AWS Notes
5.59K subscribers
449 photos
42 videos
10 files
2.8K links
AWS Notes — Amazon Web Services Educational and Information Channel

Chat: https://t.iss.one/aws_notes_chat

Contacts: @apple_rom, https://www.linkedin.com/in/roman-siewko/
Download Telegram
Forwarded from Max Skutin
Issue 43 | 24 October – 30 October, 2022

▪️ App Runner PHP, Go, .Net, and Ruby managed runtimes
▪️ Aurora
     ▫️ cluster export to S3
     ▫️ MySQL 2.11 with R6i instance support | GA
▪️ Batch
     ▫️ 4x compute and memory for Fargate jobs
     ▫️ EKS support
▪️ CDK For Kubernetes CDK8s+ and manifest validation support | GA
▪️ CloudWatch RUM
     ▫️ custom metadata attributes
     ▫️ Extended CloudWatch Metrics
▪️ Cognito
     ▫️ user pool deletion protection
     ▫️ real-time schedule adherence
▪️ Console Mobile Application CloudShell support
▪️ DataSync self-signed certificates
▪️ EC2
     ▫️  i4i.metal instance for VMware Cloud | GA
     ▫️ High Memory instances with 18/24TiB with On-Demand and Savings Plans
     ▫️ Replace Root Volume
▪️ Elemental MediaConnect flow alerts
▪️ EMR Hive Metastore check command optimization and Parquet Modular Encryption
▪️ Fault Injection Simulator network connectivity disruption
▪️ Global Accelerator AddEndpoints and RemoveEndpoints APIs
▪️ IAM Access Analyzer identify public and cross-account access
▪️ Local Zones first deployment in Europe (Hamburg and Warsaw) | GA
▪️ Location Service +2 HERE map styles
▪️ MSK
     ▫️ Apache Kafka version 3.3.1
     ▫️ Connect supports private DNS hostnames
     ▫️ new low-cost storage tier
▪️ Neptune Serverless is now generally available | GA
▪️ Organizations centrally manage POC on AWS accounts
▪️ Pinpoint console now supports pool management
▪️ Private Certificate Authority short-lived certificates
▪️ Programs
     ▫️ Control Tower delivery and ready program
     ▫️ EKS Delivery Program
     ▫️ OpenSearch Service delivery program
▪️ QuickSight
     ▫️ Customer Managed Keys (CMK) for SPICE data encryption
     ▫️ Row Level Security (RLS) on Dataset-as-a-source
▪️ RDS
▫️ events for operating system updates
▫️ memory optimized R5b instance types for Oracle
▪️ Redshift Query Editor SQL Notebooks | GA
▪️ S3 Replication SSE-C encrypted objects
▪️ SageMaker
     ▫️ 8 new Graviton-based instances for model deployment
     ▫️ Automatic Model Tuning Grid Search support
     ▫️ Canvas supports tags to track and allocate costs
     ▫️ Model Monitor Batch Transform jobs
     ▫️ Multi Model Endpoint
▪️ WAF Challenge rule action and Bot Control for Targeted Bots
▪️ WorkSpaces Web Access bi-directional audio/video
👍8
​​🆕 Transfer Elastic IP addresses from one AWS account to another:

https://docs.aws.amazon.com/vpc/latest/userguide/vpc-eips.html#transfer-EIPs-intro

You can transfer Elastic IP addresses to accounts within the same AWS Organization.
You can transfer Elastic IP addresses to standalone AWS accounts outside of AWS Organization.
You can transfer Elastic IP addresses only within the same AWS Region.
You cannot transfer Elastic IP addresses between AWS Organizations.

When you transfer an Elastic IP address, there is a two-step handshake between AWS accounts:
▪️ the source account (either a standard AWS account or an AWS Organizations account) and the transfer accounts.
▪️ when the source account starts the transfer, the transfer accounts have seven hours to accept the Elastic IP address transfer, or the Elastic IP address will return to its original owner.

