europe (Spain).</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-ec2-r8in-r8ib/">Amazon EC2 R8in and R8ib instances are now generally available</a> – Memory-optimized instances built on the same 6th-gen Intel Xeon Scalable processors and Nitro cards, with the same 600 Gbps network and 300 Gbps EBS bandwidth profiles. Well-suited for large commercial databases, data lakes, and in-memory databases such as SAP HANA. Available in US East (N. Virginia, Ohio), US West (Oregon), and Europe (Spain).</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/ec2-c8ine-m8ine/">Amazon EC2 C8ine and M8ine instances are now generally available</a> – Network-optimized instances offering up to 2.5x higher packet performance per vCPU and up to 2x higher network throughput for traffic through internet gateways compared to C6in and M6in. Designed for security and network virtual appliances including virtual firewalls, load balancers, and 5G UPF workloads. Available in US East (N. Virginia), US West (Oregon), and Asia Pacific (Tokyo) for C8ine; US East (N. Virginia) and US West (Oregon) for M8ine.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/05/bedrock-agentcore-optimization-preview/">Amazon Bedrock AgentCore adds optimization capabilities (Preview)</a> – AgentCore now offers recommendations, batch evaluations, and A/B tests to complete the observe-evaluate-improve loop for agents in production. Recommendations analyze production traces and evaluation outputs to propose optimized system prompts and tool descriptions, which you can validate with batch evaluations against pre-defined test cases or A/B tests against live traffic. Every recommendation requires your approval before it ships.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/aws-lambda-adds-ruby/">AWS Lambda adds support for Ruby 4.0</a> – Ruby 4.0, the latest LTS release, is available as a Lambda managed runtime and container base image. It includes support for Lambda advanced logging controls, including JSON structured logs, configurable logging levels, and target CloudWatch log group configuration. Available in all AWS Regions, including China Regions and AWS GovCloud (US).</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong>Other AWS news</strong><br />Here are some additional posts and resources that you might find interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/devops/amazon-q-developer-end-of-support-announcement/">Amazon Q Developer end-of-support announcement</a> – Amazon Q Developer IDE plugins and paid subscriptions will reach end of support on April 30, 2027, giving customers 12 months to transition to Kiro. New signups will be blocked starting May 15, 2026, although existing subscriptions can continue to add users. Starting May 29, 2026, Opus 4.6 will no longer be available on Q Developer Pro; Opus 4.5 and other existing models remain available, and the latest coding models including Opus 4.7 are available exclusively on Kiro. Amazon Q Developer in the AWS Management Console and first-party AWS experiences (documentation, mobile app, Slack, and Microsoft Teams) are not affected.</li>
<li><a href="https://builder.aws.com/content/3D5gTWIjP2zvKncBZBCs849xRqn/aws-10000-aideas-competition-meet-the-winners">AWS 10,000 AIdeas Competition: Meet the Winners</a> – AWS announced the 20 winners of the 10,000 AIdeas Competition, a global challenge where builders submitted AI applications built entirely with Kiro and the AWS Free Tier, with submissions from 115 countries narrowed down through four rounds of evaluation and two rounds of community voting. Winners span Global Champions, Regional Champions, Innovation Awards, and Creative Track categories, with cash prizes and AWS credits awarded across each tier.</li>
<li><a href="https://builder.aws.com/content/3C075iQJeEx03mnzHwmXO9zdgEG/aws-student-builder-groups">AWS Student Builder Groups</a> – AWS Cloud Clubs is evolving to AWS Student Builder Groups. The community now spans 600+ colleges and universities across 63 countries. Existing Cloud Club memberships, badges, and progress carry forward, and Cloud Club Captains become Group Leaders. Membership is open to any learner 18 or older. You can find a group near you on AWS Builder Center or apply to launch a new group on your campus.</li>
</ul><p><strong>Upcoming AWS events</strong><br />Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/summits/">AWS Summits</a> – AWS Summits are free in-person events covering cloud and AI. Coming up in May: <a href="https://aws.amazon.com/events/summits/singapore/">Singapore</a> (May 6), <a href="https://aws.amazon.com/events/summits/tel-aviv/">Tel Aviv</a> (May 6), <a href="https://aws.amazon.com/events/summits/warsaw/">Warsaw</a> (May 6), <a href="https://aws.amazon.com/events/summits/stockholm/">Stockholm</a> (May 7), <a href="https://aws.amazon.com/events/summits/sydney/">Sydney</a> (May 13–14), <a href="https://aws.amazon.com/events/summits/hamburg/">Hamburg</a> (May 20), <a href="https://aws.amazon.com/ko/events/summits/seoul/">Seoul</a> (May 20), <a href="https://aws.amazon.com/events/summits/amsterdam/">Amsterdam</a> (May 27), <a href="https://aws.amazon.com/it/events/summits/milano">Milano</a> (May 28), and <a href="https://aws.amazon.com/events/summits/mumbai/">Mumbai</a> (May 28).</li>
<li><a href="https://aws.amazon.com/events/community-day/">AWS Community Days</a> – Community-led conferences planned and delivered by community leaders. Upcoming events include <a href="https://aws.cloudturkey.io/">İstanbul, Türkiye</a> (May 9) and <a href="https://www.meetup.com/es-es/aws-user-group-panama/events/313780741/">Panama City, Panama</a> (May 23).</li>
</ul><p>Visit the <a href="https://builder.aws.com/?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">AWS Builder Center</a> to meet other builders, contribute solutions, and find resources that help you keep building. You can also browse upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS-led in-person and virtual events</a>, plus <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused sessions</a>.</p><a href="https://www.linkedin.com/in/esrakayabali/">— Esra</a><p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="55f35af5-cae4-4962-b5c5-47b40ccc1622" data-title="AWS Weekly Roundup: What’s Next with AWS 2026, Amazon Quick, OpenAI partnership, and more (May 4, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-whats-next-with-aws-2026-amazon-quick-openai-partnership-and-more-may-4-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-whats-next-with-aws-2026-amazon-quick-openai-partnership-and-more-may-4-2026/"/>
    <updated>2026-05-04T19:05:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/top-announcements-of-the-whats-next-with-aws-2026/</id>
    <title><![CDATA[Top announcements of the What’s Next with AWS, 2026]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today at the <a href="https://aws.amazon.com/events/whats-next-with-aws/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">What’s Next with AWS</a>, Matt Garman, CEO of AWS, Colleen Aubrey, SVP Amazon Applied AI Solutions, Julia White, CMO of AWS, and OpenAI leaders discussed how they and their customers are changing how businesses operate with agents.</p><p>Here’s our roundup of the biggest announcements from the event:</p><p><a href="https://aws.amazon.com/quick/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el"><strong>Amazon Quick</strong></a> is an AI assistant for work that connects to all of them, learns what matters to you, and takes action on your behalf. Starting today, you can use the new desktop app, sign up for Free and Plus pricing plans, generate visual assets in the chat, and easily connect Quick to even more apps.</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-quick-macos-windows-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Quick’s new desktop app (Preview)</a>: You can create a personalized experience by staying connected to your local files, calendar, and communications without opening a browser.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-quick-free-plus/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">New Free and Plus pricing plans for Quick</a>: You can sign up within minutes using your personal email address or existing Google, Apple, Github, or Amazon credentials—no AWS account required.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-quick/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Generate visual assets on the fly</a>: Available today, Quick now lets you create polished documents, presentations, infographics, and images directly from the chat interface, no design skills or hours of formatting required.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-quick-google-workspace-zoom/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Easily connect Quick to even more apps</a>: Also available today, Quick is expanding its native integrations to include Google Workspace, Zoom, Airtable, Dropbox, and Microsoft Teams.</li>
</ul><p>To learn more, visit the <a href="https://www.aboutamazon.com/news/aws/amazon-quick-desktop-ai-assistant?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">About Amazon News post</a>.</p><p><a href="https://aws.amazon.com/products/connect/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el"><strong>Amazon Connect</strong></a> is expanding from a single product into a set of four agentic AI solutions designed to work within your existing workflows: Amazon Connect Decisions (supply chains), Talent (hiring), Customer (customer experience), and Health (health care).</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-connect-decisions-april/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Connect Decisions</a> is a supply chain planning and intelligence solution that shifts teams from crisis management to proactive planning and decisioning. AI teammates, combining 30 years of Amazon operational science and 25+ specialized supply chain tools, adapt to your business, learn from your team, and continuously improve your operations.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-connect-talent-ai-powered/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Connect Talent (Preview)</a> is an agentic AI hiring solution built for talent acquisition leaders managing scaled hiring. It delivers AI-led interviews, science-backed assessments, and consistent evaluation, helping recruiters hire high quality candidates faster while providing applicants with a flexible interview experience that reduces human preconceptions.</li>
<li><a href="https://aws.amazon.com/products/connect/customer?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Connect Customer</a>, previously known as Amazon Connect, delivers intelligent, personalized customer experiences across voice, chat, and digital channels. Amazon Connect Customer now offers new configuration capabilities that enable organizations to set up conversational AI in weeks, not months, and configure experiences without technical expertise.</li>
<li><a href="https://aws.amazon.com/products/connect/health?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Connect Health</a> delivers agentic patient verification, appointment management, patient insights, ambient documentation, and medical coding — giving patients faster access to care, clinicians more time for care, and staff capacity for specialized work.</li>
</ul><p>To learn more, visit the <a href="https://www.aboutamazon.com/news/aws/amazon-connect-ai-business-set?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">About Amazon News post</a>.</p><p><strong>AWS and OpenAI extended partnership<br /></strong> AWS and OpenAI are bringing the latest OpenAI models to Amazon Bedrock, launching Codex on Amazon Bedrock, and launching Amazon Bedrock Managed Agents, powered by OpenAI (all in limited preview), giving enterprises the frontier intelligence they want on the infrastructure they trust.</p><ul><li><a href="https://aws.amazon.com/bedrock/openai/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">OpenAI models on Amazon Bedrock (Limited preview)</a>: The latest OpenAI models, including GPT-5.5 and GPT-5.4, will be available in preview on Amazon Bedrock. Use OpenAI’s frontier models through the same Bedrock APIs you already rely on, with unified security, governance, and cost controls. No additional infrastructure to configure, no new security model to learn.</li>
<li><a class="link" href="http://openai.com/index/openai-on-aws?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Codex on Amazon Bedrock (Limited preview)</a>: You can access the OpenAI coding agent within the AWS environments where they already operate at scale. You can authenticate using their AWS credentials, process inference through Amazon Bedrock infrastructure, and apply Codex usage toward their AWS cloud commitments. Codex on Bedrock is available through the Bedrock API, starting with the Codex CLI, the Codex desktop app, and Visual Studio Code extension.</li>
<li><a href="https://aws.amazon.com/bedrock/managed-agents-openai/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock Managed Agents, powered by OpenAI (Limited preview)</a>: Amazon Bedrock Managed Agents combines frontier AI models with trusted AWS infrastructure, enabling customers to quickly and easily build production-ready OpenAI-powered agents in the cloud. It is built with the OpenAI harness, which is engineered to unlock the full potential of OpenAI frontier models, delivering faster execution, sharper reasoning, and reliable steering of long-running tasks.</li>
</ul><p><img class="aligncenter wp-image-103824 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/28/2026-bedrock-managed-agents-openai.png" alt="" width="1400" height="890" /></p><p>To learn more, visit the <a href="https://aws.amazon.com/about-aws/whats-new/2026/04/bedrock-openai-models-codex-managed-agents/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS What’s New post</a> and <a href="https://www.aboutamazon.com/news/aws/bedrock-openai-models?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">About Amazon News post</a>.</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="1b2b8735-5f8e-4ac8-a583-3efe3fa65fd0" data-title="Top announcements of the What’s Next with AWS, 2026" data-url="https://aws.amazon.com/blogs/aws/top-announcements-of-the-whats-next-with-aws-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/top-announcements-of-the-whats-next-with-aws-2026/"/>
    <updated>2026-04-28T20:11:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-anthropic-meta-partnership-aws-lambda-s3-files-amazon-bedrock-agentcore-cli-and-more-april-27-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Anthropic & Meta partnership, AWS Lambda S3 Files, Amazon Bedrock AgentCore CLI, and more (April 27, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/24/TechConn-1.png"><img class="size-full wp-image-103792 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/24/TechConn-1.png" alt="" width="612" height="329" /></a></p><p>Late March took me to Seattle for the Specialist Tech Conference, one of the most energizing gatherings of AWS specialists from around the world. It was an incredible opportunity to connect with peers, exchange experiences, and go deep on the latest advancements in Generative AI and Amazon Bedrock — and a powerful reminder of something I truly believe in: when specialists come together to challenge each other, explore edge cases, and co-create solutions, the impact goes far beyond the meeting room. In a fast-moving space like AI, having a strong internal community isn’t a nice-to-have — it’s a competitive advantage.</p><p>Now, let’s get into this week’s AWS news…</p><p><strong class="c6">Headlines</strong></p><p><a href="https://aws.amazon.com/bedrock/claude/">Anthropic partnership: Claude on AWS Trainium and Graviton, and Claude Cowork in Amazon Bedrock</a> – This week, AWS and Anthropic deepened their product collaboration in meaningful ways for builders. Anthropic is now training its most advanced foundation models on AWS Trainium and Graviton infrastructure, co-engineering directly at the silicon level with Annapurna Labs to maximize computational efficiency from the hardware up through the full stack.</p><p><a href="https://aws.amazon.com/blogs/machine-learning/from-developer-desks-to-the-whole-organization-running-claude-cowork-in-amazon-bedrock/">Claude Cowork is now available in Amazon Bedrock</a> — Claude Cowork brings Anthropic’s collaborative AI capabilities directly to enterprise builders within the AWS ecosystem, enabling teams to work alongside Claude as a true collaborator, not just a tool. You can now deploy Claude Cowork within your existing Amazon Bedrock environment, keeping your data secure within AWS while leveraging the full power of Claude for team-based AI workflows.</p><p><a href="https://aws.amazon.com/claude-platform/">Claude Platform on AWS</a> (Coming soon) — A unified developer experience to build, deploy, and scale Claude-powered applications without leaving AWS. If you’re building with Generative AI on AWS, this is a significant step forward in what you’ll be able to do with Claude directly through Amazon Bedrock.</p><p><a href="https://www.aboutamazon.com/news/aws/meta-aws-graviton-ai-partnership">Meta signs agreement with AWS to power agentic AI on Amazon’s Graviton chips</a> — Meta has signed an agreement to deploy AWS Graviton processors at scale, starting with tens of millions of Graviton cores to power CPU-intensive agentic AI workloads — including real-time reasoning, code generation, search, and multi-step task orchestration.</p><p><strong class="c6">Last week’s launches</strong></p><p>Here are some launches and updates from this past week that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/aws-lambda-amazon-s3/">AWS Lambda functions can now mount Amazon S3 buckets as file systems with S3 Files</a> — You can now mount Amazon S3 buckets as file systems in AWS Lambda using S3 Files, enabling your functions to perform standard file operations without downloading data for processing. Built on Amazon EFS, S3 Files provides the simplicity of a file system with the scalability, durability, and cost-effectiveness of S3 — and multiple Lambda functions can connect to the same file system simultaneously, sharing data through a common workspace. This is particularly valuable for AI and machine learning workloads where agents need to persist memory and share state across pipeline steps.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-eks-hybrid-nodes-gateway/">Amazon EKS Hybrid Nodes gateway for hybrid Kubernetes networking</a> — Amazon Elastic Kubernetes Service now offers the Amazon EKS Hybrid Nodes gateway, which automates networking between your EKS cluster VPC and Kubernetes Pods running on EKS Hybrid Nodes. You can now eliminate the need to make on-premises pod networks routable or coordinate network infrastructure changes, greatly simplifying hybrid Kubernetes environments. The gateway automatically enables pod-to-pod traffic across cloud and on-premises environments, control plane-to-webhook communication, and connectivity for AWS services like Application Load Balancers, and is available at no additional charge.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/aurora-serverless-smarter-scaling/">Amazon Aurora Serverless: Up to 30% better performance, smarter scaling, and still scales to zero</a> — Amazon Aurora Serverless just got faster and smarter, with up to 30% better performance than the previous version and an enhanced scaling algorithm designed to handle workloads where multiple tasks compete for resources — like busy APIs and agentic AI applications with bursts of activity and long idle windows. You can now run even more demanding workloads serverlessly, paying only for what you use, and automatically scaling to zero when not in use. All improvements are available in platform version 4 at no additional cost.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/agentcore-new-features-to-build-agents-faster/">Amazon Bedrock AgentCore adds new features to help developers build agents faster</a> — Amazon Bedrock AgentCore introduces a managed harness (preview), the AgentCore CLI, and AgentCore skills for coding assistants, helping developers go from idea to working agent prototype faster. The managed harness lets you define an agent by specifying a model, system prompt, and tools and run it immediately with no orchestration code required — and when you’re ready for full control, you can export the harness orchestration as Strands-based code. The AgentCore CLI deploys your agents with the governance and auditability of infrastructure-as-code (AWS CDK today, Terraform coming soon), and is available in 14 AWS Regions at no additional charge.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong class="c6">Other AWS news</strong></p><p>Here are some additional posts and resources that you might find interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/machine-learning/introducing-granular-cost-attribution-for-amazon-bedrock/">Introducing granular cost attribution for Amazon Bedrock</a> — This post walks through how Amazon Bedrock’s granular cost attribution works and covers practical example cost tracking scenarios. You can now tag and track Bedrock usage costs at a finer level of detail — useful for organizations running multiple teams or projects on Bedrock who need precise cost visibility and chargeback capabilities.</li>
<li><a href="https://aws.amazon.com/blogs/devops/automating-incident-investigation-with-aws-devops-agent-and-salesforce-mcp-server/">Automating Incident Investigation with AWS DevOps Agent and Salesforce MCP Server</a> — This post (co-written with Salesforce) shows how AWS DevOps Agent, integrated with the Salesforce MCP Server, automates the full lifecycle of infrastructure incident investigation — from identifying issues and diagnosing root causes to notifying customers through Salesforce Service Cloud. It’s a compelling real-world example of how AI agents and MCP-based tool connectivity are reshaping DevOps workflows in production, dramatically reducing mean time to resolution.</li>
<li><a href="https://aws.amazon.com/blogs/training-and-certification/microcredentials-from-aws-are-now-free-heres-why-that-matters/">Microcredentials from AWS are now free — Here’s why that matters</a> — You can now access AWS microcredentials at no cost through AWS Skill Builder in all countries where the platform is offered. Unlike traditional multiple-choice certifications, microcredentials are hands-on assessments that place builders in simulated business scenarios where they configure, troubleshoot, and optimize directly in a live AWS environment — the same way they would on the job. A great opportunity to validate real cloud skills without a cost barrier.</li>
<li><a href="https://aws.amazon.com/blogs/machine-learning/amazon-sagemaker-ai-now-supports-optimized-generative-ai-inference-recommendations/">Amazon SageMaker AI now supports optimized generative AI inference recommendations</a> — You can now use Amazon SageMaker AI to automatically identify optimized deployment configurations for your generative AI models, including instance type, container, and inference parameters. This new capability takes the guesswork out of tuning inference infrastructure, helping you reduce costs and improve latency for your AI applications in production.</li>
</ul><p><strong class="c6">Upcoming AWS events</strong></p><p>Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/">What’s Next with AWS</a> — Tune in on April 28 for What’s Next with AWS, a virtual event featuring the latest announcements and product updates directly from AWS teams. A great opportunity to get up to speed on what’s new before diving into the week’s launches.</li>
<li><a href="https://aws.amazon.com/events/summits/">AWS Summits</a> — AWS Summits are free in-person events where you can explore the latest in cloud and AI innovation, learn best practices, and network with builders and experts. Coming up in May: <a href="https://aws.amazon.com/events/summits/singapore/">Singapore</a> (May 6), <a href="https://aws.amazon.com/events/summits/tel-aviv/">Tel Aviv</a> (May 6), <a href="https://aws.amazon.com/events/summits/warsaw/">Warsaw</a> (May 6), <a href="https://aws.amazon.com/events/summits/stockholm/">Stockholm</a> (May 7), <a href="https://aws.amazon.com/events/summits/sydney/">Sydney</a> (May 13–14), <a href="https://aws.amazon.com/ko/events/summits/seoul/">Hamburg</a> (May 20), <a href="https://aws.amazon.com/ko/events/summits/seoul/">Seoul</a> (May 20), <a href="https://aws.amazon.com/events/summits/amsterdam/">Amsterdam</a> (May 27), <a href="https://aws.amazon.com/events/summits/">Bangkok</a> (May 28), <a href="https://aws.amazon.com/it/events/summits/milano/">Milan</a> (May 28), and <a href="https://aws.amazon.com/events/summits/mumbai/">Mumbai</a> (May 28). And in June, join us in Los Angeles (June 10). Check the full schedule and register at the link above.</li>
<li><a href="https://aws.amazon.com/developer/community/community-days/">AWS Community Days</a> — Community-led conferences where content is planned, sourced, and delivered by community leaders, featuring technical discussions, workshops, and hands-on labs. Upcoming events include Athens, Greece (April 28), Vancouver, Canada (May 1), İstanbul, Türkiye (May 9), and Panama City, Panama (May 23). If you’re in Latin America, mark your calendar for the AWS Community Day Belo Horizonte (August 22) — registration is open at <a href="https://awscommunityday.com.br/">awscommunityday.com.br</a>.</li>
</ul><p>Join the <a href="https://builder.aws.com/">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development. Browse <a href="https://aws.amazon.com/events/">here</a> for upcoming AWS-led in-person and virtual events and developer-focused events.</p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><p>— Daniel Abib</p><p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="2ed2029f-2d5c-4d1b-b1b6-74ac08d385ac" data-title="AWS Weekly Roundup: Anthropic &amp; Meta partnership, AWS Lambda S3 Files, Amazon Bedrock AgentCore CLI, and more (April 27, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-anthropic-meta-partnership-aws-lambda-s3-files-amazon-bedrock-agentcore-cli-and-more-april-27-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-anthropic-meta-partnership-aws-lambda-s3-files-amazon-bedrock-agentcore-cli-and-more-april-27-2026/"/>
    <updated>2026-04-27T17:01:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-opus-4-7-in-amazon-bedrock-aws-interconnect-ga-and-more-april-20-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Claude Opus 4.7 in Amazon Bedrock, AWS Interconnect GA, and more (April 20, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Last week I had the honor of delivering a commencement speech at the <a href="https://www.unamur.be">University of Namur</a> (uNamur) for their 2025 graduation ceremony.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/20/vsbd-Diplomation-info-132.jpg"><img class="aligncenter size-full wp-image-103749" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/20/vsbd-Diplomation-info-132.jpg" alt="uNamur Graduation Ceremony" width="1024" height="683" /></a></p><p>Standing in front of freshly minted computer science graduates, I talked about the future of software development in the age of AI. My message to them was simple: AI will not make you obsolete. We’ve seen tools evolve over the decades, from punch cards to IDEs to AI-assisted coding, but the work remains yours, not the tool’s. The developers who will thrive are those who stay curious, think in systems, communicate with precision, and take ownership of what they build. The world needs <em>more</em> people with coding skills, not fewer. AI raises the bar on what we can accomplish, and that’s a good thing.</p><p>Now, let’s get into this week’s AWS news.</p><p><strong>Headlines<br /></strong> <strong><a href="https://aws.amazon.com/blogs/aws/introducing-anthropics-claude-opus-4-7-model-in-amazon-bedrock/">Anthropic’s Claude Opus 4.7 is now available in Amazon Bedrock</a></strong> – Anthropic’s most intelligent Opus model is now available in Amazon Bedrock, with improved performance across coding, long-running agents, and professional knowledge work. Claude Opus 4.7 scores 64.3% on SWE-bench Pro and 87.6% on SWE-bench Verified, extending its lead in agentic coding with stronger long-horizon autonomy and complex code reasoning. It also does better on knowledge work tasks like document creation, financial analysis, and multi-step research.</p><p>The model runs on Bedrock’s next-generation inference engine with dynamic capacity allocation, adaptive thinking (letting Claude allocate thinking token budgets based on request complexity), and the full 1M token context window. It also adds high-resolution image support for better accuracy on charts, dense documents, and screen UIs. Claude Opus 4.7 is available at launch in US East (N. Virginia), Asia Pacific (Tokyo), Europe (Ireland), and Europe (Stockholm), with up to 10,000 requests per minute per account per Region.</p><p><strong><a href="https://aws.amazon.com/blogs/aws/aws-interconnect-is-now-generally-available-with-a-new-option-to-simplify-last-mile-connectivity/">AWS Interconnect is now generally available with a new option to simplify last-mile connectivity</a></strong> – AWS Interconnect brings two managed private connectivity capabilities to general availability. The first, <strong>AWS Interconnect – Multicloud</strong>, provides Layer 3 private connections between AWS VPCs and other cloud providers (Google Cloud available now, Azure and OCI coming later in 2026). Traffic flows over the AWS global backbone and the partner cloud’s private network, never over the public internet, with built-in MACsec encryption, multi-facility resiliency, and CloudWatch monitoring. AWS published the underlying specification on GitHub under Apache 2.0 so any cloud provider can become an Interconnect partner.</p><p>The second capability, <strong>AWS Interconnect – Last Mile</strong>, simplifies high-speed private connections from branch offices, data centers, and remote locations to AWS through existing network providers. It provisions 4 redundant connections across 2 physical locations automatically, configures BGP routing, activates MACsec encryption and Jumbo Frames by default, and offers bandwidth from 1 Gbps to 100 Gbps adjustable from the console without reprovisioning. Last Mile launches in US East (N. Virginia) with Lumen as the initial partner.</p><p><strong>Last week’s launches<br /></strong> Here are some launches and updates from this past week that caught my attention:</p><ul><li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-ecr-pull-through-cache-referrers/">Amazon ECR pull through cache now supports referrer discovery and sync</a></strong> — ECR’s pull through cache now automatically discovers and syncs OCI referrers (image signatures, SBOMs, attestations) from upstream registries into your private repositories. This means end-to-end image signature verification and SBOM discovery workflows work without client-side workarounds.</li>
<li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/aws-transform-kiro-vscode/">AWS Transform is now available in Kiro and VS Code</a></strong> — AWS Transform, the agentic migration and modernization factory, is now accessible via Kiro (as a Power) and VS Code (as an extension). You can run custom transformations for common patterns like Java/Python/Node.js version upgrades and AWS SDK migrations directly from your IDE, with job state shared across the web console, CLI, and IDE.</li>
<li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/aurora-dsql-connector-for-php/">Aurora DSQL launches connector for PHP</a></strong> — A new Aurora DSQL Connector for PHP (PDO_PGSQL) simplifies building PHP applications on Aurora DSQL by automatically generating IAM tokens, handling SSL configuration, managing connection pooling, and providing opt-in optimistic concurrency control retry with exponential backoff.</li>
<li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-quick-document-level-access-controls-google-drive/">Amazon Q supports document-level access controls for Google Drive</a></strong> — Amazon Q now enforces document-level access controls for Google Drive knowledge bases, combining indexed ACL replication for fast pre-retrieval filtering with real-time permission checks against Google Drive at query time.</li>
<li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/aws-secrets-manager-post-quantum-tls/">AWS Secrets Manager now supports hybrid post-quantum TLS</a></strong> — Secrets Manager now supports hybrid post-quantum key exchange using ML-KEM to protect secrets against both current and future quantum computing threats. This is automatically enabled in Secrets Manager Agent 2.0.0+, Lambda Extension v19+, and the CSI Driver 2.0.0+.</li>
<li><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-ec2-c8in-c8ib-instances-ga/">Amazon EC2 C8in and C8ib instances are now generally available</a></strong> — Powered by custom 6th-gen Intel Xeon Scalable processors and 6th-gen AWS Nitro cards, these instances deliver up to 43% higher performance over C6in. C8in offers 600 Gbps network bandwidth (highest among enhanced networking EC2 instances), while C8ib delivers up to 300 Gbps EBS bandwidth (highest among non-accelerated compute instances), scaling up to 384 vCPUs.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong>Other AWS news<br /></strong> Here are some additional posts and resources that you might find interesting:</p><ul><li><strong><a href="https://aws.amazon.com/blogs/containers/navigating-enterprise-networking-challenges-with-amazon-eks-auto-mode/">Navigating enterprise networking challenges with Amazon EKS Auto Mode</a></strong> — This post explains how EKS Auto Mode automates Kubernetes networking infrastructure including VPC CNI configuration, load balancer provisioning, and DNS management, reducing operational overhead while preserving enterprise security controls.</li>
<li><strong><a href="https://aws.amazon.com/blogs/machine-learning/introducing-granular-cost-attribution-for-amazon-bedrock/">Introducing granular cost attribution for Amazon Bedrock</a></strong> — My colleague Micah talked about this feature last week already, but the blog post came out after last week’s roundup. Amazon Bedrock now automatically attributes inference costs to the specific IAM principal that made each API call, with results flowing into AWS Cost and Usage Reports (CUR 2.0). You can aggregate costs by team, project, or cost center using IAM principal tags and session tags.</li>
<li><strong><a href="https://aws.amazon.com/blogs/storage/accelerate-development-workflows-with-amazon-ebs-volume-clones/">Accelerate development workflows with Amazon EBS Volume Clones</a></strong> — EBS Volume Clones let you create instant, point-in-time copies of EBS volumes that are immediately usable without waiting for data transfer. The post highlights use cases including dev/test environment refreshes, disaster recovery testing, and CI/CD pipeline acceleration.</li>
<li><strong><a href="https://aws.amazon.com/blogs/migration-and-modernization/modernize-vb6-applications-at-scale-with-aws-transform-custom/">Modernize VB6 applications at scale with AWS Transform Custom</a></strong> — A walkthrough of using AWS Transform Custom’s agentic AI capabilities to convert legacy Visual Basic 6.0 applications to modern C# ASP.NET Core web applications, addressing challenges like COM dependencies, ADO-to-Entity Framework migration, and VB6 forms-to-Blazor UI conversion.</li>
<li><strong><a href="https://aws.amazon.com/blogs/migration-and-modernization/migrating-and-decomposing-apis-with-zero-downtime-using-cloudfront/">Migrating and decomposing APIs with zero-downtime using CloudFront</a></strong> — A zero-downtime API migration strategy using CloudFront Functions with CloudFront KeyValueStore for intelligent, user-aware traffic routing based on the Strangler Fig pattern. This is similar to what <a href="https://aws.amazon.com/blogs/aws/new-aws-migration-hub-refactor-spaces-helps-to-incrementally-refactor-your-applications/">AWS Migration Hub Refactor Spaces</a> offers, but implemented with just CloudFront and edge functions.</li>
</ul><p><strong>Upcoming AWS events<br /></strong> Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/"><strong>AWS Events</strong></a> — Browse upcoming AWS-led in-person and virtual events, startup events, and developer-focused events near you.</li>
<li><a href="https://pages.awscloud.com/traincert-twitch-power-hour-702702.html"><strong>AWS Power Hour</strong></a> — Weekly live training sessions on Twitch covering various AWS topics.</li>
<li><a href="https://community.aws/"><strong>Community.aws</strong></a> — Find community-led events, meetups, and user groups in your area.</li>
</ul><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="1ee02f46-4788-48a8-8eef-c901a13a284d" data-title="AWS Weekly Roundup: Claude Opus 4.7 in Amazon Bedrock, AWS Interconnect GA, and more (April 20, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-opus-4-7-in-amazon-bedrock-aws-interconnect-ga-and-more-april-20-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-opus-4-7-in-amazon-bedrock-aws-interconnect-ga-and-more-april-20-2026/"/>
    <updated>2026-04-20T17:53:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/introducing-anthropics-claude-opus-4-7-model-in-amazon-bedrock/</id>
    <title><![CDATA[Introducing Anthropic’s Claude Opus 4.7 model in Amazon Bedrock]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing <a href="https://aws.amazon.com/bedrock/anthropic/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Claude Opus 4.7 in Amazon Bedrock</a>, Anthropic’s most intelligent Opus model for advancing performance across coding, long-running agents, and professional work.</p><p><a href="https://www.anthropic.com/claude/opus">Claude Opus 4.7</a> is powered by Amazon Bedrock’s next generation inference engine, delivering enterprise-grade infrastructure for production workloads. Bedrock’s new inference engine has brand-new scheduling and scaling logic which dynamically allocates capacity to requests, improving availability particularly for steady-state workloads while making room for rapidly scaling services. It provides zero operator access—meaning customer prompts and responses are never visible to Anthropic or AWS operators—keeping sensitive data private.</p><p>According to Anthropic, Claude Opus 4.7 model provides improvements across the workflows that teams run in production such as agentic coding, knowledge work, visual understanding,long-running tasks. Opus 4.7 works better through ambiguity, is more thorough in its problem solving, and follows instructions more precisely.</p><ul><li><strong>Agentic coding</strong>: The model extends Opus 4.6’s lead in agentic coding, with stronger performance on long-horizon autonomy, systems engineering, and complex code reasoning tasks. According to Anthropic, the model records high-performance scores with 64.3% on SWE-bench Pro, 87.6% on SWE-bench Verified, and 69.4% on Terminal-Bench 2.0.</li>
<li><strong>Knowledge work</strong>: The model advances professional knowledge work, with stronger performance on document creation, financial analysis, and multi-step research workflows. The model reasons through underspecified requests, making sensible assumptions and stating them clearly, and self-verifies its output to improve quality on the first step. According to Anthropic, the model reaches 64.4% on Finance Agent v1.1.</li>
<li><strong>Long-running tasks</strong>: The model stays on track over longer horizons, with stronger performance over its full 1M token context window as it reasons through ambiguity and self-verifies its output.</li>
<li><strong>Vision</strong>: the model adds high-resolution image support, improving accuracy on charts, dense documents, and screen UIs where fine detail matters.</li>
</ul><p>The model is an upgrade from Opus 4.6 but may require prompting changes and harness tweaks to get the most out of the model. To learn more, visit <a href="https://platform.claude.com/docs/en/build-with-claude/prompt-engineering/claude-prompting-best-practices">Anthropic’s prompting guide</a>.</p><p><strong>Claude Opus 4.7 model in action</strong><br />You can get started with Claude Opus 4.7 model in <a href="https://console.aws.amazon.com/bedrock/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock console</a>. Choose <strong>Playground</strong> under <strong>Test</strong> menu and choose <strong>Claude Opus 4.7</strong> when you select model. Now, you can test your complex coding prompt with the model.</p><p><img class="aligncenter wp-image-103731 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/16/2026-bedrock-playground-model-selection.jpg" alt="" width="1800" height="1083" /></p><p>I run the following prompt example about technical architecture decision:<br /><code>Design a distributed architecture on AWS in Python that should support 100k requests per second across multiple geographic regions.</code></p><p><img class="aligncenter wp-image-103733 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/16/2026-bedrock-playground-opus4-7-prompt.jpg" alt="" width="1800" height="960" /></p><p>You can also access the model programmatically using the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/model-parameters-anthropic-claude-messages.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Anthropic Messages API</a> to call the <code>bedrock-runtime</code> through Anthropic SDK or <code>bedrock-mantle</code> endpoints, or keep using the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/inference-invoke.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Invoke</a> and <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/conversation-inference.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Converse API</a> on <code>bedrock-runtime</code> through the <a href="https://aws.amazon.com/cli/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS Command Line Interface (AWS CLI)</a> and <a href="https://aws.amazon.com/developer/tools/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS SDK</a>.</p><p>To get started with making your first API call to Amazon Bedrock in minutes, choose <strong>Quickstart</strong> in the left navigation pane in the console. After choosing your use case, you can generate a short term API key to authenticate your requests as testing purpose.</p><p>When you choose the API method such as the OpenAI-compatible Responses API, you can get sample codes to run your prompt to make your inference request using the model.</p><p><img class="aligncenter wp-image-103729 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/16/2026-bedrock-quickstart.jpg" alt="" width="1604" height="2560" /><br />To invoke the model through the Anthropic Claude Messages API, you can proceed as follows using <code>anthropic[bedrock]</code> SDK package for a streamlined experience:</p><pre class="lang-python">from anthropic import AnthropicBedrockMantle
# Initialize the Bedrock Mantle client (uses SigV4 auth automatically)
mantle_client = AnthropicBedrockMantle(aws_region=REGION)
# Create a message using the Messages API
message = mantle_client.messages.create(
    model="anthropic.claude-opus-4-7",
    max_tokens=2048,
    messages=[ 
            {"role": "user", "content": "Design a distributed architecture on AWS in Python that should support 100k requests per second across multiple geographic regions"}
    ]
)
print(message.content[0].text)</pre><p>You can also run the following command to invoke the model directly to <code>bedrock-runtime</code> endpoint using the AWS CLI and the Invoke API:</p><pre class="lang-bash">aws bedrock-runtime invoke-model \ 
 --model-id anthropic.claude-opus-4-7 \ 
 --region us-east-1 \ 
 --body '{"messages": [{"role": "user", "content": "Design a distributed architecture on AWS in Python that should support 100k requests per second across multiple geographic regions."}], "max_tokens": 512, "temperature": 0.5, "top_p": 0.9}' \ 
 --cli-binary-format raw-in-base64-out \ 
invoke-model-output.txt</pre><p>For more intelligent reasoning capability, you can use <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/claude-messages-adaptive-thinking.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Adaptive thinking</a> with Claude Opus 4.7, which lets Claude dynamically allocate thinking token budgets based on the complexity of each request.</p><p>To learn more, visit the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/model-parameters-anthropic-claude-messages.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Anthropic Claude Messages API</a> and check out <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/api-inference-examples-claude-messages-code-examples.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">code examples</a> for multiple use cases and a variety of programming languages.</p><p>To learn more, visit the Anthropic Claude Messages API and check out code examples for multiple use cases and a variety of programming languages.</p><p><strong>Things to know<br /></strong> Let me share some important technical details that I think you’ll find useful.</p><ul><li><strong>Choosing APIs</strong>: You can choose from a variety of Bedrock APIs for model inference, as well as the Anthropic Messages API. The Bedrock-native Converse API supports multi-turn conversations and Guardrails integration. The Invoke API provides direct model invocation and lowest-level control.</li>
<li><strong>Scaling and capacity</strong>: Bedrock’s new inference engine is designed to rapidly provision and serve capacity across many different models. When accepting requests, we prioritize keeping steady state workloads running, and ramp usage and capacity rapidly in response to changes in demand. During periods of high demand, requests are queued, rather than rejected. Up to 10,000 requests per minute (RPM) per account per Region are available immediately, with more available upon request.</li>
</ul><p><strong class="c7">Now available</strong><br />Anthropic’s Claude Opus 4.7 model is available today in the US East (N. Virginia), Asia Pacific (Tokyo), Europe (Ireland), and Europe (Stockholm) Regions; check the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/models-regions.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">full list of Regions</a> for future updates. To learn more, visit the <a href="https://aws.amazon.com/bedrock/anthropic/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Claude by Anthropic in Amazon Bedrock</a> page and the <a href="https://aws.amazon.com/bedrock/pricing/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon Bedrock pricing</a> page.</p><p>Give Anthropic’s Claude Opus 4.7 a try in the <a href="https://console.aws.amazon.com/bedrock?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock console</a> today and send feedback to <a href="https://repost.aws/tags/TAQeKlaPaNRQ2tWB6P7KrMag/amazon-bedrock">AWS re:Post for Amazon Bedrock</a> or through your usual AWS Support contacts.</p><p>— <a href="https://twitter.com/channyun">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="097e84e4-aecf-4f75-9484-ab5485bdc7cd" data-title="Introducing Anthropic’s Claude Opus 4.7 model in Amazon Bedrock" data-url="https://aws.amazon.com/blogs/aws/introducing-anthropics-claude-opus-4-7-model-in-amazon-bedrock/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/introducing-anthropics-claude-opus-4-7-model-in-amazon-bedrock/"/>
    <updated>2026-04-16T16:49:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-interconnect-is-now-generally-available-with-a-new-option-to-simplify-last-mile-connectivity/</id>
    <title><![CDATA[AWS Interconnect is now generally available, with a new option to simplify last-mile connectivity]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the general availability of <a href="https://docs.aws.amazon.com/interconnect/latest/userguide/what-is.html">AWS Interconnect – multicloud</a>, a managed private connectivity service that connects your <a href="https://aws.amazon.com/vpc/">Amazon Virtual Private Cloud (Amazon VPC)</a> directly to VPCs on other cloud providers. We’re also introducing <a href="https://aws.amazon.com/interconnect/lastmile/">AWS Interconnect – last mile</a>, a new capability that simplifies how you establish high-speed, private connections to AWS from your branch offices, data centers, and remote locations through your existing network providers.</p><p>Large enterprises increasingly run workloads across multiple cloud providers, whether to use specialized services, meet data residency requirements, or support teams that have standardized on different providers. Connecting those environments reliably and securely has historically required significant coordination: managing VPN tunnels, working with colocation facilities, and configuring third-party network fabrics. The result is that your networking team spends time on undifferentiated heavy lifting instead of focusing on the applications that matter to your business.</p><p>AWS Interconnect is the answer to these challenges. It is a managed connectivity service that simplifies connectivity into AWS. Interconnect provides you the ability to establish private, high-speed network connections with dedicated bandwidth to and from AWS across hybrid and multicloud environments. You can configure resilient, end-to-end connectivity with ease in a few clicks through the AWS Console by selecting your location, partner, or cloud provider, preferred Region, and bandwidth requirements, removing the friction of discovering partners and the complexity of manual network configurations.</p><p>It comes with two capabilities: multicloud connectivity between AWS and other cloud providers, and last-mile connectivity between AWS and your private on-premises networks. Both capabilities are built on the same principle: a fully managed, turnkey experience that removes the infrastructure complexity from your team.</p><p><strong>AWS Interconnect – multicloud<br /></strong> AWS Interconnect – multicloud gives you a private, managed Layer 3 connection between your AWS environment and other cloud providers, starting with Google Cloud, Microsoft Azure and Oracle Cloud Infrastructure (OCI) coming later in 2026. Traffic flows entirely over the AWS global backbone and the partner cloud’s private network, so it never traverses the public internet. This means you get predictable latency, consistent throughput, and isolation from internet congestion without having to manage any physical infrastructure yourself.</p><p>Security is built in by default. Every connection uses <a href="https://1.ieee802.org/security/802-1ae/">IEEE 802.1AE MACsec</a> encryption on the physical links between AWS routers and the partner cloud provider’s routers at the interconnection facilities. You don’t need to configure these separately. Note that each cloud provider manages encryption independently on its own backbone, so you should review the encryption documentation for your specific deployment to verify it meets your compliance requirements. Resiliency is also built in: each connection spans multiple logical links distributed across at least two physical facilities, so a single device or building failure does not interrupt your connectivity.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/09/2026-03-09_15-35-14.png"><img class="aligncenter wp-image-103313" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/09/2026-03-09_15-35-14-1024x401.png" alt="AWS Interconnect - multicloud - architecture" width="600" height="235" /></a>For monitoring, AWS Interconnect – multicloud integrates with <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a>. You get a <a href="https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/nw-monitor-how-it-works.html">Network Synthetic Monitor</a> included with each connection to track round-trip latency and packet loss, and bandwidth utilization metrics to support capacity planning.</p><p><a href="https://github.com/aws/Interconnect">AWS has published the underlying specification on GitHub</a> under the Apache 2.0 license, providing any cloud service provider the opportunity to collaborate with AWS Interconnect – multicloud. To become an AWS Interconnect partner, cloud providers must implement the technical specification and meet AWS operational requirements, including resiliency standards, support commitments, and service level agreements.</p><p><strong>How it works<br /></strong> Provisioning a connection takes minutes. I create the connection from the AWS Direct Connect console. I start from the AWS Interconnect section and select Google Cloud as the provider. I select my source and destination regions. I specify bandwidth, and provide my Google Cloud project ID. AWS generates an activation key that I use on the Google Cloud side to complete the connection. Routes propagate automatically in both directions, and my workloads can start exchanging data shortly after.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/09/2026-03-09_15-37-35.png"><img class="aligncenter wp-image-103314" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/09/2026-03-09_15-37-35-1024x537.png" alt="AWS INterconnect - multicloud - provisionning" width="599" height="314" /></a>For this demo, I start with a single VPC and I connect it to a Google Cloud VPC. I use a Direct Connect Gateway. It’s the simplest path: one connection, one attachment, and my workloads on both sides can start talking to each other in minutes.</p><p><strong>Step 1: request an interconnect in the <a href="https://console.aws.amazon.com">AWS Management Console</a>.</strong></p><p>I navigate to <strong>AWS Direct Connect</strong>, <strong>AWS Interconnect</strong> and I select <strong>Create</strong>. I first choose the cloud provider I want to connect to. In this example, Google Cloud.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/10/2026-03-09_15-54-34.png"><img class="aligncenter size-full wp-image-103333" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/10/2026-03-09_15-54-34.png" alt="AWS interconnect - 1" width="997" height="521" /></a>Then, I choose the <strong>AWS Region</strong> (<code>eu-central-1</code>) and the <strong>Google Cloud Region</strong> (<code>europe-west3</code>).</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/10/2026-03-09_15-54-51.png"><img class="aligncenter size-large wp-image-103334" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/10/2026-03-09_15-54-51-1024x344.png" alt="AWS interconnect - 2" width="1024" height="344" /></a>On step 3, I enter <strong>Description</strong>,I choose the <strong>Bandwidth</strong>, the <strong>Direct Connect gateway</strong> to attach, and the ID of my <strong>Google Cloud project</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/10/2026-03-09_15-55-40.png"><img class="aligncenter size-large wp-image-103335" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/10/2026-03-09_15-55-40-1024x430.png" alt="AWS interconnect - 3" width="1024" height="430" /></a></p><p>After reviewing and confirming the request, the console gives me an activation key. I will use that key to validate the request on the Google cloud side.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/10/2026-03-09_15-55-57.png"><img class="aligncenter size-large wp-image-103336" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/10/2026-03-09_15-55-57-1024x536.png" alt="AWS interconnect - 4" width="1024" height="536" /></a></p><p><strong>Step 2: create the transport and VPC Peering resources on my Google Cloud Platform (GCP) account.</strong></p><p>Now that I have the activation key, I continue the process on the GCP side. At the time of this writing, no web-based console was available. I choose to use the GCP command line (CLI) instead. I take note of the CIDR range in the GCP VPC subnet in the <code>europe-west3</code> region. Then, I open a Terminal and type:</p><pre class="lang-sh">gcloud network-connectivity transports create aws-news-blog \
    --region=europe-west3  \
    --activation-key=${ACTIVATION_KEY} \
    --network=default \
    --advertised-routes=10.156.0.0/20
Create request issued for: [aws-news-blog]
...
peeringNetwork: projects/oxxxp-tp/global/networks/transport-9xxxf-vpc
...
state: PENDING_CONFIG
updateTime: '2026-03-19T09:30:51.103979219Z'
</pre><p>It takes a couple of minutes for the command to complete. Once the command returns, I create a peering between my GCP VPC and the new transport I just created. I can do that in the GCP console or with the <code>gcloud</code> command line. Because I was using the Terminal for the previous command, I continued with the command line:</p><pre class="lang-bash">gcloud compute networks peerings create aws-news-blog \
      --network=default \
      --peer-network=projects/oxxxp-tp/global/networks/transport-9xxxf-vpc \
      --import-custom-routes \
      --export-custom-routes
</pre><p>The network name is the name of my GCP VPC. The peer network is given in the output of the previous command.</p><p>Once completed, I can verify the peering in the GCP console.<br /><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_10-54-20.png"><img class="aligncenter size-large wp-image-103451" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_10-54-20-1024x173.png" alt="AWS Interconnect - Peering in the Google console" width="1024" height="173" /></a></p><p>In the AWS Interconnect console, I verify the status is <strong>available</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_10-51-24.png"><img class="aligncenter size-large wp-image-103452" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_10-51-24-1024x204.png" alt="AWS Interconnect available" width="1024" height="204" /></a>In the AWS Direct Connect console, under <strong>Direct Connect gateways</strong>, I see the attachment to the new interconnect.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_13-56-28.png"><img class="aligncenter size-large wp-image-103454" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_13-56-28-1024x406.png" alt="AWS INterconnect attachment" width="1024" height="406" /></a></p><p><strong>Step 3: associate the new gateway on the AWS side</strong></p><p>I select <strong>Gateway associations</strong> and <strong>Associate gateway</strong> to attach the Virtual Private Gateway (VGW) that I created before starting this demo (pay attention to use a VGW in the same AWS Region as the interconnect)</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_13-56-34.png"><img class="aligncenter size-large wp-image-103455" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_13-56-34-1024x411.png" alt="AWS Interconnect associate CGW" width="1024" height="411" /></a></p><p>You don’t need to configure the network routing on the GCP side. On AWS, there is a final step: add a route entry in your VPC <strong>Route tables</strong> to send all traffic to the GCP IP address range through the Virtual Gateway.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_14-11-03.png"><img class="aligncenter size-large wp-image-103456" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_14-11-03-1024x406.png" alt="VPC Route to the VGW" width="1024" height="406" /></a></p><p>Once the network setup is done. I start two compute instances, one on AWS and one on GCP.</p><p>On AWS, I verify the Security Group accepts ingress traffic on TCP:8080. I connect to the machine and I start a minimal web server:</p><pre class="lang-python">python3 -c \
"from http.server import HTTPServer, BaseHTTPRequestHandler 
class H(BaseHTTPRequestHandler):
   def do_GET(self):
      self.send_response(200);self.end_headers()
      self.wfile.write(b'Hello AWS World!\n\n')
HTTPServer(('',8080),H).serve_forever()"</pre><p>On the GCP side, I open a SSH session to the machine and I call the AWS web server by its private IP address.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_13-59-37.png"><img class="aligncenter size-large wp-image-103458" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/19/2026-03-19_13-59-37-1024x342.png" alt="AWS Interconnect : curl from GCP to AWS" width="1024" height="342" /></a></p><p>Et voilà! I have a private network route between my two networks, entirely managed by the two Cloud Service Providers.</p><p><strong>Things to know<br /></strong> There are a couple of configuration options that you should keep in mind:</p><ul><li>When connecting networks, pay attention to the IP addresses range on both sides. The GCP and AWS VPC ranges can’t overlap. For this demo, the default range on AWS was <code>172.31.0.0/16</code>and the default on GCP was <code>10.156.0.0/20</code>. I was able to proceed with these default values.</li>
<li>You can configure IPV4, IPV6, or both on each side. You must select the same option on both sides.</li>
<li>The Maximum Transmission Unit (MTU) must be the same on both VPC. The default values for AWS VPCs and GCP VPCs are not. MTU is the largest packet size, in bytes, that a network interface can transmit without fragmentation. Mismatched MTU sizes between peered VPCs cause packet drops or fragmentation, leading to silent data loss, degraded throughput, and broken connections across the interconnect.</li>
<li>For more details, refer to the <a href="https://docs.cloud.google.com/network-connectivity/docs/interconnect/concepts/partner-cci-for-aws-overview">GCP Partner Cross Cloud Interconnect</a> and the <a href="https://docs.aws.amazon.com/interconnect/latest/userguide/what-is.html">AWS Interconnect User Guide</a>.</li>
</ul><p><strong>Reference architectures<br /></strong> When your deployment grows and you have multiple VPCs in a single region, AWS Transit Gateway gives you a centralized routing hub to connect them all through a single Interconnect attachment. You can segment traffic between environments, apply consistent routing policies, and integrate AWS Network Firewall if you need to inspect what crosses the cloud boundary.</p><p>And when you’re operating at global scale, with workloads spread across multiple AWS Regions and multiple Google Cloud environments, AWS Cloud WAN extends that same model across the world. Any region in your network can reach any Interconnect attachment globally, with centralized policy management and segment-based routing that applies consistently everywhere you operate.</p><p>My colleagues Alexandra and Santiago documented these reference architectures in their blog post: <a href="https://aws.amazon.com/blogs/networking-and-content-delivery/build-resilient-and-scalable-multicloud-connectivity-architectures-with-aws-interconnect-multicloud/"><strong>Build resilient and scalable multicloud connectivity architectures with AWS Interconnect – multicloud</strong></a>.</p><p><strong>AWS Interconnect – last mile<br /></strong> Based on the same architecture and design as AWS Interconnect – multicloud, AWS Interconnect – last mile provides the ability to connect your on-premises or remote location to AWS through a participating network provider’s last-mile infrastructure, directly from the <a href="https://console.aws.amazon.com">AWS Management Console</a>.</p><p>The onboarding process mirrors AWS Interconnect – multicloud: you select a provider, authenticate, and specify your connection endpoints and bandwidth. AWS generates an activation key that you provide in the provider console to complete the configuration. AWS Interconnect – last mile automatically provisions four redundant connections across two physical locations, configures BGP routing, and activates MACsec encryption and Jumbo Frames by default. The result is a resilient private connection to AWS that aligns with best practices, without requiring you to manually configure networking components.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/13/lastmile-console-v2.png"><img class="aligncenter size-full wp-image-103671" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/13/lastmile-console-v2.png" alt="AWS Interconnect - lastmile" width="793" height="431" /></a></p><p>AWS Interconnect – last mile supports bandwidths from 1 Gbps to 100 Gbps, and you can adjust bandwidth from the console without reprovisioning. The service includes a 99.99% availability SLA up to the Direct Connect port and bundles CloudWatch Network Synthetic Monitor for connection health monitoring. Just like AWS Interconnect – multicloud, AWS Interconnect – last mile attaches to a Direct Connect Gateway, which connects to your Virtual Private Gateway, Transit Gateway, or AWS Cloud WAN deployment. For more details, refer to the <a href="https://docs.aws.amazon.com/directconnect/latest/UserGuide/Welcome.html">AWS Interconnect User Guide</a>.</p><p>Scott Yow, SVP Product at Lumen Technologies, wrote:</p><blockquote class="c6">
<p>By combining AWS Interconnect – last mile with Lumen fiber network and Cloud Interconnect, we simplify the last-mile complexity that often slows cloud adoption and enable a faster, and more resilient path to AWS for customers.</p>
</blockquote><p><strong>Pricing and availability<br /></strong> AWS Interconnect – multicloud and AWS Interconnect – last mile pricing is based on a flat hourly rate for the capacity you request, billed prorata by the hour. You select the bandwidth tier that fits your workload needs.</p><p>AWS Interconnect – multicloud pricing varies by region pair: a connection between US East (N. Virginia) and Google Cloud N. Virginia is priced differently from a connection between US East (N. Virginia) and a more distant region. When you use AWS Cloud WAN, the global any-to-any routing model means traffic can traverse multiple regions, which affects the total cost of your deployment. I recommend reviewing <a href="https://aws.amazon.com/interconnect/multicloud/pricing/" target="_blank" rel="noopener noreferrer">the AWS Interconnect – multicloud pricing page</a> and <a href="https://aws.amazon.com/interconnect/lastmile/pricing/" target="_blank" rel="noopener noreferrer">AWS Interconnect – last mile pricing page</a> for the full rate card by region pair and capacity tier before sizing your connection.</p><p>AWS Interconnect – multicloud is available today in five region pairs: US East (N. Virginia) to Google Cloud N. Virginia, US West (N. California) to Google Cloud Los Angeles, US West (Oregon) to Google Cloud Oregon, Europe (London) to Google Cloud London, and Europe (Frankfurt) to Google Cloud Frankfurt. Microsoft Azure support is coming later in 2026.</p><p>AWS Interconnect – last mile is launching in US East (N. Virginia) with Lumen as the initial partner. Additional partners, including AT&amp;T and Megaport, are in progress, and additional regions are planned.</p><p>To get started with AWS Interconnect, visit the <a href="https://console.aws.amazon.com/directconnect/v2/home#/aws-interconnect">AWS Direct Connect console</a> and select AWS Interconnect from the navigation menu.</p><p>I’d love to hear how you’re using AWS Interconnect in your environment. Leave a comment below or reach out through the <a href="https://repost.aws/questions">AWS re:Post community</a>.</p><a href="https://linktr.ee/sebsto">— seb</a><p><strong>Updated on April 15</strong> – Updated wrong link for pricing pages. Oracle Cloud Infrastructure (OCI) added to list of coming providers.</p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="cc9786f4-c0df-435a-8971-1e13b81dfd1b" data-title="AWS Interconnect is now generally available, with a new option to simplify last-mile connectivity" data-url="https://aws.amazon.com/blogs/aws/aws-interconnect-is-now-generally-available-with-a-new-option-to-simplify-last-mile-connectivity/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-interconnect-is-now-generally-available-with-a-new-option-to-simplify-last-mile-connectivity/"/>
    <updated>2026-04-15T01:54:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-mythos-preview-in-amazon-bedrock-aws-agent-registry-and-more-april-13-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Claude Mythos Preview in Amazon Bedrock, AWS Agent Registry, and more (April 13, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>In my last <a href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-openai-partnership-aws-elemental-inference-strands-labs-and-more-march-2-2026/">Week in Review post</a>, I mentioned how much time I’ve been spending on <a href="https://aws.amazon.com/blogs/devops/ai-driven-development-life-cycle/">AI-Driven Development Lifecycle (AI-DLC)</a> workshops with customers this year. A common theme in those sessions is the need for better cost visibility. Teams are moving fast with AI, but as they go from experimenting to full production, finance and leadership really need to know who is using which resources and at what cost. That’s why I was so excited to see the launch of <a href="https://aws.amazon.com/about-aws/whats-new/2026/04/bedrock-iam-cost-allocation/">Amazon Bedrock new support for cost allocation by IAM user and role</a> this week. This lets you tag IAM principals with attributes like team or cost center and then activate those tags in your Billing and Cost Management console. The resulting cost data flows into AWS Cost Explorer and the detailed Cost and Usage Report, giving you a clear line of sight into model inference spending. Whether you’re scaling agents across teams, tracking foundation model use by department, or running tools like <a href="https://aws.amazon.com/solutions/guidance/claude-code-with-amazon-bedrock/">Claude Code on Amazon Bedrock</a>, this new feature is a game changer for tracking and managing your AI investments. You can get all the details on setting this up in the <a href="https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/iam-principal-cost-allocation.html">IAM principal cost allocation documentation</a>.</p><p>Now, let’s get into this week’s AWS news…</p><p><strong>Headlines<br /></strong> <strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-bedrock-claude-mythos/">Amazon Bedrock now offers Claude Mythos Preview</a></strong> Anthropic’s most sophisticated AI model to date is now available on Amazon Bedrock as a gated research preview through Project Glasswing. Claude Mythos introduces a new model class focused on cybersecurity, capable of identifying sophisticated security vulnerabilities in software, analyzing large codebases, and delivering state of the art performance across cybersecurity, coding, and complex reasoning tasks. Security teams can use it to discover and address vulnerabilities in critical software before threats emerge. Access is currently limited to allowlisted organizations, with Anthropic and AWS prioritizing internet critical companies and open source maintainers.</p><p><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/aws-agent-registry-in-agentcore-preview/">AWS Agent Registry for centralized agent discovery and governance now in preview</a></strong> AWS launched Agent Registry through Amazon Bedrock AgentCore, providing organizations with a private catalog for discovering and managing AI agents, tools, skills, MCP servers, and custom resources. The registry helps teams locate existing capabilities rather than duplicating them, with semantic and keyword search, approval workflows, and CloudTrail audit trails. It is accessible via the AgentCore Console, AWS CLI, SDK, and as an MCP server queryable from IDEs.</p><p><strong>Last week’s launches<br /></strong> Here are some launches and updates from this past week that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-s3-files/"><strong>Announcing Amazon S3 Files, making S3 buckets accessible as file systems</strong></a> — Amazon S3 Files transforms S3 buckets into shared file systems that connect any AWS compute resource directly with your S3 data. Built on Amazon EFS technology, it delivers full file system semantics with low latency performance, caching actively used data and providing multiple terabytes per second of aggregate read throughput. Applications can access S3 data through both file system and S3 APIs simultaneously without code modifications or data migration.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/opensearch-managed-prometheus-agent-tracing/"><strong>Amazon OpenSearch Service supports Managed Prometheus and agent tracing</strong></a> —Amazon OpenSearch Service now provides a unified observability platform that consolidates metrics, logs, traces, and AI agent tracing into a single interface. The update includes native Prometheus integration with direct PromQL query support, RED metrics monitoring, and OpenTelemetry GenAI semantic convention support for LLM execution visibility. Operations teams can correlate slow traces to logs and overlay Prometheus metrics on dashboards without switching between tools.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/workspaces-advisor-ai-troubleshooting/"><strong>Amazon WorkSpaces Advisor now available for AI powered troubleshooting</strong></a>— AWS launched Amazon WorkSpaces Advisor, an AI powered administrative tool that uses generative AI to help IT administrators troubleshoot Amazon WorkSpaces Personal deployments. It analyzes WorkSpace configurations, detects problems automatically, and provides actionable recommendations to restore service and optimize performance.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-braket-rigetti-cepheus/"><strong>Amazon Braket adds support for Rigetti’s 108 qubit Cepheus QPU</strong></a> — Amazon Braket now offers access to Rigetti’s Cepheus-1-108Q device, the first 100+ qubit superconducting quantum processor on the platform. The modular design features twelve 9 qubit chiplets with CZ gates that offer enhanced resilience to phase errors. It supports multiple frameworks including Braket SDK, Qiskit, CUDA-Q, and Pennylane, with pulse level control for researchers.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong>Other AWS news<br /></strong> Here are some additional posts and resources that you might find interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/storage/building-automated-aws-regional-availability-checks-with-amazon-s3/"><strong>Building automated AWS Regional availability checks with Amazon S3</strong></a>— Storage blog post on implementing automated systems for monitoring service availability across AWS regions using Amazon S3 as core infrastructure.</li>
<li><a href="https://aws.amazon.com/blogs/machine-learning/understanding-amazon-bedrock-model-lifecycle/"><strong>Understanding Amazon Bedrock model lifecycle</strong></a> — Machine learning blog post that walks through the stages foundation models go through in Bedrock from availability through deprecation, helping teams plan for model updates and manage version dependencies in production.</li>
<li><a href="https://aws.amazon.com/blogs/compute/building-memory-intensive-apps-with-aws-lambda-managed-instances/"><strong>Building memory intensive apps with AWS Lambda managed instances</strong></a> — Compute blog post exploring how Lambda managed instances extend the platform beyond lightweight workloads to support memory intensive applications while maintaining serverless benefits.</li>
<li><a href="https://builder.aws.com/content/38mhAVkwQuKrVJdfAwLImOok2UL/deploy-openclaw-on-aws-choose-the-right-options-for-your-ai-workload"><strong>Deploy OpenClaw on AWS: Choose the right options for your AI workload</strong></a> — Builder Center guide comparing four AWS deployment options for OpenClaw: Amazon Lightsail for individual developers, Amazon EC2 for startups needing deeper AWS integration, Amazon Bedrock AgentCore for serverless multiuser scenarios, and Amazon EKS for enterprises requiring VM level isolation and advanced orchestration.</li>
<li><a href="https://kiro.dev/blog/bringing-back-startup-credits/"><strong>We’re bringing back the Kiro startup credits program</strong></a> — Kiro is relaunching its startup credits initiative, offering eligible early stage companies complimentary access to Kiro Pro+ for up to one year. The three tier program (Starter, Growth, Scale) provides 2 to 30 users based on team size, with rolling applications accepted globally.</li>
</ul><p><strong>Upcoming AWS events<br /></strong> Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/whats-next-with-aws/"><strong>What’s Next with AWS</strong></a> <strong>(April 28, Virtual)</strong> Join this livestream at 9am PT for a candid discussion about how agentic AI is transforming how businesses operate. Featuring AWS CEO Matt Garman, SVP Colleen Aubrey, and OpenAI leaders discussing emerging agent capabilities, Amazon’s internal experiences, and new agentic solutions and platform capabilities.</li>
</ul><p>Browse here for upcoming <a href="https://aws.amazon.com/events/">AWS led in person and virtual events</a>, <a href="https://aws.amazon.com/startups/events">startup events</a>, and <a href="https://builder.aws.com/connect/events">developer focused events</a>.</p><hr /><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/">Weekly Roundup</a>!</p><p>~ micah</p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="1b67edca-1e8c-4cc0-b8f6-89b7c169f655" data-title="AWS Weekly Roundup: Claude Mythos Preview in Amazon Bedrock, AWS Agent Registry, and more (April 13, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-mythos-preview-in-amazon-bedrock-aws-agent-registry-and-more-april-13-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-mythos-preview-in-amazon-bedrock-aws-agent-registry-and-more-april-13-2026/"/>
    <updated>2026-04-13T18:16:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/launching-s3-files-making-s3-buckets-accessible-as-file-systems/</id>
    <title><![CDATA[Launching S3 Files, making S3 buckets accessible as file systems]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>I’m excited to announce <a href="https://aws.amazon.com/s3/features/files/">Amazon S3 Files</a>, a new file system that seamlessly connects any AWS compute resource with <a href="https://aws.amazon.com/s3/">Amazon Simple Storage Service (Amazon S3)</a>.</p><p>More than a decade ago, as an AWS trainer, I spent countless hours explaining the fundamental differences between object storage and file systems. My favorite analogy was comparing S3 objects to books in a library (you can’t edit a page, you need to replace the whole book) versus files on your computer that you can modify page by page. I drew diagrams, created metaphors, and helped customers understand why they needed different storage types for different workloads. Well, today that distinction becomes a bit more flexible.</p><p>With S3 Files, Amazon S3 is the first and only cloud object store that offers fully-featured, high-performance file system access to your data. It makes your buckets accessible as file systems. This means changes to data on the file system are automatically reflected in the S3 bucket and you have fine-grained control over synchronization. S3 Files can be attached to multiple compute resources enabling data sharing across clusters without duplication.</p><p>Until now, you had to choose between Amazon S3 cost, durability, and the services that can natively consume data from it or a file system’s interactive capabilities. S3 Files eliminates that tradeoff. S3 becomes the central hub for all your organization’s data. It’s accessible directly from any AWS compute instance, container, or function, whether you’re running production applications, training ML models, or building agentic AI systems.</p><p>You can access any general purpose bucket as a native file system on your <a href="https://aws.amazon.com/ec2/">Amazon Elastic Compute Cloud (Amazon EC2)</a> instances, containers running on <a href="https://aws.amazon.com/ecs/">Amazon Elastic Container Service (Amazon ECS)</a> or <a href="https://aws.amazon.com/eks/">Amazon Elastic Kubernetes Service (Amazon EKS)</a>, or <a href="https://aws.amazon.com/lambda/">AWS Lambda</a> functions. The file system presents S3 objects as files and directories, supporting all <a href="https://en.wikipedia.org/wiki/Network_File_System">Network File System</a> (NFS) v4.1+ operations like creating, reading, updating, and deleting files.</p><p>As you work with specific files and directories through the file system, associated file metadata and contents are placed onto the file system’s high-performance storage. By default, files that benefit from low-latency access are stored and served from the high performance storage. For files not stored on high performance storage such as those needing large sequential reads, S3 Files automatically serves those files directly from Amazon S3 to maximize throughput. For byte-range reads, only the requested bytes are transferred, minimizing data movement and costs.</p><p>The system also supports intelligent pre-fetching to anticipate your data access needs. You also have fine-grained control over what gets stored on the file system’s high performance storage. You can decide whether to load full file data or metadata only, which means you can optimize for your specific access patterns.</p><p>Under the hood, S3 Files uses <a href="https://aws.amazon.com/efs">Amazon Elastic File System (Amazon EFS)</a> and delivers ~1ms latencies for active data. The file system supports concurrent access from multiple compute resources with NFS close-to-open consistency, making it ideal for interactive, shared workloads that mutate data, from agentic AI agents collaborating through file-based tools to ML training pipelines processing datasets.</p><p><strong>Let me show you how to get started.<br /></strong> Creating my first Amazon S3 file system, mounting, and using it from an EC2 instance is straightforward.</p><p>I have an EC2 instance and a general purpose bucket. In this demo, I configure an S3 file system and access the bucket from an EC2 instance, using regular file system commands.</p><p>For this demo, I use the <a href="https://console.aws.amazon.com">AWS Management Console</a>. You can also use the <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a> or <a href="https://aws.amazon.com/what-is/iac/">infrastructure as code</a> (IaC).</p><p>Here is the architecture diagram for this demo.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/06/diagram.png"><img class="aligncenter size-large wp-image-103634" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/06/diagram-1024x596.png" alt="S3 Files demo architecture" width="1024" height="596" /></a><strong>Step 1:</strong> Create an S3 file system.</p><p>On the Amazon S3 section of the console, I choose <strong>File systems</strong> and then <strong>Create file system</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/02/2026-04-02_09-42-08.png"><img class="aligncenter size-large wp-image-103599" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/02/2026-04-02_09-42-08-1024x581.png" alt="S3 Files create file system" width="1024" height="581" /></a></p><p>I enter the name of the bucket I want to expose as a file system and choose <strong>Create file system</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/02/2026-04-02_09-45-04.png"><img class="aligncenter size-large wp-image-103600" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/02/2026-04-02_09-45-04-1024x526.png" alt="S3 Files create file system, part 2" width="1024" height="526" /></a></p><p><strong>Step 2:</strong> Discover the mount target.</p><p>A mount target is a network endpoint that will live in my virtual private cloud (VPC). It allows my EC2 instance to access the S3 file system.</p><p>The console creates the mount targets automatically. I take notes of the <strong>Mount target ID</strong>s on the <strong>Mount targets</strong> tab.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/02/2026-04-02_09-54-16.png"><img class="aligncenter size-large wp-image-103601" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/02/2026-04-02_09-54-16-1024x581.png" alt="" width="1024" height="581" /></a></p><p>When using the <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-files-getting-started.html#s3-files-getting-started-cli">CLI</a>, two separate commands are necessary to create the file system and its mount targets. First, I create the S3 file system with <code>create-file-system</code>. Then, I create the mount target with <code>create-mount target.</code></p><p><strong>Step 3:</strong> Mount the file system on my EC2 instance.</p><p>After it’s connected to an EC2 instance, I type:</p><p><code>sudo mkdir /home/ec2-user/s3files</code> <code>sudo mount -t s3files fs-0aa860d05df9afdfe:/ /home/ec2-user/s3files</code></p><p>I can now work with my S3 data directly through the mounted file system in <code>~/s3files</code>, using standard file operations.</p><p>When I make updates to my files in the file system, S3 automatically manages and exports all updates as a new object or a new version on an existing object back in my S3 bucket within minutes.</p><p>Changes made to objects on the S3 bucket are visible in the file system within a few seconds but can sometimes take a minute or longer.</p><pre class="lang-bash"># Create a file on the EC2 file system 
