< ciso
brief />
Tag Banner

All news with #aws tag

2926 articles · page 44 of 147

Fine-grained B2C Access Control with Cognito

🔐 This article demonstrates how to implement enterprise-grade authentication and authorization for a Streamlit sample application using Amazon Cognito for identity and Amazon Verified Permissions with Cedar policies for fine-grained access control. It outlines a layered architecture that separates identity verification, authorization evaluation, application logic, and enforcement to reduce blast radius. The post explains Cedar policy anatomy and common patterns—ownership, role-based, hierarchical, and emergency access—plus evaluation precedence where forbid policies take priority. Practical guidance covers required tools, provisioning steps, policy design tips, and testing recommendations to help developers scale secure applications.
read more →

AWS adds C8in instances in Asia Pacific and Europe

🚀 Amazon EC2 C8in instances are now available in additional AWS regions including Asia Pacific (Sydney, Singapore, Malaysia) and Europe (Frankfurt). These instances use custom sixth-generation Intel Xeon Scalable processors exclusive to AWS and the latest sixth-generation AWS Nitro cards, offering up to 43% higher performance versus C6in. C8in supports sizes up to 384 vCPUs and 600 Gbps networking, targeting network-intensive distributed compute and large-scale analytics. They are offered via Savings Plans, On-Demand, and Spot.
read more →

AWS MCP Server Adds Cross-Account Cross-Role Access

🚀 Today AWS introduced cross-account and cross-role access for the AWS Model Context Protocol (MCP) Server, part of the Agent Toolkit for AWS. This update lets AI coding agents such as Kiro, Claude Code, or Codex operate across multiple AWS accounts and IAM roles within a single session without restarts. Previously, changing accounts required stopping the session, updating local credentials, and restarting the MCP server; now agents can specify a profile per command. The feature is intended to streamline multi-account workflows and reduce context-switch friction. The MCP Server is available in US East (N. Virginia) and Europe (Frankfurt).
read more →

AWS CLI adds interactive install for Agent Toolkit

🔧 Today AWS added an interactive wizard to the AWS Command Line Interface that installs and manages the Agent Toolkit for AWS across multiple coding agents. The toolkit provides an MCP server, 40+ agent skills, and plugins to give agents guidance and guardrails. Users can run aws configure agent-toolkit to detect installed agents, choose skills per agent, and search, install, or update skills via the CLI. The MCP Server is available in US East (N. Virginia) and Europe (Frankfurt).
read more →

Amazon Cognito modernizes infrastructure for scale

🔒 Amazon Cognito migrated hundreds of millions of user profiles to a next-generation storage infrastructure to enable higher throughput, customer-managed encryption keys, and multi-Region replication while preserving backward compatibility and zero downtime. The architecture focuses on identity-first design, independent datasets, and reversible changes to support rapid feature iteration. Migration used shadow mode, dual-write, data backfill, anti-entropy validation, and incremental rollouts with rollback to ensure data integrity and preserve application behavior.
read more →

Amazon Cognito adds multi-Region replication support

🔁 Amazon Cognito now supports multi-Region replication, allowing near real-time synchronization of user and machine identity data — including credentials, user pool configurations, and federation setups — to a standby user pool in a designated secondary Region. This feature improves authentication resilience by providing a replica that can accept traffic during regional disruptions, preserving signed-in sessions and enabling users to authenticate with existing credentials. Multi-Region replication is offered as an add-on for user pools in the Essentials or Plus tiers and is available across multiple AWS Regions. Administrators can configure replication through the AWS Console, CLI, or SDKs; pricing and implementation guidance are provided in AWS documentation.
read more →

AWS databases now available via Vercel in more Regions

📣 Amazon Aurora PostgreSQL, Amazon Aurora DSQL, and Amazon DynamoDB serverless are now accessible through the Vercel Marketplace and v0 by Vercel in additional AWS Regions. Vercel’s flow generates spec-driven apps from natural language, provisions databases, and can create new AWS accounts with access to all three databases plus $100 USD in credits for six months. You can manage plans and view usage from the Vercel dashboard.
read more →

AWS Deadline Cloud adds plugin sync for workers

🔔 AWS Deadline Cloud now automates delivery of plugins to cloud workers for service-managed fleets. Previously requiring custom scripts or manual setup per DCC application and version, you can now upload plugin files to a specific path in your queue's job attachments Amazon S3 bucket and Deadline Cloud will sync them to workers at job start. This feature is GA for Blender and Autodesk Maya and is available in all Regions where the service is offered.
read more →

Customize Federated Sign‑In with Cognito Lambda Trigger

🔐 This post introduces the new inbound federation Lambda trigger for Amazon Cognito, which intercepts external IdP responses so you can transform, filter, and enrich attributes before a user profile is created. It explains how the trigger receives SAML and OIDC attributes, and outlines common B2B and B2C problems such as oversized group lists and duplicate accounts from different social sign-ins. The article shows how to normalize group attributes, filter excessive data, and implement automated account linking to maintain a single primary identity. It also covers performance and error-handling best practices for Lambda functions.
read more →

Amazon MQ for RabbitMQ in EU Sovereign Cloud

🔔 Amazon MQ for RabbitMQ is now available in the AWS European Sovereign Cloud (Germany) Region, an independent cloud located fully within the EU to help regulated and public sector customers meet sovereignty requirements. Amazon MQ is a managed message broker service that handles provisioning, patching, and maintenance so you can focus on applications. This launch supports RabbitMQ engine 4.2 and Graviton3-based m7g instance types from m7g.medium to m7g.16xlarge for high-performance messaging.
read more →