#VPC
🔥10👍2🎉1
Forwarded from Egor Miasnikov
Всем привет! AWS запустил Specialty Certification Challenge и при регистрации можно получить 50% скидку на экзамены - https://pages.awscloud.com/GLOBAL-ln-GC-TrainCert-Specialty-Certification-Challenge-2022-reg.html
👍9🔥1
​​AWS services that support IPv6:

https://docs.aws.amazon.com/general/latest/gr/aws-ipv6-support.html#ipv6-service-support

p.s. My forecast is that the picture can seriously change in a month. 😀

#IPv6
👍4
🎉15🔥4👍3😢1💩1
🔥26🤔1
Forwarded from Max Skutin
Issue 44 | 31 October – 6 November, 2022

▪️AMS now supports SQL Server on EC2 Operations
▪️App Runner VPC Support
▪️AppStream certificate-based authentication
▪️Braket Aquila - neutral atom quantum processor
▪️CloudFormation
    - RDS Multi-AZ deployments with two readable standbys
    - StackSets improves insights on stack instances
▪️Connect
    - DismissUserContact API | GA
   - Customer Profiles extra customer info
    - quick connects new UI, Cloudtrail support
▪️Copilot support App Runner’s privately accessible services
▪️EC2 opt out of directly shared AMI
▪️EMR on EKS cross-job parameter sharing with job templates
▪️IoT Core Location Action
▪️Kinesis Data Streams inspect data records via console
▪️Launch Wizard
    - Host Auto Failover for FSx NetApp ONTAP and SAP HANA
    - placing MSSQL tempdb in an instance store
▪️MemoryDB Redis data tiering
▪️Migration Hub Orchestrator MSSQL migration
▪️ParallelCluster multiple instance type allocation
▪️Polly Dutch NTTS voice
▪️RDS
    - Custom for SQL scaling storage
    - RDS Multi-AZ 2x faster transaction commit latency
▪️S3 on Outposts new Lifecycle actions and filters
▪️SageMaker Autopilot
    - 2x faster experiments in Hyperparameter Optimization training mode
    - AutoML experiment feature selection and data type change
▪️Security Hub new integration partner Wiz
▪️SES Virtual Deliverability Manager
▪️SNS real-time data redaction, data masking, data protection | GA
▪️Textract
    - Analyze Expense API
    - Analyze ID API
    - new forms and text extraction features
▪️VPC cross-account Elastic IP transfer
▪️WAF Granular Geographic Match
👍7
Forwarded from Boris Golynski
Что-то Dynamo DB от Маарека заходила с трудом, поискал в ютубе русскоязычное и неожиданно наткнулся на весьма годный ролик, пусть и немного староватый. Рекомендую: https://www.youtube.com/watch?v=ldV512UFkmY
👍8
AWS Outpost - полностью управляемое решение, которое позволяет пользователям вынести инфраструктуру AWS, включая сервисы, API и инструменты в собственный центр обработки данных. И теперь AWS Outposts можно заказать в Казахстан, совместно с @RinatUzbekov и @igor_sh_aws - рассказали что за зверь такой AWS Outposts, для каких целей он потребуется, какие сервисы будут доступны на нем. Демо как заказать AWS Outposts и какой процесс доставки оплаты, все это и не только в нашем видео подкасте. Для вашего удобства есть тайм-коды.
#podcast

Посмотреть и послушать можно тут:

- Видео формат - YouTube
- Apple Podcasts
- Google Podcasts
- Spotify
- PodBean
- Yandex Music
🔥13
Новый AWS Region — Цюрих, Швейцария: 🎉

https://aws.amazon.com/blogs/aws/a-new-aws-region-opens-in-switzerland/

Седьмой (!) на текущий момент в Европе, идентификатор eu-central-2. Как и в подавляющем большинстве других регионов, имеет 3 AZ.

Итого на теперь всего — 28 регионов.

#AWS_Regions
👍13🔥10👏3
​​🆕 AWS Resource Explorer:

https://aws.amazon.com/blogs/aws/introducing-aws-resource-explorer-quickly-find-resources-in-your-aws-account/

Search for resources in all regions at once.
You can search directly from the console by typing /Resources (in the picture).
Free!
So far, you can search inside only one account.

#Resource_Explorer
🔥8👍1
Forwarded from AWS User Group Tashkent
It's happening today!

We are starting our session today at 6:30PM at Westminster International University.


📌 LOCATION: Istikbol Building, Floor 2, Room 201.

Guests will be admitted from the main entry at Istikbol Street.


❗️PLEASE BRING YOUR PASSPORT, AS UNIVERSITY POLICY REQUIRE ALL GUESTS TO PRESENT A VALID FORM OF ID.

