← Back to dashboard

This week in cloud

109 updates in the last 7 days · 24 security · 2 deprecations

Microsoft Azure (36)

Azure🚨 Deprecation
5 days ago

Retirement: Microsoft HPC Pack

Microsoft is retiring all versions of HPC Pack. End of Support is August 27, 2027. HPC Pack is now entering a one-year retirement period. Microsoft will provide limited, retirement-only support during this period. The scope of this support is defined belo

#deprecation
Source: Azure UpdatesRead Original
Azure🛡️ Security
3 days ago

Preparing governments for an era of interconnected cyber risk

According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025. The post Preparing governments for an era of interconnected cyber risk appeared first on Microsoft Security Blog.

#security#security
Source: Microsoft Security BlogRead Original
Azure🛡️ Security
3 days ago

Insights from the 2026 Microsoft Digital Defense Report

Read highlights from the 2026 Microsoft Digital Defense Report, which reflects a security environment that continues to grow more interconnected. The post Insights from the 2026 Microsoft Digital Defense Report appeared first on Microsoft Security Blog.

#security#security
Source: Microsoft Security BlogRead Original
Azure🛡️ Security
5 days ago

Phishing Abuses RMM Tools for Persistent Access

Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog.

#security#ai#security
Source: Microsoft Security BlogRead Original
Azure🛡️ Security
5 days ago

​​Beyond source code: A path to the keys to the kingdom

Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. The post ​​Beyond source code: A path to the keys to the kingdom appeared first on Microsoft Security Blog.

#security#security#devops
Source: Microsoft Security BlogRead Original
Azure🛡️ Security
5 days ago

Star Blizzard refines phishing and malware delivery with the RedFlick technique

Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.

#security#ai#security
Source: Microsoft Security BlogRead Original
AzureGeneral
3 days ago

Translating an Elasticsearch Search Request to Azure Cosmos DB

This tutorial shows how common Elasticsearch search requests can be expressed using Azure Cosmos DB query patterns. Some Elasticsearch capabilities map directly to Cosmos DB full-text search functions, while others require separate queries or application-layer handling. Each step shows the closest Cosmos DB pattern and explains what changes in the process. In Elasticsearch, one search […] The post Translating an Elasticsearch Search Request to Azure Cosmos DB appeared first on Azure Cosmos DB Blog.

Cosmos DB
#serverless#ai
Source: Azure Cosmos DB BlogRead Original
AzureGeneral
3 days ago

Genspark protects live agent sessions with Azure Cosmos DB Global Secondary Indexes

This article was authored by Justin Liu, co-founder and chief architect, Genspark. The work does not end when the prompt does A user comes to Genspark with a goal: research a market, build a presentation, produce a report, analyze a dataset, or complete another complex assignment. Our agents take it from there, working across tools, […] The post Genspark protects live agent sessions with Azure Cosmos DB Global Secondary Indexes appeared first on Azure Cosmos DB Blog.

Cosmos DB
Source: Azure Cosmos DB BlogRead Original
AzureGeneral
5 days ago

Retirement: Functions on Azure Container Apps V1

The Functions on Azure Container Apps (ACA) V1 will be retired on September 29, 2027. After this date, existing Functions on ACA V1 Apps will stop running and no longer process requests or event-driven triggers. Action required Review your Azure environme

Azure Container Apps
#serverless#containers#ai
Source: Azure UpdatesRead Original
AzureReleaseLOW
5 days ago

[Launched] Generally Available: SQL Formatter

SQL Formatter is now generally available in Visual Studio Code, enabling consistent and customizable SQL script formatting.

Visual Studio Code
#SQL Formatter#Visual Studio Code#SQL#Formatting
Source: Azure UpdatesRead Original
AzureRelease
5 days ago

[Launched] Generally Available: Storage with cool access enhancement

QoS update with cool access enabled on Premium and Ultra service levels improves how Azure NetApp Files balances performance and cost for mixed hot and cool workloads. Throughput automatically adjusts as data moves to cool storage, maintaining hot‑tier pe

#release#ai#database#cost
Source: Azure UpdatesRead Original

Amazon Web Services (64)

AWS🛡️ Security
3 days ago

GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan

Today, AWS announces that Amazon GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan. Runtime Monitoring inspects operating system, network, and file activity to surface threats such as container escapes, privilege escalation, and cryptomining on Amazon EC2 instances, Amazon EKS clusters, and Amazon ECS tasks on AWS Fargate. Security Hub now bills this coverage through streamlined pricing. If you have Security Hub enabled in an account and region, you no longer receive separate Amazon GuardDuty charges for Runtime Monitoring for that account and region. That usage now appears on your bill under AWS Security Hub, where Security Hub meters it as a single usage type that spans Amazon EC2, Amazon EKS, and Amazon ECS on AWS Fargate rather than as separate charges for each resource type. Your detection coverage, your finding types, and your GuardDuty security agents all remain the same, and you do not need to reconfigure anything. Please note that the free trial for the Threat Analytics plan remains separate from the free trial for the Security Hub Essentials plan, and that this change does not add a new free trial for Runtime Monitoring. To see how the change affects your bill, you can use AWS Cost Explorer or the Security Hub usage page. For a list of AWS Regions where Security Hub is available, see the AWS Region table. For pricing details, see the AWS Security Hub pricing page. To get started, visit the AWS Security Hub product page or console.

EC2EKSECS+2
#security#containers#ai#security
Source: AWS What's NewRead Original
AWS🛡️ Security
3 days ago

Serve live, governed data in AI-built apps with Amazon Quick

With Live Data in Apps in Amazon Quick, AI-built apps query your governed Quick Sight datasets in real time instead of static, build-time snapshots. Each query runs as the person viewing the app, so row-level and column-level security apply per reader. Learn how to build, publish, and share a live-data app using natural language.

#security#ai#security
Source: AWS Machine Learning BlogRead Original
AWS🛡️ Security
3 days ago

Amazon Redshift now supports cross-Region queries for your data lake

Amazon Redshift now supports querying Amazon S3 data lake tables located in a different AWS Region. With enhanced VPC routing, data lake query traffic between Amazon S3 and Amazon Redshift stays within your own VPC. Both capabilities are powered by the integrated data lake query engine that runs directly on the compute of RG provisioned and Serverless clusters. These features are aimed at enterprises with globally distributed data and at security-sensitive customers who need tight control over how their data travels. With cross-Region support, you can use Amazon Redshift to query S3 data in another Region directly, without first copying or replicating it. This makes it easier to run global analytics, consolidate reporting across Regions, and query data that must remain in a specific Region for residency requirements. Cross-Region queries incur standard data transfer charges. Because the query engine runs on your cluster's compute, data moving between Amazon S3 and Amazon Redshift flows entirely over your VPC when you use enhanced VPC routing, never over public networks. Regulated industries such as financial services, healthcare, and government benefit from this feature as it keeps data lake queries within the network boundaries their compliance requirements demand. Both capabilities work with the integrated data lake query engine, which is available in all regions where RG provisioned and Serverless clusters are available. To learn more, see Querying your data lake tables with enhanced VPC routing in the Amazon Redshift documentation.

S3VPC
#security#serverless#ai#security
Source: AWS What's NewRead Original
AWS🛡️ Security
3 days ago

Amazon DynamoDB Accelerator (DAX) is now available in additional Regions

Today, AWS announces the availability of Amazon DynamoDB Accelerator (DAX) in 17 additional AWS Regions: Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Jakarta), Asia Pacific (Malaysia), Asia Pacific (Melbourne), Asia Pacific (New Zealand), Asia Pacific (Osaka), Asia Pacific (Seoul), Asia Pacific (Taipei), Asia Pacific (Thailand), Canada West (Calgary), Europe (Milan), Europe (Zurich), Israel (Tel Aviv), Mexico (Central), AWS GovCloud (US-East), and AWS GovCloud (US-West). DAX is a fully managed, highly available, in-memory cache for Amazon DynamoDB that delivers up to 10 times performance improvement—from single-digit milliseconds to microseconds—even at millions of requests per second. This expansion brings DAX to more geographies, helping customers accelerate read-heavy DynamoDB workloads without managing their own cache infrastructure. With DAX, you can accelerate read-intensive and bursty workloads such as real-time bidding, gaming leaderboards, and retail product catalogs, while offloading read traffic from your DynamoDB tables. DAX is API-compatible with DynamoDB, so you can add microsecond-latency caching to your applications with minimal code changes. Customers in these Regions can now meet local data residency and low-latency requirements while benefiting from DAX's fully managed operations, including automated patching, failover, and scaling. To see the full list of Regions where DAX is available, see the following resources: AWS Capabilities by Region.

RDSDynamoDB
#security#ai
Source: AWS What's NewRead Original
AWS🛡️ Security
3 days ago

Amazon Corretto 8 September 2026 Patch Updates

On September 30, 2026, Amazon announced a patch update for the following Amazon Corretto Long-Term Support (LTS) version of OpenJDK: Corretto 8u504 is now available for download. Amazon Corretto is a no-cost, multi-platform, production-ready distribution of OpenJDK. This patch includes the tzdata 2026d updates. Visit Corretto home page to download Corretto 27, Corretto 25, Corretto 21, Corretto 17, Corretto 11, or Corretto 8. You can also get the updates on your Linux system by configuring a Corretto Apt, Yum, or Apk repo. Feedback is welcomed!

