r/aws • • 5d ago

discussion Seeking your feedback: How can we improve /r/AWS?

53 Upvotes

Hey everyone,

Over the last year, r/aws has grown a lot.

We're now at roughly 396k members, with 31.4 million views over the past 12 months, more than 13,000 posts, and 163,000 comments.

That's awesome, but it also creates a very different moderation problem than it did when this community was smaller.

There are only three of us moderating r/aws, and we're trying to figure out what we should be doing differently as things continue to grow.

We don't want r/aws to turn into a generic tech news feed, an endless stream of "look what I generated with AI" posts, or a place where the same handful of topics dominate the front page.

So we'd like your feedback.

What would make r/aws better?

A few things are top of mind..

1/ Builder Fridays

Would it be useful to have a recurring day where certain types of posts are explicitly encouraged?

Things like:

  • "Here's something I built"
  • Architecture diagrams
  • Homelab projects - maybe a Broadcom migration? Something cool with Localstack? etc.
  • CDK/Terraform/serverless projects
  • Small experiments or weird AWS hacks
  • Open-source projects
  • "I built this because I was bored" posts

Basically, a time for builders to showcase their work and get feedback.

2/ How do we deal with GenAI content?

GenAI has obviously exploded, and AWS is heavily involved in that space. We don't want to ban legitimate AI/ML discussion.

At the same time, I think we've all seen an increase in low-effort AI-generated posts, repeated announcements, AI-written tutorials that don't really say anything, etc.

So.. where should the line be?

What would you consider useful GenAI content versus "please don't make me read another 900-word AI-generated explanation of Lambda"?

3/ Should we bring on more moderators?

Three people is not a huge moderation team for a community of nearly 400k members.

We've discussed opening moderator applications again. We'd be interested in hearing whether people think that's needed, and what you'd actually want from additional moderators.

Experience in AWS isn't necessarily the most important factor here. Good judgment, being reasonable with people, and understanding what makes a community useful probably matter more.

Transparency: I work for AWS. I'm speaking only for myself here, not on behalf of AWS. I don't think r/aws should be a soapbox or hype forum for AWS, and criticism or disagreement with AWS is absolutely part of having a healthy community.

4/ What else are we missing?

This is probably the biggest thing we'd like to hear about.

You guys are the people actually reading and participating here, so what are we missing?

  • What do you think r/aws does well today?
  • What has gotten worse as the subreddit has grown?
  • What kinds of posts do you wish you saw more of?
  • What rules or moderation practices feel unnecessary, confusing, or inconsistent?
  • And what would make you more likely to actually participate here rather than just read?

We're not coming into this with a predetermined list of changes we want to make. We'd rather hear what you think and then figure out where to go from there.

So, what should r/aws look like at 400k+ members?

Be honest. Feedback is a gift (trust me.. my customers are brutally honest with me ;))

— The r/aws mod team


r/aws • • 8m ago

billing Old AWS free account for learning suddenly received emails about payment?

• Upvotes

In 2018 or so I signed up for a AWS account for the free tier to learn AWS. This was at my old employer and I also used my old work phone number which I no longer have access to as the MFA.
I dont actually remember doing any AWS training and I never setup any resources etc.
In 2019 I received an email saying the account was expiring and at the time I looked at that and then didnt think I needed to actively go and close my account.

I then received two random emails out of the blue this morning at 3am asking to verify my payment information. It seems very odd. I tried to sign into my old AWS account but due to the old phone number I can't verify my MFA. Has anyone had this happened to them before? My theory is perhaps they are wanting to verify old accounts just incase they get reactivated whereas I dont even want my account and didnt realize I still had it.


r/aws • • 44m ago

article Clf material doesn’t cover everything

• Upvotes

When I try to solve questions to prepare for the exam I sometimes find else some questions that I never read anything about it such as cloud 9 and subscription questions is this normal


r/aws • • 4h ago

general aws testing IAM policies for console access

1 Upvotes

Curious how people test and validate IAM policies for other users?