echo "Hello S3 Files" &gt; s3files/hello.txt 
# and verify it's here 
ls -al s3files/hello.txt
 -rw-r--r--. 1 ec2-user ec2-user 15 Oct 22 13:03 s3files/hello.txt 
# See? the file is also on S3 
aws s3 ls s3://s3files-aws-news-blog/hello.txt 
2025-10-22 13:04:04 15 hello.txt 
# And the content is identical! 
aws s3 cp s3://s3files-aws-news-blog/hello.txt . &amp;&amp; cat hello.txt
Hello S3 Files</pre><p><strong>Things to know<br /></strong> Let me share some important technical details that I think you’ll find useful.</p><ul><li>S3 Files integrates with <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (IAM)</a> for access control and encryption. You can use <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-files-getting-started.html">identity and resource policies to manage permissions at both the file system and object level</a>.</li>
<li>Data is always encrypted in transit using TLS 1.3 and at rest using Amazon S3 managed keys (SSE-S3) or customer-managed keys with <a href="https://aws.amazon.com/kms/">AWS Key Management Service (AWS KMS)</a>.</li>
<li>S3 Files uses POSIX permissions for files and directories, checking user ID (UID) and group ID (GID) against file permissions stored as object metadata in the S3 bucket.</li>
<li>Monitor S3 Files using <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a> metrics for drive performance and updates and <a href="https://aws.amazon.com/cloudtrail/">AWS CloudTrail</a> for logging management events.</li>
<li>Verify that the latest version of the EFS driver (<a href="https://github.com/aws/efs-utils">amazon-efs-utils package</a>) is installed on your EC2 instances. This package is preinstalled on the <a href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AMIs.html">Amazon Machine Image (AMI)</a> provided by AWS. At the time of writing, you can update it to the latest version.</li>
<li>In this post, I showed you how to use S3 Files from an EC2 instance. You can also mount your S3 bucket as a file system from your ECS or EKS containers, on <a href="https://aws.amazon.com/fargate/">AWS Fargate</a> or not, and from your Lambda functions.</li>
</ul><p>Another question I frequently hear in customer conversations is about choosing the right file service for your workloads. Yes, I know what you’re thinking: AWS and its seemingly overlapping services, keeping cloud architects entertained during their architecture review meetings. Let me help demystify this one.</p><p>S3 Files works best when you need interactive, shared access to data that lives in Amazon S3 through a high performance file system interface. It’s ideal for workloads where multiple compute resources—whether production applications, agentic AI agents using Python libraries and CLI tools, or machine learning (ML) training pipelines—need to read, write, and mutate data collaboratively. You get shared access across compute clusters without data duplication, sub-millisecond latency, and automatic synchronization with your S3 bucket.</p><p>For workloads migrating from on-premises NAS environments, <a href="https://aws.amazon.com/fsx/">Amazon FSx</a> provides the familiar features and compatibility you need. Amazon FSx is also ideal for high-performance computing (HPC) and GPU cluster storage with <a href="https://docs.aws.amazon.com/fsx/latest/LustreGuide/what-is.html">Amazon FSx for Lustre</a>. It’s particularly valuable when your applications require specific file system capabilities from <a href="https://docs.aws.amazon.com/fsx/latest/ONTAPGuide/what-is-fsx-ontap.html">Amazon FSx for NetApp ONTAP</a>, <a href="https://docs.aws.amazon.com/fsx/latest/OpenZFSGuide/what-is-fsx.html">Amazon FSx for OpenZFS</a>, or <a href="https://docs.aws.amazon.com/fsx/latest/WindowsGuide/what-is.html">Amazon FSx for Windows File Server</a>.</p><p><strong>Pricing and availability<br /></strong> S3 Files is available today in all commercial <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region">AWS Regions</a>.</p><p class="jss273" data-pm-slice="1 1 []">You pay for the portion of data stored in your S3 file system, for small file read and all write operations to the file system, and for S3 requests during data synchronization between the file system and the S3 bucket. <a href="https://aws.amazon.com/s3/pricing/">The Amazon S3 pricing page has all the details</a>.</p><p>From discussions with customers, I believe S3 Files helps simplify cloud architectures by eliminating data silos, synchronization complexity, and manual data movement between objects and files. Whether you’re running production tools that already work with file systems, building agentic AI systems that rely on file-based Python libraries and shell scripts, or preparing datasets for ML training, S3 Files lets these interactive, shared, hierarchical workloads access S3 data directly without choosing between the durability of Amazon S3 and cost benefits and a file system’s interactive capabilities. You can now use Amazon S3 as the place for all your organizations’ data, knowing the data is accessible directly from any AWS compute instance, container, and function.</p><p>To learn more and get started, visit the <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-files.html">S3 Files documentation</a>.</p><p>I’d love to hear how you use this new capability. Feel free to share your feedback in the comments below.</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="b8643ec0-d098-46a0-ac3e-2e3d2e8b8f40" data-title="Launching S3 Files, making S3 buckets accessible as file systems" data-url="https://aws.amazon.com/blogs/aws/launching-s3-files-making-s3-buckets-accessible-as-file-systems/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/launching-s3-files-making-s3-buckets-accessible-as-file-systems/"/>
    <updated>2026-04-07T21:18:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-devops-agent-security-agent-ga-product-lifecycle-updates-and-more-april-6-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: AWS DevOps Agent & Security Agent GA, Product Lifecycle updates, and more (April 6, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Last week, I visited <a href="https://awsug.hk/">AWS Hong Kong User Group</a> with my team. Hong Kong has a small but strong community, and their energy and passion are high. They recently started a new AI user group, and we hope more people will join. I was able to strengthen my bond with the community through great food and conversation.</p><p><img class="aligncenter wp-image-103619 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/03/2026-aws-hongkong-usergroup.jpeg" alt="" width="1400" height="481" /></p><p>This week, I”ll first take a closer look at some of the key launches.</p><p><strong>AWS DevOps Agent and Security Agent GA</strong><br /><img class="size-full wp-image-103611 alignright c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/03/1774975872883.jpg" alt="" width="950" height="741" />At the last re:Invent, we introduced the <a href="https://aws.amazon.com/ai/frontier-agents/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">concept of frontier agents</a> that work autonomously across multiple steps to achieve outcomes, operating continuously until the job is done. The first two—<a href="https://aws.amazon.com/blogs/machine-learning/aws-launches-frontier-agents-for-security-testing-and-cloud-operations/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS DevOps Agent and AWS Security Agent—are now generally available</a> after the preview.</p><p><a href="https://aws.amazon.com/devops-agent/">AWS DevOps Agent</a> helps you run cloud operations—investigating incidents, reducing time to resolution, and preventing issues before they happen. Customers like United Airlines, Western Governors University, and T-Mobile are already using DevOps Agent to accelerate incident response and simplify operations at scale. At WGU, resolution time dropped from hours to minutes, and in preview customers report up to 75% lower MTTR and 3 to 5 times faster resolution. Learn more in <a href="https://aws.amazon.com/blogs/aws/aws-devops-agent-helps-you-accelerate-incident-response-and-improve-system-reliability-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Sébastien’s preview blog post</a> and <a href="https://aws.amazon.com/blogs/mt/announcing-general-availability-of-aws-devops-agent/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener">GA announcement</a>.</p><p><a href="https://aws.amazon.com/security-agent/">AWS Security Agent</a> brings continuous, context-aware penetration testing into the development lifecycle. This agent operates like a human penetration tester. Customers including LG CNS, HENNGE, and Wayspring are seeing strong results. At LG CNS, teams estimate over 50% faster testing and ~30% lower costs, along with significantly fewer false positives. Learn more in <a href="https://aws.amazon.com/blogs/aws/new-aws-security-agent-secures-applications-proactively-from-design-to-deployment-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Esra’s preview blog post</a> and <a href="https://aws.amazon.com/blogs/security/aws-security-agent-on-demand-penetration-testing-now-generally-available/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener">GA announcement</a>.</p><p>Both are designed to work across AWS cloud, multicloud, and on-prem environments. You can have an always-available teammate that can handle the heavy lifting, so you can focus on what matters most.</p><p><strong>AWS Service Availability Updates</strong><br />When the availability of an AWS service or feature changes, we provide customers guidance in <a href="https://docs.aws.amazon.com/general/latest/gr/service-lifecycle.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Product Lifecycle Changes</a> on available alternatives and support for migration so that disruptions to your operations are minimized. The following lifecycle changes were updated on March 31, 2026.</p><ul><li>Availability change guide for services in maintenance
</li>
<li>Availability change guide for services in sunset:
</li>
<li>Services reaching in sunset:
<ul><li>Amazon Chime SDK – Proxy Sessions</li>
</ul></li>
</ul><p>We understand that changes in availability can impact your operations. For specific guidance, consult the relevant service documentation or contact AWS Support.</p><p><strong>Last week’s launches</strong><br />Here are last week’s launches that caught my attention:</p><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">What’s New with AWS</a> page.</p><p><strong>Additional updates</strong><br />Here are some additional news items that you might find interesting:</p><p>For a full list of AWS blog posts, be sure to keep an eye on the <a href="https://aws.amazon.com/blogs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Blogs</a> page.</p><p>Learn more about AWS, browse and join upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?tab=upcoming?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused events</a> as well as <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summits</a> and <a href="https://aws.amazon.com/events/community-day/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Community Days</a>. Join the <a href="https://builder.aws.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development.</p><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Weekly Roundup</a>!</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="f9c981e1-506c-4dc2-9849-9f70089e0072" data-title="AWS Weekly Roundup: AWS DevOps Agent &amp; Security Agent GA, Product Lifecycle updates, and more (April 6, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-devops-agent-security-agent-ga-product-lifecycle-updates-and-more-april-6-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-devops-agent-security-agent-ga-product-lifecycle-updates-and-more-april-6-2026/"/>
    <updated>2026-04-06T18:51:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-bedrock-guardrails-supports-cross-account-safeguards-with-centralized-control-and-management/</id>
    <title><![CDATA[Amazon Bedrock Guardrails supports cross-account safeguards with centralized control and management]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the general availability of cross-account safeguards in <a href="https://aws.amazon.com/bedrock/guardrails/">Amazon Bedrock Guardrails</a>, a new capability that enables centralized enforcement and management of safety controls across multiple AWS accounts within an organization.</p><p>With this new capability, you can specify a guardrail in a new <a href="https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_bedrock.html">Amazon Bedrock policy</a> within the management account of your organization that automatically enforces configured safeguards across all member entities for every model invocation with Amazon Bedrock. This organization-wide implementation supports uniform protection across all accounts and generative AI applications with centralized control and management. This capability also offers flexibility to apply account-level and application-specific controls depending on use case requirements in addition to organizational safeguards.</p><ul><li><strong>Organization-level enforcements</strong> apply a single guardrail from your organization’s management account to all entities within the organization through policy settings. This guardrail automatically enforces filters across all member entities, including organizational units (OUs) and individual accounts, for all Amazon Bedrock model invocations.</li>
<li><strong>Account-level enforcement</strong> enables automatic enforcement of configured safeguards across all Amazon Bedrock model invocations in your AWS account. The configured safeguards in the account-level guardrail apply to all inference API calls.</li>
</ul><p>You can now establish and centrally manage dependable, comprehensive protection through a single, unified approach. This supports consistent adherence to corporate <a href="https://aws.amazon.com/ai/responsible-ai/">responsible AI</a> requirements while significantly reducing the administrative burden of monitoring individual accounts and applications. Your security team no longer needs to oversee and verify configurations or compliance for each account independently.</p><p><strong class="c6">Getting started with centralized enforcement in Amazon Bedrock Guardrails</strong><br />You can get started with account-level and organization-level enforcement configuration in the <a href="https://console.aws.amazon.com/bedrock/home?#/guardrails">Amazon Bedrock Guardrails console</a>. Before the enforcement configuration, you need to create a guardrail with a particular version to support the guardrail configuration remains immutable and cannot be modified by member accounts and complete <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-prereq.html">prerequisites</a> for using the new capability such as <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-resource-based-policies.html">resource-based policies for guardrails</a>.</p><p>To enable account-level enforcement, choose <strong>Create</strong> in the section of <strong>Account-level enforcement configurations</strong>.</p><p><img class="aligncenter wp-image-103607 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/03/2026-bedrock-guardrails-enforcement-1-overview-1.jpg" alt="" width="1800" height="1640" /></p><p>You can choose the guardrail and version to automatically apply to all Bedrock inference calls from this account in this Region. With general availability, we introduce the new feature defining which models will be affected by the enforcement with either <strong>Include</strong> or <strong>Exclude</strong> behavior.</p><p>You can also configure selective content guarding controls for system prompts and user prompts with either <strong>Comprehensive</strong> or <strong>Selective</strong>.</p><ul><li>Use <strong>Comprehensive</strong> when you want to enforce guardrails on everything, regardless of what the caller tags. This is the safer default when you don’t want to rely on callers to correctly identify sensitive content.</li>
<li>Use <strong>Selective</strong> when you trust callers to tag the right content and want to reduce unnecessary guardrail processing. This is useful when callers handle a mix of pre-validated and user-generated content, and only need guardrails applied to specific portions.</li>
</ul><p><img class="aligncenter wp-image-103593 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/02/2026-bedrock-guardrails-enforcement-2-account-create.jpg" alt="" width="1800" height="1581" /></p><p>After creating the enforcement, you can test and verify enforcement using a role in your account. The account-enforced guardrail should automatically apply to both prompts and outputs.</p><p>Check the response for guardrail assessment information. The guardrail response will include enforced guardrail information. You can also test by making a Bedrock inference call using <code>InvokeModel</code>, <code>InvokeModelWithResponseStream</code>, <code>Converse</code>, or <code>ConverseStream</code> APIs.</p><p><img class="aligncenter wp-image-102970 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/11/2026-bedrock-guardrails-enforcement-2-account-testing.jpg" alt="" width="2426" height="1262" /></p><p>To enable organization-level enforcement, go to <a href="https://console.aws.amazon.com/organizations/">AWS Organizations console</a> and choose <strong>Policies</strong> menu. You can enable the <strong>Bedrock policies</strong> in the console.</p><p><img class="aligncenter size-full wp-image-102971 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/11/2026-bedrock-guardrails-enforcement-3-org-policies.jpg" alt="" width="2252" height="1044" /></p><p>You can create a Bedrock policy that specifies your guardrail and attach it to your target accounts or OUs. Choose <strong>Bedrock policies</strong> enabled and <strong>Create policy</strong>. Specify your guardrail ARN and version and configure the input tags setting for in the AWS Organizations. To learn more, visit <a href="https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_bedrock.html">Amazon Bedrock policies in AWS Organizations</a> and <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-enforcements.html">Amazon Bedrock policy syntax and examples</a>.</p><p><img class="aligncenter wp-image-103594 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/02/2026-bedrock-guardrails-enforcement-3-org-policies-create.jpg" alt="" width="1800" height="1707" /></p><p>After creating the policy, you can attach the policy to your desired organizational units, accounts, root in the <strong>Targets</strong> tab.</p><p><img class="aligncenter size-full wp-image-102973 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/11/2026-bedrock-guardrails-enforcement-3-org-target.jpg" alt="" width="2392" height="1316" /></p><p>Search and select your organization root, OUs, or individual accounts to attach your policy, and choose <strong>Attach policy</strong>.</p><p><img class="aligncenter wp-image-103608 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/03/2026-bedrock-guardrails-enforcement-3-org-target-attach.jpg" alt="" width="2156" height="1084" /></p><p>You can test that the guardrail is being enforced on member accounts and verify which guardrail is enforced. From a member account attached, you should see the organization enforced guardrail under the section Organization-level enforcement configurations.</p><p><img class="aligncenter wp-image-103595 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/04/02/2026-bedrock-guardrails-enforcement-4-list.jpeg" alt="" width="1800" height="1136" /></p><p>The underlying safeguards within the specified guardrail are then automatically enforced for every model inference request across all member entities, ensuring consistent safety controls. To accommodate varying requirements of individual teams or applications, you can attach different policies with associated guardrails to different member entities through your organization.</p><p><strong class="c6">Things to know</strong><br />Here are key considerations to know about GA features:</p><ul><li>You can now choose to include or exclude specific models in Bedrock for inference, enabling centralized enforcement on model invocation calls. You can also choose to safeguard partial or complete system prompts and input prompts. To learn more, visit <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-enforcements.html">Apply cross-account safeguards with Amazon Bedrock Guardrails enforcement</a>.</li>
<li>Ensure you are specifying the accurate guardrail Amazon Resource Names (ARN) in the policy. Specifying an incorrect or invalid ARN will result in policy violations, non-enforcement of safeguards, and the inability to use the models in Amazon Bedrock for inference. To learn more, visit <a href="https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_bedrock_best_practices.html">Best practices for using Amazon Bedrock policies</a>.</li>
<li>Automated Reasoning checks are not supported with this capability.</li>
</ul><p><strong class="c6">Now available</strong><br />Cross-account safeguards in Amazon Bedrock Guardrails is generally available today in the all AWS commercial and GovCloud Regions where Bedrock Guardrails is available. For Regional availability and a future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>. Charges apply to each enforced guardrail according to its configured safeguards. For detailed pricing information on individual safeguards, visit <a href="https://aws.amazon.com/bedrock/pricing">Amazon Bedrock Pricing</a> page.</p><p>Give this capability a try in the <a href="https://console.aws.amazon.com/bedrock/home#/guardrails">Amazon Bedrock console</a> and send feedback to <a href="https://repost.aws/tags/TAlO9WA6YBQxuc0MZjaodsUw/amazon-bedrock-guardrails?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Amazon Bedrock Guardrails</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="fbcf3bed-abed-4b00-9824-e8d03bd8b14d" data-title="Amazon Bedrock Guardrails supports cross-account safeguards with centralized control and management" data-url="https://aws.amazon.com/blogs/aws/amazon-bedrock-guardrails-supports-cross-account-safeguards-with-centralized-control-and-management/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-bedrock-guardrails-supports-cross-account-safeguards-with-centralized-control-and-management/"/>
    <updated>2026-04-03T22:36:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/announcing-managed-daemon-support-for-amazon-ecs-managed-instances/</id>
    <title><![CDATA[Announcing managed daemon support for Amazon ECS Managed Instances]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing managed daemon support for <a href="https://aws.amazon.com/ecs/managed-instances/">Amazon Elastic Container Service (Amazon ECS) Managed Instances</a>. This new capability extends the managed instances experience we <a href="https://aws.amazon.com/blogs/aws/announcing-amazon-ecs-managed-instances-for-containerized-applications/">introduced in September 2025</a>, by giving platform engineers independent control over software agents such as monitoring, logging, and tracing tools, without requiring coordination with application development teams, while also improving reliability by ensuring every instance consistently runs required daemons and enabling comprehensive host-level monitoring.</p><p>When running containerized workloads at scale, platform engineers manage a wide range of responsibilities, from scaling and patching infrastructure to keeping applications running reliably and maintaining the operational agents that support those applications. Until now, many of these concerns were tightly coupled. Updating a monitoring agent meant coordinating with application teams, modifying task definitions, and redeploying entire applications, a significant operational burden when you’re managing hundreds or thousands of services.</p><p><strong>Decoupled lifecycle management for daemons<br /></strong></p><p>Amazon ECS now introduces a dedicated managed daemons construct that enables platform teams to centrally manage operational tooling. This separation of concerns allows platform engineers to independently deploy and update monitoring, logging, and tracing agents to infrastructure, while enforcing consistent use of required tools across all instances, without requiring application teams to redeploy their services. Daemons are guaranteed to start before application tasks and drain last, ensuring that logging, tracing, and monitoring are always available when your application needs them.</p><p>Platform engineers can deploy managed daemons across multiple capacity providers, or target specific capacity providers, giving them flexibility in how they roll out agents across their infrastructure. Resource management is also centralized, allowing teams to define daemon CPU and memory parameters separately from application configurations with no need to rebuild AMIs or update task definitions, while optimizing resource utilization since each instance runs exactly one daemon copy shared across multiple application tasks.</p><p><strong>Let’s try it out<br /></strong> To take ECS Managed Daemons for a spin, I decided to start with the <a href="https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/Install-CloudWatch-Agent.html">Amazon CloudWatch Agent</a> as my first managed daemon. I had previously set up an Amazon ECS cluster with a Managed Instance capacity provider using the <a href="https://docs.aws.amazon.com/AmazonECS/latest/developerguide/getting-started-managed-instances.html">documentation</a>.</p><p>From the Amazon Elastic Container Service console, I noticed a new <strong>Daemon task definitions</strong> option in the navigation pane, where I can define my managed daemons.</p><p><img class="alignnone size-large wp-image-103545" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/27/daemons-1-1024x528.png" alt="Managed daemons console" width="1024" height="528" /></p><p>I chose <strong>Create new daemon task definition</strong> to get started. For this example, I configured the CloudWatch Agent with 1 vCPU and 0.5 GB of memory. In the <strong>Daemon task definition family field</strong>, I entered a name I’d recognize later.</p><p>For the <strong>Task execution role</strong>, I selected <strong>ecsTaskExecutionRole</strong> from the dropdown. Under the <strong>Container</strong> section, I gave my container a descriptive name and pasted in the image URI: <code>public.ecr.aws/cloudwatch-agent/cloudwatch-agent:latest</code> along with a few additional details.</p><p>After reviewing everything, I chose <strong>Create</strong>.</p><p>Once my daemon task definition was created, I navigated to the <strong>Clusters</strong> page, selected my previously created cluster and found the new <strong>Daemons</strong> tab.</p><p><img class="alignnone size-large wp-image-103546" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/27/daemons-2-1024x553.png" alt="Managed daemons 2" width="1024" height="553" /></p><p>Here I can simply click the <strong>Create daemon</strong> button and complete the form to configure my daemon.</p><p><img class="alignnone size-large wp-image-103547" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/27/daemons-3-1024x575.png" alt="Managed daemons 3" width="1024" height="575" /></p><p>Under <strong>Daemon configuration</strong>, I selected my newly created daemon task definition family and then assigned my daemon a name. For <strong>Environment configuration</strong>, I selected the ECS Managed Instances capacity provider I had set up earlier. After confirming my settings, I chose <strong>Create</strong>.</p><p>Now ECS automatically ensures the daemon task launches first on every provisioned ECS managed instance in my selected capacity provider. To see this in action, I deployed a sample <a href="https://nginx.org/">nginx</a> web service as a test workload. Once my workload was deployed, I could see in the console that ECS Managed Daemons had automatically deployed the CloudWatch Agent daemon alongside my application, with no manual intervention required.</p><p>When I later updated my daemon, ECS handled the rolling deployment automatically by provisioning new instances with the updated daemon, starting the daemon first, then migrating application tasks to the new instances before terminating the old ones. This “start before stop” approach ensures continuous daemon coverage: your logging, monitoring, and tracing agents remain operational throughout the update with no gaps in data collection. The drain percentage I configured controlled the pace of this replacement, giving me complete control over addon updates without any application downtime.</p><p><strong>How it works<br /></strong> The managed daemon experience introduces a new daemon task definition that is separate from task definitions, with its own parameters and validation scheme. A new <code>daemon_bridge</code> network mode enables daemons to communicate with application tasks while remaining isolated from application networking configurations.</p><p>Managed daemons support advanced host-level access capabilities that are essential for operational tooling. Platform engineers can configure daemon tasks as privileged containers, add additional Linux capabilities, and mount paths from the underlying host filesystem. These capabilities are particularly valuable for monitoring and security agents that require deep visibility into host-level metrics, processes, and system calls.</p><p>When a daemon is deployed, ECS launches exactly one daemon process per container instance before placing application tasks. This guarantees that operational tooling is in place before your application starts receiving traffic. ECS also supports rolling deployments with automatic rollbacks, so you can update agents with confidence.</p><p><strong>Now available<br /></strong> Managed daemon support for Amazon ECS Managed Instances is available today in all <a href="https://aws.amazon.com/about-aws/global-infrastructure/regions_az/">AWS Regions</a>. To get started, visit the Amazon ECS console or review the <a href="https://docs.aws.amazon.com/ecs/">Amazon ECS documentation</a>. You can also explore the new managed daemons Application Programming Interface (APIs) by visiting <a href="https://docs.aws.amazon.com/AmazonECS/latest/developerguide/managed-daemons.html">this website</a>.</p><p>There is no additional cost to use managed daemons. You pay only for the standard compute resources consumed by your daemon tasks.</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="6d56e18d-326f-4f4f-8f8b-b045075c6cdf" data-title="Announcing managed daemon support for Amazon ECS Managed Instances" data-url="https://aws.amazon.com/blogs/aws/announcing-managed-daemon-support-for-amazon-ecs-managed-instances/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/announcing-managed-daemon-support-for-amazon-ecs-managed-instances/"/>
    <updated>2026-04-02T01:31:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/announcing-the-aws-sustainability-console-programmatic-access-configurable-csv-reports-and-scope-1-3-reporting-in-one-place/</id>
    <title><![CDATA[Announcing the AWS Sustainability console: Programmatic access, configurable CSV reports, and Scope 1–3 reporting in one place]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>As many of you are, I’m a parent. And like you, I think about the world I’m building for my children. That’s part of why today’s launch matters for many of us. I’m excited to announce the launch of the <a href="https://console.aws.amazon.com/sustainability/home">AWS Sustainability console</a>, a standalone service that consolidates all AWS sustainability reporting and resources in one place.</p><p>With the <a href="https://www.aboutamazon.com/planet/climate-pledge">The Climate Pledge</a>, Amazon set a goal in 2019 to reach net-zero carbon across our operations by 2040. That commitment shapes how AWS builds its data centers and services. In addition, AWS is also committed to helping you measure and reduce the environmental footprint of your own workloads. The AWS Sustainability console is the latest step in that direction.</p><p>The AWS Sustainability console builds on the <a href="https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/ccft-estimation.html">Customer Carbon Footprint Tool (CCFT)</a>, which lives inside the <a href="https://aws.amazon.com/aws-cost-management/aws-billing/">AWS Billing console</a>, and introduces a new set of capabilities for which you’ve been asking.</p><p>Until now, accessing your carbon footprint data required billing-level permissions. That created a practical problem: sustainability professionals and reporting teams often don’t have (and shouldn’t need) access to cost and billing data. Getting the right people access to the right data meant navigating permission structures that weren’t designed with sustainability workflows in mind. The AWS Sustainability console has its own permissions model, independent of the Billing console. Sustainability professionals can now get direct access to emissions data without requiring billing permissions to be granted alongside it.</p><p>The console includes <a href="https://en.wikipedia.org/wiki/Carbon_accounting">Scope 1, 2, and 3 emissions</a> attributed to your AWS usage and shows you a breakdown by AWS Region, service, such as <a href="https://aws.amazon.com/cloudfront/">Amazon CloudFront</a>, <a href="https://aws.amazon.com/ec2/">Amazon Elastic Compute Cloud (Amazon EC2)</a>, and <a href="https://aws.amazon.com/s3/">Amazon Simple Storage Service (Amazon S3)</a>. The underlying data and methodology haven’t changed with this launch; these are the same as the ones used by the CCFT. We changed how you can access and work with the data.</p><p>As sustainability reporting requirements have grown more complex, teams need more flexibility accessing and working with their emissions data. The console now includes a Reports page where you can download preset monthly and annual carbon emissions reports covering both market-based method (MBM) and location-based method (LBM) data. You can also build a custom comma-separated values (CSV) report by selecting which fields to include, the time granularity, and other filters.</p><p>If your organization’s fiscal year doesn’t align with the calendar year, you can now configure the console to match your reporting period. When that is set, all data views and exports reflect your fiscal year and quarters, which removes a common friction point for finance and sustainability teams working in parallel.</p><p>You can also use the new API or the <a href="https://aws.amazon.com/tools/">AWS SDKs</a> to integrate emissions data into your own reporting pipelines, dashboards, or compliance workflows. This is useful for teams that need to pull data for a specific month across a large number of accounts without setting up a data export or for organizations that need to establish custom account groupings that don’t align with their existing <a href="https://aws.amazon.com/organizations/">AWS Organizations</a> structure.</p><p>You can read about the latest features released and methodology updates directly on the <a href="https://console.aws.amazon.com/sustainability/release-notes"><strong>Release notes</strong></a> page on the <strong>Learn more</strong> tab.</p><p><strong>Lets see it in action<br /></strong> To show you the Sustainability console, I opened the <a href="https://console.aws.amazon.com">AWS Management Console</a> and searched for “sustainability” in the search bar at the top of the screen.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/09/2026-03-09_14-54-45.png"><img class="aligncenter size-large wp-image-103308" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/09/2026-03-09_14-54-45-1024x512.png" alt="Sustainability console - carbon emission 1" width="1024" height="512" /></a></p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/09/2026-03-09_14-55-17.png"><img class="aligncenter size-large wp-image-103309" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/09/2026-03-09_14-55-17-1024x663.png" alt="Sustainability console - carbon emission 2" width="1024" height="663" /></a></p><p>The <strong>Carbon emissions</strong> section gives an estimate on your carbon emissions, expressed in metric tons of carbon dioxide equivalent (MTCO2e). It shows the emissions by scope, expressed in the MBM and the LBM. On the right side of the screen, you can adjust the date range or filter by service, Regions, and more.</p><p>For those unfamiliar: Scope 1 includes direct emissions from owned or controlled sources (for example, data center fuel use); Scope 2 covers indirect emissions from the production of purchased energy (with MBM accounting for energy attribute certificates and LBM using average local grid emissions); and Scope 3 includes other indirect emissions across the value chain, such as server manufacturing and data center construction. You can read more about this in <a href="https://sustainability.aboutamazon.com/aws-customer-carbon-footprint-tool-methodology.pdf">our methodology document</a>, which was <a href="https://sustainability.aboutamazon.com/aws-customer-carbon-footprint-tool-methodology-assurance.pdf">independently verified by Apex</a>, a third-party consultant.</p><p>I can also use API or <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a> to programmatically pull the emissions data.</p><pre class="lang-bash">aws sustainability get-estimated-carbon-emissions \
     --time-period='{"Start":"2025-03-01T00:00:00Z","End":"2026-03-01T23:59:59.999Z"}'
{
    "Results": [
        {
            "TimePeriod": {
                "Start": "2025-03-01T00:00:00+00:00",
                "End": "2025-04-01T00:00:00+00:00"
            },
            "DimensionsValues": {},
            "ModelVersion": "v3.0.0",
            "EmissionsValues": {
                "TOTAL_LBM_CARBON_EMISSIONS": {
                    "Value": 0.7,
                    "Unit": "MTCO2e"
                },
                "TOTAL_MBM_CARBON_EMISSIONS": {
                    "Value": 0.1,
                    "Unit": "MTCO2e"
                }
            }
        },
...</pre><p>The combination of the visual console and the new API gives you two additional ways to work with your data, in addition to <a href="https://docs.aws.amazon.com/cur/latest/userguide/dataexports-create.html">the Data Exports</a> still available. You can now explore and identify hotspots on the console and automate the reporting you want to share with stakeholders.</p><p>The Sustainability console is designed to grow. We plan to continue to release new features as we grow the console’s capabilities alongside our customers.</p><p><strong>Get started today<br /></strong> The AWS Sustainability console is available today at no additional cost. You can access it from the AWS Management Console. Historical data is available going back to January 2022, so you can start exploring your emissions trends right away.</p><p>Get started on <a href="https://console.aws.amazon.com/sustainability/home">the console</a> today. If you want to learn more about the AWS commitment to sustainability, visit the <a href="https://aws.amazon.com/sustainability/">AWS Sustainability</a> page.</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="4427cd9b-130f-4a7f-b1c0-b572b194ef5b" data-title="Announcing the AWS Sustainability console: Programmatic access, configurable CSV reports, and Scope 1–3 reporting in one place" data-url="https://aws.amazon.com/blogs/aws/announcing-the-aws-sustainability-console-programmatic-access-configurable-csv-reports-and-scope-1-3-reporting-in-one-place/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/announcing-the-aws-sustainability-console-programmatic-access-configurable-csv-reports-and-scope-1-3-reporting-in-one-place/"/>
    <updated>2026-03-31T21:04:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-ai-ml-scholars-program-agent-plugin-for-aws-serverless-and-more-march-30-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: AWS AI/ML Scholars program, Agent Plugin for AWS Serverless, and more (March 30, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Last week, what excited me most was the <a href="https://www.linkedin.com/posts/swaminathansivasubramanian_excited-to-share-that-applications-are-ugcPost-7442263176475410433-8c8k?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAUt4OcBCLB3u7KY4pbSog9XZD5vI10JCzU">launch of the 2026 AWS AI &amp; ML Scholars program</a> by <a href="https://www.linkedin.com/in/swaminathansivasubramanian/">Swami Sivasubramanian</a>, VP of AWS Agentic AI, to provide free AI education to up to 100,000 learners worldwide. The program has two phases: a Challenge phase where you’ll learn foundational generative AI skills, followed by a fully funded three-month Udacity Nanodegree for the top 4,500 performers. Anyone 18 or older can apply, with no prior AI or ML experience required. Applications close on June 24, 2026. Visit the <a href="https://aws.amazon.com/about-aws/our-impact/scholars/?utm_source=linkedin&amp;utm_medium=s-post&amp;utm_campaign=launch">AWS AI &amp; ML Scholars webpage</a> to learn more and apply.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/27/AWS-AIML.png"><img class="aligncenter wp-image-103531 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/27/AWS-AIML.png" alt="The AWS AI &amp; ML Scholars Program is back" width="1920" height="1080" /></a></p><p>I’m also excited about the start of <a href="https://aws.amazon.com/events/summits/">AWS Summit</a> season, kicking off with AWS Summit Paris on April 1, followed by London on April 22. AWS Summits are free in-person events where builders and innovators can learn about Cloud and AI, think big, and make new connections. <a href="https://aws.amazon.com/events/summits/#empowering-you-to-innovate-with-aws">Explore the AWS Summits</a> near you and join us in person.</p><p>Now, let’s dive into this week’s AWS news…</p><p><strong>Last week’s launches</strong><br />Here are last week’s launches that caught my attention:</p><ul><li><a href="https://aws.amazon.com/blogs/aws/announcing-amazon-aurora-postgresql-serverless-database-creation-in-seconds/">Announcing Amazon Aurora PostgreSQL serverless database creation in seconds</a> — Amazon Aurora PostgreSQL now offers express configuration, a streamlined setup with preconfigured defaults that supports creating and connecting to a database in seconds. With just two clicks, you can launch an Aurora PostgreSQL serverless database. You can modify certain settings during or after creation.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-aurora-postgresql-aws-free-tier/">Amazon Aurora PostgreSQL now available with the AWS Free Tier</a> — Amazon Aurora PostgreSQL is now available on the AWS Free Tier. If you’re new to AWS, you receive $100 in AWS credits upon sign-up and can earn an additional $100 in credits by using services like Amazon Relational Database Service (Amazon RDS).</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/agent-plugin-aws-serverless/">Announcing Agent Plugin for AWS Serverless</a> — With the new Agent Plugin for AWS Serverless, you can easily build, deploy, troubleshoot, and manage serverless applications using AI coding assistants like Kiro, Claude Code, and Cursor. This plugin extends AI assistants with structured capabilities by packaging skills, sub-agents, and Model Context Protocol (MCP) servers into one modular unit. It automatically loads the guidance and expertise you need throughout development to build production-ready serverless applications on AWS.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-sagemaker-studio-kiro-cursor/">Amazon SageMaker Studio now supports Kiro and Cursor IDEs as remote IDEs</a> — You can now remotely connect from Kiro and Cursor IDEs to Amazon SageMaker Studio. This lets you use your existing Kiro and Cursor setup, including spec-driven development, conversational coding, and automated feature generation, while accessing the scalable compute resources of Amazon SageMaker Studio.</li>
<li><a href="https://aws.amazon.com/blogs/aws/customize-your-aws-management-console-experience-with-visual-settings-including-account-color-region-and-service-visibility/">Introducing visual customization capability in AWS Management Console</a> — You can now customize your AWS Management Console with visual settings like account color and control which regions and services you see. Hiding unused regions and services helps you focus better and work faster by reducing cognitive load and unnecessary scrolling.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/aurora-dsql-connector-for-ruby/">Announcing Aurora DSQL connector to simplify building Ruby applications</a> — You can now use the Aurora DSQL Connector for Ruby (pg gem) to easily build Ruby applications on Aurora DSQL. The Ruby Connector simplifies authentication and improves security by automatically generating tokens for each connection, eliminating the risks of traditional passwords while maintaining full compatibility with existing pg gem features.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/aws-Lambda-file-descriptors-increase-4096/">AWS Lambda increases the file descriptor limit for functions running on Lambda Managed Instances</a> — AWS Lambda increases the file descriptor limit from 1,024 to 4,096, a 4x increase, for functions running on Lambda Managed Instances (LMI). You can now run I/O intensive workloads such as high-concurrency web services and file-heavy data processing pipelines without running into file descriptor limits.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/lambda-32-gb-memory-16-vcpus/">AWS Lambda now supports up to 32 GB of memory and 16 vCPUs for Lambda Managed Instances</a> — AWS Lambda functions on Lambda Managed Instances now support up to 32 GB of memory and 16 vCPUs. You can run compute-intensive workloads like data processing, media transcoding, and scientific simulations without managing infrastructure. Plus, you can adjust the memory-to-vCPU ratio (2:1, 4:1, or 8:1) to fit your workload.</li>
<li><a href="https://aws.amazon.com/blogs/machine-learning/introducing-amazon-polly-bidirectional-streaming-real-time-speech-synthesis-for-conversational-ai/">Announcing Bidirectional Streaming API for Amazon Polly</a> — Traditional text-to-speech APIs use a request-response pattern. The new Bidirectional Streaming API for Amazon Polly is designed for conversational AI applications that generate text or audio incrementally, like large language model (LLM) responses. This lets you start synthesizing audio before the full text is available.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on our <a href="https://aws.amazon.com/blogs/aws/">News Blog</a> channel and the <a href="https://aws.amazon.com/new/">What’s New with AWS </a>page.</p><p><strong>Upcoming AWS events<br /></strong> Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/summits/">AWS Summits</a> — As I mentioned earlier, join AWS Summits in 2026 for free in-person events where you can explore emerging cloud and AI technologies, learn best practices, and network with industry peers and experts. Upcoming Summits include Paris (April 1), London (April 22), Bengaluru (April 23–24), Singapore (May 6), Tel Aviv (May 6), and Stockholm (May 7).</li>
<li><a href="https://aws.amazon.com/developer/community/community-days/">AWS Community Days</a> — Community-led conferences where content is planned, sourced, and delivered by community leaders, featuring technical discussions, workshops, and hands-on labs. Upcoming events include San Francisco (April 10) and Romania (April 23–24).</li>
</ul><p>Join the <a href="https://builder.aws.com/">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development. Browse the <a href="https://aws.amazon.com/events/">AWS Events and Webinars</a> for upcoming AWS-led in-person and virtual events and developer-focused events.</p><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=7c8639c6-87c6-47d6-9bd0-a5812eecb848&amp;sc_channel=el">Weekly Roundup</a>!</p><p>— <a href="https://www.linkedin.com/in/kprasadrao/">Prasad</a></p><p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="718a8cc7-c6c5-4476-ba51-4579be25184c" data-title="AWS Weekly Roundup: AWS AI/ML Scholars program, Agent Plugin for AWS Serverless, and more (March 30, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-ai-ml-scholars-program-agent-plugin-for-aws-serverless-and-more-march-30-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-ai-ml-scholars-program-agent-plugin-for-aws-serverless-and-more-march-30-2026/"/>
    <updated>2026-03-30T18:11:00+02:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/customize-your-aws-management-console-experience-with-visual-settings-including-account-color-region-and-service-visibility/</id>
    <title><![CDATA[Customize your AWS Management Console experience with visual settings including account color, region and service visibility]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>In August 2025, we introduced <a href="https://docs.aws.amazon.com/awsconsolehelpdocs/latest/gsg/getting-started-uxc.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS User Experience Customization (UXC)</a> capability to tailor user interfaces (UIs) to meet your specific needs and complete your tasks efficiently. With this capability, your account administrator can customize some UI component of <a href="https://console.aws.amazon.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Management Console</a>, such as <a href="https://aws.amazon.com/about-aws/whats-new/2025/08/aws-management-console-assigning-color-aws-account/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">assigning a color to an AWS account</a> for easier identification.</p><p>Today, we’re announcing additional customization capability in UXC that enables selective display of relevant AWS Regions and services for your team members. By hiding unused Regions and services, you can reduce cognitive load and eliminate unnecessary clicks and scrolling, helping you focus better and work faster. With this launch, we offer the ability to customize account color, Region, and service visibility together.</p><p><strong>Categorize account by color</strong><br />You can set a color for your accounts to visually distinguish between them. To get started, sign in to the <a href="https://console.aws.amazon.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Management Console</a> and choose your account name on the navigation bar. Your account color isn’t set yet. To set the color, choose <strong>Account</strong>.</p><p><img class="aligncenter wp-image-103429 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/18/2026-aws-uxc-1-change-color-1.png" alt="" width="2070" height="822" /></p><p>In the <strong>Account display settings</strong>, select your preferred account color and choose <strong>Update</strong>. You can see the chosen color in the navigation bar.</p><p><img class="aligncenter wp-image-103428 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/18/2026-aws-uxc-1-change-color-setting.png" alt="" width="2070" height="858" /></p><p>By changing the account color, you can clearly distinguish the account’s purpose. For example, you can use orange for development accounts, light blue for test accounts, and red for production accounts.</p><p><strong>Customize Regions and services visibility</strong><br />You can control which AWS Regions appear in the Region selector or which AWS services appear in the console navigation. In other words, you can set to show only the Regions and services that are relevant to your account.</p><p>To get started, choose the gear icon on the navigation bar and choose <strong>See all user settings</strong>. If you are in an administrator role, you can see a new <strong>Account settings</strong> tab in the unified settings. If you have not configured a setting, all Regions and services are visible.</p><p><img class="aligncenter wp-image-103430 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/18/2026-aws-uxc-2-visible-setting-1.png" alt="" width="2064" height="1034" /></p><p>To set visible Regions, choose <strong>Edit</strong> in the <strong>Visible Regions</strong> section. Select your visible Regions to <strong>All available Regions</strong> or <strong>Select Regions</strong> and configure your list. Choose <strong>Save changes</strong>.</p><p><img class="aligncenter wp-image-103431 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/18/2026-aws-uxc-2-visible-setting-1-Regions.png" alt="" width="2042" height="1308" /></p><p>After configuring visible Region setting, you will find only selected Regions in the Regions selector on the navigation bar in the console.</p><p><img class="aligncenter wp-image-103434 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/18/2026-aws-uxc-3-Regions.png" alt="" width="2052" height="772" /></p><p>You can also set visible services in the same way. Search or select services from the category. I used the <strong>Popular services</strong> category to select my favorites. When you finish selection, choose <strong>Save changes</strong>.</p><p><img class="aligncenter wp-image-103432 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/18/2026-aws-uxc-2-visible-setting-2-Services.png" alt="" width="2050" height="1252" /></p><p>After configuring visible services setting, you will find only selected services in the <strong>All services</strong> menu on the navigation bar.</p><p><img class="aligncenter wp-image-103435 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/18/2026-aws-uxc-4-Services.png" alt="" width="2062" height="1150" /></p><p>When you search the service name in the search bar, you can only choose selected services.</p><p><img class="aligncenter wp-image-103436 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/18/2026-aws-uxc-4-Services-search.png" alt="" width="2062" height="836" /></p><p>The Regions and services visibility settings control only the appearance of services and Regions in the console. They don’t restrict access through the <a href="https://aws.amazon.com/cli/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Command Line Interface (AWS CLI)</a>, <a href="https://builder.aws.com/build/tools?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS SDKs</a>, AWS APIs, or <a href="https://aws.amazon.com/q/developer/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Q Developer</a>.</p><p>You can also manage these account customization settings programmatically with new <code>visibleServices</code> and <code>visibleRegions</code> parameters. For example, you can use <a href="https://aws.amazon.com/cloudformation/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS CloudFormation</a> sample template:</p><pre class="lang-yaml">AWSTemplateFormatVersion: "2010-09-09"
Description: Customize AWS Console appearance for this account
Resources:
  AccountCustomization:
    Type: AWS::UXC::AccountCustomization
    Properties:
      AccountColor: red
      VisibleServices:
        - s3
        - ec2
        - lambda
      VisibleRegions:
        - us-east-1
        - us-west-2</pre><p>And you can deploy your Cloudformation template.</p><pre class="lang-bash">$ aws cloudformation deploy \
  --template-file account-customization.yaml \
  --stack-name my-account-customization</pre><p>To learn more, visit the <a href="https://docs.aws.amazon.com/awsconsolehelpdocs/latest/APIReference/Welcome.html">AWS User Experience Customization API Reference</a> and <a href="https://docs.aws.amazon.com/AWSCloudFormation/latest/TemplateReference/aws-resource-uxc-accountcustomization.html">AWS CloudFormation template reference</a>.</p><p>Give it a try in the <a href="https://console.aws.amazon.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS Management Console</a> today and provide feedback by selecting the <strong>Feedback</strong> link at the bottom of the console, posting to the <a href="https://repost.aws/tags/TAnTglnGsnR_CdJMgsyCH_uA/aws-management-console?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS re:Post forum for the AWS Management Console</a>, or reaching out to your AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="2a0db8c3-466b-4a02-8a71-b0a249178afc" data-title="Customize your AWS Management Console experience with visual settings including account color, region and service visibility" data-url="https://aws.amazon.com/blogs/aws/customize-your-aws-management-console-experience-with-visual-settings-including-account-color-region-and-service-visibility/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/customize-your-aws-management-console-experience-with-visual-settings-including-account-color-region-and-service-visibility/"/>
    <updated>2026-03-26T22:34:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/announcing-amazon-aurora-postgresql-serverless-database-creation-in-seconds/</id>
    <title><![CDATA[Announcing Amazon Aurora PostgreSQL serverless database creation in seconds]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>At re:Invent 2025, <a href="https://www.linkedin.com/in/colinlazier/">Colin Lazier</a>, vice president of databases at AWS, emphasized the importance of building at the speed of an idea—enabling rapid progress from concept to running application. Customers can already create production-ready <a href="https://aws.amazon.com/dynamodb/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon DynamoDB</a> tables and <a href="https://aws.amazon.com/rds/aurora/dsql/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Aurora DSQL</a> databases in seconds. He <a href="https://youtu.be/MBvyZENChk0?si=meDKK2zJturw-hK0&amp;t=1084">previewed</a> creating an <a href="https://aws.amazon.com/rds/aurora/serverless/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Aurora serverless</a> database with the same speed, and customers have since requested quick access and speed to this capability.</p><p><img class="aligncenter size-full wp-image-103204" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/27/2026-aurora-express-1-reinvent-preview.jpg" alt="" width="1262" height="680" /></p><p>Today, we’re announcing the general availability of a new express configuration for Amazon Aurora PostgreSQL, a streamlined database creation experience with preconfigured defaults designed to help you get started in seconds.</p><p>With only two clicks, you can have an Aurora PostgreSQL serverless database ready to use in seconds. You have the flexibility to modify certain settings during and after database creation in the new configuration. For example, you can change the capacity range for the serverless instance at the time of create or add read replicas, modify parameter groups after the database is created. Aurora clusters with express configuration are created without an <a href="https://aws.amazon.com/vpc/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Amazon Virtual Private Cloud (Amazon VPC)</a> network and include an internet access gateway for secure connections from your favorite development tools – no VPN, or AWS Direct Connect required. Express configuration also sets up <a href="https://aws.amazon.com/iam/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS Identity and Access Management (IAM)</a> authentication for your administrator user by default, enabling passwordless database authentication from the beginning without additional configuration.</p><p>After it’s created, you have access to features available for Aurora PostgreSQL serverless, such as deploying additional read replicas for high availability and automated failover capabilities. This launch also introduces a new internet access gateway routing layer for Aurora. Your new serverless instance comes enabled by default with this feature, which allows your applications to connect securely from anywhere in the world through the internet using the PostgreSQL wire protocol from a wide range of developer tools. This gateway is distributed across multiple Availability Zones, offering the same level of high availability as your Aurora cluster.</p><p>Creating and connecting to Aurora in seconds means fundamentally rethinking how you get started. We launched multiple capabilities that work together to help you onboard and run your application with Aurora. Aurora is now available on <a href="https://aws.amazon.com/free/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Free Tier</a>, which you gain hands-on experience with Aurora at no upfront cost. After it’s created, you can directly query an Aurora database in <a href="https://aws.amazon.com/cloudshell/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS CloudShell</a> or using programming languages and developer tools through a new internet accessible routing component for Aurora. With integrations such as v0 by <a href="https://vercel.com/">Vercel</a>, you can use natural language to start building your application with the features and benefits of Aurora.</p><p><strong class="c6">Create an Aurora PostgreSQL serverless database in seconds</strong><br />To get started, go to the <a href="https://console.aws.amazon.com/rds/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Aurora and RDS console</a> and in the navigation pane, choose <strong>Dashboard</strong>. Then, choose <strong>Create</strong> with a rocket icon.</p><p><img class="aligncenter wp-image-103396 size-large c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/16/2026-aurora-express-configuration-1-1024x431.jpg" alt="" width="1024" height="431" /></p><p>Review pre-configured settings in the <strong>Create with express configuration</strong> dialog box. You can modify the DB cluster identifier or the capacity range as needed. Choose <strong>Create database</strong>.</p><p><img class="aligncenter wp-image-103397 size-large c8" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/16/2026-aurora-express-configuration-2-1024x820.png" alt="" width="1024" height="820" /></p><p>You can also use the <a href="https://aws.amazon.com/cli/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Command Line Interface (AWS CLI)</a> or <a href="https://builder.aws.com/build/tools/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS SDKs</a> with the parameter <code>--express-configuration</code> to create both a cluster and an instance within the cluster with a single API call which makes it ready for running queries in seconds.To learn more, visit <a href="https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/CHAP_GettingStartedAurora.CreatingConnecting.AuroraPostgreSQL.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Creating an Aurora PostgreSQL DB cluster with express configuration</a>.</p><p>Here is a CLI command to create the cluster:</p><pre class="lang-bash">$ aws rds create-db-cluster --db-cluster-identifier channy-express-db \
    --engine aurora-postgresql \
    –with-express-configuration</pre><p>Your Aurora PostgreSQL serverless database should be ready in seconds. A success banner confirms the creation, and the database status changes to <strong>Available</strong>.</p><p><img class="aligncenter wp-image-103223 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/27/2026-aurora-express-configuration-3.jpg" alt="" width="2060" height="1957" /></p><p>After your database is ready, go to the <strong>Connectivity &amp; security</strong> tab to access three connection options. When connecting through SDKs, APIs, or third-party tools including agents, choose <strong>Code snippets</strong>. You can choose various programming languages such as .NET, Golang, JDBC, Node.js, PHP, PSQL, Python, and TypeScript. You can paste the code from each step into your tool and run the commands.</p><p>For example, the following Python code is dynamically generated to reflect the authentication configuration:</p><pre class="lang-python">import psycopg2
import boto3
auth_token = boto3.client('rds', region_name='ap-south-1').generate_db_auth_token(DBHostname='channy-express-db-instance-1.abcdef.ap-south-1.rds.amazonaws.com', Port=5432, DBUsername='postgres', Region='ap-south-1')
conn = None
try:
    conn = psycopg2.connect(
        host='channy-express-db-instance-1.abcdef.ap-south-1.rds.amazonaws.com',
        port=5432,
        database='postgres',
        user='postgres',
        password=auth_token,
        sslmode='require'
    )
    cur = conn.cursor()
    cur.execute('SELECT version();')
    print(cur.fetchone()[0])
    cur.close()
except Exception as e:
    print(f"Database error: {e}")
    raise
finally:
    if conn:
        conn.close()
const { Client } = require('pg');
const AWS = require('aws-sdk');
AWS.config.update({ region: 'ap-south-1' });
async function main() {
  let password = '';
  const signer = new AWS.RDS.Signer({ region: 'ap-south-1', hostname: 'channy-express-db-instance-1.abcdef.ap-south-1.rds.amazonaws.com', port: 5432, username: 'postgres' });
  password = signer.getAuthToken({});
  const client = new Client({
    host: 'channy-express-db-instance-1.abcdef.ap-south-1.rds.amazonaws.com',
    port: 5432,
    database: 'postgres',
    user: 'postgres',
    password,
    ssl: { rejectUnauthorized: false }
  });
  try {
    await client.connect();
    const res = await client.query('SELECT version()');
    console.log(res.rows[0].version);
  } catch (error) {
    console.error('Database error:', error);
    throw error;
  } finally {
    await client.end();
  }
}
main().catch(console.error);</pre><p>Choose <strong>CloudShell</strong> for quick access to the AWS CLI which launches directly from the console. When you choose Launch <strong>CloudShell</strong>, you can see the command is pre-populated with relevant information to connect to your specific cluster. After connecting to the shell, you should see the <code>psql login</code> and the <code>postgres =&gt; prompt</code> to run SQL commands.</p><p><img class="aligncenter wp-image-103209 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/27/2026-aurora-express-configuration-4.jpg" alt="" width="2122" height="1094" /></p><p>You can also choose <strong>Endpoints</strong> to use tools that only support username and password credentials, such as pgAdmin. When you choose <strong>Get token</strong>, you use an <a href="https://aws.amazon.com/iam/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Identity and Access Management (IAM)</a> authentication token generated by the utility in the password field. The token is generated for the master username that you set up at the time of creating the database. The token is valid for 15 minutes at a time. If the tool you’re using terminates the connection, you will need to generate the token again.</p><p><strong class="c6">Building your application faster with Aurora databases</strong><br />At re:Invent 2025, we <a href="https://aws.amazon.com/blogs/aws/aws-free-tier-update-new-customers-can-get-started-and-explore-aws-with-up-to-200-in-credits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">announced enhancements to the AWS Free Tier program</a>, offering up to $200 in AWS credits that can be used across AWS services. You’ll receive $100 in AWS credits upon sign-up and can earn an additional $100 in credits by using services such as Amazon Relational Database Service (Amazon RDS), AWS Lambda, and Amazon Bedrock. In addition, Amazon Aurora is now available across a broad set of eligible <a href="https://aws.amazon.com/free/database/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Free Tier database services</a>.</p><p><img class="aligncenter size-large wp-image-103220 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/27/2026-aurora-express-configuration-5-1024x447.jpg" alt="" width="1024" height="447" /></p><p>Developers are embracing platforms such as Vercel, where natural language is all it takes to build production-ready applications. We <a href="https://aws.amazon.com/about-aws/whats-new/2025/12/aws-databases-are-available-on-the-vercel/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">announced integrations with Vercel Marketplace</a> to create and connect to an AWS database directly from Vercel in seconds and <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/aws-databases-available-vercel-v0/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">v0 by Vercel</a>, an AI-powered tool that transforms your ideas into production-ready, full-stack web applications in minutes. It includes Aurora PostgreSQL, Aurora DSQL, and DynamoDB databases. You can also connect your existing databases created through express configuration with Vercel. To learn more, visit <a href="https://vercel.com/marketplace/aws">AWS for Vercel</a>.</p><p><img class="aligncenter size-large wp-image-103218 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/27/2026-aurora-express-configuration-6-1024x663.jpg" alt="" width="1024" height="663" /></p><p>Like Vercel, we’re bringing our databases seamlessly into their experiences and are integrating directly with widely adopted frameworks, AI assistant coding tools, environments, and developer tools, all to unlock your ability to build at the speed of an idea.</p><p>We introduced <a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-aurora-postgresql-integration-kiro-powers/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Aurora PostgreSQL integration with Kiro powers</a>, which developers can use to build Aurora PostgreSQL backed applications faster with AI agent-assisted development through <a href="https://kiro.dev">Kiro</a>. You can use Kiro power for Aurora PostgreSQL within <a href="https://kiro.dev/powers/#how-do-i-install-powers?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener">Kiro IDE</a> and from the <a href="https://kiro.dev/powers/" target="_blank" rel="noopener">Kiro powers webpage</a> for one-click installation. To learn more about this Kiro Power, read <a href="https://aws.amazon.com/blogs/database/introducing-amazon-aurora-powers-for-kiro/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener">Introducing Amazon Aurora powers for Kiro</a> and <a href="https://awslabs.github.io/mcp/servers/postgres-mcp-server?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener">Amazon Aurora Postgres MCP Server</a>.</p><p><img class="aligncenter size-large wp-image-103219" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/27/2026-aurora-express-configuration-7-1024x697.png" alt="" width="1024" height="697" /></p><p><strong class="c6">Now available</strong><br />You can create an Aurora PostgreSQL serverless database in seconds today in all AWS commercial Regions. For Regional availability and a future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>.</p><p>You pay only for capacity consumed based on Aurora Capacity Units (ACUs) billed per second from zero capacity, which automatically starts up, shuts down, and scales capacity up or down based on your application’s needs. To learn more, visit the <a href="https://aws.amazon.com/rds/aurora/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Aurora Pricing page</a>.</p><p>Give it a try in the <a href="https://console.aws.amazon.com/rds/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Aurora and RDS console</a> and send feedback to <a href="https://repost.aws/tags/TAxfQ-h0UrRZ69nv5Q_M-BRQ/aurora-postgresql?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Aurora PostgreSQL</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="df1b9b21-48ac-4f0e-9827-96b58ab74d49" data-title="Announcing Amazon Aurora PostgreSQL serverless database creation in seconds" data-url="https://aws.amazon.com/blogs/aws/announcing-amazon-aurora-postgresql-serverless-database-creation-in-seconds/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/announcing-amazon-aurora-postgresql-serverless-database-creation-in-seconds/"/>
    <updated>2026-03-25T21:37:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-nvidia-nemotron-3-super-on-amazon-bedrock-nova-forge-sdk-amazon-corretto-26-and-more-march-23-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: NVIDIA Nemotron 3 Super on Amazon Bedrock, Nova Forge SDK, Amazon Corretto 26, and more (March 23, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Hello! I’m Daniel Abib, and this is my first AWS Weekly Roundup. I’m a Senior Specialist Solutions Architect at AWS, focused on the generative AI and Amazon Bedrock. With over 28 years of experience in solution architecture, software development, and cloud architecture, I help Startups &amp; Enterprises harness the power of generative AI with Amazon Bedrock. I’ve been at AWS for more than six and a half years, working closely with customers across Latin America, and I’m also passionate about Serverless technologies.</p><p><img class="alignnone wp-image-103472 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/20/Daniel-1024x760.jpg" alt="" width="1024" height="760" /></p><p>Outside of work and endurance sports, I’m a dedicated father to Cecília (7) and Rafael (4), who keep me busier—and happier— than any distributed system ever could. I’m based in São Paulo, you can find me on <a href="https://www.linkedin.com/in/danielabib/">LinkedIn</a> and <a href="https://x.com/DCABib">X (@DCABib)</a>, where I share insights about generative AI, Amazon Bedrock, AWS serverless services, and the occasional Ironman throwback.</p><p>Now, let’s get into this week’s AWS news…</p><p><strong>Last week’s launches<br /></strong> Here are some launches and updates from this past week that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-redshift-increases-performance-for-new-queries/">Amazon Redshift increases performance for new queries in dashboards and ETL workloads by up to 7x</a> — Amazon Redshift now delivers up to 7x faster performance for new queries in dashboards and ETL workloads. Queries you run for the first time — without cached results — now execute significantly faster, reducing wait times for interactive dashboards and accelerating your ETL pipelines. This is particularly impactful for workloads with high query variability where cache hits are less frequent.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-bedrock-nemotron-3-super/">NVIDIA Nemotron 3 Super now available on Amazon Bedrock</a> — NVIDIA Nemotron 3 Super is now available in Amazon Bedrock, expanding the lineup of foundation models you can access through the unified Bedrock API. Nemotron 3 Super is a high-performance language model optimized for tasks such as text generation, complex reasoning, summarization, and code generation. You can now invoke Nemotron 3 Super alongside other foundation models in your existing Bedrock workflows, without managing any infrastructure.</li>
<li><a href="https://aws.amazon.com/blogs/machine-learning/introducing-nova-forge-sdk-a-seamless-way-to-customize-nova-models-for-enterprise-ai/">Introducing Nova Forge SDK, a seamless way to customize Nova models for enterprise AI</a> — Nova Forge SDK provides a streamlined way to fine-tune and customize Amazon Nova models for enterprise use cases. You can adapt Nova models to your domain-specific data and deploy them directly within Amazon Bedrock, reducing the complexity of building tailored AI solutions. The SDK handles the heavy lifting of model customization, letting you focus on your business logic rather than the underlying infrastructure.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-corretto-26-generally-available/">Amazon Corretto 26 is now generally available</a> — Amazon Corretto 26, the latest long-term support (LTS) release of the no-cost, production-ready distribution of OpenJDK, is now generally available. Corretto 26 includes the latest Java language features, performance improvements, and security patches, all backed by long-term support from AWS. You can use it across development and production environments on Amazon Linux, Windows, macOS, and Docker images.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/lambda-availability-zone-metadata/">AWS Lambda now supports Availability Zone metadata</a> — AWS Lambda now provides Availability Zone metadata for your function invocations. You can now identify which Availability Zone your Lambda function is running in, enabling better observability, more informed architectural decisions, and simplified troubleshooting for latency-sensitive and multi-AZ workloads. This is particularly useful when correlating Lambda execution with other AZ-aware services in your architecture.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/cloudwatch-http-log-collector/">Amazon CloudWatch Logs now supports log ingestion using HTTP-based protocol</a> — Amazon CloudWatch Logs now supports ingesting logs using an HTTP-based protocol, making it simpler to send logs from applications and services that use standard HTTP endpoints. You can now route logs to CloudWatch Logs without requiring custom agents or additional SDK integrations, lowering the barrier to centralized log management across your workloads.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-eks-announces-sla-8xl-scaling-tier/">Amazon EKS announces 99.99% Service Level Agreement and new 8XL scaling tier for Provisioned Control Plane clusters</a> — Amazon EKS now offers a 99.99% Service Level Agreement (SLA) for clusters running on Provisioned Control Plane, up from the 99.95% SLA offered on standard control plane. EKS is also introducing the 8XL scaling tier, the largest available Provisioned Control Plane tier, which doubles the Kubernetes API server request processing capacity of the next lower 4XL tier — ideal for large-scale workloads like AI/ML training, high-performance computing (HPC), and large-scale data processing.</li>
</ul><p><strong>Other AWS news<br /></strong> Here are some additional posts and resources that you might find interesting:</p><ul><li><a href="https://kiro.dev/students/">Kiro for students</a> — Kiro is now available for students, giving the next generation of builders access to AI-powered development tools at no cost. As Swami Sivasubramanian <a href="https://www.linkedin.com/posts/swaminathansivasubramanian_students-are-the-future-decision-makers-shaping-activity-7440078471449681920-p2l4">shared on LinkedIn</a>, “Students are the future decision-makers shaping technology” — and Kiro gives them hands-on experience building with AI from day one. If you’re a student or know someone who is, this is a great opportunity to start building with AI-assisted development.</li>
<li><a href="https://strandsagents.com/blog/steering-accuracy-beats-prompts-workflows/">Strands Steering Hooks achieved 100% agent accuracy</a> — The Strands Agents team published results showing that Steering Hooks can achieve 100% agent accuracy, outperforming both prompt engineering and rigid workflow approaches for controlling agent behavior. As Swami <a href="https://www.linkedin.com/posts/swaminathansivasubramanian_building-reliable-ai-agents-often-goes-something-activity-7440433427205574656-ZTdR">highlighted on LinkedIn</a>, building reliable AI agents often means rethinking how we guide model behavior — and Steering Hooks offer a compelling new path to agent reliability.</li>
<li><a href="https://builder.aws.com/content/39Ya8ta5NEGZMTCepqfvaK8AwXq/introducing-badges-on-aws-builder-center">Introducing Badges on AWS Builder Center</a> — AWS Builder Center now features badges that recognize your contributions and achievements within the builder community. You can earn badges by sharing solutions, participating in challenges, and engaging with fellow builders. It’s a great way to showcase your expertise and track your growth.</li>
<li><a href="https://builder.aws.com/content/3B3nNUqr0aOLu1GbK1dyjmW0Z9h/keep-building-together-the-power-of-community">Keep Building Together: The Power of Community</a> — A thoughtful read on the power of community-driven learning and collaboration in the AWS ecosystem. Whether you’re just getting started with AWS or you’ve been building for years, the builder community is a place to connect, share knowledge, and grow together. I highly recommend checking it out.</li>
</ul><p><strong>Upcoming AWS events<br /></strong> Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/summits/">AWS Summits</a> — Join AWS Summits in 2026, free in-person events where you can explore emerging cloud and AI technologies, learn best practices, and network with industry peers and experts. Upcoming Summits include Paris (April 1), London (April 22), Bengaluru (April 23–24), Singapore (May 6), Tel Aviv (May 6), and Stockholm (May 7).</li>
<li><a href="https://aws.amazon.com/developer/community/community-days/">AWS Community Days</a> — Community-led conferences where content is planned, sourced, and delivered by community leaders, featuring technical discussions, workshops, and hands-on labs. Upcoming events include San Francisco (April 10) and Romania (April 23–24).</li>
<li><a href="https://www.awswomensummitlatam.com/home.html">AWSome Women Summit LATAM</a> — Taking place on March 28 in Mexico City, this event celebrates and empowers women in cloud technology across Latin America. A fantastic initiative for the LATAM tech community.</li>
</ul><p>Join the <a href="https://builder.aws.com/">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development. Browse the <a href="https://aws.amazon.com/events/">AWS Events and Webinars</a> for upcoming AWS-led in-person and virtual events and developer-focused events.</p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="7a852120-5453-4a2f-a071-0e6f96f9f3c9" data-title="AWS Weekly Roundup: NVIDIA Nemotron 3 Super on Amazon Bedrock, Nova Forge SDK, Amazon Corretto 26, and more (March 23, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-nvidia-nemotron-3-super-on-amazon-bedrock-nova-forge-sdk-amazon-corretto-26-and-more-march-23-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-nvidia-nemotron-3-super-on-amazon-bedrock-nova-forge-sdk-amazon-corretto-26-and-more-march-23-2026/"/>
    <updated>2026-03-23T17:40:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/20-years-in-the-aws-cloud-how-time-flies/</id>