#security#ai#cost
Source: AWS What's NewRead Original
AWS🛡️ Security
4 days ago

AWS Security Hub introduces remediation plans to prioritize and fix security exposures

AWS Security Hub now offers remediation plans that group related exposure findings sharing a root cause. Instead of addressing each exposure individually, you can now fix a single underlying resource, such as a misconfigured setting or overly permissive policy, and resolve or reduce the severity of multiple exposures at once. Each remediation plan includes prioritization guidance (Critical, High, Medium, or Low), impact assessment, and detailed step-by-step instructions with examples in multiple formats including AWS CLI, Terraform, CloudFormation, Python, and CDK. Security Hub automatically prioritizes plans so those reducing the most risk appear first, helping you focus remediation efforts where they matter most. AI agents can also programmatically consume remediation plans through the API to automate security fixes across your environment. Remediation plans are available in every AWS Region where AWS Security Hub is available and at no additional cost under AWS Security Hub Essentials plan. To learn more, visit the AWS Security Hub documentation.

CloudFormationSecurity Hub
#security#ai#security#cost
Source: AWS What's NewRead Original
AWS🛡️ Security
4 days ago

Announcing DNS analytics and insights for Route 53 Global Resolver and DNS Firewall

Route 53 Global Resolver and DNS Firewall now provide DNS analytics and insights through native Amazon CloudWatch integration. These new capabilities enable network administrators and security teams to gain full observability into DNS query patterns, monitor DNS Firewall rule effectiveness, detect anomalous activity, and optimize DNS infrastructure performance. DNS analytics and insights is available in all AWS Regions where Amazon CloudWatch, Route 53 Global Resolver, and DNS Firewall are available. With CloudWatch Metrics and Contributor Insights, customers can search and analyze DNS query logs, create metric filters for specific patterns such as blocked queries and DNS response codes, and set automated alarms. A new Analytics tab in both the Global Resolver and DNS Firewall consoles provides streamlined access to all analytics in one place. For example, customers can create a metric filter for blocked DNS queries by VPC and set an alarm to trigger when more than 10 queries are blocked within an hour, enabling rapid response to potential security threats. Standard Amazon CloudWatch pricing applies to the metrics that customers opt in to. To learn more, visit the Route 53 documentation.

CloudWatchVPCRoute 53
#security#ai#security#networking
Source: AWS What's NewRead Original
AWS🛡️ Security
4 days ago

Improve your secrets security posture with actionable recommendations in the AWS Secrets Manager console

​​​AWS Secrets Manager now integrates with the AWS Recommended Actions framework to surface contextual, actionable suggestions for your secrets directly in the Secrets Manager console. ​​ ​​With this launch, you can view tailored recommendations alongside your secrets to improve your security posture and follow best practices without leaving the console. For example, you can identify secrets that need rotation configured, use a customer managed key instead of default service-provided key for encryption, and act on secrets configuration improvements, all from a single view.​ ​​This feature is available in all AWS Commercial Regions where AWS Secrets Manager is offered, at no additional cost. To get started, visit the AWS Secrets Manager console.​

Secrets Manager
#security#ai#security#cost
Source: AWS What's NewRead Original
AWS🛡️ Security
4 days ago

AWS Continuum for Penetration Testing now available in 6 additional Regions

AWS Continuum for Penetration Testing now available in 6 additional Regions AWS Continuum for Penetration Testing (AWS Security Agent) is a managed security service that enables AWS customers to conduct penetration testing against their web applications and APIs. Previously limited in geographic reach, the service now addresses the growing need for localized security testing by expanding into six additional AWS Regions: Asia Pacific (Seoul), Canada (Montreal), Europe (London), US East (Columbus), Europe (Paris), and Europe (Stockholm). This expansion helps organizations operating across these geographies meet data residency requirements while maintaining robust security testing programs. With this regional expansion, customers can now run penetration testing workloads closer to their production environments. Security and compliance teams can leverage AWS Continuum for Penetration Testing for critical use cases including vulnerability assessments, compliance validation against frameworks such as PCI DSS and ISO 27001, and continuous security posture evaluations. This expansion is now generally available in Asia Pacific (Seoul), Canada (Montreal), Europe (London), US East (Ohio), Europe (Paris), and Europe (Stockholm), with existing supported Regions remaining fully operational. To learn more about AWS Continuum for Penetration Testing and how to get started in these newly supported Regions, visit https://aws.amazon.com/continuum/.

#security#ai#security
Source: AWS What's NewRead Original
AWS🛡️ Security
4 days ago

Amazon Quick now supports live data from your datasets in apps

Today, Amazon Quick adds support for building applications that use live data directly from your Quick datasets, so the KPIs, charts, tables, and insights in your application always reflect the latest data. These applications go beyond viewing data. They facilitate intelligent, data-driven business operations workflows where each person can act on what they see, from handling requests and approvals to triggering the next step. Each application user sees data under their own Amazon Quick permissions, so the row-level and column-level security you already set up is applied. To build one, give the app builder chat agent the name of the dataset you want to use and describe in plain language what you want to build. This lets you enrich an application, such as a team portal that handles requests and approvals and now also shows current pipeline numbers, where each application user sees only the data their permissions allow. This feature is available in all supported regions of apps in Amazon Quick. To see how it works, read the blog post. To learn more, see Connecting to datasets in the Amazon Quick User Guide.

Workflows
#security#ai#security#devops
Source: AWS What's NewRead Original
AWS🛡️ Security
5 days ago

Amazon Kinesis Video Streams now supports VPC endpoints with AWS PrivateLink

Amazon Kinesis Video Streams now supports interface VPC endpoints powered by AWS PrivateLink, providing private connectivity from your Amazon Virtual Private Cloud (Amazon VPC). Traffic between your VPC and Kinesis Video Streams stays on the AWS network and is not exposed to the public internet, across the control plane and the video ingestion and playback data planes. Customers with strict security, compliance, or network-isolation requirements can now ingest, store, and play back video without internet gateways, NAT devices, or public IP addresses. For example, connected-camera or IoT video workloads in a private subnet can send media to Kinesis Video Streams and retrieve it for playback and analytics entirely over private connectivity. You create the endpoint from the Amazon VPC console, AWS CLI, or AWS SDKs and can attach a VPC endpoint policy to control access. VPC endpoints for Amazon Kinesis Video Streams are available in all AWS Regions where Amazon Kinesis Video Streams is available, including the AWS GovCloud (US) Regions and the China (Beijing) Region, operated by Beijing Sinnet Technology Co., Ltd. ("Sinnet"). To learn more, see our Getting Started Guide.

VPCKinesis
#security#ai#security#networking
Source: AWS What's NewRead Original
AWS🛡️ Security
5 days ago

OpenAI GPT-6.1 Sol is now generally available on Amazon Bedrock

Today, AWS announces the general availability of GPT-6.1 Sol from OpenAI on Amazon Bedrock. An upgrade to GPT-6 Sol, GPT-6.1 Sol delivers exceptionally strong performance on agentic coding, computer use, and professional work. According to OpenAI, it approaches GPT-6 Astra across demanding evaluations at roughly one-fifth of the cost, giving developers more room to build and run capable agents at scale. The Amazon Bedrock inference engine delivers the performance, security, and reliability required for production workloads. Use GPT-6.1 Sol to build features, debug issues, iterate on solutions, carry out multistep workflows, and investigate complex codebases. It also supports explicit prompt caching on Amazon Bedrock, making it practical for agentic workloads that reuse context across repeated requests. Established AWS controls help you secure workloads, govern access, and audit model invocation activity. You can get started in the Amazon Bedrock console or programmatically through supported Amazon Bedrock APIs. For information about supported AWS Regions, endpoints, APIs, features, inference profiles and pricing, see the Amazon Bedrock documentation. To learn more, read the blog.

BedrockWorkflows
#security#ai#security#cost
Source: AWS What's NewRead Original
AWS🛡️ Security
5 days ago

Amazon Aurora now supports PostgreSQL 18.6, 17.11, 16.15, 15.19, 14.24

Amazon Aurora PostgreSQL-Compatible Edition now supports PostgreSQL versions 18.6, 17.11, 16.15, 15.19, and 14.24, which include bug fixes from the PostgreSQL community and Aurora-specific enhancements. We recommend upgrading to the latest minor versions to benefit from these improvements and address Common Vulnerabilities and Exposures (CVEs), as detailed in the release notes. You can upgrade your databases during scheduled maintenance windows using automatic minor version upgrades. To simplify operations at scale, enable automatic minor version upgrades and use the AWS Organizations Upgrade Rollout Policy to orchestrate multiple upgrades in phases, validating on lower-priority environments before upgrading your most critical ones. For more information, see Upgrading Amazon Aurora PostgreSQL DB clusters. Amazon Aurora is designed for high performance and availability at global scale with full PostgreSQL compatibility. It provides scale-to-zero serverless compute, Aurora Global Database for multi-Region resilience, Aurora I/O-Optimized for improved price performance on I/O-intensive workloads, and built-in security and continuous backups. To get started, take a look at our getting started page.

#security#serverless#ai#security
Source: AWS What's NewRead Original
AWS🛡️ Security
5 days ago

Amazon RDS for PostgreSQL announces Extended Support minor versions 13.23-rds.20260514, 12.22-rds.20260514 and 11.22-rds.20260514

Amazon Relational Database Service (RDS) for PostgreSQL announces Amazon RDS Extended Support minor versions 13.23-rds.20260514, 12.22-rds.20260514, and 11.22-rds.20260514. Amazon RDS Extended Support provides up to three additional years of fixes for critical Common Vulnerabilities and Exposures (CVE) and bugs beyond a major version's end of standard support date, giving you more time to upgrade to a new major version. You can upgrade your database using Amazon RDS Blue/Green Deployments, in-place upgrade, or restore from a snapshot. Learn more about performing version upgrades in the Amazon RDS for PostgreSQL User Guide. Amazon RDS for PostgreSQL makes it simple to set up, operate, and scale PostgreSQL deployments in the cloud. Create or update a fully managed Amazon RDS database in the Amazon RDS Management Console or by using the AWS Command Line Interface (AWS CLI).

