AWS Notes
5.6K subscribers
444 photos
42 videos
10 files
2.8K links
AWS Notes — Amazon Web Services Educational and Information Channel

Chat: https://xn--r1a.website/aws_notes_chat

Contacts: @apple_rom, https://www.linkedin.com/in/roman-siewko/
Download Telegram
Reduce encryption costs by using S3 Bucket Keys on existing objects:

https://aws.amazon.com/blogs/storage/reduce-encryption-costs-by-using-amazon-s3-bucket-keys-on-existing-objects/

In this blog, we’ve walked through the steps to implement S3 Bucket Keys for objects with different KMS keys within same bucket. By doing so, we were able to significantly reduce request traffic from S3 to KMS, decreasing KMS costs by 80 percent.

#S3 #KMS
​​Weekly Summary on AWS (March 27 - April 2)

🔸 Aurora PostgreSQL + TDS Protocol
🔸 Backup
Restore individual VMware virtual disks
VMware Cloud on AWS Outposts
🔸 CloudFront + Server Timing headers
🔸 Connect + Contact Lens
🔸 EC2 + automatic recovery of instances by default 👈
🔸 EC2 AMI + reducing visibility of public AMIs older than two years ⚠️
🔸 ECS + container instances per cluster 20005000
🔸 EKS + EBS CSI Driver add-on GA 👀
🔸 EMR Managed Scaling + Spark shuffle data awareness
🔸 EventBridge Schema Registry + Golang 👍
🔸 Firewall Manager + Palo Alto Networks Cloud NGFW 💥
🔸 FSx for NetApp ONTAP + change the throughput capacity
🔸 Glue 2.0 + fuzzy matching and deduplication
🔸 Glue DataBrew + ORC file format
🔸 Lambda console + bulk update of layers
🔸 License Manager + AWS Marketplace
🔸 Organizations + central AWS account closure 🎉
🔸 SageMaker Data Wrangler + Databricks
🔸 Security Hub 👇
12 controls for security posture monitoring
Company and product names for custom integrations
🔸 Storage Gateway + VMware ESXi 7.0 and Microsoft Hyper-V 2022 and 2019 hypervisors
🔸 Well-Architected Tool + Sustainability Pillar
🔸 WorkSpace + branding 👀

🔹 Aurora PostgreSQL 13.6, 12.10, 11.15, 10.20 and Babelfish for Aurora PostgreSQL 1.2.0
🔹 Hadoop S3A connector + S3 Access Points
🔹 RDS for Oracle + January 2022 PSU for 12.1 and RU for 12.2 and 19c

#AWS_week
👍3😁1
​​Kubernetes 1.22 для EKS, EKS Distro и EKS Anywhere:

https://aws.amazon.com/blogs/containers/amazon-eks-now-supports-kubernetes-1-22/

Спустя официального релиза 1.22 прошло 8 месяцев и в результате сделанный в прошлый раз прогноз на эту версию был неточен аж на четыре с половиной месяца! Что лишь подчёркивает, как много изменений в новой версии:

https://docs.aws.amazon.com/eks/latest/userguide/kubernetes-versions.html#kubernetes-1.22

Точней уже не новой, т.к. ещё четыре месяца назад вышла 1.23. 😐

Несмотря на такую задержку, всё же, предположу, что 1.23 появится на AWS ещё летом, поставлю на 15 августа.

Отдельно стоит отметить, что поддержка версии EKS 1.18 была совсем недавно прекращена - 31 марта.

#EKS
👍4🤔3👏1
​​Lambda Function URL: 🎉

https://aws.amazon.com/blogs/aws/announcing-aws-lambda-function-urls-built-in-https-endpoints-for-single-function-microservices/

Each function URL is globally unique and can be associated with a function’s alias or the function’s unqualified ARN, which implicitly invokes the $LATEST version.

For example, if you map a function URL to your $LATEST version, each code update will be available immediately via the function URL.