    <title><![CDATA[20 years in the AWS Cloud – how time flies!]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p><img class="size-full wp-image-103375 alignright" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/16/2026-aws-20th-200x200-1.jpg" alt="" width="200" height="171" />AWS has reached its 20th anniversary! With a steady pace of innovation, AWS has grown to offer over 240 comprehensive cloud services and continues to launch thousands of new features annually for millions of customers. During this time, over 4,700 posts have been published on this blog—more than double the number since <a href="https://aws.amazon.com/blogs/aws/ten-years-in-the-aws-cloud-how-time-flies/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Jeff Barr wrote the 10th anniversary post</a>.</p><p><strong class="c6">AWS changed my life</strong><br />Reflecting on what I was doing 20 years ago, I met Jeff in Seoul on March 13, 2006, when he came as the keynote speaker for the <a href="https://channy.creation.net/blog/293">Korea NGWeb conference</a>. At that time, Amazon was one of the first pioneers to initiate an API economy, introducing ecommerce API services. After the keynote speech, he returned home that evening, and I believe he wrote the <a href="http://aws.amazon.com/blogs/aws/amazon_s3/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon S3 launch blog post</a> on the flight back to the United States.</p><p><img class="aligncenter size-full wp-image-103377" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/16/2026-ngweb-seoul-jeff-barr-2006.jpg" alt="" width="1000" height="329" /></p><p>That short meeting with him brought significant changes to my life. He became my role model as a blogger, and I began building API-based services in my company and opening them to third-party developers. When I was a PhD student while taking a break from work, I realized that for individual researchers like me, AWS Cloud services are powerful tools for conducting large-scale research projects. After returning to work, my company became one of the <a href="https://www.youtube.com/watch?v=FAsDEsVFGDU">first AWS customers in Korea</a> in 2014. Countless developers—myself included—have embraced cloud computing and actively used its capabilities to accomplish what was previously impossible.</p><p>Over the past decade, the technology landscape has transformed dramatically. Deep learning emerged as a breakthrough in AI, evolving through <a href="https://aws.amazon.com/generative-ai/">generative AI</a> based on <a href="https://aws.amazon.com/what-is/large-language-model/">large language models</a> (LLMs) to today’s <a href="https://aws.amazon.com/ai/agentic-ai/">agentic AI</a> technology. Jeff wrote, “When looking into the future, you need to be able to distinguish between flashy distractions and genuine trends, while remaining flexible enough to pivot if yesterday’s niche becomes today’s mainstream technology.” This principle guides how AWS approaches innovation—we start by listening to what customers truly need. The real trend isn’t pursuing every emerging technology, but rather reimagining solutions that address customers’ most critical challenges.</p><p><strong class="c6">20 years of AWS</strong><br />For the first 10 years, Jeff selected his favorite AWS launches and blog posts. <a href="http://aws.amazon.com/blogs/aws/amazon_s3/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Amazon S3</a>, <a href="http://aws.amazon.com/blogs/aws/amazon_ec2_beta/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Amazon EC2</a> (2006), <a href="http://aws.amazon.com/blogs/aws/introducing-rds-the-amazon-relational-database-service/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Amazon Relational Database Service</a>, <a href="http://aws.amazon.com/blogs/aws/introducing-amazon-virtual-private-cloud-vpc/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Amazon Virtual Private Cloud</a> (2009), <a href="https://aws.amazon.com/blogs/aws/amazon-dynamodb-internet-scale-data-storage-the-nosql-way/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon DynamoDB</a>, <a href="http://aws.amazon.com/blogs/aws/amazon-redshift-the-new-aws-data-warehouse/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Amazon Redshift</a> (2012), <a href="http://aws.amazon.com/blogs/aws/amazon-workspaces-desktop-computing-in-the-cloud/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Amazon WorkSpaces</a>, <a href="http://aws.amazon.com/blogs/aws/amazon-kinesis-real-time-processing-of-streamed-data/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">Amazon Kinesis</a> (2013), <a href="https://aws.amazon.com/blogs/aws/run-code-cloud/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Lambda</a> (2014), and <a href="http://aws.amazon.com/blogs/aws/aws-iot-cloud-services-for-connected-devices/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer">AWS IoT</a> (2015).</p><p><img class="aligncenter size-full wp-image-103379" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/16/2026-aws-stickers.jpg" alt="" width="982" height="329" /></p><p>While I also hate to play favorites, I want to choose some of my favorite AWS blog posts of the past decade.</p><ul><li><strong>Deploying containers easily</strong> (2014) – <a href="https://aws.amazon.com/blogs/aws/cloud-container-management/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Container Service</a> makes it straightforward for you to run any number of containers across a managed cluster of Amazon EC2 instances using powerful APIs and other tools. In 2017, we launched <a href="https://aws.amazon.com/blogs/aws/amazon-elastic-container-service-for-kubernetes/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Kubernetes Service</a> as a fully managed Kubernetes service and <a href="https://aws.amazon.com/blogs/aws/aws-fargate/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Fargate</a> as a serverless deployment option.</li>
<li><strong>High availability database at global scale</strong> (2017) – <a href="https://aws.amazon.com/blogs/aws/now-available-amazon-aurora-with-postgresql-compatibility/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Aurora</a> is a modern relational database service offering performance and high availability at scale. In 2018, we launched <a href="https://aws.amazon.com/blogs/aws/aurora-serverless-ga/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Aurora Serverless v1</a>, and this serverless database evolved to <a href="https://aws.amazon.com/blogs/database/introducing-scaling-to-0-capacity-with-amazon-aurora-serverless-v2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Aurora Serverless v2</a> to scale down to zero. In 2025, we also launched <a href="https://aws.amazon.com/blogs/aws/amazon-aurora-dsql-is-now-generally-available/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Aurora DSQL</a> is the fastest serverless distributed SQL database for always available applications.</li>
<li><strong>Machine learning (ML) at your fingertips</strong> (2017) – <a href="https://aws.amazon.com/blogs/aws/sagemaker/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon SageMaker</a> is a fully managed end-to-end ML service that data scientists, developers, and ML experts can use to quickly build, train, and host machine learning models at scale. In 2024, we launched <a href="https://aws.amazon.com/blogs/aws/introducing-the-next-generation-of-amazon-sagemaker-the-center-for-all-your-data-analytics-and-ai/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">the next generation of Amazon SageMaker</a>, a unified platform for data, analytics, and AI and introduced <a href="https://aws.amazon.com/sagemaker/ai/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon SageMaker AI</a> to focus specifically on building, training, and deploying AI and ML models at scale.</li>
<li><strong>Best price performance for cloud workloads</strong> (2018) – We launched <a href="https://aws.amazon.com/blogs/aws/new-ec2-instances-a1-powered-by-arm-based-aws-graviton-processors/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 A1 instances</a> powered by the first generation of Arm-based <a href="https://aws.amazon.com/ec2/graviton/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Graviton Processors</a> designed to deliver the best price performance for your cloud workloads. Last year, we <a href="https://aws.amazon.com/about-aws/whats-new/2025/12/ec2-m9g-instances-graviton5-processors-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">previewed EC2 M9g instances</a> powered by AWS Graviton5 processors. Over 90,000 AWS customers have reaped the benefits of Graviton supporting popular AWS services such as Amazon ECS and Amazon EKS, AWS Lambda, Amazon RDS, Amazon ElastiCache, Amazon EMR, and Amazon OpenSearch Service.</li>
<li><strong>Run AWS Cloud in your data center</strong> (2019) – <a href="https://aws.amazon.com/blogs/aws/aws-outposts-now-available-order-your-racks-today/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Outposts</a> is a family of fully managed services delivering AWS infrastructure and services to virtually any on-premises or edge location for a truly consistent hybrid experience. Now, AWS Outposts is available in a <a href="https://aws.amazon.com/outposts/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">variety of form factors</a>, from 1U and 2U Outposts servers to 42U Outposts racks, and multiple rack deployments. Customers such as DISH, Fanduel, Morningstar, Philips, and others use Outposts in workloads requiring low latency access to on-premises systems, local data processing, data residency, and application migration with local system interdependencies.</li>
<li><strong>Best price performance for ML workloads</strong> (2019) – We launched <a href="https://aws.amazon.com/blogs/aws/amazon-ec2-update-inf1-instances-with-aws-inferentia-chips-for-high-performance-cost-effective-inferencing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 Inf1 instances</a> powered by the first generation of <a href="https://aws.amazon.com/ai/machine-learning/inferentia/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Inferentia chips</a> designed to provide fast, low-latency inferencing. In 2022, we launched <a href="https://aws.amazon.com/blogs/aws/amazon-ec2-trn1-instances-for-high-performance-model-training-are-now-available/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 Trn1 instances</a> powered by the first generation of <a href="https://aws.amazon.com/ai/machine-learning/trainium/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Trainium chips</a> optimized for high performance AI training. Last year, we launched <a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-ec2-trn3-ultraservers/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 Trn3 UltraServers</a> powered by Trainium3 to deliver the best token economics for next-generation generative AI applications. Customers such as Anthropic, Decart, poolside, Databricks, Ricoh, Karakuri, SplashMusic, and others are realizing performance and cost benefits of Trainium-based instances and UltraServers.</li>
<li><strong>Build your generative AI apps on AWS</strong> (2023) – <a href="https://aws.amazon.com/blogs/aws/amazon-bedrock-is-now-generally-available-build-and-scale-generative-ai-applications-with-foundation-models/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Bedrock</a> is a fully managed service that offers a choice of industry leading AI models along with a broad set of capabilities that you need to build generative AI applications, simplifying development with security, privacy, and responsible AI. Last year, we <a href="https://aws.amazon.com/blogs/aws/introducing-amazon-bedrock-agentcore-securely-deploy-and-operate-ai-agents-at-any-scale/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">introduced Amazon Bedrock AgentCore</a>, an agentic platform for building, deploying, and operating effective agents securely at scale. Now, more than 100,000 customers worldwide choose Amazon Bedrock to deliver personalized experiences, automate complex workflows, and uncover actionable insights.</li>
<li><strong>Your AI coding companion</strong> (2023) – We launched <a href="https://aws.amazon.com/blogs/aws/amazon-codewhisperer-free-for-individual-use-is-now-generally-available/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon CodeWhisperer</a> as the industry’s first cloud-based AI coding assistant service. The service delivered code generation from comments, open-source code reference tracking, and vulnerability scanning capabilities. In 2024, we rebranded the service to <a href="https://aws.amazon.com/blogs/aws/amazon-q-developer-now-generally-available-includes-new-capabilities-to-reimagine-developer-experience/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Q Developer</a> and expanded its features to include a chat-based assistant in the console, project-based code generation, and code transformation tools. In 2025, this service evolved into <a href="https://kiro.dev/blog/introducing-kiro/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Kiro</a>, a new agentic AI development tool that brings structure to AI coding through spec-driven development, taking projects from prototype to production. Recently, Kiro <a href="https://kiro.dev/blog/introducing-kiro-autonomous-agent/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">previewed an autonomous agent</a>, a frontier agent that works independently on development tasks, maintaining context and learning from every interaction.</li>
<li><strong>Broaden your AI model choices</strong> (2024) – We launched <a href="https://aws.amazon.com/blogs/aws/build-rag-and-agent-based-generative-ai-applications-with-new-amazon-titan-text-premier-model-available-in-amazon-bedrock/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Titan models</a> further increasing cost-effective AI model choice for text and multimodal needs in Amazon Bedrock. At AWS re:Invent 2024, we announced <a href="https://aws.amazon.com/blogs/aws/introducing-amazon-nova-frontier-intelligence-and-industry-leading-price-performance/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Nova</a> models that delivers frontier intelligence and industry leading price performance. Now Amazon Nova has a portfolio of AI offerings—including Amazon Nova models, <a href="https://aws.amazon.com/blogs/aws/introducing-amazon-nova-forge-build-your-own-frontier-models-using-nova/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Nova Forge</a>, a new service to build your own frontier models; and <a href="https://aws.amazon.com/blogs/aws/build-reliable-ai-agents-for-ui-workflow-automation-with-amazon-nova-act-now-generally-available/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Nova Act</a>, a new service to build agents that automate browser-based UI workflows powered by a custom <a href="https://aws.amazon.com/blogs/aws/introducing-amazon-nova-2-lite-a-fast-cost-effective-reasoning-model/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Nova 2 Lite model</a>.</li>
</ul><p><strong class="c6">Build with AI: Your path forward</strong><br />A decade ago, AWS responded to the emergence of deep learning by launching the broadest and deepest ML services, such as Amazon SageMaker, democratizing AI for a wide range of customers—from individual developers and startups to large enterprises—regardless of their technical expertise.</p><p>AI technology has advanced significantly, but building and deploying AI models and applications still remains complex for many developers and organizations. AWS offers the broadest selection of AI models through Amazon Bedrock, including leading providers such as <a href="https://www.aboutamazon.com/news/aws/amazon-invests-additional-4-billion-anthropic-ai?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Anthropic</a> and <a href="https://www.aboutamazon.com/news/aws/amazon-open-ai-strategic-partnership-investment?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">OpenAI</a>. By using our model training and inference infrastructure and <a href="https://aws.amazon.com/ai/responsible-ai/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">responsible AI</a> both practical and scalable, you can accelerate trusted AI innovation while maintaining control of your data and costs—all built on our global infrastructure’s operational excellence.</p><p>Reinvent your idea, keep on learning, build confidently with AI you can trust, and share your successes with us! New AWS customers receive up to $200 in credits to try <a href="https://aws.amazon.com/free/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS AI for free</a>. If you’re a student, start building with <a href="https://kiro.dev/students/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Kiro for free</a> using 1,000 credits per month for one year.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="46328b6c-28c0-462c-ba7e-97baca4d90a0" data-title="20 years in the AWS Cloud – how time flies!" data-url="https://aws.amazon.com/blogs/aws/20-years-in-the-aws-cloud-how-time-flies/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/20-years-in-the-aws-cloud-how-time-flies/"/>
    <updated>2026-03-19T14:35:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/our-first-2026-heroes-cohort-is-here/</id>
    <title><![CDATA[Our First 2026 Heroes Cohort Is Here!]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>We’re thrilled to celebrate three exceptional developer community leaders as AWS Heroes. These individuals represent the heart of what makes the AWS community so vibrant. In addition to sharing technical knowledge, they build connections, forge genuine human relationships, and create pathways for others to grow. From pioneering cloud culture in mountain villages to leading cybersecurity education across continents, these Heroes demonstrate that true leadership extends beyond technical expertise to the communities we build and the lives we impact.</p><h2 class="c6">Maurizio – Pignola, Italy</h2><p><a href="https://builder.aws.com/community/@margoneto81" target="_blank" rel="noopener noreferrer"><img class="alignleft" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/17/Maurizio_175x263.jpg" width="175" height="263" alt="image" /></a>Community Hero <a href="https://builder.aws.com/community/@margoneto81" target="_blank" rel="noopener noreferrer">Maurizio</a> is a CTO and organizer of the AWS User Group Basilicata, recognized for his dedication to building tech ecosystems where they previously did not exist. For over a decade, he has pioneered cloud culture through a philosophy centered on genuine human connection and knowledge transfer. He founded an international tech conference in a small mountain village, creating a unique space where global experts and local talent meet, blending deep technical sessions on cloud architectures, DevOps, and web scaling with unconventional networking experiences. Beyond organizing events, Maurizio is a tireless mentor working across generations, which span from introducing children to coding to helping university students and professionals transition into cloud architecture. His impact is defined by a rare combination of technical leadership and inclusive community building that draws people from across Europe.</p><h2 class="c6">Ray Goh – Singapore</h2><p><a href="https://builder.aws.com/community/@rayg" target="_blank" rel="noopener noreferrer"><img class="alignleft" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/17/Ray_175x263.jpg" width="175" height="263" alt="image" /></a>Artificial Intelligence Hero <a href="https://builder.aws.com/community/@rayg" target="_blank" rel="noopener noreferrer">Ray Goh</a> is a seasoned AWS machine learning and AI community leader based in Singapore and a long-standing contributor in various AWS community programs since 2018, from AWS ASEAN Cloud Warrior and AWS Dev/Cloud Alliance to being part of the pioneer batch of AWS Community Builders in 2020. He founded The Gen-C (a Generative AI Learning Community) in 2024, organizing regular public workshops at libraries across Singapore on topics ranging from LLM fine-tuning to AI agents on AWS. Ray has spoken at AWS re:Invent, AWS Summit ASEAN, AWS Community Day Hong Kong, and numerous user group meetups, and guest-authored for the AWS Machine Learning Blog. He spearheaded the world’s largest enterprise AWS DeepRacer program for DBS Bank in 2020, upskilling over 3,100 employees, and trained more than 1,300 ASEAN students in LLM techniques in 2025. His community work extends to skills-based CSR initiatives teaching AI and machine learning to women, children, and youths, with contributions featured on CNBC and Euromoney.</p><h2 class="c6">Sheyla Leacock – Panama City, Panama</h2><p><a href="https://builder.aws.com/community/@sheyla" target="_blank" rel="noopener noreferrer"><img class="alignleft" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/17/Sheyla-Leacock_175x263.jpg" width="175" height="263" alt="image" /></a>Security Hero <a href="https://builder.aws.com/community/@sheyla" target="_blank" rel="noopener noreferrer">Sheyla Leacock</a> is an IT security professional, mentor, technical author, and international speaker contributing to the global cloud and cybersecurity community. She has spoken at AWS Summit Mexico, AWS Summit LATAM in Peru, and led PeerTalk sessions at AWS re:Invent, while also leading the AWS User Group in Panama and regularly participating in AWS Community Days and regional meetups. Beyond AWS-focused events, she has delivered talks at more than 20 international conferences and publishes technical articles and educational content on AWS cloud computing and cybersecurity. She collaborates with universities as a guest lecturer, supporting the development of emerging technology and cybersecurity talent. Through community leadership, knowledge sharing, and education, she contributes to strengthening the AWS and cybersecurity ecosystem.</p><h2 class="c6">Learn More</h2><p>Visit the <a href="https://builder.aws.com/connect/community/heroes" target="_blank" rel="noopener">AWS Heroes webpage</a> if you’d like to learn more about the AWS Heroes program, or to connect with a Hero near you.</p><p>— <a href="https://twitter.com/taylorjacobsen" target="_blank" rel="noopener noreferrer">Taylor</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="e2efbf2a-4c31-49bf-8647-1db10db94675" data-title="Our First 2026 Heroes Cohort Is Here!" data-url="https://aws.amazon.com/blogs/aws/our-first-2026-heroes-cohort-is-here/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/our-first-2026-heroes-cohort-is-here/"/>
    <updated>2026-03-18T17:26:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-s3-turns-20-amazon-route-53-global-resolver-general-availability-and-more-march-16-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Amazon S3 turns 20, Amazon Route 53 Global Resolver general availability, and more (March 16, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Twenty years ago this past week, Amazon S3 launched publicly on March 14, 2006. While <a href="https://aws.amazon.com/s3/?nc2=type_a">Amazon Simple Storage Service</a> is often considered the foundational storage service that defined cloud infrastructure, what began as a simple object storage service has grown into something far larger in scope and scale.</p><p>As of March 2026, S3 stores more than 500 trillion objects, serves more than 200 million requests per second globally across hundreds of exabytes of data, and the price has dropped to just over 2 cents per gigabyte — an approximately 85% reduction since launch. My colleague <a href="https://aws.amazon.com/blogs/aws/author/stormacq/">Sébastien Stormacq</a> wrote a detailed look at the engineering and the road ahead in <a href="https://aws.amazon.com/blogs/aws/twenty-years-of-amazon-s3-and-building-whats-next/">Twenty years of Amazon S3 and building what’s next</a>, and if you want to read about those earliest customers and how they shaped what AWS became, I recommend <a href="https://www.aboutamazon.com/news/aws/the-earliest-aws-customers-who-helped-build-the-cloud">How three startups helped Amazon invent cloud computing and paved the way for AI</a>. Twenty years is worth pausing to celebrate.</p><p>Alongside the 20th anniversary of S3, <a href="https://aws.amazon.com/blogs/aws/author/channy-yun/">Channy Yun</a> also wrote about a new S3 feature this week: Account regional namespaces for Amazon S3 general purpose buckets. With this feature, you can create general purpose buckets in your own account regional namespace by appending your account’s unique suffix to your requested bucket name, ensuring your desired names are always reserved exclusively for your account. You can enforce adoption across your organization using AWS IAM policies and AWS Organizations service control policies with the new <code>s3:x-amz-bucket-namespace</code> condition key. Read <a href="https://aws.amazon.com/blogs/aws/introducing-account-regional-namespaces-for-amazon-s3-general-purpose-buckets/">Channy’s post</a> to learn more about account regional namespaces for Amazon S3 general purpose buckets.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/16/aws20-hero-amazon-news-ck-030626.jpg"><img class="alignnone size-full wp-image-103383" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/16/aws20-hero-amazon-news-ck-030626.jpg" alt="" width="2000" height="1125" /></a></p><p>This week’s featured launch is one I have a personal connection to: the <a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-route-53-global-resolver/">general availability of Amazon Route 53 Global Resolver</a>. I wrote about the <a href="https://aws.amazon.com/blogs/aws/introducing-amazon-route-53-global-resolver-for-secure-anycast-dns-resolution-preview/">preview</a> of this capability back in December at re:Invent 2025, and I had a great time putting that post together, so I am happy to hear that it’s generally available now.</p><p>Amazon Route 53 Global Resolver is an internet-reachable anycast DNS resolver that provides DNS resolution for authorized clients from any location. It is now generally available across 30 AWS Regions, with support for both IPv4 and IPv6 DNS query traffic. Route 53 Global Resolver gives authorized clients in your organization anycast DNS resolution of public internet domains and private domains associated with Route 53 private hosted zones — from any location, not just from within a specific VPC or Region. It also provides DNS query filtering to block potentially malicious domains, domains that are not safe for work, and domains associated with advanced DNS threats such as DNS tunneling and Domain Generation Algorithms (DGA). Centralized query logging is included as well. With general availability, Global Resolver adds protection against Dictionary DGA threats.</p><p><strong>Last week’s launches</strong><br />Here are some of the other announcements from last week:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-bedrock-agentcore-runtime-stateful-mcp/">Amazon Bedrock AgentCore Runtime now supports stateful MCP server features</a> — Amazon Bedrock AgentCore Runtime now supports stateful Model Context Protocol (MCP) server features, enabling developers to build MCP servers that use elicitation, sampling, and progress notifications alongside existing support for resources, prompts, and tools. With stateful MCP sessions, each user session runs in a dedicated microVM with isolated resources, and the server maintains session context across multiple interactions using an <code>Mcp-Session-Id</code> header. Elicitation enables server-initiated, multi-turn conversations to gather structured input from users during tool execution. Sampling allows servers to request LLM-generated content from the client for tasks such as personalized recommendations. Progress notifications keep clients informed during long-running operations. To learn more, see the <a href="https://docs.aws.amazon.com/bedrock-agentcore/">Amazon Bedrock AgentCore</a> documentation.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-workspaces-windows-server-2025/">Amazon WorkSpaces now supports Microsoft Windows Server 2025</a> — New bundles powered by Microsoft Windows Server 2025 are now available for Amazon WorkSpaces Personal and Amazon WorkSpaces Core. These bundles include security capabilities such as Trusted Platform Module 2.0 (TPM 2.0), Unified Extensible Firmware Interface (UEFI) Secure Boot, Secured-core server, Credential Guard, Hypervisor-protected Code Integrity (HVCI), and DNS-over-HTTPS. Existing Windows Server 2016, 2019, and 2022 bundles remain available. You can use the managed Windows Server 2025 bundles or create a custom bundle and image. This support is available in all AWS Regions where Amazon WorkSpaces is available. For more information, visit the <a href="https://aws.amazon.com/workspaces-family/workspaces/faqs/">Amazon WorkSpaces FAQs</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/aws-builder-id-sign-in-github-amazon/">AWS Builder ID now supports Sign in with GitHub and Amazon</a> — AWS Builder ID now supports two additional social login options: GitHub and Amazon. These options join the existing Google and Apple sign-in capabilities. With this update, developers can access their AWS Builder ID profile — and services including AWS Builder Center, AWS Training and Certification, and Kiro — using their existing GitHub or Amazon account credentials, without managing a separate set of credentials. To learn more and get started, visit the <a href="https://docs.aws.amazon.com/signin/latest/userguide/sign-in-builder-id.html">AWS Builder ID</a> documentation.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-redshift-reusable-templates-copy/">Amazon Redshift introduces reusable templates for COPY operations</a> — Amazon Redshift now supports templates for the COPY command, allowing you to store and reuse frequently used COPY parameters. Templates help maintain consistency across data ingestion operations, reduce the effort required to execute COPY commands, and simplify maintenance by applying template updates automatically to all future uses. Support for COPY templates is available in all AWS Regions where Amazon Redshift is available, including the AWS GovCloud (US) Regions. To get started, see the <a href="https://docs.aws.amazon.com/redshift/latest/dg/r_COPY-WITH-TEMPLATE.html?refid=d8ec3b19-0f37-4f8c-8c12-189f913e205c">documentation</a> or read the <a href="https://aws.amazon.com/blogs/big-data/standardize-amazon-redshift-operations-using-templates/">Standardize Amazon Redshift operations using Templates</a> blog.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on our <a href="https://aws.amazon.com/blogs/aws/">News Blog</a> channel the <a href="https://aws.amazon.com/new/">What’s New with AWS</a> page.</p><p><strong>Upcoming AWS events</strong><br />Check your calendar and sign up for upcoming AWS events:</p><p><a href="https://aws.amazon.com/events/summits/?trk=ep_card_event_page&amp;awsf.location=*all&amp;refid=ep_card_event_page">AWS Summits</a> – Join AWS Summits in 2026, free in-person events where you can explore emerging cloud and AI technologies, learn best practices, and network with industry peers and experts. Upcoming Summits include <a href="https://aws.amazon.com/events/summits/paris/">Paris</a> (April 1), <a href="https://aws.amazon.com/events/summits/london/">London</a> (April 22), and <a href="https://aws.amazon.com/events/summits/bengaluru/">Bengaluru</a> (April 23–24).</p><p><a href="https://aws.amazon.com/events/community-day/">AWS Community Days</a> – Community-led conferences where content is planned, sourced, and delivered by community leaders, featuring technical discussions, workshops, and hands-on labs. Upcoming events include <a href="https://www.awsugpune.in/">Pune</a> (March 21), <a href="https://www.aws-cscd.com/">San Francisco</a> (April 10), and <a href="https://aws-community.ro/">Romania</a> (April 23-24).</p><p><a href="https://aws.amazon.com/events/aws-at-nvidia-gtc26/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS at NVIDIA GTC 2026</a> — Join us at our AWS sessions, booths, demos, and ancillary events in NVIDIA GTC 2026 on March 16 – 19, 2026 in San Jose. You can receive 20% off event passes through AWS and request a 1:1 meeting at GTC.</p><p><a href="https://builder.aws.com/content/39zVQT5ykq9bhnngp3kPeQNqjOc/aws-community-gameday-europe-on-the-1703-think-you-know-aws-come-prove-it">AWS Community GameDay Europe</a> — Taking place on March 17, 2026, AWS Community GameDay Europe is a team-based, hands-on AWS challenge event running simultaneously across 50+ cities in Europe. Your team is dropped into a broken AWS environment — misconfigured services, failing architectures, and security gaps — and has two hours to fix as much as possible. Find your nearest city and sign up at <a href="https://www.awsgameday.eu/">awsgameday.eu</a>.</p><p>Join the <a href="https://builder.aws.com/?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development. Browse here for upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS-led in-person and virtual events</a> and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused events</a>.</p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><a href="https://www.linkedin.com/in/esrakayabali/">— Esra</a><p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="75d86e95-0d1d-450f-92c9-69ac9c081346" data-title="AWS Weekly Roundup: Amazon S3 turns 20, Amazon Route 53 Global Resolver general availability, and more (March 16, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-s3-turns-20-amazon-route-53-global-resolver-general-availability-and-more-march-16-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-s3-turns-20-amazon-route-53-global-resolver-general-availability-and-more-march-16-2026/"/>
    <updated>2026-03-16T17:02:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/twenty-years-of-amazon-s3-and-building-whats-next/</id>
    <title><![CDATA[Twenty years of Amazon S3 and building what’s next]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Twenty years ago today, on March 14, 2006, <a href="https://aws.amazon.com/s3/">Amazon Simple Storage Service (Amazon S3)</a> quietly launched with a modest one-paragraph announcement on the <a href="https://aws.amazon.com/about-aws/whats-new/2006/03/announcing-amazon-s3---simple-storage-service/">What’s New page</a>:</p><blockquote>
<p>Amazon S3 is storage for the Internet. It is designed to make web-scale computing easier for developers. Amazon S3 provides a simple web services interface that can be used to store and retrieve any amount of data, at any time, from anywhere on the web. It gives any developer access to the same highly scalable, reliable, fast, inexpensive data storage infrastructure that Amazon uses to run its own global network of web sites.</p>
</blockquote><p>Even <a href="https://aws.amazon.com/blogs/aws/amazon_s3/">Jeff Barr’s blog post</a> was only a few paragraphs, written before catching a plane to a developer event in California. No code examples. No demo. Very low fanfare. Nobody knew at the time that this launch would shape our entire industry.</p><p><strong>The early days: Building blocks that just work</strong><br />At its core, S3 introduced two straightforward primitives: PUT to store an object and GET to retrieve it later. But the real innovation was the philosophy behind it: create building blocks that handle the undifferentiated heavy lifting, which freed developers to focus on higher-level work.</p><p>From day one, S3 was guided by five fundamentals that remain unchanged today.</p><p><strong>Security</strong> means your data is protected by default. <strong>Durability</strong> is designed for 11 nines (99.999999999%), and we operate S3 to be lossless. <strong>Availability</strong> is designed into every layer, with the assumption that failure is always present and must be handled. <strong>Performance</strong> is optimized to store virtually any amount of data without degradation. <strong>Elasticity</strong> means the system automatically grows and shrinks as you add and remove data, with no manual intervention required.</p><p>When we get these things right, the service becomes so straightforward that most of you never have to think about how complex these concepts are.</p><p><strong>S3 today: Scale beyond imagination</strong><br />Throughout 20 years, S3 has remained committed to its core fundamentals even as it’s grown to a scale that’s hard to comprehend.</p><p>When S3 first launched, it offered approximately one petabyte of total storage capacity across about 400 storage nodes in 15 racks spanning three data centers, with 15 Gbps of total bandwidth. We designed the system to store tens of billions of objects, with a maximum object size of 5 GB. The initial price was 15 cents per gigabyte.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/10/s3-illustration-2.png"><img class="aligncenter size-large wp-image-103329" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/10/s3-illustration-2-1024x538.png" alt="S3 key metrics illustration" width="1024" height="538" /></a></p><p>Today, S3 stores more than 500 trillion objects and serves more than 200 million requests per second globally across hundreds of exabytes of data in 123 Availability Zones in 39 AWS Regions, for millions of customers. The <a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-s3-maximum-object-size-50-tb/">maximum object size has grown from 5 GB to 50 TB</a>, a 10,000 fold increase. If you stacked all of the tens of millions S3 hard drives on top of each other, they would reach the International Space Station and almost back.</p><p>Even as S3 has grown to support this incredible scale, the price you pay has dropped. Today, AWS charges slightly over <a href="https://aws.amazon.com/s3/pricing/">2 cents per gigabyte</a>. That’s a price reduction of approximately 85% since launch in 2006. In parallel, we’ve continued to introduce ways to further optimize storage spend with storage tiers. For example, our customers have collectively saved more than $6 billion in storage costs by using <a href="https://aws.amazon.com/s3/storage-classes/intelligent-tiering/">Amazon S3 Intelligent-Tiering</a> as compared to <a href="https://aws.amazon.com/s3/storage-classes/">Amazon S3 Standard</a>.</p><p>Over the past two decades, the <a href="https://docs.aws.amazon.com/AmazonS3/latest/API/Welcome.html">S3 API</a> has been adopted and used as a reference point across the storage industry. Multiple vendors now offer S3 compatible storage tools and systems, implementing the same API patterns and conventions. This means skills and tools developed for S3 often transfer to other storage systems, making the broader storage landscape more accessible.</p><p>Despite all of this growth and industry adoption, perhaps the most remarkable achievement is this: the code you wrote for S3 in 2006 still works today, unchanged. Your data went through 20 years of innovation and technical advances. We migrated the infrastructure through multiple generations of disks and storage systems. All the code to handle a request has been rewritten. But the data you stored 20 years ago is still available today, and we’ve maintained complete API backward compatibility. That’s our commitment to delivering a service that continually “just works.”</p><p><strong>The engineering behind the scale</strong> <strong><br /></strong> What makes S3 possible at this scale? Continuous innovation in engineering.</p><p>Much of what follows is drawn from a conversation between Mai-Lan Tomsen Bukovec, VP of Data and Analytics at AWS, and <a href="https://www.linkedin.com/in/gergelyorosz/">Gergely Orosz</a> of <a href="https://newsletter.pragmaticengineer.com/podcast">The Pragmatic Engineer</a>. The <a href="https://newsletter.pragmaticengineer.com/p/how-aws-s3-is-built">in-depth interview</a> goes further into the technical details for those who want to go deeper. In the following paragraphs, I share some examples:</p><p>At the heart of S3 durability is a system of microservices that continuously inspect every single byte across the entire fleet. These auditor services examine data and automatically trigger repair systems the moment they detect signs of degradation. S3 is designed to be lossless: the 11 nines design goal reflects how the replication factor and re-replication fleet are sized, but the system is built so that objects aren’t lost.</p><p>S3 engineers use <a href="https://www.amazon.science/publications/using-lightweight-formal-methods-to-validate-a-key-value-storage-node-in-amazon-s3">formal methods and automated reasoning</a> in production to mathematically prove correctness. When engineers check in code to the index subsystem, automated proofs verify that consistency hasn’t regressed. This same approach proves correctness in <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/replication.html">cross-Region replication</a> or for <a href="https://aws.amazon.com/blogs/security/protect-sensitive-data-in-the-cloud-with-automated-reasoning-zelkova/">access policies</a>.</p><p>Over the past 8 years, AWS has been progressively rewriting performance-critical code in the S3 request path in Rust. Blob movement and disk storage have been rewritten, and work is actively ongoing across other components. Beyond raw performance, Rust’s type system and memory safety guarantees eliminate entire classes of bugs at compile time. This is an essential property when operating at S3 scale and correctness requirements.</p><p>S3 is built on a design philosophy: “Scale is to your advantage.” Engineers design systems so that increased scale improves attributes for all users. The larger S3 gets, the more de-correlated workloads become, which improves reliability for everyone.</p><p><strong>Looking forward</strong><br />The vision for S3 extends beyond being a storage service to becoming the universal foundation for all data and AI workloads. Our vision is simple: you store any type of data one time in S3, and you work with it directly, without moving data between specialized systems. This approach reduces costs, eliminates complexity, and removes the need for multiple copies of the same data.</p><p>Here are a few standout launches from recent years:</p><ul><li><a href="https://aws.amazon.com/blogs/aws/new-amazon-s3-tables-storage-optimized-for-analytics-workloads/">S3 Tables</a> – Fully managed Apache Iceberg tables with automated maintenance that optimize query efficiency and reduce storage cost over time.</li>
<li><a href="https://aws.amazon.com/blogs/aws/amazon-s3-vectors-now-generally-available-with-increased-scale-and-performance/">S3 Vectors</a> – Native vector storage for semantic search and RAG, supporting up to 2 billion vectors per index with sub-100ms query latency. In only 5 months (July–December 2025), you created more than 250,000 indices, ingested more than 40 billion vectors, and performed more than 1 billion queries.</li>
<li><a href="https://aws.amazon.com/blogs/aws/amazon-s3-metadata-now-supports-metadata-for-all-your-s3-objects/">S3 Metadata</a> – Centralized metadata for instant data discovery, removing the need to recursively list large buckets for cataloging and significantly reducing time-to-insight for large data lakes.</li>
</ul><p>Each of these capabilities operates at S3 cost structure. You can handle multiple data types that traditionally required expensive databases or specialized systems but are now economically feasible at scale.</p><p>From 1 petabyte to hundreds of exabytes. From 15 cents to 2 cents per gigabyte. From simple object storage to the foundation for AI and analytics. Through it all, our five fundamentals–security, durability, availability, performance, and elasticity–remain unchanged, and your code from 2006 still works today.</p><p>Here’s to the next 20 years of innovation on <a href="https://aws.amazon.com/s3/">Amazon S3</a>.</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="3b94ea0c-cf5d-4e8e-9437-7b8aaacae233" data-title="Twenty years of Amazon S3 and building what’s next" data-url="https://aws.amazon.com/blogs/aws/twenty-years-of-amazon-s3-and-building-whats-next/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/twenty-years-of-amazon-s3-and-building-whats-next/"/>
    <updated>2026-03-13T13:58:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/introducing-account-regional-namespaces-for-amazon-s3-general-purpose-buckets/</id>
    <title><![CDATA[Introducing account regional namespaces for Amazon S3 general purpose buckets]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing a new feature of <a href="https://aws.amazon.com/s3/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Simple Storage Service (Amazon S3)</a> you can use to create general purpose buckets in your own account regional namespace simplifying bucket creation and management as your data storage needs grow in size and scope. You can create general purpose bucket names across multiple AWS Regions with assurance that your desired bucket names will always be available for you to use.</p><p>With this feature, you can predictably name and create general purpose buckets in your own account regional namespace by appending your account’s unique suﬃx in your requested bucket name. For example, I can create the bucket <code>mybucket-123456789012-us-east-1-an</code> in my account regional namespace. <code>mybucket</code> is the bucket name prefix that I specified, then I add my account regional suffix to the requested bucket name: <code>-123456789012-us-east-1-an</code>. If another account tries to create buckets using my account’s suffix, their requests will be automatically rejected.</p><p>Your security teams can use <a href="https://aws.amazon.com/iam/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Identity and Access Management (AWS IAM)</a> policies and <a href="https://aws.amazon.com/organizations/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Organizations</a> service control policies to enforce that your employees only create buckets in their account regional namespace using the new <code>s3:x-amz-bucket-namespace</code> condition key, helping teams adopt the account regional namespace across your organization.</p><p><strong class="c6">Create your S3 bucket with account regional namespace in action</strong><br />To get started, choose <strong>Create bucket</strong> in the <a href="https://console.aws.amazon.com/s3?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon S3 console</a>. To create your bucket in your account regional namespace, choose <strong>Account regional namespace</strong>. If you choose this option, you can create your bucket with any name that is unique to your account and region.</p><p>This configuration supports all of the same features as general purpose buckets in the global namespace. The only difference is that only your account can use bucket names with your account’s suffix. The bucket name prefix and the account regional suffix combined must be between 3 and 63 characters long.</p><p><img class="aligncenter size-full wp-image-102981 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/12/2026-s3-bucket-account-regional-namespace.png" alt="" width="2098" height="2381" /></p><p>Using the <a href="https://aws.amazon.com/cli/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Command Line Interface (AWS CLI)</a>, you can create a bucket with account regional namespace by specifying the <code>x-amz-bucket-namespace:account-regional</code> request header and providing a compatible bucket name.</p><pre class="lang-bash">$ aws s3api create-bucket --bucket mybucket-123456789012-us-east-1-an \
   --bucket-namespace account-regional \
   --region us-east-1</pre><p>You can use the <a href="https://aws.amazon.com/sdk-for-python/">AWS SDK for Python (Boto3)</a> to create a bucket with account regional namespace using <code>CreateBucket</code> API request.</p><pre class="lang-python">import boto3
class AccountRegionalBucketCreator:
    """Creates S3 buckets using account-regional namespace feature."""
    ACCOUNT_REGIONAL_SUFFIX = "-an"
    def __init__(self, s3_client, sts_client):
        self.s3_client = s3_client
        self.sts_client = sts_client
    def create_account_regional_bucket(self, prefix):
        """
        Creates an account-regional S3 bucket with the specified prefix.
        Resolves caller AWS account ID using the STS GetCallerIdentity API.
        Format: ---an
        """
        account_id = self.sts_client.get_caller_identity()['Account']
        region = self.s3_client.meta.region_name
        bucket_name = self._generate_account_regional_bucket_name(
            prefix, account_id, region
        )
        params = {
            "Bucket": bucket_name,
            "BucketNamespace": "account-regional"
        }
        if region != "us-east-1":
            params["CreateBucketConfiguration"] = {
                "LocationConstraint": region
            }
        return self.s3_client.create_bucket(**params)
    def _generate_account_regional_bucket_name(self, prefix, account_id, region):
        return f"{prefix}-{account_id}-{region}{self.ACCOUNT_REGIONAL_SUFFIX}"
if __name__ == '__main__':
    s3_client = boto3.client('s3')
    sts_client = boto3.client('sts')
    creator = AccountRegionalBucketCreator(s3_client, sts_client)
    response = creator.create_account_regional_bucket('test-python-sdk')
    print(f"Bucket created: {response}")</pre><p>You can update your infrastructure as code (IaC) tools, such as <a href="https://aws.amazon.com/cloudformation/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS CloudFormation</a>, to simplify creating buckets in your account regional namespace. AWS CloudFormation offers the pseudo parameters, <code>AWS::AccountId</code> and <code>AWS::Region</code>, making it easy to build <a href="https://docs.aws.amazon.com/AWSCloudFormation/latest/TemplateReference/aws-resource-s3-bucket.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">CloudFormation templates</a> that create account regional namespace buckets.</p><p>The following example demonstrates how you can update your existing CloudFormation templates to start creating buckets in your account regional namespace:</p><pre class="lang-json">BucketName: !Sub "amzn-s3-demo-bucket-${AWS::AccountId}-${AWS::Region}-an"
BucketNamespace: "account-regional"</pre><p>Alternatively, you can also use the <code>BucketNamePrefix</code> property to update your CloudFormation template. By using the <code>BucketNamePrefix</code>, you can provide only the customer defined portion of the bucket name and then it automatically adds the account regional namespace suffix based on the requesting AWS account and Region specified.</p><pre class="lang-json">BucketNamePrefix: 'amzn-s3-demo-bucket'
BucketNamespace: "account-regional"
</pre><p>Using these options, you can build a custom CloudFormation template to easily create general purpose buckets in your account regional namespace.</p><p><strong>Things to know</strong><br />You can’t rename your existing global buckets to bucket names with account regional namespace, but you can create new general purpose buckets in your account regional namespace. Also, the account regional namespace is only supported for general purpose buckets. S3 table buckets and vector buckets already exist in an account-level namespace and S3 directory buckets exist in a zonal namespace.</p><p>To learn more, visit <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/gpbucketnamespaces.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Namespaces for general purpose buckets</a> in the Amazon S3 User Guide.</p><p><strong class="c6">Now available</strong><br />Creating general purpose buckets in your account regional namespace in Amazon S3 is now available in 37 AWS Regions including the AWS China and AWS GovCloud (US) Regions. You can create general purpose buckets in your account regional namespace at no additional cost.</p><p>Give it a try in the <a href="https://console.aws.amazon.com/s3?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon S3 console</a> today and send feedback to <a href="https://repost.aws/tags/TADSTjraA0Q4-a1dxk6eUYaw/amazon-simple-storage-service?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Amazon S3</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="6eb1e990-d30d-4de9-ac14-de5c634b2689" data-title="Introducing account regional namespaces for Amazon S3 general purpose buckets" data-url="https://aws.amazon.com/blogs/aws/introducing-account-regional-namespaces-for-amazon-s3-general-purpose-buckets/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/introducing-account-regional-namespaces-for-amazon-s3-general-purpose-buckets/"/>
    <updated>2026-03-12T22:18:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-connect-health-bedrock-agentcore-policy-gameday-europe-and-more-march-9-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Amazon Connect Health, Bedrock AgentCore Policy, GameDay Europe, and more (March 9, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Fiti AWS Student Community Kenya!</p><p>Last week was an incredible whirlwind: a round of meetups, hands-on workshops, and career discussions across Kenya that culminated with the AWS Student Community Day at <a href="https://www.linkedin.com/school/meru-university-of-science-and-technology-must/">Meru University of Science and Technology</a>, with keynotes from my colleagues <a href="https://www.linkedin.com/in/veliswa-boya/">Veliswa</a> and <a href="https://www.linkedin.com/in/tiffanysouterre/">Tiffany</a>, and sessions on everything from GitOps to cloud-native engineering, and a whole lot of AI agent building.</p><table><tbody><tr><td><img class="aligncenter wp-image-103322 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/09/1772482486843-1-1024x500.jpg" alt="" width="1024" height="500" /></td>
<td><img class="aligncenter wp-image-103323 size-large" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/09/2026-jaws-days-1-1024x500.jpg" alt="" width="1024" height="500" /></td>
</tr></tbody></table><p><a href="https://jawsdays2026.jaws-ug.jp/floormap/">JAWS Days 2026</a> is the largest AWS Community Day in the world, with over 1,500 attendees on March 7th. This event started with a keynote speech on building an AI-driven development team by <a href="https://www.linkedin.com/in/jeffbarr/">Jeff Barr</a>, and included over 100 technical and community experience sessions, lightning talks, and workshops such as Game Days, Builders Card Challenges, and networking parties.</p><p>Now, let’s get into this week’s AWS news…</p><p><strong>Last week’s launches</strong><br />Here are some launches and updates from this past week that caught my attention:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-connect-health-agentic-ai-healthcare/">Introducing Amazon Connect Health, Agentic AI Built for Healthcare</a> — Amazon Connect Health is now generally available with five purpose-built AI agents for healthcare: patient verification, appointment management, patient insights, ambient documentation, and medical coding. All features are HIPAA-eligible and deployable within existing clinical workflows in days.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/policy-amazon-bedrock-agentcore-generally-available/">Policy in Amazon Bedrock AgentCore is now generally available</a> — You can now use centralized, fine-grained controls for agent-tool interactions that operate outside your agent code. Security and compliance teams can define tool access and input validation rules using natural language that automatically converts to Cedar, the AWS open-source policy language.</li>
<li><a href="https://aws.amazon.com/blogs/aws/introducing-openclaw-on-amazon-lightsail-to-run-your-autonomous-private-ai-agents/">Introducing OpenClaw on Amazon Lightsail to run your autonomous private AI agents</a> — You can deploy a private AI assistant on your own cloud infrastructure with built-in security controls, sandboxed agent sessions, one-click HTTPS, and device pairing authentication. Amazon Bedrock serves as the default model provider, and you can connect to Slack, Telegram, WhatsApp, and Discord.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/vpc-encryption-controls-pricing/">AWS announces pricing for VPC Encryption Controls</a> — Starting March 1, 2026, VPC Encryption Controls transitions from free preview to a paid feature. You can audit and enforce encryption-in-transit of all traffic flows within and across VPCs in a region, with monitor mode to detect unencrypted traffic and enforce mode to prevent it.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/dbsp-opensearch-service-neptune-analytics/">Database Savings Plans now supports Amazon OpenSearch Service and Amazon Neptune Analytics</a> — You can save up to 35% on eligible serverless and provisioned instance usage with a one-year commitment. Savings Plans automatically apply regardless of engine, instance family, size, or AWS Region.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/elastic-beanstalk-ai-analysis/">AWS Elastic Beanstalk now offers AI-powered environment analysis</a> — When your environment health is degraded, Elastic Beanstalk can now collect recent events, instance health, and logs and send them to Amazon Bedrock for analysis, providing step-by-step troubleshooting recommendations tailored to your environment’s current state.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/aws-simplifies-iam-role-creation-and-setup/">AWS simplifies IAM role creation and setup in service workflows</a> — You can now create and configure IAM roles directly within service workflows through a new in-console panel, without switching to the IAM console. The feature supports Amazon EC2, Lambda, EKS, ECS, Glue, CloudFormation, and more.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/lambda-durable-kiro-power/">Accelerate Lambda durable functions development with new Kiro power</a> — You can now build resilient, long-running multi-step applications and AI workflows faster with AI agent-assisted development in Kiro. The power dynamically loads guidance on replay models, step and wait operations, concurrent execution patterns, error handling, and deployment best practices.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-gamelift-servers-ddos-protection/">Amazon GameLift Servers launches DDoS Protection</a> — You can now protect session-based multiplayer games against DDoS attacks with a co-located relay network that authenticates client traffic using access tokens and enforces per-player traffic limits, at no additional cost to GameLift Servers customers.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">What’s New with AWS</a> page.</p><p><strong>From AWS community</strong><br />Here are my personal favorite posts from AWS community and my colleagues:</p><ul><li><a href="https://builder.aws.com/content/3AhVKdfIvhOgaTT8Eu1PXzzLxRm/i-built-a-portable-ai-memory-layer-with-mcp-aws-bedrock-and-a-chrome-extension">I Built a Portable AI Memory Layer with MCP, AWS Bedrock, and a Chrome Extension</a> — Learn how to build a persistent memory layer for AI agents using MCP and Amazon Bedrock, packaged as a Chrome extension that carries context across sessions and applications.</li>
<li><a href="https://dev.to/aws/when-the-model-is-the-machine-25g4">When the Model Is the Machine</a> — Mike Chambers built an experimental app where an AI agent generates a complete, interactive web application at runtime from a single prompt — no codebase, no framework, no persistent state. A thought-provoking exploration of what happens when the model becomes the runtime.</li>
</ul><p><strong>Upcoming AWS events</strong><br />Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://builder.aws.com/content/39zVQT5ykq9bhnngp3kPeQNqjOc/aws-community-gameday-europe-on-the-1703-think-you-know-aws-come-prove-it">AWS Community GameDay Europe</a> — Think you know AWS? Prove it at the AWS Community GameDay Europe on March 17, a gamified learning event where teams compete to solve real-world technical challenges using AWS services.</li>
<li><a href="https://aws.amazon.com/events/aws-at-nvidia-gtc26/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS at NVIDIA GTC 2026</a> — Join us at our AWS sessions, booths, demos, and ancillary events in NVIDIA GTC 2026 on March 16 – 19, 2026 in San Jose. You can receive 20% off event passes through AWS and request a 1:1 meeting at GTC.</li>
<li><a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summits</a> — Join AWS Summits in 2026: free in-person events where you can explore emerging cloud and AI technologies, learn best practices, and network with industry peers and experts. Upcoming Summits include <a href="https://aws.amazon.com/events/summits/paris/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Paris</a> (April 1), <a href="https://aws.amazon.com/events/summits/london/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">London</a> (April 22), and <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Bengaluru</a> (April 23–24).</li>
<li><a href="https://aws.amazon.com/events/community-day/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Community Days</a> — Community-led conferences where content is planned, sourced, and delivered by community leaders. Upcoming events include <a href="https://www.awscommunityday.sk/">Slovakia</a> (March 11), <a href="https://www.awsugpune.in/">Pune</a> (March 21), and the AWSome Women Summit LATAM in <a href="https://www.awswomensummitlatam.com/home.html">Mexico City</a> (March 28)</li>
</ul><p>Browse here for upcoming <a href="https://aws.amazon.com/events/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">developer-focused events</a>.</p><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Weekly Roundup</a>!</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="e26a14bc-f45f-416c-b36b-f4c4072d4cca" data-title="AWS Weekly Roundup: Amazon Connect Health, Bedrock AgentCore Policy, GameDay Europe, and more (March 9, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-connect-health-bedrock-agentcore-policy-gameday-europe-and-more-march-9-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-connect-health-bedrock-agentcore-policy-gameday-europe-and-more-march-9-2026/"/>
    <updated>2026-03-09T17:15:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/introducing-openclaw-on-amazon-lightsail-to-run-your-autonomous-private-ai-agents/</id>
    <title><![CDATA[Introducing OpenClaw on Amazon Lightsail to run your autonomous private AI agents]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the general availability of <a href="https://openclaw.ai">OpenClaw</a> on <a href="https://aws.amazon.com/lightsail/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Lightsail</a> to launch OpenClaw instance, pairing your browser, enabling AI capabilities, and optionally connecting messaging channels. Your Lightsail OpenClaw instance is pre-configured with <a href="https://aws.amazon.com/bedrock">Amazon Bedrock</a> as the default AI model provider. Once you complete setup, you can start chatting with your AI assistant immediately — no additional configuration required.</p><p>OpenClaw is an open-source self-hosted autonomous private AI agent that acts as a personal digital assistant by running directly on your computer. You can AI agents on OpenClaw through your browser to connect to messaging apps like WhatsApp, Discord, or Telegram to perform tasks such as managing emails, browsing the web, and organizing files, rather than just answering questions.</p><p>AWS customers have asked if they can run OpenClaw on AWS. Some of them blogged about running OpenClaw on <a href="https://aws.amazon.com/ec2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2</a> instances. As someone who has experienced installing OpenClaw directly on my home device, I learned that this is not easy and that there are many security considerations.</p><p>So, let me introduce how to launch a pre-configured OpenClaw instance on Amazon Lightsail more easily and run it securely.</p><p><strong class="c6">OpenClaw on Amazon Lightsail in action</strong><br />To get started, go to the <a href="https://lightsail.aws.amazon.com/ls/webapp/home?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Lightsail console</a> and choose <strong>Create instance</strong> on the <strong>Instances</strong> section. After choosing your preferred AWS Region and Availability Zone, Linux/Unix platform to run your instance, choose OpenClaw under <strong>Select a blueprint</strong>.</p><p><img class="aligncenter wp-image-103267 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/04/2026-openclaw-lightsail-1.png" alt="" width="2138" height="1366" /></p><p>You can choose your instance plan (4 GB memory plan is recommended for optimal performance) and enter a name for your instance. Finally choose <strong>Create instance</strong>. Your instance will be in a <strong>Running</strong> state in a few minutes.</p><p><img class="aligncenter wp-image-103269 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/04/2026-openclaw-lightsail-2-1.png" alt="" width="2148" height="1673" /></p><p>Before you can use the OpenClaw dashboard, you should pair your browser with OpenClaw. This creates a secure connection between your browser session and OpenClaw. To pair your browser with OpenClaw, choose <strong>Connect using SSH</strong> in the <strong>Getting started</strong> tab.</p><p>When a browser-based SSH terminal opens, you can see the dashboard URL, security credentials displayed in the welcome message. Copy them and open the dashboard in a new browser tab. In the OpenClaw dashboard, you can paste the copied access token into the Gateway Token field in the OpenClaw dashboard.</p><p><img class="aligncenter wp-image-103287 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/04/2026-openclaw-lightsail-4.png" alt="" width="2046" height="1740" /></p><p>When prompted, press <code>y</code> to continue and <code>a</code> to approve with device pairing in the SSH terminal. When pairing is complete, you can see the <strong>OK</strong> status in the OpenClaw dashboard and your browser is now connected to your OpenClaw instance.</p><p><img class="aligncenter wp-image-103271 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/04/2026-openclaw-lightsail-5.png" alt="" width="2148" height="1526" /></p><p>Your OpenClaw instance on Lightsail is configured to use Amazon Bedrock to power its AI assistant. To enable Bedrock API access, copy the script in the <strong>Getting started</strong> tab and run copied script into the <a href="https://aws.amazon.com/cloudshell/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS CloudShell</a> terminal.</p><p><img class="aligncenter wp-image-103272 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/04/2026-openclaw-lightsail-3.png" alt="" width="2005" height="676" /></p><p>Once the script is complete, go to <strong>Chat</strong> in the OpenClaw dashboard to start using your AI assistant!</p><p>You can set up OpenClaw to work with messaging apps like Telegram and WhatsApp for interacting with your AI assistant directly from your phone or messaging client. To learn more, visit <a href="https://docs.aws.amazon.com/lightsail/latest/userguide/amazon-lightsail-quick-start-guide-openclaw.html#amazon-lightsail-openclaw-connect-messaging?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Get started with OpenClaw on Lightsail</a> in the Amazon Lightsail User Guide.</p><p><img class="aligncenter size-large wp-image-103279" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/04/2026-openclaw-lightsail-7-1024x413.png" alt="" width="1024" height="413" /></p><p><strong>Things to know</strong><br />Here are key considerations to know about this feature:</p><ul><li><strong>Permission</strong> — You can customize AWS IAM permissions granted to your OpenClaw instance. The setup script creates an IAM role with a policy that grants access to Amazon Bedrock. You can customize this policy at any time. But, you should be careful when modifying permissions because it may prevent OpenClaw from generating AI responses. To learn more, visit <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS IAM policies</a> in the AWS documentation</li>
<li><strong>Cost</strong> — You pay for the instance plan you selected on an on-demand hourly rate only for what you use. Every message sent to and received from the OpenClaw assistant is processed through Amazon Bedrock using a token-based pricing model. If you select a third-party model distributed through <a href="https://aws.amazon.com/marketplace/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Marketplace</a> such as Anthropic Claude or Cohere, there may be additional software fees on top of the per-token cost.</li>
<li><strong>Security</strong> — Running a personal AI agnet on OpenClaw is powerful, but it may cause security threat if you are careless. I recommend to hide your OpenClaw gateway never to expose it to open internet. The gateway auth token is your password, so rotate it often and store it in your envirnment file not hardcoded in config file. To learn more about security tips, visit <a href="https://docs.openclaw.ai/gateway/security">Security on OpenClaw gateway</a>.</li>
</ul><p><strong class="c6">Now available</strong><br />OpenClaw on Amazon Lightsail is now available in all AWS commercial Regions where <a href="https://docs.aws.amazon.com/lightsail/latest/userguide/understanding-regions-and-availability-zones-in-amazon-lightsail.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Lightsail is available</a>. For Regional availability and a future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>.</p><p>Give a try in the <a href="https://lightsail.aws.amazon.com/ls/webapp/home?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Lightsail console</a> and send feedback to <a href="https://repost.aws/tags/TAG40l8mpESXKixja2uhSvgQ/amazon-lightsail?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Amazon Lightsail</a> or through your usual AWS support contacts.</p><p>– <a href="https://linkedin.com/in/channy">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="c2ea70b9-d528-4143-9a6a-f2ade01b7254" data-title="Introducing OpenClaw on Amazon Lightsail to run your autonomous private AI agents" data-url="https://aws.amazon.com/blogs/aws/introducing-openclaw-on-amazon-lightsail-to-run-your-autonomous-private-ai-agents/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/introducing-openclaw-on-amazon-lightsail-to-run-your-autonomous-private-ai-agents/"/>
    <updated>2026-03-04T21:04:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-openai-partnership-aws-elemental-inference-strands-labs-and-more-march-2-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: OpenAI partnership, AWS Elemental Inference, Strands Labs, and more (March 2, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>This past week, I’ve been deep in the trenches helping customers transform their businesses through AI-DLC (AI-Driven Lifecycle) workshops. Throughout 2026, I’ve had the privilege of facilitating these sessions for numerous customers, guiding them through a structured framework that helps organizations identify, prioritize, and implement AI use cases that deliver measurable business value.</p><p><img class="alignnone size-large wp-image-103232" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/01/Screenshot-2026-03-01-at-11.34.10%E2%80%AFAM-1024x622.png" alt="Screenshot of GenAI Developer Hour" width="1024" height="622" /></p><p>AI-DLC is a methodology that takes companies from AI experimentation to production-ready solutions by aligning technical capabilities with business outcomes. If you’re interested in learning more, check out <a href="https://aws.amazon.com/blogs/devops/ai-driven-development-life-cycle/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">this blog post</a> that dives deeper into the framework, or watch as <a href="https://www.linkedin.com/in/riyadani/">Riya Dani</a> teaches me all about AI-DLC on our recent <a href="https://www.youtube.com/watch?v=5kUb_IZdlB8">GenAI Developer Hour livestream</a>!</p><p>Now, let’s get into this week’s AWS news…</p><p><img class="size-full wp-image-103235 alignright" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/03/02/2026-amazon-openai.png" alt="" width="150" height="130" /><a href="https://www.aboutamazon.com/news/aws/amazon-open-ai-strategic-partnership-investment?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">OpenAI and Amazon announced a multi-year strategic partnership</a> to accelerate AI innovation for enterprises, startups, and end consumers around the world. Amazon will invest $50 billion in OpenAI, starting with an initial $15 billion investment and followed by another $35 billion in the coming months when certain conditions are met. AWS and OpenAI are co-creating a Stateful Runtime Environment powered by OpenAI models, available through <a href="https://aws.amazon.com/bedrock/">Amazon Bedrock</a>, which allows developers to keep context, remember prior work, work across software tools and data sources, and access compute.</p><p>AWS will serve as the exclusive third-party cloud distribution provider for <a href="https://openai.com/index/introducing-openai-frontier/">OpenAI Frontier</a>, enabling organizations to build, deploy, and manage teams of AI agents. OpenAI and AWS are expanding their existing $38 billion multi-year agreement by $100 billion over 8 years, with OpenAI committing to consume approximately 2 gigawatts of Trainium capacity, spanning both Trainium3 and <a href="https://aws.amazon.com/ai/machine-learning/trainium/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">next-generation Trainium4 chips</a>.</p><p><strong>Last week’s launches</strong><br />Here are some launches and updates from this past week that caught my attention:</p><ul><li><a href="https://aws.amazon.com/blogs/aws/aws-security-hub-extended-offers-full-stack-enterprise-security-with-curated-partner-solutions/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Hub Extended offers full-stack enterprise security with curated partner solutions</a> — AWS launched Security Hub Extended, a plan that simplifies procurement, deployment, and integration of full-stack enterprise security solutions including 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk, Upwind, and Zscaler. With AWS as the seller of record, customers benefit from pre-negotiated pay-as-you-go pricing, a single bill, no long-term commitments, unified security operations within Security Hub, and unified Level 1 support for AWS Enterprise Support customers.</li>
<li><a href="https://aws.amazon.com/blogs/aws/transform-live-video-for-mobile-audiences-with-aws-elemental-inference/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Transform live video for mobile audiences with AWS Elemental Inference</a> — AWS launched Elemental Inference, a fully managed AI service that automatically transforms live and on-demand video for mobile and social platforms in real time. The service uses AI-powered cropping to create vertical formats optimized for TikTok, Instagram Reels, and YouTube Shorts, and automatically extracts highlight clips with 6-10 second latency. Beta testing showed large media companies achieved 34% or more savings on AI-powered live video workflows. Deep dive into the <a href="https://aws.amazon.com/blogs/media/how-aws-built-a-live-ai-powered-vertical-video-capability-for-fox-sports-with-aws-elemental-inference/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Fox Sports implementation</a>.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/aws-mediaconvert-introduces-video-probe/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">MediaConvert introduces new video probe API</a> — AWS Elemental MediaConvert introduced a free Probe API for quick metadata analysis of media files, reading header metadata to return codec specifications, pixel formats, and color space details without processing video content.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-bedrock-projects-api-mantle-inference-engine/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">OpenAI-compatible Projects API in Amazon Bedrock</a> — Projects API provides application-level isolation for your generative AI workloads using OpenAI-compatible APIs in the Mantle inference engine in Amazon Bedrock. You can organize and manage your AI applications with improved access control, cost tracking, and observability across your organization.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-location-service-introduces-kiro-power-claude-skill-llm-context/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Location Service introduces LLM Context</a> — Amazon Location launched curated AI Agent context as a Kiro power, Claude Code plugin, and agent skill in the open Agent Skills format, improving code accuracy and accelerating feature implementation for location-based capabilities.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-eks-node-monitoring-agent-open-source/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EKS Node Monitoring Agent is now open source</a> — The Amazon EKS Node Monitoring Agent is now open source on GitHub, allowing visibility into implementation, customization, and community contributions.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/aws-appconfig-new-relic-for-automated-rollback/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS AppConfig integrates with New Relic</a> — AWS AppConfig launched integration with New Relic Workflow Automation for automated, intelligent rollbacks during feature flag deployments, reducing detection-to-remediation time from minutes to seconds.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">What’s New with AWS</a> page.</p><p><strong>Other AWS news</strong><br />Here are some additional posts and resources that you might find interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/opensource/introducing-strands-labs-get-hands-on-today-with-state-of-the-art-experimental-approaches-to-agentic-development/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Introducing Strands Labs</a> — We created Strands Labs as a separate Git organization to support experimental agentic AI projects and push the frontier of agentic development. At launch, we’re making Strands Labs available with three projects. The first is <a href="https://github.com/strands-labs/robots">Robots</a>, the second is <a href="https://github.com/strands-labs/robots-sim">Robots Sim</a> and the third is <a href="https://github.com/strands-labs/ai-functions">AI Functions</a>.</li>
<li><a href="https://aws.amazon.com/blogs/architecture/6000-aws-accounts-three-people-one-platform-lessons-learned/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">6,000 AWS accounts, three people, one platform: Lessons learned</a> — Architecture blog post on managing massive multi-account environments. Learn how ProGlove implemented a large-scale account-per-tenant model on AWS and how that model shifts complexity from service code to platform operations.</li>
<li><a href="https://aws.amazon.com/blogs/machine-learning/building-intelligent-event-agents-using-amazon-bedrock-agentcore-and-amazon-bedrock-knowledge-bases/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Building intelligent event agents using Amazon Bedrock AgentCore and Amazon Bedrock Knowledge Bases</a> — Practical guide to building event-driven agents. Check out how you can use Amazon Bedrock AgentCore components to rapidly productionize an event assistant—taking it from prototype to enterprise-ready deployment at scale.</li>
</ul><p><strong>From AWS community</strong><br />Here are my personal favorite posts from AWS community:</p><ul><li><a href="https://builder.aws.com/content/3AFEHrVf0iugHBclfZGPGDGAfm0/how-to-run-a-kiro-ai-coding-workshop-that-actually-works?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">How to Run a Kiro AI Coding Workshop That Actually Works</a> — Running a Kiro workshop at your company or user group? Here is the full step-by-step facilitator guide, resources, and references.</li>
<li><a href="https://builder.aws.com/content/3AAxqZdFuNaiEWCZIiVYlpbt3ml/rag-vs-graphrag-when-agents-hallucinate-answers?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">RAG vs GraphRAG: When Agents Hallucinate Answers</a> — This demo builds a travel booking agent with Strands Agents and compares RAG (FAISS) vs GraphRAG (Neo4j) to measure which approach reduces hallucinations when answering queries</li>
<li><a href="https://aws.amazon.com/blogs/developer/announcing-new-output-formats-in-aws-cli-v2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">New output formats in AWS CLI v2</a> — You can now use two new features for the AWS Command Line Interface (AWS CLI) v2: structured error output and the “off” output format.</li>
</ul><p><strong>Upcoming AWS events</strong><br />Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/aws-at-nvidia-gtc26/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS at NVIDIA GTC 2026</a> — Join us at our AWS sessions, booths, demos, ancillary events in NVIDIA GTC 2026 on March 16 – 19, 2026 in San Jose. You can receive 20% off event passes through AWS and request a 1:1 meeting at GTC.</li>
<li><a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summits</a> — Join AWS Summits in 2026, free in-person events where you can explore emerging cloud and AI technologies, learn best practices, and network with industry peers and experts. Upcoming Summits include <a href="https://aws.amazon.com/events/summits/paris/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Paris</a> (April 1), <a href="https://aws.amazon.com/events/summits/london/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">London</a> (April 22), and <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Bengaluru</a> (April 23–24).</li>
<li><a href="https://aws.amazon.com/events/community-day/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Community Days</a> — Community-led conferences where content is planned, sourced, and delivered by community leaders. Upcoming events include <a href="https://jawsdays2026.jaws-ug.jp/">JAWS Days in Tokyo</a> (March 7), <a href="https://www.acdchennai.com/">Chennai</a> (March 7), <a href="https://www.awscommunityday.sk/">Slovakia</a> (March 11), and <a href="https://www.awsugpune.in/">Pune</a> (March 21).</li>
</ul><p>Browse here for upcoming <a href="https://aws.amazon.com/events/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">developer-focused events</a>.</p><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Weekly Roundup</a>!</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="0b7e0f18-6c19-4a65-be2d-a6152907127f" data-title="AWS Weekly Roundup: OpenAI partnership, AWS Elemental Inference, Strands Labs, and more (March 2, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-openai-partnership-aws-elemental-inference-strands-labs-and-more-march-2-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-openai-partnership-aws-elemental-inference-strands-labs-and-more-march-2-2026/"/>
    <updated>2026-03-02T20:05:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-security-hub-extended-o%EF%AC%80ers-full-stack-enterprise-security-with-curated-partner-solutions/</id>