RDS
#security#database#devops
Source: AWS What's NewRead Original
AWS🛡️ Security
5 days ago

Accelerating development workflows with Kiro CLI as a Pre-Commit and Git Hook Agent

Code review feedback is most valuable when it arrives early. A security vulnerability caught in a pull request saves hours. The same vulnerability caught in production costs days. But what if you could catch it before the code even leaves the developer’s machine – at the time of git commit? Git hooks run automatically at […]

Workflows
#security#security#cost
Source: AWS DevOps BlogRead Original
AWS🛡️ Security
5 days ago

Frozen package management for air-gapped RHEL-family AMIs

Learn a serverless, two-account pattern for running regulated, air-gapped RHEL-family fleets on AWS. It separates connected package ingestion from the air-gapped workload, adds explicit human approval for package changes, and keeps EC2 Image Builder AMIs and Patch Manager on one frozen Amazon S3 repository snapshot.

EC2S3
#security#serverless#ai
Source: AWS Compute BlogRead Original
AWSGeneral
3 days ago

Scaling cloud migrations with agentic AI on Amazon Bedrock AgentCore

Learn how AWS Professional Services uses a multi-agent framework built on Amazon Bedrock AgentCore to automate enterprise cloud migrations end to end. Purpose-built AI agents handle discovery, infrastructure as code generation, portfolio governance, and post-migration operations, reducing IaC development time from weeks to minutes.

EKSBedrock
#ai
Source: AWS Machine Learning BlogRead Original
AWSFeature
3 days ago

Introducing filtered export from Amazon DynamoDB to Amazon S3

Filtered export for Amazon DynamoDB helps you export only the items and attributes you need to Amazon S3, without consuming table capacity. This post introduces the feature and shows how to recover a single tenant's data, share a tenant's history with selected attributes, and relocate a tenant to another Region.

S3DynamoDB
#feature
Source: AWS Database BlogRead Original
AWSPreview
3 days ago

AWS Well-Architected Agent is now available in preview

AWS announces the preview of AWS Well-Architected Agent, a AI-powered service that is the next-gen evolution of AWS Trusted Advisor and the AWS Well-Architected Tool. The agent analyzes and optimizes AWS infrastructure across cost, security, performance, and reliability, delivering contextualized recommendations prioritized by business goals. It automatically correlates key metrics and application topology against Well-Architected best practices and analyzes Terraform, CDK templates and CloudFormation templates to deliver automation-ready fixes where applicable. With AWS Well-Architected Agent, teams can define their business goals and get prioritized recommendations prioritized by impact and effort at the resource, application, and architecture levels. For example, a team prioritizing reliability can receive recommendations to add multi-AZ failover to a critical database, complete with an SSM runbook that automates the configuration change and a cross-pillar analysis showing how this change affects cost and performance before you commit. Where applicable, recommendations are delivered with SSM runbooks, prescriptive CLI scripts, and guided console walkthroughs so teams can move quickly. The agent can also conduct automated reviews of your IaC templates that include Terraform, CloudFormation, or CDK templates, identifying gaps, and returning the IaC code changes needed to align with Well-Architected best practices. Access to the AWS Well-Architected Agent and its recommendations is available in US East (N. Virginia), US East (Ohio), and US West (Oregon). You can onboard workloads from any AWS commercial Region. AWS Well-Architected Agent is delivered by AWS Support and available to AWS customers with an AWS Support plan. Learn more about AWS Well-Architected Agent in the User Guide. Get started here.

CloudFormation
#preview#ai#security#database
Source: AWS What's NewRead Original
AWSGeneral
3 days ago

Build agent memory with NVIDIA NeMo Agent Toolkit and Amazon S3 Vectors

Learn how to use Amazon S3 Vectors as the persistent memory layer within the NVIDIA NeMo Agent Toolkit (NAT), deployed on Amazon Elastic Kubernetes Service (Amazon EKS). This post shows how NAT's memory subsystem works and how to implement Amazon S3 Vectors as a custom memory provider, using a multi-agent investment research use case.

S3EKS
#kubernetes
Source: AWS Machine Learning BlogRead Original
AWSFeature
3 days ago

Amazon DynamoDB introduces filtered export to Amazon S3

Amazon DynamoDB now supports filtered export for tables. Export to Amazon S3 allows you to export your table data for analytics, data sharing, and other offline uses, as either a full export or an incremental export over a time window. Filtered export enables you to specify exactly which items and attributes to export, producing a dataset that contains only the data relevant to your use case. With filtered export, you use a key condition expression on a key attribute and a filter expression on any attribute to select which items to export, and a projection expression to choose which attributes to include. The export then returns only the items and attributes you want. You can use that subset of data to perform granular data recovery, move a slice of data between accounts, or run analytics while meeting your compliance rules. Filtered export works with both full exports and incremental exports. Filtered export is available in all AWS Regions, except the AWS GovCloud (US) Regions. To get started, see the following resources: DynamoDB data export to Amazon S3 in the DynamoDB developer guide Filtering a table export in the DynamoDB developer guide Introducing filtered export from Amazon DynamoDB to Amazon S3 blog post

S3DynamoDB
#feature#ai
Source: AWS What's NewRead Original
AWSGeneral
3 days ago

Uplifting conversion across the acquisition funnel with personalization using contextual bandits on AWS

Generative AI makes it cheap to produce personalized content at scale, but which variation do you show each customer? Amazon Payments used a multi-objective contextual bandit on Amazon SageMaker AI to personalize an acquisition funnel, achieving a high single-digit conversion lift for one audience, and learning why content, not the model, was the constraint.

SageMaker
#ai
Source: AWS Machine Learning BlogRead Original
AWSGeneral
3 days ago

Implementing feature flags in container environments with AWS AppConfig

Learn how to implement dynamic feature flags in Amazon ECS and Amazon EKS using AWS AppConfig with the sidecar pattern. You set up an AWS AppConfig feature flag, deploy the AWS AppConfig Agent as a sidecar container, and toggle application behavior at runtime without rebuilding or redeploying your containers.

EKSECS
#containers#ai
Source: AWS Containers BlogRead Original
AWSGeneral
3 days ago

Working with foreign key constraints in Aurora DSQL

Amazon Aurora DSQL supports foreign key constraints, letting you enforce referential integrity directly in the database. This post covers defining foreign keys, immediate versus deferred enforcement, adding constraints to existing tables, and how optimistic concurrency control resolves conflicts in distributed workloads.

#ai#database
Source: AWS Database BlogRead Original
AWSGeneral
3 days ago

Building ambient agents with Amazon Bedrock AgentCore: From event-driven signals to human-in-the-loop workflows

Ambient agents respond to events such as an Amazon S3 upload, a schedule, or an alert instead of waiting for a chat prompt. This post walks through building framework-agnostic ambient agents on Amazon Bedrock AgentCore using Amazon SQS, AWS Lambda, and Amazon DynamoDB, with a single ask_human tool and a Jobs page for human-in-the-loop review.

LambdaS3DynamoDB+2
#serverless#ai
Source: AWS Machine Learning BlogRead Original
AWSGeneral
3 days ago

Implementing Multi-Environment Access for Claude Platform on AWS

Learn how to configure secure, multi-environment access to Claude Platform on AWS from a single subscription: cross-account SigV4 for AWS workloads, workspace-scoped API keys for developers, and OIDC federation for external environments, with workspace-level isolation in a dedicated AI Services account.

#ai
Source: AWS Machine Learning BlogRead Original
AWSGeneral
3 days ago

Simplify dashboard drill-down with the Amazon Quick Sight hierarchy filter

Amazon Quick Sight is a fully managed, cloud-native business intelligence (BI) capability for building and publishing interactive dashboards. The new hierarchy filter gives dashboard authors rich, multi-level filtering in a single compact control, reducing clutter and guiding readers to the data they need in fewer steps.

RDS
Source: AWS Machine Learning BlogRead Original
AWSGeneral
3 days ago

Amazon GuardDuty now supports centralized management using AWS Organizations declarative policies

Amazon GuardDuty now supports AWS Organizations declarative policies, enabling you to centrally enable GuardDuty threat detection across every account and Region in your AWS organization. Using an organization policy, you can now apply a centrally managed GuardDuty enablement configuration. The configuration applies to existing accounts and is automatically maintained as new accounts join your organization. Enabling GuardDuty across all relevant accounts and Regions helps ensure comprehensive threat detection coverage. Previously, keeping enablement aligned across a large multi-account, multi-Region environment meant configuring GuardDuty's enablement settings separately in each Region, which could drift over time. Now you can define a central GuardDuty policy from your delegated administrator account that sets an enablement baseline across your organization (at the organization root, OUs, or individual accounts). The policy supports a default configuration that applies in every Region where GuardDuty is available, as well as per-Region overrides for Regions that require different enablement. Enablement set by a policy cannot be overridden via the GuardDuty console or API. GuardDuty declarative policy support is available in all AWS commercial Regions and the AWS GovCloud (US) Regions. To get started, make sure the delegated administrator has permission to manage GuardDuty policies. Then, sign in to the GuardDuty console and choose Organization policies, or create a policy programmatically using AWS Organizations APIs. To learn more, see Managing accounts using organization policies in the Amazon GuardDuty User Guide and Amazon GuardDuty policies in the AWS Organizations User Guide.

GuardDuty
#ai
Source: AWS What's NewRead Original
AWSRelease
3 days ago

Amazon S3 Object Lock variable retention with event holds is now available in AWS GovCloud (US) Regions

Amazon S3 Object Lock support for variable retention with event holds is now available in AWS GovCloud (US-East) and AWS GovCloud (US-West). Amazon S3 Object Lock variable retention allows you to apply write-once-read-many (WORM) protection to objects whose required retention period starts with a future event, such as a contract closing or an audit completing. You place an event hold with a retention duration on an object and S3 protects the object while the hold is in place. When you release the hold, S3 retains the object for the duration you specified. Unlike legal holds, which end protection immediately upon removal, event holds provide WORM compliance for the required retention period after the triggering event, so you can meet event-based retention requirements without retaining data longer than your policy requires. To learn more, read the AWS Storage Blog post, the S3 Object Lock overview page, and the S3 documentation. This capability has been assessed by Cohasset Associates for use in environments subject to SEC Rule 17a-4(f), FINRA Rule 4511, and CFTC Regulation 1.31.