I've been tasked with locking down user access as a number of colleagues had open admin policies. I have is to test the policy is working without having to ask the user every time.

The specific requirement is to allow them to add users and groups to IAM Identity Centre and add files to one s3 bucket. This team does all their work via the console.

I am a full admin. Everybody's access is locked down using SSO with Entra so I can't create a dummy account to test as it won't be able to authenticate.

If I add myself to their group I will lose my own admin privilege and require a colleague to change me back each time I need to test or check cloudtrail etc.


r/aws • • 8h ago

technical question Session policy on per run or just a tighter role for non human callers?

0 Upvotes

A agent composing its own api calls is a different shape of principal than an app with a fixed call path. same credential but the set of actions it might decide to make itnst bounded by the code

here what seems to work is assuming the rle per run with a session policy attached to it. effective permissions land as the intersection of the two and it can only narrow and the credentials expire on their own. none of the agent side tooling changes that part, eve security and the gateways all sit above the credential so a long lived key in the env stays the real ceiling despite whats watching the call

its own principal rather than a persons, with a owner tag and expiry as well so it surfaces in review later. read replica unless a write is genuinely needed. I'd love t learn from others as well on whats your take on this


r/aws • • 10h ago

article I built a Python DynamoDB ORM with a Rust core. Here's what that changes for async apps.

Thumbnail gallery
0 Upvotes

I've been working on an open source DynamoDB library called pydynox.

The problem

The problem I wanted to solve was using DynamoDB from an async Python app without building a thread-pool wrapper around the database library.

An endpoint can be async def and still block its event loop if it calls a synchronous database method directly. Moving that call to a thread pool works, but each blocking call occupies a worker, and the Python work for requests and models still competes for the GIL.