    <title><![CDATA[AWS Security Hub Extended oﬀers full-stack enterprise security with curated partner solutions]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>At re:Invent 2025, we <a href="https://aws.amazon.com/blogs/aws/aws-security-hub-now-generally-available-with-near-real-time-analytics-and-risk-prioritization/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">introduced</a> a completely re-imagined <a href="https://aws.amazon.com/security-hub/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Hub</a> that unifies AWS security services, including <a href="https://aws.amazon.com/guardduty/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon GuardDuty</a> and <a href="https://aws.amazon.com/inspector/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Inspector</a> into a single experience. This unified experience automatically and continuously analyzes security findings in combination to help you prioritize and respond to your critical security risks.</p><p class="jss271" data-pm-slice="1 1 []">Today, we’re announcing <a href="https://aws.amazon.com/security-hub/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Hub Extended</a>, a plan of Security Hub that simplifies how you procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, and security operations. With the Extended plan, you can expand your security portfolio beyond AWS to help protect your enterprise estate through a curated selection of AWS Partner solutions, including 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk, a Cisco company, Upwind, and Zscaler.</p><p>With AWS as the seller of record, you benefit from pre-negotiated pay-as-you-go pricing, a single bill, and no long-term commitments. You can also get unified security operations experience within Security Hub and unified Level 1 support for <a href="https://aws.amazon.com/premiumsupport/plans/enterprise/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Enterprise Support customers</a>. You told us that managing multiple procurement cycles and vendor negotiations was creating unnecessary complexity, costing you time and resources. In response, we’ve curated these partner offerings for you to establish more comprehensive protection across your entire technology stack through a single, simplified experience.</p><p>Security findings from all participating solutions are emitted in the <a href="https://github.com/ocsf">Open Cybersecurity Schema Framework (OCSF)</a> schema and automatically aggregated in AWS Security Hub. With the Extended plan, you can combine AWS and partner security solutions to quickly identify and respond to risks that span boundaries.</p><p><strong class="c6">The Security Hub Extended plan in action</strong><br />You can access the partner solutions directly within the <a href="https://console.aws.amazon.com/securityhub/v2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Security Hub console</a> by selecting <strong>Extended plan</strong> under the <strong>Management</strong> menu. From there, you can review and deploy any combination of curated and partner offerings.</p><p><img class="aligncenter wp-image-103186 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/26/2026-security-hub-extended-plan1.jpg" alt="" width="1800" height="1033" /></p><p>You can review details of each partner offering directly in the Security Hub console and subscribe. When you subscribe, you’ll be directed to an automated on-boarding experience from each partner. Once onboarded, consumption-based metering is automatic and you are billed monthly as part of your Security Hub bill.</p><p><img class="aligncenter wp-image-103178 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/26/2026-security-hub-extended-plan2.jpg" alt="" width="2406" height="1156" /></p><p>Security findings from all solutions are automatically consolidated in AWS Security Hub. This gives you immediate and direct access to all security findings in normalized OCSF schema.</p><p>To learn more about how to enhance your security posture with these integrations for AWS Security Hub, visit the <a href="https://docs.aws.amazon.com/securityhub/latest/userguide/what-are-securityhub-services.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Hub User Guide</a>.</p><p><strong class="c6">Now available</strong><br />The AWS Security Hub Extended plan is now generally available in all AWS commercial Regions where Security Hub is available. You can use flexible pay-as-you-go or flat-rate pricing—no upfront investments or long-term commitments required. For more information about pricing, visit the <a href="https://aws.amazon.com/security-hub/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Hub pricing page</a>.</p><p>Give it a try today in the <a href="https://console.aws.amazon.com/securityhub/v2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Security Hub console</a> and send feedback to <a href="https://repost.aws/tags/TAFZPV4oyuS6-TWxLQfz5qSQ?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Security Hub</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="2dd2089c-42f2-465e-b738-6f7ba342e311" data-title="AWS Security Hub Extended oﬀers full-stack enterprise security with curated partner solutions" data-url="https://aws.amazon.com/blogs/aws/aws-security-hub-extended-o%EF%AC%80ers-full-stack-enterprise-security-with-curated-partner-solutions/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-security-hub-extended-o%EF%AC%80ers-full-stack-enterprise-security-with-curated-partner-solutions/"/>
    <updated>2026-02-26T19:52:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-security-hub-extended-offers-full-stack-enterprise-security-with-curated-partner-solutions/</id>
    <title><![CDATA[AWS Security Hub Extended oﬀers full-stack enterprise security with curated partner solutions]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>At re:Invent 2025, we <a href="https://aws.amazon.com/blogs/aws/aws-security-hub-now-generally-available-with-near-real-time-analytics-and-risk-prioritization/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">introduced</a> a completely re-imagined <a href="https://aws.amazon.com/security-hub/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Hub</a> that unifies AWS security services, including <a href="https://aws.amazon.com/guardduty/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon GuardDuty</a> and <a href="https://aws.amazon.com/inspector/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Inspector</a> into a single experience. This unified experience automatically and continuously analyzes security findings in combination to help you prioritize and respond to your critical security risks.</p><p class="jss271" data-pm-slice="1 1 []">Today, we’re announcing <a href="https://aws.amazon.com/security-hub/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Hub Extended</a>, a plan of Security Hub that simplifies how you procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, and security operations. With the Extended plan, you can expand your security portfolio beyond AWS to help protect your enterprise estate through a curated selection of AWS Partner solutions, including 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk, a Cisco company, Upwind, and Zscaler.</p><p>With AWS as the seller of record, you benefit from pre-negotiated pay-as-you-go pricing, a single bill, and no long-term commitments. You can also get unified security operations experience within Security Hub and unified Level 1 support for <a href="https://aws.amazon.com/premiumsupport/plans/enterprise/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Enterprise Support customers</a>. You told us that managing multiple procurement cycles and vendor negotiations was creating unnecessary complexity, costing you time and resources. In response, we’ve curated these partner offerings for you to establish more comprehensive protection across your entire technology stack through a single, simplified experience.</p><p>Security findings from all participating solutions are emitted in the <a href="https://github.com/ocsf">Open Cybersecurity Schema Framework (OCSF)</a> schema and automatically aggregated in AWS Security Hub. With the Extended plan, you can combine AWS and partner security solutions to quickly identify and respond to risks that span boundaries.</p><p><strong class="c6">The Security Hub Extended plan in action</strong><br />You can access the partner solutions directly within the <a href="https://console.aws.amazon.com/securityhub/v2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Security Hub console</a> by selecting <strong>Extended plan</strong> under the <strong>Management</strong> menu. From there, you can review and deploy any combination of curated and partner offerings.</p><p><img class="aligncenter wp-image-103186 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/26/2026-security-hub-extended-plan1.jpg" alt="" width="1800" height="1033" /></p><p>You can review details of each partner offering directly in the Security Hub console and subscribe. When you subscribe, you’ll be directed to an automated on-boarding experience from each partner. Once onboarded, consumption-based metering is automatic and you are billed monthly as part of your Security Hub bill.</p><p><img class="aligncenter wp-image-103178 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/26/2026-security-hub-extended-plan2.jpg" alt="" width="2406" height="1156" /></p><p>Security findings from all solutions are automatically consolidated in AWS Security Hub. This gives you immediate and direct access to all security findings in normalized OCSF schema.</p><p>To learn more about how to enhance your security posture with these integrations for AWS Security Hub, visit the <a href="https://docs.aws.amazon.com/securityhub/latest/userguide/what-are-securityhub-services.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Hub User Guide</a>.</p><p><strong class="c6">Now available</strong><br />The AWS Security Hub Extended plan is now generally available in all AWS commercial Regions where Security Hub is available. You can use flexible pay-as-you-go or flat-rate pricing—no upfront investments or long-term commitments required. For more information about pricing, visit the <a href="https://aws.amazon.com/security-hub/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Security Hub pricing page</a>.</p><p>Give it a try today in the <a href="https://console.aws.amazon.com/securityhub/v2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Security Hub console</a> and send feedback to <a href="https://repost.aws/tags/TAFZPV4oyuS6-TWxLQfz5qSQ?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Security Hub</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="2dd2089c-42f2-465e-b738-6f7ba342e311" data-title="AWS Security Hub Extended oﬀers full-stack enterprise security with curated partner solutions" data-url="https://aws.amazon.com/blogs/aws/aws-security-hub-extended-offers-full-stack-enterprise-security-with-curated-partner-solutions/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-security-hub-extended-offers-full-stack-enterprise-security-with-curated-partner-solutions/"/>
    <updated>2026-02-26T19:52:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/transform-live-video-for-mobile-audiences-with-aws-elemental-inference/</id>
    <title><![CDATA[Transform live video for mobile audiences with AWS Elemental Inference]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing <a href="https://aws.amazon.com/elemental-inference/">AWS Elemental Inference</a>, a fully managed AI service that automatically transforms and maximizes live and on-demand video broadcasts to engage audiences at scale. At launch, you’ll be able to use AWS Elemental Inference to adapt video content into vertical formats optimized for mobile and social platforms in real time.</p><p>With AWS Elemental Inference, broadcasters and streamers can reach audiences on social and mobile platforms such as TikTok, Instagram Reels, and YouTube Shorts without manual postproduction work or AI expertise.</p><p>Today’s viewers consume content differently than they did even a few years ago. However, most broadcasts are produced in landscape format for traditional viewing. Converting these broadcasts into vertical formats for mobile platforms typically requires time-consuming manual editing that causes broadcasters and streamers to miss viral moments and lose audiences to mobile-first destinations.</p><p><strong>Let’s try it out<br /></strong> AWS Elemental Inference offers flexible deployment options to fit your existing workflow. You can choose to create a feed through the standalone console or configure AWS Elemental Inference through the <a href="https://aws.amazon.com/medialive/">AWS Elemental MediaLive</a> console.</p><p><img class="alignnone size-large wp-image-103082" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/17/elemental-01-1024x557.png" alt="AWS Elemental Inference console" width="1024" height="557" /></p><p>To get started with AWS Elemental Inference, navigate to the <a href="https://aws.amazon.com/console/">AWS Management Console</a> and choose <strong>AWS Elemental Inference</strong>. From the dashboard, choose <strong>Create feed</strong> to establish your top-level resource for AI-powered video processing. A feed contains your feature configurations and begins in CREATING state before transitioning to AVAILABLE when ready.</p><p><img class="alignnone size-large wp-image-103083" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/17/elemental-02-1024x597.png" alt="AWS Elemental Inference console" width="1024" height="597" /></p><p>After creating your feed, you can configure outputs for either vertical video cropping or clip generation. For cropping, you can start with an empty feed. The service automatically manages cropping parameters based on your video specifications. For clip generation, choose <strong>Add output</strong>, provide a name (such as “highlight-clips”), select <strong>Clipping</strong> as the output type, and set the status to <strong>ENABLED</strong>.</p><p>This standalone interface provides a streamlined experience for configuring and managing your AI-powered video transformations, making it straightforward to get started with vertical video creation and clip generation.</p><p><img class="alignnone size-large wp-image-103084" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/17/medialive-01-1024x448.png" alt="AWS MediaLive inference" width="1024" height="448" /></p><p>Alternatively, you can enable AWS Elemental Inference directly within your AWS Elemental MediaLive channel configuration. You can use this integrated approach to add AI capabilities to your existing live video workflows without modifying your architecture. Enable the features you need as part of your channel setup, and AWS Elemental Inference will work in parallel with your video encoding.</p><p><img class="alignnone size-large wp-image-103085" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/17/medialive-03-1024x736.png" alt="AWS MediaLive inference console" width="1024" height="736" /></p><p>After it’s enabled, you can configure <strong>Smart Crop</strong> with outputs for different resolution specifications within an <strong>Output group</strong>.</p><p><img class="alignnone size-large wp-image-103086" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/17/medialive-05-1024x790.png" alt="AWS MediaLive inference console" width="1024" height="790" /></p><p>AWS Elemental MediaLive now includes a dedicated AWS Elemental Inference tab on the channel details page, providing a centralized view of your AI-powered video transformation configuration. The tab displays the service <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference-arns.html">Amazon Resource Name (ARN)</a>, data endpoints, and feed output details, including which features, such as Smart Crop, are enabled and their current operational status.</p><p><strong>How AWS Elemental Inference works<br /></strong> The service uses an agentic AI application that analyses video in real time and automatically applies the right optimizations at the right moments. Detection of vertical video cropping and clip generation happens independently, executing multistep transformations that require no human intervention to extract value.</p><p>AWS Elemental Inference analyzes video and automatically applies AI capabilities with no human-in-the-loop prompting required. While you focus on quality video production, the service autonomously optimizes content to create personalized content experiences for your audience.</p><p>AWS Elemental Inference applies AI capabilities in parallel with live video, achieving 6–10 second latency compared to minutes for traditional postprocessing approaches. This “process once, optimize everywhere” method runs multiple AI features simultaneously on the same video stream, eliminating the need to reprocess content for each capability.</p><p>The service integrates seamlessly with AWS Elemental MediaLive, so you can enable AI features without modifying your existing video architecture. AWS Elemental Inference uses fully managed <a href="https://aws.amazon.com/what-is/foundation-models/">foundation models (FMs)</a> that are automatically updated and optimized, so you don’t need dedicated AI teams or specialized expertise.</p><p><strong>Key features at launch<br /></strong> Enjoy the following key features when AWS Elemental Inference launches:</p><ul><li>Vertical video creation – AI-powered cropping intelligently transforms landscape broadcasts into vertical formats (9:16 aspect ratio) optimized for social and mobile platforms. The service tracks subjects and keeps key action visible, maintaining broadcast quality while automatically reformatting content for mobile viewing.</li>
<li>Clip generation with advanced metadata analysis – Automatically detects and extracts clips from live content, highlighting moments for real-time distribution. For live broadcasts, this means identifying game-winning plays in soccer and basketball—reducing manual editing from hours to minutes.</li>
</ul><p>Keep an eye on this space as more features and capabilities will be introduced throughout this year, including tighter integration with core <a href="https://aws.amazon.com/media-services/elemental/">AWS Elemental</a> services and features to help customers monetize their video content.</p><p><strong>Now available<br /></strong> AWS Elemental Inference is available today in 4 <a href="https://aws.amazon.com/about-aws/global-infrastructure/regions_az/">AWS Regions</a>: US East (N. Virginia), US West (Oregon), Europe (Ireland), and Asia Pacific (Mumbai). You can enable AWS Elemental Inference through the AWS Elemental MediaLive console or integrate it into your workflows using the <a href="https://docs.aws.amazon.com/medialive/latest/apireference/what-is.html">AWS Elemental MediaLive APIs</a>.</p><p>With consumption-based pricing, you pay only for the features you use and the video you process, with no upfront costs or commitments. This means you can scale during peak events and optimize costs during quieter periods.</p><p>To learn more about AWS Elemental Inference, visit the <a href="https://aws.amazon.com/elemental-inference">AWS Elemental Inference product page</a>. For technical implementation details, see the <a href="https://docs.aws.amazon.com/elemental-inference">AWS Elemental Inference documentation</a>.</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="f941fd3e-843b-49f9-b8ff-76fd23c26059" data-title="Transform live video for mobile audiences with AWS Elemental Inference" data-url="https://aws.amazon.com/blogs/aws/transform-live-video-for-mobile-audiences-with-aws-elemental-inference/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/transform-live-video-for-mobile-audiences-with-aws-elemental-inference/"/>
    <updated>2026-02-24T19:55:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-sonnet-4-6-in-amazon-bedrock-kiro-in-govcloud-regions-new-agent-plugins-and-more-february-23-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Claude Sonnet 4.6 in Amazon Bedrock, Kiro in GovCloud Regions, new Agent Plugins, and more (February 23, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Last week, my team met many developers at <a href="https://www.developerweek.com/">Developer Week</a> in San Jose. My colleague, Vinicius Senger delivered a great keynote about renascent software—a new way of building and evolving applications where humans and AI collaborate as co-developers using Kiro. Other colleagues spoke about building and deploying production-ready AI agents. Everyone stayed to ask and hear the questions related to agent memory, multi-agent patterns, meta-tooling and hooks. It was interesting how many developers were actually building agents.</p><p><img class="aligncenter size-full wp-image-103102" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/20/2026-developer-week-conference.jpg" alt="" width="1800" height="594" /></p><p>We are continuing to meet developers and hear their feedback at third-party developer conferences. You can meet us at the <a href="https://devnexus.com/">dev/nexus</a>, the largest and longest-running Java ecosystem conference on March 4-6 in Atlanta. My colleague, <a href="https://devnexus.com/speakers/james-ward">James Ward</a> will speak about building AI Agents with Spring and MCP, and <a href="https://devnexus.com/speakers/vinicius-senger">Vinicius Senger</a> and <a href="https://devnexus.com/speakers/jonathan-vogel">Jonathan Vogel</a> will speak about 10 tools and tips to upgrade your Java code with AI. I’ll keep sharing places for you to connect with us.</p><p><strong>Last week’s launches</strong><br />Here are some of the other announcements from last week:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/claude-sonnet-4.6-available-in-amazon-bedrock/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Claude Sonnet 4.6 model in Amazon Bedrock</a> – You can now use Claude Sonnet 4.6 which offers frontier performance across coding, agents, and professional work at scale. Claude Sonnet 4.6 approaches Opus 4.6 intelligence at a lower cost. It enables faster, high-quality task completion, making it ideal for high-volume coding and knowledge work use cases.</li>
<li><a href="https://aws.amazon.com/blogs/aws/amazon-ec2-hpc8a-instances-powered-by-5th-gen-amd-epyc-processors-are-now-available/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 Hpc8a instances powered by 5th Gen AMD EPYC processors</a> – You can use new Hpc8a instances delivering up to 40% higher performance, increased memory bandwidth, and 300 Gbps Elastic Fabric Adapter networking. You can accelerate compute-intensive simulations, engineering workloads, and tightly coupled HPC applications.</li>
<li><a href="https://aws.amazon.com/blogs/aws/announcing-amazon-sagemaker-inference-for-custom-amazon-nova-models/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon SageMaker Inference for custom Amazon Nova models</a> – You can now configure the instance types, auto-scaling policies, and concurrency settings for custom Nova model deployments with Amazon SageMaker Inference to best meet your needs.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-ec2-nested-virtualization-on-virtual/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Nested virtualization on virtual Amazon EC2 instances</a> – You can create nested virtual machines by running KVM or Hyper-V on virtual EC2 instances. You can leverage this capability for use cases such as running emulators for mobile applications, simulating in-vehicle hardware for automobiles, and running Windows Subsystem for Linux on Windows workstations.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-aurora-server-side-encryption-at-rest/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Server-Side Encryption by default in Amazon Aurora</a> – Amazon Aurora further strengthens your security posture by automatically applying server-side encryption by default to all new databases clusters using AWS-owned keys. This encryption is fully managed, transparent to users, and with no cost or performance impact.</li>
<li><a href="https://kiro.dev/blog/introducing-govcloud/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Kiro in AWS GovCloud (US) Regions</a> – You can use Kiro for the development teams behind government missions. Developers in regulated environments can now leverage Kiro’s agentic AI tool with the rigorous security controls required.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">What’s New with AWS</a> page.</p><p><strong>Additional updates</strong><br />Here are some additional news items that you might find interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/developer/introducing-agent-plugins-for-aws/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Introducing Agent Plugins for AWS</a> – You can see how new open-source Agent Plugins for AWS extend coding agents with skills for deploying applications to AWS. Using the <code>deploy-on-aws</code> plugin, you can generate architecture recommendations, cost estimates, and infrastructure-as-code directly from your coding agent.</li>
<li><a href="https://www.allthingsdistributed.com/2026/02/a-chat-with-byron-cook-on-automated-reasoning-and-trust-in-ai-systems.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">A chat with Byron Cook on automated reasoning and trust in AI systems</a> – You can hear how to verify AI systems doing the right thing using automated reasoning when they generate code or manage critical decisions. Byron Cook’s team has spent a decade proving correctness in AWS and apply those techniques to agentic systems.</li>
<li><a href="https://aws.amazon.com/blogs/devops/best-practices-for-deploying-aws-devops-agent-in-production/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Best practices for deploying AWS DevOps Agent in production</a> – You can read best practices for setting up DevOps Agent Spaces that balance investigation capability with operational efficiency. According to <a href="https://www.linkedin.com/posts/swaminathansivasubramanian_what-happens-when-an-application-goes-down-activity-7429241370197880832-hDHh?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAABGHXYBf20AS88WHERjRIUKOnefBR3chJA">Swami Sivasubramanian</a>, AWS DevOps Agent, a frontier agent that resolves and proactively prevents incidents, has handled thousands of escalations, with an estimated root cause identification rate of over 86% within Amazon.</li>
</ul><p><strong>From AWS community</strong><br />Here are my personal favorite posts from AWS community:</p><ul><li><a href="https://dev.to/aws/everything-you-need-to-know-about-aws-for-your-first-developer-job-52o2">Everything You Need to Know About AWS for Your First Developer Job</a> – Your first week as a developer will not look like the tutorials you followed previous. Read Ifeanyi Otuonye’s real-world AWS guide for your first job.</li>
<li><a href="https://builder.aws.com/content/39P4kYpFQyYBeumcrXQp6IGhhDc/let-an-ai-agent-do-your-job-searching?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Let an AI Agent Do Your Job Searching</a> – Still manually checking career pages during a job search? AWS Hero Danielle H. built an AI agent that does the work for you.</li>
<li><a href="https://builder.aws.com/content/3A1s1pHJUvbDQW227CLmcKw17OQ/building-the-aws-serverless-power-for-kiro?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Building the AWS Serverless Power for Kiro</a> – A former AWS Serverless Hero, Gunnar Grosch built a Kiro Power to integrate 25 MCP tools, ten steering guides, and structured decision guidance for the full development lifecycle.</li>
</ul><p>Join the <a href="https://builder.aws.com/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Builder Center</a> to connect with community, share knowledge, and access content that supports your development.</p><p><strong>Upcoming AWS events</strong><br />Check your calendar and sign up for upcoming AWS events:</p><ul><li><a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Summits</a> – Join AWS Summits in 2026, free in-person events where you can explore emerging cloud and AI technologies, learn best practices, and network with industry peers and experts. Upcoming Summits include <a href="https://aws.amazon.com/events/summits/paris/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Paris</a> (April 1), <a href="https://aws.amazon.com/events/summits/london/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">London</a> (April 22), and <a href="https://aws.amazon.com/events/summits/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Bengaluru</a> (April 23–24).</li>
<li><a href="https://builder.aws.com/content/38zSJWK4FkDqvJDwnQ0n9nqKvSx/announcing-amazon-nova-ai-hackathon-turn-your-ideas-into-reality?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Nova AI Hackathon</a> – Join developers worldwide to build innovative generative AI solutions using frontier foundation models and compete for $40,000 in prizes across five categories including agentic AI, multimodal understanding, UI automation, and voice experiences during this six-week challenge from February 2nd to March 16th, 2026.</li>
<li><a href="https://aws.amazon.com/events/community-day/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Community Days</a> – Community-led conferences where content is planned, sourced, and delivered by community leaders, featuring technical discussions, workshops, and hands-on labs. Upcoming events include <a href="https://awsahmedabad.community/">Ahmedabad</a> (February 28), <a href="https://jawsdays2026.jaws-ug.jp/">JAWS Days in Tokyo</a> (March 7), <a href="https://www.acdchennai.com/">Chennai</a> (March 7), <a href="https://www.awscommunityday.sk/">Slovakia</a> (March 11), and <a href="https://www.awsugpune.in/">Pune</a> (March 21).</li>
</ul><p>Browse here for upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS led in-person and virtual events</a>, <a href="https://aws.amazon.com/startups/events?tab=upcoming">startup events</a>, and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused events</a>.</p><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Weekly Roundup</a>!</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="6397d396-c915-4dac-843f-ffb9b9f335f4" data-title="AWS Weekly Roundup: Claude Sonnet 4.6 in Amazon Bedrock, Kiro in GovCloud Regions, new Agent Plugins, and more (February 23, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-sonnet-4-6-in-amazon-bedrock-kiro-in-govcloud-regions-new-agent-plugins-and-more-february-23-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-sonnet-4-6-in-amazon-bedrock-kiro-in-govcloud-regions-new-agent-plugins-and-more-february-23-2026/"/>
    <updated>2026-02-23T17:56:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-ec2-hpc8a-instances-powered-by-5th-gen-amd-epyc-processors-are-now-available/</id>
    <title><![CDATA[Amazon EC2 Hpc8a Instances powered by 5th Gen AMD EPYC processors are now available]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the general availability of <a href="https://aws.amazon.com/ec2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Compute Cloud (Amazon EC2)</a> Hpc8a instances, a new high performance computing (HPC) optimized instance type powered by latest 5th Generation AMD EPYC processors with a maximum frequency of up to 4.5 GHz. These instances are ideal for compute-intensive tightly coupled HPC workloads, including computational fluid dynamics, simulations for faster design iterations, high-resolution weather modeling within tight operational windows, and complex crash simulations that require rapid time-to-results.</p><p>The new Hpc8a instances deliver up to 40% higher performance, 42% greater memory bandwidth, and up to 25% better price-performance compared to previous generation <a href="https://aws.amazon.com/blogs/aws/new-amazon-ec2-hpc7a-instances-powered-by-4th-gen-amd-epyc-processors-optimized-for-high-performance-computing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Hpc7a instances</a>. Customers benefit from the high core density, memory bandwidth, and low-latency networking that helped them scale efficiently and reduce job completion times for their compute-intensive simulation workloads.</p><p><strong class="c6">Hpc8a instances</strong><br />Hpc8a instances are available with 192 cores, 768 GiB memory, and 300 Gbps <a href="https://aws.amazon.com/hpc/efa/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Elastic Fabric Adapter (EFA)</a> networking to run applications requiring high levels of inter node communications at scale.</p><table class="c10"><tbody><tr class="c8"><td class="c7"><strong>Instance Name</strong></td>
<td class="c7"><strong>Physical Cores</strong></td>
<td class="c7"><strong>Memory (Gib)</strong></td>
<td class="c7"><strong>EFA Network Bandwidth (Gbps)</strong></td>
<td class="c7"><strong>Network Bandwidth (Gbps)</strong></td>
<td class="c7"><strong>Attached Storage</strong></td>
</tr><tr class="c9"><td class="c7"><strong>Hpc8a.96xlarge</strong></td>
<td class="c7">192</td>
<td class="c7">768</td>
<td class="c7">Up to 300</td>
<td class="c7">75</td>
<td class="c7">EBS Only</td>
</tr></tbody></table><p>Hpc8a instances are available in a single <strong>96xlarge</strong> size with a 1:4 core-to-memory ratio. You will have the capability to right size based on HPC workload requirements by customizing the number of cores needed at launch instances. These instances also use sixth-generation <a href="https://aws.amazon.com/ec2/nitro/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Nitro</a> cards, which offload CPU virtualization, storage, and networking functions to dedicated hardware and software, enhancing performance and security for your workloads.</p><p>You can use Hpc8a instances with <a href="https://aws.amazon.com/hpc/parallelcluster/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS ParallelCluster</a> and <a href="https://aws.amazon.com/pcs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Parallel Computing Service (AWS PCS)</a> to simplify workload submission and cluster creation and <a href="https://aws.amazon.com/fsx/lustre/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon FSx for Lustre</a> for sub-millisecond latencies and up to hundreds of gigabytes per second of throughput for storage. To achieve the best performance for HPC workloads, these instances have Simultaneous Multithreading (SMT) disabled.</p><p><strong class="c6">Now available</strong><br />Amazon EC2 Hpc8a instances are now available in US East (Ohio) and Europe (Stockholm) <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Regions</a>. For Regional availability and a future roadmap, search the instance type in the <strong>CloudFormation</strong> resources tab of <a href="https://builder.aws.com/build/capabilities/explore?tab=cfn-resources&amp;trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Capabilities by Region</a>.</p><p>You can purchase these instances as <a href="https://aws.amazon.com/ec2/pricing/on-demand/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">On-Demand Instances</a> and <a href="https://aws.amazon.com/savingsplans/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Savings Plan</a>. To learn more, visit the <a href="https://aws.amazon.com/ec2/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 Pricing page</a>.</p><p>Give Hpc8a instances a try in the <a href="https://console.aws.amazon.com/ec2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 console</a>. To learn more, visit the <a href="https://aws.amazon.com/ec2/instance-types/hpc8a/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 Hpc8a instances page</a> and send feedback to <a href="https://repost.aws/tags/TAO-wqN9fYRoyrpdULLa5y7g/amazon-ec-2?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for EC2</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="ab875734-5a8b-427b-b1ca-06783d43e420" data-title="Amazon EC2 Hpc8a Instances powered by 5th Gen AMD EPYC processors are now available" data-url="https://aws.amazon.com/blogs/aws/amazon-ec2-hpc8a-instances-powered-by-5th-gen-amd-epyc-processors-are-now-available/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-ec2-hpc8a-instances-powered-by-5th-gen-amd-epyc-processors-are-now-available/"/>
    <updated>2026-02-17T00:12:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/announcing-amazon-sagemaker-inference-for-custom-amazon-nova-models/</id>
    <title><![CDATA[Announcing Amazon SageMaker Inference for custom Amazon Nova models]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Since we launched <a href="https://aws.amazon.com/blogs/aws/announcing-amazon-nova-customization-in-amazon-sagemaker-ai/">Amazon Nova customization in Amazon SageMaker AI</a> at AWS NY Summit 2025, customers have been asking for the same capabilities with <a href="https://aws.amazon.com/nova/">Amazon Nova</a> as they do when they customize open weights models in <a href="https://aws.amazon.com/sagemaker/ai/deploy/">Amazon SageMaker Inference</a>. They also wanted have more control and flexibility in custom model inference over instance types, auto-scaling policies, context length, and concurrency settings that production workloads demand.</p><p>Today, we’re announcing the general availability of custom Nova model support in Amazon SageMaker Inference, a production-grade, configurable, and cost-efficient managed inference service to deploy and scale full-rank customized Nova models. You can now experience an end-to-end customization journey to train Nova Micro, Nova Lite, and Nova 2 Lite models with reasoning capabilities using <a href="https://aws.amazon.com/sagemaker/ai/train/">Amazon SageMaker Training Jobs</a> or <a href="https://aws.amazon.com/sagemaker/ai/hyperpod/">Amazon HyperPod</a> and seamlessly deploy them with managed inference infrastructure of Amazon SageMaker AI.</p><p>With Amazon SageMaker Inference for custom Nova models, you can reduce inference cost through optimized GPU utilization using <a href="https://aws.amazon.com/ec2">Amazon Elastic Compute Cloud (Amazon EC2)</a> <a href="https://aws.amazon.com/ec2/instance-types/g5/">G5</a> and <a href="https://aws.amazon.com/ec2/instance-types/g6/">G6</a> instances over <a href="https://aws.amazon.com/ec2/instance-types/p5/">P5 instances</a>, auto-scaling based on 5-minute usage patterns, and configurable inference parameters. This feature enables deployment of customized Nova models with continued pre-training, supervised fine-tuning, or reinforcement fine-tuning for your use cases. You can also set advanced configurations about context length, concurrency, and batch size for optimizing the latency-cost-accuracy tradeoff for your specific workloads.</p><p>Let’s see how to deploy customized Nova models on SageMaker AI real-time endpoints, configure inference parameters, and invoke your models for testing.</p><p><strong class="c6">Deploy custom Nova models in SageMaker Inference</strong><br />At AWS re:Invent 2025, we introduced <a href="https://aws.amazon.com/blogs/aws/new-serverless-customization-in-amazon-sagemaker-ai-accelerates-model-fine-tuning/">new serverless customization in Amazon SageMaker AI</a> for popular AI models including Nova models. With a few clicks, you can seamlessly select a model and customization technique, and handle model evaluation and deployment. If you already have a trained custom Nova model artifact, you can deploy the models on SageMaker Inference through the <a href="https://console.aws.amazon.com/sagemaker?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">SageMaker Studio</a> or <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/api-and-sdk-reference-overview.html">SageMaker AI SDK</a>.</p><p>In the SageMaker Studio, choose a trained Nova model in Models in your models in the <strong>Models</strong> menu. You can deploy the model by choosing <strong>Deploy</strong> button, <strong>SageMaker AI</strong> and <strong>Create new endpoint</strong>.</p><p><img class="aligncenter size-full wp-image-102959" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/11/2026-sagemaker-ai-custom-nova-1-deploy.jpg" alt="" width="2380" height="1282" /></p><p>Choose the endpoint name, instance type, and advanced options such as instance count, max instance count, permission and networking, and <strong>Deploy</strong> button. At GA launch, you can use <code>g5.12xlarge</code>, <code>g5.24xlarge</code>, <code>g5.48xlarge</code>, <code>g6.12xlarge</code>, <code>g6.24xlarge</code>, <code>g6.48xlarge</code>, and <code>p5.48xlarge</code> instance types for the Nova Micro model, <code>g5.24xlarge</code>, <code>g5.48xlarge</code>, <code>g6.24xlarge</code>, <code>g6.48xlarge</code>, and <code>p5.48xlarge</code> for the Nova Lite model, and <code>p5.48xlarge</code> for the Nova 2 Lite model.</p><p><img class="aligncenter size-full wp-image-102961" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/11/2026-sagemaker-ai-custom-nova-2-deploy.jpg" alt="" width="2348" height="1466" /></p><p>Creating your endpoint requires time to provision the infrastructure, download your model artifacts, and initialize the inference container.</p><p>After model deployment completes and the endpoint status shows <strong>InService</strong>, you can perform real-time inference using the new endpoint. To test the model, choose the <strong>Playground</strong> tab and input your prompt in the <strong>Chat</strong> mode.</p><p><img class="aligncenter wp-image-103015 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/16/2026-sagemaker-ai-custom-nova-3-deploy-1.jpg" alt="" width="2560" height="1950" /></p><p>You can also use the SageMaker AI SDK to create two resources: a SageMaker AI model object that references your Nova model artifacts, and an endpoint configuration that defines how the model will be deployed.</p><p>The following code creates a SageMaker AI model that references your Nova model artifacts:</p><pre class="lang-python"># Create a SageMaker AI model
    model_response = sagemaker.create_model(
        ModelName= 'Nova-micro-ml-g5-12xlarge',
        PrimaryContainer={
            'Image': '123456789012.dkr.ecr.us-east-1.amazonaws.com/nova-inference-repo:v1.0.0',
            'ModelDataSource': {
                'S3DataSource': {
                   'S3Uri': 's3://your-bucket-name/path/to/model/artifacts/',
                   'S3DataType': 'S3Prefix',
                   'CompressionType': 'None'
                }
            },
            # Model Parameters
            'Environment': {
                'CONTEXT_LENGTH': 8000,
                'CONCURRENCY': 16,
                'DEFAULT_TEMPERATURE': 0.0,
                'DEFAULT_TOP_P': 1.0
            }
        },
        ExecutionRoleArn=SAGEMAKER_EXECUTION_ROLE_ARN,
        EnableNetworkIsolation=True
    )
    print("Model created successfully!")</pre><p>Next, create an endpoint configuration that defines your deployment infrastructure and deploy your Nova model by creating a SageMaker AI real-time endpoint. This endpoint will host your model and provide a secure HTTPS endpoint for making inference requests.</p><pre class="lang-python"># Create Endpoint Configuration
    production_variant = {
        'VariantName': 'primary',
        'ModelName': 'Nova-micro-ml-g5-12xlarge',
        'InitialInstanceCount': 1,
        'InstanceType': 'ml.g5.12xlarge',
    }
    config_response = sagemaker.create_endpoint_config(
        EndpointConfigName= 'Nova-micro-ml-g5-12xlarge-Config',
        ProductionVariants= production_variant
    )
    print("Endpoint configuration created successfully!")
# Deploy your Noval model
    endpoint_response = sagemaker.create_endpoint(
        EndpointName= 'Nova-micro-ml-g5-12xlarge-endpoint',
        EndpointConfigName= 'Nova-micro-ml-g5-12xlarge-Config'
    )
    print("Endpoint creation initiated successfully!")
</pre><p>After the endpoint is created, you can send inference requests to generate predictions from your custom Nova model. Amazon SageMaker AI supports synchronous endpoints for real-time with streaming/non-streaming modes and asynchronous endpoints for batch processing.</p><p>For example, the following code creates streaming completion format for text generation:</p><pre class="lang-python"># Streaming chat request with comprehensive parameters
streaming_request = {
"messages": [
        {"role": "user", "content": "Compare our Q4 2025 actual spend against budget across all departments and highlight variances exceeding 10%"}
    ],
    "max_tokens": 512,
    "stream": True,
    "temperature": 0.7,
    "top_p": 0.95,
    "top_k": 40,
    "logprobs": True,
    "top_logprobs": 2,
    "reasoning_effort": "low",  # Options: "low", "high"
    "stream_options": {"include_usage": True}
}
invoke_nova_endpoint(streaming_request)
def invoke_nova_endpoint(request_body):
"""
    Invoke Nova endpoint with automatic streaming detection.
    Args:
        request_body (dict): Request payload containing prompt and parameters
    Returns:
        dict: Response from the model (for non-streaming requests)
        None: For streaming requests (prints output directly)
    """
    body = json.dumps(request_body)
    is_streaming = request_body.get("stream", False)
    try:
        print(f"Invoking endpoint ({'streaming' if is_streaming else 'non-streaming'})...")
        if is_streaming:
            response = runtime_client.invoke_endpoint_with_response_stream(
                EndpointName=ENDPOINT_NAME,
                ContentType='application/json',
                Body=body
            )
            event_stream = response['Body']
            for event in event_stream:
                if 'PayloadPart' in event:
                    chunk = event['PayloadPart']
                    if 'Bytes' in chunk:
                        data = chunk['Bytes'].decode()
                        print("Chunk:", data)
        else:
            # Non-streaming inference
            response = runtime_client.invoke_endpoint(
                EndpointName=ENDPOINT_NAME,
                ContentType='application/json',
                Accept='application/json',
                Body=body
            )
            response_body = response['Body'].read().decode('utf-8')
            result = json.loads(response_body)
            print("✅ Response received successfully")
            return result
    except ClientError as e:
        error_code = e.response['Error']['Code']
        error_message = e.response['Error']['Message']
        print(f"❌ AWS Error: {error_code} - {error_message}")
    except Exception as e:
        print(f"❌ Unexpected error: {str(e)}")</pre><p>To use full code examples, visit <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/nova-model.html">Customizing Amazon Nova models on Amazon SageMaker AI</a>. To learn more about best practices on deploying and managing models, visit <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/best-practices.html">Best Practices for SageMaker AI</a>.</p><p><strong class="c6">Now available</strong><br />Amazon SageMaker Inference for custom Nova models is available today in US East (N. Virginia) and US West (Oregon) AWS Regions. For Regional availability and a future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>.</p><p>The feature supports Nova Micro, Nova Lite, and Nova 2 Lite models with reasoning capabilities, running on EC2 G5, G6, and P5 instances with auto-scaling support. You pay only for the compute instances you use, with per-hour billing and no minimum commitments. For more information, visit <a href="https://aws.amazon.com/sagemaker/ai/pricing/">Amazon SageMaker AI Pricing page</a>.</p><p>Give it a try in <a href="https://console.aws.amazon.com/sagemaker?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon SageMaker AI console</a> and send feedback to <a href="https://repost.aws/tags/TAT80swPyVRPKPcA0rsJYPuA/amazon-sagemaker?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">AWS re:Post for SageMaker</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="06298100-6aea-4142-918e-b54729592b91" data-title="Announcing Amazon SageMaker Inference for custom Amazon Nova models" data-url="https://aws.amazon.com/blogs/aws/announcing-amazon-sagemaker-inference-for-custom-amazon-nova-models/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/announcing-amazon-sagemaker-inference-for-custom-amazon-nova-models/"/>
    <updated>2026-02-16T22:25:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-ec2-m8azn-instances-new-open-weights-models-in-amazon-bedrock-and-more-february-16-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Amazon EC2 M8azn instances, new open weights models in Amazon Bedrock, and more (February 16, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>I joined AWS in 2021, and since then I’ve watched the <a href="https://aws.amazon.com/ec2">Amazon Elastic Compute Cloud (Amazon EC2)</a> instance family grow at a pace that still surprises me. From AWS Graviton-powered instances to specialized accelerated computing options, it feels like every few months there’s a new instance type landing that pushes performance boundaries further. As of February 2026, AWS offers over 1,160 Amazon EC2 instance types, and that number keeps climbing.</p><p>This week’s opening news is a good example: The general availability of <a href="https://aws.amazon.com/about-aws/whats-new/2026/02/aws-m8azn-instances-generally-available/">Amazon EC2 M8azn instances</a>. These are general purpose, high-frequency, high-network instances powered by fifth generation AMD EPYC processors, offering the highest maximum CPU frequency in the cloud at 5 GHz. Compared to the previous generation M5zn instances, M8azn instances deliver up to 2x compute performance, 4.3x higher memory bandwidth, and a 10x larger L3 cache. They also provide up to 2x networking throughput and up to 3x <a href="https://aws.amazon.com/ebs">Amazon Elastic Block Store (Amazon EBS)</a> throughput compared with M5zn.</p><p><img class="alignnone size-full wp-image-103010" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/02/15/wir-feb16-2026-v3.png" alt="" width="3024" height="1692" /></p><p>Built on the <a href="https://aws.amazon.com/ec2/nitro/">AWS Nitro System</a> using sixth generation Nitro Cards, M8azn instances target workloads such as real-time financial analytics, high-performance computing, high-frequency trading, CI/CD pipelines, gaming, and simulation modeling across automotive, aerospace, energy, and telecommunications. The instances feature a 4:1 ratio of memory to vCPU and are available in 9 sizes ranging from 2 to 96 vCPUs with up to 384 GiB of memory, including two bare metal variants. For more information visit the <a href="https://aws.amazon.com/ec2/instance-types/m8a">Amazon EC2 M8azn instance page</a>.</p><p><strong>Last week’s launches</strong><br />Here are some of the other announcements from last week:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-bedrock-adds-support-six-open-weights-models/">Amazon Bedrock adds support for six fully managed open weights models</a> – Amazon Bedrock now supports DeepSeek V3.2, MiniMax M2.1, GLM 4.7, GLM 4.7 Flash, Kimi K2.5, and Qwen3 Coder Next. These models span frontier reasoning and agentic coding workloads. DeepSeek V3.2 and Kimi K2.5 target reasoning and agentic intelligence, GLM 4.7 and MiniMax M2.1 support autonomous coding with large output windows, and Qwen3 Coder Next and GLM 4.7 Flash provide cost-efficient alternatives for production deployment. These models are powered by Project Mantle and provide out-of-the-box compatibility with OpenAI API specifications. With the launch, you can also use new open weight models–<a href="https://kiro.dev/blog/open-weight-models/">DeepSeek v3.2 , MiniMax 2.1, and Qwen3 Coder Next in Kiro</a>, a spec-driven AI development tool.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-bedrock-expands-aws-privatelink-support-openai-api-endpoints/">Amazon Bedrock expands support for AWS PrivateLink</a> – Amazon Bedrock now supports AWS PrivateLink for the <code>bedrock-mantle</code> endpoint, in addition to existing support for the <code>bedrock-runtime</code> endpoint. The bedrock-mantle endpoint is powered by Project Mantle, a distributed inference engine for large-scale machine learning model serving on Amazon Bedrock. Project Mantle provides serverless inference with quality of service controls, higher default customer quotas with automated capacity management, and out-of-the-box compatibility with OpenAI API specifications. AWS PrivateLink support for OpenAI API-compatible endpoints is available in 14 AWS Regions. To get started, visit the Amazon Bedrock console or the OpenAI API compatibility documentation.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-eks-auto-mode-enhanced-logging/">Amazon EKS Auto Mode announces enhanced logging for managed Kubernetes capabilities</a> – You can now configure log delivery sources using Amazon CloudWatch Vended Logs in Amazon EKS Auto Mode. This helps you collect logs from Auto Mode’s managed Kubernetes capabilities for compute autoscaling, block storage, load balancing, and pod networking. Each Auto Mode capability can be configured as a CloudWatch Vended Logs delivery source with built-in AWS authentication and authorization at a reduced price compared to standard CloudWatch Logs. You can deliver logs to CloudWatch Logs, Amazon S3, or Amazon Data Firehose destinations. This feature is available in all Regions where EKS Auto Mode is available.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-opensearch-serverless-supports-collection-groups/">Amazon OpenSearch Serverless now supports Collection Groups</a> – You can use new Collection Groups to share OpenSearch Compute Units (OCUs) across collections with different AWS Key Management Service (AWS KMS) keys. Collection Groups reduce overall OCU costs through a shared compute model while maintaining collection-level security and access controls. They also introduce the ability to specify minimum OCU allocations alongside maximum OCU limits, providing guaranteed baseline capacity at startup for latency-sensitive applications. Collection Groups are available in all Regions where Amazon OpenSearch Serverless is currently available.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/rds-aurora-backup-configuration-restoring-snapshots/">Amazon RDS now supports backup configuration when restoring snapshots</a> – You can view and modify the backup retention period and preferred backup window before and during snapshot restore operations. Previously, restored database instances and clusters inherited backup parameter values from snapshot metadata and could only be modified after restore was complete. You can now view backup settings as part of automated backups and snapshots, and specify or modify these values when restoring, eliminating the need for post-restoration modifications. This is available for all Amazon RDS database engines (MySQL, PostgreSQL, MariaDB, Oracle, SQL Server, and Db2) and Amazon Aurora (MySQL-Compatible and PostgreSQL-Compatible editions) in all AWS commercial Regions and AWS GovCloud (US) Regions at no additional cost.</li>
</ul><p>For a full list of AWS announcements, be sure to keep an eye on the <a href="https://aws.amazon.com/new/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">What’s New with AWS</a> page.</p><p><strong>Upcoming AWS events</strong><br />Check your calendar and sign up for upcoming AWS events:</p><p><a href="https://aws.amazon.com/events/summits/?trk=ep_card_event_page&amp;awsf.location=*all&amp;refid=ep_card_event_page">AWS Summits</a> – Join AWS Summits in 2026, free in-person events where you can explore emerging cloud and AI technologies, learn best practices, and network with industry peers and experts. Upcoming Summits include <a href="https://aws.amazon.com/events/summits/paris/">Paris</a> (April 1), <a href="https://aws.amazon.com/events/summits/london/">London</a> (April 22), and <a href="https://aws.amazon.com/events/summits/">Bengaluru</a> (April 23–24).</p><p><a href="https://aws.amazon.com/uki/cloud-services/aws-events/ai-and-data-conference-2026/">AWS AI and Data Conference 2026</a> – A free, single-day in-person event on March 12 at the Lyrath Convention Centre in Ireland. The conference covers designing, training, and deploying agents with Amazon Bedrock, Amazon SageMaker, and QuickSight, integrating them with AWS data services, and applying governance practices to operate them at scale. The agenda includes strategic guidance and hands-on labs for architects, developers, and business leaders.</p><p><a href="https://aws.amazon.com/events/community-day/">AWS Community Days</a> – Community-led conferences where content is planned, sourced, and delivered by community leaders, featuring technical discussions, workshops, and hands-on labs. Upcoming events include <a href="https://awsahmedabad.community/">Ahmedabad</a> (February 28), <a href="https://www.awscommunityday.sk/">Slovakia</a> (March 11), and <a href="https://www.awsugpune.in/">Pune</a> (March 21).</p><p>Join the <a href="https://builder.aws.com/?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">AWS Builder Center</a> to connect with builders, share solutions, and access content that supports your development. Browse here for upcoming <a href="https://aws.amazon.com/events/explore-aws-events/?refid=e61dee65-4ce8-4738-84db-75305c9cd4fe">AWS led in-person and virtual events</a> and <a href="https://builder.aws.com/connect/events?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">developer-focused events</a>.</p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><a href="https://www.linkedin.com/in/esrakayabali/">— Esra</a><p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="9f8f37a4-feea-4162-a9f4-36a5124962f1" data-title="AWS Weekly Roundup: Amazon EC2 M8azn instances, new open weights models in Amazon Bedrock, and more (February 16, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-ec2-m8azn-instances-new-open-weights-models-in-amazon-bedrock-and-more-february-16-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-ec2-m8azn-instances-new-open-weights-models-in-amazon-bedrock-and-more-february-16-2026/"/>
    <updated>2026-02-16T18:28:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-opus-4-6-in-amazon-bedrock-aws-builder-id-sign-in-with-apple-and-more-february-9-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Claude Opus 4.6 in Amazon Bedrock, AWS Builder ID Sign in with Apple, and more (February 9, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Here are the notable launches and updates from last week that can help you build, scale, and innovate on AWS.</p><p><strong class="c6">Last week’s launches</strong><br />Here are the launches that got my attention this week.</p><p>Let’s start with news related to compute and networking infrastructure:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-ec2-c8id-m8id-r8id-instances/">Introducing Amazon EC2 C8id, M8id, and R8id instances:</a> These new Amazon EC2 C8id, M8id, and R8id instances are powered by custom Intel Xeon 6 processors. These instances offer up to 43% higher performance and 3.3x more memory bandwidth compared to previous generation instances.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/aws-network-firewall-new-price-reduction/">AWS Network Firewall announces new price reductions:</a> The service has added the hourly and data processing discounts on NAT Gateways that are service-chained with Network Firewall secondary endpoints. Additionally, AWS Network Firewall has removed additional data processing charges for Advanced Inspection, which enables Transport Layer Security (TLS) inspection of encrypted network traffic.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-ecs-nlb-linear-canary-deployments/">Amazon ECS adds Network Load Balancer support for Linear and Canary deployments:</a> Applications that commonly use NLB, such as those requiring TCP/UDP-based connections, low latency, long-lived connections, or static IP addresses, can take advantage of managed, incremental traffic shifting natively from ECS when rolling out updates.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/aws-config-new-resource-types/">AWS Config now supports 30 new resource types:</a> These range across key services including Amazon EKS, Amazon Q, and AWS IoT. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/dynamodb-gt-multi-account/">Amazon DynamoDB global tables now support replication across multiple AWS accounts:</a> DynamoDB global tables are a fully managed, serverless, multi-Region, and multi-active database. With this new capability, you can replicate tables across AWS accounts and Regions to improve resiliency, isolate workloads at the account level, and apply distinct security and governance controls.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-rds-provides-enhanced-console-experience/">Amazon RDS now provides an enhanced console experience to connect to a database:</a> The new console experience provides ready-made code snippets for Java, Python, Node.js, and other programming languages as well as tools like the <code>psql</code> command line utility. These code snippets are automatically adjusted based on your database’s authentication settings. For example, if your cluster uses IAM authentication, the generated code snippets will use token-based authentication to connect to the database. The console experience also includes integrated CloudShell access, offering the ability to connect to your databases directly from within the RDS console.</li>
</ul><p>Then, I noticed three news items related to security and how you authenticate on AWS:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/aws-builder-id-sign-in-apple/">AWS Builder ID now supports Sign in with Apple:</a> AWS Builder ID, your profile for accessing AWS applications including AWS Builder Center, AWS Training and Certification, AWS re:Post, AWS Startups, and Kiro, now supports sign-in with Apple as a social login provider. This expansion of sign-in options builds on the existing sign-in with Google capability, providing Apple users with a streamlined way to access AWS resources without managing separate credentials on AWS.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/aws-sts-supports-validation-identity-provider-claims/">AWS STS now supports validation of select identity provider specific claims from Google, GitHub, CircleCI and OCI:</a> You can reference these custom claims as condition keys in IAM role trust policies and resource control policies, expanding your ability to implement fine-grained access control for federated identities and help you establish your data perimeters. This enhancement builds upon IAM’s existing OIDC federation capabilities, which allow you to grant temporary AWS credentials to users authenticated through external OIDC-compatible identity providers.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/02/console-displays-account-name-on-nav-bar/">AWS Management Console now displays Account Name on the Navigation bar for easier account identification:</a> You now have an easy way to identify your accounts at a glance. You can now quickly distinguish between accounts visually using the account name that appears in the navigation bar for all authorized users in that account.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-cloudfront-mutual-tls-for-origins/">Amazon CloudFront announces mutual TLS support for origins:</a> Now with origin mTLS support, you can implement a standardized, certificate-based authentication approach that eliminates operational burden. This enables organizations to enforce strict authentication for their proprietary content, ensuring that only verified CloudFront distributions can establish connections to backend infrastructure ranging from AWS origins and on-premises servers to third-party cloud providers and external CDNs.</li>
</ul><p>Finally, there is not a single week without news around AI :</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2026/2/claude-opus-4.6-available-amazon-bedrock/">Claude Opus 4.6 now available in Amazon Bedrock:</a> Opus 4.6 is Anthropic’s most intelligent model to date and a premier model for coding, enterprise agents, and professional work. Claude Opus 4.6 brings advanced capabilities to Amazon Bedrock customers, including industry-leading performance for agentic tasks, complex coding projects, and enterprise-grade workflows that require deep reasoning and reliability.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/2/claude-opus-4.6-available-amazon-bedrock/">Structured outputs now available in Amazon Bedrock:</a> Amazon Bedrock now supports structured outputs, a capability that provides consistent, machine-readable responses from foundation models that adhere to your defined JSON schemas. Instead of prompting for valid JSON and adding extra checks in your application, you can specify the format you want and receive responses that match it—making production workflows more predictable and resilient.</li>
</ul><p><strong class="c6">Upcoming AWS events</strong><br />Check your calendars so that you can sign up for this upcoming event:</p><p><a href="https://aws-community.ro/">AWS Community Day Romania (April 23–24, 2026):</a> This community-led AWS event brings together developers, architects, entrepreneurs, and students for more than 10 professional sessions delivered by AWS Heroes, Solutions Architects, and industry experts. Attendees can expect expert-led technical talks, insights from speakers with global conference experience, and opportunities to connect during dedicated networking breaks, all hosted at a premium venue designed to support collaboration and community engagement.</p><p>If you’re looking for more ways to stay connected beyond this event, join the <a href="https://builder.aws.com/?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">AWS Builder Center</a> to learn, build, and connect with builders in the AWS community.</p><p>Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=e82bba63-d46d-4435-acd0-7531b14ad817&amp;sc_channel=el">Weekly Roundup</a>.</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="19d4e3e5-7274-4193-85ce-5c099e1c8919" data-title="AWS Weekly Roundup: Claude Opus 4.6 in Amazon Bedrock, AWS Builder ID Sign in with Apple, and more (February 9, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-opus-4-6-in-amazon-bedrock-aws-builder-id-sign-in-with-apple-and-more-february-9-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-claude-opus-4-6-in-amazon-bedrock-aws-builder-id-sign-in-with-apple-and-more-february-9-2026/"/>
    <updated>2026-02-09T21:42:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-ec2-c8id-m8id-and-r8id-instances-with-up-to-22-8-tb-local-nvme-storage-are-generally-available/</id>
    <title><![CDATA[Amazon EC2 C8id, M8id, and R8id instances with up to 22.8 TB local NVMe storage are generally available]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Last year, we launched the <a href="https://aws.amazon.com/ec2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Compute Cloud (Amazon EC2)</a> <a href="https://aws.amazon.com/blogs/aws/introducing-new-compute-optimized-amazon-ec2-c8i-and-c8i-flex-instances/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">C8i instances</a>, <a href="https://aws.amazon.com/blogs/aws/new-general-purpose-amazon-ec2-m8i-and-m8i-flex-instances-are-now-available/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">M8i instances</a>, and <a href="https://aws.amazon.com/blogs/aws/best-performance-and-fastest-memory-with-the-new-amazon-ec2-r8i-and-r8i-flex-instances/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">R8i instances</a> powered by custom Intel Xeon 6 processors available only on AWS with sustained all-core 3.9 GHz turbo frequency. They deliver the highest performance and fastest memory bandwidth among comparable Intel processors in the cloud.</p><p>Today we’re announcing new Amazon EC2 C8id, M8id, and R8id instances backed up to 22.8TB of NVMe-based SSD block-level instance storage physically connected to the host server. These instances offer 3 times more vCPUs, memory and local storage compared to previous sixth-generation instances.</p><p>These instances deliver up to 43% higher compute performance and 3.3 times more memory bandwidth compared to previous sixth-generation instances. They also deliver up to 46% higher performance for I/O intensive database workloads, and up to 30% faster query results for I/O intensive real-time data analytics compared to previous sixth generation instances.</p><ul><li><strong>C8id instances</strong> are ideal for compute-intensive workloads, including those that need access to high-speed, low-latency local storage like video encoding, image manipulation, and other forms of media processing.</li>
<li><strong>M8id instances</strong> are best for workloads that require a balance of compute and memory resources along with high-speed, low-latency local block storage, including data logging, media processing, and medium-sized data stores.</li>
<li><strong>R8id instances</strong> are designed for memory-intensive workloads such as large-scale SQL and NoSQL databases, in-memory databases, large-scale data analytics, and AI inference.</li>
</ul><p>C8id, M8id, and R8id instances now scale up to <strong>96xlarge</strong> (versus <strong>32xlarge</strong> sizes in the sixth generation) with up to 384 vCPUs, 3TiB of memory, and 22.8TB of local storage that make it easier to scale up applications and drive greater efficiencies. These instances also offer two bare metal sizes (<strong>metal-48xl</strong> and <strong>metal-96xl</strong>), allowing you to right size your instances and deploy your most performance sensitive workloads that benefit from direct access to physical resources.</p><p>The instances are available in 11 sizes per family, as well as two bare metal configurations each:</p><table class="c10"><thead><tr class="c7"><th class="c6">Instance Name</th>
<th class="c6">vCPUs</th>
<th class="c6">Memory (GiB) (C/M/R)</th>
<th class="c6">Local NVMe storage (GB)</th>
<th class="c6">Network bandwidth (Gbps)</th>
<th class="c6">EBS bandwidth (Gbps)</th>
</tr></thead><tbody><tr class="c9"><td class="c8"><strong>large</strong></td>
<td class="c8">2</td>
<td class="c8">4/8/16*</td>
<td class="c8">1 x 118</td>
<td class="c8">Up to 12.5</td>
<td class="c8">Up to 10</td>
</tr><tr class="c9"><td class="c8"><strong>xlarge</strong></td>
<td class="c8">4</td>
<td class="c8">8/16/32*</td>
<td class="c8">1 x 237</td>
<td class="c8">Up to 12.5</td>
<td class="c8">Up to 10</td>
</tr><tr class="c9"><td class="c8"><strong>2xlarge</strong></td>
<td class="c8">8</td>
<td class="c8">16/32/64*</td>
<td class="c8">1 x 474</td>
<td class="c8">Up to 15</td>
<td class="c8">Up to 10</td>
</tr><tr class="c9"><td class="c8"><strong>4xlarge</strong></td>
<td class="c8">16</td>
<td class="c8">32/64/128*</td>
<td class="c8">1 x 950</td>
<td class="c8">Up to 15</td>
<td class="c8">Up to 10</td>
</tr><tr class="c9"><td class="c8"><strong>8xlarge</strong></td>
<td class="c8">32</td>
<td class="c8">64/128/256*</td>
<td class="c8">1 x 1,900</td>
<td class="c8">15</td>
<td class="c8">10</td>
</tr><tr class="c9"><td class="c8"><strong>12xlarge</strong></td>
<td class="c8">48</td>
<td class="c8">96/192/384*</td>
<td class="c8">1 x 2,850</td>
<td class="c8">22.5</td>
<td class="c8">15</td>
</tr><tr class="c9"><td class="c8"><strong>16xlarge</strong></td>
<td class="c8">64</td>
<td class="c8">128/256/512*</td>
<td class="c8">1 x 3,800</td>
<td class="c8">30</td>
<td class="c8">20</td>
</tr><tr class="c9"><td class="c8"><strong>24xlarge</strong></td>
<td class="c8">96</td>
<td class="c8">192/384/768*</td>
<td class="c8">2 x 2,850</td>
<td class="c8">40</td>
<td class="c8">30</td>
</tr><tr class="c9"><td class="c8"><strong>32xlarge</strong></td>
<td class="c8">128</td>
<td class="c8">256/512/1024*</td>
<td class="c8">2 x 3,800</td>
<td class="c8">50</td>
<td class="c8">40</td>
</tr><tr class="c9"><td class="c8"><strong>48xlarge</strong></td>
<td class="c8">192</td>
<td class="c8">384/768/1536*</td>
<td class="c8">3 x 3,800</td>
<td class="c8">75</td>
<td class="c8">60</td>
</tr><tr class="c9"><td class="c8"><strong>96xlarge</strong></td>
<td class="c8">384</td>
<td class="c8">768/1536/3072*</td>
<td class="c8">6 x 3,800</td>
<td class="c8">100</td>
<td class="c8">80</td>
</tr><tr class="c9"><td class="c8"><strong>metal-48xl</strong></td>
<td class="c8">192</td>
<td class="c8">384/768/1536*</td>
<td class="c8">3 x 3,800</td>
<td class="c8">75</td>
<td class="c8">60</td>
</tr><tr class="c9"><td class="c8"><strong>metal-96xl</strong></td>
<td class="c8">384</td>
<td class="c8">768/1536/3072*</td>
<td class="c8">6 x 3,800</td>
<td class="c8">100</td>
<td class="c8">80</td>
</tr></tbody></table><p class="c11"><em>*Memory values are for C8id/M8id/R8id respectively.</em></p><p>These instances support the <a href="https://docs.aws.amazon.com/ebs/latest/userguide/instance-bandwidth-configuration.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Instance Bandwidth Configuration (IBC)</a> feature like other eighth-generation instance types, offering flexibility to allocate resources between network and <a href="https://aws.amazon.com/ebs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Block Store (Amazon EBS)</a> bandwidth. You can scale network or EBS bandwidth by 25%, allocating resources optimally for each workload. These instances also use sixth-generation AWS Nitro cards offloading CPU virtualization, storage, and networking functions to dedicated hardware and software, enhancing performance and security for your workloads.</p><p>You can use any <a href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AMIs.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Machine Images (AMIs)</a> that include drivers for the <a href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/enhanced-networking-ena.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Elastic Network Adapter (ENA)</a> and NVMe to fully utilize the performance and capabilities. All current generation AWS Windows and Linux AMIs come with the AWS NVMe driver installed by default. If you use an AMI that does not have the AWS NVMe driver, you can manually install <a href="https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/aws-nvme-drivers.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS NVMe drivers</a>.</p><p>As I noted in <a href="https://aws.amazon.com/blogs/aws/new-amazon-ec2-m6id-and-c6id-instances-with-up-to-7-6-tb-local-nvme-storage/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">my previous blog post</a>, here are a couple of things to remind you about the local NVMe storage on these instances:</p><ul><li>You don’t have to specify a block device mapping in your AMI or during the instance launch; the local storage will show up as one or more devices (<code>/dev/nvme[0-26]n1</code> on Linux) after the guest operating system has booted.</li>
<li>Each local NVMe device is hardware encrypted using the <code>XTS-AES-256</code> block cipher and a unique key. Each key is destroyed when the instance is stopped or terminated.</li>
<li>Local NVMe devices have the same lifetime as the instance they are attached to and do not persist after the instance has been stopped or terminated.</li>
</ul><p>To learn more, visit <a href="https://docs.aws.amazon.com/ebs/latest/userguide/nvme-ebs-volumes.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EBS volumes and NVMe</a> in the Amazon EBS User Guide.</p><p><strong class="c12">Now available</strong><br />Amazon EC2 C8id, M8id and R8id instances are available in US East (N. Virginia), US East (Ohio), and US West (Oregon) <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Regions</a>. R8id instances are additionally available in Europe (Frankfurt) Region. For Regional availability and a future roadmap, search the instance type in the <strong>CloudFormation</strong> resources tab of <a href="https://builder.aws.com/build/capabilities/explore?tab=cfn-resources&amp;trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Capabilities by Region</a>.</p><p>You can purchase these instances as <a href="https://aws.amazon.com/ec2/pricing/on-demand/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">On-Demand Instances</a>, <a href="https://aws.amazon.com/savingsplans/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Savings Plans</a>, and <a href="https://aws.amazon.com/ec2/spot/pricing/?trk=trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Spot Instances</a>. These instances are also available as <a href="https://aws.amazon.com/ec2/pricing/dedicated-instances/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Dedicated Instances</a> and <a href="https://aws.amazon.com/ec2/dedicated-hosts/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Dedicated Hosts</a>. To learn more, visit the <a href="https://aws.amazon.com/ec2/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 Pricing page</a>.</p><p>Give C8id, M8id, and R8id instances a try in the <a href="https://console.aws.amazon.com/ec2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 console</a>. To learn more, visit the <a href="https://aws.amazon.com/ec2/instance-types/c8i/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">EC2 C8i instances</a>, <a href="https://aws.amazon.com/ec2/instance-types/m8i/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">M8i instances</a>, and <a href="https://aws.amazon.com/ec2/instance-types/r8i/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">R8i instances</a> page and send feedback to <a href="https://repost.aws/tags/TAO-wqN9fYRoyrpdULLa5y7g/amazon-ec-2?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for EC2</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="4eea21eb-5ed0-4cfb-9448-80e863e43f0b" data-title="Amazon EC2 C8id, M8id, and R8id instances with up to 22.8 TB local NVMe storage are generally available" data-url="https://aws.amazon.com/blogs/aws/amazon-ec2-c8id-m8id-and-r8id-instances-with-up-to-22-8-tb-local-nvme-storage-are-generally-available/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-ec2-c8id-m8id-and-r8id-instances-with-up-to-22-8-tb-local-nvme-storage-are-generally-available/"/>
    <updated>2026-02-04T23:31:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-iam-identity-center-now-supports-multi-region-replication-for-aws-account-access-and-application-use/</id>
    <title><![CDATA[AWS IAM Identity Center now supports multi-Region replication for AWS account access and application use]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the general availability of <a href="https://aws.amazon.com/iam/identity-center/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS IAM Identity Center</a> multi-Region support to enable <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-accounts.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS account access</a> and <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/awsapps.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">managed application use</a> in additional <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Regions</a>.</p><p>With this feature, you can replicate your workforce identities, permission sets, and other metadata in your organization instance of IAM Identity Center connected to an external identity provider (IdP), such as Microsoft Entra ID and Okta, from its current primary Region to additional Regions for improved resiliency of AWS account access.</p><p>You can also deploy AWS managed applications in your preferred Regions, close to application users and datasets for improved user experience or to meet data residency requirements. Your applications deployed in additional Regions access replicated workforce identities locally for optimal performance and reliability.</p><p>When you replicate your workforce identities to an additional Region, your workforce gets an active AWS access portal endpoint in that Region. This means that in the unlikely event of an IAM Identity Center service disruption in its primary Region, your workforce can still access their AWS accounts through the AWS access portal in an additional Region using already provisioned permissions. You can continue to manage IAM Identity Center configurations from the primary Region, maintaining centralized control.</p><p><strong class="c6">Enable IAM Identity Center in multiple Regions</strong><br />To get started, you should confirm that the AWS managed applications you’re currently using support <a href="https://docs.aws.amazon.com/kms/latest/cryptographic-details/basic-concepts.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">customer managed AWS Key Management Service (AWS KMS) key</a> enabled in AWS Identity Center. When we introduced <a href="https://aws.amazon.com/blogs/aws/aws-iam-identity-center-now-supports-customer-managed-kms-keys-for-encryption-at-rest/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">this feature</a> in October 2025, Seb recommended using multi-Region AWS KMS keys unless your company policies restrict you to single-Region keys. Multi-Region keys provide consistent key material across Regions while maintaining independent key infrastructure in each Region.</p><p>Before replicating IAM Identity Center to an additional Region, you must first replicate the customer managed AWS KMS key to that Region and configure the replica key with the permissions required for IAM Identity Center operations. For instructions on creating multi-Region replica keys, refer to <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/identity-center-customer-managed-keys.html#replicate-kms-key?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Create multi-Region replica keys</a> in the AWS KMS Developer Guide.</p><p>Go to the <a href="https://console.aws.amazon.com/singlesignon/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">IAM Identity Center console</a> in the primary Region, for example, US East (N. Virginia), choose <strong>Settings</strong> in the left-navigation pane, and select the <strong>Management</strong> tab. Confirm that your configured encryption key is a multi-Region customer managed AWS KMS key. To add more Regions, choose <strong>Add Region</strong>.</p><p><img class="aligncenter wp-image-102879 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/29/2026-idc-multiRegion-1.png" alt="" width="1382" height="628" /></p><p>You can choose additional Regions to replicate the IAM Identity Center in a list of the available Regions. When choosing an additional Region, consider your intended use cases, for example, data compliance or user experience.</p><p>If you want to run AWS managed applications that access datasets limited to a specific Region for compliance reasons, choose the Region where the datasets reside. If you plan to use the additional Region to deploy AWS applications, verify that the required <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/awsapps-that-work-with-identity-center.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">applications support</a> your chosen Region and deployment in additional Regions.</p><p><img class="aligncenter size-full wp-image-102821 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/16/2026-idc-multiRegion-2.png" alt="" width="1350" height="742" /></p><p>Choose <strong>Add Region</strong>. This starts the initial replication whose duration depends on the size of your Identity Center instance.</p><p><img class="aligncenter wp-image-102880 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/29/2026-idc-multiRegion-3.png" alt="" width="1140" height="271" /></p><p>After the replication is completed, your users can access their AWS accounts and applications in this new Region. When you choose <strong>View ACS URLs</strong>, you can view <a href="https://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-tech-overview-2.0.html">SAML</a> information, such as an Assertion Consumer Service (ACS) URL, about the primary and additional Regions.</p><p><strong class="c6">How your workforce can use an additional Region</strong><br />AWS Identity Center supports SAML single sign-on with external IdPs, such as Microsoft Entra ID and Okta. Upon authentication in the IdP, the user is redirected to the AWS access portal. To enable the user to be redirected to the AWS access portal in the newly added Region, you need to add the additional Region’s ACS URL to the IdP configuration.</p><p>The following screenshots show you how to do this in the Okta admin console:</p><p><img class="aligncenter wp-image-102861 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/22/2026-idc-multiRegion-4-1.png" alt="" width="2132" height="1057" /></p><p>Then, you can create a bookmark application in your identity provider for users to discover the additional Region. This bookmark app functions like a browser bookmark and contains only the URL to the AWS access portal in the additional Region.</p><p><img class="aligncenter wp-image-102860 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/22/2026-idc-multiRegion-4-1-1.png" alt="" width="1970" height="888" /></p><p>You can also deploy AWS managed applications in additional Regions using your existing deployment workflows. Your users can access applications or accounts using the existing access methods, such as the <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/multi-region-workforce-access.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS access portal</a>, an application link, or through the <a href="https://aws.amazon.com/cli/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Command Line Interface (AWS CLI)</a>.</p><p>To learn more about which AWS managed applications support deployment in additional Regions, visit the <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/awsapps-that-work-with-identity-center.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">IAM Identity Center User Guide</a>.</p><p><strong class="c6">Things to know</strong><br />Here are key considerations to know about this feature:</p><ul><li><strong>Consideration</strong> – To take advantage of this feature at launch, you must be using an organization instance of IAM Identity Center connected to an external IdP. Also, the primary and additional Regions must be enabled by default in an AWS account. Account instances of IAM Identity Center, and the other two identity sources (Microsoft Active Directory and IAM Identity Center directory) are presently not supported.</li>
