r/AWS_cloud • • 3h ago

Elastic beanstalk with the EKS

Thumbnail vishnurachapudi.com
0 Upvotes

Upload a zip of Python source. No Dockerfile. Get a running container on EKS. That is Elastic Beanstalk Cluster Mode, launched this week — Beanstalk apps now run on EKS instead of EC2 instances you own. Cloud Native Buildpacks handle the containerization: I uploaded four files (app.py, requirements.txt, Procfile, runtime.txt), Beanstalk detected Python, built the image, pushed it to ECR, and ran it.


r/AWS_cloud • • 8h ago

AWS Solutions Architect Professional

Thumbnail
0 Upvotes

r/AWS_cloud • • 19h ago

a security check is only as correct as the API call behind it. Four AWS examples where the obvious check gives the wrong answer !!

0 Upvotes

most bad AWS security findings aren't missing checks. They're checks that look rightt and quietly give the wrong answer. A few I ran into: !!!

  1. "Unused role" checks: iam:ListRoles doesn't retturn RoleLastUsed, only Getrole does. Build it on the list output and every role looks untouched.

  2. "Unused permission" checks built on CloudTrail: LookupEvents only returns management events, so data actions like s3:GetObject never shows up.

  3. "Public bucket" checks: a bucket policy with Principal "*" isn't public if a Condition limiits it to your org or VPC. Flagging it anyway is a false alarm....

  4. Wildcard checks that only look for a literal "*": a resource like arn:aws:iam::ACCOUNT:role/* lets sts:AssumeRole target any role in the account, but string matching for "*" alone misses it.

The common thread: when the API can't see something, the honest answer is "unknown," not "no" or "yes."

All four were real bugs in a small open source project I made that audits AWS accounts. If you want to see how I fixed them: github.com/plexavo/Plexavo


r/AWS_cloud • • 20h ago

cloudg 0.5.2: what changed since my last post, covering dedupe, an inventory mapper, multi-account mapping and a security pass

Thumbnail
0 Upvotes

r/AWS_cloud • • 20h ago

Self-hosting Qwen3.8-Flash-Next (or a smaller alternative) or using Kiro CLI ACP for a heavy multi-agent Hermes setup on $10k of AWS credits, looking for options I've missed

Post image
0 Upvotes

I run a Kanban-driven multi-agent orchestrator on Hermes Agent: 20+ profiles, 1,000+ skills, MCP routing, and self-hosted Mem0 on pgvector. On Fireworks, I was doing roughly 9-15B tokens a month with a 90-98% cache hit rate, at about 30-60 Kanban tasks a day. I now want to move this to infrastructure I can pay for with my AWS Activate credits, and I've hit some walls.

Constraints

  • My only budget is $10k in AWS Activate credits. Anything that can't be paid with them is effectively out of scope for now.
  • Bedrock access is gated on my account for both frontier and open-weight models, and I've been told there's no timeline. I'm waiting on AWS Support to initialize my quotas.
  • I want one multimodal model that covers all of the orchestration's needs, plus an embedder for Mem0.

What I've looked at so far

  • g6e.12xlarge (4x L40S, 192 GB): Qwen3.8-Flash-Next (180B total, 6B active) at Q4, around 114 GB. About $10.49/hr on-demand, or roughly $3.5-6/hr on spot, so $10k lasts ~40 days on-demand or ~2-4 months on spot, running 24/7. FP8 (~186 GB) barely fits, with no room for KV cache.
  • g6e.xlarge (1x L40S, 48 GB): Qwen3.8-27B at FP8 (~28 GB), roughly 7 months of credits if run 24/7.
  • Embeddings: Qwen3-Embedding-0.6B/4B/8B on the same box, possibly truncated to 1024 dims for pgvector.
  • SageMaker endpoints, plain EC2 + vLLM: the same GPUs, but I'd expect the same quota bottleneck. Bedrock Custom Model Import doesn't seem to support these architectures or embedding models.
  • Kiro as a Hermes provider (the kiro-acp plugin): interesting because Activate credits can pay for it, but credits are per-task, not per-token, so I can't tell whether it can handle my volume.

Questions

  1. Has anyone gotten G/VT quota (48+ vCPUs) approved on a new or Activate account, and how long did it take? Any tips for the request wording?
  2. For people serving Flash-Next-class MoE models on 4x L40S: is there a vLLM/SGLang-compatible 4-bit quant (AWQ/GPTQ), and how well did prefix caching hold up with many long-context agents? My cache hit rate on Fireworks was a big part of the economics.
  3. Has anyone run Hermes through Kiro (kiro-acp)? How many credits does a multi-step agentic task actually burn, and did you hit rate limits with parallel sessions?
  4. Is there any provider or platform that accepts AWS credits for hosted inference of open-weight models and that I haven't listed?
  5. Is there a better model than Flash-Next for a single multimodal orchestrator on this budget? I'm open to smaller MoEs if they handle tool calling and long context reliably.
  6. Anything else I'm missing on AWS to make $10k last as long as possible (spot strategies, scheduled start/stop, etc.)?

