AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now reports session token size in API responses, […]
security
Architecting resilient authentication with Amazon Cognito multi-Region replication
Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a core architectural requirement. However, building multi-Region authentication has traditionally required complex custom replication solutions that […]
general
AWS Billing Conductor now supports custom rates and usage tier pricing configurations
AWS Billing Conductor now lets you define custom rate pricing for AWS services, including defining custom usage tiers to configure rates by the desired usage volume. Customers and Partners using AWS Billing Conductor to model commercial agreements with subsidiaries, affiliates, or end customers can now more easily reflect their negotiated pricing on pro forma billing data. Using SKU-scoped pricing rules, you can enter a custom rate and configure usage tier thresholds — instead of marking up or down from the public on-demand rates tied to pre-defined AWS usage tiers. By configuring exact rates and tier breaks directly in a pricing rule, you no longer need to calculate percentage-based markups or markdowns against public on-demand pricing to model your commercial agreements. This gives you precise control over your pro forma billing configuration. Custom rates and custom usage tiers configuration via SKU-scoped pricing rules is available in all commercial AWS Regions, excluding the Amazon Web Services China (Beijing) Region, operated by Sinnet, and the Amazon Web Services China (Ningxia) Region, operated by NWCD. To learn more, visit the AWS Billing Conductor product page, or review the User Guide.
general
Amazon SageMaker AI now supports instance preference lists for training and processing jobs
Today, Amazon SageMaker AI announces instance preference lists for training and processing jobs, making it easier and faster to find compute capacity for your workloads. Many AI training, fine-tuning, and data processing workloads run comparably well on any of several instance types or sizes. However, before now, you had to name only one instance type at the time of job submission and wait for SageMaker to find that specific instance for your job. For high-demand GPUs during peak periods, where wait times can be unpredictable, customers sometimes had to build complex retry logic or concurrently submit multiple jobs with different instance types to find the first available option. Now you can simply provide a prioritized list of the instance types your workload accepts, and SageMaker automatically runs your job on the first available configuration from your preferences. With this solution, your training or processing job will likely start sooner. To use this feature, you specify your instance type and count preferences in priority order when submitting the training or processing job. For example, your list might contain a preference of two instances of ml.g6.48xlarge or four instances of ml.g5.48xlarge. SageMaker works through the list and launches your job on the first configuration where capacity is available. You can also configure the capacity sourcing from on-demand sources or from your reserved SageMaker Flexible Training Plans within the same job submission. This feature simplifies the process of getting compute for your jobs during high-demand periods and reduces the undifferentiated manual retrying you would otherwise do, all within the SageMaker training and processing job APIs you already use. Instance preference lists for SageMaker training and processing jobs is available today in all AWS Regions where SageMaker is available through the SageMaker CLIs, APIs, SDKs and Console UI. To learn more, see our documentation or our launch blog.
release
Analyze your CloudTrail events using natural language in Amazon Q Console
AWS CloudTrail, a service that records API activity across your AWS account for security auditing, compliance, and operational troubleshooting, now integrates with Amazon Q Console to help you investigate your AWS account activity using natural language. You can ask Amazon Q Console questions about your CloudTrail configuration, query your logged events for security investigations, and troubleshoot operational issues without writing queries or manually parsing log files. With this integration, you can ask Amazon Q Console to check whether your CloudTrail trails are properly configured, identify gaps in your logging coverage, and confirm which data event sources you are tracking. You can investigate security concerns by asking who accessed a specific IAM role, what changes were made to your VPC configuration, or whether there were unauthorized access attempts in the past week. For operational troubleshooting, you can ask Amazon Q Console to find who created or deleted specific resources, identify which API calls are generating errors, trace activity from a specific IP address, or determine why your bill spiked. Amazon Q Console can query your CloudTrail trails, associated CloudWatch log groups, and event data stores on your behalf, providing answers grounded in your actual account activity rather than generic documentation. This integration is available in all AWS commercial regions where Amazon Q Console is supported. To get started, open Amazon Q in AWS Management Console and ask questions about your CloudTrail configuration or account activity. For more information, visit the AWS CloudTrail documentation.
security
Optimizing cost and latency with Amazon Bedrock prompt caching
Prompt caching in Amazon Bedrock can cut input token costs by up to 90% when you repeatedly send the same context to foundation models. This post walks through six practical prompt caching scenarios using the Converse API: message content, system prompt, tool definition, mixed TTL, tenant isolation, and LangChain integration.
general
Build an AI-powered product tagging system with Amazon SageMaker serverless model customization
Manually tagging thousands of catalog products is slow and inconsistent. This walkthrough shows how to customize Qwen3-8B with supervised fine-tuning (SFT) and reinforcement learning with verifiable rewards (RLVR) on Amazon SageMaker serverless model customization, then deploy it for asynchronous inference to build a cost-efficient product tagging system.
general
Announcing instance preference lists for Amazon SageMaker AI training jobs
Amazon SageMaker AI now offers instance preference lists for training and processing jobs. Specify an ordered list of up to five instance types, and SageMaker AI automatically launches on the first type with available capacity, eliminating manual retry loops and capacity-watching scripts.