<li><strong>Operation</strong> – The primary Region remains the central place for managing workforce identities, account access permissions, external IdP, and other configurations. You can use the IAM Identity Center console in additional Regions with a limited feature set. Most operations are read-only, except for application management and user session revocation.</li>
<li><strong>Monitoring</strong> – All workforce actions are emitted in <a href="https://aws.amazon.com/cloudtrail/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS CloudTrail</a> in the Region where the action was performed. This feature enhances account access continuity. You can set up <a href="https://docs.aws.amazon.com/whitepapers/latest/organizing-your-aws-environment/break-glass-access.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">break-glass access</a> for privileged users to access AWS if the external IdP has a service disruption.</li>
</ul><p><strong class="c6">Now available<br /></strong> AWS IAM Identity Center multi-Region support is now available in the <a href="https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-regions.html#manage-acct-regions-regional-availability?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">17 enabled-by-default commercial AWS Regions</a>. For Regional availability and a future roadmap, visit the <a class="c-link" href="https://builder.aws.com/build/capabilities/explore?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>. You can use this feature at no additional cost. Standard <a href="https://aws.amazon.com/kms/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS KMS charges</a> apply for storing and using customer managed keys.</p><p>Give it a try in the <a href="https://console.aws.amazon.com/singlesignon/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Identity Center console</a>. To learn more, visit the <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/multi-region-iam-identity-center.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">IAM Identity Center User Guide</a> and send feedback to <a href="https://repost.aws/tags/TAJNFEvp8UQUaLplKZtOsAaw/aws-iam-identity-center?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for Identity Center</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="62c696c4-2f35-4458-a3e5-71372e6dba58" data-title="AWS IAM Identity Center now supports multi-Region replication for AWS account access and application use" data-url="https://aws.amazon.com/blogs/aws/aws-iam-identity-center-now-supports-multi-region-replication-for-aws-account-access-and-application-use/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-iam-identity-center-now-supports-multi-region-replication-for-aws-account-access-and-application-use/"/>
    <updated>2026-02-03T20:13:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-bedrock-agent-workflows-amazon-sagemaker-private-connectivity-and-more-february-2-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Amazon Bedrock agent workflows, Amazon SageMaker private connectivity, and more (February 2, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/31/Screenshot-2026-01-31-at-19.17.02.png"><img class="wp-image-102903 size-medium alignright" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/31/Screenshot-2026-01-31-at-19.17.02-300x213.png" alt="" width="300" height="213" /></a>Over the past week, we passed <a href="https://en.wikipedia.org/wiki/Laba_Festival">Laba festival</a>, a traditional marker in the Chinese calendar that signals the final stretch leading up to the Lunar New Year. For many in China, it’s a moment associated with reflection and preparation, wrapping up what the year has carried, and turning attention toward what lies ahead.</p><p>Looking forward, next week also brings <a href="https://en.wikipedia.org/wiki/Lichun">Lichun</a>, the beginning of spring and the first of the 24 solar terms. In Chinese tradition, spring is often seen as the season when growth begins and new cycles take shape. There’s a common saying that “a year’s plans begin in spring,” capturing the idea that this is a time to set one’s direction and start fresh.</p><p><strong class="c6">Last week’s launches</strong><br />Here are the launches that got my attention this week:</p><ul><li><a href="https://aws.amazon.com/bedrock/">Amazon Bedrock</a> enhances support for agent workflows with server-side tools and extended prompt caching – Amazon Bedrock introduced two updates that improve how developers build and operate AI agents. <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-bedrock-server-side-custom-tools-responses-api/">The Responses API now supports server-side tool use</a>, so agents can perform actions such as web search, code execution, and database updates within AWS security boundaries. <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-bedrock-one-hour-duration-prompt-caching/">Bedrock also adds a 1-hour time-to-live (TTL) option for prompt caching</a>, which helps improve performance and reduce the cost for long-running, multi-turn agent workflows. Server-side tools are available with OpenAI GPT OSS 20B and 120B models, and the 1-hour prompt caching TTL is generally available for select Claude models by Anthropic in Amazon Bedrock.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-sagemaker-unified-studio-aws-privatelink/">Amazon SageMaker Unified Studio adds private VPC connectivity with AWS PrivateLink</a> – <a href="https://aws.amazon.com/sagemaker/unified-studio/">Amazon SageMaker Unified Studio</a> now supports AWS PrivateLink, providing private connectivity between your VPC and SageMaker Unified Studio without routing customer data over the public internet. With SageMaker service endpoints onboarded into a VPC, data traffic remains within the AWS network and is governed by IAM policies, supporting stricter security and compliance requirements.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/change-the-server-side-encryption-type-of-s3-objects/">Amazon S3 adds support for changing object encryption without data movement</a> – <a href="https://aws.amazon.com/s3/">Amazon S3</a> now supports changing the server-side encryption type of existing encrypted objects without moving or re-uploading data. Using the <code>UpdateObjectEncryption</code> API, you can switch from SSE-S3 to SSE-KMS, rotate customer -managed AWS Key Management Service (AWS KMS) keys, or standardize encryption across buckets at scale with S3 Batch Operations while preserving object properties and lifecycle eligibility.</li>
<li><a href="https://aws.amazon.com/blogs/database/introducing-pre-warming-for-amazon-keyspaces-tables/">Amazon Keyspaces introduces table pre-warming for predictable high-throughput workloads</a> – Amazon Keyspaces (for Apache Cassandra) now supports table pre-warming, which helps you proactively set warm throughput levels so tables can handle high read and write traffic instantly without cold-start delays. Pre-warming helps reduce throttling during sudden traffic spikes, such as product launches or sales events, and works with both on-demand and provisioned capacity modes, including multi-Region tables. The feature supports consistent, low-latency performance while giving you more control over throughput readiness.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-dynamodb-global-tables-with-mrsc-fis/">Amazon DynamoDB MRSC global tables integrate with AWS Fault Injection Service</a> – <a href="https://aws.amazon.com/dynamodb/">Amazon DynamoDB</a> multi-Region strong consistency (MRSC) global tables now integrate with AWS Fault Injection Service. With this integration, you can simulate Regional failures, test replication behavior, and validate application resiliency for strongly consistent, multi-Region workloads.</li>
</ul><p><strong class="c6">Additional updates</strong><br />Here are some additional projects, blog posts, and news items that I found interesting:</p><ul><li><a href="https://aws.amazon.com/blogs/networking-and-content-delivery/building-zero-trust-access-across-multi-account-aws-environments/">Building zero-trust access across multi-account AWS environments with AWS Verified Access</a> – This post walks through how to implement AWS Verified Access in a centralized, shared-services architecture. It shows how to integrate with AWS IAM Identity Center and AWS Resource Access Manager (AWS RAM) to apply zero trust access controls at the application layer and reduce operational overhead across multi-account AWS environments.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-eventbridge-increases-event-payload-size-256-kb-1-mb/">Amazon EventBridge increases event payload size to 1 MB</a> – Amazon EventBridge now supports event payloads up to 1 MB, an increase from the previous 256 KB limit. This update helps event-driven architectures carry richer context in a single event, including complex JSON structures, telemetry data, and machine learning (ML) or generative AI outputs, without splitting payloads or relying on external storage.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2025/01/aws-announces-deployment-agent-sops-in-aws-mcp-server-preview/">AWS MCP Server adds deployment agent SOPs (preview)</a> – AWS introduced deployment standard operating procedures (SOPs) that AI agents can deploy web applications to AWS from a single natural language prompt in MCP -compatible integrated development environments (IDEs) and command line interfaces (CLIs) such as Kiro, Cursor, and Claude Code. The agent generates AWS Cloud Development Kit (AWS CDK) infrastructure, deploys AWS CloudFormation stacks, and sets up continuous integration and continuous delivery (CI/CD) workflows following AWS best practices. The preview supports frameworks including React, Vue.js, Angular, and Next.js.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/aws-network-firewall-web-category-based-filtering/">AWS Network Firewall adds generation AI traffic visibility with web category filtering</a> – AWS Network Firewall now provides visibility into generative AI application traffic through predefined web categories. You can use these categories directly in firewall rules to govern access to generative AI tools and other web services. When combined with TLS inspection, category-based filtering can be applied at the full URL level.</li>
<li>A<a href="https://aws.amazon.com/about-aws/whats-new/2026/01/aws-Lambda-observability-for-kafka-esm/">WS Lambda adds enhanced observability for Kafka event source mappings</a> – <a href="https://aws.amazon.com/lambda/">AWS Lambda</a> introduced enhanced observability for Kafka event source mappings, providing Amazon CloudWatch Logs and metrics to monitor event polling configuration, scaling behavior, and event processing state. The update improves visibility into Kafka-based Lambda workloads, helping teams diagnose configuration issues, permission errors, and function failures more efficiently. The capability supports both Amazon Managed Streaming for Apache Kafka (Amazon MSK) and self-managed Apache Kafka event sources.</li>
<li><a href="https://aws.amazon.com/blogs/devops/aws-cloudformation-2025-year-in-review/">AWS CloudFormation 2025 year in review</a> – This year-in-review post highlights CloudFormation updates delivered throughout 2025, with a focus on early validation, safer deployments, and improved developer workflows. It covers enhancements such as improved troubleshooting, drift-aware change sets, stack refactoring, StackSets updates, and new -IDE and AI -assisted tooling, including the CloudFormation language server and the Infrastructure as Code (IaC) MCP server.</li>
</ul><p><strong class="c6">Upcoming AWS events</strong><br />Check your calendars so that you can sign up for this upcoming event:</p><p><a href="https://aws-community.ro/">AWS Community Day Romania (April 23–24, 2026)</a> – This community-led AWS event brings together developers, architects, entrepreneurs, and students for more than 10 professional sessions delivered by AWS Heroes, Solutions Architects, and industry experts. Attendees can expect expert-led technical talks, insights from speakers with global conference experience, and opportunities to connect during dedicated networking breaks, all hosted at a premium venue designed to support collaboration and community engagement.</p><p>If you’re looking for more ways to stay connected beyond this event, join the <a href="https://builder.aws.com/?trk=e61dee65-4ce8-4738-84db-75305c9cd4fe&amp;sc_channel=el">AWS Builder Center</a> to learn, build, and connect with builders in the AWS community.</p><p>Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=e82bba63-d46d-4435-acd0-7531b14ad817&amp;sc_channel=el">Weekly Roundup</a>.</p><p>–<a href="http://www.linkedin.com/in/zhengyubin714">betty</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="0d928235-4ce9-4b67-9230-7a831da6c5b6" data-title="AWS Weekly Roundup: Amazon Bedrock agent workflows, Amazon SageMaker private connectivity, and more (February 2, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-bedrock-agent-workflows-amazon-sagemaker-private-connectivity-and-more-february-2-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-bedrock-agent-workflows-amazon-sagemaker-private-connectivity-and-more-february-2-2026/"/>
    <updated>2026-02-02T18:19:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-ec2-g7e-instances-with-nvidia-blackwell-gpus-january-26-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Amazon EC2 G7e instances with NVIDIA Blackwell GPUs (January 26, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Hey! It’s my first post for 2026, and I’m writing to you while watching our driveway getting dug out. I hope wherever you are you are safe and warm and your data is still flowing!</p><p><img class="alignnone size-large wp-image-102867" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/26/IMG_0652-1024x676.jpg" alt="Our driveway getting snow plowed" width="1024" height="676" /></p><p>This week brings exciting news for customers running GPU-intensive workloads, with the launch of our newest graphics and AI inference instances powered by NVIDIA’s latest Blackwell architecture. Along with several service enhancements and regional expansions, this week’s updates continue to expand the capabilities available to AWS customers.</p><p><strong>Last week’s launches</strong></p><p><strong><a href="https://aws.amazon.com/blogs/aws/announcing-amazon-ec2-g7e-instances-accelerated-by-nvidia-rtx-pro-6000-blackwell-server-edition-gpus/">Amazon EC2 G7e instances are now generally available</a></strong> — The new G7e instances accelerated by NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs deliver up to 2.3 times better inference performance compared to G6e instances. With two times the GPU memory and support for up to 8 GPUs providing 768 GB of total GPU memory, these instances enable running medium-sized models of up to 70B parameters with FP8 precision on a single GPU. G7e instances are ideal for generative AI inference, spatial computing, and scientific computing workloads. Available now in US East (N. Virginia) and US East (Ohio).</p><p><strong>Additional updates</strong></p><p>I thought these projects, blog posts, and news items were also interesting:</p><p><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-corretto-january-2026-quarterly-updates/">Amazon Corretto January 2026 Quarterly Updates</a></strong> — AWS released quarterly security and critical updates for Amazon Corretto Long-Term Supported (LTS) versions of OpenJDK. Corretto 25.0.2, 21.0.10, 17.0.18, 11.0.30, and 8u482 are now available, ensuring Java developers have access to the latest security patches and performance improvements.</p><p><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-ecr-cross-repository-layer-sharing/">Amazon ECR now supports cross-repository layer sharing</a></strong> — Amazon Elastic Container Registry now enables you to share common image layers across repositories through blob mounting. This feature helps you achieve faster image pushes by reusing existing layers and reduce storage costs by storing common layers once and referencing them across repositories.</p><p><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-cloudwatch-database-insights-on-demand-analysis-available-additional-regions/">Amazon CloudWatch Database Insights expands to four additional regions</a></strong> — CloudWatch Database Insights on-demand analysis is now available in Asia Pacific (New Zealand), Asia Pacific (Taipei), Asia Pacific (Thailand), and Mexico (Central). This feature uses machine learning to help identify performance bottlenecks and provides specific remediation advice.</p><p><strong><a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-connect-conditional-logic-real-time-updates-step-by-step-guides/">Amazon Connect adds conditional logic and real-time updates to Step-by-Step Guides</a></strong> — Amazon Connect Step-by-Step Guides now enables managers to build dynamic guided experiences that adapt based on user interactions. Managers can configure conditional user interfaces with dropdown menus that show or hide fields, change default values, or adjust required fields based on prior inputs. The feature also supports automatic data refresh from Connect resources, ensuring agents always work with current information.</p><p><strong>Upcoming AWS events</strong></p><p>Keep a look out and be sure to sign up for these upcoming events:</p><p><strong><a href="https://aws.amazon.com/best-of-reinvent/">Best of AWS re:Invent</a> (January 28-29, Virtual)</strong> — Join us for this free virtual event bringing you the most impactful announcements and top sessions from AWS re:Invent. AWS VP and Chief Evangelist Jeff Barr will share highlights during the opening session. Sessions run January 28 at 9:00 AM PT for AMER, and January 29 at 9:00 AM SGT for APJ and 9:00 AM CET for EMEA. Register to access curated technical learning, strategic insights from AWS leaders, and live Q&amp;A with AWS experts.</p><p><strong><a href="https://awsahmedabad.community/">AWS Community Day Ahmedabad</a> (February 28, 2026, Ahmedabad, India)</strong> — The 11th edition of this community-driven AWS conference brings together cloud professionals, developers, architects, and students for expert-led technical sessions, real-world use cases, tech expo booths with live demos, and networking opportunities. This free event includes breakfast, lunch, and exclusive swag.</p><p>Join the <a href="https://aws.amazon.com/builders">AWS Builder Center</a> to learn, build, and connect with builders in the AWS community. Browse for upcoming in-person and virtual developer-focused events in your area.</p><hr /><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><p>~ micah</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="8fe51a14-6e7b-45a6-8012-5567601665db" data-title="AWS Weekly Roundup: Amazon EC2 G7e instances with NVIDIA Blackwell GPUs (January 26, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-ec2-g7e-instances-with-nvidia-blackwell-gpus-january-26-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-ec2-g7e-instances-with-nvidia-blackwell-gpus-january-26-2026/"/>
    <updated>2026-01-26T17:25:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/announcing-amazon-ec2-g7e-instances-accelerated-by-nvidia-rtx-pro-6000-blackwell-server-edition-gpus/</id>
    <title><![CDATA[Announcing Amazon EC2 G7e instances accelerated by NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing the general availability of <a href="https://aws.amazon.com/ec2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Compute Cloud (Amazon EC2)</a> G7e instances that deliver cost-effective performance for generative AI inference workloads and the highest performance for graphics workloads.</p><p>G7e instances are accelerated by the NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs and are well suited for a broad range of GPU-enabled workloads including spatial computing and scientific computing workloads. G7e instances deliver up to 2.3 times inference performance compared to <a href="https://aws.amazon.com/ec2/instance-types/g6e/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">G6e instances</a>.</p><p>Improvements made compared to predecessors:</p><ul><li><strong>NVIDIA RTX PRO 6000 Blackwell GPUs</strong> — NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs offer two times the GPU memory and 1.85 times the GPU memory bandwidth compared to G6e instances. By using the higher GPU memory offered by G7e instances, you can run medium-sized models of up to 70B parameters with FP8 precision on a single GPU.</li>
<li><strong>NVIDIA GPUDirect P2P</strong> — For models that are too large to fit into the memory of a single GPU, you can split the model or computations across multiple GPUs. G7e instances reduce the latency of your multi-GPU workloads with support for NVIDIA GPUDirect P2P, which enables direct communication between GPUs over PCIe interconnect. These instances offer the lowest peer to peer latency for GPUs on the same PCIe switch. Additionally, G7e instances offer up to four times the inter-GPU bandwidth compared to L40s GPUs featured in G6e instances, boosting the performance of multi-GPU workloads. These improvements mean you can run inference for larger models across multiple GPUs offering up to 768 GB of GPU memory in a single node.</li>
<li><strong>Networking</strong> — G7e instances offer four times the networking bandwidth compared to G6e instances, which means you can use the instance for small-scale multi-node workloads. Additionally, multi-GPU G7e instances support NVIDIA GPUDirect Remote Direct Memory Access (RDMA) with <a href="https://aws.amazon.com/hpc/efa/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Elastic Fabric Adapter (EFA)</a>, which reduces the latency of remote GPU-to-GPU communication for multi-node workloads. These instance sizes also support NVIDIA GPUDirectStorage with <a href="https://aws.amazon.com/fsx/lustre/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon FSx for Lustre</a>, which increases throughput by up to 1.2 Tbps to the instances compared to G6e instances, which means you can quickly load your models.</li>
</ul><p><strong class="c6">EC2 G7e specifications</strong><br />G7e instances feature up to 8 NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs with up to 768 GB of total GPU memory (96 GB of memory per GPU) and Intel Emerald Rapids processors. They also support up to 192 vCPUs, up to 1,600 Gbps of network bandwidth, up to 2,048 GiB of system memory, and up to 15.2 TB of local NVMe SSD storage.</p><p>Here are the specs:</p><table class="c11"><tbody><tr class="c9"><td class="c7"><strong>Instance name<br /></strong></td>
<td class="c7"><strong> GPUs</strong></td>
<td class="c8"><strong>GPU memory (GB)</strong></td>
<td class="c8"><strong>vCPUs</strong></td>
<td class="c8"><strong>Memory (GiB)</strong></td>
<td class="c8"><strong>Storage (TB)</strong></td>
<td class="c8"><strong>EBS bandwidth (Gbps)</strong></td>
<td class="c8"><strong>Network bandwidth (Gbps)</strong></td>
</tr><tr class="c10"><td class="c7"><strong>g7e.2xlarge</strong></td>
<td class="c8">1</td>
<td class="c8">96</td>
<td class="c8">8</td>
<td class="c8">64</td>
<td class="c8">1.9 x 1</td>
<td class="c8">Up to 5</td>
<td class="c8">50</td>
</tr><tr class="c10"><td class="c7"><strong>g7e.4xlarge</strong></td>
<td class="c8">1</td>
<td class="c8">96</td>
<td class="c8">16</td>
<td class="c8">128</td>
<td class="c8">1.9 x 1</td>
<td class="c8">8</td>
<td class="c8">50</td>
</tr><tr class="c10"><td class="c7"><strong>g7e.8xlarge</strong></td>
<td class="c8">1</td>
<td class="c8">96</td>
<td class="c8">32</td>
<td class="c8">256</td>
<td class="c8">1.9 x 1</td>
<td class="c8">16</td>
<td class="c8">100</td>
</tr><tr class="c10"><td class="c7"><strong>g7e.12xlarge</strong></td>
<td class="c8">2</td>
<td class="c8">192</td>
<td class="c8">48</td>
<td class="c8">512</td>
<td class="c8">3.8 x 1</td>
<td class="c8">25</td>
<td class="c8">400</td>
</tr><tr class="c10"><td class="c7"><strong>g7e.24xlarge</strong></td>
<td class="c8">4</td>
<td class="c8">384</td>
<td class="c8">96</td>
<td class="c8">1024</td>
<td class="c8">3.8 x 2</td>
<td class="c8">50</td>
<td class="c8">800</td>
</tr><tr><td class="c7"><strong>g7e.48xlarge</strong></td>
<td class="c8">8</td>
<td class="c8">768</td>
<td class="c8">192</td>
<td class="c8">2048</td>
<td class="c8">3.8 x 4</td>
<td class="c8">100</td>
<td class="c8">1600</td>
</tr></tbody></table><p>To get started with G7e instances, you can use the <a href="https://aws.amazon.com/ai/machine-learning/amis/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Deep Learning AMIs (DLAMI)</a> for your machine learning (ML) workloads. To run instances, you can use <a href="https://console.aws.amazon.com/ec2?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Management Console</a>, <a href="https://aws.amazon.com/cli/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Command Line Interface (AWS CLI)</a> or <a href="http://docs.aws.amazon.com/AWSJavaScriptSDK/latest/AWS/EC2.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS SDKs</a>. For a managed experience, you can use G7e instances with <a href="https://aws.amazon.com/ecs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Container Service (Amazon ECS)</a>, <a href="https://aws.amazon.com/eks/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Kubernetes Service (Amazon EKS)</a>. Support for <a href="https://aws.amazon.com/sagemaker-ai/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon SageMaker AI</a> is also coming soon.</p><p><strong class="c6">Now available</strong><br />Amazon EC2 G7e instances are available today in the US East (N. Virginia) and US East (Ohio) <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Regions</a>. For Regional availability and a future roadmap, search the instance type in the <strong>CloudFormation</strong> resources tab of <a href="https://builder.aws.com/build/capabilities/explore?tab=cfn-resources&amp;trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Capabilities by Region</a>.</p><p>The instances can be purchased as <a href="https://aws.amazon.com/ec2/pricing/on-demand/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">On-Demand Instances</a>, <a href="https://aws.amazon.com/savingsplans/?trk=cc9e0036-98c5-4fa8-8df0-5281f75284ca&amp;sc_channel=el">Savings Plan</a>, and <a href="https://aws.amazon.com/ec2/spot/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Spot Instances</a>. G7e instances are also available in <a href="https://aws.amazon.com/ec2/pricing/dedicated-instances/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Dedicated Instances</a> and <a href="https://aws.amazon.com/ec2/dedicated-hosts/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Dedicated Hosts</a>. To learn more, visit the <a href="https://aws.amazon.com/ec2/pricing">Amazon EC2 Pricing page</a>.</p><p>Give G7e instances a try in the <a href="https://console.aws.amazon.com/ec2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 console</a>. To learn more, visit the <a href="https://aws.amazon.com/ec2/instance-types/g7e/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 G7e instances page</a> and send feedback to <a href="https://repost.aws/tags/TAO-wqN9fYRoyrpdULLa5y7g/amazon-ec-2?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for EC2</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="2d4d5458-3bf7-47db-8e0d-cd842b325466" data-title="Announcing Amazon EC2 G7e instances accelerated by NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs" data-url="https://aws.amazon.com/blogs/aws/announcing-amazon-ec2-g7e-instances-accelerated-by-nvidia-rtx-pro-6000-blackwell-server-edition-gpus/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/announcing-amazon-ec2-g7e-instances-accelerated-by-nvidia-rtx-pro-6000-blackwell-server-edition-gpus/"/>
    <updated>2026-01-20T22:22:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-kiro-cli-latest-features-aws-european-sovereign-cloud-ec2-x8i-instances-and-more-january-19-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: Kiro CLI latest features, AWS European Sovereign Cloud, EC2 X8i instances, and more (January 19, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>At the end of 2025 I was happy to take a long break to enjoy the incredible summers that the southern hemisphere provides. I’m back and writing my first post in 2026 which also happens to be my last post for the AWS News Blog (more on this later).</p><p>The AWS community is starting the year strong with various AWS re:invent re:Caps being hosted around the globe, with some communities already hosting their <a href="https://aws.amazon.com/events/community-day/?trk=e82bba63-d46d-4435-acd0-7531b14ad817&amp;sc_channel=el">AWS Community Day events</a>, the <a href="https://luma.com/gr8eck5u">AWS Community Day Tel Aviv 2026</a> was hosted last week.</p><table><tbody><tr><td style="width: 50%;"><img class="aligncenter size-large wp-image-102837" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/19/IMG-20260116-WA0007-1024x682.jpg" alt="" width="1024" height="682" /></td>
<td><img class="aligncenter size-large wp-image-102838" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/19/IMG-20260116-WA0006-1024x682.jpg" alt="" width="1024" height="682" /></td>
</tr></tbody></table><p><strong>Last week’s launches</strong><br />Here are last week’s launches that caught my attention:</p><ul><li><a href="https://kiro.dev/changelog/cli/1-24/?sc_channel=sm&amp;sc_publisher=LINKEDIN&amp;sc_country=global&amp;sc_geo=GLOBAL&amp;sc_outcome=awareness">Kiro CLI latest features</a> – Kiro CLI now has granular controls for web fetch URLs, keyboard shortcuts for your custom agents, enhanced diff views, and much more. With these enhancements, you can now use allowlists or blocklists to restrict which URLs the agent can access, ensure a frictionless experience when working with multiple specialized agents in a single session, to name a few.</li>
<li><a href="https://aws.amazon.com/blogs/aws/opening-the-aws-european-sovereign-cloud/">AWS European Sovereign Cloud</a> – Following <a href="https://aws.amazon.com/blogs/aws/in-the-works-aws-european-sovereign-cloud/">an announcement in 2023 of plans to build a new, independent cloud infrastructure</a>, last week we announced the general availability of the AWS European Sovereign Cloud to all customers. The cloud is ready to meet the most stringent sovereignty requirements of European customers with a comprehensive set of AWS services.</li>
<li><a href="https://aws.amazon.com/blogs/aws/amazon-ec2-x8i-instances-powered-by-custom-intel-xeon-6-processors-are-generally-available-for-memory-intensive-workloads/">Amazon EC2 X8i instances</a> – <a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-ec2-x8i-instances-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Previously launched in preview at AWS re:Invent 2025</a>, last week we announced the general availability of new memory-optimized Amazon Elastic Compute Cloud (Amazon EC2) X8i instances. These instances are powered by custom Intel Xeon 6 processors with a sustained all-core turbo frequency of 3.9 GHz, available only on AWS. These SAP certified instances deliver the highest performance and fastest memory bandwidth among comparable Intel processors in the cloud.</li>
</ul><p><strong>Additional updates</strong><br />These projects, blog posts, and news articles also caught my attention:</p><ul><li><a href="https://www.linkedin.com/feed/update/urn:li:activity:7416901230293102592/">5 core features in Amazon Quick Suite</a> – AWS VP Agentic AI Swami Sivasubramanian talks about how he uses Amazon Quick Suite for just about everything. In October 2025 we <a href="https://aws.amazon.com/blogs/aws/reimagine-the-way-you-work-with-ai-agents-in-amazon-quick-suite/">announced Amazon Quick Suite</a>, a new agentic teammate that quickly answers your questions at work and turns insights into actions for you. Amazon Quick Suite has become one of my favorite productivity tools, helping me with my research on various topics in addition to providing me with multiple perspectives on a topic.</li>
<li><a href="https://aws.amazon.com/blogs/machine-learning/deploy-ai-agents-on-amazon-bedrock-agentcore-using-github-actions/">Deploy AI agents on Amazon Bedrock AgentCore using GitHub Actions</a> – Last year we announced Amazon Bedrock AgentCore, a flexible service that helps you seamlessly create and manage AI agents across different frameworks and models, whether hosted on Amazon Bedrock or other environments. Learn how to use a GitHub Actions workflow to automate the deployment of AI agents on AgentCore Runtime. This approach delivers a scalable solution with enterprise-level security controls, providing complete continuous integration and delivery (CI/CD) automation.</li>
</ul><p><img class="aligncenter size-full wp-image-102839" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/19/ml-19418-image-1-1.png" alt="" width="730" height="403" /></p><p><strong>Upcoming AWS events</strong><br />Join us January 28 or 29 (depending on your time zone) for <a href="https://aws.amazon.com/best-of-reinvent/">Best of AWS re:Invent</a>, a free virtual event where we bring you the most impactful announcements and top sessions from AWS re:Invent. Jeff Barr, AWS VP and Chief Evangelist, will share his highlights during the opening session.</p><p>There is still time until January 21 to compete for $250,000 in prizes and AWS credits in the <a href="https://builder.aws.com/connect/events/10000aideas?trk=e82bba63-d46d-4435-acd0-7531b14ad817&amp;sc_channel=el">Global 10,000 AIdeas Competition</a> (yes, the second letter is an I as in Idea, not an L as in like). No code required yet: simply submit your idea, and if you’re selected as a semifinalist, you’ll build your app using <a href="https://kiro.dev/?trk=e82bba63-d46d-4435-acd0-7531b14ad817&amp;sc_channel=el">Kiro</a> within <a href="https://aws.amazon.com/free?trk=e82bba63-d46d-4435-acd0-7531b14ad817&amp;sc_channel=el">AWS Free Tier</a> limits. Beyond the cash prizes and potential featured placement at <a href="https://reinvent.awsevents.com/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">AWS re:Invent 2026</a>, you’ll gain hands-on experience with next-generation AI tools and connect with innovators globally.</p><p>Earlier this month, <a href="https://builder.aws.com/community/community-builders/?trk=e82bba63-d46d-4435-acd0-7531b14ad817&amp;sc_channel=el">the 2026 application for the Community Builders program launched</a>. The application is open until January 21st, midnight PST so here’s your last chance to ensure that you don’t miss out.</p><p>If you’re interested in these opportunities, join the <a href="https://builder.aws.com/?trk=e82bba63-d46d-4435-acd0-7531b14ad817&amp;sc_channel=el">AWS Builder Center</a> to learn with builders in the AWS community.</p><p>With that, I close one of my most meaningful chapters here at AWS. It’s been an absolute pleasure to write for you and I thank you for taking the time to read the work that my team and I pour our absolute hearts into. I’ve grown from the close collaborations with the launch teams and the feedback from all of you. The Sub-Sahara Africa (SSA) community has grown significantly, and I want to dedicate more time focused on this community, I’m still at AWS and I look forward to meeting at an event near you!</p><p>Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=e82bba63-d46d-4435-acd0-7531b14ad817&amp;sc_channel=el">Weekly Roundup</a>!</p><p>– <a href="https://linkedin.com/in/veliswa-boya">Veliswa Boya</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="d979bb6a-85fb-49f3-acdb-d6b31ef6cbd7" data-title="AWS Weekly Roundup: Kiro CLI latest features, AWS European Sovereign Cloud, EC2 X8i instances, and more (January 19, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-kiro-cli-latest-features-aws-european-sovereign-cloud-ec2-x8i-instances-and-more-january-19-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-kiro-cli-latest-features-aws-european-sovereign-cloud-ec2-x8i-instances-and-more-january-19-2026/"/>
    <updated>2026-01-20T01:24:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-ec2-x8i-instances-powered-by-custom-intel-xeon-6-processors-are-generally-available-for-memory-intensive-workloads/</id>
    <title><![CDATA[Amazon EC2 X8i instances powered by custom Intel Xeon 6 processors are generally available for memory-intensive workloads]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Since a <a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-ec2-x8i-instances-preview/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">preview launch</a> at AWS re:Invent 2025, we’re announcing the general availability of new memory-optimized <a href="https://aws.amazon.com/ec2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Compute Cloud (Amazon EC2)</a> X8i instances. These instances are powered by custom Intel Xeon 6 processors with a sustained all-core turbo frequency of 3.9 GHz, available only on AWS. These SAP certified instances deliver the highest performance and fastest memory bandwidth among comparable Intel processors in the cloud.</p><p>X8i instances are ideal for memory-intensive workloads including in-memory databases such as SAP HANA, traditional large-scale databases, data analytics, and electronic design automation (EDA), which require high compute performance and a large memory footprint.</p><p>These instances provide 1.5 times more memory capacity (up to 6 TB), and 3.4 times more memory bandwidth compared to previous generation <a href="https://aws.amazon.com/ko/ec2/instance-types/x2i/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">X2i instances</a>. These instances offer up to 43% higher performance compared to X2i instances, with higher gains on some of the real-world workloads. They deliver up to 50% higher SAP Application Performance Standard (SAPS) performance, up to 47% faster PostgreSQL performance, up to 88% faster Memcached performance, and up to 46% faster AI inference performance.</p><p>During the preview, customers like <a href="https://www.sap.com/products/erp/rise.html">RISE with SAP</a> utilized up to 6 TB of memory capacity with 50% higher compute performance compared to X2i instances. This enabled faster transaction processing and improved query response times for SAP HANA workloads. <a href="https://orion.com/">Orion</a> reduced the number of active cores on X8i instances compared to X2idn instances while maintaining performance thresholds, cutting SQL Server licensing costs by 50%.</p><p><strong class="c6">X8i instances</strong><br />X8i instances are available in 14 sizes including three larger instance sizes (<strong>48xlarge</strong>, <strong>64xlarge</strong>, and <strong>96xlarge</strong>), so you can choose the right size for your application to scale up, and two bare metal sizes (<strong>metal-48xl</strong> and <strong>metal-96xl</strong>) to deploy workloads that benefit from direct access to physical resources. X8i instances feature up to 100 Gbps of network bandwidth with support for the <a href="https://aws.amazon.com/hpc/efa/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Elastic Fabric Adapter (EFA)</a> and up to 80 Gbps of throughput to <a href="https://aws.amazon.com/ebs/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon Elastic Block Store (Amazon EBS)</a>.</p><p>Here are the specs for X8i instances:</p><table class="c10"><tbody><tr class="c8"><td class="c7"><strong>Instance name</strong></td>
<td class="c7"><strong>vCPUs</strong></td>
<td class="c7"><strong>Memory<br /></strong> <strong>(GiB)</strong></td>
<td class="c7"><strong>Network bandwidth (Gbps)</strong></td>
<td class="c7"><strong>EBS bandwidth (Gbps)</strong></td>
</tr><tr class="c9"><td class="c7"><strong>x8i.large</strong></td>
<td class="c7">2</td>
<td class="c7">32</td>
<td class="c7">Up to 12.5</td>
<td class="c7">Up to 10</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.xlarge</strong></td>
<td class="c7">4</td>
<td class="c7">64</td>
<td class="c7">Up to 12.5</td>
<td class="c7">Up to 10</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.2xlarge</strong></td>
<td class="c7">8</td>
<td class="c7">128</td>
<td class="c7">Up to 15</td>
<td class="c7">Up to 10</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.4xlarge</strong></td>
<td class="c7">16</td>
<td class="c7">256</td>
<td class="c7">Up to 15</td>
<td class="c7">Up to 10</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.8xlarge</strong></td>
<td class="c7">32</td>
<td class="c7">512</td>
<td class="c7">15</td>
<td class="c7">10</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.12xlarge</strong></td>
<td class="c7">48</td>
<td class="c7">768</td>
<td class="c7">22.5</td>
<td class="c7">15</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.16xlarge</strong></td>
<td class="c7">64</td>
<td class="c7">1,024</td>
<td class="c7">30</td>
<td class="c7">20</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.24xlarge</strong></td>
<td class="c7">96</td>
<td class="c7">1,536</td>
<td class="c7">40</td>
<td class="c7">30</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.32xlarge</strong></td>
<td class="c7">128</td>
<td class="c7">2,048</td>
<td class="c7">50</td>
<td class="c7">40</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.48xlarge</strong></td>
<td class="c7">192</td>
<td class="c7">3,072</td>
<td class="c7">75</td>
<td class="c7">60</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.64xlarge</strong></td>
<td class="c7">256</td>
<td class="c7">4,096</td>
<td class="c7">80</td>
<td class="c7">70</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.96xlarge</strong></td>
<td class="c7">384</td>
<td class="c7">6,144</td>
<td class="c7">100</td>
<td class="c7">80</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.metal-48xl</strong></td>
<td class="c7">192</td>
<td class="c7">3,072</td>
<td class="c7">75</td>
<td class="c7">60</td>
</tr><tr class="c9"><td class="c7"><strong>x8i.metal-96xl</strong></td>
<td class="c7">384</td>
<td class="c7">6,144</td>
<td class="c7">100</td>
<td class="c7">80</td>
</tr></tbody></table><p>X8i instances support the <a href="https://docs.aws.amazon.com/ebs/latest/userguide/instance-bandwidth-configuration.html?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">instance bandwidth configuration (IBC)</a> feature like other eighth-generation instance types, offering flexibility to allocate resources between network and EBS bandwidth. You can scale network or EBS bandwidth by up to 25%, improving database performance, query processing speeds, and logging efficiency. These instances also use sixth-generation <a href="https://aws.amazon.com/ec2/nitro/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Nitro</a> cards, which offload CPU virtualization, storage, and networking functions to dedicated hardware and software, enhancing performance and security for your workloads.</p><p><strong class="c6">Now available</strong><br />Amazon EC2 X8i instances are now available in US East (N. Virginia), US East (Ohio), US West (Oregon), and Europe (Frankfurt) <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Regions</a>. For Regional availability and a future roadmap, search the instance type in the <strong>CloudFormation</strong> resources tab of <a href="https://builder.aws.com/build/capabilities/explore?tab=cfn-resources&amp;trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS Capabilities by Region</a>.</p><p>You can purchase these instances as <a href="https://aws.amazon.com/ec2/pricing/on-demand/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">On-Demand Instances</a>, <a href="https://aws.amazon.com/savingsplans/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Savings Plan</a>, and <a href="https://aws.amazon.com/ec2/spot/pricing/?trk=trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Spot Instances</a>. To learn more, visit the <a href="https://aws.amazon.com/ec2/pricing/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 Pricing page</a>.</p><p>Give X8i instances a try in the <a href="https://console.aws.amazon.com/ec2/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 console</a>. To learn more, visit the <a href="https://aws.amazon.com/ec2/instance-types/x8i/?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">Amazon EC2 X8i instances page</a> and send feedback to <a href="https://repost.aws/tags/TAO-wqN9fYRoyrpdULLa5y7g/amazon-ec-2?trk=d8ec3b19-0f37-4f8c-8c12-189f913e205c&amp;sc_channel=el">AWS re:Post for EC2</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="a7bedda7-d110-48b9-8d38-2ec87687a96c" data-title="Amazon EC2 X8i instances powered by custom Intel Xeon 6 processors are generally available for memory-intensive workloads" data-url="https://aws.amazon.com/blogs/aws/amazon-ec2-x8i-instances-powered-by-custom-intel-xeon-6-processors-are-generally-available-for-memory-intensive-workloads/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-ec2-x8i-instances-powered-by-custom-intel-xeon-6-processors-are-generally-available-for-memory-intensive-workloads/"/>
    <updated>2026-01-15T23:52:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/opening-the-aws-european-sovereign-cloud/</id>
    <title><![CDATA[Opening the AWS European Sovereign Cloud]]></title>
    <summary><![CDATA[<table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p class="c6"><a href="#german">Deutsch</a> | English | <a href="#spanish">Español</a> | <a href="#french">Français</a> | <a href="#italian">Italiano</a></p><p>As a European citizen, I understand first-hand the importance of digital sovereignty, especially for our public sector organisations and highly regulated industries. Today, I’m delighted to share that the <a href="https://aws.eu/">AWS European Sovereign Cloud</a> is now generally available to all customers. <a href="https://aws.amazon.com/blogs/aws/in-the-works-aws-european-sovereign-cloud/">We first announced our plans to build this new independent cloud infrastructure in 2023</a>, and today it’s ready to meet the most stringent sovereignty requirements of European customers <a href="https://aws.amazon.com/blogs/security/announcing-initial-services-available-in-the-aws-european-sovereign-cloud-backed-by-the-full-power-of-aws/">with a comprehensive set of AWS services</a>.</p><div id="attachment_102650" class="wp-caption aligncenter c7"><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/12/13/AdobeStock_426378211.jpeg"><img aria-describedby="caption-attachment-102650" class="size-large wp-image-102650" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/12/13/AdobeStock_426378211-1024x341.jpeg" alt="Brandenburg Gate" width="1024" height="341" /></a><p id="caption-attachment-102650" class="wp-caption-text">Berlin, Brandenburg Gate at sunset</p></div><p><strong>Meeting European sovereignty requirements<br /></strong> Organizations across Europe face increasingly complex regulatory requirements around data residency, operational control, and governance independence. Too often today, European organisations with the highest sovereignty requirements are stuck in legacy on-premises environments or offerings with reduced services and functionality. In response to this critical need, the AWS European Sovereign Cloud is the only fully featured and independently operated sovereign cloud backed by strong technical controls, sovereign assurances, and legal protections. Public sector entities and businesses in highly regulated industries need cloud infrastructure that provides enhanced sovereignty controls that maintain the innovation, security, and reliability they expect from modern cloud services. These organisations require assurance that their data and operations remain under European jurisdiction, with clear governance structures and operational autonomy within the European Union (EU).</p><p><strong>A new independent cloud infrastructure for Europe</strong><br />The AWS European Sovereign Cloud represents a physically and logically separate cloud infrastructure, with all components located entirely within the EU. The first <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region">AWS Region</a> in the AWS European Sovereign Cloud is located in the state of Brandenburg, Germany, and is generally available today. This Region operates independently from existing AWS Regions. The infrastructure features multiple Availability Zones with redundant power and networking, designed to operate continuously even if connectivity with the rest of the world is interrupted.</p><p>We plan to extend the AWS European Sovereign Cloud footprint from Germany across the EU to support stringent isolation, in-country data residency, and low latency requirements. This will start with new sovereign <a href="https://docs.aws.amazon.com/local-zones/latest/ug/what-is-aws-local-zones.html">Local Zones</a> located in Belgium, the Netherlands, and Portugal. In addition, you will be able to extend the AWS European Sovereign Cloud infrastructure with <a href="https://aws.amazon.com/dedicatedlocalzones/">AWS Dedicated Local Zones</a>, <a href="https://aws.amazon.com/about-aws/global-infrastructure/ai-factories/">AWS AI Factories</a>, or <a href="https://aws.amazon.com/outposts/">AWS Outposts</a> in locations you select, including your own on-premises data centres.</p><p>The AWS European Sovereign Cloud and its Local Zones provide enhanced sovereign controls through its unique operational model. The AWS European Sovereign Cloud will be operated exclusively by EU residents located in the EU. This covers activities such as day-to-day operations, technical support, and customer service. We’re gradually transitioning the AWS European Sovereign Cloud <a href="https://www.aboutamazon.eu/news/aws/aws-european-sovereign-cloud-to-be-operated-by-eu-citizens">to be operated exclusively by EU citizens located in the EU</a>. During this transition period, we will continue to work with a blended team of EU residents and EU citizens located in the EU.</p><p>The infrastructure is managed through dedicated European legal entities established under German law. In October 2025, AWS appointed <a href="https://www.aboutamazon.eu/news/aws/stephane-israel-appointed-to-lead-the-aws-european-sovereign-cloud">Stéphane Israël</a>, an EU citizen residing in the EU, as managing director. Stéphane will be responsible for the management and operations of the AWS European Sovereign Cloud, including infrastructure, technology, and services, as well as leading AWS broader digital sovereignty efforts. In January 2026, AWS also appointed <a href="https://www.linkedin.com/in/stefanhoechbaue">Stefan Hoechbauer</a> (Vice President, Germany and Central Europe, AWS) as a managing director of the AWS European Sovereign Cloud. He will work alongside Stéphane Israel to lead the AWS European Sovereign Cloud.</p><p>An advisory board comprised exclusively of EU citizens, and including two independent third-party representatives, provides additional oversight and expertise on sovereignty matters.</p><p><strong>Enhanced data residency and control</strong><br />The AWS European Sovereign Cloud provides comprehensive data residency assurances so you can meet the most stringent data residency requirements. As with our existing AWS Regions around the world, all your content remains within the Region you select unless you choose otherwise. Beyond content, customer-created metadata including roles, permissions, resource labels, and configurations also stays within the EU. The infrastructure features its own dedicated <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (IAM)</a> and billing system, all operating independently within European borders.</p><p>Technical controls built into the infrastructure <a href="https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/design-goals.html">prevent access to the AWS European Sovereign Cloud from outside the EU</a>. The infrastructure includes <a href="https://aws.amazon.com/blogs/security/establishing-a-european-trust-service-provider-for-the-aws-european-sovereign-cloud/">a dedicated European trust service provider for certificate authority operations</a> and uses dedicated <a href="https://aws.amazon.com/route53/">Amazon Route 53</a> name servers. These servers will only use <a href="https://aws.eu/faq/#operational-autonomy">European Top-Level Domains (TLDs) for their own names</a>. The AWS European Sovereign Cloud has no critical dependencies on non-EU personnel or infrastructure.</p><p><strong>Security and compliance framework<br /></strong> The AWS European Sovereign Cloud maintains the same core security capabilities you expect from AWS, including encryption, key management, access governance, and the <a href="https://aws.amazon.com/ec2/nitro/">AWS Nitro System</a> for compute isolation. This means your EC2 instances benefit from cryptographically verified platform integrity and hardware-enforced boundaries that prevent unauthorized access to your data without compromising on performance, giving you both the sovereignty controls and the computational power your workloads require. The infrastructure undergoes <a href="https://aws.amazon.com/blogs/compute/aws-nitro-system-gets-independent-affirmation-of-its-confidential-compute-capabilities/">independent third-party audits</a>, with compliance programs including ISO/IEC 27001:2013, SOC 1/2/3 reports, and <a href="https://www.bsi.bund.de/EN/Home/home_node.html">Federal Office for Information Security (BSI)</a> C5 attestation.</p><p>The <a href="https://aws.amazon.com/blogs/security/exploring-the-new-aws-european-sovereign-cloud-sovereign-reference-framework/">AWS European Sovereign Cloud: Sovereign Reference Framework</a> defines the specific sovereignty controls across governance independence, operational control, data residency, and technical isolation. This framework is available in <a href="https://aws.amazon.com/artifact/">AWS Artifact</a> and provides end-to-end visibility through SOC 2 attestation.</p><p><strong>Comprehensive service availability<br /></strong> You can access a broad range of AWS services in the AWS European Sovereign Cloud from launch, including <a href="https://aws.amazon.com/sagemaker/">Amazon SageMaker</a> and <a href="https://aws.amazon.com/bedrock/">Amazon Bedrock</a> for artificial intelligence and machine learning (AI/ML) workloads. For compute, you can use <a href="https://aws.amazon.com/ec2/">Amazon Elastic Compute Cloud (Amazon EC2)</a> and <a href="https://aws.amazon.com/lambda/">AWS Lambda</a>. Container orchestration is available through <a href="https://aws.amazon.com/eks/">Amazon Elastic Kubernetes Service (Amazon EKS)</a> and <a href="https://aws.amazon.com/ecs/">Amazon Elastic Container Service (Amazon ECS)</a>. Database services include <a href="https://aws.amazon.com/rds/aurora/">Amazon Aurora</a>, <a href="https://aws.amazon.com/dynamodb/">Amazon DynamoDB</a>, and <a href="https://aws.amazon.com/rds/">Amazon Relational Database Service (Amazon RDS)</a>. Storage options include <a href="https://aws.amazon.com/s3/">Amazon Simple Storage Service (Amazon S3)</a> and <a href="https://aws.amazon.com/ebs/">Amazon Elastic Block Store (Amazon EBS)</a>, with networking through <a href="https://aws.amazon.com/vpc/">Amazon Virtual Private Cloud (Amazon VPC)</a> and security services including <a href="https://aws.amazon.com/kms/">AWS Key Management Service (AWS KMS)</a> and <a href="https://aws.amazon.com/private-ca/">AWS Private Certificate Authority</a>. For an up-to-date list of services, refer to the <a href="https://builder.aws.com/build/capabilities/explore?f=eJyrVipOzUlNLklNCUpNz8zPK1ayUoqOUUotLU7WTUnVTU0sLtE1jFGKVdKBK3QsS8zMSUzKzMksqQSqdsyrVEARqgUA4l8dog&amp;tab=service-feature">AWS Capabilities matrix</a> recently published on the AWS Builder Center.</p><p>The AWS European Sovereign Cloud is <a href="https://aws.amazon.com/blogs/apn/range-of-aws-partner-solutions-set-to-launch-on-the-aws-european-sovereign-cloud/">supported by AWS Partners</a> who are committed to helping you meet your sovereignty requirements. Partners including Adobe, Cisco, Cloudera, Dedalus, Esri, Genesys, GitLab, Mendix, Pega, SAP, SnowFlake, Trend Micro, and Wiz are making their solutions available in the AWS European Sovereign Cloud, providing you with the tools and services you need across security, data analytics, application development, and industry-specific workloads. This broad partner support helps you build sovereign solutions that combine AWS services with trusted partner technologies.</p><p><strong>Significant investment in European infrastructure<br /></strong> The AWS European Sovereign Cloud is backed by a €7.8 billion investment in infrastructure, jobs creation, and skills development. This investment is expected to contribute €17.2 billion to the European economy through 2040 and support roughly 2,800 full-time equivalent jobs annually in local businesses.</p><p><strong>Some technical details<br /></strong> The AWS European Sovereign Cloud is available to all customers, regardless of where they are located. You can access the infrastructure using the <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference-arns.html">partition</a> name <code>aws-eusc</code> and the Region name <code>eusc-de-east-1</code>. A partition is a group of AWS Regions. Each AWS account is scoped to one partition.</p><p>The infrastructure supports all standard AWS access methods including the <a href="https://console.amazonaws-eusc.eu/">AWS Management Console</a>, <a href="https://aws.amazon.com/tools/">AWS SDKs</a>, and the <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a>, making it straightforward to integrate into your existing workflows and automation. After having created a new root account for the AWS European Sovereign Cloud partition, you start by creating new IAM identities and roles specific to this infrastructure, giving you complete control over access management within the European sovereign environment.</p><p><strong>Getting started<br /></strong> The AWS European Sovereign Cloud provides European organisations with enhanced sovereignty controls whilst maintaining access to AWS innovation and capabilities. You can contract for services through Amazon Web Services EMEA SARL, with pricing in EUR and billing in any of <a href="https://aws.amazon.com/legal/aws-emea/">the eight currencies we support today</a>. The infrastructure uses familiar AWS architecture, service portfolio, and APIs, making it straightforward to build and migrate applications.</p><p>The <a href="https://aws.eu/de/esca">AWS European Sovereign Cloud addendum</a> contains the additional contractual commitments for the AWS European Sovereign Cloud.</p><p>For me as a European, this launch represents the AWS commitment to meeting the specific needs of our continent and providing the cloud capabilities that drive innovation across industries. I invite you to find out more about the AWS European Sovereign Cloud and how it can help your organisation meet its sovereignty requirements. Read <a href="https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/introduction.html">Overview of the AWS European Sovereign Cloud</a> to learn more about the design goals and approach, <a href="https://eusc-de-east-1.signin.amazonaws-eusc.eu/signup?request_type=register">sign up for a new account</a>, and plan for the deployment of your first workload today.</p><a href="https://linktr.ee/sebsto">— seb</a><hr id="german" /><h4 class="c8">German version</h4><p><strong>Start der AWS European Sovereign Cloud</strong></p><p>Als Bürger Europas weiß ich aus eigener Erfahrung, wie wichtig digitale Souveränität ist, insbesondere für unsere öffentlichen Einrichtungen und stark regulierten Branchen. Ich freue mich, Ihnen heute mitteilen zu können, dass die <a href="https://aws.eu/">AWS European Sovereign Cloud</a> nun für alle Kunden allgemein verfügbar ist. <a href="https://aws.amazon.com/blogs/aws/in-the-works-aws-european-sovereign-cloud/">Wir haben unsere Pläne zum Aufbau dieser neuen unabhängigen Cloud-Infrastruktur erstmals im Jahr 2023 vorgestellt</a>. Heute ist diese Infrastruktur bereit, <a href="https://aws.amazon.com/blogs/security/announcing-initial-services-available-in-the-aws-european-sovereign-cloud-backed-by-the-full-power-of-aws/">mit einem umfassenden Angebot an AWS-Services</a> die strengsten Souveränitätsanforderungen europäischer Kunden zu erfüllen.</p><div class="wp-caption aligncenter c7"><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/12/13/AdobeStock_426378211.jpeg"><img aria-describedby="caption-attachment-102650" class="size-large wp-image-102650" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/12/13/AdobeStock_426378211-1024x341.jpeg" alt="Brandenburg Gate" width="1024" height="341" /></a><p class="wp-caption-text">Berlin, Brandenburger Tor bei Sonnenuntergang</p></div><p><strong class="c9">Erfüllung europäischer Souveränitätsanforderungen<br /></strong> Organisationen in ganz Europa sehen sich mit zunehmend komplexen regulatorischen Anforderungen in Bezug auf Datenresidenz, operative Kontrolle und Unabhängigkeit der Governance konfrontiert. Europäische Organisationen mit höchsten Souveränitätsanforderungen sind heutzutage allzu oft in veralteten lokalen Umgebungen oder Angeboten mit eingeschränkten Services und Funktionen gefangen. Die AWS European Sovereign Cloud ist die Antwort auf diesen dringenden Bedarf. Sie ist die einzige unabhängig betriebene souveräne Cloud mit vollem Funktionsumfang, die durch strenge technische Kontrollen, Souveränitätszusicherungen und rechtlichen Schutz abgesichert ist. Einrichtungen des öffentlichen Sektors und Unternehmen in stark regulierten Branchen benötigen eine Cloud-Infrastruktur, die erweiterte Souveränitätskontrollen bietet und gleichzeitig die von modernen Cloud-Services erwartete Innovation, Sicherheit und Zuverlässigkeit gewährleistet. Diese Organisationen benötigen die Zusicherung, dass ihre Daten und Aktivitäten unter europäischer Zuständigkeit bleiben, mit klaren Governance-Strukturen und operativer Autonomie innerhalb der Europäischen Union (EU).</p><p><strong class="c9">Eine neue unabhängige Cloud-Infrastruktur für Europa</strong><br />Die AWS European Sovereign Cloud ist eine physisch und logisch getrennte Cloud-Infrastruktur, deren Komponenten sich vollständig innerhalb der EU befinden. Die erste <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region">AWS-Region</a> in der AWS European Sovereign Cloud befindet sich im deutschen Bundesland Brandenburg und ist ab heute allgemein verfügbar. Diese Region arbeitet unabhängig von bestehenden AWS-Regionen. Die Infrastruktur umfasst mehrere Availability Zones mit redundanter Stromversorgung und Netzwerkverbindung, die auch bei einer Unterbrechung der Verbindung zum Rest der Welt einen kontinuierlichen Betrieb gewährleisten.</p><p>Wir beabsichtigen, die Präsenz der AWS European Sovereign Cloud von Deutschland aus EU-weit auszuweiten, um strenge Anforderungen hinsichtlich Isolierung, Datenresidenz innerhalb einzelner Länder und geringer Latenz zu erfüllen. Dies beginnt mit neuen souveränen <a href="https://docs.aws.amazon.com/local-zones/latest/ug/what-is-aws-local-zones.html">Local Zones</a> in Belgien, den Niederlanden und Portugal. Darüber hinaus können Sie die Infrastruktur der AWS European Sovereign Cloud mit <a href="https://aws.amazon.com/dedicatedlocalzones/">dedizierten AWS Local Zones</a>, <a href="https://aws.amazon.com/about-aws/global-infrastructure/ai-factories/">AWS AI Factories</a> oder <a href="https://aws.amazon.com/outposts/">AWS Outposts</a> an Standorten Ihrer Wahl, einschließlich Ihrer eigenen lokalen Rechenzentren, erweitern.</p><p>Dank ihres einzigartigen Betriebsmodells bieten die AWS European Sovereign Cloud und ihre Local Zones erweiterte Souveränitätskontrollen. Der Betrieb der AWS European Sovereign Cloud wird ausschließlich von EU-Bürgern mit Wohnsitz in der EU sichergestellt. Dies umfasst Aktivitäten wie den täglichen Betrieb, den technischen Support und den Kundenservice. Wir stellen die AWS European Sovereign Cloud schrittweise so um, dass <a href="https://www.aboutamazon.eu/news/aws/aws-european-sovereign-cloud-to-be-operated-by-eu-citizens">als Betriebspersonal ausschließlich EU-Bürger mit Wohnsitz in der EU zum Einsatz kommen</a>. Während dieser Übergangsphase werden wir weiterhin mit einem gemischten Team aus in der EU ansässigen Personen und in der EU lebenden EU-Bürgern arbeiten.</p><p>Die Infrastruktur wird durch spezielle europäische juristische Personen nach deutschem Recht verwaltet. Im Oktober 2025 berief AWS <a href="https://www.aboutamazon.eu/news/aws/stephane-israel-appointed-to-lead-the-aws-european-sovereign-cloud">Stéphane Israël</a>, einen in der EU ansässigen EU-Bürger, zum Geschäftsführer. Stéphane wird für das Management und den Betrieb der AWS European Sovereign Cloud verantwortlich zeichnen. Dies umfasst die Bereiche Infrastruktur, Technologie und Services sowie die Federführung bei den breit angelegten Initiativen von AWS auf dem Gebiet der digitalen Souveränität. Im Januar 2026 ernannte AWS zudem <a href="https://www.linkedin.com/in/stefanhoechbaue">Stefan Hoechbauer</a> (Vice President, Germany and Central Europe, AWS) zum Geschäftsführer der AWS European Sovereign Cloud. Er wird gemeinsam mit Stéphane Israel die Leitung der AWS European Sovereign Cloud innehaben.</p><p>Ein Beirat, dem ausschließlich EU-Bürger, einschließlich zwei unabhängigen externen Vertretern, angehören, fungiert als zusätzliche Kontrollinstanz und bringt Fachwissen in Fragen der Souveränität ein.</p><p><strong class="c9">Verbesserte Datenresidenz und -kontrolle</strong><br />Die AWS European Sovereign Cloud bietet umfassende Garantien hinsichtlich der Datenresidenz, sodass Sie selbst die strengsten Anforderungen in diesem Bereich erfüllen können. Wie auch bei unseren bestehenden AWS-Regionen weltweit verbleiben alle Ihre Inhalte in der von Ihnen ausgewählten Region, sofern Sie keine anderen Einstellungen vornehmen. Neben den Inhalten verbleiben auch die vom Kunden erstellten Metadaten, einschließlich Rollen, Berechtigungen, Ressourcenbezeichnungen und Konfigurationen, innerhalb der EU. Die Infrastruktur verfügt über ein eigenes <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (IAM)</a> und ein eigenes Abrechnungssystem – beides wird innerhalb der europäischen Grenzen unabhängig betrieben.</p><p>In die Infrastruktur integrierte technische Kontrollen <a href="https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/design-goals.html">verhindern den Zugriff auf die AWS European Sovereign Cloud von außerhalb der EU</a>. Die Infrastruktur umfasst <a href="https://aws.amazon.com/blogs/security/establishing-a-european-trust-service-provider-for-the-aws-european-sovereign-cloud/">einen dedizierten europäischen Trust Service Provider</a> für Zertifizierungsstellen und nutzt dedizierte <a href="https://aws.amazon.com/route53/">Amazon-Route-53</a>-Namenserver. Diese Server verwenden ausschließlich <a href="https://aws.eu/faq/#operational-autonomy">europäische Top-Level-Domains (TLDs) für ihre eigenen Namen</a>. Die AWS European Sovereign Cloud unterliegt keinen kritischen Abhängigkeiten hinsichtlich Personal oder Infrastruktur außerhalb der EU.</p><p><strong class="c9">Sicherheits- und Compliance-Framework<br /></strong> Die AWS European Sovereign Cloud bietet dieselben zentralen Sicherheitsfunktionen, die Sie von AWS erwarten. Dazu gehören Verschlüsselung, Schlüsselverwaltung, Zugriffskontrolle und das <a href="https://aws.amazon.com/ec2/nitro/">AWS Nitro System</a> für die Isolierung von Rechenressourcen. Dies bedeutet, dass Ihre EC2-Instanzen von einer kryptografisch verifizierten Plattformintegrität und hardwaregestützten Grenzen profitieren, die unbefugten Zugriff auf Ihre Daten verhindern, ohne die Leistung zu beeinträchtigen. So erhalten Sie sowohl die Souveränitätskontrollen als auch die Rechenleistung, die Ihre Workloads erfordern. Die Infrastruktur wird <a href="https://aws.amazon.com/blogs/compute/aws-nitro-system-gets-independent-affirmation-of-its-confidential-compute-capabilities/">unabhängigen Audits durch Dritt</a>e unterzogen. Die Compliance-Programme umfassen ISO/IEC 27001:2013, SOC-1/2/3-Berichte und das C5-Zertifikat des <a href="https://www.bsi.bund.de/EN/Home/home_node.html">Bundesamtes für Sicherheit in der Informationstechnik (BSI)</a>.</p><p>Das <a href="https://aws.amazon.com/blogs/security/exploring-the-new-aws-european-sovereign-cloud-sovereign-reference-framework/">AWS European Sovereign Cloud: Sovereign Reference Framework</a> definiert spezifische Souveränitätskontrollen in den Bereichen Governance-Unabhängigkeit, operative Kontrolle, Datenresidenz und technische Isolierung. Dieses Framework ist in <a href="https://aws.amazon.com/artifact/">AWS Artifact</a> verfügbar und bietet durch SOC-2-Zertifizierung durchgängige Transparenz.</p><p><strong class="c9">Umfassende Serviceverfügbarkeit<br /></strong> Von Beginn an steht Ihnen in der AWS European Sovereign Cloud eine breite Palette von AWS-Services zur Verfügung – darunter <a href="https://aws.amazon.com/sagemaker/">Amazon SageMaker</a> und <a href="https://aws.amazon.com/bedrock/">Amazon Bedrock</a> für Workloads im Bereich Künstliche Intelligenz und Machine Learning (KI/ML). Für die Rechenleistung stehen Ihnen <a href="https://aws.amazon.com/ec2/">Amazon Elastic Compute Cloud (Amazon EC2)</a> und <a href="https://aws.amazon.com/lambda/">AWS Lambda</a> zur Verfügung. Die Container-Orchestrierung ist über den <a href="https://aws.amazon.com/eks/">Amazon Elastic Kubernetes Service (Amazon EKS)</a> und den <a href="https://aws.amazon.com/ecs/">Amazon Elastic Container Service (Amazon ECS)</a> verfügbar. Zu den Datenbank-Services gehören <a href="https://aws.amazon.com/rds/aurora/">Amazon Aurora</a>, <a href="https://aws.amazon.com/dynamodb/">Amazon DynamoDB</a> und <a href="https://aws.amazon.com/rds/">Amazon Relational Database Service (Amazon RDS)</a>. Die Speicheroptionen umfassen <a href="https://aws.amazon.com/s3/">Amazon Simple Storage Service (Amazon S3)</a> und <a href="https://aws.amazon.com/ebs/">Amazon Elastic Block Store (Amazon EBS)</a> mit Vernetzung über <a href="https://aws.amazon.com/vpc/">Amazon Virtual Private Cloud (Amazon VPC)</a> und Sicherheits-Services wie <a href="https://aws.amazon.com/kms/">AWS Key Management Service (AWS KMS)</a> und <a href="https://aws.amazon.com/private-ca/">AWS Private Certificate Authority</a>. Eine aktuelle Liste der Services finden Sie in der <a href="https://builder.aws.com/build/capabilities/explore?f=eJyrVipOzUlNLklNCUpNz8zPK1ayUoqOUUotLU7WTUnVTU0sLtE1jFGKVdKBK3QsS8zMSUzKzMksqQSqdsyrVEARqgUA4l8dog&amp;tab=service-feature">AWS-Funktionsmatrix</a>, die kürzlich im AWS Builder Center veröffentlicht wurde.</p><p>Die AWS European Sovereign Cloud wird von <a href="https://aws.amazon.com/blogs/apn/range-of-aws-partner-solutions-set-to-launch-on-the-aws-european-sovereign-cloud/">AWS-Partnern unterstützt</a>, die es sich zur Aufgabe gemacht haben, Ihnen bei der Erfüllung Ihrer Souveränitätsanforderungen zur Seite zu stehen. Partner wie Adobe, Cisco, Cloudera, Dedalus, Esri, Genesys, GitLab, Mendix, Pega, SAP, SnowFlake, Trend Micro und Wiz stellen ihre Lösungen in der AWS European Sovereign Cloud zur Verfügung und bieten Ihnen die Tools und Services, die Sie in den Bereichen Sicherheit, Datenanalyse, Entwicklung von Anwendungen und branchenspezifische Workloads benötigen. Dank dieser umfassenden Unterstützung durch Partner können Sie eigenständige Lösungen, die AWS-Services mit bewährten Partnertechnologien kombinieren, entwickeln.</p><p><strong class="c9">Erhebliche Investitionen in die europäische Infrastruktur<br /></strong> Hinter der AWS European Sovereign Cloud steht eine Investition in Höhe von 7,8 Milliarden Euro in Infrastruktur, die Schaffung von Arbeitsplätzen und die Entwicklung von Kompetenzen. Diese Investition wird bis 2040 voraussichtlich 17,2 Milliarden Euro zur europäischen Wirtschaftsleistung beitragen und jährlich rund 2 800 Vollzeitstellen in lokalen Unternehmen sichern.</p><p><strong class="c9">Einige technische Details<br /></strong> Die AWS European Sovereign Cloud steht allen Kunden zur Verfügung, unabhängig davon, wo sie sich befinden. Sie können mit dem <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference-arns.html">Partitionsnamen</a> aws-eusc und dem Regionsnamen eusc-de-east-1 auf die Infrastruktur zugreifen. Eine Partition ist eine Gruppe von AWS-Regionen. Jedes AWS-Konto ist auf eine Partition beschränkt.</p><p>Die Infrastruktur unterstützt alle gängigen AWS-Zugriffsmethoden, einschließlich der <a href="https://console.amazonaws-eusc.eu/">AWS Management Console</a>, <a href="https://aws.amazon.com/tools/">AWS SDKs</a> und der <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a>, sodass sie sich problemlos in Ihre bestehenden Workflows und Automatisierungsprozesse integrieren lässt. Nachdem Sie ein neues Root-Konto für die Partition der AWS European Sovereign Cloud erstellt haben, beginnen Sie mit der Erstellung neuer IAM-Identitäten und -Rollen, die speziell für diese Infrastruktur vorgesehen sind. Dadurch erhalten Sie die vollständige Kontrolle über die Zugriffsverwaltung innerhalb der europäischen souveränen Umgebung.</p><p><strong class="c9">Erste Schritte<br /></strong> Die AWS European Sovereign Cloud bietet europäischen Organisationen erweiterte Souveränitätskontrollen und gewährleistet gleichzeitig den Zugriff auf die Innovationen und Funktionen von AWS. Sie können Services über Amazon Web Services EMEA SARL in Auftrag geben. Die Preise werden in Euro angegeben und die Abrechnung erfolgt in <a href="https://aws.amazon.com/legal/aws-emea/">einer der acht Währungen, die wir derzeit unterstützen</a>. Die Infrastruktur basiert auf der bekannten AWS-Architektur, dem AWS-Serviceportfolio und den AWS-APIs, wodurch die Entwicklung und Migration von Anwendungen vereinfacht wird.</p><p>Der <a href="https://aws.eu/de/esca">AWS European Sovereign Cloud Addendum</a> enthält die zusätzlichen vertraglichen Verpflichtungen für die AWS European Sovereign Cloud.</p><p>Für mich als Europäer symbolisiert dieser Launch das Engagement von AWS, den spezifischen Anforderungen unseres Kontinents gerecht zu werden und Cloud-Funktionen bereitzustellen, die Innovationen in allen Branchen vorantreiben. Ich lade Sie ein, mehr über die AWS European Sovereign Cloud zu erfahren und zu entdecken, wie sie Ihrer Organisation dabei helfen kann, ihre Souveränitätsanforderungen zu erfüllen. Lesen Sie die <a href="https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/introduction.html">Übersicht über die AWS European Sovereign Cloud</a> und erfahren Sie mehr über die Designziele und den Ansatz. <a href="https://eusc-de-east-1.signin.amazonaws-eusc.eu/signup?request_type=register">Registrieren Sie sich für ein neues Konto</a> und planen Sie noch heute die Bereitstellung Ihrer ersten Workload.</p><p><a href="https://linktr.ee/sebsto">— seb</a></p><hr id="french" /><h4 class="c8">French version</h4><p><strong>Ouverture de l’AWS European Souvereign Cloud</strong></p><p>En tant que citoyen européen, je mesure personnellement l’importance de la souveraineté numérique, en particulier pour nos organisations du secteur public et les industries fortement réglementées. Aujourd’hui, j’ai le plaisir d’annoncer que l’<a href="https://aws.eu/">AWS European Sovereign Cloud</a> est désormais disponible pour l’ensemble de nos clients. <a href="https://aws.amazon.com/blogs/aws/in-the-works-aws-european-sovereign-cloud/">Nous avions annoncé pour la première fois notre projet de construction de cette nouvelle infrastructure cloud indépendante en 2023</a>, et elle est aujourd’hui prête à répondre aux exigences de souveraineté les plus strictes des clients européens, <a href="https://aws.amazon.com/blogs/security/announcing-initial-services-available-in-the-aws-european-sovereign-cloud-backed-by-the-full-power-of-aws/">avec un large ensemble de services AWS</a>.</p><div class="wp-caption aligncenter c7"><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/12/13/AdobeStock_426378211.jpeg"><img aria-describedby="caption-attachment-102650" class="size-large wp-image-102650" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/12/13/AdobeStock_426378211-1024x341.jpeg" alt="Brandenburg Gate" width="1024" height="341" /></a><p class="wp-caption-text">Berlin, porte de Brandebourg au coucher du soleil</p></div><p><strong>Répondre aux exigences européennes en matière de souveraineté<br /></strong> Partout en Europe, les organisations sont confrontées à des exigences réglementaires de plus en plus complexes en matière de résidence des données, de contrôle opérationnel et d’indépendance de la gouvernance. Trop souvent aujourd’hui, les organisations européennes ayant les besoins de souveraineté les plus élevés se retrouvent contraintes de rester sur des environnements sur site, ou de recourir à des offres cloud aux services et fonctionnalités limités. Pour répondre à cet enjeu critique, l’AWS European Sovereign Cloud est le seul cloud souverain entièrement fonctionnel, exploité de manière indépendante, et reposant sur des contrôles techniques robustes, des garanties de souveraineté et des protections juridiques solides. Les acteurs du secteur public et les entreprises des secteurs fortement réglementés ont besoin d’une infrastructure cloud offrant des contrôles de souveraineté renforcés, sans renoncer à l’innovation, à la sécurité et à la fiabilité attendues des services cloud modernes. Ces organisations doivent avoir l’assurance que leurs données et leurs opérations restent sous juridiction européenne, avec des structures de gouvernance claires et une autonomie opérationnelle au sein de l’Union européenne (UE).</p><p><strong>Une nouvelle infrastructure cloud indépendante pour l’Europe</strong><br />L’AWS European Sovereign Cloud repose sur une infrastructure cloud physiquement et logiquement distincte, dont l’ensemble des composants est situé exclusivement au sein de l’UE. La première <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region">région AWS</a> de l’AWS European Sovereign Cloud est implantée dans le Land de Brandebourg, en Allemagne, et est disponible dès aujourd’hui. Cette région fonctionne de façon indépendante par rapport aux autres régions AWS existantes. L’infrastructure comprend plusieurs zones de disponibilité, avec des systèmes redondants d’alimentation et de réseau, conçus pour fonctionner en continu même en cas d’interruption de la connectivité avec le reste du monde.</p><p>Nous prévoyons d’étendre l’empreinte de l’AWS European Sovereign Cloud depuis l’Allemagne à l’ensemble de l’UE, afin de répondre aux exigences strictes d’isolation, de résidence des données dans certains pays et de faible latence. Cette extension débutera avec de nouvelles <a href="https://docs.aws.amazon.com/local-zones/latest/ug/what-is-aws-local-zones.html">Local Zones</a> souveraines situées en Belgique, aux Pays-Bas et au Portugal. En complément, vous pourrez étendre l’infrastructure de l’AWS European Sovereign Cloud à l’aide des <a href="https://aws.amazon.com/dedicatedlocalzones/">AWS Dedicated Local Zones</a>, des <a href="https://aws.amazon.com/about-aws/global-infrastructure/ai-factories/">AWS AI Factories</a> ou d’<a href="https://aws.amazon.com/outposts/">AWS Outposts</a>, dans les sites de votre choix, y compris au sein de vos propres centres de données sur site.