< ciso
brief />
Tag Banner

All news with #aws s3 tag

167 articles

CloudFront OAC Adds Native Support for S3 MRAP

🔒 Starting today, CloudFront can use Origin Access Control (OAC) to restrict access to Amazon S3 Multi-Region Access Points (MRAP), allowing only designated CloudFront distributions to reach MRAP origins. This native integration removes the need for customers to compute and forward SigV4a Authorization headers via custom Lambda@Edge functions. CloudFront now signs requests to S3 MRAP origins, improving cache-miss fill performance from the nearest replicated region and enforcing OAC-secured access. The feature is available globally except in the CloudFront China region and can be enabled via Console, SDK, CLI, or CloudFormation with no additional fees.
read more →

Redshift adds long-term system table retention

📌 Amazon Redshift now supports long-term retention of system table data through native integration with Amazon S3 Tables in Apache Iceberg format. This eliminates the prior 7-day limit and removes the need for custom ETL pipelines by automatically writing, partitioning, compacting, and retaining system table data in S3. The stored data can be queried via Redshift, Athena, or any Iceberg-compatible engine for cross-warehouse observability and auditing.
read more →

Amazon S3 Metadata and Annotations Reach GovCloud

🔎 Amazon S3 Metadata and annotations are now available in AWS GovCloud (US-East) and AWS GovCloud (US-West), enabling faster discovery, understanding, and enrichment of S3 data. S3 Metadata captures system-defined details like object size and source and stores them in Amazon S3 Tables for near real-time tabular queries. Annotations let you attach rich business context in JSON, XML, or YAML (up to 1 GB per object) that travels with the object and follows durability and consistency properties.
read more →

Securing Amazon S3: Identify and Remediate Over‑Permissions

🔒 This post explains how to detect and remediate over‑permissioned Amazon S3 buckets across single‑ or multi‑account AWS environments. It outlines a five‑phase workflow—setup, detection, remediation, continuous monitoring, and cleanup—while recommending AWS Config, Security Hub, EventBridge, IAM Access Analyzer, and Lambda‑based scanning scripts. The guidance focuses on methodology and customization for security engineers, cloud architects, and DevOps teams.
read more →

AWS Backup adds direct S3 access to backups

🛈 AWS Backup for Amazon S3 now supports creating S3 Access Points to provide immediate read-only access to backup data using standard S3 APIs without performing a restore. You can create an access point for an S3 recovery point and read data with operations like GetObject, HeadObject, and ListObjectsV2. Access points apply to snapshot and continuous recovery points, work with vaults (including logically air-gapped vaults), and support shared recovery points across accounts. While an access point exists the recovery point is protected from deletion. This capability is available in select AWS Regions and can be managed via the AWS Backup console, API, or CLI.
read more →

AWS Glue Data Catalog adds S3 Tables export

🔔 Today AWS Glue Data Catalog preview adds two features: exporting catalog metadata to S3 Tables and enabling semantic search for catalogs encrypted with customer managed AWS KMS keys. Exported metadata — including glossary terms, custom attachments, and descriptions — is written to the managed aws-catalog S3 table bucket in Apache Iceberg format, enabling SQL queries, auditing, and time travel in engines like Amazon Athena and third-party tools. These capabilities are available in US East (N. Virginia), US East (Ohio), US West (Oregon), and Europe (Ireland); S3 Tables usage follows S3 pricing.
read more →

Amazon S3 Vectors launches in Germany sovereign cloud

🟦 Amazon S3 Vectors is now available in the AWS European Sovereign Cloud (Germany) Region. Amazon S3 Vectors is purpose-built vector storage for AI agents, inference, Retrieval Augmented Generation (RAG), and semantic search at billion-vector scale. It offers the elasticity, durability, and availability of Amazon S3 with dedicated APIs to store, access, and query vectors without provisioning infrastructure.
read more →

MSK Express adds native delivery to Amazon S3

🚀 Amazon MSK Express brokers now deliver Apache Kafka data directly to Amazon S3 general purpose buckets, providing a fully managed, auto-scaling capability for high-throughput data delivery. This feature handles scaling, retries, and backpressure for mission-critical workloads and can reduce ingestion and delivery costs by up to 60% versus self-managed connectors. MSK Express supports throughput up to 10 GB/s to S3 and eliminates the need to provision additional broker egress throughput, simplifying operations and lowering infrastructure costs.
read more →

Amazon S3 Tables Adds Apache Iceberg V3 Variant

🟦 Amazon S3 Tables now support the Variant data type from the Apache Iceberg Version 3 specification, enabling direct writing of semi-structured data like JSON without a fixed schema. Variant shards data into hidden columns and generates Parquet column statistics to optimize queries through techniques such as file pruning. S3 Tables also handle ongoing maintenance including compaction for Variant columns and the feature is available in multiple global AWS Regions.
read more →

Amazon RDS for SQL Server adds SQL Server 2025

🛠️ Amazon RDS for SQL Server now supports Microsoft SQL Server 2025 across Enterprise, Standard, and Developer editions. SQL Server 2025 integrates AI into the database engine, enabling T-SQL to call external REST endpoints and work with AWS services like Amazon Bedrock, Amazon SageMaker, Amazon S3, and AWS Lambda. Standard Edition capacity and features have been expanded, and a new free Developer edition is available for testing.
read more →