S3
#release#ai#database
Source: AWS What's NewRead Original
AWSGeneral
4 days ago

AWS Transfer Family now supports custom CloudWatch log groups for managed workflows

AWS Transfer Family now lets you choose a custom log group in Amazon CloudWatch Logs for managed workflow execution logs. You can organize workflow logs to monitor individual workflows separately or bring logs from related workflows together. Previously, every workflow attached to a Transfer Family server sent its execution logs to that server’s CloudWatch log group, so you could not set a separate log destination for each workflow. When creating a workflow through the AWS Transfer Family console or API, you can now select a workflow-level log group that is separate from the server’s log group. Transfer Family delivers workflow logs only to the selected group, so no server logging role is required. Workflow logs retain their existing structured JSON format and remain queryable using Amazon CloudWatch Logs Insights. You can also send logs from multiple workflows to a shared log group to create consolidated metrics and dashboards for tracking workflow execution. If you do not select a structured log destination, workflow logs continue using the server’s role-based logging configuration when configured. Existing workflows continue using their current logging configuration. This feature is available in all AWS Regions where Transfer Family managed workflows are offered. To learn more, visit the Transfer Family managed workflows User Guide.

RDSCloudWatchWorkflows
#ai#monitoring
Source: AWS What's NewRead Original
AWSGeneral
4 days ago

AWS Budgets now supports email verification for notification subscribers

AWS Budgets lets you set custom cost and usage thresholds and alerts you by email when your spending crosses the threshold. AWS Budgets now verifies new email subscribers before sending them budget alerts. When you add an email address to a budget notification, AWS Budgets sends a verification email to that address, and the address begins receiving notifications once the recipient confirms it. Verification applies to email addresses added from 9/30/26 onward. Addresses already subscribed on existing budgets are unaffected and need no action. For a new address, the recipient confirms it by following the link in the verification email, which opens the AWS Management Console. The AWS Budgets console shows the verification status of every subscriber, with a resend option for addresses still pending confirmation. AWS Budgets delivers these notifications through AWS User Notifications, and recipients can opt out at any time. AWS Budgets email verification is available in all AWS Regions, except the AWS GovCloud (US) Regions and the China Regions. To learn more, see Adding email recipients to a budget notification in the AWS Billing and Cost Management User Guide.

#ai#cost
Source: AWS What's NewRead Original
AWSGeneral
4 days ago

AWS Glue Data Catalog now supports table optimization, statistics, and crawlers for Apache Iceberg V3

AWS Glue Data Catalog now supports table optimization, statistics, and crawlers for Apache Iceberg Version 3 (V3) tables. With these new capabilities, you can automatically maintain V3 tables, optimize them for query performance, and discover them in Amazon S3. With table optimization, you can compact V3 tables using binpack, sort, or z-order strategies to improve query performance, and remove expired snapshots and orphan files to reduce storage costs. These optimizations support V3 data types, including variant, geospatial, and nanosecond-precision timestamps. You can also generate number of distinct values (NDV) statistics for V3 tables, which analytics engines use to plan queries efficiently. In addition, you can use Glue crawlers to discover V3 tables stored in Amazon S3 and register them in Glue Data Catalog, making them available to query with any V3-compatible engines. These capabilities are available for Iceberg V3 tables in all AWS Regions where Glue Data Catalog table optimization, statistics, and crawlers are available. To learn more, see Glue Optimization, Glue Statistics, and Glue crawlers in the Glue Developer Guide.

S3
#ai#database#cost
Source: AWS What's NewRead Original
AWSUpdate
4 days ago

Serverless Storage on Amazon EMR Serverless now supports terabyte-scale shuffle

Amazon EMR Serverless now offers enhanced serverless storage capabilities with support for up to 1TB shuffle operations, raising the previous 200 GB per-job limit. Amazon EMR Serverless makes it simple for data engineers and data scientists to run open-source big data analytics frameworks without configuring, managing, and scaling clusters or servers. This enhancement enables enterprise customers to run production-scale Apache Spark workloads that require processing large volumes of shuffle data during complex operations such as joins, aggregations, and sorting. Enterprise data teams can now confidently migrate production workloads that routinely process terabyte-scale datasets without worrying about storage constraints. This enhancement is particularly valuable for workloads involving large table joins across multi-terabyte datasets, and complex aggregations on high-cardinality data that require extensive data shuffling. The addition of spill support ensures that jobs can seamlessly handle memory-intensive operations by offloading data to disk when necessary, improving job reliability and success rates for demanding analytical workloads. This feature is available with Amazon emr-7.14, emr-spark-8.1 and later, in 18 AWS Regions where Amazon EMR Serverless is available. See the Amazon EMR documentation for the full list of supported Regions and their applicable limits. To learn more about Amazon EMR Serverless and get started with terabyte-scale shuffle support, visit the Amazon EMR Serverless page.

#update#serverless#ai#database
Source: AWS What's NewRead Original
AWSGeneral
4 days ago

AWS IAM Identity Center extends multi-Region support to more AWS Regions

IAM Identity Center helps you connect your workforce identities to AWS once and streamline access management to AWS accounts and applications. You can now replicate IAM Identity Center to opt-in AWS Regions, and between Regions within the AWS GovCloud (US) and AWS China Regions. Previously, multi-Region support was available in the enabled-by-default commercial AWS Regions. This helps you improve the resilience of user access to AWS accounts and deploy AWS applications in the AWS Regions that best align with your business needs. When you enable multi-Region support, IAM Identity Center automatically replicates your identities, entitlements, and other information from the primary Region to additional Regions. If IAM Identity Center is affected by a disruption in the primary Region, users continue to have access to their AWS accounts using already provisioned entitlements in the additional Regions. AWS application administrators can use the standard application deployment workflow to deploy their application in an additional Region while you continue to administer IAM Identity Center in the primary Region. Multi-Region support is available for organization instances that use an external identity provider or the IAM Identity Center directory as the identity source, and requires a multi-Region customer managed KMS key (CMK). When you create a new instance, you can enable multi-Region support with a single click, which also creates the CMK. For existing instances, create a multi-Region CMK in AWS KMS, then configure it in IAM Identity Center. Standard AWS KMS charges apply for storing and using CMKs. IAM Identity Center is provided at no additional cost. For the full list of AWS Regions where multi-Region support is available, see AWS Capabilities by Region. To learn more about multi-Region support, see Using IAM Identity Center across multiple AWS Regions. To find out which AWS applications support deployment in additional Regions, visit AWS applications that you can us

IAMKMS
#ai#devops#cost
Source: AWS What's NewRead Original
AWSGeneral
4 days ago

Amazon S3 Tables now support up to 100 table buckets per AWS Region in an AWS account

Amazon S3 Tables now support up to 100 table buckets per AWS Region in an AWS account, increased from 10. This allows you to create up to 1 million tables per AWS Region in an AWS account. With a higher table bucket allowance, you can create a separate table bucket for each dataset, workload, or team, and apply table bucket-level settings such as encryption, access policies, and replication to each. The higher quota applies by default to all accounts at no additional cost. S3 Tables deliver the first cloud object store with built-in Apache Iceberg support, and the easiest way to store tabular data at scale. S3 Tables perform continual table maintenance to automatically optimize query efficiency and storage cost over time, even as your data lake scales and evolves. The higher default quota is available in all AWS Regions where S3 Tables are available. If you need a quota beyond the default, you can request an increase through AWS Support. To learn more, visit the S3 Tables overview page, user guide, and quotas documentation.

S3
#ai#security#database#cost
Source: AWS What's NewRead Original
AWSRelease
4 days ago

Apache Iceberg materialized views now support system-managed write protection

Today, AWS announces system-managed materialized views for Apache Iceberg. Materialized views let you precompute an expensive query once and reuse the result across engines. Because this result is an open Iceberg table in your data lake, anyone with write access can change it, either through the catalog or by writing to the files in Amazon S3. System-managed materialized views close this gap by only allowing AWS Glue to write the materialized view's data and definition, so the result stays exactly as computed regardless of who has write access to the table or the underlying S3 files. To get started, write the SQL that defines the materialized view and, optionally, a refresh schedule. AWS Glue then computes the results, stores them as a standard Apache Iceberg table in your Amazon S3 Tables bucket, and keeps them current on your schedule. Because the result is an ordinary Iceberg table in the AWS Glue Data Catalog, any Iceberg-compatible engine can read it directly, while the service guarantees no other writer can alter it. You get a governed, always-consistent dataset that you can confidently share. You can still refresh, reschedule, or drop the view whenever you need to. System-managed Apache Iceberg materialized views are available in all regions where Apache Iceberg materialized views are supported. To learn more, see System-managed materialized views in the AWS Glue Developer Guide.

S3
#release#ai#database
Source: AWS What's NewRead Original
AWSGeneral
4 days ago

Amazon Quick adds Hierarchy Filter for guided dashboard drill-down

Amazon Quick now supports the hierarchy filter, a single control that lets readers drill through related dimensions such as Region, Country, and City. It replaces several stacked filter controls with one, cutting clutter and guiding readers to their data in fewer clicks. The filter holds up to five dimension levels, arranged broadest to most detailed. Readers open one dropdown and expand each level in turn, with every selection narrowing the next and auto-selecting its parent chain. Authors create it by adding a filter, setting its type to Hierarchy filter, and arranging the fields parent to child. For a retail sales dashboard, instead of stacking Region, Country, and City controls side by side, an author adds one hierarchy filter. A reader expands a region to see its countries, then a country to see its cities, selecting any mix along the way. The relationships are visible in the control, so readers do not need to know which country belongs to which region. The hierarchy filter is available today in all AWS Regions where Amazon Quick is supported. To see how it works, read the blog post. To learn more, see Hierarchy filters in the Amazon Quick User Guide.