Lambda Function URL vs. API Gateway

Function URLs are best for use cases where you must implement a single-function microservice with a public endpoint that doesn’t require the advanced functionality of API Gateway, such as request validation, throttling, custom authorizers, custom domain names, usage plans, or caching.

Pricing

Function URLs are included in Lambda’s request and duration pricing. (So it's FREE!💪)

▪️ Rest API (first 333 mil) = $3.5
▪️ HTTP API (first 300 mil) = $1.0
▫️ Lambda URL = Free
▪️ CloudFront proxying to Lambda URL = ~ $1.0 to $1.2

Timeout (seconds)

▪️ Rest API = 29
▪️ HTTP API = 30
▫️ Lambda URL = 900
▪️ CloudFront proxying to Lambda URL = 60 (by default)

#Lambda
🎉12👍3🔥1
11
​​Weekly Summary on AWS (April 3-9)

🔸 Amplify Geo for iOS
Amplify Geo + React Component for Maps
Amplify Hosting + GitHub App
Amplify Studio + file storage
🔸 AppConfig Feature Flags + Jira
🔸 AppSync + enhanced subscriptions filtering
🔸 Athena
ACID transactions GA
Amazon Ion format
🔸 Backup + FSx for Lustre Persistent_2
🔸 CloudFormation + RStudio on SageMaker
🔸 CloudWatch Metrics Insights GA
🔸 Connect + playing voice prompts from S3
Connect Wisdom + Zendesk
Updated UI
🔸 Console
New EC2 Console launch page 👀
Unified AWS Console settings + Region/language/service 👈
🔸 DocumentDB + Performance Insights
🔸 EC2 m6a.metal & c6a.metal instances 💥
🔸 ECS Exec + Windows containers on Fargate
🔸 EKS 1.22 🎉
🔸 EventBridge + global endpoints 👍
🔸 IoT Device Management & Device Defender + ListMetricValues API GA
🔸 Lambda Function URL 🔥
🔸 MemoryDB for Redis + ACK (AWS Controllers for Kubernetes)
🔸 OpenSearch
Custom dictionaries with IK Analysis plugin
Cross-cluster Replication
Cross-cluster Search
Observability
Version 1.2 👈
🔸 Pinpoint API 2.0
🔸 PrivateLink + FSx API
🔸 RDS Proxy + PostgreSQL 13 🎉
🔸 Route 53 + usage-based pricing
🔸 Redshift
Microsoft Azure AD & Power BI
RBAC
🔸 RDS for SQL Server + SQL Server Agent job replication
🔸 Shield Advanced + automatic DDoS mitigation for ALB

🔹 Data transfer + FREE cross-AZ for PrivateLink, TGW, and Client VPN 💪
🔹 OpsWorks for Configuration Management + Puppet Enterprise LTS 2019.8
🔹 Compute Optimizer + 66 new instance types
🔹 RDS for Oracle + M6i / R6i instances
🔹 Security Hub + 5 new controls & Data Theorem

#AWS_week
🔥2👍1
​​Weekly Summary on AWS (April 10-16)

🔸 AppStream 2.0 + session scripts for Elastic fleets
🔸 App Runner + X-Ray 👈
🔸 CloudWatch Metric Streams + additional statistics
🔸 DataSync + FSx for OpenZFS
🔸 EC2 Console launch page + EFS & FSx 👀
🔸 Fargate + 20X faster scaling 💪
🔸 FSx for NetApp ONTAP + single AZ deployment 💥
🔸 Kinesis Data Firehose + Coralogix
🔸 Personalize + resource tagging
🔸 PrivateLink + Connect Wisdom
🔸 SSO synchronization from AD 👍
🔸 WorkSpaces + G4dn instances

🔹 Aurora MySQL + cipher suites
🔹 Chime SDK for JavaScript 3.0 and React Components 3.0
🔹 Registry of Open Data + 16 new or updated datasets

#AWS_week
👍2
​​Aurora Serverless v2:

https://aws.amazon.com/blogs/aws/amazon-aurora-serverless-v2-is-generally-available-instant-scaling-for-demanding-workloads/

Aurora Serverless v2 enables you to scale your database to hundreds of thousands of transactions per second and cost-effectively manage the most demanding workloads. It scales database capacity in fine-grained increments to closely match the needs of your workload without disrupting connections or transactions.