</p><p>L’AWS European Sovereign Cloud et ses Local Zones offrent des contrôles de souveraineté renforcés grâce à un modèle opérationnel unique. L’AWS European Sovereign Cloud est exploité exclusivement par des résidents de l’UE basés dans l’UE. Cela couvre notamment les opérations quotidiennes, le support technique et le service client. Nous sommes en train d’opérer une transition progressive afin que l’AWS European Sovereign Cloud soit <a href="https://www.aboutamazon.eu/news/aws/aws-european-sovereign-cloud-to-be-operated-by-eu-citizens">exploité exclusivement par des citoyens de l’UE résidant dans l’UE</a>. Durant cette période de transition, nous continuons de travailler avec une équipe mixte composée de résidents de l’UE et de citoyens de l’UE basés dans l’UE.</p><p>L’infrastructure est gérée par des entités juridiques européennes dédiées, établies conformément au droit allemand. En octobre 2025, AWS a nommé <a href="https://www.aboutamazon.eu/news/aws/stephane-israel-appointed-to-lead-the-aws-european-sovereign-cloud">Stéphane Israël</a>, citoyen de l’UE résidant dans l’UE, au poste de directeur général. Stéphane est responsable de la gestion et de l’exploitation de l’AWS European Sovereign Cloud, couvrant l’infrastructure, la technologie et les services, ainsi que de la direction des initiatives plus larges d’AWS en matière de souveraineté numérique. En janvier 2026, AWS a également nommé <a href="https://www.linkedin.com/in/stefanhoechbaue">Stefan Hoechbauer</a> (Vice-président, Allemagne et Europe centrale, AWS) comme directeur général de l’AWS European Sovereign Cloud. Il travaillera aux côtés de Stéphane Israël pour piloter l’AWS European Sovereign Cloud.</p><p>Un conseil consultatif, composé exclusivement de citoyens de l’UE et incluant deux représentants indépendants, apporte un niveau supplémentaire de supervision et d’expertise sur les questions de souveraineté.</p><p><strong>Résidence des données et contrôle renforcés</strong><br />L’AWS European Sovereign Cloud fournit des garanties complètes en matière de résidence des données afin de répondre aux exigences les plus strictes. Comme dans les régions AWS existantes à travers le monde, l’ensemble de vos contenus reste dans la région que vous sélectionnez, sauf indication contraire de votre part. Au-delà des contenus, les métadonnées créées par les clients — telles que les rôles, les autorisations, les étiquettes de ressources et les configurations — restent également au sein de l’UE. L’infrastructure dispose de son propre système dédié de <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (IAM)</a> et de facturation, opérant de manière totalement indépendante à l’intérieur des frontières européennes.</p><p>Des contrôles techniques intégrés à l’infrastructure <a href="https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/design-goals.html">empêchent tout accès à l’AWS European Sovereign Cloud depuis l’extérieur de l’UE</a>. L’infrastructure comprend <a href="https://aws.amazon.com/blogs/security/establishing-a-european-trust-service-provider-for-the-aws-european-sovereign-cloud/">un prestataire européen de services de confiance dédié pour les opérations d’autorité de certification</a> et utilise des serveurs de noms <a href="https://aws.amazon.com/route53/">Amazon Route 53</a> dédiés. Ces serveurs n’utilisent <a href="https://aws.eu/faq/#operational-autonomy">que des domaines de premier niveau (TLD) européens pour leurs propres noms</a>. L’AWS European Sovereign Cloud ne présente aucune dépendance critique vis-à-vis de personnels ou d’infrastructures situés en dehors de l’UE.</p><p><strong>Cadre de sécurité et de conformité<br /></strong> L’AWS European Sovereign Cloud conserve les capacités de sécurité fondamentales attendues d’AWS, notamment le chiffrement, la gestion des clés, la gouvernance des accès et le <a href="https://aws.amazon.com/ec2/nitro/">système AWS Nitro</a> pour l’isolation des charges de calcul. Concrètement, vos instances EC2 bénéficient d’une intégrité de plateforme vérifiée cryptographiquement et de frontières matérielles, empêchant tout accès non autorisé à vos données sans compromis sur les performances. Vous bénéficiez ainsi à la fois des contrôles de souveraineté et de la puissance de calcul nécessaires à vos charges de travail. L’infrastructure fait l’objet <a href="https://aws.amazon.com/blogs/compute/aws-nitro-system-gets-independent-affirmation-of-its-confidential-compute-capabilities/">d’audits indépendants réalisés par des tiers</a>, et s’inscrit dans des programmes de conformité incluant ISO/IEC 27001:2013, les rapports SOC 1/2/3, ainsi que l’attestation C5 de l’<a href="https://www.bsi.bund.de/EN/Home/home_node.html">Office fédéral allemand pour la sécurité de l’information (BSI)</a>.</p><p>Le <a href="https://aws.amazon.com/blogs/security/exploring-the-new-aws-european-sovereign-cloud-sovereign-reference-framework/">AWS European Sovereign Cloud: Sovereign Reference Framework</a> définit précisément les contrôles de souveraineté couvrant l’indépendance de la gouvernance, le contrôle opérationnel, la résidence des données et l’isolation technique. Ce cadre est disponible dans <a href="https://aws.amazon.com/artifact/">AWS Artifact</a> et offre une visibilité de bout en bout via une attestation SOC 2.</p><p><strong>Disponibilité étendue des services<br /></strong> Dès son lancement, l’AWS European Sovereign Cloud donne accès à un large éventail de services AWS, notamment <a href="https://aws.amazon.com/sagemaker/">Amazon SageMaker</a> et <a href="https://aws.amazon.com/bedrock/">Amazon Bedrock</a> pour les charges de travail d’intelligence artificielle et de machine learning (IA/ML). Pour le calcul, vous pouvez utiliser <a href="https://aws.amazon.com/ec2/">Amazon Elastic Compute Cloud (Amazon EC2)</a> et <a href="https://aws.amazon.com/lambda/">AWS Lambda</a>. L’orchestration de conteneurs est disponible via <a href="https://aws.amazon.com/eks/">Amazon Elastic Kubernetes Service (Amazon EKS)</a> et <a href="https://aws.amazon.com/ecs/">Amazon Elastic Container Service (Amazon ECS)</a>. Les services de bases de données incluent <a href="https://aws.amazon.com/rds/aurora/">Amazon Aurora</a>, <a href="https://aws.amazon.com/dynamodb/">Amazon DynamoDB</a> et <a href="https://aws.amazon.com/rds/">Amazon Relational Database Service (Amazon RDS)</a>. Les options de stockage comprennent <a href="https://aws.amazon.com/s3/">Amazon Simple Storage Service (Amazon S3)</a> et <a href="https://aws.amazon.com/ebs/">Amazon Elastic Block Store (Amazon EBS)</a>, avec des capacités réseau via <a href="https://aws.amazon.com/vpc/">Amazon Virtual Private Cloud (Amazon VPC)</a> et des services de sécurité tels que <a href="https://aws.amazon.com/kms/">AWS Key Management Service (AWS KMS)</a> et <a href="https://aws.amazon.com/private-ca/">AWS Private Certificate Authority</a>. Pour obtenir la liste la plus à jour des services disponibles, consultez la <a href="https://builder.aws.com/build/capabilities/explore?f=eJyrVipOzUlNLklNCUpNz8zPK1ayUoqOUUotLU7WTUnVTU0sLtE1jFGKVdKBK3QsS8zMSUzKzMksqQSqdsyrVEARqgUA4l8dog&amp;tab=service-feature">matrice des capacités AWS</a> récemment publiée sur l’AWS Builder Center.</p><p>L’AWS European Sovereign Cloud est <a href="https://aws.amazon.com/blogs/apn/range-of-aws-partner-solutions-set-to-launch-on-the-aws-european-sovereign-cloud/">supporté par de nombreux partenaires AWS</a> engagés à vous aider à répondre à vos exigences de souveraineté. Des partenaires tels qu’Adobe, Cisco, Cloudera, Dedalus, Esri, Genesys, GitLab, Mendix, Pega, SAP, SnowFlake, Trend Micro et Wiz rendent leurs solutions disponibles sur l’AWS European Sovereign Cloud, vous offrant ainsi les outils et services nécessaires dans les domaines de la sécurité, de l’analyse de données, du développement applicatif et des charges de travail spécifiques à certains secteurs industriels. Cet ensemble de partenaires vous permet de construire des solutions souveraines combinant les services AWS et des technologies de partenaires de confiance.</p><p><strong>Un investissement majeur dans l’infrastructure européenne<br /></strong> L’AWS European Sovereign Cloud s’appuie sur un investissement de 7,8 milliards d’euros dans l’infrastructure, la création d’emplois et le développement des compétences. Cet investissement devrait contribuer à hauteur de 17,2 milliards d’euros à l’économie européenne d’ici 2040 et soutenir environ 2.800 emplois équivalent temps plein par an au sein des entreprises locales.</p><p><strong>Quelques détails techniques<br /></strong> L’AWS European Sovereign Cloud est accessible à tous les clients, quel que soit leur lieu d’implantation. Vous pouvez accéder à l’infrastructure en utilisant le nom de <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference-arns.html">partition</a> <code>aws-eusc</code> et le nom de région <code>eusc-de-east-1</code>. Une partition correspond à un ensemble de régions AWS. Chaque compte AWS est rattaché à une seule partition.</p><p>L’infrastructure prend en charge toutes les méthodes d’accès AWS standards, y compris la <a href="https://console.amazonaws-eusc.eu/">console de gestion AWS</a>, les <a href="https://aws.amazon.com/tools/">AWS SDKs</a> et la <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a>, ce qui facilite son intégration dans vos flux de travail et vos automatisations existants. Après avoir créé un nouveau compte racine pour la partition AWS European Sovereign Cloud, vous commencez par définir de nouvelles identités et rôles IAM spécifiques à cette infrastructure, vous donnant un contrôle total sur la gestion des accès au sein de l’environnement souverain européen.</p><p><strong>Pour commencer<br /></strong> L’AWS European Sovereign Cloud offre aux organisations européennes des contrôles de souveraineté renforcés tout en leur permettant de continuer à bénéficier de l’innovation et des capacités d’AWS. Vous pouvez contractualiser les services via Amazon Web Services EMEA SARL, avec une tarification en euros et une facturation possible dans l’une des <a href="https://aws.amazon.com/legal/aws-emea/">huit devises que nous prenons en charge aujourd’hui</a>. L’infrastructure repose sur une architecture, un portefeuille de services et des API AWS familiers, ce qui simplifie le développement et la migration des applications.</p><p>L’<a href="https://aws.eu/de/esca">avenant AWS European Sovereign Cloud</a> précise les engagements contractuels supplémentaires propres à l’AWS European Sovereign Cloud.</p><p>En tant qu’Européen, ce lancement illustre l’engagement d’AWS à répondre aux besoins spécifiques de notre continent et à fournir les capacités cloud qui stimulent l’innovation dans tous les secteurs. Je vous invite à découvrir l’AWS European Sovereign Cloud et à comprendre comment il peut aider votre organisation à satisfaire ses exigences de souveraineté. Consultez <a href="https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/introduction.html">Overview of the AWS European Sovereign Cloud</a> (en anglais) pour en savoir plus sur les objectifs de conception et l’approche retenue, <a href="https://eusc-de-east-1.signin.amazonaws-eusc.eu/signup?request_type=register">créez un nouveau compte</a> et planifiez dès aujourd’hui le déploiement de votre première charge de travail.</p><a href="https://linktr.ee/sebsto">— seb</a><hr id="italian" /><h4 class="c8">Italian version</h4><p><strong>Lancio di AWS European Sovereign Cloud</strong></p><p>Come cittadino europeo, conosco benissimo l’importanza della sovranità digitale, in particolare per le nostre organizzazioni del settore pubblico e dei settori altamente regolamentati. Oggi sono lieto di annunciare che <a href="https://aws.eu/">AWS European Sovereign Cloud</a> è ora generalmente disponibile per tutti i clienti. <a href="https://aws.amazon.com/blogs/aws/in-the-works-aws-european-sovereign-cloud/">Abbiamo annunciato per la prima volta i nostri piani per la creazione di questa nuova infrastruttura cloud indipendente nel 2023.</a> Finalmente oggi è pronta a soddisfare i più rigorosi requisiti di sovranità dei clienti europei <a href="https://aws.amazon.com/blogs/security/announcing-initial-services-available-in-the-aws-european-sovereign-cloud-backed-by-the-full-power-of-aws/">con un set completo di servizi AWS</a>.</p><div class="wp-caption aligncenter c7"><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/12/13/AdobeStock_426378211.jpeg"><img aria-describedby="caption-attachment-102650" class="size-large wp-image-102650" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/12/13/AdobeStock_426378211-1024x341.jpeg" alt="Brandenburg Gate" width="1024" height="341" /></a><p class="wp-caption-text">Berlino, Porta di Brandeburgo al tramonto</p></div><p><strong class="c9">Soddisfare i requisiti di sovranità europea<br /></strong> Le organizzazioni di tutta Europa devono far fronte a requisiti normativi sempre più complessi in materia di residenza dei dati, controllo operativo e indipendenza della governance. Troppo spesso, le organizzazioni europee con i più elevati requisiti di sovranità sono bloccate a causa di offerte o ambienti on-premises legacy con funzionalità e servizi ridotti. In risposta a questa esigenza fondamentale, l’AWS European Sovereign Cloud rappresenta l’unico cloud sovrano con funzionalità complete e a gestione autonoma. supportato da solidi controlli tecnici, garanzie di sovranità e protezioni legali. Gli enti pubblici e le aziende di settori altamente regolamentati necessitano di un’infrastruttura cloud che fornisca controlli di sovranità avanzati che garantiscano l’innovazione, la sicurezza e l’affidabilità che si aspettano dai moderni servizi cloud. Queste organizzazioni devono essere certe che i propri dati e le proprie operazioni restino sotto la giurisdizione europea, con chiare strutture di governance e autonomia operativa nell’ambito dell’Unione europea (UE).</p><p><strong class="c9">Una nuova infrastruttura cloud indipendente per l’Europa</strong><br />L’AWS European Sovereign Cloud rappresenta un’infrastruttura cloud separata fisicamente e logicamente, con tutti i componenti situati interamente all’interno dell’UE. La prima <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region">Regione AWS</a> nell’AWS European Sovereign Cloud, situata nello stato di Brandeburgo (Germania) e ora disponibile a livello generale, opera indipendentemente dalle Regioni AWS esistenti. L’infrastruttura presenta diverse zone di disponibilità con risorse di alimentazione e rete ridondanti, progettate per funzionare continuamente anche in caso di interruzione della connettività con il resto del mondo.</p><p>Abbiamo intenzione di estendere la presenza dell’AWS European Sovereign Cloud dalla Germania all’intera UE per supportare i rigorosi requisiti di isolamento, residenza dei dati all’interno di un determinato Paese e bassa latenza. Inizieremo con nuove <a href="https://docs.aws.amazon.com/local-zones/latest/ug/what-is-aws-local-zones.html">zone locali</a> sovrane situate in Belgio, nei Paesi Bassi e in Portogallo. Inoltre, sarà possibile estendere l’infrastruttura AWS European Sovereign Cloud con <a href="https://aws.amazon.com/dedicatedlocalzones/">Zone locali AWS dedicate</a>, <a href="https://aws.amazon.com/about-aws/global-infrastructure/ai-factories/">AWS AI Factories</a> o <a href="https://aws.amazon.com/outposts/">AWS Outposts</a> in posizioni selezionate, inclusi i data center on-premises.</p><p>L’AWS European Sovereign Cloud e le relative zone locali forniscono controlli sovrani avanzati tramite un modello operativo esclusivo. L’AWS European Sovereign Cloud sarà gestito esclusivamente da residenti UE che si trovano nell’UE. Ciò copre attività come operazioni quotidiane, supporto tecnico e servizio clienti. Stiamo gradualmente trasformando l’AWS European Sovereign Cloud <a href="https://www.aboutamazon.eu/news/aws/aws-european-sovereign-cloud-to-be-operated-by-eu-citizens">in modo che sia gestito esclusivamente da cittadini UE che si trovano nell’UE</a>. Durante questo periodo di transizione, continueremo a lavorare con un team misto di residenti e cittadini comunitari che si trovano nell’UE.</p><p>L’infrastruttura è gestita da entità giuridiche europee dedicate, costituite secondo il diritto tedesco. Nell’ottobre 2025, AWS ha assegnato l’incarico di managing director a <a href="https://www.aboutamazon.eu/news/aws/stephane-israel-appointed-to-lead-the-aws-european-sovereign-cloud">Stéphane Israël</a>, cittadino comunitario residente nell’UE. Sarà responsabile della gestione e delle operazioni dell’AWS European Sovereign Cloud, inclusi infrastruttura, tecnologia e servizi, oltre a guidare le più ampie iniziative di sovranità digitale di AWS. Nel gennaio 2026, AWS ha inoltre nominato managing director dell’AWS European Sovereign Cloud <a href="https://www.linkedin.com/in/stefanhoechbaue">Stefan Höchbauer</a> (vicepresidente, Germania ed Europa centrale, AWS). Collaborerà con Stéphane Israël per guidare l’AWS European Sovereign Cloud.</p><p>Un comitato consultivo composto esclusivamente da cittadini comunitari, inclusi due rappresentanti terzi indipendenti, fornirà ulteriore supervisione e competenza in materia di sovranità.</p><p><strong class="c9">Ottimizzazione del controllo e della residenza dei dati</strong><br />L’AWS European Sovereign Cloud offre garanzie complete sulla residenza dei dati in modo da poter soddisfare i requisiti più rigorosi in materia. Come per le nostre Regioni AWS esistenti a livello mondiale, tutti i contenuti restano all’interno della Regione selezionata, a meno che non si scelga diversamente. Oltre ai contenuti, anche i metadati creati dai clienti, tra cui ruoli, autorizzazioni, etichette delle risorse e configurazioni, restano nell’ambito dell’UE. L’infrastruttura è dotata di un proprio sistema <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (AWS IAM)</a> e di fatturazione dedicato, completamente gestito in modo indipendente all’interno dei confini europei.</p><p>I controlli tecnici integrati nell’infrastruttura <a href="https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/design-goals.html">impediscono l’accesso all’AWS European Sovereign Cloud dall’esterno dell’UE</a>. L’infrastruttura include <a href="https://aws.amazon.com/blogs/security/establishing-a-european-trust-service-provider-for-the-aws-european-sovereign-cloud/">un provider di servizi fiduciari europeo dedicato per le operazioni delle autorità di certificazione</a> e utilizza nameserver <a href="https://aws.amazon.com/route53/">Amazon Route 53</a> dedicati. Questi server utilizzeranno solo <a href="https://aws.eu/faq/#operational-autonomy">domini di primo livello (TLD) europei per i propri nomi</a>. L’AWS European Sovereign Cloud non ha dipendenze fondamentali da personale o infrastrutture non UE.</p><p><strong class="c9">Framework di sicurezza e conformità<br /></strong> L’AWS European Sovereign Cloud mantiene le stesse funzionalità di sicurezza di base di AWS, tra cui crittografia, gestione delle chiavi, governance degli accessi e <a href="https://aws.amazon.com/ec2/nitro/">AWS Nitro System</a> per l’isolamento computazionale. Ciò significa che le istanze EC2 beneficiano dell’integrità della piattaforma verificata a livello di crittografia e dei limiti imposti dall’hardware che impediscono l’accesso non autorizzato ai dati senza compromettere le prestazioni, offrendo i controlli di sovranità e la potenza di calcolo richiesti dai carichi di lavoro. L’infrastruttura è sottoposta ad <a href="https://aws.amazon.com/blogs/compute/aws-nitro-system-gets-independent-affirmation-of-its-confidential-compute-capabilities/">audit di terze parti indipendenti</a>, con programmi di conformità che includono ISO/IEC 27001:2013, report SOC 1/2/3 e attestazione C5 dell’<a href="https://www.bsi.bund.de/EN/Home/home_node.html">Ufficio Federale per la Sicurezza Informatica (BSI)</a>.</p><p>L’<a href="https://aws.amazon.com/blogs/security/exploring-the-new-aws-european-sovereign-cloud-sovereign-reference-framework/">AWS European Sovereign Cloud: Sovereign Reference Framework</a> definisce i controlli di sovranità specifici in termini di indipendenza della governance, controllo operativo, residenza dei dati e isolamento tecnico. Questo framework è disponibile in <a href="https://aws.amazon.com/artifact/">AWS Artifact</a> e fornisce visibilità end-to-end tramite l’attestazione SOC 2.</p><p><strong class="c9">Disponibilità completa del servizio<br /></strong> Dal momento del lancio, sarà possibile accedere a un’ampia gamma di servizi AWS nell’AWS European Sovereign Cloud, tra cui <a href="https://aws.amazon.com/sagemaker/">Amazon SageMaker</a> e <a href="https://aws.amazon.com/bedrock/">Amazon Bedrock</a> per carichi di lavoro di intelligenza artificiale e machine learning (IA/ML). Per i calcoli, è possibile utilizzare <a href="https://aws.amazon.com/ec2/">Amazon Elastic Compute Cloud (Amazon EC2)</a> e <a href="https://aws.amazon.com/lambda/">AWS Lambda</a>. L’orchestrazione di container è disponibile tramite <a href="https://aws.amazon.com/eks/">Amazon Elastic Kubernetes Service (Amazon EKS)</a> e <a href="https://aws.amazon.com/ecs/">Amazon Elastic Container Service (Amazon ECS)</a>. I servizi di database includono <a href="https://aws.amazon.com/rds/aurora/">Amazon Aurora</a>, <a href="https://aws.amazon.com/dynamodb/">Amazon DynamoDB</a> e <a href="https://aws.amazon.com/rds/">Amazon Relational Database Service (Amazon RDS)</a>. Le opzioni di storage includono <a href="https://aws.amazon.com/s3/">Amazon Simple Storage Service (Amazon S3)</a> e <a href="https://aws.amazon.com/ebs/">Amazon Elastic Block Store (Amazon EBS)</a>, con connessione in rete tramite <a href="https://aws.amazon.com/vpc/">Amazon Virtual Private Cloud (Amazon VPC)</a> e servizi di sicurezza tra cui <a href="https://aws.amazon.com/kms/">Servizio AWS di gestione delle chiavi (AWS KMS)</a> e <a href="https://aws.amazon.com/private-ca/">Autorità di certificazione privata AWS (AWS Private CA)</a>. Per un elenco aggiornato dei servizi, è possibile consultare l’<a href="https://builder.aws.com/build/capabilities/explore?f=eJyrVipOzUlNLklNCUpNz8zPK1ayUoqOUUotLU7WTUnVTU0sLtE1jFGKVdKBK3QsS8zMSUzKzMksqQSqdsyrVEARqgUA4l8dog&amp;tab=service-feature">elenco delle funzionalità AWS</a> pubblicato di recente su AWS Builder Center.</p><p>L’AWS European Sovereign Cloud è <a href="https://aws.amazon.com/blogs/apn/range-of-aws-partner-solutions-set-to-launch-on-the-aws-european-sovereign-cloud/">supportato dai partner AWS</a>, che aiutano a soddisfare i propri requisiti di sovranità. Partner come Adobe, Cisco, Cloudera, Dedalus, Esri, Genesys, GitLab, Mendix, Pega, SAP, SnowFlake, Trend Micro e Wiz stanno rendendo disponibili le loro soluzioni nell’AWS European Sovereign Cloud, fornendo gli strumenti e i servizi necessari per la sicurezza, l’analisi dei dati, lo sviluppo di applicazioni e i carichi di lavoro specifici del settore. Questo ampio supporto dei partner aiuta a creare soluzioni sovrane che combinano i servizi AWS con tecnologie di partner affidabili.</p><p><strong class="c9">Investimenti significativi nelle infrastrutture europee<br /></strong> L’AWS European Sovereign Cloud è sostenuto da un investimento di 7,8 miliardi di euro destinati a infrastrutture, creazione di posti di lavoro e sviluppo delle competenze. Si prevede che questo investimento contribuirà con 17,2 miliardi di euro all’economia europea fino al 2040 e sosterrà circa 2.800 posti di lavoro equivalenti a tempo pieno all’anno nelle aziende locali.</p><p><strong class="c9">Alcuni dettagli tecnici<br /></strong> L’AWS European Sovereign Cloud è disponibile per tutti i clienti, indipendentemente da dove si trovino. È possibile accedere all’infrastruttura utilizzando il nome della <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference-arns.html">partizione</a> aws-eusc e il nome della Regione eusc-de-east-1. Una partizione è un gruppo di Regioni AWS. Ogni account AWS è associato a una partizione.</p><p>L’infrastruttura supporta tutti i metodi di accesso AWS standard, tra cui la <a href="https://console.amazonaws-eusc.eu/">Console di gestione AWS</a>, gli <a href="https://aws.amazon.com/tools/">SDK AWS</a> e l’<a href="https://aws.amazon.com/cli/">interfaccia della linea di comando AWS (AWS CLI)</a>, semplificando l’integrazione nell’automazione e nei flussi di lavoro esistenti. Dopo aver creato un nuovo account root per la partizione Di AWS European Sovereign Cloud, si inizia creando nuove identità e ruoli IAM specifici per questa infrastruttura, che consentiranno di avere il controllo completo sulla gestione degli accessi all’interno dell’ambiente sovrano europeo.</p><p><strong class="c9">Nozioni di base<br /></strong> L’AWS European Sovereign Cloud fornisce alle organizzazioni europee controlli di sovranità avanzati pur mantenendo l’accesso all’innovazione e alle funzionalità di AWS. È possibile contrattare servizi tramite Amazon Web Services EMEA SARL, con prezzi in EUR e fatturazione in una <a href="https://aws.amazon.com/legal/aws-emea/">delle otto valute supportate oggi</a>. L’infrastruttura utilizza l’architettura AWS, il portafoglio di servizi e le API tradizionali, semplificando la creazione e la migrazione delle applicazioni.</p><p>L’<a href="https://aws.eu/de/esca">addendum di AWS European Sovereign Cloud</a> include gli impegni contrattuali aggiuntivi per l’AWS European Sovereign Cloud.</p><p>Per me come europeo, questo lancio rappresenta l’impegno di AWS per soddisfare le esigenze specifiche del nostro continente e fornire le funzionalità cloud che guidano l’innovazione in tutti i settori. Invito tutti a scoprire di più sull’AWS European Sovereign Cloud e su come può aiutare le organizzazioni a soddisfare i requisiti di sovranità. Nella <a href="https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/introduction.html">Panoramica di AWS European Sovereign Cloud</a> sono disponibili maggiori informazioni sugli obiettivi e sull’approccio di progettazione, <a href="https://eusc-de-east-1.signin.amazonaws-eusc.eu/signup?request_type=register">creare un nuovo account</a>  e pianificare l’implementazione del primo carico di lavoro oggi stesso.</p><p><a href="https://linktr.ee/sebsto">— seb</a></p><hr id="spanish" /><h4 class="c8">Spanish version</h4><p><strong>Apertura de AWS European Sovereign Cloud</strong></p><p>Como ciudadano europeo, comprendo de primera mano la importancia de la soberanía digital, especialmente para las organizaciones de nuestro sector público y las industrias altamente reguladas. Hoy me complace anunciar que la <a href="https://aws.eu/">AWS European Sovereign Cloud</a> ya está disponible de forma generalizada para todos los clientes. <a href="https://aws.amazon.com/blogs/aws/in-the-works-aws-european-sovereign-cloud/">Anunciamos por primera vez nuestros planes de crear esta nueva infraestructura de nube independiente en 2023</a>, y hoy está lista para cumplir los requisitos de soberanía más estrictos de los clientes europeos <a href="https://aws.amazon.com/blogs/security/announcing-initial-services-available-in-the-aws-european-sovereign-cloud-backed-by-the-full-power-of-aws/">con un exhaustivo conjunto de servicios de AWS</a>.</p><p>Berlín, Puerta de Brandeburgo al atardecer</p><p><strong class="c9">Cumplimiento de los requisitos de soberanía europeos<br /></strong> Las organizaciones de toda Europa se enfrentan a unos requisitos normativos cada vez más complejos en relación con la residencia de los datos, el control operativo y la independencia de la gobernanza. Hoy en día, con demasiada frecuencia, las organizaciones europeas con los requisitos de soberanía más estrictos se ven atrapadas en entornos locales heredados u ofertas con servicios y funcionalidades reducidos. En respuesta a esta necesidad crítica, la AWS European Sovereign Cloud es la única nube soberana independiente con todas las características que está respaldada por sólidos controles técnicos, garantías de soberanía y protecciones legales. Las entidades del sector público y las empresas de industrias altamente reguladas necesitan una infraestructura en la nube que proporcione controles de soberanía mejorados que mantengan la innovación, la seguridad y la fiabilidad que se esperan de los servicios modernos en la nube. Estas organizaciones necesitan la garantía de que sus datos y operaciones permanecen bajo la jurisdicción europea, con estructuras de gobernanza claras y autonomía operativa dentro de la Unión Europea (UE).</p><p><strong class="c9">Una nueva infraestructura de nube independiente para Europa</strong><br />La AWS European Sovereign Cloud es una infraestructura de nube separada de manera física y lógica, en la que todos los componentes están ubicados íntegramente dentro de la UE. La primera <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region">región de AWS</a> de la AWS European Sovereign Cloud se encuentra en el estado de Brandeburgo (Alemania) y ya está disponible para el público en general. Esta región opera de forma independiente de las regiones de AWS existentes. La infraestructura cuenta con varias zonas de disponibilidad con fuentes de alimenacion y redes redundantes, diseñadas para funcionar de forma continua incluso si se interrumpe la conectividad con el resto del mundo.</p><p>Tenemos previsto ampliar la presencia de la AWS European Sovereign Cloud de Alemania a toda la UE para cumplir los requisitos de aismlamiento estrictos, residencia de los datos dentro del país y baja latencia. Esto comenzará con nuevas <a href="https://docs.aws.amazon.com/local-zones/latest/ug/what-is-aws-local-zones.html">zonas locales</a> soberanas ubicadas en Bélgica, los Países Bajos y Portugal. Además, podrá ampliar la infraestructura de la AWS European Sovereign Cloud con <a href="https://aws.amazon.com/dedicatedlocalzones/">zonas locales dedicadas de AWS</a>, <a href="https://aws.amazon.com/about-aws/global-infrastructure/ai-factories/">AWS AI Factories</a> o <a href="https://aws.amazon.com/outposts/">AWS Outposts</a> en las ubicaciones que elija, incluidos sus propios centros de datos locales.</p><p>La AWS European Sovereign Cloud y sus zonas locales proporcionan controles soberanos mejorados a través de su modelo operativo único. La AWS European Sovereign Cloud será operada exclusivamente por residentes de la UE ubicados en la UE. Abarca actividades como las operaciones diarias, la asistencia técnica y el servicio de atención al cliente. Estamos realizando una transición gradual de la AWS European Sovereign Cloud para que <a href="https://www.aboutamazon.eu/news/aws/aws-european-sovereign-cloud-to-be-operated-by-eu-citizens">se opere exclusivamente por ciudadanos de la UE ubicados en la UE</a>. Durante este período de transición, seguiremos trabajando con un equipo mixto de residentes de la UE y ciudadanos de la UE ubicados en la UE.</p><p>La infraestructura se administra a través de entidades jurídicas europeas especializadas constituidas en el marco de la legislación alemana. En octubre de 2025, AWS nombró director general a <a href="https://www.aboutamazon.eu/news/aws/stephane-israel-appointed-to-lead-the-aws-european-sovereign-cloud">Stéphane Israël</a>, ciudadano de la UE que reside en la UE. Stéphane será responsable de la administración y las operaciones de la AWS European Sovereign Cloud, lo que incluye la infraestructura, la tecnología y los servicios, además de liderar los esfuerzos más amplios de AWS en materia de soberanía digital. En enero de 2026, AWS también nombró a <a href="https://www.linkedin.com/in/stefanhoechbaue">Stefan Hoechbauer</a> (vicepresidente de AWS para Alemania y Europa Central) director general de la AWS European Sovereign Cloud. Stefan dirigirá la AWS European Sovereign Cloud junto con Stéphane Israël.</p><p>Un consejo consultivo compuesto exclusivamente por ciudadanos de la UE, que incluye a dos representantes independientes externos, proporciona supervisión y experiencia adicional en materia de soberanía.</p><p><strong class="c9">Mejor control y residencia de datos</strong><br />La AWS European Sovereign Cloud ofrece amplias garantías de residencia de datos para que pueda cumplir los requisitos más estrictos en materia de residencia de datos. Al igual que ocurre con nuestras regiones de AWS existentes en todo el mundo, todo el contenido permanece dentro la región que elija, a menos que decida lo contrario. Además del contenido, los metadatos creados por los clientes, incluidos los roles, los permisos, las etiquetas de recursos y las configuraciones, también permanecen dentro de la UE. La infraestructura cuenta con su propio sistema dedicado de <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (AWS IAM)</a> y facturación, que funciona de forma independiente dentro de las fronteras europeas.</p><p>Los controles técnicos integrados en la infraestructura <a href="https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/design-goals.html">impiden el acceso a la AWS European Sovereign Cloud desde fuera de la UE</a>. La infraestructura incluye <a href="https://aws.amazon.com/blogs/security/establishing-a-european-trust-service-provider-for-the-aws-european-sovereign-cloud/">un proveedor de servicios de confianza europeo dedicado para las operaciones de las autoridades de certificación</a> y utiliza servidores de nombres de <a href="https://aws.amazon.com/route53/">Amazon Route 53</a> dedicados. Estos servidores solo usarán <a href="https://aws.eu/faq/#operational-autonomy">dominios de nivel superior europeos para sus propios nombres</a>. La AWS European Sovereign Cloud no tiene dependencias críticas de personal o infraestructura fuera de la UE.</p><p><strong class="c9">Marco de seguridad y cumplimiento<br /></strong> La AWS European Sovereign Cloud mantiene las mismas capacidades de seguridad básicas que cabe esperar de AWS, como el cifrado, la administración de claves, la gobernanza del acceso y <a href="https://aws.amazon.com/ec2/nitro/">AWS Nitro System</a> para el aislamiento de la computación. Esto significa que sus instancias de EC2 se benefician de la integridad de la plataforma verificada criptográficamente y de los límites impuestos por el hardware que impiden el acceso no autorizado a sus datos sin comprometer el rendimiento, lo que le proporciona tanto los controles de soberanía como la potencia computacional que requieren sus cargas de trabajo. La infraestructura se somete a <a href="https://aws.amazon.com/blogs/compute/aws-nitro-system-gets-independent-affirmation-of-its-confidential-compute-capabilities/">auditorías independientes externas</a>, con programas de cumplimiento que incluyen la norma ISO/IEC 27001:2013, informes SOC 1/2/3 y la certificación C5 de la <a href="https://www.bsi.bund.de/EN/Home/home_node.html">Oficina Federal de Seguridad de la Información</a>.</p><p>El <a href="https://aws.amazon.com/blogs/security/exploring-the-new-aws-european-sovereign-cloud-sovereign-reference-framework/">marco de referencia de soberanía de la AWS European Sovereign Cloud</a> define los controles de soberanía específicos en relación con la independencia de la gobernanza, el control operativo, la residencia de datos y el aislamiento técnico. Este marco está disponible en <a href="https://aws.amazon.com/artifact/">AWS Artifact</a> y proporciona visibilidad total a través de la certificación SOC 2.</p><p><strong class="c9">Disponibilidad total del servicio<br /></strong> Puede acceder a una amplia variedad de servicios de AWS en la AWS European Sovereign Cloud desde su lanzamiento, incluidos <a href="https://aws.amazon.com/sagemaker/">Amazon SageMaker</a> y <a href="https://aws.amazon.com/bedrock/">Amazon Bedrock</a> para cargas de trabajo de inteligencia artificial y machine learning. Para el procesamiento, puede usar <a href="https://aws.amazon.com/ec2/">Amazon Elastic Compute Cloud (Amazon EC2)</a> y <a href="https://aws.amazon.com/lambda/">AWS Lambda</a>. La orquestación de contenedores está disponible a través de <a href="https://aws.amazon.com/eks/">Amazon Elastic Kubernetes Service (Amazon EKS)</a> y <a href="https://aws.amazon.com/ecs/">Amazon Elastic Container Service (Amazon ECS)</a>. Los servicios de bases de datos incluyen <a href="https://aws.amazon.com/rds/aurora/">Amazon Aurora</a>, <a href="https://aws.amazon.com/dynamodb/">Amazon DynamoDB</a> y <a href="https://aws.amazon.com/rds/">Amazon Relational Database Service (Amazon RDS)</a>. Dispone de opciones de almacenamiento como <a href="https://aws.amazon.com/s3/">Amazon Simple Storage Service (Amazon S3)</a> y <a href="https://aws.amazon.com/ebs/">Amazon Elastic Block Store (Amazon EBS)</a>, con redes a través de <a href="https://aws.amazon.com/vpc/">Amazon Virtual Private Cloud (Amazon VPC)</a> y servicios de seguridad como <a href="https://aws.amazon.com/kms/">AWS Key Management Service (AWS KMS)</a> y <a href="https://aws.amazon.com/private-ca/">AWS Private Certificate Authority</a>. Para obtener una lista actualizada de los servicios, consulte la <a href="https://builder.aws.com/build/capabilities/explore?f=eJyrVipOzUlNLklNCUpNz8zPK1ayUoqOUUotLU7WTUnVTU0sLtE1jFGKVdKBK3QsS8zMSUzKzMksqQSqdsyrVEARqgUA4l8dog&amp;tab=service-feature">matriz de capacidades de AWS</a> que se ha publicado recientemente en AWS Builder Center.</p><p>La AWS European Sovereign Cloud <a href="https://aws.amazon.com/blogs/apn/range-of-aws-partner-solutions-set-to-launch-on-the-aws-european-sovereign-cloud/">cuenta con el respaldo de los socios de AWS</a>, que se comprometen a ayudarle a cumplir sus requisitos de soberanía. Socios como Adobe, Cisco, Cloudera, Dedalus, Esri, Genesys, GitLab, Mendix, Pega, SAP, SnowFlake, Trend Micro y Wiz ofrecen sus soluciones en la AWS European Sovereign Cloud, lo que le proporciona las herramientas y los servicios que necesita en materia de seguridad, análisis de datos, desarrollo de aplicaciones y cargas de trabajo específicas del sector. Este amplio apoyo de los socios le ayuda a crear soluciones soberanas que combinan los servicios de AWS con tecnologías de socios de confianza.</p><p><strong class="c9">Inversión importante. en la infraestructura europea<br /></strong> La AWS European Sovereign Cloud está respaldada por una inversión de 7.800 millones de EUR en infraestructura, creación de empleo y desarrollo de habilidades. Se espera que esta inversión aporte 17.200 millones de EUR a la economía europea para 2040 y ayude a crear el equivalente a aproximadamente 2.800 puestos de trabajo a tiempo completo por año en empresas locales.</p><p><strong class="c9">Algunos detalles técnicos<br /></strong> La AWS European Sovereign Cloud está disponible para todos los clientes, independientemente de dónde se encuentren. Puede acceder a la infraestructura utilizando el nombre de <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference-arns.html">partición</a> aws-eusc y el nombre de región eusc-de-east-1. Una partición es un grupo de regiones de AWS. Cada cuenta de AWS tiene limitado su alcance a una sola partición.</p><p>La infraestructura admite todos los métodos de acceso estándar de AWS, como la <a href="https://console.amazonaws-eusc.eu/">Consola de administración de AWS</a>, los <a href="https://aws.amazon.com/tools/">AWS SDK</a> y la <a href="https://aws.amazon.com/cli/">Interfaz de la línea de comandos de AWS (AWS CLI)</a>, lo que facilita la integración en sus flujos de trabajo y automatización existentes. Tras crear una nueva cuenta raíz para la partición de la AWS European Sovereign Cloud, primero deberá crear nuevas identidades y roles de IAM específicos para esta infraestructura, lo que le permitirá tener un control total sobre la administración del acceso en el entorno soberano europeo.</p><p><strong class="c9">Cómo empezar<br /></strong> La AWS European Sovereign Cloud proporciona a las organizaciones europeas controles de soberanía mejorados, al tiempo que mantiene el acceso a la innovación y las capacidades de AWS. Puede contratar los servicios a través de Amazon Web Services EMEA SARL, con precios en EUR y facturación en cualquiera de <a href="https://aws.amazon.com/legal/aws-emea/">las ocho divisas que admitimos actualmente</a>. La infraestructura utiliza la arquitectura, la cartera de servicios y las API habituales de AWS, lo que facilita la creación y la migración de aplicaciones.</p><p>La <a href="https://aws.eu/de/esca">adenda de la AWS European Sovereign Cloud</a> contiene los compromisos contractuales adicionales para la AWS European Sovereign Cloud.</p><p>Para mí, como europeo, este lanzamiento representa el compromiso de AWS de satisfacer las necesidades específicas de nuestro continente y proporcionar las capacidades en la nube que impulsan la innovación en todos los sectores. Le invito a descubrir más sobre la AWS European Sovereign Cloud y cómo puede ayudar a su organización a cumplir sus requisitos de soberanía. Lea la <a href="https://docs.aws.amazon.com/whitepapers/latest/overview-aws-european-sovereign-cloud/introduction.html">descripción general de la AWS European Sovereign Cloud</a> para obtener más información sobre los objetivos y el enfoque del diseño, <a href="https://eusc-de-east-1.signin.amazonaws-eusc.eu/signup?request_type=register">regístrese para obtener una nueva cuenta</a> y planifique hoy mismo el despliegue de su primera carga de trabajo.</p><p><a href="https://linktr.ee/sebsto">— seb</a></p>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/opening-the-aws-european-sovereign-cloud/"/>
    <updated>2026-01-15T08:12:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-lambda-for-net-10-aws-client-vpn-quickstart-best-of-aws-reinvent-and-more-january-12-2026/</id>
    <title><![CDATA[AWS Weekly Roundup: AWS Lambda for .NET 10, AWS Client VPN quickstart, Best of AWS re:Invent, and more (January 12, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>At the beginning of January, I tend to set my top resolutions for the year, a way to focus on what I want to achieve. If AI and cloud computing are on your resolution list, consider creating an <a href="https://aws.amazon.com/free?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">AWS Free Tier</a> account to receive up to $200 in credits and have 6 months of risk-free experimentation with AWS services.</p><p>During this period, you can explore essential services across compute, storage, databases, and AI/ML, plus access to over 30 always-free services with monthly usage limits. After 6 months, you can decide whether to upgrade to a standard AWS account.</p><p>Whether you’re a student exploring career options, a developer expanding your skill set, or a professional building with cloud technologies, this hands-on approach lets you focus on what matters most: developing real expertise in the areas you’re passionate about.</p><p><strong>Last week’s launches</strong><br />Here are the launches that got my attention this week:</p><ul><li><a href="https://aws.amazon.com/lambda?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">AWS Lambda</a> – Now <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/aws-lambda-dot-net-10/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">supports creating serverless applications using .NET 10</a> both as a managed runtime and a container base image. AWS will automatically apply updates to the managed runtime and base image as they become available. More info in <a href="https://aws.amazon.com/blogs/compute/net-10-runtime-now-available-in-aws-lambda/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">this blog post</a>.</li>
<li><a href="https://aws.amazon.com/ecs/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Amazon ECS</a> – Adds <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-ecs-tmpfs-mounts-aws-fargate-managed-instances/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">support for tmpfs mounts to Linux tasks running on AWS Fargate and Amazon ECS Managed Instances</a> in addition to the EC2 launch type. With tmpfs, you can create memory-backed file systems for your containerized workloads without writing data to task storage.</li>
<li><a href="https://aws.amazon.com/config/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">AWS Config</a> – Can now discover, assess, audit, and remediate <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/aws-config-new-resource-types/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">additional AWS resource types</a> across key services including Amazon EC2, Amazon SageMaker, and Amazon S3 Tables.</li>
<li><a href="https://aws.amazon.com/amazon-mq/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Amazon MQ</a> – <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-mq-http-based-rabbitmq-brokers/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Introduces HTTP based authentication for RabbitMQ brokers</a>. You can configure this plugin on brokers by making changes to the associated configuration file. It now also <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-mq-certificate-based-authentication-mutual-tls-rabbitmq/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">supports certificate based authentication with mutual TLS</a> for RabbitMQ brokers.</li>
<li><a href="https://aws.amazon.com/managed-workflows-for-apache-airflow/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Amazon MWAA</a> – You can <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/apache-airflow-2-11-support-amazon-managed-workflows/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">now create Apache Airflow version 2.11 environments</a> with Amazon Managed Workflows for Apache Airflow. This version of Apache Airflow introduces changes that help you prepare for upgrading to Apache Airflow 3.</li>
<li><a href="https://aws.amazon.com/ec2/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Amazon EC2</a> – <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-ec2-m8i-instances-additional-regions/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">M8i</a>, <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-ec2-c8i-c8i-flex-instances-additional-aws-regions/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">C8i and C8i-flex</a>, <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-ec2-r8i-r8i-flex-instances-additional-aws-regions/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">R8i and R8i-flex</a>, and <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-ec2-i7ie-instances-additional-aws-regions/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">I7ie instances are now available</a> in additional AWS Regions.</li>
<li><a href="https://aws.amazon.com/vpn/client-vpn/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">AWS Client VPN</a> – A <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/aws-client-vpn-onboarding-quickstart-setup/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">new quickstart reduces the number of steps required</a> to set up a Client VPN endpoint.</li>
<li><a href="https://aws.amazon.com/quicksuite/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Amazon Quick Suite</a> – Added <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/3p-agent-in-quick/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">integrations for AI agents and to its built-in actions library</a>. For example, these now include GitHub, Notion, Canva, Box, Linear, Hugging Face, Monday.com, HubSpot, Intercom, and more.</li>
</ul><p><strong>Additional updates<br /></strong> Here are some additional projects, blog posts, and news items that I found interesting:</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/12/crossmodal-search-amazon-nova-multimodal-embeddings-architecture.png"><img class="aligncenter size-full wp-image-102789" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/12/crossmodal-search-amazon-nova-multimodal-embeddings-architecture.png" alt="Crossmodal search with Amazon Nova Multimodal Embeddings Architecture" width="1430" height="653" /></a></p><p><strong>Upcoming AWS events<br /></strong> Join us January 28 or 29 (depending on your time zone) for <a href="https://aws.amazon.com/best-of-reinvent/">Best of AWS re:Invent</a>, a free virtual event where we bring you the most impactful announcements and top sessions from AWS re:Invent. Jeff Barr, AWS VP and Chief Evangelist, will share his highlights during the opening session.</p><p>There is still time until January 21 to compete for $250,000 in prizes and AWS credits in the <a href="https://builder.aws.com/connect/events/10000aideas?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Global 10,000 AIdeas Competition</a> (yes, the second letter is an I as in Idea, not an L as in like). No code required yet: simply submit your idea, and if you’re selected as a semifinalist, you’ll build your app using <a href="https://kiro.dev/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Kiro</a> within <a href="https://aws.amazon.com/free?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">AWS Free Tier</a> limits. Beyond the cash prizes and potential featured placement at <a href="https://reinvent.awsevents.com/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">AWS re:Invent 2026</a>, you’ll gain hands-on experience with next-generation AI tools and connect with innovators globally.</p><p>If you’re interested in these opportunities, join the <a href="https://builder.aws.com/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">AWS Builder Center</a> to learn with builders in the AWS community.</p><p>That’s all for this week. Check back next Monday for another <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/?trk=39d9c26c-b157-46ae-bde6-9cf598f5c9e0&amp;sc_channel=el">Weekly Roundup</a>!</p><p>– <a href="https://x.com/danilop">Danilo</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="3c6b480e-81e3-4317-82be-dc0ca3fde21f" data-title="AWS Weekly Roundup: AWS Lambda for .NET 10, AWS Client VPN quickstart, Best of AWS re:Invent, and more (January 12, 2026)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-lambda-for-net-10-aws-client-vpn-quickstart-best-of-aws-reinvent-and-more-january-12-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-lambda-for-net-10-aws-client-vpn-quickstart-best-of-aws-reinvent-and-more-january-12-2026/"/>
    <updated>2026-01-12T18:39:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/happy-new-year-aws-weekly-roundup-10000-aideas-competition-amazon-ec2-amazon-ecs-managed-instances-and-more-january-5-2026/</id>
    <title><![CDATA[Happy New Year! AWS Weekly Roundup: 10,000 AIdeas Competition, Amazon EC2, Amazon ECS Managed Instances and more (January 5, 2026)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Happy New Year! I hope the holidays gave you time to recharge and spend time with your loved ones.</p><p>Like every year, I took a few weeks off after <a href="https://aws.amazon.com/reinvent/">AWS re:Invent</a> to rest and plan ahead. I used some of that downtime to plan the next cohort for <a href="https://besaprogram.com/">Become a Solutions Architect (BeSA)</a>. BeSA is a free mentoring program that I, along with a few other <a href="https://aws.amazon.com/">Amazon Web Services (AWS)</a> employees, volunteer to host as a way to help people excel in their cloud and AI careers. We’re kicking off a 6-week cohort on “Agentic AI on AWS” starting February 21, 2026. Visit the <a href="https://besaprogram.com/">BeSA website</a> to learn more.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/02/10k-AIdeas-1080x1080-1.jpg"><img class="alignright wp-image-102711 size-medium" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2026/01/02/10k-AIdeas-1080x1080-1-300x300.jpg" alt="" width="300" height="300" /></a>There is still time to submit your idea for the <a href="https://builder.aws.com/connect/events/10000aideas">Global 10,000 AIdeas Competition</a> and compete for $250,000 in cash prizes, AWS credits, and recognition, including potential featured placement at AWS re:Invent 2026 and across AWS channels.</p><p>You will gain hands-on experience with next-generation AI development tools, connect with innovators globally, and access technical enablement through biweekly workshops, AWS User Groups, and AWS Builder Center resources.</p><p>The deadline is January 21, 2026, and no code is required yet. If you’re selected as a semifinalist, you’ll build your app then. Your finished app needs to use Kiro for at least part of development, stay within <a href="https://aws.amazon.com/free/">AWS Free Tier</a> limits, and be completely original and not yet published.</p><p>If you haven’t yet caught up with all the new releases and announcements from AWS re:Invent 2025, check out our <a href="https://aws.amazon.com/blogs/aws/top-announcements-of-aws-reinvent-2025/">top announcements post</a> or <a href="https://reinvent.awsevents.com/on-demand/">watch the keynotes, innovation talks, and breakout sessions on-demand</a>.</p><p><strong>Launches from the last few weeks</strong><br />I’d like to highlight some launches that got my attention since our last Week in Review on December 15, 2025:</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/generally-available-amazon-ec2-m8gn-m8gb-instances/">Amazon EC2 M8gn and M8gb instances</a> – New M8gn and M8gb instances are powered by AWS Graviton4 processors to deliver up to 30% better compute performance than AWS Graviton3 processors. M8gn instances feature the latest 6th generation AWS Nitro Cards, and offer up to 600 Gbps network bandwidth, the highest network bandwidth among network-optimized EC2 instances. M8gb offer up to 150 Gbps of Amazon EBS bandwidth to provide higher EBS performance compared to same-sized equivalent Graviton4-based instances.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/direct-connect-resilience-testing-fault-injection-service/">AWS Direct Connect supports resilience testing with AWS Fault Injection Service</a> – You can now use AWS Fault Injection Service to test how your applications handle Direct Connect Border Gateway Protocol (BGP) failover in a controlled environment. For example, you can validate that traffic routes to redundant virtual interfaces when a primary virtual interface’s BGP session is disrupted and your applications continue to function as expected.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/176-security-hub-controls-control-tower/">New AWS Security Hub controls in AWS Control Tower</a> – AWS Control Tower now supports 176 additional Security Hub controls in the Control Catalog, covering use cases including security, cost, durability, and operations. With this launch, you can search, discover, enable, and manage these controls directly from AWS Control Tower to govern additional use cases across your multi-account environment.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/aws-transform-hybrid-network-migration/">AWS Transform supports network conversion for hybrid data center migrations</a> – You can now use AWS Transform for VMware to automatically convert networks from hybrid data centers. This removes manual network mapping for environments running both VMware and other workloads. The service analyzes VLANs and IP ranges across all exported source networks and maps them to AWS constructs such as virtual private clouds (VPCs), subnets, and security groups.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/nvidia-nemotron-3-nano-amazon-bedrock/">NVIDIA Nemotron 3 Nano available on Amazon Bedrock</a> – Amazon Bedrock now supports NVIDIA Nemotron 3 Nano 30B A3B model, NVIDIA’s latest breakthrough in efficient language modeling that delivers high reasoning performance, built-in tool calling support, and extended context processing with 256K token context window.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-ec2-az-id-api-support/">Amazon EC2 supports Availability Zone ID across its APIs</a> – You can specify the Availability Zone ID (AZ ID) parameter directly in your Amazon EC2 APIs to guarantee consistent placement of resources. AZ IDs are consistent and static identifiers that represent the same physical location across all AWS accounts, helping you optimize resource placement. Prior to this launch, you had to use an AZ name while creating a resource, but these names could map to different physical locations. This mapping made it difficult to ensure resources were always co-located, especially when operating with multiple accounts.</li>
<li><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-ecs-managed-instances-ec2-spot-instances/">Amazon ECS Managed Instances supports Amazon EC2 Spot Instances</a> – Amazon ECS Managed Instances now supports Amazon EC2 Spot Instances, extending the range of capabilities available with AWS managed infrastructure. You can use spare EC2 capacity at up to 90% discount compared to On-Demand prices for fault-tolerant workloads in Amazon ECS Managed Instances.</li>
</ul><p>See <a href="https://aws.amazon.com/new/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">AWS What’s New</a> for more launch news that I haven’t covered here. That’s all for this week. Check back next Monday for another Weekly Roundup!</p><p>Here’s to a fantastic start to 2026. Happy building!</p><p>– <a href="https://www.linkedin.com/in/kprasadrao/">Prasad</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="0253ba8e-0988-4f4a-a27b-8726db8ce8aa" data-title="Happy New Year! AWS Weekly Roundup: 10,000 AIdeas Competition, Amazon EC2, Amazon ECS Managed Instances and more (January 5, 2026)" data-url="https://aws.amazon.com/blogs/aws/happy-new-year-aws-weekly-roundup-10000-aideas-competition-amazon-ec2-amazon-ecs-managed-instances-and-more-january-5-2026/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/happy-new-year-aws-weekly-roundup-10000-aideas-competition-amazon-ec2-amazon-ecs-managed-instances-and-more-january-5-2026/"/>
    <updated>2026-01-05T18:10:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-ecs-amazon-cloudwatch-amazon-cognito-and-more-december-15-2025/</id>
    <title><![CDATA[AWS Weekly Roundup: Amazon ECS, Amazon CloudWatch, Amazon Cognito and more (December 15, 2025)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Can you believe it? We’re nearly at the end of 2025. And what a year it’s been! From re:Invent recap events, to AWS Summits, AWS Innovate, AWS re:Inforce, Community Days, and DevDays and, recently, adding that cherry on the cake, re:Invent 2025, we have lived through a year filled with exciting moments and technology advancements which continue to shape our new modern world.</p><p>Speaking of re:Invent, if you haven’t caught up yet on all the new releases and announcements (and there were plenty of exciting launches across every area), be sure to check out our curated post highlighting the <a href="https://aws.amazon.com/blogs/aws/top-announcements-of-aws-reinvent-2025?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">top announcements from AWS re:Invent 2025</a>. We’ve organized all the key releases into easy-to-navigate categories and included links so you can dive deeper into anything that sparks your interest.</p><p>While the year may be wrapping up, our teams are still busy working on things that you have either asked for as customers or that we pro-actively create to make your lives easier. Last week had quite a few interesting releases as usual, so let’s look at a few that I think could be useful for many of you out there.</p><p><strong>Last week’s launches</strong></p><p><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-workspaces-secure-browser-web-content-filtering/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon WorkSpaces Secure Browser introduces Web Content Filtering</a> – Organizations can now control web access through category-based filtering across 25+ predefined categories, granular URL policies, and integrated compliance logging. The feature works alongside existing Chrome policies and integrates with Session Logger for enhanced monitoring and is available at no additional cost in 10 AWS Regions with pay-as-you-go pricing.</p><p><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-aurora-dsql-cluster-creation-in-seconds/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon Aurora DSQL now supports cluster creation in seconds</a> – Developers can now instantly provision Aurora DSQL databases with setup time reduced from minutes to seconds, enabling rapid prototyping through the integrated AWS console query editor or AI-powered development via the Aurora DSQL Model Context Protocol server. Available at no additional cost in all AWS Regions where Aurora DSQL is offered, with AWS Free Tier access available.</p><p><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-aurora-postgresql-integration-kiro-powers/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon Aurora PostgreSQL now supports integration with Kiro powers</a> – Developers can now accelerate Aurora PostgreSQL application development using AI-assisted coding through Kiro powers, a repository of pre-packaged Model Context Protocol servers. The Aurora PostgreSQL integration provides direct database connectivity for queries, schema management, and cluster operations, dynamically loading relevant context as developers work. Available for one-click installation in Kiro IDE across all AWS Regions.</p><p><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-ecs-custom-container-stop-signals-fargate/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon ECS now supports custom container stop signals on AWS Fargate</a> – Fargate tasks now honor the stop signal configured in container images, enabling graceful shutdowns for containers that rely on signals like SIGQUIT or SIGINT instead of the default SIGTERM. The ECS container agent reads the STOPSIGNAL instruction from OCI-compliant images and sends the appropriate signal during task termination. Available at no additional cost across all AWS Regions.</p><p><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-cloudwatch-sdk-json-cbor-protocols/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon CloudWatch SDK supports optimized JSON, CBOR protocols</a> – CloudWatch SDK now defaults to JSON and CBOR protocols, delivering lower latency, reduced payload sizes, and decreased client-side CPU and memory usage compared to the traditional AWS Query protocol. Available at no additional cost across all AWS Regions and SDK language variants.</p><p><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/amazon-cognito-identity-pools-private-connectivity-aws-privatelink/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon Cognito identity pools now support private connectivity with AWS PrivateLink</a> – Organizations can now securely exchange federated identities for temporary AWS credentials through private VPC connections, eliminating the need to route authentication traffic over the public internet. Available in all AWS Regions where Cognito identity pools are supported, except AWS China (Beijing) and AWS GovCloud (US) Regions.</p><p><a href="https://aws.amazon.com/about-aws/whats-new/2025/12/application-migration-service-ipv6?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">AWS Application Migration Service supports IPv6</a> – Organizations can now migrate applications using IPv6 addressing through dual-stack service endpoints that support both IPv4 and IPv6 communications. During replication, testing, and cutover phases, you can use IPv4, IPv6, or dual-stack configurations to launch servers in your target environment. Available at no additional cost in all AWS Regions that support MGN and EC2 dual-stack endpoints.</p><p>And that’s it for the AWS News Blog Weekly Roundup…not just for this week, but for 2025! We’ll be taking a break and returning in January to continue bringing you the latest AWS releases and updates.</p><p>As we close out 2025, it’s remarkable to look back at just how much has changed since the beginning of year. From groundbreaking AI capabilities to transformative infrastructure innovations, AWS has delivered an incredible year of releases that have reshaped what’s possible in the cloud. Throughout it all, the AWS News Blog has been right here with you every week with our Weekly Roundup series, helping you stay informed and ready to take advantage of each new opportunity as it arrived. We’re grateful you’ve joined us on this journey, and we can’t wait to continue bringing you the latest AWS innovations when we return in January 2026.</p><p>Until then, happy building, and here’s to an even more exciting year ahead!</p><a href="https://link.codingmatheus.com/linkedin">Matheus Guimaraes | @codingmatheus</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="a31a556d-c15f-49bb-9753-fa6cb63aa282" data-title="AWS Weekly Roundup: Amazon ECS, Amazon CloudWatch, Amazon Cognito and more (December 15, 2025)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-ecs-amazon-cloudwatch-amazon-cognito-and-more-december-15-2025/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-amazon-ecs-amazon-cloudwatch-amazon-cognito-and-more-december-15-2025/"/>
    <updated>2025-12-15T17:42:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-reinvent-keynote-recap-on-demand-videos-and-more-december-8-2025/</id>
    <title><![CDATA[AWS Weekly Roundup: AWS re:Invent keynote recap, on-demand videos, and more (December 8, 2025)]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>The week after AWS re:Invent builds on the excitement and energy of the event and is a good time to learn more and understand how the recent announcements can help you solve your challenges and unlock new opportunities. As usual, we have you covered with our <a href="https://aws.amazon.com/blogs/aws/top-announcements-of-aws-reinvent-2025/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">top announcements of AWS re:Invent 2025</a> that you can learn all about here.</p><p>For me, one moment stood out above all the technical announcements: watching <a href="https://builder.aws.com/community/heroes/RaphaelQuisumbing?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Rafi (Raphael Francis Quisumbing)</a> from the Philippines receive the Now Go Build Award from <a href="https://www.allthingsdistributed.com/">Werner Vogels</a>. Rafi has been an AWS Hero since 2015 and co-lead of <a href="https://www.facebook.com/groups/AWSUGPH/">AWS User Group Philippines</a> since 2013. His dedication to building communities and empowering developers across the region embodies what this award represents. You can read more about Rafi on <a href="https://thekernel.news/#:~:text=Winner%20of%20the%202025%20Now%20Go%20Build%20Award%3A%20Raphael%20Quisumbing">The Kernel</a>. Congrats, Rafi!</p><p><img class="aligncenter size-full wp-image-102608 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/12/08/2025-news-nowgobuild-1.png" alt="" width="1830" height="1142" /></p><p><strong>The keynote recap: Agents, renaissance, and the developer’s role<br /></strong> This year’s AWS re:Invent keynotes painted a clear picture of where we’re headed.</p><p><a href="https://www.youtube.com/watch?v=q3Sb9PemsSo"><strong>Matt Garman</strong> </a>emphasized that developers are “the heart of AWS” and that “freedom to invent” remains AWS’s core mission after 20 years. He focused on AI agents as the next inflection point: “AI assistants are starting to give way to AI agents that can perform tasks and automate on your behalf. This is where we’re starting to see material business returns from your AI investments.”</p><p><a href="https://www.youtube.com/watch?v=prVdCIHlipg"><strong>Swami Sivasubramanian</strong></a> highlighted the transformative moment we’re in: “For the first time in history, we can describe what we want to accomplish in natural language, and agents generate the plan. They write the code, call the necessary tools, and execute the complete solution.” AWS is building production-ready infrastructure that’s secure, reliable, and scalable—purpose-built for the non-deterministic nature of agents.</p><p><a href="https://www.youtube.com/watch?v=JeUpUK0nhC0"><strong>Peter DeSantis and Dave Brown</strong></a> reinforced that the core attributes AWS has obsessed over for 20 years—security, availability, performance, elasticity, cost, and agility—are more important than ever in the AI era. Dave Brown showcased Graviton and AWS’s custom silicon innovations that deliver these attributes at scale.</p><p><a href="https://www.youtube.com/watch?v=3Y1G9najGiI"><strong>Werner Vogels</strong></a> delivered his final keynote after 14 years, introducing the concept of the “renaissance developer”—someone who is curious, thinks in systems, and communicates effectively. His message about AI and developer evolution resonated: “Will AI take my job? Maybe. Will AI make me obsolete? Absolutely not… if you evolve.” He emphasized that developers must be owners: “The work is yours, not that of the tools. You build it, you own it.”</p><p>You can also watch from keynotes, innovation talks to breakout sessions and more in the <a href="https://reinvent.awsevents.com/on-demand/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">on-demand video page</a>.</p><p><strong>Innovations Talks</strong></p><ul><li><a href="https://youtu.be/L_Q7LPB5HcA">Harnessing analytics for humans and AI (INV201)</a></li>
<li><a href="https://youtu.be/D0UkoghAVM0">AI agents in action: Architecting the future of applications (INV202)</a></li>
<li><a href="https://youtu.be/qHvm3oFmRls">The agent-enabled workplace: Transforming businesses with AI (INV203)</a></li>
<li><a href="https://youtu.be/tqHCjUSRKxc">Build and scale AI: from reliable agents to transformative systems (INV204)</a></li>
<li><a href="https://youtu.be/A8BYnqiHfeA">Reinventing software development with AI agents (INV205)</a></li>
<li><a href="https://youtu.be/2_Ev5YCO2Ik">Unlocking possibilities with AWS Compute (INV207)</a></li>
<li><a href="https://youtu.be/MBvyZENChk0">Databases made effortless so agents and developers can change the world (INV208)</a></li>
<li><a href="https://youtu.be/_Wi_4I40bqQ">The next frontier: Building the agentic future of Financial Services (INV209)</a></li>
<li><a href="https://youtu.be/pIiZupnNpPM">Infrastructure for the impossible: Turning public sector barriers into breakthroughs (INV210)</a></li>
<li><a href="https://youtu.be/zj44evAY_AA">Behind the curtain: How Amazon’s AI innovations are powered by AWS (INV211)</a></li>
<li><a href="https://youtu.be/6b1Ho9hr8-0">Migrate, modernize, and move your business into the AI era (INV212)</a></li>
<li><a href="https://youtu.be/RkdPAFJEPSA">The power of cloud network innovation (INV213)</a></li>
<li><a href="https://youtu.be/q3ZRbCTnB3U">Intelligent security: Protection at scale from development to production (INV214)</a></li>
<li><a href="https://youtu.be/beWO7h7Ut44">AWS storage beyond data boundaries: Building the data foundation (INV215)</a></li>
</ul><table><tbody><tr><td><strong>Breakout sessions — Topics</strong></td>
<td><strong>Breakout sessions — Segments</strong></td>
</tr><tr><td valign="top">
<ul><li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf8hzMmCGt2F--Oa6rF2rktF&amp;trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c">Analytics</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf9m3loOlzEtdpobt-85B04t&amp;trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c">Application Integration</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf9t-nSD6dYTv-szvZxsBeh0&amp;trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c">Architecture</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf-UqnINCmXu-dDZJm_B3bbJ" data-sk="tooltip_parent">Artificial Intelligence</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf-H-1ygVzXLcZifTGGIreNK&amp;trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c">Business Applications</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf8fUGVeljVNpQwugV7XBZRt" data-sk="tooltip_parent">Cloud Operations</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf_0uJ0iFTpJ6zhvGpSl-jsy" data-sk="tooltip_parent">Compute</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf9l1y_VZAm0vG2hproZMtip" data-sk="tooltip_parent">Database</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf8HawFRm2kL9935mQmLyGy1" data-sk="tooltip_parent">Developer Tools</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf_5JZDW_n_p6sGrZpWzPK-3&amp;trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c">End-User Computing</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf9Vml7a6_rh4BNrLTTU0euv" data-sk="tooltip_parent">Hybrid Cloud &amp; Multi Cloud</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf_LuBI1bIWPHQi88G6QR6KM" data-sk="tooltip_parent">Industry Solutions</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf8Kb_IJfMCw7CA630dbJL7a" data-sk="tooltip_parent">Migration &amp; Modernization</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf8-QA1Hi5D-W2vRdc3h7FpK" data-sk="tooltip_parent">Networking &amp; Content Delivery</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf-a5wgEXBveQkE0MpHprsQt&amp;trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c">Open Source</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf_1rHZpRPA6MDUBv_OKz6Qk&amp;trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c">Security &amp; Identity</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf-Gzj7psv0r9d1u9_yYAGus&amp;trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c">Serverless &amp; Containers</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf9MLj95GGJAqCTecdrkT6mQ&amp;trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c">Storage</a></li>
</ul></td>
<td valign="top">
<ul><li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf-SZMaPAmK7huvDT6GBF18B" data-sk="tooltip_parent">Developer Community</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf_NqSnDKx7Hbb9FrNQKmxg7&amp;trk=direct">Digital Native Business</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf_NqSnDKx7Hbb9FrNQKmxg7&amp;trk=direct">Enterprise</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf9BqAa6B07Xia-qmR23RHaJ&amp;trk=direct">Independent Software Vendor</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf_bh3ol1Obzb3P8n6BQENH9&amp;trk=direct">New to AWS</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf9iOBmyb15YPGkoMK1hAX_x&amp;trk=direct" data-sk="tooltip_parent">Partner Enablement</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf-W_5uNnQaCqUaXJHt37Luo&amp;trk=direct">Public Sector</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf9MBvsGS5rB-X7CMvG21ib-&amp;trk=direct">Senior Leaders</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf_Chz_eS8KUdzzbuACSV0CE&amp;trk=direct">Small &amp; Medium Business</a></li>
<li><a href="https://www.youtube.com/playlist?list=PL2yQDdvlhXf-yRZ2GBW1PJzz5cneMld9Z&amp;trk=direct">Startup</a></li>
</ul></td>
</tr></tbody></table><p><strong>Last week’s launches<br /></strong> Here are the launches that caught my attention not yet covered in our <a href="https://aws.amazon.com/blogs/aws/top-announcements-of-aws-reinvent-2025/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">top announcements of AWS re:Invent 2025</a> post:</p><ul><li><a href="https://kiro.dev/blog/introducing-kiro-autonomous-agent/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Kiro Autonomous Agent</a> – Building on Kiro’s general availability in November with team features, AWS introduced an autonomous agent that maintains awareness across sessions, learns from pull requests and feedback, and handles bug triage and code coverage improvements spanning multiple repositories. “Orders of magnitude more efficient” than first-generation AI coding tools, Matt Garman said. Kiro is now Amazon’s standard AI development environment company-wide.</li>
<li><a href="https://docs.aws.amazon.com/bedrock/latest/userguide/kb-multimodal.html?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Multimodal Retrieval for Bedrock Knowledge Bases (GA)</a> – Build AI-powered search and question-answering applications that work across text, images, audio, and video files. Developers can now ingest multimodal content with full control of parsing, chunking, embedding, and vector storage options, then send text or image queries to retrieve relevant segments across all media types.</li>
<li><a href="https://docs.aws.amazon.com/interconnect/latest/userguide/what-is.html?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">AWS Interconnect – Multicloud (Preview)</a> – Quickly establish private, secure, high-speed network connections with dedicated bandwidth and built-in resiliency between Amazon VPCs and other cloud environments. Starting in preview with Google Cloud as the first launch partner, with Microsoft Azure support coming in 2026.</li>
</ul><p>See <a href="https://aws.amazon.com/new/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">AWS What’s New</a> for more launch news that I haven’t covered here. That’s all for this week. Check back next Monday for another Weekly Roundup!</p><p>Happy building!</p><p>— <a href="https://www.linkedin.com/in/donnieprakoso">Donnie</a></p><p><em>This post is part of our <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/">Weekly Roundup series</a>. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="9c33e027-6703-462e-9fdb-4e9d21c69b7c" data-title="AWS Weekly Roundup: AWS re:Invent keynote recap, on-demand videos, and more (December 8, 2025)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-reinvent-keynote-recap-on-demand-videos-and-more-december-8-2025/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-reinvent-keynote-recap-on-demand-videos-and-more-december-8-2025/"/>
    <updated>2025-12-08T18:05:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/improve-model-accuracy-with-reinforcement-fine-tuning-in-amazon-bedrock/</id>
    <title><![CDATA[Amazon Bedrock adds reinforcement ﬁne-tuning simplifying how developers build smarter, more accurate AI models]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Organizations face a challenging trade-off when adapting AI models to their specific business needs: settle for generic models that produce average results, or tackle the complexity and expense of advanced model customization. Traditional approaches force a choice between poor performance with smaller models or the high costs of deploying larger model variants and managing complex infrastructure. Reinforcement fine-tuning is an advanced technique that trains models using feedback instead of massive labeled datasets, but implementing it typically requires specialized ML expertise, complicated infrastructure, and significant investment—with no guarantee of achieving the accuracy needed for specific use cases.</p><p>Today, we’re announcing reinforcement fine-tuning in <a href="https://aws.amazon.com/bedrock/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Amazon Bedrock</a>, a new <a href="https://aws.amazon.com/bedrock/customize/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">model customization</a> capability that creates smarter, more cost-effective models that learn from feedback and deliver higher-quality outputs for specific business needs. Reinforcement fine-tuning uses a feedback-driven approach where models improve iteratively based on reward signals, delivering 66% accuracy gains on average over base models.</p><p>Amazon Bedrock automates the reinforcement fine-tuning workflow, making this advanced model customization technique accessible to everyday developers without requiring deep <a href="https://aws.amazon.com/ai/machine-learning/">machine learning (ML)</a> expertise or large labeled datasets.</p><p><strong>How reinforcement fine-tuning works<br /></strong> Reinforcement fine-tuning is built on top of <a href="https://aws.amazon.com/what-is/reinforcement-learning/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">reinforcement learning</a> principles to address a common challenge: getting models to consistently produce outputs that align with business requirements and user preferences.</p><p>While traditional fine-tuning requires large, labeled datasets and expensive human annotation, reinforcement fine-tuning takes a different approach. Instead of learning from fixed examples, it uses reward functions to evaluate and judge which responses are considered good for particular business use cases. This teaches models to understand what makes a quality response without requiring massive amounts of pre-labeled training data, making advanced model customization in Amazon Bedrock more accessible and cost-effective.</p><p>Here are the benefits of using reinforcement fine-tuning in Amazon Bedrock:</p><ul><li><strong>Ease of use</strong> – Amazon Bedrock automates much of the complexity, making reinforcement fine-tuning more accessible to developers building AI applications. Models can be trained using existing API logs in Amazon Bedrock or by uploading datasets as training data, eliminating the need for labeled datasets or infrastructure setup.</li>
<li><strong>Better model performance</strong> – Reinforcement fine-tuning improves model accuracy by 66% on average over base models, enabling optimization for price and performance by training smaller, faster, and more efficient model variants. This works with <a href="https://aws.amazon.com/nova/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Amazon Nova 2 Lite</a> model, improving quality and price performance for specific business needs, with support for additional models coming soon.</li>
<li><strong>Security –</strong> Data remains within the secure AWS environment throughout the entire customization process, mitigating security and compliance concerns.</li>
</ul><p>The capability supports two complementary approaches to provide flexibility for optimizing models:</p><ul><li><strong>Reinforcement Learning with Verifiable Rewards (RLVR)</strong> uses rule-based graders for objective tasks like code generation or math reasoning.</li>
<li><strong>Reinforcement Learning from AI Feedback (RLAIF)</strong> employs AI-based judges for subjective tasks like instruction following or content moderation.</li>