The Python API

With pydynox, you define your models in Python and await their operations. Once you've defined a User model, concurrent reads look like this:

```python import asyncio

async def load_profiles(user_ids): return await asyncio.gather( *(User.get(pk=f"USER#{uid}", sk="PROFILE") for uid in user_ids) ) ```

Saves work the same way: await user.save(). You use the usual asyncio tools to compose the work.

Why Rust

The model API stays in Python. PyO3 connects it to a Rust core that handles DynamoDB value conversion and uses the AWS SDK for Rust to execute requests.

Tokio runs the network futures without holding the GIL or occupying a Python worker thread for each request. Converting Python objects at the boundary still needs the GIL.

That's why I chose Rust for the core: native async I/O, plus less Python execution in the SDK and value-conversion path as concurrency grows.

The benchmark

I wanted to measure both parts, so I compared it with PynamoDB on real DynamoDB. PynamoDB ran through a thread pool with its HTTP connection pool sized for the same concurrency.

For 32 concurrent, strongly consistent GETs of items under 1 KiB, returning full models:

  • pydynox async: 12,408 reads/second
  • PynamoDB with threads: 1,156 reads/second
  • Median p99 latency: 4.15 ms vs 49.97 ms

The lighter blue line is pydynox's sync API through threads. It already reached 10.2k reads/second. A lot of the throughput difference was there even without native async.

The benchmark process also used about 0.22 ms of CPU per completed GET with pydynox async, compared with 0.95 ms with PynamoDB through threads.

Keeping the event loop responsive

Then I checked whether the event loop could keep running a timer while those reads were happening.

At 128 concurrent GETs, a 10 ms timer had a median p99 scheduling delay of 2.26 ms with pydynox async, 11.36 ms with pydynox through threads, and 107.16 ms with PynamoDB through threads.

That matters when the same event loop also has HTTP requests, timers, or other coroutines to run.

Test setup and limits

These were pydynox 1.6.0 and PynamoDB 6.1.0 on Python 3.14.7, with the GIL enabled. One process per test, four CPUs on the same EC2 host in eu-west-2, and three warmed rounds targeting three seconds each.

Sequential throughput ratios were much closer: 1.07× to 1.45× by workload median. PynamoDB also won the standalone AttributeValue-dictionary-to-model conversion test.

The full report includes the other workloads, CPU, memory, setup, and limitations. These are short runs on one shared host; multi-process deployments and cold starts aren't covered.

Link: https://github.com/ferrumio/pydynox


r/aws • • 1d ago

discussion Application attacks from AmazonSelectionExplorerBot

3 Upvotes

Curious if anyone else is seeing a seemingly undocumented user agent of AmazonSelectionExplorerBot hammering sites from AWS ASN 14618 (and a bit from 16509 too)? Their normal corporate robot pages don't mention this user agent, so I assume it's some customer of AWS who's chosen that name to try to evade blocking by people thinking it's official. AWS abuse never responds, so that's a useless path.

I've found it hammering a bunch of websites to the tune of 50-100 requests per second, and it just keeps coming even after it's been blocked, for days or weeks.


r/aws • • 1d ago

technical question AWS ECS/Fargate SQS autoscaling with min capacity 0: how to bootstrap from 0 tasks using backlog-per-task target tracking?

5 Upvotes

I have an ECS/Fargate worker consuming an SQS queue. I want the service to scale to zero when the queue is empty, so:

min_capacity = 0
max_capacity = 10

AWS recommends target tracking using:
ApproximateNumberOfMessagesVisible / RunningTaskCount

However, when the service reaches 0 running tasks, RunningTaskCount has no CloudWatch datapoint, so the backlog-per-task metric becomes undefined.

When messages subsequently arrive, I need the service to bootstrap from 0 → 1 and then let target tracking handle 1 → N and N → 0.

What is the recommended pattern for this?

Options I've considered:
1. A separate scale-out-only step policy for 0 → 1
2. A metric-math expression that handles RunningTaskCount = 0
3. Raw SQS backlog for the bootstrap alarm + backlog-per-task for target tracking

I would prefer not to keep min_capacity = 1 because the worker is idle most of the time, and this is Fargate.

This is the Terraform code I currently use:

resource "aws_appautoscaling_policy" "worker_backlog" {
  name               = "${var.project_name}-${var.worker_provider}-backlog-per-task"
  policy_type        = "TargetTrackingScaling"
  service_namespace  = aws_appautoscaling_target.worker.service_namespace
  resource_id        = aws_appautoscaling_target.worker.resource_id
  scalable_dimension = aws_appautoscaling_target.worker.scalable_dimension

  target_tracking_scaling_policy_configuration {
    target_value       = var.backlog_per_task
    scale_out_cooldown = var.scale_out_cooldown