#ai
Source: AWS What's NewRead Original
AWSGeneral
5 days ago

Amazon Redshift simplifies access to secure logging with federated permissions

Amazon Redshift now makes it easier to troubleshoot and audit queries on data protected by federated permissions with fine-grained access control (FGAC). Using the new DEBUG permission, data owners can let specific identities see unredacted secure logging records across multiple Redshift data warehouses. With Amazon Redshift federated permissions, you define data permissions once, and Redshift enforces them automatically across every Redshift warehouse in your AWS account. When a query accesses FGAC-protected data, secure logging redacts sensitive values in system table records, such as rewritten query text, error messages, and object names. This protects the producer's data from consumers. At the same time, authorized auditors and administrators need visibility into these records to troubleshoot queries and meet compliance requirements, without turning off secure logging. With the new DEBUG permission, a superuser or database owner can choose which identities see these records without redaction. You grant DEBUG with the standard Redshift GRANT command, typically to an IAM user, IAM role, or IAM Identity Center user or group, so that identity can see unredacted records for its own queries. You can also grant DEBUG to the administrators of a consumer account for full log visibility during troubleshooting and audit. Records authorized for account administrators also stay unredacted when you export Redshift system table data to Amazon S3 Tables. You get precise, auditable control over who can see logs, and secure logging stays on. The feature is available in all AWS Regions where Amazon Redshift is supported. To learn more, see federated permissions, Usage Notes and secure logging in the Amazon Redshift documentation.

S3RDSIAM
#ai#database#monitoring
Source: AWS What's NewRead Original
AWSRelease
5 days ago

Amazon Bedrock expands Claude model availability to in-country inferencing in India

Anthropic's Claude Opus 5, Claude Sonnet 5, and Claude Haiku 4.5 are now available in India through Amazon Bedrock geographic cross-Region inference. You can access these models while processing data within the India Regions, and get started from the Amazon Bedrock console or with the Messages, InvokeModel, and Converse APIs.

Bedrock
#release#ai
Source: AWS Machine Learning BlogRead Original
AWSFeature
5 days ago

Introducing Anthropic models on Amazon Bedrock for in-region inference in Seoul and Singapore

Amazon Bedrock now supports Anthropic's Claude Opus 5 and Claude Sonnet 5 with in-region inference in Seoul, and Claude Sonnet 5 in Singapore. If you have local data processing requirements in South Korea or Singapore, you can now use these Anthropic models at scale, with inference processed entirely within the Region you call.

Bedrock
#feature
Source: AWS Machine Learning BlogRead Original
AWSPreview
5 days ago

Amazon Bedrock Managed Agents, powered by OpenAI, is now available in preview

Developed jointly by AWS and OpenAI, Bedrock Managed Agents (BMA) is built on a customized version of OpenAI's Agents API engineered to be AWS-native and integrated with AWS resources. You can now build agents optimized for OpenAI models that run entirely inside AWS with the identities, permissions, and governance controls you already use. BMA manages how the model preserves state, selects and uses tools, executes code, and coordinates work across multiple steps and decisions. Durable sessions retain messages, tool calls, and intermediate results so you can return later, provide new information, and continue from the progress already made. You can add reusable skills for specialized procedures and connect agents to tools, including via Model Context Protocol (MCP) servers. Each agent operates with its own IAM role, supports human approval before consequential actions, and records supported API activity with AWS CloudTrail. During preview, there is no additional charge for BMA beyond the underlying AWS resources your agents consume. Pricing is subject to change at general availability. Get started with Amazon Bedrock Managed Agents today through supported APIs. BMA is available in preview in US East (N. Virginia), US West (Oregon), and US East (Ohio). For details, see the Amazon Bedrock documentation.

RDSIAMBedrock
#preview#ai#cost
Source: AWS What's NewRead Original
AWSUpdate
5 days ago

Amazon RDS now adds full snapshot size information to the Console and API

Amazon RDS now displays the full snapshot size for RDS Snapshots. With this enhancement, customers can now retrieve full snapshot sizes programmatically through the DescribeDBSnapshots API using the new field, ‘FullSnapshotSizeInBytes’. They can also view this on the console with the ‘Full Snapshot Size’ column. Amazon RDS snapshots are incremental. This means that if you take multiple snapshots of a volume over time, each snapshot only stores the new or modified blocks while maintaining references to unchanged blocks from previous snapshots. The ‘FullSnapshotSizeInBytes’ field shows you the total size of all blocks that make up a snapshot, including both the blocks stored directly in that snapshot and all blocks referenced from previous snapshots. For instance, if you have a 100 GB database volume with 50 GB of data, the ‘full snapshot size’ would show 50 GB regardless of whether it's the first snapshot or a subsequent one. Please note that this is different from the incremental snapshot size, which only refers to the size of newly changed blocks stored in that specific snapshot. Full snapshot size is available all Amazon RDS database instances in all commercial AWS Regions. You can start using it today through the Amazon RDS Management Console, the AWS Command Line Interface (CLI), or the AWS SDKs. To learn more, see the Amazon RDS User Guide.

RDS
#update#ai#database
Source: AWS What's NewRead Original
AWSGeneral
5 days ago

Implementing customer managed keys for AWS Lambda durable functions with Terraform

Lambda durable functions checkpoint execution state to durable storage, and for regulated payment workloads that data is sensitive. This post shows how to configure a customer managed key in AWS KMS to encrypt durable execution data, define a least-privilege key policy, and verify encryption through AWS CloudTrail, all deployed with Terraform.

LambdaKMS
#serverless#ai#security#database
Source: AWS Compute BlogRead Original
AWSGeneral
5 days ago

Amazon Connect Customer now lets business users manage more reference data to adjust contact center configurations in real time

Amazon Connect Customer now lets administrators store more of the reference data that drives their contact center configurations. Administrators can now use data tables to hold up to 20,000 values per table for defining configurations such as operating hours, escalation rules, AI agent prompts or queue assignments that drive contact flows. Administrators can now also export tables, edit hundreds of records, move tables between Connect Customer instances, or load reference data from external systems using tools and sources such as Excel and DynamoDB. Business teams can keep this data current themselves, adjusting their contact center configurations as conditions change without depending on technical resources. This feature is available in all AWS commercial and AWS GovCloud (US-West) regions where Amazon Connect Customer is offered. To learn more, see Create and configure data tables in the Amazon Connect Administrator Guide. To learn more about Amazon Connect, visit the Amazon Connect Customer website .

RDSDynamoDB
#ai
Source: AWS What's NewRead Original
AWSRelease
5 days ago

Amazon WorkSpaces Applications introduces unified graphics images

Today, Amazon WorkSpaces Applications announces unified graphics images, a single image type that works across all supported graphics instance families, including G4dn, G5, G6, and G7. Previously, each graphics generation required its own dedicated image. Now customers can use one image to create and manage fleets on any supported graphics instance family. Unified graphics images simplify image management and make it easier to adopt newer GPU generations as they become available. When creating a fleet using the unified graphics image, the console displays all compatible instance types, so you can choose the right price and performance for your workload. Fleets built on a unified graphics image can also change instance types across supported families using the console or the UpdateFleet API, an operation previously limited to sizes within a single instance family. Unified graphics images are available in all AWS commercial and AWS GovCloud (US) Regions where Amazon WorkSpaces Applications graphics instances are supported. To get started, upgrade an existing graphics image through Managed Image Update or launch an image builder from a unified base image. To learn more, visit the Amazon WorkSpaces Applications documentation.

#release#ai
Source: AWS What's NewRead Original
AWSGeneral
5 days ago

Prompt engineering fundamentals for Amazon Quick

Prompt engineering in Amazon Quick shapes how accurately its AI-powered features respond to your requests. Part 1 of a two-part series covers the foundational principles and reusable frameworks (specificity, context-setting, few-shot examples, and the CRISPE framework) for consistent, high-quality results across Amazon Quick.

#ai
Source: AWS Machine Learning BlogRead Original
AWSGeneral
5 days ago

Prompt engineering by Quick component: Patterns and pitfalls

Part 2 of our Amazon Quick prompt engineering series goes component by component. Learn the prompt patterns that get the best results from Amazon Quick Research, Quick Flows, Quick Sight, chat agents, and action integrations, plus the common pitfalls to avoid.

Source: AWS Machine Learning BlogRead Original
AWSRelease
5 days ago

AWS Service Availability Updates

We're announcing availability changes to the following AWS services and features. Services moving to Maintenance Services moving to maintenance will no longer be accessible to new customers starting October 29, 2026. Customers already using these services and features can continue to do so. AWS will continue to operate and support these services and features. We recommend that customers learn about the changes in the product pages and documentation. · Amazon Chime SDK SIP Media Application · Amazon WorkSpaces Secure Browser Services entering Sunset The following services are entering sunset, and we are announcing the date upon which we will end operations and support of the service. Customers using these services should click on the links below to understand the sunset timeline and begin planning migration to alternatives as recommended in the updated service web pages and documentation. · Amazon Managed Blockchain (end of support September 29, 2027) · Amazon DevOps Guru (end of support September 30, 2027) · AWS Backint Agent for SAP ASE (end of support September 29, 2027) · AWS Infrastructure Composer (standalone console end of support December 7, 2026) Services reaching End of Support The following services have reached end of support and are no longer available as of September 29, 2026. · Amazon Mechanical Turk For customers affected by these changes, we've prepared comprehensive migration guides, and our support teams are ready to assist with your transition. Visit the AWS Product Lifecycle Page to learn more, and subscribe to the RSS feed for future updates.