</ul><p><strong>Getting started with reinforcement fine-tuning in Amazon Bedrock</strong><br />Let’s walk through creating a reinforcement fine-tuning job.</p><p>First, I access the <a href="https://console.aws.amazon.com/bedrock/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Amazon Bedrock console</a>. Then, I navigate to the <strong>Custom models</strong> page. I choose <strong>Create</strong> and then choose <strong>Reinforcement fine-tuning job</strong>.</p><p><img class="aligncenter wp-image-102279 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/28/2025-news-bedrock-rev-3-1.png" alt="" width="1440" height="917" /></p><p>I start by entering the name of this customization job and then select my base model. At launch, reinforcement fine-tuning supports <a href="https://aws.amazon.com/nova/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Amazon Nova 2 Lite</a>, with support for additional models coming soon.</p><p><img class="aligncenter size-full wp-image-101326 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/18/2025-news-bedrock-rl-2-0.png" alt="" width="1146" height="607" /></p><p>Next, I need to provide training data. I can use my stored invocation logs directly, eliminating the need to upload separate datasets. I can also upload new JSONL files or select existing datasets from <a href="https://aws.amazon.com/s3/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Amazon Simple Storage Service (Amazon S3)</a>. Reinforcement fine-tuning automatically validates my training dataset and supports the OpenAI Chat Completions data format. If I provide invocation logs in the Amazon Bedrock <a href="https://docs.aws.amazon.com/bedrock/latest/APIReference/API_runtime_InvokeModel.html">invoke</a> or <a href="https://docs.aws.amazon.com/bedrock/latest/APIReference/API_runtime_Converse.html">converse</a> format, Amazon Bedrock automatically converts them to the Chat Completions format.</p><p><img class="aligncenter wp-image-102280 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/28/2025-news-bedrock-rev-3-2.png" alt="" width="1337" height="381" /></p><p>The reward function setup is where I define what constitutes a good response. I have two options here. For objective tasks, I can select <strong>Custom code</strong> and write custom Python code that gets executed through <a href="https://aws.amazon.com/lambda/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">AWS Lambda</a> functions. For more subjective evaluations, I can select <strong>Model as judge</strong> to use <a href="https://aws.amazon.com/what-is/foundation-models/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">foundation models (FMs)</a> as judges by providing evaluation instructions.</p><p>Here, I select <strong>Custom code</strong>, and I create a new Lambda function or use an existing one as a reward function. I can start with one of the provided templates and customize it for my specific needs.</p><p><img class="aligncenter wp-image-102281 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/28/2025-news-bedrock-rev-3-3.png" alt="" width="1440" height="474" /></p><p>I can optionally modify default hyperparameters like learning rate, batch size, and epochs.</p><p><img class="aligncenter wp-image-102282 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/28/2025-news-bedrock-rev-3-4.png" alt="" width="1334" height="1133" /></p><p>For enhanced security, I can configure virtual private cloud (VPC) settings and <a href="https://aws.amazon.com/kms/">AWS Key Management Service (AWS KMS)</a> encryption to meet my organization’s compliance requirements. Then, I choose <strong>Create</strong> to start the model customization job.</p><p><img class="aligncenter wp-image-102284 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/28/2025-news-bedrock-rev-3-6.png" alt="" width="1264" height="882" /></p><p>During the training process, I can monitor real-time metrics to understand how the model is learning. The training metrics dashboard shows key performance indicators including reward scores, loss curves, and accuracy improvements over time. These metrics help me understand whether the model is converging properly and if the reward function is effectively guiding the learning process.</p><p><img class="aligncenter size-full wp-image-102206 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/27/2025-news-bedrock-rev-4.png" alt="" width="2207" height="2279" /></p><p>When the reinforcement fine-tuning job is completed, I can see the final job status on the <strong>Model details</strong> page.</p><p><img class="aligncenter size-full wp-image-102207 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/27/2025-news-bedrock-rev-3.png" alt="" width="2194" height="1388" /></p><p>Once the job is completed, I can deploy the model with a single click. I select <strong>Set up inference</strong>, then choose <strong>Deploy for on-demand</strong>.</p><p><img class="aligncenter size-full wp-image-102208 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/27/2025-news-bedrock-rev-5.png" alt="" width="2224" height="957" /></p><p>Here, I provide a few details for my model.</p><p><img class="aligncenter size-full wp-image-102209 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/27/2025-news-bedrock-rev-6.png" alt="" width="2659" height="1269" /></p><p>After deployment, I can quickly evaluate the model’s performance using the Amazon Bedrock playground. This helps me to test the fine-tuned model with sample prompts and compare its responses against the base model to validate the improvements. I select <strong>Test in playground.</strong></p><p><img class="aligncenter size-full wp-image-102210 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/27/2025-news-bedrock-rev-7.png" alt="" width="2166" height="1102" /></p><p>The playground provides an intuitive interface for rapid testing and iteration, helping me confirm that the model meets my quality requirements before integrating it into production applications.</p><p><img class="aligncenter size-full wp-image-102211 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/27/2025-news-bedrock-rev-8.png" alt="" width="2783" height="1628" /></p><p><strong>Interactive demo</strong><br />Learn more by navigating an interactive demo of <a href="https://aws.storylane.io/share/2wbkrcppkxdr">Amazon Bedrock reinforcement fine-tuning</a> in action.</p><p><img class="aligncenter wp-image-102214 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/27/2025-news-bedrock-rev-9.png" alt="" width="1798" height="967" /></p><p><strong>Additional things to know</strong><br />Here are key points to note:</p><ul><li><strong>Templates —</strong> There are seven ready-to-use reward function templates covering common use cases for both objective and subjective tasks.</li>
<li><strong>Pricing —</strong> To learn more about pricing, refer to the <a href="https://aws.amazon.com/bedrock/pricing/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Amazon Bedrock pricing page</a>.</li>
<li><strong>Security —</strong> Training data and custom models remain private and aren’t used to improve FMs for public use. It supports VPC and AWS KMS encryption for enhanced security.</li>
</ul><p>Get started with reinforcement fine-tuning by visiting the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/reinforcement-fine-tuning.html">reinforcement fine-tuning documentation</a> and by accessing the <a href="https://console.aws.amazon.com/bedrock?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Amazon Bedrock console</a>.</p><p>Happy building!<br />— <a href="https://www.linkedin.com/in/donnieprakoso">Donnie</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="e8293dcd-0524-43ea-8e86-7520bc50b472" data-title="Amazon Bedrock adds reinforcement ﬁne-tuning simplifying how developers build smarter, more accurate AI models" data-url="https://aws.amazon.com/blogs/aws/improve-model-accuracy-with-reinforcement-fine-tuning-in-amazon-bedrock/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/improve-model-accuracy-with-reinforcement-fine-tuning-in-amazon-bedrock/"/>
    <updated>2025-12-03T17:08:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/new-serverless-customization-in-amazon-sagemaker-ai-accelerates-model-fine-tuning/</id>
    <title><![CDATA[New serverless customization in Amazon SageMaker AI accelerates model fine-tuning]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>Today, I’m happy to announce new serverless customization in <a href="https://aws.amazon.com/sagemaker/ai/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon SageMaker AI</a> for popular AI models, such as <a href="https://aws.amazon.com/ai/generative-ai/nova/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon Nova</a>, <a href="https://aws.amazon.com/bedrock/deepseek/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">DeepSeek</a>, <a href="https://aws.amazon.com/bedrock/openai/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">GPT-OSS</a>, <a href="https://aws.amazon.com/bedrock/meta/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Llama</a>, and <a href="https://aws.amazon.com/bedrock/qwen/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Qwen</a>. The new customization capability provides an easy-to-use interface for the latest fine-tuning techniques like reinforcement learning, so you can accelerate the AI model customization process from months to days.</p><p>With a few clicks, you can seamlessly select a model and customization technique, and handle model evaluation and deployment—all entirely serverless so you can focus on model tuning rather than managing infrastructure. When you choose serverless customization, SageMaker AI automatically selects and provisions the appropriate compute resources based on the model and data size.</p><p><strong class="c6">Getting started with serverless model customization</strong><br />You can get started customizing models in <a href="https://aws.amazon.com/sagemaker/ai/studio/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon SageMaker Studio</a>. Choose <strong>Models</strong> in the left navigation pane and check out your favorite AI models to be customized.</p><p><img class="aligncenter size-full wp-image-101130" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/17/2025-sagemaker-ai-custom-model-1-models.jpg" alt="" width="2560" height="1393" data-wp-editing="1" /></p><p><strong>Customize with UI</strong><br />You can customize AI models in a only few clicks. In the <strong>Customize model</strong> dropdown list for a specific model such as <strong>Meta Llama 3.1 8B Instruct</strong>, choose <strong>Customize with UI</strong>.</p><p><img class="aligncenter wp-image-101777 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/2025-sagemaker-ai-custom-model-2-with-ui.jpg" alt="" width="1989" height="2560" /></p><p>You can select a customization technique used to adapt the base model to your use case. SageMaker AI supports <strong>Supervised Fine-Tuning</strong> and the latest model customization techniques including <strong>Direct Preference Optimization</strong>, <strong>Reinforcement Learning from Verifiable Rewards (RLVR)</strong>, and <strong>Reinforcement Learning from AI Feedback (RLAIF)</strong>. Each technique optimizes models in different ways, with selection influenced by factors such as dataset size and quality, available computational resources, task at hand, desired accuracy levels, and deployment constraints.</p><p>Upload or select a training dataset to match the format required by the customization technique selected. Use the values of batch size, learning rate, and number of epochs recommended by the technique selected. You can conﬁgure advanced settings such as hyperparameters, a newly introduced serverless MLﬂow application for experiment tracking, and network and storage volume encryption. Choose <strong>Submit</strong> to get started on your model training job.</p><p>After your training job is complete, you can see the models you created in the <strong>My Models</strong> tab. Choose <strong>View details</strong> in one of your models.</p><p><img class="aligncenter wp-image-101144 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/17/2025-sagemaker-ai-custom-model-3-with-ui-1.jpg" alt="" width="2076" height="1396" /></p><p>By choosing <strong>Continue customization</strong>, you can continue to customize your model by adjusting hyperparameters or training with different techniques. By choosing <strong>Evaluate</strong>, you can evaluate your customized model to see how it performs compared to the base model.</p><p>When you complete both jobs, you can choose either the <strong>SageMaker</strong> or <strong>Bedrock</strong> in the <strong>Deploy</strong> dropdown list to deploy your model.</p><p><img class="aligncenter wp-image-101778 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/2025-sagemaker-ai-custom-model-4-with-ui-1-1.jpg" alt="" width="2040" height="1460" /></p><p>You can choose <a href="https://aws.amazon.com/bedrock/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon Bedrock</a> for serverless inference. Choose <strong>Bedrock</strong> and the model name to deploy the model into Amazon Bedrock. To find your deployed models, choose <strong>Imported models</strong> in the <a href="https://console.aws.amazon.com/bedrock?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Bedrock console</a>.</p><p><img class="aligncenter wp-image-101781 size-full c8" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/2025-sagemaker-ai-custom-model-5-with-ui-deploy-bedrock.jpg" alt="" width="2392" height="1050" /></p><p>You can also deploy your model to a SageMaker AI inference endpoint if you want to control your deployment resources such as an instance type and instance count. After the SageMaker AI deployment is <strong>In service</strong>, you can use this endpoint to perform inference. In the <strong>Playground</strong> tab, you can test your customized model with a single prompt or chat mode.</p><p><img class="aligncenter wp-image-101444 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/19/2025-sagemaker-ai-custom-model-6-with-ui-1.jpg" alt="" width="2230" height="2014" /></p><p>With the serverless MLﬂow capability, you can automatically log all critical experiment metrics without modifying code and access rich visualizations for further analysis.</p><p><strong>Customize with code</strong><br />When you choose customizing with code, you can see a sample notebook to fine-tune or deploy AI models. If you want to edit the sample notebook, open it in JupyterLab. Alternatively, you can deploy the model immediately by choosing <strong>Deploy</strong>.</p><p><img class="aligncenter wp-image-101784 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/2025-sagemaker-ai-custom-model-3-with-code-1-tune-1.jpg" alt="" width="2278" height="1446" /></p><p>You can choose the Amazon Bedrock or SageMaker AI endpoint by selecting the deployment resources either from <a href="https://aws.amazon.com/sagemaker/ai/deploy/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon SageMaker Inference</a> or <a href="https://aws.amazon.com/sagemaker/ai/hyperpod/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon SageMaker Hyperpod</a>.</p><p><img class="aligncenter size-full wp-image-101160 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/17/2025-sagemaker-ai-custom-model-3-with-code-2-deploy.jpg" alt="" width="2220" height="1262" /></p><p>When you choose <strong>Deploy</strong> on the bottom right of the page, it will be redirected back to the model detail page. After the SageMaker AI deployment is in service, you can use this endpoint to perform inference.</p><p>Okay, you’ve seen how to streamline the model customization in the SageMaker AI. You can now choose your favorite way. To learn more, visit the <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/whatis.html?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon SageMaker AI Developer Guide</a>.</p><p><strong class="c6">Now available</strong><br /><a href="https://aws.amazon.com/sagemaker/ai/model-customization/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">New serverless AI model customization</a> in Amazon SageMaker AI is now available in US East (N. Virginia), US West (Oregon), Asia Pacific (Tokyo), and Europe (Ireland) Regions. You only pay for the tokens processed during training and inference. To learn more details, visit <a href="https://aws.amazon.com/sagemaker/ai/pricing/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon SageMaker AI pricing page</a>.</p><p>Give it a try in <a href="https://console.aws.amazon.com/sagemaker?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Amazon SageMaker Studio</a> and send feedback to <a href="https://repost.aws/tags/TAT80swPyVRPKPcA0rsJYPuA/amazon-sagemaker?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">AWS re:Post for SageMaker</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy">Channy</a></p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="51695978-8bb2-471e-b8b5-6be8c2638279" data-title="New serverless customization in Amazon SageMaker AI accelerates model fine-tuning" data-url="https://aws.amazon.com/blogs/aws/new-serverless-customization-in-amazon-sagemaker-ai-accelerates-model-fine-tuning/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/new-serverless-customization-in-amazon-sagemaker-ai-accelerates-model-fine-tuning/"/>
    <updated>2025-12-03T17:08:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/introducing-checkpointless-and-elastic-training-on-amazon-sagemaker-hyperpod/</id>
    <title><![CDATA[Introducing checkpointless and elastic training on Amazon SageMaker HyperPod]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing two new AI model training features within <a href="https://aws.amazon.com/sagemaker/ai/hyperpod/">Amazon SageMaker HyperPod</a>: checkpointless training, an approach that mitigates the need for traditional checkpoint-based recovery by enabling peer-to-peer state recovery, and elastic training, enabling AI workloads to automatically scale based on resource availability.</p><ul><li><strong>Checkpointless training</strong> – Checkpointless training eliminates disruptive checkpoint-restart cycles, maintaining forward training momentum despite failures, reducing recovery time from hours to minutes. Accelerate your AI model development, reclaim days from development timelines, and confidently scale training workflows to thousands of AI accelerators.</li>
<li><strong>Elastic training </strong> – Elastic training maximizes cluster utilization as training workloads automatically expand to use idle capacity as it becomes available, and contract to yield resources as higher-priority workloads like inference volumes peak. Save hours of engineering time per week spent reconfiguring training jobs based on compute availability.</li>
</ul><p>Rather than spending time managing training infrastructure, these new training techniques mean that your team can concentrate entirely on enhancing model performance, ultimately getting your AI models to market faster. By eliminating the traditional checkpoint dependencies and fully utilizing available capacity, you can significantly reduce model training completion times.</p><p><strong class="c6">Checkpointless training: How it works</strong><br />Traditional checkpoint-based recovery has these sequential job stages: 1) job termination and restart, 2) process discovery and network setup, 3) checkpoint retrieval, 4) data loader initialization, and 5) training loop resumption. When failures occur, each stage can become a bottleneck and training recovery can take up to an hour on self-managed training clusters. The entire cluster must wait for every single stage to complete before training can resume. This can lead to the entire training cluster sitting idle during recovery operations, which increases costs and extends the time to market.</p><p>Checkpointless training removes this bottleneck entirely by maintaining continuous model state preservation across the training cluster. When failures occur, the system instantly recovers by using healthy peers, avoiding the need for a checkpoint-based recovery that requires restarting the entire job. As a result, checkpointless training enables fault recovery in minutes.</p><p><img class="aligncenter size-full wp-image-101253 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/18/2025-sageamker-hyperpod-checkpointless-training.gif" alt="" width="800" height="592" /></p><p>Checkpointless training is designed for incremental adoption and built on four core components that work together: 1) collective communications initialization optimizations, 2) memory-mapped data loading that enables caching, 3) in-process recovery, and 4) checkpointless peer-to-peer state replication. These components are orchestrated through the <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/sagemaker-eks-operator.html">HyperPod training operator</a> that is used to launch the job. Each component optimizes a specific step in the recovery process, and together they enable automatic detection and recovery of infrastructure faults in minutes with zero manual intervention, even with thousands of AI accelerators. You can progressively enable each of these features as your training scales.</p><p>The latest <a href="https://aws.amazon.com/nova/">Amazon Nova</a> models were trained using this technology on tens of thousands of accelerators. Additionally, based on internal studies on cluster sizes ranging between 16 GPUs to over 2,000 GPUs, checkpointless training showcased significant improvements in recovery times, reducing downtime by over 80% compared to traditional checkpoint-based recovery.</p><p>To learn more, visit <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/hyperpod-checkpointless-training.html">HyperPod Checkpointless Training</a> in the Amazon SageMaker AI Developer Guide.</p><p><strong class="c6">Elastic training: How it works</strong><br />On clusters that run different types of modern AI workloads, accelerator availability can change continuously throughout the day as short-duration training runs complete, inference spikes occur and subside, or resources free up from completed experiments. Despite this dynamic availability of AI accelerators, traditional training workloads remain locked into their initial compute allocation, unable to take advantage of idle accelerators without manual intervention. This rigidity leaves valuable GPU capacity unused and prevents organizations from maximizing their infrastructure investment.</p><p><img class="size-full wp-image-101255 alignright c8" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/18/2025-sageamker-hyperpod-elastic-training.gif" alt="" width="400" height="437" />Elastic training transforms how training workloads interact with cluster resources. Training jobs can automatically scale up to utilize available accelerators and gracefully contract when resources are needed elsewhere, all while maintaining training quality.</p><p>Workload elasticity is enabled through the HyperPod training operator that orchestrates scaling decisions through integration with the Kubernetes control plane and resource scheduler. It continuously monitors cluster state through three primary channels: pod lifecycle events, node availability changes, and resource scheduler priority signals. This comprehensive monitoring enables near-instantaneous detection of scaling opportunities, whether from newly available resources or requests from higher-priority workloads.</p><p>The scaling mechanism relies on adding and removing data parallel replicas. When additional compute resources become available, new data parallel replicas join the training job, accelerating throughput. Conversely, during scale-down events (for example, when a higher-priority workload requests resources), the system scales down by removing replicas rather than terminating the entire job, allowing training to continue at reduced capacity.</p><p>Across different scales, the system preserves the global batch size and adapts learning rates, preventing model convergence from being adversely impacted. This enables workloads to dynamically scale up or down to utilize available AI accelerators without any manual intervention.</p><p>You can start elastic training through the HyperPod recipes for publicly available foundation models (FMs) including Llama and GPT-OSS. Additionally, you can modify your PyTorch training scripts to add elastic event handlers, which enable the job to dynamically scale.</p><p>To learn more, visit the <a href="https://docs.aws.amazon.com/sagemaker/latest/dg/hyperpod-elastic-training.html">HyperPod Elastic Training</a> in the Amazon SageMaker AI Developer Guide. To get started, find the <a href="https://github.com/aws/sagemaker-hyperpod-recipes">HyperPod recipes</a> available in the AWS GitHub repository.</p><p><strong class="c6">Now available</strong><br />Both these new HyperPod features are available in <mark>[REGION LIST]</mark> AWS Regions. You can use these training techniques without additional cost. To learn more, visit the <a href="https://aws.amazon.com/sagemaker/hyperpod?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">SageMaker HyperPod product page</a> and <a href="https://aws.amazon.com/sagemaker/pricing?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">SageMaker AI pricing page</a>.</p><p>Give it a try and send feedback to <a href="https://repost.aws/tags/TAT80swPyVRPKPcA0rsJYPuA/amazon-sagemaker">AWS re:Post for SageMaker</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy">Channy</a></p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="e9ff4725-9aa0-45f0-8719-079fb6a71e9b" data-title="Introducing checkpointless and elastic training on Amazon SageMaker HyperPod" data-url="https://aws.amazon.com/blogs/aws/introducing-checkpointless-and-elastic-training-on-amazon-sagemaker-hyperpod/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/introducing-checkpointless-and-elastic-training-on-amazon-sagemaker-hyperpod/"/>
    <updated>2025-12-03T17:07:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/announcing-replication-support-and-intelligent-tiering-for-amazon-s3-tables/</id>
    <title><![CDATA[Announcing replication support and Intelligent-Tiering for Amazon S3 Tables]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing two new capabilities for <a href="https://aws.amazon.com/s3/features/tables/">Amazon S3 Tables</a>: support for the new Intelligent-Tiering storage class that automatically optimizes costs based on access patterns, and replication support to automatically maintain consistent <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-tables.html">Apache Iceberg</a> table replicas across <a href="https://docs.aws.amazon.com/global-infrastructure/latest/regions/aws-regions.html">AWS Regions</a> and <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#account">accounts</a> without manual sync.</p><p>Organizations working with tabular data face two common challenges. First, they need to manually manage storage costs as their datasets grow and access patterns change over time. Second, when maintaining replicas of Iceberg tables across Regions or accounts, they must build and maintain complex architectures to track updates, manage object replication, and handle metadata transformations.</p><p><strong>S3 Tables Intelligent-Tiering storage class<br /></strong> With the S3 Tables Intelligent-Tiering storage class<strong>,</strong> data is automatically tiered to the most cost-effective access tier based on access patterns. Data is stored in three low-latency tiers: Frequent Access, Infrequent Access (40% lower cost than Frequent Access), and Archive Instant Access (68% lower cost compared to Infrequent Access). After 30 days without access, data moves to Infrequent Access, and after 90 days, it moves to Archive Instant Access. This happens without changes to your applications or impact on performance.</p><p>Table maintenance activities, including compaction, snapshot expiration, and unreferenced file removal, operate without affecting the data’s access tiers. Compaction automatically processes only data in the Frequent Access tier, optimizing performance for actively queried data while reducing maintenance costs by skipping colder files in lower-cost tiers.</p><p>By default, all existing tables use the Standard storage class. When creating new tables, you can specify Intelligent-Tiering as the storage class, or you can rely on the default storage class configured at the table bucket level. You can set Intelligent-Tiering as the default storage class for your table bucket to automatically store tables in Intelligent-Tiering when no storage class is specified during creation.</p><p><strong>Let me show you how it works<br /></strong> You can use the <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a> and the <code>put-table-bucket-storage-class</code> and <code>get-table-bucket-storage-class</code> commands to change or verify the storage tier of your S3 table bucket.</p><pre class="lang-sh"># Change the storage class
aws s3tables put-table-bucket-storage-class \
   --table-bucket-arn $TABLE_BUCKET_ARN  \
   --storage-class-configuration storageClass=INTELLIGENT_TIERING
# Verify the storage class
aws s3tables get-table-bucket-storage-class \
   --table-bucket-arn $TABLE_BUCKET_ARN  \
{ "storageClassConfiguration":
   { 
      "storageClass": "INTELLIGENT_TIERING"
   }
}</pre><p><strong>S3 Tables replication support<br /></strong> The new S3 Tables replication support helps you maintain consistent read replicas of your tables across AWS Regions and accounts. You specify the destination table bucket and the service creates read-only replica tables. It replicates all updates chronologically while preserving parent-child snapshot relationships. Table replication helps you build global datasets to minimize query latency for geographically distributed teams, meet compliance requirements, and provide data protection.</p><p>You can now easily create replica tables that deliver similar query performance as their source tables. Replica tables are updated within minutes of source table updates and support independent encryption and retention policies from their source tables. Replica tables can be queried using <a href="https://aws.amazon.com/sagemaker/unified-studio/">Amazon SageMaker Unified Studio</a> or any Iceberg-compatible engine including <a href="https://duckdb.org/">DuckDB</a>, <a href="https://py.iceberg.apache.org/">PyIceberg</a>, <a href="https://spark.apache.org/">Apache Spark</a>, and <a href="https://trino.io/">Trino</a>.</p><p>You can create and maintain replicas of your tables through the <a href="https://console.aws.amazon.com">AWS Management Console</a> or APIs and <a href="https://aws.amazon.com/tools/">AWS SDKs</a>. You specify one or more destination table buckets to replicate your source tables. When you turn on replication, S3 Tables automatically creates read-only replica tables in your destination table buckets, backfills them with the latest state of the source table, and continually monitors for new updates to keep replicas in sync. This helps you meet time-travel and audit requirements while maintaining multiple replicas of your data.</p><p><strong>Let me show you how it works<br /></strong> To show you how it works, I proceed in three steps. First, I create an S3 table bucket, create an Iceberg table, and populate it with data. Second, I configure the replication. Third, I connect to the replicated table and query the data to show you that changes are replicated.</p><p>For this demo, the S3 team kindly gave me access to an <a href="https://aws.amazon.com/emr">Amazon EMR</a> cluster already provisioned. You can follow <a href="https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-gs.html">the Amazon EMR documentation to create your own cluster</a>. They also created two S3 table buckets, a source and a destination for the replication. Again, <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-tables-buckets-create.html">the S3 Tables documentation will help you to get started</a>.</p><p>I take a note of the two S3 Tables bucket Amazon Resource Names (ARNs). In this demo, I refer to these as the environment variables <code>SOURCE_TABLE_ARN</code> and <code>DEST_TABLE_ARN</code>.</p><p><strong>First step: Prepare the source database</strong></p><p>I start a terminal, connect to the EMR cluster, start a Spark session, create a table, and insert a row of data. The commands I use in this demo are documented in <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-tables-integrating-open-source.html">Accessing tables using the Amazon S3 Tables Iceberg REST endpoint</a>.</p><pre class="lang-spark">sudo spark-shell \
--packages "org.apache.iceberg:iceberg-spark-runtime-3.5_2.12:1.4.1,software.amazon.awssdk:bundle:2.20.160,software.amazon.awssdk:url-connection-client:2.20.160" \
--master "local[*]" \
--conf "spark.sql.extensions=org.apache.iceberg.spark.extensions.IcebergSparkSessionExtensions" \
--conf "spark.sql.defaultCatalog=spark_catalog" \
--conf "spark.sql.catalog.spark_catalog=org.apache.iceberg.spark.SparkCatalog" \
--conf "spark.sql.catalog.spark_catalog.type=rest" \
--conf "spark.sql.catalog.spark_catalog.uri=https://s3tables.us-east-1.amazonaws.com/iceberg" \
--conf "spark.sql.catalog.spark_catalog.warehouse=arn:aws:s3tables:us-east-1:012345678901:bucket/aws-news-blog-test" \
--conf "spark.sql.catalog.spark_catalog.rest.sigv4-enabled=true" \
--conf "spark.sql.catalog.spark_catalog.rest.signing-name=s3tables" \
--conf "spark.sql.catalog.spark_catalog.rest.signing-region=us-east-1" \
--conf "spark.sql.catalog.spark_catalog.io-impl=org.apache.iceberg.aws.s3.S3FileIO" \
--conf "spark.hadoop.fs.s3a.aws.credentials.provider=org.apache.hadoop.fs.s3a.SimpleAWSCredentialProvider" \
--conf "spark.sql.catalog.spark_catalog.rest-metrics-reporting-enabled=false"
spark.sql("""
CREATE TABLE s3tablesbucket.test.aws_news_blog (
customer_id STRING,
address STRING
) USING iceberg
""")
spark.sql("INSERT INTO s3tablesbucket.test.aws_news_blog VALUES ('cust1', 'val1')")
spark.sql("SELECT * FROM s3tablesbucket.test.aws_news_blog LIMIT 10").show()
+-----------+-------+
|customer_id|address|
+-----------+-------+
|      cust1|   val1|
+-----------+-------+</pre><p>So far, so good.</p><p><strong>Second step: Configure the replication for S3 Tables</strong></p><p>Now, I use the CLI on my laptop to configure the S3 table bucket replication.</p><p>Before doing so, I create an <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (IAM)</a> policy to authorize the replication service to access my S3 table bucket and encryption keys. <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-tables-replication-tables.html,">Refer to the S3 Tables replication documentation for the details</a>. The permissions I used for this demo are:</p><pre class="lang-json">{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "s3:*",
                "s3tables:*",
                "kms:DescribeKey",
                "kms:GenerateDataKey",
                "kms:Decrypt"
            ],
            "Resource": "*"
        }
    ]
}</pre><p>After having created this IAM policy, I can now proceed and configure the replication:</p><pre class="lang-sh">aws s3tables-replication put-table-replication \
--table-arn ${SOURCE_TABLE_ARN} \
--configuration  '{
    "role": "arn:aws:iam::&lt;MY_ACCOUNT_NUMBER&gt;:role/S3TableReplicationManualTestingRole", 
    "rules":[
        {
            "destinations": [
                {
                    "destinationTableBucketARN": "${DST_TABLE_ARN}"
                }]
        }
    ]
</pre><p>The replication starts automatically. Updates are typically replicated within minutes. The time it takes to complete depends on the volume of data in the source table.</p><p><strong>Third step: Connect to the replicated table and query the data</strong></p><p>Now, I connect to the EMR cluster again, and I start a second Spark session. This time, I use the destination table.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/14/2025-11-14_13-59-13.png"><img class="aligncenter size-full wp-image-100986" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/14/2025-11-14_13-59-13.png" alt="S3 Tables replication - destination table" width="802" height="424" /></a></p><p>To verify the replication works, I insert a second row of data on the source table.</p><pre class="lang-spark">spark.sql("INSERT INTO s3tablesbucket.test.aws_news_blog VALUES ('cust2', 'val2')")
</pre><p>I wait a few minutes for the replication to trigger. I follow the status of the replication with the <code>get-table-replication-status</code> command.</p><pre class="lang-sh">aws s3tables-replication get-table-replication-status \
--table-arn ${SOURCE_TABLE_ARN} \
{
    "sourceTableArn": "arn:aws:s3tables:us-east-1:012345678901:bucket/manual-test/table/e0fce724-b758-4ee6-85f7-ca8bce556b41",
    "destinations": [
        {
            "replicationStatus": "pending",
            "destinationTableBucketArn": "arn:aws:s3tables:us-east-1:012345678901:bucket/manual-test-dst",
            "destinationTableArn": "arn:aws:s3tables:us-east-1:012345678901:bucket/manual-test-dst/table/5e3fb799-10dc-470d-a380-1a16d6716db0",
            "lastSuccessfulReplicatedUpdate": {
                "metadataLocation": "s3://e0fce724-b758-4ee6-8-i9tkzok34kum8fy6jpex5jn68cwf4use1b-s3alias/e0fce724-b758-4ee6-85f7-ca8bce556b41/metadata/00001-40a15eb3-d72d-43fe-a1cf-84b4b3934e4c.metadata.json",
                "timestamp": "2025-11-14T12:58:18.140281+00:00"
            }
        }
    ]
}</pre><p>When replication status shows <code>ready</code>, I connect to the EMR cluster and I query the destination table. Without surprise, I see the new row of data.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/14/2025-11-14_14-44-40.png"><img class="aligncenter size-full wp-image-100987" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/14/2025-11-14_14-44-40.png" alt="S3 Tables replication - target table is up to date" width="778" height="126" /></a></p><p><strong>Additional things to know<br /></strong> Here are a couple of additional points to pay attention to:</p><ul><li>Replication for S3 Tables supports both Apache Iceberg V2 and V3 table formats, giving you flexibility in your table format choice.</li>
<li>You can configure replication at the table bucket level, making it straightforward to replicate all tables under that bucket without individual table configurations.</li>
<li>Your replica tables maintain the storage class you choose for your destination tables, which means you can optimize for your specific cost and performance needs.</li>
<li>Any Iceberg-compatible catalog can directly query your replica tables without additional coordination—they only need to point to the replica table location. This gives you flexibility in choosing query engines and tools.</li>
</ul><p><strong>Pricing and availability<br /></strong> You can track your storage usage by access tier through <a href="https://docs.aws.amazon.com/cur/latest/userguide/what-is-cur.html">AWS Cost and Usage Reports</a> and <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a> metrics. For replication monitoring, <a href="https://aws.amazon.com/cloudtrail/">AWS CloudTrail</a> logs provide events for each replicated object.</p><p>There are no additional charges to configure Intelligent-Tiering. You only pay for storage costs in each tier. Your tables continue to work as before, with automatic cost optimization based on your access patterns.</p><p>For S3 Tables replication, you pay the S3 Tables charges for storage in the destination table, for replication PUT requests, for table updates (commits), and for object monitoring on the replicated data. For cross-Region table replication, you also pay for inter-Region data transfer out from Amazon S3 to the destination Region based on the Region pair.</p><p>As usual, refer to the <a href="https://aws.amazon.com/s3/pricing/">Amazon S3 pricing page</a> for the details.</p><p>Both capabilities are available today in all AWS Regions where <a href="https://docs.aws.amazon.com/general/latest/gr/s3.html#s3_region">S3 Tables are supported</a>.</p><p>To learn more about these new capabilities, visit the <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-tables.html">Amazon S3 Tables documentation</a> or try them in the <a href="https://console.aws.amazon.com/s3/table-buckets">Amazon S3 console</a> today. Share your feedback through AWS re:Post for Amazon S3 or through your AWS Support contacts.</p><a href="https://linktr.ee/sebsto">— seb</a></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="e73c113b-82e0-4d8f-9a0a-34bce32c7919" data-title="Announcing replication support and Intelligent-Tiering for Amazon S3 Tables" data-url="https://aws.amazon.com/blogs/aws/announcing-replication-support-and-intelligent-tiering-for-amazon-s3-tables/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/announcing-replication-support-and-intelligent-tiering-for-amazon-s3-tables/"/>
    <updated>2025-12-02T17:19:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-s3-storage-lens-adds-performance-metrics-support-for-billions-of-prefixes-and-export-to-s3-tables/</id>
    <title><![CDATA[Amazon S3 Storage Lens adds performance metrics, support for billions of prefixes, and export to S3 Tables]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing three new capabilities for <a href="https://aws.amazon.com/s3/storage-lens/">Amazon S3 Storage Lens</a> that give you deeper insights into your storage performance and usage patterns. With the addition of performance metrics, support for analyzing billions of prefixes, and direct export to <a href="https://aws.amazon.com/s3/features/tables/?trk=7c8639c6-87c6-47d6-9bd0-a5812eecb848&amp;sc_channel=el">Amazon S3 Tables,</a> you have the tools you need to optimize application performance, reduce costs, and make data-driven decisions about your Amazon S3 storage strategy.</p><p><strong>New performance metric categories</strong><br />S3 Storage Lens now includes eight new performance metric categories that help identify and resolve performance constraints across your organization. These are available at organization, account, bucket, and prefix levels. For example, the service helps you identify small objects in a bucket or prefix that can  slow down application performance. This can be mitigated by batching small objects for using the <a href="https://aws.amazon.com/s3/storage-classes/express-one-zone/?trk=7c8639c6-87c6-47d6-9bd0-a5812eecb848&amp;sc_channel=el">Amazon S3 Express One Zone</a> storage class for higher performance small object workloads.</p><p>To access the new performance metrics, you need to enable performance metrics in the S3 Storage Lens advanced tier when creating a new Storage Lens dashboard or editing an existing configuration.</p><table class="c9"><tbody><tr class="c7"><td class="c6"><strong>Metric category</strong></td>
<td class="c6"><strong>Details</strong></td>
<td class="c6"><strong>Use case</strong></td>
<td class="c6"><strong>Mitigation</strong></td>
</tr><tr class="c8"><td class="c6">Read request size</td>
<td class="c6">Distribution of read request sizes (GET) by day</td>
<td class="c6">Identify dataset with small read request patterns that slow down performance</td>
<td class="c6">Small request: Batch small objects or use Amazon S3 Express One Zone for high-performance small object workloads</td>
</tr><tr class="c8"><td class="c6">Write request size</td>
<td class="c6">Distribution of write request sizes (PUT, POST, COPY, and UploadPart) by day</td>
<td class="c6">Identify dataset with small write request patterns that slow down performance</td>
<td class="c6">Large request: Parallelize requests, use MPU or use AWS CRT</td>
</tr><tr class="c8"><td class="c6">Storage size</td>
<td class="c6">Distribution of object sizes</td>
<td class="c6">Identify dataset with small small objects that slow down performance</td>
<td class="c6">Small object sizes: Consider bundling small objects</td>
</tr><tr class="c8"><td class="c6">Concurrent PUT 503 errors</td>
<td class="c6">Number of 503s due to concurrent PUT operation on same object</td>
<td class="c6">Identify prefixes with concurrent PUT throttling that slow down performance</td>
<td class="c6">For single writer, modify retry behavior or use Amazon S3 Express One Zone. For multiple writers, use consensus mechanism or use Amazon S3 Express One Zone</td>
</tr><tr class="c8"><td class="c6">Cross-Region data transfer</td>
<td class="c6">Bytes transferred and requests sent across Region, in Region</td>
<td class="c6">Identify potential performance and cost degradation due to cross-Region data access</td>
<td class="c6">Co-locate compute with data in the same AWS Region</td>
</tr><tr class="c8"><td class="c6">Unique objects accessed</td>
<td class="c6">Number or percentage of unique objects accessed per day</td>
<td class="c6">Identify datasets where small subset of objects are being frequently accessed. These can be moved to higher performance storage tier for better performance</td>
<td class="c6">Consider moving active data to Amazon S3 Express One Zone or other caching solutions</td>
</tr><tr class="c8"><td class="c6">FirstByteLatency (existing <a href="https://aws.amazon.com/cloudwatch/?trk=7c8639c6-87c6-47d6-9bd0-a5812eecb848&amp;sc_channel=el">Amazon CloudWatch</a> metric)</td>
<td class="c6">Daily average of first byte latency metric</td>
<td class="c6">The daily average per-request time from the complete request being received to when the response starts to be returned</td>
<td class="c6">
</td></tr><tr class="c8"><td class="c6">TotalRequestLatency (existing Amazon CloudWatch metric)</td>
<td class="c6">Daily average of Total Request Latency</td>
<td class="c6">The daily average elapsed per request time from the first byte received to the last byte sent</td>
<td class="c6">
</td></tr></tbody></table><p><strong>How it works<br /></strong> On the <a href="https://console.aws.amazon.com/s3/storage-analytics-insights/?trk=7c8639c6-87c6-47d6-9bd0-a5812eecb848&amp;sc_channel=el">Amazon S3 console</a> I choose <strong>Create Storage Lens dashboard</strong> to create a new dashboard. You can also edit an existing dashboard configuration. I then configure general settings such as providing a <strong>Dashboard name</strong>, <strong>Status</strong>, and the optional <strong>Tags.</strong> Then, I choose <strong>Next</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/metricsdashboard1.png"><img class="aligncenter size-large wp-image-101722" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/metricsdashboard1-1024x283.png" alt="" width="1024" height="283" /></a><br />Next, I define the scope of the dashboard by selecting <strong>Include all Regions and Include all buckets</strong> and specifying the Regions and buckets to be included.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/metricsdashboard2.png"><img class="aligncenter size-large wp-image-101724" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/metricsdashboard2-1024x227.png" alt="" width="1024" height="227" /></a><br />I opt in to the <strong>Advanced tier</strong> in the Storage Lens dashboard configuration, select <strong>Performance metrics</strong>, then choose <strong>Next</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/metricsdashboard3.png"><img class="aligncenter size-large wp-image-101725" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/metricsdashboard3-1024x394.png" alt="" width="1024" height="394" /></a><br />Next, I select <strong>Prefix aggregation</strong> as an additional metrics aggregation, then leave the rest of the information as default before I choose <strong>Next</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/Screenshot-2025-11-18-at-11.13.31-PM.png"><img class="aligncenter size-large wp-image-101833" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/Screenshot-2025-11-18-at-11.13.31-PM-1024x464.png" alt="" width="1024" height="464" /></a><br />I select the <strong>Default metrics report</strong>, then <strong>General purpose bucket</strong> as the bucket type, and then select the Amazon S3 bucket in my AWS account as the <strong>Destination bucket</strong>. I leave the rest of the information as default, then select <strong>Next</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/Screenshot-2025-11-24-at-5.25.01-PM.png"><img class="aligncenter size-large wp-image-101834" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/Screenshot-2025-11-24-at-5.25.01-PM-1024x382.png" alt="" width="1024" height="382" /></a><br />I review all the information before I choose <strong>Submit</strong> to finalize the process.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/metricsdashboard6.png"><img class="aligncenter size-large wp-image-101728" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/metricsdashboard6-871x1024.png" alt="" width="871" height="1024" /></a><br />After it’s enabled, I’ll receive daily performance metrics directly in the <a href="https://console.aws.amazon.com/s3/?trk=7c8639c6-87c6-47d6-9bd0-a5812eecb848&amp;sc_channel=el">Storage Lens console</a> dashboard. You can also choose to export report in CSV or Parquet format to any bucket in your account or publish to Amazon CloudWatch. The performance metrics are aggregated and published daily and will be available at multiple levels: organization, account, bucket, and prefix. In this dropdown menu, I choose the % concurrent PUT 503 error for the <strong>Metric</strong>, Last 30 days for the <strong>Date range</strong>, and 10 for the <strong>Top N buckets</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/Screenshot-2025-11-18-at-10.46.28-PM.png"><img class="aligncenter size-large wp-image-101738" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/Screenshot-2025-11-18-at-10.46.28-PM-1024x434.png" alt="" width="1024" height="434" /></a><br />The Concurrent PUT 503 error count metric tracks the number of 503 errors generated by simultaneous PUT operations to the same object. Throttling errors can degrade application performance. For a single writer, modify retry behavior or use higher performance storage tier such as Amazon S3 Express One Zone to mitigate concurrent PUT 503 errors. For multiple writers scenario, use a consensus mechanism to avoid concurrent PUT 503 errors or use higher performance storage tier such as Amazon S3 Express One Zone.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/oasis_conc_PUT.png"><img class="aligncenter size-large wp-image-100904" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/13/oasis_conc_PUT-1024x730.png" alt="" width="1024" height="730" /></a></p><p><strong>Complete analytics for all prefixes in your S3 buckets</strong><br />S3 Storage Lens now supports analytics for all prefixes in your S3 buckets through a new <strong>Expanded prefixes metrics report</strong>. This capability removes previous limitations that restricted analysis to prefixes meeting a 1% size threshold and a maximum depth of 10 levels. You can now track up to billions of prefixes per bucket for analysis at the most granular prefix level, regardless of size or depth.</p><p>The Expanded prefixes metrics report includes all existing S3 Storage Lens metric categories: storage usage, activity metrics (requests and bytes transferred), data protection metrics, and detailed status code metrics.</p><p><strong>How to get started</strong><br />I follow the same steps outlined in the <strong>How it works</strong> section to create or update the Storage Lens dashboard. In Step 4 on the console, where you select export options, you can select the new <strong>Expanded prefixes metrics report</strong>. Thereafter, I can export the expanded prefixes metrics report in CSV or Parquet format to any general purpose bucket in my account for efficient querying of my Storage Lens data.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/metricsdashboard5-1.png"><img class="aligncenter size-large wp-image-101729" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/metricsdashboard5-1-1024x350.png" alt="" width="1024" height="350" /></a><br /><strong>Good to know<br /></strong> This enhancement addresses scenarios where organizations need granular visibility across their entire prefix structure. For example, you can identify prefixes with incomplete multipart uploads to reduce costs, track compliance across your entire prefix structure for encryption and replication requirements, and detect performance issues at the most granular level.</p><p><strong>Export S3 Storage Lens metrics to S3 Tables<br /></strong> S3 Storage Lens metrics can now be automatically exported to S3 Tables, a fully managed feature on AWS with built-in Apache Iceberg support. This integration provides daily automatic delivery of metrics to AWS managed S3 Tables for immediate querying without requiring additional processing infrastructure.</p><p><strong>How to get started</strong><br />I start by following the process outlined in Step 5 on the console, where I choose the export destination. This time, I choose <strong>Expanded prefixes metrics report</strong>. In addition to General purpose bucket, I choose <strong>Table bucket</strong>.</p><p>The new Storage Lens metrics are exported to new tables in an <a href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-tables-buckets.html">AWS managed bucket</a> <code>aws-s3</code>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/18/seer1.png"><img class="aligncenter size-large wp-image-101352" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/18/seer1-1024x429.png" alt="" width="1024" height="429" /></a><br />I select the <strong>expanded_prefixes_activity_metrics</strong> table to view API usage metrics for expanded prefix reports.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/18/seer2.png"><img class="aligncenter size-large wp-image-101353" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/18/seer2-1024x446.png" alt="" width="1024" height="446" /></a><br />I can preview the table on the Amazon S3 console or use <a href="https://aws.amazon.com/athena">Amazon Athena</a> to query the table.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/18/seer3.png"><img class="aligncenter size-large wp-image-101354" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/18/seer3-1024x323.png" alt="" width="1024" height="323" /></a><br /><strong>Good to know<br /></strong> S3 Tables integration with S3 Storage Lens simplifies metric analysis using familiar SQL tools and AWS analytics services such as Amazon Athena, <a href="https://quicksight.aws">Amazon QuickSight</a>, <a href="https://aws.amazon.com/emr">Amazon EMR</a>, and <a href="https://aws.amazon.com/redshift/">Amazon Redshift</a>, without requiring a data pipeline. The metrics are automatically organized for optimal querying, with custom retention and encryption options to suit your needs.</p><p>This integration enables cross-account and cross-Region analysis, custom dashboard creation, and data correlation with other AWS services. For example, you can combine Storage Lens metrics with S3 Metadata to analyze prefix-level activity patterns and identify objects in prefixes with cold data that are eligible for transition to lower-cost storage tiers.</p><p>For your agentic AI workflows, you can use natural language to query S3 Storage Lens metrics in S3 Tables with the <a href="https://aws.amazon.com/about-aws/whats-new/2025/07/amazon-s3-tables-mcp-server/">S3 Tables MCP Server</a>. Agents can ask questions such as ‘which buckets grew the most last month?’ or ‘show me storage costs by storage class’ and get instant insights from your observability data.</p><p><strong>Now available<br /></strong> All three enhancements are available in all <a href="https://builder.aws.com/build/capabilities/explore?tab=service-feature">AWS Regions</a> where S3 Storage Lens is currently offered (except the China Regions and AWS GovCloud (US)).</p><p>These features are included in the Amazon S3 Storage Lens Advanced tier at no additional charge beyond standard advanced tier pricing. For the S3 Tables export, you pay only for S3 Tables storage, maintenance, and queries. There is no additional charge for the export functionality itself.</p><p>To learn more about Amazon S3 Storage Lens performance metrics, support for billions of prefixes, and export to S3 Tables, refer to the <a href="http://docs.aws.amazon.com/AmazonS3/latest/userguide/storage_lens.html">Amazon S3 user guide</a>. For pricing details, visit the <a href="https://aws.amazon.com/s3/pricing/">Amazon S3 pricing page</a>.</p><p><a href="https://linkedin.com/in/veliswa-boya">Veliswa Boya</a>.</p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="48e36b96-2fbe-437c-9c0d-5e8bc450a319" data-title="Amazon S3 Storage Lens adds performance metrics, support for billions of prefixes, and export to S3 Tables" data-url="https://aws.amazon.com/blogs/aws/amazon-s3-storage-lens-adds-performance-metrics-support-for-billions-of-prefixes-and-export-to-s3-tables/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-s3-storage-lens-adds-performance-metrics-support-for-billions-of-prefixes-and-export-to-s3-tables/"/>
    <updated>2025-12-02T17:15:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-bedrock-agentcore-adds-quality-evaluations-and-policy-controls-for-deploying-trusted-ai-agents/</id>
    <title><![CDATA[Amazon Bedrock AgentCore adds quality evaluations and policy controls for deploying trusted AI agents]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing new capabilities in <a href="https://aws.amazon.com/bedrock/agentcore/">Amazon Bedrock AgentCore</a> to further remove barriers holding AI agents back from production. Organizations across industries are already building on AgentCore, the most advanced platform to build, deploy, and operate highly capable agents securely at any scale. In just 5 months since preview, the <a href="https://github.com/aws/bedrock-agentcore-sdk-python">AgentCore SDK</a> has been downloaded over 2 million times. For example:</p><ul><li>PGA TOUR, a pioneer and innovation leader in sports has built a multi-agent content generation system to create articles for their digital platforms. The new solution, built on AgentCore, enables the PGA TOUR to provide comprehensive coverage for every player in the field, by increasing content writing speed by 1,000 percent while achieving a 95 percent reduction in costs.</li>
<li>Independent software vendors (ISVs) like Workday are building the software of the future on AgentCore. AgentCore Code Interpreter provides Workday Planning Agent with secure data protection and essential features for financial data exploration. Users can analyze financial and operational data through natural language queries, making financial planning intuitive and self-driven. This capability reduces time spent on routine planning analysis by 30 percent, saving approximately 100 hours per month.</li>
<li>Grupo Elfa, a Brazilian distributor and retailer, relies on AgentCore Observability for complete audit traceability and real-time metrics of their agents, transforming their reactive processes into proactive operations. Using this unified platform, their sales team can handle thousands of daily price quotes while the organization maintains full visibility of agent decisions, helping achieve 100 percent traceability of agent decisions and interactions, and reduced problem resolution time by 50 percent.</li>
</ul><p>As organizations scale their agent deployments, they face challenges around implementing the right boundaries and quality checks to confidently deploy agents. The autonomy that makes agents powerful also makes them hard to confidently deploy at scale, as they might access sensitive data inappropriately, make unauthorized decisions, or take unexpected actions. Development teams must balance enabling agent autonomy while ensuring they operate within acceptable boundaries and with the quality you require to put them in front of customers and employees.</p><p>The new capabilities available today take the guesswork out of this process and help you build and deploy trusted AI agents with confidence:</p><ul><li><strong>Policy in AgentCore</strong> (Preview) – Defines clear boundaries for agent actions by intercepting AgentCore Gateway tool calls before they run using policies with fine-grained permissions.</li>
<li><strong>AgentCore Evaluations</strong> (Preview) – Monitors the quality of your agents based on real-world behavior using built-in evaluators for dimensions such as correctness and helpfulness, plus custom evaluators for business-specific requirements.</li>
</ul><p>We’re also introducing features that expand what agents can do:</p><ul><li><strong>Episodic functionality in AgentCore Memory</strong> – A new long-term strategy that helps agents learn from experiences and adapt solutions across similar situations for improved consistency and performance in similar future tasks.</li>
<li><strong>Bidirectional streaming in AgentCore Runtime</strong> – Deploys voice agents where both users and agents can speak simultaneously following a natural conversation flow.</li>
</ul><p><strong>Policy in AgentCore for precise agent control</strong><br />Policy gives you control over the actions agents can take and are applied outside of the agent’s reasoning loop, treating agents as autonomous actors whose decisions require verification before reaching tools, systems, or data. It integrates with AgentCore Gateway to intercept tool calls as they happen, processing requests while maintaining operational speed, so workflows remain fast and responsive.</p><p>You can create policies using natural language or directly use <a href="https://www.cedarpolicy.com/">Cedar</a>—an open source policy language for fine-grained permissions—simplifying the process to set up, understand, and audit rules without writing custom code. This approach makes policy creation accessible to development, security, and compliance teams who can create, understand, and audit rules without specialized coding knowledge.</p><p>The policies operate independently of how the agent was built or which model it uses. You can define which tools and data agents can access—whether they are APIs, <a href="https://aws.amazon.com/lambda/">AWS Lambda</a> functions, <a href="https://modelcontextprotocol.io/">Model Context Protocol (MCP)</a> servers, or third-party services—what actions they can perform, and under what conditions.</p><p>Teams can define clear policies once and apply them consistently across their organization. With policies in place, developers gain the freedom to create innovative agentic experiences, and organizations can deploy their agents to act autonomously while knowing they’ll stay within defined boundaries and compliance requirements.</p><p><strong>Using Policy in AgentCore<br /></strong> You can start by creating a policy engine in the new <strong>Policy</strong> section of the <a href="https://console.aws.amazon.com/bedrock-agentcore">AgentCore console</a> and associate it with one or more AgentCore gateways.</p><p>A policy engine is a collection of policies that are evaluated at the gateway endpoint. When associating a gateway with a policy engine, you can choose whether to enforce the result of the policy—effectively permitting or denying access to a tool call—or to only emit logs. Using logs helps you test and validate a policy before enabling it in production.</p><p>Then, you can define the policies to apply to have granular control over access to the tools offered by the associated AgentCore gateways.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/agentcore-policy-console.png"><img class="aligncenter size-full wp-image-101864" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/agentcore-policy-console.png" alt="Amazon Bedrock AgentCore Policy console" width="995" height="791" /></a></p><p>To create a policy, you can start with a natural language description (that should include information of the authentication claims to use) or directly edit Cedar code.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/agentcore-policy-add.png"><img class="aligncenter size-full wp-image-101868" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/agentcore-policy-add.png" alt="Amazon Bedrock AgentCore Policy add" width="1251" height="1007" /></a></p><p>Natural language-based policy authoring provides a more accessible way for you to create fine-grained policies. Instead of writing formal policy code, you can describe rules in plain English. The system interprets your intent, generates candidate policies, validates them against the tool schema, and uses automated reasoning to check safety conditions—identifying prompts that are overly permissive, overly restrictive, or contain conditions that can never be satisfied.</p><p>Unlike generic <a href="https://aws.amazon.com/what-is/large-language-model/">large language model (LLM)</a> translations, this feature understands the structure of your tools and generates policies that are both syntactically correct and semantically aligned with your intent, while flagging rules that cannot be enforced. It is also available as a <a href="https://modelcontextprotocol.io/">Model Context Protocol (MCP)</a> server, so you can author and validate policies directly in your preferred AI-assisted coding environment as part of your normal development workflow. This approach reduces onboarding time and helps you write high-quality authorization rules without needing Cedar expertise.</p><p>The following sample policy uses information from the OAuth claims in the JWT token used to authenticate to an AgentCore gateway (for the <code>role</code>) and the arguments passed to the tool call (<code>context.input</code>) to validate access to the tool processing a refund. Only an authenticated user with the <code>refund-agent</code> role can access the tool but for amounts (<code>context.input.amount</code>) lower than $200 USD.</p><pre class="lang-cedar">permit(
  principal is AgentCore::OAuthUser,
  action == AgentCore::Action::"RefundTool__process_refund",
  resource == AgentCore::Gateway::"&lt;GATEWAY_ARN&gt;"
)
when {
  principal.hasTag("role") &amp;&amp;
  principal.getTag("role") == "refund-agent" &amp;&amp;
  context.input.amount &lt; 200
};</pre><p><strong>AgentCore Evaluations for continuous, real-time quality intelligence</strong><br />AgentCore Evaluations is a fully managed service that helps you continuously monitor and analyze agent performance based on real-world behavior. With AgentCore Evaluations, you can use built-in evaluators for common quality dimensions such as correctness, helpfulness, tool selection accuracy, safety, goal success rate, and context relevance. You can also create custom model-based scoring systems configured with your choice of prompt and model for business-tailored scoring while the service samples live agent interactions and scores them continuously.</p><p>All results from AgentCore Evaluations are visualized in <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a> alongside AgentCore Observability insights, providing one place for unified monitoring. You can also set up alerts and alarms on the evaluation scores to proactively monitor agent quality and respond when metrics fall outside acceptable thresholds.</p><p>You can use AgentCore Evaluations during the testing phase where you can check an agent against the baseline before deployment to stop faulty versions from reaching users, and in production for continuous improvement of your agents. When quality metrics drop below defined thresholds—such as a customer service agent satisfaction declining or politeness scores dropping by more than 10 percent over an 8-hour period—the system triggers immediate alerts, helping to detect and address quality issues faster.</p><p><strong>Using AgentCore Evaluations<br /></strong> You can create an online evaluation in the new <strong>Evaluations</strong> section of the <a href="https://console.aws.amazon.com/bedrock-agentcore">AgentCore console</a>. You can use as data source an AgentCore agent endpoint or a CloudWatch log group used by an external agent. For example, I use here the same sample customer support agent I shared when we <a href="https://aws.amazon.com/blogs/aws/introducing-amazon-bedrock-agentcore-securely-deploy-and-operate-ai-agents-at-any-scale/">introduced AgentCore in preview</a>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/agentcore-evaluations-source.png"><img class="aligncenter size-full wp-image-101865" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/agentcore-evaluations-source.png" alt="Amazon Bedrock AgentCore Evaluations source" width="982" height="813" /></a></p><p>Then, you can select the evaluators to use, including custom evaluators that you can define starting from the existing templates or build from scratch.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/agentcore-evaluations-evaluators.png"><img class="aligncenter size-full wp-image-101866" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/agentcore-evaluations-evaluators.png" alt="Amazon Bedrock AgentCore Evaluations source" width="980" height="991" /></a></p><p>For example, for a customer support agent, you can select metrics such as:</p><ul><li><strong>Correctness</strong> – Evaluates whether the information in the agent’s response is factually accurate</li>
<li><strong>Faithfulness</strong> – Evaluates whether information in the response is supported by provided context/sources</li>
<li><strong>Helpfulness</strong> – Evaluates from user’s perspective how useful and valuable the agent’s response is</li>
<li><strong>Harmfulness</strong> – Evaluates whether the response contains harmful content</li>
<li><strong>Stereotyping</strong> – Detects content that makes generalizations about individuals or groups</li>
</ul><p>The evaluators for tool selection and tool parameter accuracy can help you understand if an agent is choosing the right tool for a task and extracting the correct parameters from the user queries.</p><p>To complete the creation of the evaluation, you can choose the sampling rate and optional filters. For permissions, you can create a new <a href="https://aws.amazon.com/iam/">AWS Identity and Access Management (IAM)</a> service role or pass an existing one.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/agentcore-evaluations-filters-permissions.png"><img class="aligncenter size-full wp-image-101867" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/agentcore-evaluations-filters-permissions.png" alt="Amazon Bedrock AgentCore Evaluations create" width="983" height="643" /></a></p><p>The results are published, as they are evaluated, on <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a> in the AgentCore Observability dashboard. You can choose any of the bar chart sections to see the corresponding traces and gain deeper insight into the requests and responses behind that specific evaluation.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/27/agentcore-evaluations-results.png"><img class="aligncenter size-full wp-image-102185" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/27/agentcore-evaluations-results.png" alt="Amazon AgentCore Evaluations results" width="2360" height="1652" /></a></p><p>Because the results are in CloudWatch, you can use all of its feature to create, for example, alarms and automations.</p><p><strong>Creating custom evaluators in AgentCore Evaluations<br /></strong> Custom evaluators allow you to define business-specific quality metrics tailored to your agent’s unique requirements. To create a custom evaluator, you provide the model to use as a judge, including inference parameters such as temperature and max output tokens, and a tailored prompt with the judging instructions. You can start from the prompt used by one of the built-in evaluators or enter a new one.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/26/agentcore-policy-custom-evaluator.png"><img class="aligncenter size-full wp-image-102068" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/26/agentcore-policy-custom-evaluator.png" alt="AgentCore Evaluations create custom evaluator" width="1183" height="954" /></a></p><p>Then, you define the scale to produce in output. It can be either numeric values or custom text labels that you define. Finally, you configure whether the evaluation is computed by the model on single traces, full sessions, or for each tool call.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/26/agentcore-policy-custom-evaluator-scale.png"><img class="aligncenter size-full wp-image-102069" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/26/agentcore-policy-custom-evaluator-scale.png" alt="AgentCore Evaluations custom evaluator scale" width="1183" height="699" /></a></p><p><strong>AgentCore Memory episodic functionality for experience-based learning<br /></strong> AgentCore Memory, a fully managed service that gives AI agents the ability to remember past interactions, now includes a new <a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/long-term-memory-long-term.html">long-term memory</a> strategy that gives agents the ability to learn from past experiences and apply those lessons to provide more helpful assistance in future interactions.</p><p>Consider booking travel with an agent: over time, the agent learns from your booking patterns—such as the fact that you often need to move flights to later times when traveling for work due to client meetings. When you start your next booking involving client meetings, the agent proactively suggests flexible return options based on these learned patterns. Just like an experienced assistant who learns your specific travel habits, agents with episodic memory can now recognize and adapt to your individual needs.</p><p>When you enable the new episodic functionality, AgentCore Memory captures structured episodes that record the context, reasoning process, actions taken, and outcomes of agent interactions, while a reflection agent analyzes these episodes to extract broader insights and patterns. When facing similar tasks, agents can retrieve these learnings to improve decision-making consistency and reduce processing time. This reduces the need for custom instructions by including in the agent context only the specific learnings an agent needs to complete a task instead of a long list of all possible suggestions.</p><p><strong>AgentCore Runtime bidirectional streaming for more natural conversations</strong><br />With AgentCore Runtime, you can deploy agentic applications with few lines of code. To simplify deploying conversational experiences that feel natural and responsive, AgentCore Runtime now supports bidirectional streaming. This capability enables voice agents to listen and adapt while users speak, so that people can interrupt agents mid-response and have the agent immediately adjust to the new context—without waiting for the agent to finish its current output. Rather than traditional turn-based interaction where users must wait for complete responses, bidirectional streaming creates flowing, natural conversations where agents dynamically change their response based on what the user is saying.</p><p>Building these conversational experiences from the ground up requires significant engineering effort to handle the complex flow of simultaneous communication. Bidirectional streaming simplifies this by managing the infrastructure needed for agents to process input while generating output, handling interruptions gracefully, and maintaining context throughout dynamic conversation shifts. You can now deploy agents that naturally adapt to the fluid nature of human conversation—supporting mid-thought interruptions, context switches, and clarifications without losing the thread of the interaction.</p><p><strong>Things to know</strong><br /><a href="https://aws.amazon.com/bedrock/agentcore/">Amazon Bedrock AgentCore</a>, including the preview of Policy, is available in the US East (Ohio, N. Virginia), US West (Oregon), Asia Pacific (Mumbai, Singapore, Sydney, Tokyo), and Europe (Frankfurt, Ireland) <a href="https://aws.amazon.com/about-aws/global-infrastructure/regions_az/">AWS Regions</a> . The preview of AgentCore Evaluations is available in the US East (Ohio, N. Virginia), US West (Oregon), Asia Pacific (Sydney), and Europe (Frankfurt) Regions. For Regional availability and future roadmap, visit <a href="https://builder.aws.com/capabilities/">AWS Capabilities by Region</a>.</p><p>With AgentCore, you pay for what you use with no upfront commitments. For detailed pricing information, visit the <a href="https://aws.amazon.com/bedrock/pricing/">Amazon Bedrock pricing page</a>. AgentCore is also a part of the <a href="https://aws.amazon.com/free">AWS Free Tier</a> that new AWS customers can use to get started at no cost and explore key AWS services.</p><p>These new features work with any open source framework such as <a href="https://www.crewai.com/">CrewAI</a>, <a href="https://www.langchain.com/langgraph">LangGraph</a>, <a href="https://www.llamaindex.ai/">LlamaIndex</a>, and <a href="https://strandsagents.com/">Strands Agents</a>, and with any foundation model. AgentCore services can be used together or independently, and you can get started using your favorite AI-assisted development environment with the <a href="https://awslabs.github.io/mcp/servers/amazon-bedrock-agentcore-mcp-server">AgentCore open source MCP server</a>.</p><p>To learn more and get started quickly, visit the <a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/what-is-bedrock-agentcore.html">AgentCore Developer Guide</a>.</p><p>— <a href="https://x.com/danilop">Danilo</a></p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="abf27f60-117f-43d2-b6f3-b2ec43dc82ff" data-title="Amazon Bedrock AgentCore adds quality evaluations and policy controls for deploying trusted AI agents" data-url="https://aws.amazon.com/blogs/aws/amazon-bedrock-agentcore-adds-quality-evaluations-and-policy-controls-for-deploying-trusted-ai-agents/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-bedrock-agentcore-adds-quality-evaluations-and-policy-controls-for-deploying-trusted-ai-agents/"/>
    <updated>2025-12-02T17:14:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/build-multi-step-applications-and-ai-workflows-with-aws-lambda-durable-functions/</id>
    <title><![CDATA[Build multi-step applications and AI workflows with AWS Lambda durable functions]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Modern applications increasingly require complex and long-running coordination between services, such as multi-step payment processing, AI agent orchestration, or approval processes awaiting human decisions. Building these traditionally required significant effort to implement state management, handle failures, and integrate multiple infrastructure services.</p><p>Starting today, you can use <a href="https://aws.amazon.com/lambda/durable-functions/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">AWS Lambda durable functions</a> to build reliable multi-step applications directly within the familiar AWS Lambda experience. Durable functions are regular Lambda functions with the same event handler and integrations you already know. You write sequential code in your preferred programming language, and durable functions track progress, automatically retry on failures, and suspend execution for up to one year at defined points, without paying for idle compute during waits.</p><p>AWS Lambda durable functions use a checkpoint and replay mechanism, known as durable execution, to deliver these capabilities. After enabling a function for durable execution, you add the new open source durable execution SDK to your function code. You then use SDK primitives like “steps” to add automatic checkpointing and retries to your business logic and “waits” to efficiently suspend execution without compute charges. When execution terminates unexpectedly, Lambda resumes from the last checkpoint, replaying your event handler from the beginning while skipping completed operations.</p><p><strong>Getting started with AWS Lambda durable functions<br /></strong> Let me walk you through how to use durable functions.</p><p>First, I create a new <a href="https://console.aws.amazon.com/lambda?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Lambda function in the console</a> and select <strong>Author from scratch</strong>. In the <strong>Durable execution</strong> section, I select <strong>Enable</strong>. Note that, durable function setting can only be set during function creation and currently can’t be modified for existing Lambda functions.</p><p><img class="aligncenter size-full wp-image-101851 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/2025-news-durable-function-4.png" alt="" width="1066" height="889" /></p><p>After I create my Lambda durable function, I can get started with the provided code.</p><p><img class="aligncenter size-full wp-image-101860 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/2025-news-durable-function-5.png" alt="" width="1311" height="1405" /></p><p>Lambda durable functions introduces two core primitives that handle state management and recovery:</p><ul><li><strong>Steps</strong>—The <code>context.step()</code> method adds automatic retries and checkpointing to your business logic. After a step is completed, it will be skipped during replay.</li>
<li><strong>Wait</strong>—The <code>context.wait()</code> method pauses execution for a specified duration, terminating the function, suspending and resuming execution without compute charges.</li>
</ul><p>Additionally, Lambda durable functions provides other operations for more complex patterns: <code>create_callback()</code> creates a callback that you can use to await results for external events like API responses or human approvals, <code>wait_for_condition()</code> pauses until a specific condition is met like polling a REST API for process completion, and <code>parallel()</code> or <code>map()</code> operations for advanced concurrency use cases.</p><p><strong>Building a production-ready order processing workflow<br /></strong> Now let’s expand the default example to build a production-ready order processing workflow. This demonstrates how to use callbacks for external approvals, handle errors properly, and configure retry strategies. I keep the code intentionally concise to focus on these core concepts. In a full implementation, you could enhance the validation step with <a href="https://console.aws.amazon.com/bedrock?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">Amazon Bedrock</a> to add AI-powered order analysis.</p><p>Here’s how the order processing workflow works:</p><ul><li>First, <code>validate_order()</code> checks order data to ensure all required fields are present.</li>
<li>Next, <code>send_for_approval()</code> sends the order for external human approval and waits for a callback response, suspending execution without compute charges.</li>
<li>Then, <code>process_order()</code> completes order processing.</li>
<li>Throughout the workflow, try-catch error handling distinguishes between terminal errors that stop execution immediately and recoverable errors inside steps that trigger automatic retries.</li>
</ul><p>Here’s the complete order processing workflow with step definitions and the main handler:</p><pre class="language-python">import random
from aws_durable_execution_sdk_python import (
    DurableContext,
    StepContext,
    durable_execution,
    durable_step,
)
from aws_durable_execution_sdk_python.config import (
    Duration,
    StepConfig,
    CallbackConfig,
)
from aws_durable_execution_sdk_python.retries import (
    RetryStrategyConfig,
    create_retry_strategy,
)
@durable_step
def validate_order(step_context: StepContext, order_id: str) -&gt; dict:
    """Validates order data using AI."""