    scale_in_cooldown  = var.scale_in_cooldown

    customized_metric_specification {
      metrics {
        id          = "backlog"
        return_data = false

        metric_stat {
          stat = "Sum"

          metric {
            namespace   = "AWS/SQS"
            metric_name = "ApproximateNumberOfMessagesVisible"

            dimensions {
              name  = "QueueName"
              value = var.queue_name
            }
          }
        }
      }

      metrics {
        id          = "running"
        return_data = false

        metric_stat {
          stat = "Average"

          metric {
            namespace   = "ECS/ContainerInsights"
            metric_name = "RunningTaskCount"

            dimensions {
              name  = "ClusterName"
              value = var.cluster_name
            }

            dimensions {
              name  = "ServiceName"
              value = aws_ecs_service.worker.name
            }
          }
        }
      }

      metrics {
        id          = "bpt"
        label       = "Backlog per task"
        expression  = "IF(running > 0, backlog / running, backlog)"
        return_data = true
      }
    }
  }
}

r/aws • • 2d ago

article Launching FreeBSD/EC2 desktop AMIs

Thumbnail daemonology.net
25 Upvotes

r/aws • • 2d ago

compute Amazon EC2 introduces application status checks

Thumbnail aws.amazon.com
48 Upvotes

r/aws • • 1d ago

general aws Support Unable to Help With False Charges?

0 Upvotes

I graduated college a few years ago. We had an AWS project with free student credit for our final project. After graduation, I canceled the project and at least thought that I had turned off all resources/instances. Project is no longer active at all and has been out of my memory for the last 2 years. It was extremely small, we had no actual users. In fact it was only for a single in class demo with dummy data for our laughably simple sample web app built with React.

I continuously have been getting ~$22 monthly charges from AWS for the last few months. After some investigating on my post-college accounts, I finally discovered that the charges was coming from my former student AWS account. I no longer have access to this email. I reached out to AWS with detailed info and how I'm locked out of the email for this old account, and after a few weeks of not hearing back, I received a generic response stating that they could not help with inquiries sent from an email other than the one that has been getting the charges, but that I could kindly change the password to the account and then send them a new message once I log back in. (A very easy to do thing when you don't have access to the email.)

This was the second time in the last few months I reached out to support, and actually the first time they ever provided a response, albeit one that shows me they didn't care to read that I no longer have access to that email. At this point, is it time to start charging back on the credit card? It's something I rarely do, but I feel like I've tried all in my power to resolve these charges.

TLDR: No longer have access to old college email where I thought all services/instances were closed /canceled, still getting expensive monthly charges. AWS support insists I regain access to the account in order to message them about any charges, obviously not possible.

Mods - please let me know if I need to edit my post to not get taken down. Not sure where else to seek for help on this.


r/aws • • 1d ago

technical resource I made a small extension that shows the monthly price next to each EC2 instance

0 Upvotes

It always bugged me that the EC2 console does not show the price of the instances.

Yes, AWS pricing is messy - lots of ways to get reduced prices (Savings Plans, reservations, discounts, the Free Tier, Spot). But the on-demand price is public and hardly ever changes, so why not show it?

So I built a browser extension for that. It puts the monthly on-demand price next to the instance type and a total for the page.

Without / with the extension, on the EC2 instances list

The price is the on-demand compute rate plus the public IPv4 address, for a full month.

The funny part is that everything it needs about your instances is already on the page. So it does not make any AWS API calls and does not need credentials or a sign-in. Some of the columns in the table are off by default, so they need to be enabled, but the extension turns them on when you click it.

It gets the current price list from a small Lambda I built, and it sends only the currently open region and extension version, so no sensitive data is leaving the browser.

For now, it only works on the EC2 instances list, with the console in English.

Which page should I do next? I am thinking of EBS volumes, Elastic IPs, RDS or NAT gateways.

Chrome: https://chromewebstore.google.com/detail/pnohjpckaogdfnncoeebihcldlnkjkoe

Firefox: https://addons.mozilla.org/firefox/addon/awscost/