If you have an existing Aurora cluster, you can create an Aurora Serverless v2 instance within the same cluster. This way, you’ll have a mixed configuration cluster where both provisioned and Aurora Serverless v2 instances can coexist within the same cluster.

Aurora Serverless v2 capacity scales up and down within the minimum 0.5 ACUs and maximum 128 ACUs configuration.

Versions supported:
🔹 PostgreSQL 13
🔸 MySQL 8.0

#Aurora #Serverless
👍4🎉1
​​Weekly Summary on AWS (April 17-23)

🔸 ACK (AWS Controllers for Kubernetes) + EKS, ECR, DynamoDB, S3, Autoscaling and API Gateway v2 + GA 👀
🔸 Amazon Linux 2022 + ECS-optimized AMI
🔸 Amplify Geo for Android + GA
🔸 Amplify Studio + GA 💪
🔸 Athena + 10 new data sources 🔥
🔸 Aurora Serverless v2 + GA 🎉
🔸 Batch + dynamically update configuration
🔸 CloudFormation + 35 new resources
🔸 Connect + API for phone numbers
🔸 DevOps Guru Proactive Insights for Serverless Applications
🔸 EC2 Auto Scaling + default instance warm-up time
🔸 EKS + OpenTelemetry Operator addon
🔸 Glue
Auto Scaling + GA
Interactive Sessions + GA
Glue Studio Detect PII + GA
Glue Studio Job Notebooks + GA
🔸 IoT TwinMaker + GA 👍
🔸 Kendra
Box Connector
Quip Connector
🔸 Keyspaces + Spark Cassandra connector
🔸 KMS + HMAC 👀
🔸 Macie + discovering more types of sensitive data
🔸 Migration Hub Orchestrator
🔸 Neptune
Free trial 👈
IAM global condition keys
openCypher GA
🔸 Personalize + starting and stopping recommender
🔸 PrivateLink + Batch
🔸 QuickSight + 1-click public embedding
🔸 RDS + Multi-AZ for Outposts
🔸 Redshift Audit Logging + CloudWatch
🔸 SageMaker Serverless Inference + GA
🔸 Security Hub + cross-Region security scores and compliance statuses
🔸 Step Functions + 20 new AWS SDK integrations
🔸 Textract + Queries

🔹 Corretto 18.0.1, 17.0.3, 11.0.15, and 8u332
🔹 Launch Wizard
IIS
Microsoft Exchange Server
🔹 MQ + ActiveMQ 5.16.4

#AWS_week
👍2
​​Weekly Summary on AWS (April 24-30)

🔸 Audit Manager + AWS Config custom rules
🔸 CloudFormation + AWS::EC2::KeyPair 👍
🔸 Connect
API to search by name, agent hierarchies, and tags
PutUserStatus
Search and review Voice ID results
🔸 EC2 i4i instances 💥
🔸 EC2 key pairs
Retrieve public key and creation date
PPK for ED25519
🔸 IAM + aws:ResourceAccount, aws:ResourceOrgPaths, and aws:ResourceOrgID 👀
🔸 Interactive Video Service + stream chat
🔸 Lambda + Insights via Application Insights
🔸 Lightsail
HTTPS redirects
TLS policy
🔸 MSK Serverless + GA 🎉
🔸 Network Firewall + AWS Managed Threat Signatures
🔸 Rekognition Streaming Video Events + GA 🎉
🔸 RDS
IPv6 👍
Query results in JSON
Usage metrics against AWS service limits
🔸 SageMaker Data Wrangler
Data Quality and Insights Report
Random and stratified samples
🔸 SES v2 + 40MB message size
🔸 Service Catalog CDK constructs ⚠️
🔸 Snow
Large Data Migration Manager
Managing devices remotely
Update of device certificates