    step_context.logger.info(f"Validating order: {order_id}")
    # In production: calls Amazon Bedrock to validate order completeness and accuracy
    return {"order_id": order_id, "status": "validated"}
@durable_step
def send_for_approval(step_context: StepContext, callback_id: str, order_id: str) -&gt; dict:
    """Sends order for approval using the provided callback token."""
    step_context.logger.info(f"Sending order {order_id} for approval with callback_id: {callback_id}")
    # In production: send callback_id to external approval system
    # The external system will call Lambda SendDurableExecutionCallbackSuccess or
    # SendDurableExecutionCallbackFailure APIs with this callback_id when approval is complete
    return {
        "order_id": order_id,
        "callback_id": callback_id,
        "status": "sent_for_approval"
    }
@durable_step
def process_order(step_context: StepContext, order_id: str) -&gt; dict:
    """Processes the order with retry logic for transient failures."""
    step_context.logger.info(f"Processing order: {order_id}")
    # Simulate flaky API that sometimes fails
    if random.random() &gt; 0.4:
        step_context.logger.info("Processing failed, will retry")
        raise Exception("Processing failed")
    return {
        "order_id": order_id,
        "status": "processed",
        "timestamp": "2025-11-27T10:00:00Z",
    }
@durable_execution
def lambda_handler(event: dict, context: DurableContext) -&gt; dict:
    try:
        order_id = event.get("order_id")
        # Step 1: Validate the order
        validated = context.step(validate_order(order_id))
        if validated["status"] != "validated":
            raise Exception("Validation failed")  # Terminal error - stops execution
        context.logger.info(f"Order validated: {validated}")
        # Step 2: Create callback
        callback = context.create_callback(
            name="awaiting-approval",
            config=CallbackConfig(timeout=Duration.from_minutes(3))
        )
        context.logger.info(f"Created callback with id: {callback.callback_id}")
        # Step 3: Send for approval with the callback_id
        approval_request = context.step(send_for_approval(callback.callback_id, order_id))
        context.logger.info(f"Approval request sent: {approval_request}")
        # Step 4: Wait for the callback result
        # This blocks until external system calls SendDurableExecutionCallbackSuccess or SendDurableExecutionCallbackFailure
        approval_result = callback.result()
        context.logger.info(f"Approval received: {approval_result}")
        # Step 5: Process the order with custom retry strategy
        retry_config = RetryStrategyConfig(max_attempts=3, backoff_rate=2.0)
        processed = context.step(
            process_order(order_id),
            config=StepConfig(retry_strategy=create_retry_strategy(retry_config)),
        )
        if processed["status"] != "processed":
            raise Exception("Processing failed")  # Terminal error
        context.logger.info(f"Order successfully processed: {processed}")
        return processed
    except Exception as error:
        context.logger.error(f"Error processing order: {error}")
        raise error  # Re-raise to fail the execution
</pre><p>This code demonstrates several important concepts:</p><ul><li><strong>Error handling</strong>—The try-catch block handles terminal errors. When an unhandled exception is thrown outside of a step (like the validation check), it terminates the execution immediately. This is useful when there’s no point in retrying, such as invalid order data.</li>
<li><strong>Step retries</strong>—Inside the <code>process_order</code> step, exceptions trigger automatic retries based on the default (step 1) or configured <code>RetryStrategy</code> (step 5). This handles transient failures like temporary API unavailability.</li>
<li><strong>Logging</strong>—I use <code>context.logger</code> for the main handler and <code>step_context.logger</code> inside steps. The context logger suppresses duplicate logs during replay.</li>
</ul><p>Now I create a test event with <code>order_id</code> and invoke the function asynchronously to start the order workflow. I navigate to the <strong>Test</strong> tab and fill in the optional <strong>Durable execution name</strong> to identify this execution. Note that, durable functions provides built-in idempotency. If I invoke the function twice with the same execution name, the second invocation returns the existing execution result instead of creating a duplicate.</p><p><img class="aligncenter size-full wp-image-102269 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/28/2025-news-durable-function-rev-8-2.png" alt="" width="1297" height="1257" /></p><p>I can monitor the execution by navigating to the <strong>Durable executions</strong> tab in the Lambda console:</p><p><img class="aligncenter wp-image-102325 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/29/2025-news-durable-function-rev-9-1.png" alt="" width="693" height="624" /></p><p>Here I can see each step’s status and timing. The execution shows <code>CallbackStarted</code> followed by <code>InvocationCompleted</code>, which indicates the function has terminated and execution is suspended to avoid idle charges while waiting for the approval callback.</p><p><img class="aligncenter size-full wp-image-102314 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/29/2025-news-durable-function-rev-3-1-1.png" alt="" width="1397" height="419" /></p><p>I can now complete the callback directly from the console by choosing <strong>Send success</strong> or <strong>Send failure</strong>, or programmatically using the Lambda API.</p><p><img class="aligncenter size-full wp-image-102315 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/29/2025-news-durable-function-rev-3-2.png" alt="" width="1645" height="725" /></p><p>I choose <strong>Send success</strong>.</p><p><img class="aligncenter size-full wp-image-102195 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/27/2025-news-durable-function-rev-6.png" alt="" width="1342" height="967" /></p><p>After the callback completes, the execution resumes and processes the order. If the <code>process_order</code> step fails due to the simulated flaky API, it automatically retries based on the configured strategy. Once all retries succeed, the execution completes successfully.</p><p><img class="aligncenter size-full wp-image-102316 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/29/2025-news-durable-function-rev-3-3.png" alt="" width="1387" height="834" /></p><p><strong>Monitoring executions with Amazon EventBridge<br /></strong> You can also monitor durable function executions using Amazon EventBridge. Lambda automatically sends execution status change events to the default event bus, allowing you to build downstream workflows, send notifications, or integrate with other AWS services.</p><p>To receive these events, create an EventBridge rule on the default event bus with this pattern:</p><pre class="language-json">{
  "source": ["aws.lambda"],
  "detail-type": ["Durable Execution Status Change"]
}
</pre><p><strong>Things to know<br /></strong> Here are key points to note:</p><ul><li><strong>Availability</strong>—Lambda durable functions are now available in US East (Ohio) AWS Region. For the latest Region availability, visit the <a href="https://builder.aws.com/build/capabilities/explore?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">AWS Capabilities by Region</a> page.</li>
<li><strong>Programming language support</strong>—At launch, AWS Lambda durable functions supports JavaScript/TypeScript (Node.js 22/24) and Python (3.13/3.14). We recommend bundling the durable execution SDK with your function code using your preferred package manager. The SDKs are fast-moving, so you can easily update dependencies as new features become available.</li>
<li><strong>Using Lambda versions</strong>—When deploying durable functions to production, use Lambda versions to ensure replay always happens on the same code version. If you update your function code while an execution is suspended, replay will use the version that started the execution, preventing inconsistencies from code changes during long-running workflows.</li>
<li><strong>Testing your durable functions</strong>—You can test durable functions locally without AWS credentials using the separate testing SDK with pytest integration and the <a href="https://aws.amazon.com/serverless/sam/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">AWS Serverless Application Model (AWS SAM) command line interface (CLI)</a> for more complex integration testing.</li>
<li><strong>Open source SDKs</strong>—The durable execution SDKs are open source for <a href="https://github.com/aws/aws-durable-execution-sdk-js">JavaScript/TypeScript</a> and <a href="https://github.com/aws/aws-durable-execution-sdk-python">Python</a>. You can review the source code, contribute improvements, and stay updated with the latest features.</li>
<li><strong>Pricing</strong>—To learn more on AWS Lambda durable functions pricing, refer to the <a href="https://aws.amazon.com/lambda/pricing/?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">AWS Lambda pricing</a> page.</li>
</ul><p>Get started with AWS Lambda durable functions by visiting the <a href="https://console.aws.amazon.com/lambda?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">AWS Lambda console</a>. To learn more, refer to <a href="https://docs.aws.amazon.com/lambda/latest/dg/durable-functions.html?trk=c4ea046f-18ad-4d23-a1ac-cdd1267f942c&amp;sc_channel=el">AWS Lambda durable functions</a> documentation page.</p><p>Happy building!</p><p>— <a href="https://www.linkedin.com/in/donnieprakoso">Donnie</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="d4475bd4-1897-4726-a25b-6c72a2f101d5" data-title="Build multi-step applications and AI workflows with AWS Lambda durable functions" data-url="https://aws.amazon.com/blogs/aws/build-multi-step-applications-and-ai-workflows-with-aws-lambda-durable-functions/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/build-multi-step-applications-and-ai-workflows-with-aws-lambda-durable-functions/"/>
    <updated>2025-12-02T17:12:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-rds-for-oracle-and-rds-for-sql-server-add-new-capabilities-to-enhance-performance-and-optimize-costs/</id>
    <title><![CDATA[New capabilities to optimize costs and improve scalability on Amazon RDS for SQL Server and Oracle]]></title>
    <summary><![CDATA[<table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Managing database environments demands a balance of resource efficiency and scalability. Organizations need flexible options across their entire database lifecycle, spanning development, testing, and production workloads with diverse storage and compute requirements.</p><p>To address these needs, we’re announcing four new capabilities for <a href="https://aws.amazon.com/rds/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon Relational Database Service (Amazon RDS)</a> to help customers optimize their costs as well as improve efficiency and scalability for their <a href="https://awsblog.awsapps.com/workdocs-amazon/index.html#/document/893b3209d71ce7ba2c73c433e532f1f34708c2309572eb0f77352bc3f4ffb01f?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon RDS for Oracle</a> and <a href="https://aws.amazon.com/rds/sqlserver?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon RDS for SQL Server</a> databases. These enhancements include SQL Server Developer Edition support and expanded storage capabilities for both RDS for Oracle and RDS for SQL Server. Additionally, you can have CPU optimization options for RDS for SQL Server on M7i and R7i instances, which offer price reductions from previous generation instances and separately billed licensing fees.</p><p>Let’s explore what’s new.</p><p><strong>SQL Server Developer Edition support<br /></strong> SQL Server Developer Edition is now available on RDS for SQL Server, offering a free SQL Server edition that includes all the Enterprise Edition functionalities. Developer Edition is licensed specifically for non-production workloads, so you can build and test applications without incurring SQL Server licensing costs in your development and testing environments.</p><p>This release brings significant cost savings to your development and testing environments, while maintaining consistency with your production configurations. You’ll have access to all Enterprise Edition features in your development environment, making it easier to test and validate your applications. Additionally, you’ll benefit from the full suite of Amazon RDS features, including automated backups, software updates, monitoring, and encryption capabilities throughout your development process.</p><p>To get started, upload your SQL Server binary files to <a href="https://aws.amazon.com/s3?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon Simple Storage Service (Amazon S3)</a> and use them to create your Developer Edition instance. You can migrate existing data from your Enterprise or Standard Edition instances to Developer Edition instances using built-in SQL Server backup and restore operations.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/28/image-22-5.png"><img class="aligncenter size-full wp-image-102267" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/28/image-22-5.png" alt="" width="1069" height="679" /></a></p><p><strong>M7i/R7i instances on RDS for SQL Server with support for optimize CPU<br /></strong> You can now use M7i and R7i instances on Amazon RDS for SQL Server to achieve several key benefits. These instances offer significant cost savings over previous generation instances. You also get improved transparency over your database costs with licensing fees and Amazon RDS DB instances costs billed separately.</p><p>RDS for SQL Server M7i/R7i instances offer up to 55% lower costs compared to previous generation instances. <a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/29/Screenshot-2025-11-26-at-20.17.37-1.png"><img class="aligncenter size-full wp-image-102340" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/29/Screenshot-2025-11-26-at-20.17.37-1.png" alt="" width="805" height="148" /></a></p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/29/Screenshot-2025-11-26-at-20.17.44-1.png"><img class="aligncenter size-full wp-image-102339" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/29/Screenshot-2025-11-26-at-20.17.44-1.png" alt="" width="804" height="146" /></a></p><p>Using the optimize CPU capability on these instances, you can customize the number of vCPUs on license-included RDS for SQL Server instances. This enhancement is particularly valuable for database workloads that require high memory and input/output operations per second (IOPS), but lower vCPU counts</p><p>This feature provides substantial benefits for your database operations. You can significantly reduce vCPU-based licensing costs while maintaining the same memory and IOPS performance levels your applications require. The capability supports higher memory-to-vCPU ratios and automatically disables hyperthreading while maintaining instance performance. Most importantly, you can fine-tune your CPU settings to precisely match your specific workload requirements, providing optimal resource utilization.</p><p>To get started, select SQL Server with an M7i or R7i instance type when creating a new database instance. Under <strong>Optimize CPU</strong> select <strong>Configure the number of vCPUs</strong> and set your desired vCPU count.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/26/image-42-1.png"><img class="aligncenter size-full wp-image-102110" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/26/image-42-1.png" alt="" width="2184" height="572" /></a></p><p><strong>Additional storage volumes for RDS for Oracle and SQL Server<br /></strong> Amazon RDS for Oracle and Amazon RDS for SQL Server now support up to 256 TiB storage size, a fourfold increase in storage size per database instance, through the addition of up to three additional storage volumes.</p><p>The additional storage volumes provide extensive flexibility in managing your database storage needs. You can configure your volumes using both io2 and gp3 volumes to create an optimal storage strategy. You can store frequently accessed data on high-performance Provisioned IOPS SSD (io2) volumes while keeping historical data on cost-effective General Purpose SSD (gp3) volumes, which balances performance and cost. For temporary storage needs, such as month-end processing or data imports, you can add storage volumes as needed. After these operations are complete, you can empty the volumes and then remove them to reduce unnecessary storage costs.</p><p>These storage volumes offer operational flexibility with zero downtime and you can add or remove additional storage volumes without interrupting your database operations. You can also scale up multiple volumes in parallel to quickly meet growing storage demands. For Multi-AZ deployments, all additional storage volumes are automatically replicated to maintain high availability.</p><p>You can add storage volumes to new or existing database instances through the <a href="https://console.aws.amazon.com/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">AWS Management Console</a>, <a href="https://aws.amazon.com/cli?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">AWS Command Line Interface (AWS CLI)</a>, or <a href="https://builder.aws.com/build/tools?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">AWS SDKs</a>.</p><p>Let me show you a quick example. I’ll add a storage volume to an existing RDS for Oracle database instance.</p><p>First, I navigate to the RDS console, then to my RDS for Oracle database instance detail page. I look under Configuration and I find the <strong>Additional storage volumes</strong> section.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/image-22-4.png"><img class="aligncenter size-full wp-image-101915" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/image-22-4.png" alt="" width="2266" height="556" /></a></p><p>You can add up to three additional storage volumes and each must be named according to a naming convention. Storage volumes can’t have the same name and you must choose between rdsdbdata2, rdsdbdata3, and rdsdbdata4. For RDS for Oracle database instances, I can add additional storage volumes to the database instance with the primary storage volume size of 200 GiB or higher.</p><p>I’m going to add two volumes, so I choose <strong>Add additional storage volume</strong> and then fill in all the required information. I choose <code>rdsdbdata2</code> as the volume name and give it 12000 GiB of allocated storage with 60000 provisioned IOPS on an io2 storage type. For my second additional storage volume, <code>rdsdbdata3</code>, I choose to have 2000 GiB on gp3 with 15000 provisioned IOPS.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/image-23-3.png"><img class="aligncenter size-full wp-image-101934" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/25/image-23-3.png" alt="" width="2712" height="1550" /></a></p><p>After confirmation, I wait for Amazon RDS to process my request and then my additional volumes are available.</p><p>You can also use the AWS CLI to add volumes during creation of database instances or when modifying them.</p><p><strong>Things to know<br /></strong> These capabilities are now available in all commercial <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">AWS Regions</a> and the <a href="https://aws.amazon.com/govcloud-us?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">AWS GovCloud (US)</a> Regions where Amazon RDS for Oracle and Amazon RDS for SQL Server are offered.</p><p>You can learn more about each of these capabilities in the Amazon RDS documentation for <a href="https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Welcome.html?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Developer Edition</a>, <a href="https://docs.aws.amazon.com/AmazonRDS/UserGuide/SQLServer.Concepts.General.OptimizeCPU.html?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">optimize CPU</a>, <a href="https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/User_Oracle_AdditionalStorage.html?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">additional storage volumes for RDS for Oracle</a> and <a href="https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Appendix.SQLServer.CommonDBATasks.DatabaseStorage.html?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">additional storage volumes for RDS for SQL Server</a>.</p><p>To learn more about the unbundled pricing structure for M7i and R7i instances on RDS for SQL Server, visit the <a href="https://aws.amazon.com/rds/sqlserver/pricing/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon RDS for SQL Server pricing page</a>.</p><p>To get started with any of these capabilities, go to the <a href="https://console.aws.com/rds?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon RDS console</a> or learn more by visiting the <a href="https://docs.aws.amazon.com/rds?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon RDS documentation</a>.</p>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-rds-for-oracle-and-rds-for-sql-server-add-new-capabilities-to-enhance-performance-and-optimize-costs/"/>
    <updated>2025-12-02T17:09:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/introducing-database-savings-plans-for-aws-databases/</id>
    <title><![CDATA[Introducing Database Savings Plans for AWS Databases]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>Since <a href="https://aws.amazon.com/?nc2=h_home">Amazon Web Services (AWS)</a> introduced <a href="https://aws.amazon.com/savingsplans/">Savings Plans</a>, customers have been able to lower the cost of running sustained workloads while maintaining the flexibility to manage usage across accounts, resource types, and <a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html#region">AWS Regions</a>. Today, we’re extending this flexible pricing model to AWS managed database services with the launch of Database Savings Plans, which help customers reduce database costs by up to 35% when they commit to a consistent amount of usage ($/hour) over a <strong>1-year</strong> term. Savings automatically apply each hour to eligible usage across supported database services, and any additional usage beyond the commitment is billed at on-demand rates.</p><p>As organizations build and manage data-driven and AI applications, they often use different database services, engines and deployment types, including instance-based and serverless options, to meet evolving business needs. Database Savings Plans provide the flexibility to choose how workloads run while maintaining cost efficiency. If customers are in the middle of a migration or modernization effort, they can switch database engines and adjust deployment types, such as from provisioned to serverless as part of ongoing cost optimization, while continuing to receive discounted rates. If a customer’s business expands globally, they can also shift usage across AWS Regions and continue to benefit from the same commitment. By applying a consistent hourly commitment, customers can maintain predictable spend even as usage patterns evolve and analyze coverage and utilization using familiar cost management tools.</p><p><strong class="c6">New Savings Plans<br /></strong> Each plan defines where pricing applies, the range of available discounts, and the level of flexibility provided across supported database engines, instance families, sizes, deployment options, or AWS Regions.</p><p>The hourly commitment automatically applies to all eligible usage regardless of Region, with support for <a href="https://aws.amazon.com/rds/aurora/?nc2=type_a">Amazon Aurora</a>, <a href="https://aws.amazon.com/rds/?nc2=type_a">Amazon Relational Database Service (Amazon RDS)</a>, <a href="https://aws.amazon.com/dynamodb/?nc2=type_a">Amazon DynamoDB</a>, <a href="https://aws.amazon.com/elasticache/?nc2=type_a">Amazon ElastiCache</a>, <a href="https://aws.amazon.com/documentdb/?nc2=type_a">Amazon DocumentDB (with MongoDB compatibility)</a>, <a href="https://aws.amazon.com/neptune/?nc2=type_a">Amazon Neptune</a>, <a href="https://aws.amazon.com/keyspaces/?nc2=type_a">Amazon Keyspaces (for Apache Cassandra)</a>, <a href="https://aws.amazon.com/timestream/?nc2=type_a">Amazon Timestream</a>, and <a href="https://aws.amazon.com/dms/?nc2=type_a">AWS Database Migration Service (AWS DMS)</a>. As new eligible database offerings, instance types, or Regions become available, Savings Plans will automatically apply to that usage.</p><p>Discounts vary by deployment model and service type. Serverless deployments provide up to 35% savings compared to on-demand rates. Provisioned instances across supported database services deliver up to 20% savings. For Amazon DynamoDB and Amazon Keyspaces, on-demand throughput workloads receive up to 18% savings, and provisioned capacity offers up to 12%. Together, these savings help customers optimize costs while maintaining consistent coverage for database usage. To learn more about the pricing and eligible usage, visit the <a href="https://aws.amazon.com/savingsplans/database-pricing/">Database Savings Plans pricing page</a>.</p><p><strong class="c6">Purchasing Database Savings Plans<br /></strong> <a href="https://aws.amazon.com/aws-cost-management/aws-cost-explorer/?nc2=type_a">AWS Billing and Cost Management Console</a> helps you choose Savings Plans and guides you through the purchase process. You can get started from the <a href="https://aws.amazon.com/console/?nc2=type_a">AWS Management Console</a> or use the <a href="https://aws.amazon.com/cli/">AWS Command Line Interface (AWS CLI)</a> and the API. There are two ways to evaluate Database Savings Plans purchases, in the Recommendations view and in the Purchase Analyzer.</p><p><strong>Recommendations</strong> – are automatically generated from your recent on-demand usage. To reach the Recommendations view in the <a href="https://console.aws.amazon.com/cost-reports/home?region=us-east-1#/dashboard"><strong>Billing and Cost Management console</strong></a>, choose <strong>Savings and Commitments</strong>, <strong>Savings Plans</strong>, and <strong>Recommendations</strong> in the navigation pane. In the <strong>Recommendations</strong> view, select <strong>Database Savings Plans</strong> and configure the <strong>Recommendation options</strong>. AWS Savings Plans recommendations analyze your historical on-demand usage to identify the hourly commitment that delivers the highest overall savings.<a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/15/recommendation-1.png"><img class="aligncenter size-full wp-image-101049" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/15/recommendation-1.png" alt="" width="3006" height="990" /></a></p><p><strong>The Purchase Analyzer</strong> – is designed for modeling custom commitment levels. If you want to purchase a different amount than the recommended commitment on the <strong>Purchase Analyzer</strong> page, select <strong>Database Savings Plans</strong> and configure <strong>Lookback period</strong> and <strong>Hourly commitment</strong> to simulate alternative commitment levels and see the projected impact on <strong>Cost</strong>, <strong>Coverage</strong>, and <strong>Utilization</strong>.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/20/image-1-17.png"><img class="aligncenter size-full wp-image-101457" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/20/image-1-17.png" alt="" width="1206" height="970" /></a></p><p>This way is preferred if your purchasing strategy includes smaller, incremental commitments over time or if you expect future usage changes that could affect your ideal purchase amount.</p><p>After reviewing the recommendations or running simulations in Savings Plans Recommendations or Savings Plans Purchase Analyzer, choose <strong>Add to cart</strong> to proceed with your chosen commitment. If you prefer to purchase directly, you can also navigate to the <strong>Purchase Savings Plans</strong> page. The console updates estimated discounts and coverage in real time as you adjust each setting, so you can evaluate the impact before completing your order.</p><p><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/20/purchase-savings-plans.png"><img class="aligncenter size-full wp-image-101459" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/20/purchase-savings-plans.png" alt="" width="2876" height="1222" /></a></p><p>You can learn more about how to choose and purchase Database Saving Plans by visiting the <a href="https://docs.aws.amazon.com/savingsplans/latest/userguide/what-is-savings-plans.html">Savings Plans User Guide</a> documents.</p><p><strong class="c6">Now available<br /></strong> Database Savings Plans are available in all AWS Regions outside of China. Give them a try and start shaping your database strategy with more flexibility and predictable costs.</p><p>– <a href="https://www.linkedin.com/in/zhengyubin714/">Betty</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="0c4d304d-9e06-4fc3-a9ab-9b551ef376ff" data-title="Introducing Database Savings Plans for AWS Databases" data-url="https://aws.amazon.com/blogs/aws/introducing-database-savings-plans-for-aws-databases/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/introducing-database-savings-plans-for-aws-databases/"/>
    <updated>2025-12-02T17:09:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-cloudwatch-introduces-unified-data-management-and-analytics-for-operations-security-and-compliance/</id>
    <title><![CDATA[Amazon CloudWatch introduces unified data management and analytics for operations, security, and compliance]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab">
<p></p></td></tr></tbody>


</table><p>Today we’re expanding <a href="https://aws.amazon.com/cloudwatch/">Amazon CloudWatch</a> capabilities to unify and manage log data across operational, security, and compliance use cases with flexible and powerful analytics in one place and with reduced data duplication and costs.</p><p>This enhancement means that CloudWatch can automatically normalize and process data to offer consistency across sources with built-in support for <a href="https://docs.aws.amazon.com/security-lake/latest/userguide/open-cybersecurity-schema-framework.html">Open Cybersecurity Schema Framework (OCSF)</a> and <a href="https://opentelemetry.io/">Open Telemetry (OTel)</a> formats, so you can focus on analytics and insights. CloudWatch also introduces Apache Iceberg compatible access to your data through <a href="https://aws.amazon.com/s3/features/tables/">Amazon Simple Storage Service (Amazon S3) Tables</a>, so that you can run analytics, not only locally but also using <a href="https://aws.amazon.com/athena">Amazon Athena</a>, <a href="https://aws.amazon.com/sagemaker/unified-studio/">Amazon SageMaker Unified Studio</a>, or any other Iceberg-compatible tool.</p><p>You can also correlate your operational data in CloudWatch with other business data from your preferred tools to correlate with other data. This unified approach streamlines management and provides comprehensive correlation across security, operational, and business use cases.</p><p>Here are the detailed enhancements:</p><ul><li><strong>Streamline data ingestion and normalization</strong> – CloudWatch automatically collects AWS vended logs across accounts and AWS Regions, integrating with <a href="https://aws.amazon.com/organizations/">AWS Organizations</a> from AWS services including <a href="https://aws.amazon.com/cloudtrail/">AWS CloudTrail,</a> <a href="https://aws.amazon.com/vpc/">Amazon Virtual Private Cloud (Amazon VPC)</a> Flow Logs, <a href="https://aws.amazon.com/waf">AWS WAF</a> access logs, <a href="https://aws.amazon.com/route53">Amazon Route 53</a> resolver logs, and pre-built connectors for third-party sources such as endpoint (CrowdStrike, SentinelOne), identity (Okta, Entra ID), cloud security (Wiz), network security (Zscaler, Palo Alto Networks), productivity and collaboration (Microsoft Office 365, Windows Event Logs, and GitHub), along with IT service manager with ServiceNow CMBD. To normalize and process your data as they are being ingested, CloudWatch offers managed OCSF conversion for various AWS and third-party data sources and other processors such ad Grok for custom parsing, field-level operations, and string manipulations.</li>
<li><strong>Reduce costly log data management</strong> – CloudWatch consolidates log management into a single service with built-in governance capabilities without storing and maintaining multiple copies of the same data across different tools and data stores. The unified data store of CloudWatch eliminates the need for complex ETL pipelines and reduces your operational costs and management overhead needed to maintain multiple separate data stores and tools.</li>
<li><strong>Discover business insights from log data</strong> – You can run queries in CloudWatch using natural language queries and popular query languages such as LogsQL, PPL, and SQL through a single interface, or query your data using your preferred analytics tools through Apache Iceberg-compatible tables. The new Facets interface gives you intuitive filtering by source, application, account, region, and log type, which you can use to run queries across log groups of multiple AWS accounts and Regions with intelligent parameter inference.</li>
</ul><p>In the next sections we explore the new log management and analytics features of the CloudWatch Logs!</p><p><strong>1. Data discovery and management by data sources and types</strong></p><p>You can see a high-level overview of logs and all data sources with a new Logs Management View in the CloudWatch console. To get started, go to the <a href="https://console.aws.amazon.com/cloudwatch/home">CloudWatch console</a> and choose <strong>Log Management</strong> under the <strong>Logs</strong> menu in the left navigation pane. In the <strong>Summary</strong> tab, you can observe your logs data sources and types, insights into how your log groups are doing across ingestion, and anomalies.</p><p><img class="aligncenter wp-image-101615 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/21/2025-cloudwatch-log-1-data-management-overview-1-1.png" alt="" width="2554" height="1833" /></p><p>Choose the <strong>Data sources</strong> tab to find and manage your log data by data sources, types, and fields. CloudWatch ingests and automatically categorizes data sources by AWS services, third-party, or custom sources such as application logs.</p><p><img class="aligncenter wp-image-101619 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/21/2025-cloudwatch-log-management-2-data-sources-2.png" alt="" width="2428" height="1856" /></p><p>Choose the <strong>Data source actions</strong> to integrate S3 Tables to make future logs for selected data sources. You have the flexibility to analyze the logs through Athena and Amazon Redshift and other query engines such as Spark using Iceberg compatible access patterns. With this integration, logs from CloudWatch are available in a read-only <code>aws-cloudwatch</code> S3 Tables bucket.</p><p>When you choose a specific data source such as CloudTrail data, you can view the details of the data source that includes information regarding data format, pipeline, facets/field indexes, S3 Tables association, and the number of logs with that data source. You can observe all log groups included in this data source and type and edit a source/type field index policy using the new schema support.</p><p><img class="aligncenter wp-image-102254 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/28/2025-cloudwatch-log-management-3-data-sources-detail-2.png" alt="" width="2294" height="1370" /></p><p>To learn more about how to manage your data sources and index policy, visit <a href="https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/data-sources.html?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Data sources</a> in the Amazon CloudWatch Logs User Guide.</p><p><strong>2. Ingestion and transformation using CloudWatch pipelines</strong></p><p>You can create pipelines to streamline collecting, transforming, and routing telemetry and security data while standardizing data formats to optimize observability and security data management. The new pipeline feature of CloudWatch connects data from a catalogue of data sources, so that you can add and configure pipeline processors from a library to parse, enrich, and standardize data.</p><p><img class="aligncenter wp-image-102253 size-full c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/28/2025-cloudwatch-log-management-4-pipeline-list-1.jpg" alt="" width="2064" height="466" /></p><p>In the <strong>Pipeline</strong> tab, choose <strong>Add pipeline</strong>. It shows you the pipeline configuration wizard. This wizard guides you through five steps where you can choose the data source and other source details such as log source types, configure destination, configure up to 19 processors to perform an action on your data (such as filtering, transforming, or enriching), and finally review and deploy the pipeline.</p><p><img class="aligncenter wp-image-101618 size-full" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/21/2025-cloudwatch-log-management-4-pipeline-wizards.jpg" alt="" width="2560" height="1022" /></p><p>You also have the option to create pipelines through the new <strong>Ingestion</strong> experience in CloudWatch. To learn more about how to set up and manage the pipelines, visit <a href="https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/cloudwatch-pipelines.html?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Pipelines</a> in the Amazon CloudWatch Logs User Guide.</p><p><strong>3. Enhanced analytics and querying based on data sources</strong></p><p>You can enhance analytics with support for Facets and querying based on data sources. Facets enable interactive exploration and drill-down into logs and their values are automatically extracted based on the selected time period.</p><p>Choose the <strong>Facets</strong> tab in the <strong>Log Insights</strong> under the <strong>Logs</strong> menu in the left navigation pane. You can view available facets and values that appear in the panel. Choose one or more facets and values to interactively explore your data. I choose Facets regarding a VPC Flow Logs group and action, query to list the five most frequent patterns in my VPC Flow Logs through the AI query generator, and get the result patterns.</p><p><img class="aligncenter size-full wp-image-100830 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/12/2025-cloudwatch-log-management-5-log-insights.png" alt="" width="2854" height="2287" /></p><p>You can save your query with the selected Facets and values that you have specified. When you next choose your saved query, the logs to be queried have the pre-specified facets and values. To learn more about Facet management, visit <a href="https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/CloudWatchLogs-Facets.html?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">Facets</a> in the CloudWatch Logs User Guide.</p><p>As I previously noted, you can integrate data sources into S3 Tables and query together. For example, using a Query Editor in Athena, you can query correlates network traffic with AWS API activity from a specific IP range (<code>174.163.137.*</code>) by joining VPC Flow Logs with CloudTrail logs based on matching source IP addresses.</p><p><img class="aligncenter size-full wp-image-101642 c6" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/22/2025-cloudwatch-log-management-5-log-insights-athena.png" alt="" width="2514" height="2234" /></p><p>This type of integrated search is particularly valuable for security monitoring, incident investigation, and suspicious behavior detection. You can view if an IP that’s making network connections is also performing sensitive AWS operations such as creating users, modifying security groups, or accessing data.</p><p>To learn more, visit <a href="https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/s3-tables-integration.html?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">S3 Tables integration with CloudWatch</a> in the CloudWatch Logs User Guide.</p><p><strong class="c7">Now available</strong><br />New log management features of Amazon CloudWatch are available today in all AWS Regions except the AWS GovCloud (US) Regions and China Regions. For Regional availability and future roadmap, visit the <a class="c-link" href="https://builder.aws.com/capabilities/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el" target="_blank" rel="noopener noreferrer" data-stringify-link="https://builder.aws.com/capabilities/" data-sk="tooltip_parent">AWS Capabilities by Region</a>. There are no upfront commitments or minimum fees, and you pay for the usage of existing CloudWatch Logs for data ingestion, storage, and queries. To learn more, visit the <a href="https://aws.amazon.com/cloudwatch/pricing/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">CloudWatch pricing page</a>.</p><p>Give it a try in the <a href="https://console.aws.amazon.com/cloudwatch/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">CloudWatch console</a>. To learn more, visit the <a href="https://aws.amazon.com/cloudwatch/?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">CloudWatch product page</a> and send feedback to <a href="https://repost.aws/tags/TAK9UOZOiFRI2NrXQ-VpOPfQ/amazon-cloudwatch-logs?trk=769a1a2b-8c19-4976-9c45-b6b1226c7d20&amp;sc_channel=el">AWS re:Post for CloudWatch Logs</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channy/">Channy</a></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="eb53a97d-aac8-4a55-8aa1-e7db452eb516" data-title="Amazon CloudWatch introduces unified data management and analytics for operations, security, and compliance" data-url="https://aws.amazon.com/blogs/aws/amazon-cloudwatch-introduces-unified-data-management-and-analytics-for-operations-security-and-compliance/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-cloudwatch-introduces-unified-data-management-and-analytics-for-operations-security-and-compliance/"/>
    <updated>2025-12-02T17:07:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/new-and-enhanced-aws-support-plans-add-ai-capabilities-to-expert-guidance/</id>
    <title><![CDATA[New and enhanced AWS Support plans add AI capabilities to expert guidance]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>Today, we’re announcing a fundamental shift in how <a href="https://aws.amazon.com/premiumsupport/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">AWS Support</a> helps customers move from reactive problem-solving to proactive issue prevention. This evolution introduces new Support plans that combine AI-powered capabilities with <a href="https://aws.amazon.com/?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">Amazon Web Services (AWS)</a> expertise. The new and enhanced plans help you identify and address potential issues before they impact your business operations, helping you to operate and optimize your cloud workloads more effectively.</p><p>The portfolio includes three plans designed to match different operational needs. Each plan offers distinct capabilities, with higher tiers including all the capabilities of lower tiers plus additional features and enhanced service levels. Let’s have a look at them.</p><p><strong>New and enhanced AWS Support paid plans<br /></strong> <strong>Business Support+</strong> transforms the developer, startup, and small business experience by providing intelligent assistance powered by AI. You can choose to engage directly with AWS experts or start with AI-powered contextual recommendations that seamlessly transition to AWS experts when needed. AWS experts respond in within 30 minutes for critical cases(twice as fast as before), maintaining previous context and saving you from having to repeat yourself.</p><p>With a low-cost monthly subscription, this plan delivers advanced operational capabilities through a combination of AI-powered tools and AWS expertise. The plan provides personalized recommendations to help optimize your workloads based on your specific environment, while maintaining seamless access to AWS experts for technical support when needed.</p><p><strong>Enterprise Support</strong> builds on our established support model, this tier accelerates innovation and cloud operations success through intelligent operations and AI-powered trusted human guidance. Your designated technical account manager (TAM) combines deep AWS knowledge with data-driven insights from your environment to help identify optimization opportunities and potential risks before they impact your operations. The plan also offers access to AWS Security Incident Response at no additional fee, a comprehensive service that centralizes tracking, storage, and management of security events while providing automated monitoring and investigation capabilities to strengthen your security posture.</p><p>Through AI-powered assistance and continuous monitoring of your AWS environment, this tier helps you achieve new levels of scale in your operations. With up to 15-minute response times for production-critical issues and support engineers who receive personalized context delivered by AI agents, this tier enables faster and more personalized resolution while maintaining operational excellence. Additionally, you also get access to interactive programs and hands-on workshops to foster continuous technical growth.</p><p><strong>Unified Operations Support</strong> delivers our highest level of context-aware Support through an expanded team of AWS experts. Your core team comprised of a Technical Account Manager, a Domain Engineer, and a designated Senior Billing and Account Specialist is complemented by on-demand experts in migration, incident management, and security. These designated experts understand your unique environment and operational history, providing guidance through your preferred collaboration channels while combining their architectural knowledge with AI-powered insights.</p><p>Through comprehensive around-the-clock monitoring and AI-powered automation, this tier strengthens your mission-critical operations with proactive risk identification and contextual guidance. When critical incidents occur, you receive 5-minute response times with technical recommendations provided by Support engineers who understand your workloads. The team conducts systematic application reviews, helps validate operational readiness, and supports business-critical events, which means you can focus on innovation while maintaining the highest levels of operational excellence.</p><p><strong>Transforming your cloud operations</strong><br />AWS Support is evolving to help you build, operate, and optimize your cloud infrastructure more effectively. We maintain context of your account’s support history and previous cases, configuration, and previous cases, so our AI-powered capabilities and AWS experts can deliver more relevant and effective solutions tailored to your specific environment.</p><p>Support plan capabilities will continuously evolve to add comprehensive visibility into your infrastructure, delivering actionable insights across performance, security, and cost dimensions with clear evaluation of business impact and cost benefits. This combination of AI-powered tools and AWS expertise represents a fundamental shift from reactive to proactive operations, helping you prevent issues before they impact your business.</p><p>Subscribers of AWS Developer Support, AWS Business Support (classic), and AWS Enterprise On-Ramp Support plans can continue to receive their current level of support through January 1, 2027. You can transition to one of the new and enhanced plans at any time before then by visiting the AWS Management Console or by reaching out to your AWS account team. Customers subscribed to AWS Enterprise Support can begin using the new features of this plan at any time.</p><p><strong>Things to know<br /></strong> Business Support+, Enterprise Support, and Unified Operations are available in all commercial AWS Regions. Existing customers can continue their current plans or explore the new offerings for enhanced performance and efficiency.</p><p>Business Support+ starts at $29 per month, a 71% savings over the previous Business Support monthly minimum. Enterprise Support starts at $5,000 per month, a 67% savings over the previous Enterprise Support minimum price. Unified Operations, designed for organizations with mission-critical workloads and including a designated team of AWS experts, starts at $50,000 a month. All new Support plans use pricing tiers, which rewards higher usage with lower marginal prices for Support.</p><p>For critical cases, AWS Support provides different target response times across the plans. Business Support+ offers a 30-minute response time, Enterprise Support responds within 15 minutes, and Unified Operations Support delivers the fastest response time at 5 minutes.</p><p>To learn more about AWS Support plans and features, visit the <a href="https://aws.amazon.com/premiumsupport?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">AWS Support page</a> or sign in to the <a href="https://console.aws.amazon.com?trk=ac97e39c-d115-4d4a-b3fe-c695e0c9a7ee&amp;sc_channel=el">AWS Management Console</a>.</p><p>For hands-on guidance with AWS Support features, schedule a consultation with your account team.</p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="2a8d7168-c5f9-4e0a-9126-c39396c66d86" data-title="New and enhanced AWS Support plans add AI capabilities to expert guidance" data-url="https://aws.amazon.com/blogs/aws/new-and-enhanced-aws-support-plans-add-ai-capabilities-to-expert-guidance/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/new-and-enhanced-aws-support-plans-add-ai-capabilities-to-expert-guidance/"/>
    <updated>2025-12-02T17:07:00+01:00</updated>
  </entry>
  <entry>
    <id>https://aws.amazon.com/blogs/aws/amazon-opensearch-service-improves-vector-database-performance-and-cost-with-gpu-acceleration-and-auto-optimization/</id>
    <title><![CDATA[Amazon OpenSearch Service improves vector database performance and cost with GPU acceleration and auto-optimization]]></title>
    <summary><![CDATA[<section class="blog-post-content lb-rtxt"><table><tbody><tr><td>
<p></p></td></tr></tbody>


</table><p>Today we’re announcing serverless GPU acceleration and auto-optimization for vector index in <a href="https://aws.amazon.com/opensearch-service/">Amazon OpenSearch Service</a> that helps you build large-scale vector databases faster with lower costs and automatically optimize vector indexes for optimal trade-offs between search quality, speed, and cost.</p><p>Here are the new capabilities introduced today:</p><ul><li><strong>GPU acceleration</strong> – You can build vector databases up to 10 times faster at a quarter of the indexing cost when compared to non-GPU acceleration, and you can create billion-scale vector databases in under an hour. With significant gains in cost saving and speed, you get an advantage in time-to-market, innovation velocity, and adoption of vector search at scale.</li>
<li><strong>Auto-optimization</strong> – You can find the best balance between search latency, quality, and memory requirements for your vector field without needing vector expertise. This optimization helps you achieve better cost-savings and recall rates when compared to default index configurations, while manual index tuning can take weeks to complete.</li>
</ul><p data-pm-slice="1 1 []">You can use these capabilities to build vector databases faster and more cost-effectively on OpenSearch Service. You can use them to power generative AI applications, search product catalogs and knowledge bases, and more. You can enable GPU acceleration and auto-optimization when you create a new OpenSearch domain or collection, as well as update an existing domain or collection.</p><p>Let’s go through how it works!</p><p><strong class="c6">GPU acceleration for vector index</strong><br />When you enable GPU acceleration on your OpenSearch Service domain or Serverless collection, OpenSearch Service automatically detects opportunities to accelerate your vector indexing workloads. This acceleration helps build the vector data structures in your OpenSearch Service domain or Serverless collection.</p><p>You don’t need to provision the GPU instances, manage their usage or pay for idle time. OpenSearch Service securely isolates your accelerated workloads to your domain’s or collection’s <a href="https://aws.amazon.com/vpc">Amazon Virtual Private Cloud (Amazon VPC)</a> within your account. You pay only for useful processing through the OpenSearch Units (OCU) – Vector Acceleration pricing.</p><p>To enable GPU acceleration, go to the <a href="https://console.aws.amazon.com/aos/home">OpenSearch Service console</a> and choose <strong>Enable GPU Acceleration</strong> in the <strong>Advanced features</strong> section when you create or update your OpenSearch Service domain or Serverless collection.</p><p><img class="aligncenter size-full wp-image-100952 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/14/2025-opensearch-gpu-accel-auto-tune-1-gpu-setting.jpg" alt="" width="2238" height="960" /></p><p>You can use the following <a href="https://aws.amazon.com/cli">AWS Command Line Interface (AWS CLI)</a> command to enable GPU acceleration for an existing OpenSearch Service domain.</p><pre class="lang-bash">$ aws opensearch update-domain-config \
    --domain-name my-domain \
    --aiml-options '{"ServerlessVectorAcceleration": {"Enabled": true}}'
</pre><p>You can create a vector index optimized for GPU processing. This example index stores 768-dimensional vectors for text embeddings by enabling <code>index.knn.remote_index_build.enabled</code>.</p><pre class="lang-json">PUT my-vector-index
{
    "settings": {
        "index.knn": true,
        "index.knn.remote_index_build.enabled": true
    },
    "mappings": {
        "properties": {
        "vector_field": {
        "type": "knn_vector",
        "dimension": 768,
      },
      "text": {
        "type": "text"
      }
    }
  }
}</pre><p>Now you can add vector data and optimize your index using standard OpenSearch Service operations using the bulk API. The GPU acceleration is automatically applied to indexing and force-merge operations.</p><pre class="lang-json">POST my-vector-index/_bulk
{"index": {"_id": "1"}}
{"vector_field": [0.1, 0.2, 0.3, ...], "text": "Sample document 1"}
{"index": {"_id": "2"}}
{"vector_field": [0.4, 0.5, 0.6, ...], "text": "Sample document 2"}</pre><p>We ran index build benchmarks and observed speed gains from GPU acceleration ranging between 6.4 to 13.8 times. Stay tuned for more benchmarks and further details in upcoming posts.</p><p><img class="aligncenter size-full wp-image-101751 c8" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/24/2025-opensearchservice-gpu-acceralation-benchmark.png" alt="" width="1000" height="600" /></p><p>To learn more, visit <a href="https://docs.aws.amazon.com/opensearch-service/latest/developerguide/gpu-acceleration-vector-index.html">GPU acceleration for vector indexing</a> in the Amazon OpenSearch Service Developer Guide.</p><p><strong class="c6">Auto-optimizing vector databases</strong><br />You can use the new vector ingestion feature to ingest documents from <a href="https://aws.amazon.com/s3">Amazon Simple Storage Service (Amazon S3)</a>, generate vector embeddings, optimize indexes automatically, and build large-scale vector indexes in minutes. During the ingestion, auto-optimization generates recommendations based on your vector fields and indexes of your OpenSearch Service domain or Serverless collection. You can choose one of these recommendations to quickly ingest and index your vector dataset instead of manually configuring these mappings.</p><p>To get started, choose <strong>Vector ingestion</strong> under the <strong>Ingestion</strong> menu in the left navigation pane of <a href="https://console.aws.amazon.com/aos/home">OpenSearch Service console</a>.</p><p><img class="aligncenter size-full wp-image-101470 c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/20/2025-opensearch-service-auto-optimize-1.png" alt="" width="2342" height="1286" /></p><p>You can create a new vector ingestion job with the following steps:</p><ul><li><strong>Prepare dataset</strong> – Prepare OpenSearch Service parquet documents in an S3 bucket and choose a domain or collection for your destination.</li>
<li><strong>Configure index and automate optimizations</strong> – Auto-optimize your vector fields or manually configure them.</li>
<li><strong>Ingest and accelerate indexing</strong> – Use OpenSearch ingestion pipelines to load data from Amazon S3 into OpenSearch Service. Build large vector indexes up to 10 times faster at a quarter of the cost.</li>
</ul><p>In <strong>Step 2</strong>, configure your vector index with auto-optimize vector field. Auto-optimize is currently limited to one vector field. Further index mappings can be input after the auto-optimization job has completed.</p><p><img class="aligncenter wp-image-101471 size-full c7" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/11/20/2025-opensearch-service-auto-optimize-3.png" alt="" width="2266" height="1679" /></p><p>Your vector field optimization settings depend on your use case. For example, if you need high search quality (recall rate) and don’t need faster responses, then choose <strong>Modest</strong> for the <strong>Latency requirements (p90)</strong> and more than or equal to <strong>0.9</strong> for the <strong>Acceptable search quality (recall)</strong>. When you create a job, it starts to ingest vector data and auto-optimize vector index. The processing time depends on the vector dimensionality.</p><p>To learn more, visit <a href="https://docs.aws.amazon.com/opensearch-service/latest/developerguide/serverless-auto-optimize.html">Auto-optimize vector index</a> in the OpenSearch Service Developer Guide.</p><p><strong class="c6">Now available</strong><br />GPU acceleration in Amazon OpenSearch Service is now available in the US East (N. Virginia), US West (Oregon), Asia Pacific (Sydney), Asia Pacific (Tokyo), and Europe (Ireland) Regions. Auto-optimization in OpenSearch Service is now available in the US East (Ohio), US East (N. Virginia), US West (Oregon), Asia Pacific (Mumbai), Asia Pacific (Singapore), Asia Paciﬁc (Sydney), Asia Pacific (Tokyo), Europe (Frankfurt), and Europe (Ireland) Regions.</p><p>OpenSearch Service separately charges for used OCU – Vector Acceleration only to index your vector databases. For more information, visit<a href="https://aws.amazon.com/opensearch-service/pricing/">OpenSearch Service pricing page</a>.</p><p>Give it a try and send feedback to the <a href="https://repost.aws/tags/TA6VFzFFY6QQa_KlHRKR-WsA/amazon-opensearch-service">AWS re:Post for Amazon OpenSearch Service</a> or through your usual AWS Support contacts.</p><p>— <a href="https://linkedin.com/in/channyun">Channy</a></p></section><aside class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="dcdf7d1c-b771-4c62-84ea-ed35df912bc1" data-title="Amazon OpenSearch Service improves vector database performance and cost with GPU acceleration and auto-optimization" data-url="https://aws.amazon.com/blogs/aws/amazon-opensearch-service-improves-vector-database-performance-and-cost-with-gpu-acceleration-and-auto-optimization/"><p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div>
</aside>]]></summary>
    <link href="https://aws.amazon.com/blogs/aws/amazon-opensearch-service-improves-vector-database-performance-and-cost-with-gpu-acceleration-and-auto-optimization/"/>
    <updated>2025-12-02T17:06:00+01:00</updated>
  </entry>
</feed>
