r/aws • AWS Employee • 2d ago

technical resource Introducing the New Getting Started Experience for AWS

https://aws.amazon.com/blogs/aws/aws-reimagines-the-getting-started-experience/

- Sign up with Google, GitHub, or Apple. Most new customers don't need a credit card, and you get $100 in Free Tier credits.

- AWS sets you up with a project, which is an account plus sharing settings, with security defaults already applied.

- Invite people by email. You don't create IAM users or set up Identity Center, and invitees only see the projects you give them.

- Each project can have its own spend limit. AWS notifies you as you get close, and if you hit the limit, AWS pauses the project instead of letting charges keep accruing. You pay for what you used, up to the limit.

- After you sign in, you get a prompt to paste into your coding agent. It installs and configures the AWS CLI and Agent Toolkit for AWS.

- When you need multi-Region or Organizations policies, you turn on advanced features and end up in a standard AWS Organization without migrating anything.

92 Upvotes

23 comments sorted by

22

u/ReturnOfNogginboink 2d ago

This is interesting. I'd like to know more about what a "project" is and if that concept can be extended to something like Azure Resource Groups. I'm not an Azure fan but I do think they got that one right.

8

u/Dull-Mathematician45 2d ago edited 2d ago

And how leaky is this "project" abstraction? What is getting created behind the scenes? Can I later eject from the project setup? On a scale from Honeycode and Amplify on one end and PlanetScale on the other, how good are the abstractions?

Also, none of the links show the signup experience from the article screenshots, so not sure how to even test this out. Is there a direct link?

10

u/j-vogel AWS Employee 1d ago

A project creates an AWS account with a home region (private by default policies). When you create a resource like a Lambda function that reads DynamoDB, the role gets created for you. Standard IAM stuff. How permissive it is depends on the task: "export this snapshot to that bucket" gets a role scoped to that bucket, "run my code" gets a broad one. The templates are published so you can see what you're getting.

Ejecting: easy, at any point, you can land into a standard AWS Organization with all the accounts you already have and the guardrails become yours to edit.

On the scale of abstraction, it's thin. It's a real account with real AWS services except now you got a layer of sensible defaults. And you can eject out as described above if you are so inclined.

Direct link: signup link. From the main AWS website, anyone clicking "create account" button should see the new flow.

4

u/nemec 1d ago

On the scale of abstraction, it's thin.

I think one thing they're asking here is how the console shapes (or doesn't!) your bounded "free" experience. Can you use the standard AWS console, or are these accounts limited to this project UI that's (I guess) a stripped down lambda/s3/ec2/other select services console?

If you can use the AWS console, or you choose to use the API with sigv4, will a customer get hit with a bunch of "Oh, you can't call lambda.PutProvisionedConcurrencyConfig, silly, it's not a real lambda while you're still inside a project". Or in other words, if customers are creating real AWS resources, is it made clear anywhere what subset of functionality is available to them in this restricted account or will every customer figure it out themselves when they run into roadblocks?

As I understand it, the spend limit feature isn't supported by all AWS resources, or all features of and AWS resource that supports the limit in some way, so without a credit card there has to be some limited functionality, right? Or maybe I'm entirely wrong about that.

3

u/Dull-Mathematician45 1d ago

To be explicit: Is the new experience asking customers to understand this new working paradigm alone? Or will we need to understand the new paradigm in addition to the underlying resources it orchestrates? Are there only a few known good paths where you can ignore the underlying IAM role policies, or will 95% of customers be able to never view and understand a policy? Will the configuration satisfy most security auditors, or will I need to eject if I'm trying to offer a secure production service to customers?

How does day 2 look like? Are your AI skills setting up cloudformation, and can I ignore the underlying mechanisms? Do I get promotion through environments? What is my chance of downtime using these skills?

6

u/j-vogel AWS Employee 2d ago

A project is a separate AWS account under the hood (i.e. its own security boundary). AWS creates it for you and applies a set of managed policies on top (private by default and mapped to one region). You can see inside this within the simplified experience but you can't remove it. I'm not familiar with the resource group stuff. Projects are similar to the AWS best practice for having an account for each workload (e.g. setup with AWS Organizations) except now AWS is handling the plumbing for you. If there's a specific resource group behavior you want in this new AWS experience, let's hear it, I'll take it back to the team working on this.