If you have any questions, you can ask them in our Telegram chat.
👍2🔥2
🆕 EventBridge Scheduler: 🎉🎉🎉

https://aws.amazon.com/blogs/compute/introducing-amazon-eventbridge-scheduler/

EventBridge Scheduler provides at-least-once event delivery to targets, and you can create schedules that adjust to different delivery patterns:

Time window allows you to start a schedule within a window of time. This means that the scheduled tasks are dispersed across the time window to reduce the impact of multiple requests on downstream services.
Maximum retention time of the event is the maximum time to keep an unprocessed event in the scheduler. If the target is not responding during this time, the event is dropped or sent to a DLQ.
🔁 Retries with exponential backoff help to retry a failed task with delayed attempts. This improves the success of the task when the target is available.
✉️ A dead letter queue is an SQS queue where events that failed to get delivered to the target are routed.

By default, EventBridge Scheduler tries to send the event for 24 hours and a maximum of 185 times.

⚠️ Quota on schedules: 1 million per account (soft limit)

#EventBridge
👍5🎉2
​​«Эффективное масштабирование кластеров Kubernetes с помощью Karpenter» - Виктор Ведмич, AWS.
Видео с DevOpsDays Almaty 11 ноября 2022 года, ссылка с отметкой времени на начало доклада:

https://youtu.be/xR_d-Z-BbPg?t=10044

#video
👍19
Forwarded from AWS Weekly
Issue #45 | 7 November – 13 November 2022

▪️ Amazon Time Sync public NTP service | guide
▪️ AppConfig achieves FedRAMP High Authority To Operate
▪️ Athena Query Result Reuse to accelerate queries
▪️ Aurora logical replication cache
▪️ Aurora Serverless v2 is now available in 20 regions
▪️ Backup VMware to EC2 workloads restore
▪️ Billing Conductor recurring custom line items
▪️ Certificate Manager ECDSA P-256 TLS certificates support
▪️ CloudTrail delegated administrator account
▪️ CloudTrail Lake Customer Managed KMS Keys (CMK) encryption
▪️ CloudWatch Logs export to SSE-KMS encrypted S3 buckets
▪️ Config 14 new resource types
▪️ EC2
| attribute-based instance type selection for ASG, EC2 Fleet, and Spot Fleet
| macOS Ventura support
| placement groups cross-account sharing
| price and capacity optimized allocation strategy for Spot Instances
▪️ ECS task scale-in protection | blog
▪️ ElastiCache IPv6 support | Redis 7 support
▪️ EventBridge New Scheduler | new
▪️ Firewall Manager import existing Network Firewall resources
▪️ Ground Station Customer Provided Ephemeris | in preview
▪️ IoT Device Defender audit check of revoked intermediate CA
▪️ Kendra is now FedRAMP High Compliant
▪️ Keyspaces Murmur3Partioner support
▪️ Lambda new Telemetry API | blog
▪️ Lightsail domain registration and DNS autoconfiguration
▪️ OpenSearch Service cross-VPC connectivity with PrivateLink
▪️ Polly Swedish, Norwegian and Finnish | VPC Support | GA
▪️ Private 5G multiple radio-units support
▪️ QuickSight send SPICE consumption metrics to CloudWatch
▪️ RDS for SQL Access to Transaction Log Backups
▪️ RDS new GP3 storage volumes support: no multi-az
▪️ Resource Explorer resource search and discovery service | GA
▪️ SageMaker Canvas
| correlation matrices for advanced data analysis
| customer managed keys for time series forecast models
| Stable Diffusion and Bloom models
| TensorFlow Text Classification algorithms
▪️ Secrets Manager API RPS limit increase
▪️ Security Hub CIS Benchmark 1.4.0
▪️ SNS subscription filter policies quota increase by 50x
▪️ VPC IPv6 Subnet default GR now supports multiple addresses
▪️ Wavelength Zone in Manchester
▪️ Well-Architected Tool speed up reviews with workload discovery
▪️ WorkSpaces WSP protocol API
👍9
Хорошие комментарии от Андрея Девяткина по AWS Startup Security Baseline:

https://fivexl.io/blog/fivexl-reaction/

Особенно солидарен по пункту Enforce a password policy, ведь IAM users в идеале быть не должно вообще, потому этот пункту заведомо ущербный.

📓 AWS Prescriptive Guidance — AWS Startup Security Baseline (AWS SSB)

#security
👍3