// news
News
The latest news, updates and insights from the AWS ecosystem — written by cloud builders, for cloud builders.
ACM ACME Migration Is an Operations Project
Moving existing ACME clients to AWS Certificate Manager requires renewal telemetry, quota planning, hybrid connectivity, and incident drills before certificate lifetimes shrink further.
Agent Authorization Needs to Understand Time and Sequence
Amazon Bedrock AgentCore temporal policies extend authorization beyond identity so agent actions can be checked against workflow history, freshness, approvals, and cumulative limits.
Autonomous Incident Operations Need Boundaries
The AWS DevOps Agent and ServiceNow integration is most useful when tool permissions, approval paths, evidence, and rollback limits are explicit.
Backup Value Is Measured by How Quickly You Can Inspect and Recover
Amazon S3 Access Points for AWS Backup recovery points provide read-only access for investigation, targeted recovery, and validation without restoring an entire backup first.
Beyond the SDK Demo: Building Production-Ready .NET Agents with AgentCore
Moving a .NET AI agent from an SDK sample to Amazon Bedrock AgentCore means making deliberate choices about streaming, sessions, testing, deployment, and portability.
Cross-Account ECS Telemetry Needs a Platform Boundary
A centralized AWS Distro for OpenTelemetry gateway can reduce per-task overhead and close observability gaps across multi-account ECS environments, including Windows .NET workloads.
On-Premises Syslog Becomes Useful Evidence When Hybrid Operations Can Trust It
Managed syslog ingestion and CloudWatch Log Alarms can connect on-premises network events to AWS DevOps Agent investigations, but delivery and normalization need to be proven first.
Persistent Compute Changes the Bedrock AgentCore Boundary
Amazon Bedrock AgentCore runtime instances bring persistent sessions and shared compute to agent workloads, changing the trade-off between stateless scale and durable execution.
Portable Agent Plugins Need Strong Contracts, Not Just a Shared Folder
The Agent Plugins standard can reduce repeated packaging work, but portability depends on explicit contracts for permissions, versions, lifecycle, and observability.
Real-Time Voice AI Is a Session Coordination Problem
A serverless voice AI pattern with Amazon Bedrock AgentCore and AppSync Events shows that audio transport, liveness, session state, and observability matter as much as model latency.
Response Streaming for .NET on Lambda Changes Perceived Latency
Response streaming for .NET on AWS Lambda can deliver tokens and large responses earlier, but buffering, headers, timeouts, and disconnects become part of the API contract.
Scaling Lakehouse Authorization Without Role Explosion
Tag-based authorization with Amazon Lake Formation can scale enterprise lakehouse governance without turning every dataset and user into a new IAM role.
EC2 capacity planning gets better when reservations become queryable
Amazon EC2 Capacity Manager data exports to S3 and Athena help teams analyze long-term capacity reservation usage across accounts and Regions.
Agent UIs need protocols, not only chat boxes
AG-UI with Amazon Bedrock AgentCore shows how agent frontends can support generative UI, shared state, and human-in-the-loop workflows without coupling every frontend to one agent framework.
Autonomous incident resolution needs boundaries before autonomy
AWS DevOps Agent with Datadog MCP Server points toward AI-assisted incident response, but production teams need permissions, approvals, rollback, and observability boundaries before autonomous fixes.
AI-powered resilience testing is useful when it discovers real dependencies
An AWS resilience framework using Resilience Hub, Fault Injection Service, Systems Manager, and Bedrock AgentCore shows how teams can move from assumed reliability to continuous validation.
Secure multi-tenant RAG needs authorization at retrieval time
AWS shows how Amazon Bedrock Knowledge Bases and Verified Permissions can enforce runtime document access for intra-tenant RAG applications without duplicating every knowledge base.
Landing zone automation still needs human approval and operating model clarity
AWS Transform landing zone automation can compress foundation setup, but builders still need clear account strategy, guardrails, cost ownership, and approval workflows.
AI-driven migration orchestration is useful when it reduces handoff friction
AWS guidance on AI-driven large-scale server migration shows how Transform, Cloud Migration Factory, MGN, AgentCore, and Kiro can reduce coordination overhead across migration waves.
AWS Continuum points to security workflows that reason before they remediate
AWS Continuum for code vulnerabilities previews a security model that prioritizes, validates, and recommends remediation with context before moving toward automation.
Aurora DSQL is interesting for auth because consistency is product behavior
Amazon Aurora DSQL can support authentication and session workloads with strong consistency, serverless scaling, and IAM-based database access, but schema and retry design still matter.
Bedrock resilience patterns make LLM availability an architecture concern
AWS guidance on Amazon Bedrock and LLM gateway resilience shows why production generative AI systems need quota isolation, cross-Region routing, and multi-model fallback design.
Voice analytics needs durable orchestration more than another demo pipeline
AWS Lambda durable functions and Amazon Bedrock can simplify voice analytics workflows, especially when transcription, summarization, sentiment, and storage need reliable multi-step orchestration.