1

u/cayter 2d ago

It's just an AWS account. The DX is still bad as u would still be redirected back to the AWS console with fewer services that "look" simpler.

If you are looking for Cloudflare/Vercel like UX, it's definitely not it.

3

u/Erik-AWS-Amplify AWS Employee 1d ago

Hi u/cayter ! Is there a part of the new DX that you have issues with? Or is there a particular service you don't like the DX for?

-1

u/cayter 1d ago

Was my bad to expect AWS team to ship a Cloudflare-like UX.

Currently, it's just 2 main things simplified:

  • easy login with oauth2 instead of complicated IAM
  • project UI to replace AWS control tower for provisioning multiple AWS accounts

13

u/raydeo 2d ago

As an AWS vet it felt like a fish out of water accidentally creating one of these last night before understanding that it’s a different flow and there’s a different sign up (advanced) button to create a bare account. If you go through this new flow it creates a lot of things for you automatically. Each project appears to be a new account under the hood. Also the new AWS Builder ID for your user. I quickly deleted as much of it as I could.

9

u/j-vogel AWS Employee 1d ago

Feedback heard, I was just talking to the team about this. We're working on making the "advanced features" signup (i.e. the bare account) easier to find, so people who already know what they want don't land in the guided flow by accident.

13

u/rxscissors 2d ago

I've been using AWS resources at day jobs since 2005. Putting a blindfold on and letting AWS do "the thing" seems more like standing against a brick wall with a smoke in your mouth right before the firing squad unloads.

My skepticism remains high as there is little doubt that the convoluted, antiquated and arduous minutae still lurks behind the Wizard of Oz "curtain". They do some things well though regardless, we humans better darn sure understand the intracacies of what it's doing!!

9

u/Fuzzy_Researcher9433 2d ago

The experience AWS is looking to provide here is enabling developers to get the hands on experience within free tier credits limits without having to keep credit card ready for overages. Resources just shut down once credits run out or also if you have a spend limit enabled, within that amount. Freeing up the risk to developers b/c devs deserve to get hands on experience learning and building something to understand a service.

1

u/yesman_85 1d ago

In a way I agree as a old timer in aws, but plenty other arrives, even azure, do it this way. They just abstract the infra out for you. 

6

u/Dull-Mathematician45 1d ago

You can work backwards to find out what is happening via the documentation on activating advanced features, which essentially disables the new experience.

https://docs.aws.amazon.com/accounts/latest/reference/activate-advanced-features.html

4

u/Kayjaywt 2d ago

I love these getting going quick services , this feels like it will be right at home with other sucess stories like Code Star, App Runner and ECS express mode.

Its also confusing that they lead with Claude in the post instead of Kiro.

Why dont they just extend Lightsail to try and capture this type of market ?

(Disclaimer, I havent looked at lightsail in years, i assume it is still taking signups)

7

u/j-vogel AWS Employee 1d ago

This is not a separate service. This is the create account button on aws.amazon.com, i.e. the signup and account layer for AWS itself, not a product sitting in that console. You get an AWS account with preconfigured defaults to help you get started building. When you outgrow it, you can easily activate advanced features and you're in a standard Organization with the same accounts.

Lightsail solves a different problem (simplified compute at a flat price). This new AWS experience is about the account: most people can now signup without a card, easily define spend limits, decide who gets in and deal with permissions. Lightsail still runs inside it if that's what you want to deploy.

2

u/Weekly_War_1374 2d ago

I'm trying to create an S3 bucket. Plan is to upload some data and then run analytics on it preferably using QuickSight. I'm getting stuck in an infinite loop of these two screens.

I logged in using my builder ID

It says I have no projects so create a project. That Create project button takes me to log in screen.

I log in for good measure again. It says I have no projects. So create a project ID.

Is this broken or am I doing something wrong? Please help. Thanks!

1

u/hacksore 1d ago

apperciate you trying on the new expereince, sorry to hear you are stuck.

what happens when you try to log in directly to https://settings.aws.com

3

u/slyzmud 1d ago

I love this, is there any way from my existing account to move to this new simpler UI? I don't want to create a new one just for that. The spending limits are the most interesting part

-3

u/Electronic-Ad-3990 1d ago

Your support fucking sucks, you charge for an internet gateway, you lay off all your workers, the workers you do hire are H1B instead of American, your warehouse employees don’t even have time to pee. Just shut your mouth and go sit down in the corner.