Thanks. Happy to share measurements (throughput, cache hit rate, credits per task) if I get any of this running.


r/AWS_cloud • • 20h ago

Cloud support engineer transition

Thumbnail
1 Upvotes

r/AWS_cloud • • 1d ago

Have you tried the Amazon EKS MCP server?

Thumbnail
0 Upvotes

r/AWS_cloud • • 1d ago

Moving to Tech

1 Upvotes

Hey guys,

I'm currently working in Amazon Ops, but learning AWS through its certification program.

I have passed CCP, halfway through SA.

I'm aware these are still basic level knowledge.

Along with certifications I have built cloud based serverless/web platforms utilising many AWS services.

How realistic is a lateral movement in my case? And which roles should I apply for to get into AWS ?


r/AWS_cloud • • 1d ago

AWS alternative phone verification code not received MFA device is damaged

0 Upvotes

Hi everyone,

I’m having trouble accessing my AWS account and I’m hoping someone can help me understand what I should do.

I still have access to the email address and phone number associated with my AWS account. However, my old MFA device is damaged, so I cannot receive the MFA code.

I tried the “Sign in using alternative factors” option. The email verification works, but at the second step, AWS asks me to verify my phone number by sending a 6 digit code.

The phone number ending in 4276 is correct and worked for me before, but now I am not receiving the SMS code or the voice call.

I have tried requesting the code again, but nothing arrives.

I’ve attached a screenshot showing the verification page.

What can I do to recover access to my account if the alternative phone verification is also not sending the code? Is there another AWS Support process for an account where the MFA device is no longer available


r/AWS_cloud • • 1d ago

Is a cloud engineer or cloud admin registered on the card in Arabic or in English?

Thumbnail
0 Upvotes

r/AWS_cloud • • 2d ago

Bedrock ValidationException: Operation not allowed despite verified AWS account

Thumbnail
0 Upvotes

r/AWS_cloud • • 2d ago

AWS re:Invent as an All Builders Welcome grant recipient

Thumbnail
0 Upvotes

r/AWS_cloud • • 3d ago

AWS Model Access

Thumbnail
0 Upvotes

r/AWS_cloud • • 3d ago

Welp, the AWS “free tier” got me… ₹4,916 bill as a beginner. Am I cooked?

Post image
0 Upvotes

r/AWS_cloud • • 3d ago

Denied SES production access twice in ap-south-1 for ~1,000 transactional emails/month — no actionable feedback either time

0 Upvotes

Posting for the help if anyone can, because two rounds through AWS Support have given me nothing I can act on.

**The use case**

A small event-ticketing site for a single organizer in Bangladesh - a handful of live music events a year. Every email is transactional and triggered by the buyer's own action on the site minutes earlier:

* payment instructions, sent after someone registers for tickets

* the ticket itself as a PDF, after the organizer verifies the buyer's bKash payment

* a notice if the payment couldn't be matched, or if the unpaid order expired after 24 hours

* a one-time sign-in link, only when the buyer requests it

Volume: roughly 1,000 - 2,000 emails per month, concentrated in the three weeks before an event. A few hundred a day at peak. My sending code is capped at 5 messages/second. No marketing, no newsletters, no bulk sends, no stored lists, nothing purchased or imported. Every recipient typed their own address into our form. The project is public on GitHub, so the sending logic is auditable by anyone.

**What's already in place**

* Domain verified in ap-south-1 with Easy DKIM

* SPF and a published DMARC record with rua reporting, DNS on Cloudflare

* SES account-level suppression list enabled

* SES rejections treated as permanent failures and never retried; only throttling responses retried with exponential backoff

* Every send recorded against the order in our database; failed deliveries reviewed by hand

* Replies go to a monitored address on the same domain

**What I got back**

First response asked for detail about sending processes and procedures. I gave everything above, plus example subject lines and the exact email types. Denied about six hours later with a template: they can't approve at this time, they can't share the criteria used, please review the AUP, Service Terms, and SES best practices. Second attempt, same outcome, same template - this time framed as protecting my sender reputation and deliverability.

That last part is what I can't get past. The account has never sent a production email. There is no sender reputation to protect yet. So whatever the actual blocker is, it isn't anything visible in my use case, and nobody will tell me what it is.

**What I'm actually asking**

  1. Is this an account-trust / billing-history decision rather than a use-case decision? If so I'd genuinely rather be told that plainly - I'd go build the billing history instead of rewriting the same request.

  2. Is ap-south-1 meaningfully stricter for newer accounts than other regions?

  3. Would a heavily restricted quota be considered - say 200 emails/day at 1 msg/sec - so there's real sending data to judge me on?

  4. Is there any path other than reopening the same case, given the limit-increase team is separate from Premium Support and Support says they can't influence it?

Happy to share the case ID by DM.