🔹 Control Tower landing zone v.2.9
🔹 EKS + Karpenter v0.9.0 with Pod Affinity 👈
🔹 Launch Wizard + clone inputs for SAP
🔹 Polly + Neural TTS voice in Brazilian Portuguese
🔹 RDS for MariaDB + m6i/r6i instances
🔹 RDS for MySQL + m6i/r6i instances
🔹 RDS for PostgreSQL + m6i/r6i instances
🔹 Wavelength Zone + Toronto

#AWS_week
👍61
Forwarded from CloudSec Wine (Артем Марков)
🔶 AWS Security Fundamentals

Self-paced course to learn fundamental AWS cloud security concepts, including AWS access control, data encryption methods, and how network access to your AWS infrastructure can be secured.

https://explore.skillbuilder.aws/learn/course/external/view/elearning/48/aws-security-fundamentals-second-edition

#aws
👍62
​​Weekly Summary on AWS (May 1-7)

🔸 AMB (Amazon Managed Blockchain) + Goerli for Ethereum
🔸 AppConfig Feature Flag Lambda Extension + Arm/Graviton2
🔸 Braket Hybrid Jobs + embedded circuit simulators
🔸 CodeGuru Reviewer + suppress recommendations
🔸 Compute Optimizer + 4 new Trusted Advisor checks 👍
🔸 Connect
Schedule Manager + displays metrics
StopContact
Up to 6 participants on a customer service call
🔸 EKS console + info about the Kubernetes resources 👀
🔸 IoT Secure Tunneling + single-use token and token rotation
🔸 Kinesis Video Streams + image extraction
🔸 Lex + custom vocabulary
🔸 Outposts + RDS storage autoscaling
🔸 Quicksight line chart + 2 50010 000 data points
🔸 RDS for PostgreSQL + cascading read replicas for 14.1+ 👈
🔸 RDS Performance Insights + custom time window
🔸 SageMaker Canvas + new data preparation features
🔸 SAM CLI + X-Ray
🔸 Service Catalog Provisioning constructs for AWS CDK

🔹 ElastiCache + new console
🔹 Panorama + Lenovo ThinkEdge SE70
🔹 RDS for SQL Server + SQL Server 2016 SP3, 2017 CU27, and 2019 CU15
🔹 Rekognition + Face API version 6
🔹 SageMaker Data Wrangler + M5/R5 instances

#AWS_week
👍41
​​Weekly Summary on AWS (May 8-14)

🔸 Amplify Android Library + Kotlin
🔸 Athena + Hive views
🔸 Backup Audit Manager + compliance status for VMware Virtual Machines
🔸 CloudWatch
AMI events 👍
CloudWatch Synthetics + canary resources deletion
Prometheus usage metrics
Secrets Manager usage metrics
🔸 EC2 NitroTPM & UEFI Secure Boot + GA 🎉
🔸 EKS Anywhere + curated packages 👀
🔸 EFS + locks per connection 819265536
🔸 GameKit for Unreal Engine + Android, iOS, and MacOS 🎉
🔸 IoT SiteWise + BatchGetAssetPropertyValueHistoryBatchGetAssetPropertyValue, and BatchGetAssetPropertyAggregates
🔸 Lambda + Node.js 16 💥
🔸 Lex + phrase hints
🔸 PrivateLink + IPv6 💪
🔸 SSO + delegated admin 👈
🔸 VPC
Multiple IPv6 CIDR blocks ⚠️
Traffic Mirroring + GWLB

🔹 FreeRTOS + Espressif, NXP and STMicroelectronics
🔹 SageMaker Notebook Instances + ml.g5 & Python 3.8
🔹 Step Functions + new console

#AWS_week
👍5