#release#ai#devops
Source: AWS What's NewRead Original
AWSGeneral
5 days ago

Building an AI-powered contract intelligence platform with Amazon Quick and Amazon Bedrock AgentCore

Manually extracting data from hundreds of vendor contracts doesn't scale, and RAG chat tools fall short on portfolio-wide questions. This post shares a contract intelligence platform on AWS that uses AI agents to extract and verify contract fields, then answers aggregate and single-contract questions through Amazon Quick analytics.

Bedrock
#ai
Source: AWS Machine Learning BlogRead Original
AWSRelease
5 days ago

Simplify AMI discovery with Amazon EC2 and SSM Parameter Store

Managing Amazon EC2 AMIs at scale means constantly mapping AMI IDs to their AWS Systems Manager parameter paths by hand. A recent enhancement to the DescribeImages API returns the associated SSM parameter directly. This post shows how to use it across the AWS CLI, AWS CloudFormation, Terraform, and Auto Scaling launch templates.

EC2CloudFormation
#release
Source: AWS Compute BlogRead Original
AWSGeneral
5 days ago

How Condé Nast built multimodal video discovery with Amazon Bedrock

Condé Nast's editorial teams spent an average of 250 minutes per task searching a library of more than 140,000 videos using only titles and descriptions. Working with the AWS Generative AI Innovation Center, they built a multimodal video discovery solution on Amazon Bedrock and Amazon OpenSearch Service that cut discovery time to under 2 minutes.

Bedrock
#ai
Source: AWS Machine Learning BlogRead Original
AWSGeneral
5 days ago

Amazon Bedrock expands Claude model availability to India, South Korea, and Singapore

We're excited to announce the availability of Anthropic's Claude Opus 5, Claude Sonnet 5, and Claude Haiku 4.5 on Amazon Bedrock in India, Claude Opus 5 and Claude Sonnet 5 in South Korea, as well as Claude Sonnet 5 in Singapore. Customers who need to process data within a specific geography, including those in financial services, healthcare, and the public sector, can now use these models at scale while keeping inference in-country. In India, the regional endpoint is served through geographic cross-Region inference across the Mumbai and Hyderabad Regions. Customers in India can access these models while processing data in India Regions, in addition to the already supported global cross-Region inference. In South Korea, Amazon Bedrock supports Claude Opus 5 and Claude Sonnet 5 models with in-region inference on the bedrock-runtime endpoint in the Seoul (ap-northeast-2) Region. In Singapore (ap-southeast-1), Amazon Bedrock supports Claude Sonnet 5 with in-region inference on the bedrock-runtime endpoint. Amazon Bedrock processes inference requests and data within the Region you call, and the processing never leaves that Region. For the most current information about model availability in each Region, see Regional availability by models in the Amazon Bedrock User Guide.

Bedrock
#ai
Source: AWS What's NewRead Original
AWSRelease
5 days ago

AWS Transform now supports Apache Kafka migration assessments for Amazon MSK

You can now use AWS Transform agentic migration assessments to evaluate the migration of on-premises Apache Kafka clusters to Amazon Managed Streaming for Apache Kafka (Amazon MSK). AWS Transform migration assessments use agentic AI to analyze your workloads, recommend the best-fit AWS services, and generate a total cost of ownership (TCO) business case with pricing options and actionable next steps - all in minutes, through natural-language chat or with AWS Transform MCP server. For Apache Kafka workloads, the assessment agent delivers compatibility checks, right-sized Amazon MSK Express broker recommendations, and projected costs - helping you quickly build a migration business case and accelerate your migration decisions. Evaluating a Kafka-to-MSK migration often involves multiple steps - mapping topologies, validating compatibility, right-sizing brokers, and projecting costs - that can take weeks when done manually. With this launch, you can start your migration assessment by uploading a Kafka cluster inventory file or simply describing your clusters in chat. The assessment agent then handles the heavy lifting - checking each cluster for MSK compatibility across topology, version, configurations, authentication, and quotas; sizing MSK Express brokers; and projecting costs across broker hours, storage, data-in, and cross-AZ transfer. Additionally, you can create what-if scenarios with customized assumptions - compare pricing across Regions, adjust retention, or explore alternative configurations - to generate a comprehensive migration business case that gives stakeholders the confidence to move forward. Migration assessments for Amazon MSK are available in all AWS Regions where AWS Transform is offered. To get started, visit the Amazon MSK Developer Guide, Assess MSK migration readiness with AI tools, or the AWS Transform user guide.

EKS
#release#ai#security#database
Source: AWS What's NewRead Original
AWSGeneral
6 days ago

AWS Transfer Family now supports downloading multiple files and folders in web apps

AWS Transfer Family now lets web app users download multiple files and folders at once. End users can select any combination of files and folders and download them together in a single action. The download is delivered as a zip archive that preserves the original folder structure when unzipped. You can get started by selecting files and folders in a location and choosing Download from the action menu. Previously, end users could download only one file at a time, and folders could not be downloaded at all. The web app shows the files to be downloaded and real-time progress with a success or failed status for each one. Multiple-file download is available in Google Chrome, Mozilla Firefox, and Chromium-based browsers such as Microsoft Edge. It is not currently supported in Safari, where end users can still download files one at a time. This capability is available in all AWS Regions where Transfer Family Web Apps is offered. To learn more, visit the Transfer Family web apps User Guide.

#ai
Source: AWS What's NewRead Original
AWSRelease
6 days ago

AWS DataSync now supports shared VPCs

AWS DataSync now supports shared Virtual Private Clouds (VPCs). You can create DataSync agents and run transfer tasks using subnets shared across AWS accounts with AWS Resource Access Manager (RAM). It allows you to transfer data privately over a shared subnet and VPC endpoint managed in a central account, rather than one per account. Customers that centralize their networking previously had to create a separate DataSync VPC endpoint in every account that connected privately through AWS PrivateLink. Each endpoint consumed IP addresses and added operational overhead to maintain across accounts. With shared VPC support, a single endpoint in the account that owns the VPC serves every account the subnet is shared with, conserving IP address space and removing the need for a per-account endpoint. This launch also helps within a single account setup. You can now use one VPC endpoint across multiple subnets, removing the earlier requirement for a matching VPC endpoint in each subnet. Shared VPC is supported for both Enhanced mode and Basic mode agent-based tasks. To get started, create a DataSync agent using the console or the CreateAgent API and specify a subnet shared with your account via AWS RAM. AWS DataSync support for Shared VPCs is available in all AWS Regions, except AWS Secret Regions, where AWS DataSync is offered. To learn more, visit the AWS DataSync feature documentation.

VPC
#release#ai#networking
Source: AWS What's NewRead Original
AWSRelease
6 days ago

AWS Systems Manager now supports sharing documents through AWS Resource Access Manager

AWS Systems Manager now lets you share your Systems Manager Documents (SSM Documents) with an entire AWS organization or with specific organizational units (OUs) using AWS Resource Access Manager (AWS RAM). Previously, you could only share a document publicly or with a list of individual account IDs. You can now easily share a document with your organization or OUs, and Systems Manager automatically keeps that sharing up to date as accounts are added to or removed from your organization or OU, so you no longer need to track and update accounts manually. To share a document, you create an AWS RAM resource share, add the SSM Documents you want to share, and select the organizations or OUs to share them with. Because sharing is managed through AWS RAM and resource-based policies, access is granted through standard AWS authorization. When you share a document with an account outside your organization, that account receives a resource share invitation and gains access only after it accepts, giving both the document owner and the consumer more control over shared access. This capability is available in the Systems Manager console, the AWS Command Line Interface (AWS CLI), and the AWS SDKs, in all AWS Regions where AWS Systems Manager is available. There is no additional charge to share documents through AWS RAM. To get started, open the Documents page in the Systems Manager console, or see the AWS Systems Manager User Guide at https://docs.aws.amazon.com/systems-manager/latest/userguide/documents-ssm-sharing.html.

#release#ai#security
Source: AWS What's NewRead Original
AWSGeneral
6 days ago

Amazon ElastiCache Serverless for Valkey now supports public endpoints

Amazon ElastiCache Serverless for Valkey now supports public endpoints, letting you connect to your cache directly from a laptop, a serverless function, or any application running outside AWS, without setting up a VPN, a bastion host, or an SSH tunnel. With a public endpoint, ElastiCache Serverless gives you a fully managed cache reachable over the internet, with no VPC to configure and no infrastructure to provision, and you can create one in under a minute. Use it to rapidly prototype, connect AI coding tools and agents straight to your cache, or add caching to workloads that can't reach a VPC. Every connection uses IAM authentication over TLS 1.3, so there's no password to store or rotate. Connect using Valkey GLIDE 2.2 or later, which has built-in IAM support, or another Valkey client paired with the Developer Toolkit for ElastiCache, an open-source library that generates and refreshes IAM authentication tokens for you. Public endpoints for ElastiCache Serverless are available in all commercial AWS Regions and the China Regions. There is no additional charge for using public endpoints beyond standard ElastiCache Serverless pricing. To get started, create a Valkey 9.0 or later serverless cache with a public endpoint using the AWS Management Console, AWS SDK, or AWS CLI. To learn more about public endpoints, see Create a Valkey serverless cache with a public endpoint.