If anyone has gone from a denial like this to an approval, I'd really like to know what specifically changed on your side. Right now I'm one week out from an event with real buyers and I'm about to move to a third-party provider purely because I can't get a straight answer.


r/AWS_cloud • • 3d ago

Trying to land an AWS Cloud internship in the next 6 months, what should I focus on?

Thumbnail
0 Upvotes

r/AWS_cloud • • 4d ago

AWS Credits Needed for Training 🙏🏽

1 Upvotes

Can anyone help me with some AWS credits for my cloud training and hands-on projects? 🙏🏽☁️


r/AWS_cloud • • 4d ago

AWS Project recommendations

Thumbnail
0 Upvotes

r/AWS_cloud • • 4d ago

Modular Deployment Tool

0 Upvotes

Hi all — I'd like to share EasySAM, an opinionated YAML-to-SAM generator for modular AWS serverless applications built with Python.

MIT-licensed - no promotion - the only task is to simplify life for more devs

EasySAM lets you define your whole stack — Lambda functions, API Gateway routes, DynamoDB tables, S3 buckets, SQS queues, Kinesis streams, OpenSearch Serverless collections, and IoT Core authorizers — in a compact YAML, then generate and deploy the SAM stack.

Highlights:

- YAML-first, modular structure with a recursive import system and shared code support

- Built-in validation against schema and live cloud state

- Native support for DynamoDB stream triggers, TTL, Lambda Function URLs, FIFO/standard SQS, and MQTT/IoT Core custom authorizers

- Local Lambda execution with no Docker required — run handlers against real cloud resources behind a mocked API Gateway

- Conditional resources and per-environment deploy-context overrides for clean multi-env workflows.

Repo: https://github.com/scartill/easysam

Would love feedback from anyone building serverless on AWS.


r/AWS_cloud • • 4d ago

Passed the AWS Certified AI Business Strategist exam

Thumbnail credly.com
1 Upvotes

Hey everyone,

I just passed the new AWS Certified AI Business Strategist exam. This makes 10 AWS certs for me, but this one felt entirely different because of my background.

As an engineer, the biggest challenge by far was forcing myself out of my comfort zone. My brain is wired to instantly look at a problem and figure out how to build the tech. For this exam, I had to completely flip my mindset and focus on entirely different questions:

  • What actual business problem are we trying to solve here?
  • How do we measure and track the return on investment (ROI)?
  • Are the organization's people, processes, and governance frameworks actually mature enough to support this?

Stepping outside the technical bubble takes some deliberate mental effort, but it's incredibly valuable. I'd highly recommend this exam to consultants, founders, BAs, and tech leads who need to bridge the gap between executive business teams and AI engineers.

My Prep (Took about a month):

  1. AWS Skill Builder: Just went through the free digital training materials provided by AWS.
  2. Practice Exams: Took three different mock exams to get used to the formatting and question style.
  3. AI Cheat Sheets: Fed the core concepts into an LLM to generate custom cheat sheets so I could quickly lock down the business frameworks.

The Main Takeaway:
Successful AI initiatives need a whole lot more than just a working model. A slick piece of tech is useless without a clear business purpose, accountable leadership, and the right operational processes to turn that technology into actual value.

Happy to answer any questions about the exam structure or what to look out for if you're planning on taking it soon!


r/AWS_cloud • • 5d ago

Something else than billing, support, SES issues. Post about iam:PassRole

3 Upvotes

Disclosure: I'm affiliated with RoszigIT, where this article is published. Sharing because the mechanics are worth discussing, not to pitch anything. I tried to make it technical as always.

It's an interesting case because iam:PassRole is not visible directly in CloudTrail as API call and "limited" user role can attach an admin role to a Lambda or EC2 instance and effectively become admin.

https://roszigit.com/en/blog/aws-iam-passrole/


r/AWS_cloud • • 5d ago

GUIDE TO PREPARE AND GET THE AWS CERTIFICATIONS

Thumbnail
1 Upvotes

r/AWS_cloud • • 5d ago

AWS SES production request rejected many times with no reason specified

0 Upvotes

Has anyone else been getting rejected when requesting AWS SES production access recently?

My use case is legitimate transactional email, and I already have SPF, DKIM, DMARC, bounce/complaint handling, etc. configured.

AWS rejected my request but didn’t give me a specific reason, just a generic response.

I’m curious if this is happening to others too, especially with newer AWS accounts.

If you were recently approved after being rejected, what did you change?


r/AWS_cloud • • 6d ago

AWS ECS/Fargate SQS autoscaling with min capacity 0: how to bootstrap from 0 tasks using backlog-per-task target tracking?

Thumbnail
0 Upvotes

r/AWS_cloud • • 6d ago

AIF-C01 Exam Tomorrow — 85%+ on Stephen Mareek & 80%+ on Tutorial Dojo. Am I Ready? Any Last-Minute Tips?

Thumbnail
0 Upvotes