Amazon Bedrock console redesigned for model workflows

🛠️ The Amazon Bedrock console has been redesigned to match real-world model development workflows: experiment, iterate, and scale. The refreshed UI centers on the bedrock-mantle endpoint and is compatible with the OpenAI Responses API, OpenAI Chat Completions API, and the Anthropic Messages API. Users can browse and compare models, create projects to run evaluations, and get project-aware code snippets prefilled with model ID, region, endpoint URL, and API key references. The new experience is available in all Regions where the bedrock-mantle endpoint is offered.
read more →

AWS IoT Device Management adds MQTT session visibility

🔧 AWS IoT Device Management now surfaces MQTT session data in its connectivity status API, helping teams troubleshoot device connectivity and audit connection patterns across IoT fleets. The update provides session timeout and expiry values and, optionally, socket-level details like source/destination IPs, ports, and client VPC endpoint IDs. Access to socket information is controlled by granular IAM policies. The API keeps connection records indefinitely, exceeding the 30-minute retention of AWS IoT Core's GetConnection API.
read more →

Step Functions adds AgentCore AI reasoning steps

🤖 AWS Step Functions now integrates with the Amazon Bedrock AgentCore managed harness (preview) to add AI agent reasoning steps to workflows. The integration lets you declare agents via configuration, run agents in parallel or sequence, add human approvals, and view execution history with agent inputs, outputs, token usage, and CloudWatch links. You can reuse or create harnesses from Workflow Studio, apply per-invocation overrides, and persist agent context with session IDs. The harness preview and integration are available in select regions and standard Step Functions and Bedrock pricing applies.
read more →

OpenAI GPT-5.4 Now in AWS GovCloud (US‑West)

🛡️ Amazon Bedrock now offers OpenAI GPT‑5.4 in AWS GovCloud (US‑West), enabling government and regulated industry customers to use OpenAI's most capable frontier model with the security and compliance of GovCloud. GPT‑5.4 delivers native computer-use capabilities and advanced reasoning across coding, documents, and multi-step agentic tasks, running on Bedrock's high-performance inference engine. Data remains in-partition and is not used to train models.
read more →

Compute Optimizer adds 32-day lookback for rightsizing

🛠️ AWS Compute Optimizer now supports extending the default 14-day lookback period to 32 days for Amazon EBS volume and Amazon ECS service rightsizing recommendations at no extra cost. The longer lookback captures monthly utilization patterns such as month-end processing to improve optimization decisions for cost and performance. The 32-day option is available for EC2 instance, EC2 Auto Scaling group, RDS database, EBS volume, and ECS service recommendations. You can set the lookback at organization, account, or resource level via the console, AWS SDK, or AWS CLI, and it’s available in all AWS Regions where Compute Optimizer is offered except GovCloud (US) and China.
read more →

ARC Region Switch adds Aurora and Neptune blocks

🔔 Amazon Application Recovery Controller (ARC) Region switch introduces three new execution blocks: Amazon Aurora serverless scaling, Amazon Aurora provisioned scaling, and Amazon Neptune global database failover. These blocks automate database scaling and failover for multi-Region workloads, eliminating manual steps that add recovery time. They support cross-account orchestration so a single plan can coordinate operations across multiple accounts and Regions.
read more →

Keyspaces adds iterator position for CDC streams

🔔 Amazon Keyspaces (for Apache Cassandra) now includes an iterator position in the GetRecords response for CDC streams, indicating whether a consumer is AT_TIP or BEHIND_TIP. This enables consumers to reduce unnecessary polling and lower CDC consumption costs by adjusting polling frequency based on stream position. The feature is available in all Regions where Keyspaces CDC is supported and requires the latest AWS SDK.
read more →

Amazon SageMaker Unified Studio adds 12 languages

🔧 Amazon SageMaker Unified Studio now offers a localized user interface in twelve languages, including Simplified and Traditional Chinese, French, German, Japanese, Korean, Spanish, Portuguese (Brazilian), Italian, Indonesian, Turkish, and American English. Language selection is automatic via the browser or manually set through the profile Language selector, and the choice applies across the entire studio. This localization is available in all AWS Regions where SageMaker Unified Studio is offered and supports both AWS IAM Identity Center-based and IAM-based domains.
read more →

AWS Config Adds Nine New Supported Resource Types

🔔 AWS Config now supports nine additional AWS resource types across Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker. This update expands visibility and governance, allowing you to discover, assess, audit, and remediate a broader set of resources. If you record all resource types, AWS Config will automatically begin tracking these additions, and they are available for use in Config rules and Config aggregators. The newly supported resource types are listed for monitoring in all Regions where the services are available.
read more →

ECS Managed Instances Add Trainium and Inferentia

🚀 Amazon ECS Managed Instances now supports AWS Trainium and AWS Inferentia accelerators, enabling scalable training and inference for generative AI workloads. This fully managed compute option offloads infrastructure operations to AWS while preserving the full capabilities of Amazon EC2. You can select Inferentia2, Trainium1, or Trainium2 when creating a capacity provider and set NEURON_CORE=all to allocate the accelerator per task. Management charges apply in addition to standard EC2 costs.
read more →