IAMVPC
#serverless#ai#security#networking
Source: AWS What's NewRead Original
AWSPreview
6 days ago

Amazon Route 53 Resolver DNS Firewall support for Palo Alto Networks Advanced DNS Security is now Generally Available (GA)

​​Amazon Route 53 Resolver DNS Firewall support for Palo Alto Networks (PANW) Advanced DNS Security is now generally available across 32 AWS Regions, allowing security teams to detect and block malicious DNS traffic directly from their VPCs using PANW Advanced DNS Security rules without deploying separate firewalls or modifying VPC configurations.​ ​​Previewed at AWS Summit New York City, the feature enables security administrators to enforce DNS threat protections (Command and Control, Malware, Phishing, Newly Registered Domains, etc.) from Palo Alto Networks directly using Route 53 DNS Firewall rules to inspect and block malicious DNS query traffic from Amazon VPCs and hybrid cloud (via Route 53 Resolver Endpoints).​ ​​With general availability, PANW Advanced DNS Security on DNS Firewall is now supported in all AWS Regions where DNS Firewall is offered. Customers can subscribe to and enable the feature directly via the Route 53 DNS Firewall console, share licenses across organization accounts via AWS License Manager, and associate DNS Firewall rule groups containing PANW rules with VPCs using AWS Resource Access Manager, Route 53 Profiles, or AWS Firewall Manager.​ ​​​To learn more and get started, see Route 53 DNS Firewall documentation. To view Route 53 DNS Firewall pricing, visit Route 53 pricing page. To learn more about the AWS Marketplace listing and pricing for PANW Advanced DNS Security, see the AWS Marketplace listing.​​

VPCRoute 53
#preview#ai#security#networking
Source: AWS What's NewRead Original
AWSPreview
7 days ago

Amazon SageMaker Unified Studio now supports two new connection capabilities: Iceberg REST Catalog connections and IAM authentication for Amazon DocumentDB

Amazon SageMaker Unified Studio now supports two new connection capabilities: (1) Iceberg REST Catalog (IRC) connections for external Apache Iceberg catalogs, and (2) IAM authentication for Amazon DocumentDB. Together, they let data teams connect to a broader set of governed data sources and use credential-less authentication across projects. Iceberg REST Catalog connections. SageMaker Unified Studio now supports Iceberg REST Catalog (IRC) connections, letting customers connect to external Apache Iceberg catalogs that follow the Iceberg REST specification. Supported catalog types include Snowflake Open Catalog (Polaris), Databricks Unity Catalog, and a Generic IRC type for any other spec-compliant catalog. Once connected, customers can browse the catalog in Data Explorer (list catalog/schema/table, view columns, sample data), read and write it in Visual ETL as a source or append/overwrite sink, and query it from data notebooks. Authentication uses OAuth2 or bearer token, and data access uses vended, short-lived Amazon S3 credentials. The connection lifecycle is fully supported - create, edit, delete, and test connection. IAM authentication for Amazon DocumentDB. SageMaker Unified Studio now supports IAM authentication for Amazon DocumentDB connections, so customers can connect to DocumentDB without storing a database username or password in the connection or notebook. The connection authenticates using its own IAM role, which DocumentDB validates via AWS Security Token Service (AWS STS). This requires Amazon DocumentDB 5.0 or later instance-based clusters with TLS enabled. The connection can be used from data notebooks, Data Explorer, Test Connection, and Visual ETL data preview. These connection capabilities are available today in all AWS Regions where Amazon SageMaker Unified Studio is available, at no additional cost. To learn more about Amazon SageMaker Unified Studio, refer to the Amazon SageMaker Unified Studio User Guide.

S3IAMSageMaker
#preview#ai#security#database
Source: AWS What's NewRead Original

Google Cloud (9)

GCP🛡️ Security
4 days ago

The future of browser-based security: Leveraging browser data for proactive defense

The browser has changed significantly. Rather than just a window to the web, it serves as an AI workspace and central operating environment for the modern enterprise. With knowledge workers spending over 56% of their workday in the browser, it is a key gateway for daily work, complex workflows, and direct interaction with autonomous AI agents (Omdia, 2026). To keep pace with threat actors, organizations need a browser strategy that places browser telemetry at the center of their security architecture.The rise of shadow AI and agentic riskAs enterprises adopt AI, new vulnerabilities have emerged. Shadow AI —the unauthorized use of public generative AI tools—can expose sensitive corporate IP through prompt sharing and autonomous agent actions. Ninety-two percent of organizations express concern around potential data leakage through these channels. Leaving this unmonitored creates significant risk (Omdia, 2026).Legacy security stacks, including traditional endpoint detection and response (EDR) and perimeter firewalls, are fundamentally blind to in-browser interactions. They completely miss high-risk threat vectors unique to AI-driven workflows, such as:Malicious extensions that "read" sensitive financial data or "write" keyloggers onto sign-in pages."Living off the land" (LOTL) tactics and session hijacking.State-sponsored threat actors leveraging AI to accelerate the attack lifecycle.Chrome Enterprise Premium: Your high-fidelity telemetry engineChrome Enterprise Premium addresses this visibility gap by capturing browser telemetry. Rather than relying on external observation after the fact, Chrome Enterprise records signals directly at the point of user interaction.Core Capabilities for Modern DefenseReal-time signals: Continuous telemetry for network events, high-risk user behaviors, and suspicious domain access.Extension telemetry: Granular visibility into side-loaded extensions and extension-to-domain communications that traditional EDR might miss.GenAI and SaaS app

WorkflowsRDS
#security#ai#security#networking
Source: Google Cloud BlogRead Original
GCP🛡️ Security
5 days ago

Google Cloud partners deliver new security agents and AI defenses with Gemini Enterprise

As threat actors increasingly use AI to accelerate and develop cyberattacks, enterprise defenders need to rely on both AI and a critical defender’s advantage: Business context that only you possess. Enterprise cyber defense spans identity, network, endpoint, data, cloud, and application layers, often split across a dozen or more products, each with its own context. At Google Cloud Next, we brought partner-built agents into Gemini Enterprise to give you one place to discover and deploy specialized agents across functions including sales, content and creative workflows, HR, and security. Today, we're expanding our catalog of partner-built security offerings in the Gemini Enterprise ecosystem to help you leverage your full security context from one unified interface. These new security agents and integrations from leading cybersecurity vendors span two areas: partner security agents that your teams invoke directly in Gemini Enterprise, and protections for AI and agentic workloads. By bringing them into Gemini Enterprise, you can now orchestrate multi-step security workflows directly in your Gemini Enterprise environment, bringing AI-powered capabilities to your defenses. Meet new security agents and agentic defenses built with Gemini Enterprise Acalvio: The Acalvio ShadowPlex deception agent, accessible through Gemini Enterprise, automates the deployment of decoys and honeytokens across enterprise networks and embeds deception guardrails directly into customer’s operating environment, with no manual configuration required. ShadowPlex deploys network decoys, identity honey accounts, retrieval-augmented generation (RAG) decoys, honey skills, and honeytokens at scale, trapping unauthorized interactions quickly. Britive: The Britive Emergency Termination Agent, built on Gemini Enterprise, lets security teams contain a compromised human or non-human identity from a single natural-language request instead of working across multiple consoles. The agent confirms the identity,

WorkflowsGemini
#security#serverless#ai#security
Source: Google Cloud BlogRead Original
GCP🛡️ Security
5 days ago

Defending at machine speed: Securing the public sector in the agentic era

Over the last three decades in cybersecurity, I’ve witnessed major paradigm shifts — yet none match the velocity and complexity of today’s landscape. Attackers are now using AI to move at machine speed: accelerating intrusions, exploiting zero-day vulnerabilities, and rendering legacy defenses obsolete.Reactive, manual security reviews can no longer keep pace with sophisticated and increasingly automated threats. Building true cyber resilience means shifting from reactive troubleshooting to a proactive defense — one where continuous posture validation and autonomous remediation are built directly into every workload from day one.Public sector teams require a unified, structured approach to continuously scan, validate, and remediate software vulnerabilities. Google AI Threat Defense brings together the reasoning power of Gemini, deep multi-cloud visibility from Wiz, autonomous code remediation with CodeMender, and Mandiant frontline threat intelligence into a singular, continuous operational loop.By securing the entire software lifecycle from code to cloud, this unified system enables agencies to continuously monitor and neutralize emerging threats at machine speed — safeguarding critical infrastructure, mission integrity, and public trust.Real-world cyber defenses in actionAcross state governments and higher education institutions, security and IT leaders are using Google’s AI and security solutions to secure highly dynamic environments, systems, and operations in the agentic era. Let’s take a closer look at how organizations across the public sector are automating defense and building resilience.The State of Iowa: Under CISO Shane Dwyer, the state partnered with Google Public Sector to eliminate operational blindness, consolidating more than 20 separate security environments into a single, centralized security operations center (SOC). By ingesting large volumes of telemetry through Google Security Operations, Iowa established a unified operational view across its m

WorkflowsGeminiRDS
#security#ai#security#networking
Source: Google Cloud BlogRead Original
GCPRelease
3 days ago

Enabling Cloud Storage end-to-end checksums for improved data integrity and durability

At Google Cloud, we know that you count on us to maintain the durability and integrity of your data at all times, both at rest and in transit. And now we’re making it easier for developers to take advantage of native data integrity features in Cloud Storage, by enabling end-to-end checksumming by default in all the Cloud Storage SDKs. Like in any disk-based storage system, bits can flip anywhere in their journey, from the application all the way down to the disk. Cloud Storage has always let clients provide a checksum of the object data being uploaded, and receive a checksum of the data being downloaded. Also since its inception, Cloud Storage stores a checksum for every object in its metadata, regardless of how the object was uploaded into Cloud Storage. But until recently, ensuring end-to-end data integrity required extra work on the part of developers to calculate and provide checksums to Cloud Storage. Cloud Storage always calculates the crc32 (32-bit cyclic redundancy check) of data it receives and ensures data stored on disk matches this checksum. When a client request includes the object’s checksum, Cloud Storage ensures that this checksum also matches. However, when an upload request doesn’t include a checksum, that upload is vulnerable to a bit flip while the data is in-flight, prior to the server-side checksum computation. Not all customers and clients enable client-side checksums by default, leaving data in this phase unprotected. To address this gap, the latest version of all Cloud Storage SDKs now internally checksums data being uploaded and passes this checksum to Cloud Storage, if it’s not provided by the application. The SDKs also support verifying the object’s checksum when an object is being downloaded. Finally, there are many use-cases where applications download select ranges of objects instead of the full object. When using Cloud Storage SDKs with our gRPC API to perform a range read, the SDKs take advantage of gRPC’s built-in end-to-end range c