AWS launches Athens Local Zone for Greece

📣 The Athens Local Zone by AWS is now generally available, offering localized infrastructure in Greece to support data residency and low-latency use cases. It provides EC2 C7i/M7i/R7i instances, Amazon S3 (including One Zone-IA), Amazon EBS with Local Snapshots and multiple volume types, ECS, EKS, VPC, Direct Connect, and Application Load Balancer. Customers can enable the zone (eu-central-1-ath-1a) via AWS Global View or API and use standard AWS pricing models and APIs with no minimum commitment.
read more →

Amazon S3 Event Notifications include system tags

🔔 Amazon S3 Event Notifications now include system-generated tags in events delivered to destinations such as Amazon EventBridge, Amazon SQS, Amazon SNS, and AWS Lambda. These tags are metadata labels applied to buckets by AWS services and can be used to filter events across thousands of buckets with a single EventBridge rule rather than listing each bucket individually. Enable S3 Event Notifications via the AWS Management Console, SDK, or CLI; tags already applied by services like AWS CloudFormation are automatically included in new notifications. This capability is available at no additional cost in all AWS Regions and requires no configuration changes.
read more →

S3 removes 30‑day minimum for IA transitions

🔔 You can now transition objects to S3 Standard-Infrequent Access (Standard-IA) and S3 One Zone-Infrequent Access (One Zone-IA) immediately after creation, removing the previous 30-day minimum in S3 Standard. These classes provide up to 40% lower storage costs than S3 Standard with millisecond access, suitable for backups, log analytics, and compliance data that becomes cold quickly. Configure new S3 Lifecycle rules with 0-day transitions via the S3 console, AWS CLI, or SDKs, available in all Regions where the storage classes are offered.
read more →

Lambda supports self-managed S3 code storage

🛠️ AWS Lambda now supports referencing code directly from your own Amazon S3 buckets using self-managed code storage, removing the prior requirement for Lambda to copy deployment packages into Lambda-managed storage. This change eliminates the previous 75GB default storage constraint (now raised to 300GB) and can reduce function activation time by avoiding the copy step. No additional Lambda charges apply; you pay standard S3 storage and any applicable data transfer fees.
read more →

SageMaker Studio Workflows Adds 19 New Operators

🔔 Amazon SageMaker Unified Studio Workflows now includes 19 new operators for Amazon Bedrock, Amazon S3 Tables, S3 Vectors, AWS Glue Data Catalog, and Amazon MWAA Serverless. These operators let users add tasks via the visual workflow creator to orchestrate services without writing custom integration code. The capabilities include managing Bedrock guardrails, provisioning and deleting S3 Tables and S3 Vectors, managing Glue Data Catalog assets, and triggering MWAA Serverless runs. This feature is available in all Regions where SageMaker Unified Studio is offered.
read more →

Amazon S3 Vectors Now Available in GovCloud

🔔 Amazon S3 Vectors is now available in AWS GovCloud (US-East) and AWS GovCloud (US-West). The service offers purpose-built vector storage for AI agents, inference, Retrieval Augmented Generation (RAG), and semantic search at billion-vector scale. S3 Vectors provides the elasticity, durability, and availability of Amazon S3 with dedicated APIs to store, access, and query vectors without provisioning infrastructure. Check AWS Regions and endpoints for the full availability list.
read more →

S3 Express One Zone arrives in Frankfurt region

🚀 Amazon S3 Express One Zone is now available in the AWS Europe (Frankfurt) Region. The storage class provides high-performance, single-Availability Zone storage designed for consistent single-digit millisecond access for frequently accessed and latency-sensitive workloads. S3 Express One Zone offers up to 10x faster access and request costs up to 80% lower than S3 Standard, supporting use cases like machine learning training, interactive analytics, and key-value caching in AI search engines.
read more →

Amazon S3 delivers server access logs to CloudWatch

📣 Amazon S3 now supports delivering server access logs to Amazon CloudWatch Logs, enabling instant querying, alarms, cross-account and cross-Region aggregation, and AWS KMS encryption for access log data. You can also mirror logs to Amazon S3 Tables in Apache Iceberg format at no additional storage cost. These delivery options complement existing free delivery to S3 buckets and provide more flexibility for monitoring and analysis.
read more →

AWS Backup boosts Amazon S3 copy performance

🚀 AWS Backup now performs S3 backup copy operations up to 8x faster for buckets with millions of objects and low change rates by using enhanced change tracking. This removes the need to scan all objects in the destination account or Region, reducing copy time across accounts and AWS Regions. The improvement records object events as they occur and applies automatically to new cross-account and cross-Region copy jobs at no additional cost in supported Regions.
read more →

AWS Announces Hanoi Local Zone with Local Storage

📢 AWS today announced general availability of a new Local Zone in Hanoi, Vietnam, bringing infrastructure closer to end users. The Hanoi Local Zone supports Amazon EC2 with C7i, M7i, and R7i instances, Amazon S3 including One Zone-IA, and Amazon EBS with Local Snapshots and multiple volume types. Customers can enable the zone (ap-southeast-1-han-1a) via AWS Global View or the ModifyAvailabilityZoneGroup API.
read more →