release
Amazon Connect Customer now enables agents to bid on preferred shifts
Amazon Connect Customer now enables agents to bid on preferred shifts, giving them more control over their work schedules. Schedulers first establish agent ranking either by uploading a CSV file or generating a randomized ranking. Connect Customer then uses forecasted demand and shift profiles to generate available shifts and presents them to agents to rank. For example, in a Monday–Friday 6AM–10PM shift profile with 9-hour shifts, required shifts are 6AM–3PM (500 agents), 9AM–6PM (800 agents), and 1PM–10PM (600 agents). Once the bidding window closes, Connect Customer automatically assigns each agent to their highest-ranked available shift while using agent ranking as a tiebreaker. Shift bidding gives agents a structured way to influence their own schedules, while reducing the time schedulers spend on manual shift assignments, improving both agent satisfaction and scheduling efficiency. This feature is available in all AWS Regions where Amazon Connect Customer agent scheduling is available. To learn more about Amazon Connect Customer agent scheduling, click here.
general
Operationalizing least privilege: Automate IAM remediation through your CI/CD pipeline
The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten permissions later. But later rarely comes. Permissions accumulate, AWS Identity and Access […]
general
Abnormal AI: Amazon Bedrock AgentCore for agentic email security at scale
Learn how Abnormal AI deployed Amazon Bedrock AgentCore Code Interpreter as an ephemeral compute scratch pad for the agents behind its real-time email threat detection at billion-message scale, plus the sandbox design decisions and practical lessons for builders deploying Code Interpreter in production.
security
Manage end-user OAuth consent for AI agents with Amazon Bedrock AgentCore
Amazon Bedrock AgentCore Identity now offers a Consent portal, a managed web experience and session binding endpoint for AgentCore Gateway. This post walks through provisioning a portal, configuring GitHub and Slack authorization code grant targets, and the end-user consent flow, and shows how to review activity in AWS CloudTrail.
release
AWS improves regional resiliency for root user sign-in
AWS root user sign-in is now served across US East (N. Virginia), US East (Ohio), and US West (Oregon), with sign-in traffic distributed across all three Regions. This change reduces reliance on US East (N. Virginia) and improves resiliency during service disruptions. AWS automatically routes your root user sign-in to a supported Region without requiring you to select a Region or change how you sign in. This improvement is available now for all AWS accounts. In AWS CloudTrail, ConsoleLogin events for root user sign-ins are recorded in the Region that processed the sign-in request. To maintain full visibility into root user sign-in activity, update your monitoring and alerting to cover US East (N. Virginia), US East (Ohio), and US West (Oregon). To learn more, see the AWS Sign-In documentation and the CloudTrail ConsoleLogin event reference.
update
Validating multi-agent decisions with Step Functions and Bedrock AgentCore
Orchestrating specialized Amazon Bedrock AgentCore agents with AWS Step Functions gives you the reasoning power of generative AI with the guardrails of deterministic validation. Agents propose options, and deterministic code validates them before any action is taken, demonstrated here with an airline rebooking workflow.
general
Resolve Amazon Aurora PostgreSQL lock contention with Database Insights: Part 2
Part 1 showed how row lock contention degrades Amazon Aurora PostgreSQL throughput. In Part 2, use Amazon CloudWatch Database Insights and its Lock Tree to pinpoint blocking sessions, then resolve contention with query termination, timeout parameters, and architectural patterns such as SKIP LOCKED and row splitting that restore throughput.
general
Troubleshooting row lock contention in Amazon Aurora PostgreSQL: Part 1 – Understanding row lock contention in PostgreSQL
Row lock contention can collapse database throughput during a flash sale even when CPU and I/O look healthy. In Part 1 of this series, learn how PostgreSQL row locking works and how to monitor lock contention in Amazon Aurora PostgreSQL and Amazon RDS for PostgreSQL using system views, the pgrowlocks extension, and the log_lock_waits parameter.
general
How Ninth Wave built AI-powered open finance onboarding on Amazon Bedrock
Learn how Ninth Wave built Compass, a multi-agent AI onboarding assistant on Amazon Bedrock AgentCore that validates bank APIs against Financial Data Exchange (FDX) standards, scores compliance, and compresses open finance onboarding from weeks to minutes while meeting SOC 2 and PCI DSS requirements.
general
The generative AI customization spectrum: From prompt engineering to custom models on AWS
Pick the right generative AI customization approach on AWS with an 8-step decision framework, from prompt engineering and RAG to fine-tuning, continued pre-training, and Amazon Nova Forge. Start simple and escalate only when you must.
general
Automate replenishment with MMF, Databricks Genie, and Amazon Quick
Foundation models made catalog-wide demand forecasting easy; the hard part is now acting on the forecast. This post builds a closed detect-decide-act loop on Databricks and Amazon Quick that reconciles demand surges against live supplier availability and places replenishment orders unattended, escalating to a human only when no supplier can cover a surge.
general
Monitoring production agent lifecycle with AWS DevOps Agent and AgentCore Evaluations
Multi-agent systems fail in ways traditional monitoring misses. This post presents a dual-layer approach to monitoring production agents: Amazon Bedrock AgentCore Evaluations for continuous quality scoring and AWS DevOps Agent for autonomous infrastructure investigation, shown on a four-agent airline reservation system.