Cloud StorageRDS
#release#ai#security#networking
Source: Google Cloud BlogRead Original
GCPRelease
3 days ago

Accelerating analytics: PayPal’s journey with Managed Service for Apache Spark

In a data-driven world, PayPal’s ability to deliver timely and actionable insights is central to staying ahead. At PayPal, data powers everything from fraud detection to user experience enhancements. Data is also central to unleashing the potential of agentic solutions and experiences. Over time, though, our analytics environment had become a complex ecosystem of various technologies and solutions assembled on-premise to address growing demands. While this approach supported our needs at the time, it began presenting new challenges to scale and maintain. Navigating a challenging analytics landscape Due to expedited growth and acquisitions, our data analytics platform gradually turned into an uneven landscape. Each new platform or integration addressed a specific business need, but together, they increased operational overhead and introduced performance blockages. Scalability became increasingly difficult, and time-to-insight slowed as processes grew more complex. Complexity breeds stagnation PayPal’s legacy data analytics platform was powerful—handling petabytes daily—but it was also increasingly rigid following rapid growth. Scaling up during peak retail events or global launches meant months of planning, slow manual provisioning of hardware, and too often, a compromise between speed and cost. As PayPal continued to scale globally, we recognized the need for a streamlined, unified infrastructure to drive data efficiency and accelerate innovation. The solution: Unified, cloud-native analytics To overcome these obstacles, we migrated our analytics workloads from legacy Hadoop on-premise platforms to Google’s Managed Service for Apache Spark. Key reasons for this choice included: Rapid provisioning and elastic scaling: Managed Spark enabled us to deploy clusters in minutes and scale based on processing needs, eliminating lengthy setup and idle resource costs. Unified infrastructure: Standardizing on Apache Spark created consistency across teams while leveraging Manage

Cloud StorageBigQueryWorkflows
#release#ai#database#cost
Source: Google Cloud BlogRead Original
GCPPreview
4 days ago

October 01, 2026

BigQuery Change An updated version of the Simba JDBC driver for BigQuery is now available. Feature Chatting with graphs in conversational analytics is now generally available. You can use a combination of multiple graphs, tables, views, and UDFs as data sources. Feature BigQuery pipelines provides support for automated metadata enrichment and Knowledge Catalog data quality scorecard integration. In addition, the Data Engineering Agent can proactively generate semantic metadata for your pipeline assets. For more information, see Metadata enrichment and data quality scorecard integration. These features are generally available. Bigtable Feature You can use Google Cloud Data Agent Kit to browse Bigtable instances and tables, design schemas, and run GoogleSQL queries from your IDE or coding agent. This feature is generally available (GA). For more information, see Data Agent Kit is now GA: Bring Google Data Cloud to any coding agent. Dataform Feature Dataform provides support for automated metadata enrichment and Knowledge Catalog data quality scorecard integration for Dataform workflows and BigQuery pipelines. For more information, see Add metadata for Knowledge Catalog. This feature is generally available. Google Cloud VMware Engine Feature Generally available: Bring Your Own License (BYOL) license management for Google Cloud VMware Engine is generally available (GA). BYOL license management lets you register and manage portable VMware Cloud Foundation (VCF) license keys in the Google Cloud console across projects associated with your Cloud Billing account. For more information, see License management. Network Intelligence Center Announcement Network Services Monitoring is available in Preview. Network Services Monitoring visualizes communication paths and network metrics for Google Kubernetes Engine services and workloads with ambient networking enabled. Feature Cloud Network Insights supports using Google Cloud CLI commands to download Microsoft Azure and Amazon Web

Kubernetes EngineBigQueryPub/Sub+2
#preview#kubernetes#ai#networking
Source: Google Cloud Release NotesRead Original
GCPRelease
5 days ago

Accelerating agentic RL and evaluation research velocity with 45x faster GKE Agent Sandbox

When scaling up agentic reinforcement learning (RL) and evaluation across massive parallel rollouts, frontier AI labs inevitably hit a bottleneck: Expensive GPU clusters sit idle, waiting minutes for CPU sandbox cold-starts, plus thousands of multi-gigabyte SWE-bench-style image pulls and scheduling backlogs. It’s a sandbox infrastructure problem that silently slows down your research and burns your training budget. To solve this fundamental infrastructure bottleneck, today we are introducing GKE Agent Sandbox optimized for RL along with the Agent Sandbox RL orchestration SDK, plus native integrations for popular RL gyms and harnesses, now generally available. As the operating system for modern AI, Kubernetes has evolved to power massive GPU/TPU training clusters and distributed inference. Now Kubernetes is expanding to drive the next AI compute frontier: agents. But unlike static workloads, agentic workloads evolve rapidly, so infrastructure must evolve just as fast. Rather than guessing at what RL researchers needed, we placed Kubernetes itself on an auto-research and verification loop driven by performance benchmarks and evaluations. We used heavy agentic benchmarks like SWE-bench to intentionally stress-test and break our own clusters. Every bottleneck that surfaced — from etcd timeouts to GPU idle spikes — was fed back into our development cycle to refine GKE’s core primitives. This resulted in a purpose-built sandbox layer for agentic RL and eval workloads that features: 10x - 45x faster time-to-first-command: GKE can spin up a sandbox environment in 1–9 seconds instead of 45–85 seconds, keeping your expensive GPUs fully in use. Reduced tail latency: We reduced the worst-case sandbox wait times from 7.5 minutes down to under 10 seconds. 3x less control-plane churn: Each RL training step triggers a rollout burst, where thousands of sandboxes are requested at once. The SDK has an in-place recycling strategy that reuses pods across rollouts instead of deleting an

GKERDS
#release#kubernetes#containers#ai
Source: Google Cloud BlogRead Original
GCPGeneral
5 days ago

Graph Workflows in ADK: Everything You Need to Know

Graph engineering is the design work: breaking a task into nodes, connecting them with edges, and deciding where code, models, or people control the next step. The Agent Development Kit (ADK)'s Workflow turns that design into an executable process, with functions and agents doing the work. Through a refund example, this post shows how to run steps in parallel, route decisions, pause for human review, and process a list of cases. It also explains when to declare the paths in a static graph and when to let Python schedule further work as results arrive.TL;DR: Using a refund workflow in ADK, we'll cover fan-out and fan-in, deterministic and agent routers, human-in-the-loop pauses, parallel workers, and dynamic orchestration— along with when to use a static graph or let Python decide what runs next.Start with a single agentWe can give one agent the tools and instructions to handle the refund request from start to finish: code_block <ListValue: [StructValue([('code', 'refund_agent = Agent(\r\n name="refund_agent", model=MODEL,\r\n tools=[fetch_order, fetch_payment, fetch_history],\r\n instruction="""You handle refund requests.\r\n 1. Look up the order.\r\n 2. Check the payment record.\r\n 3. Check the customer\'s refund history.\r\n 4. Deny if there\'s an open chargeback or it\'s past 30 days.\r\n Approve if it\'s under $50 and they\'ve had fewer than three\r\n refunds this year.\r\n 5. Write the customer an email explaining the decision.""",\r\n)'), ('language', 'lang-py'), ('caption', <wagtail.rich_text.RichText object at 0x7f104432bf90>)])]> This puts the model in charge of choosing the tools, applying the policy, and writing the reply. But the prompt already describes distinct pieces of work: three lookups, a decision, and a response. Making those pieces separate nodes lets us decide how each should run. Assume the customer has selected an order and clicked “Request refund.” The app knows the order ID, so the workflow can begin with the lookups.Let independent steps

WorkflowsRDS
#serverless#ai
Source: Google Cloud BlogRead Original
GCPPreview
6 days ago

September 29, 2026

API Gateway Feature Configure streaming for LLM responses and other traffic You can now create API Gateway gateways that stream requests and responses instead of buffering them. This Public Preview feature supports incremental response delivery over HTTP/2 or HTTP/1.1 chunked transfer encoding, Server-Sent Events (SSE), WebSockets, and gRPC bidirectional streaming. A common use is streaming token-by-token responses from a large language model (LLM). To enable streaming, create a gateway with the --enable-streaming flag. The streaming mode is fixed when you create the gateway and can't be changed later. For more information, see Configure streaming for LLM responses and other traffic. App Engine flexible environment .NET Feature App Engine permanently blocks insecure traffic with TLS version 1.1 and earlier. For appspot.com domains, this block occurs at the connection level. For custom domains, the connection might succeed, but the requests are blocked. For more information, see Secure minimum TLS. App Engine flexible environment Go Feature App Engine permanently blocks insecure traffic with TLS version 1.1 and earlier. For appspot.com domains, this block occurs at the connection level. For custom domains, the connection might succeed, but the requests are blocked. For more information, see Secure minimum TLS. App Engine flexible environment Java Feature App Engine permanently blocks insecure traffic with TLS version 1.1 and earlier. For appspot.com domains, this block occurs at the connection level. For custom domains, the connection might succeed, but the requests are blocked. For more information, see Secure minimum TLS. App Engine flexible environment Node.js Feature App Engine permanently blocks insecure traffic with TLS version 1.1 and earlier. For appspot.com domains, this block occurs at the connection level. For custom domains, the connection might succeed, but the requests are blocked. For more information, see Secure minimum TLS. App Engine flexible enviro

Cloud RunCompute EngineBigQuery+2
#preview#ai#security#networking
Source: Google Cloud Release NotesRead Original
This Week in Cloud — Nerdie Cloud News