Claude Sonnet 5 on Bedrock should trigger model selection reviews
Claude Sonnet 5 availability on Amazon Bedrock gives builders another production model option, but adoption should be driven by evaluation, cost, latency, and agent reliability.
Valkey 9.1 on ElastiCache is about cache efficiency and isolation
Valkey 9.1 for Amazon ElastiCache improves throughput, memory efficiency, access control, commands, and observability for high-scale cache workloads.
Graviton5 C9g makes CPU compute modernization worth another look
Amazon EC2 C9g and C9gd instances powered by AWS Graviton5 can improve compute price-performance, but teams need compatibility testing and workload-specific benchmarks.
EC2 G7 instances are a reminder to size GPU workloads by bottleneck
Amazon EC2 G7 instances bring NVIDIA RTX PRO 4500 Blackwell GPUs to AWS, but builders should evaluate them by memory, networking, storage, and software fit instead of GPU generation alone.
ACM ACME support turns certificate automation into a governance problem
AWS Certificate Manager now supports ACME for public certificates, giving teams a standard automation path while keeping domain control, audit, and policy centralized.
Bedrock managed entitlements make model access a platform control
Amazon Bedrock managed entitlements let organizations subscribe to marketplace models centrally and distribute access across accounts without broad AWS Marketplace permissions.
CloudFormation Express mode is about feedback loops, not just faster deploys
AWS CloudFormation Express mode shortens infrastructure iteration by completing after configuration is applied, but builders need clear guardrails for when stabilization still matters.
CloudFormation pre-deployment validation makes IaC failures cheaper
AWS CloudFormation and CDK pre-deployment validation now runs on stack operations, helping builders catch quota, Config, and ECR issues before failed deployments waste time.
Replicating S3 bucket configuration needs workflow discipline
AWS shows how Step Functions can replicate S3 bucket configuration across Regions, but builders should decide where automation ends and infrastructure as code should remain the source of truth.
Faster S3 access log queries make storage security more usable
AWS shows how CloudWatch and S3 Tables can make S3 access logs easier to query, which helps builders turn storage audit data into operational and security signals.
Lambda durable functions fit the messy middle of agent workflows
AWS Lambda durable functions give multi-agent and human-in-the-loop workflows checkpointing, replay, callbacks, and polling without forcing every team to assemble custom orchestration infrastructure.
Redshift multi-warehouse improvements reduce the analytics freshness trade-off
Amazon Redshift multi-warehouse enhancements improve materialized views, remote DDL, and concurrency scaling so analytics teams can separate ingestion and consumption more cleanly.
Secure ML environments need productivity and exfiltration controls together
An AWS architecture using SageMaker AI, VPC endpoints, DNS controls, and WorkSpaces Secure Browser shows how ML teams can protect sensitive data without returning to expensive air-gapped workflows.
S3 Storage Lens groups make storage cost conversations less generic
Amazon S3 Storage Lens groups help teams inspect storage by workload-specific criteria, making cost, lifecycle, and data hygiene work more actionable.
Running pgvector on Aurora is a production operations decision
AWS guidance on pgvector in Amazon Aurora PostgreSQL highlights that vector search is not only a model feature; it needs indexing, memory, partitioning, and observability discipline.
AWS Transform makes migration assessments more conversational, but data quality still wins
AWS Transform assessments use agentic AI to turn migration planning into an interactive business-case workflow, but builders still need inventory discipline and assumption control.
OpenSearch Serverless next generation changes the economics of tenant isolation
Amazon OpenSearch Serverless next-generation architecture makes collection-per-tenant search more practical with scale-to-zero compute and regional endpoint routing.
Restricting AWS Console access by network is a useful perimeter, not a complete identity strategy
AWS sign-in resource-based policies and resource control policies can restrict Management Console access to expected networks, adding a practical layer to data perimeter designs.
S3 Files makes Lambda file workflows simpler, but not automatically better
Amazon S3 Files lets Lambda functions work with S3-backed file paths instead of download-process-upload code, which can simplify workloads if teams understand consistency, throughput, and VPC implications.
EKS Auto Mode improvements show why managed Kubernetes is becoming operational engineering
Recent EKS Auto Mode runtime, compute, storage, and networking improvements reduce Kubernetes operational friction, but teams still need workload-level SLOs and migration discipline.
EKS control plane egress through your VPC closes a real private-cluster gap
Amazon EKS customer-routed control plane egress lets Kubernetes API server traffic use customer VPC routing, security controls, and private endpoints for webhooks and OIDC dependencies.
Lambda MicroVMs make isolated sandboxes a serverless design choice
AWS Lambda MicroVMs give builders a new option for running user-generated and AI-generated code with VM-level isolation, fast resume, and controlled lifecycle state.
Lambda runtime upgrades need campaigns, not reminders
AWS Transform custom can help teams upgrade Lambda runtimes at scale, but the durable improvement is treating runtime changes as governed modernization campaigns.
Before downsizing EC2, simulate the EBS burst budget
AWS shows how to simulate EBS burst credits before downsizing EC2 instances, a practical cost-optimization step that avoids turning compute savings into storage throttling.