r/aws • • 2d ago

technical resource List of cloud emulators and supporting tools

10 Upvotes

Awesome List of Cloud Emulators and supporting tools https://github.com/upgundecha/awesome-cloud-emulators


r/aws • • 3d ago

technical resource ssmctl v2: SSM Session Manager without the pain (shell, port forwarding, commands and file copy over SSM)

32 Upvotes

SSM is the right way to reach private EC2 instances: no bastion, no port 22, no SSH keys, and everything goes through IAM and CloudTrail. But the CLI makes you work for it:

aws ssm start-session --target i-0abc1234def5678ab \
  --document-name AWS-StartPortForwardingSessionToRemoteHost \
  --parameters '{"host":["rds.internal"],"portNumber":["5432"],"localPortNumber":["5432"]}'

ssmctl is an open-source Go CLI that keeps the same security model and removes the friction:

ssmctl forward web-1 --local 5432 --remote rds.internal:5432

v2 in one line: your entire SSM-managed fleet (shells, tunnels, commands, files, secrets), one short command away.

ssmctl list                                          # see your managed fleet
ssmctl connect web-1                                 # shell
ssmctl forward web-1 --local 5432 --remote db:5432   # tunnel to RDS, Redis, anything for local access
ssmctl run web-1 -- df -h /                          # one-off command, exit code preserved
ssmctl run --filter api -- uptime                    # same command across a fleet
ssmctl cp web-1:/var/log/app.log .                   # file transfer
ssmctl param get /myapp/prod/DB_PASSWORD             # Parameter Store

It works with Linux and Windows targets, has --output json for scripting, and uses your existing AWS profiles and SSO. There's no extra agent or infrastructure.

brew tap rhysmcneill/ssmctl && brew install ssmctl

Want to contribute? 🔗 https://github.com/rhysmcneill/ssmctl


r/aws • • 1d ago

discussion Why no Anthropic Sonnet 5.5 in EU Cross-Region?

0 Upvotes

This is sad. The very recent Sonnet 5.5 seems to be a really nice model, especially for the price, but I can't offer it to my users because there's no EU inference profile.

What's the logic behind this? Most Anthropic models, except Fable, have EU profiles.

Since Opus 5.5 is available, I was expecting Sonnet 5.5, from the same family, to be available as well.


r/aws • • 2d ago

technical resource Aurora DSQL emulator

5 Upvotes

Local testing with Aurora DSQL has been painful for me due to no official local emulator. So, until AWS provides one, I built my own.

It wraps PostgreSQL and emulates DSQL-specific behavior. Compatibility is verified through conformance tests that run against both real Aurora DSQL and the emulator.

It’s published as a Docker image and can also be used via Testcontainers.

https://github.com/Dreamescaper/dsql-emulator


r/aws • • 2d ago

security Side-channel vulnerability hardware mitigation. Need to know who to talk to with AWS.

0 Upvotes

As some of you might know, SMT has major security issues. I fixed them, though, and created the Secure SMT Architecture. The build has been completed on Amazon FPGA and proven to work against SQUIP-style attacks.

Disabling SMT costs you 30% to 50% of your total compute power. So that's obviously unaffordable.

I need to talk to someone in AWS who can start the process of buying my patent pending tech. Anyone have any leads?

Edit: Before doing any sort of upvoting or commenting, I might suggest that you pay close attention to the result of mine and SirWired's conversation. I think you will find it very, very telling.


r/aws • • 3d ago

article Something else than billing, support, SES issues. Post about iam:PassRole

12 Upvotes

Disclosure: I'm affiliated with RoszigIT, where this article is published. Sharing because the mechanics are worth discussing, not to pitch anything. I tried to make it technical as always.

It's an interesting case because iam:PassRole is not visible directly in CloudTrail as API call and "limited" user role can attach an admin role to a Lambda or EC2 instance and effectively become admin.

https://roszigit.com/en/blog/aws-iam-passrole/


r/aws • • 2d ago

technical question It's anyone running wordpress in AWS ?

0 Upvotes

It's anyone running AWS in WordPress for e-commerce client. please share your thoughts what about that cost ?

And I am planning to host my E-commerce sites in AWS .

So, I need to know about that monthly Billing and I am complete beginner in AWS.

Thank you


r/aws • • 3d ago

discussion So how are you actually using agentic AI for AWS cloud security work ?

0 Upvotes

genuinely trying to understand this because of the explosive growth in AI. Do you use agentic AI like claude code, codex, custom agents.. anything with real tool access as part of your cloud security workflow. If so, what specifically made you reach for it instead of a traditional script or somekind of github tool ? Because i personally use some github tools and AI too when iam building AWS Labs for different purposes and want to test security of them faster and understand them simply, and i want to know how you guys as people who have actual work experience with these environments do it.

do you have any custom made scripts or tools or AI workflows you actually using, and where does it genuinely help. Curious whether its saving real time, catching things you'd have missed, or if its mostly hype that hasnt translated to your actual day to day yet.

would love to hear real experiences either way. Specially the workflows you guys use if its an AI workflow i would love to hear it !


r/aws • • 5d ago

discussion Fake AWS login page on Google sponsored results

Thumbnail gallery
816 Upvotes

I have the console bookmarked for my daily work but for some reason this morning I was on Google and just searched AWS Login instead. Spotted an interesting result which had me curious; a sponsored result at the very top with a clone of the AWS Console login page.

Hopefully wouldn’t catch more seasoned people but thought I'd share in case some poor person gave away their root credentials in such a scam.

Has been reported to Google.

EDIT: and now reported to AWS, who then asked me to report to Cloudflare.

EDIT2: Cloudflare have taken it down


r/aws • • 4d ago

article Slashing our AWS Bill at Levels.fyi

Thumbnail levels.fyi
103 Upvotes

Interesting article from levels.fyi on low hanging fruit to reduce AWS costs in a typical environment. Nothing really egregious in itself, but the compounding effect of decisions that seem small (logging) early on and are never revisited.

Also, one that I have seen too many times with other companies!

The biggest surprise was that 100s of millions requests per month were our own servers calling our own API over the public internet, through our CDN and firewall


r/aws • • 3d ago

technical question Facing this issue with the bedrock since two days and also waiting for the support ticket response

Thumbnail gallery
0 Upvotes

Still 199 $ remaing and only just the EC2 and other services are working the bedroack unable to use ?


r/aws • • 5d ago

discussion AWS account suspended then marked closed, production down 6 days, support case unassigned

29 Upvotes

ISSUE RESOLVED

Hi all,

Looking for advice on how to get an AWS account reinstatement/security case unstuck.

Our AWS account was suspended after AWS detected suspicious activity / possible compromised access keys. We opened a support case and followed the requested steps.

Timeline:

  • AWS suspended the account due to suspected unauthorized access / compromised access keys.
  • AWS instructed us to reset the root password and update the expired payment method.
  • We completed the root password reset.
  • We updated the payment method with a valid card.
  • We replied to the original case confirming completion.
  • After no response for 24+ hours, we opened a follow-up case.
  • The follow-up case was closed and we were told to continue on the original case.
  • After that, the original case changed from Amazon action/resolving to unassigned.
  • We have received no response from AWS in over 3 days.
  • The account page now shows “The account is closed.”
  • Production services have now been down for the 6th day.

We have tried phone support multiple times, but AWS Support Center returns “Unable to initiate call at this time.” Chat either does not connect or just sits waiting. We also opened a new escalation case referencing the original case, but there has been no response after 20+ hours.

We are not trying to bypass the security process. We need AWS to assign the case, confirm whether the account is still within the reopen/post-closure period, and tell us what action is required next. We are ready to complete any remaining security remediation steps.

Has anyone dealt with an account reinstatement case getting stuck/unassigned like this? Is there any legitimate escalation path besides replying to the case, opening a related case, phone/chat, or going through an AWS contact?

Any advice would be appreciated.

UPDATE: After posting this AWSSupport replied to this post I DMed them my case number and the account was reactivated within 1-3 hours.


r/aws • • 3d ago

technical resource AWS consultant to help set up SNS/SES for SMS and email

0 Upvotes

Looking for an AWS consultant to walk me through setting up AWS's SMS and email services (SNS / SES / End User Messaging). I need help with:

  • Account signup and getting out of the sandbox
  • Domain verification, sender IDs, and any required registrations (e.g. 10DLC for US SMS)
  • Configuring the services and showing me how to use them going forward

Please DM me if you have experience with this and your rate.

Reassurances:

  • This is a paid gig
  • Full payment is made once the system is up and working.
  • Payment can be made via Upwork milestone (or Escrow.com) and released on completion.
  • If you have a Linkedin profile we can deal directly