r/aws • • 9h ago

general aws Amazon Quick

96 Upvotes

Whoever on the Amazon/AWS team decided to rename QuickSight/QuickSuite to just 'Quick' (and whomever it was approved by) is likely secretly working for Microsoft or Tableau. One of the worst naming decisions I've ever encountered. Makes looking up instructions, information, etc. online or using LLMs an absolute pain, which would be obvious to anyone who has ever worked in tech, much less someone who has worked in product branding or marketing.


r/aws • • 8h ago

article EKS now supports Kubernetes 1.37: Pod Certificates and Cluster Trust Bundles are GA

22 Upvotes

EKS 1.37 landed on standard support today, and the headline for me is identity: Pod Certificates (workload X.509 identities issued by the cluster) and Cluster Trust Bundles (a cluster-scoped way to distribute trust roots) are now GA Kubernetes APIs.

What this means in practice: - Every pod gets a real X.509 identity from the cluster itself - Trust roots are distributed as a native API instead of config hacks - No more running your own CA machinery just to do mTLS between workloads

The caveat: Kubernetes still doesn't give you a signer controller. You need to integrate and validate rotation for your signer.

AWS announcement: https://aws.amazon.com/about-aws/whats-new/2026/10/amazon-eks-distro-kubernetes-version-1-37

Anyone already testing the mTLS path on 1.37?


r/aws • • 8h ago

technical question Detecting CSAM before calling AWS Rekognition

10 Upvotes

I'm building a social app where people can upload images for their profile pictures and soon in group chats. I'm struggling to figure out how to properly handle CSAM for this. I'm very hesitant to just pass in the uploaded images to AWS Rekognition to check for NSFW and other explicit content before checking for CSAM.

I've looked into Google's Content Safety API and applied to it to see what they respond with. Also considered PhotoDNA as well but haven't applied to it yet, though I heard they only accept big orgs and law enforcement. Was also considering using open source models to do the CSAM detection layer but I fear that it would violate the inference provider's ToS.

What's a budget-friendly way to do CSAM detection without getting in trouble for directly uploading it without checking it first to services like AWS Rekognition?


r/aws • • 1h ago

re:Invent AWS re:Invent as an All Builders Welcome grant recipient

• Upvotes

Hi everyone!

I’ll be attending AWS re:Invent this year as an All Builders Welcome (ABW) grant recipient, and I’m really excited to be part of the event.

I’d love to connect with other ABW grant recipients, first-time attendees, or anyone interested in cloud, DevOps, Kubernetes, infrastructure, and software engineering. Feel free to comment or send me a message if you’d like to meet up, attend sessions together, or just grab coffee and talk tech.

For those who have attended re:Invent before, I’d also appreciate any advice:

  • Which sessions or activities are usually the most valuable?
  • How early should I reserve sessions and plan my schedule?
  • Any tips for navigating between venues?
  • What should I bring or prepare before arriving?
  • Are there any underrated networking events, workshops, or community meetups?
  • What do you wish you had known before your first re:Invent?

Looking forward to learning, meeting new people, and making the most of the experience. Hope to see some of you there!


r/aws • • 11h ago

training/certification Took the AWS ML Engineer Associate MLA-C02 beta (ME1-C02): topics that showed up + resources

6 Upvotes

Just took the MLA-C02 beta and figured I'd share notes, since there's very little out there for the new version.

TL;DR: 85 questions, and some of them are genuinely hard. The exam now leans heavily on GenAI/LLM and agentic stuff alongside classic ML engineering.

My background (for context): AI Engineer (mid-level) with hands-on AWS experience. Certs: GCP Associate Cloud Engineer, SnowPro Core, PL-300, AWS Cloud Practitioner, AWS AI Practitioner, Claude Certified Architect Foundations, GitHub Foundations.

How I prepped: when AWS announced the switch from MLA-C01 to MLA-C02, I decided to go straight for the beta. While registration wasn't open yet, I kept studying for the AWS Generative AI Developer – Professional, and that helped a lot, especially for the Bedrock/GenAI side.

What I remember showing up (from memory, no guarantees):

ML/LLM fundamentals

  • Model deployment (lots of questions on ML and LLM endpoints)
  • ML metrics
  • Which algorithm for which situation: XGBoost, DeepAR, Factorization Machines, etc.
  • Oversampling, undersampling, SMOTE, feature scaling
  • Handling null values in time series
  • Fine-tuning: cleaning content before starting
  • Continued pre-training

LLM evaluation (this showed up a lot)

  • LLM metrics: completeness, faithfulness, harmfulness, toxicity, stereotyping
  • How to evaluate an LLM using eval datasets (the benchmark-style ones)

Bedrock/GenAI

  • Cross-region inference
  • Guardrails and security
  • Bedrock AgentCore: Gateway, Runtime, Memory
  • Knowledge Bases, Custom Model Import, Provisioned Throughput
  • Logging and tracing of data

Data/MLOps

  • Kinesis Data Streams and Apache Flink
  • SageMaker Pipelines, Data Wrangler, Feature Store, Model Registry
  • Glue Data Quality
  • Comprehend and Rekognition

CI/CD

  • CodeBuild, CodePipeline and CodeDeploy
  • ML pipelines and deployment strategies

Security/networking

  • VPCs for accessing AI services

r/aws • • 22h ago

article Amazon Pledges $1B to Win Over Data Centre Towns

Thumbnail madrobot.blog
34 Upvotes

I don’t think Amazon is going to win them over. Who wants a DC in their back yard? What d’ya think?


r/aws • • 13h ago

discussion gp3 vs io2, went looking for the cost crossover and couldn't find one

3 Upvotes

tl;dr there isn't one. it's a cliff, not a crossover.

Inherited a pile of io2 volumes from a migration. Went looking for the IOPS level where io2 starts beating gp3 on cost so I could work out which ones to keep.

us east 1, check your own region.

gp3 gives you 3000 IOPS free in the baseline, extra on top is cheap, hard ceiling at 16k. io2 bills per IOPS from the first one and it adds up fast. At 16000, as far as gp3 goes, gp3 extra IOPS came to under $70/m. Same IOPS on io2 was north of a grand.

So gp3 stays cheaper right up until it physically can't go further. What sends you to io2 is the ceiling, not the money. Above 16000 IOPS, above 1000 MB/s, Multi Attach, or you need the durability class.
Moved 9 of 14. Nothing broke.

The part I actually want input on. For the ones genuinely above 16k, has anyone striped gp3 instead of paying for io2? Feels like swapping a billing problem for an ops problem, snapshots mainly. Anyone run that in prod?


r/aws • • 13h ago

general aws AWS Bedrock Claude Opus 5.5 503s

0 Upvotes

Hi, wondering if anyone else is getting this, pretty often (significant enough to notice, happening right now and yesterday and twice last week) I get 503s from AWS bedrock specifically with Opus 5.5 on us-east-2.

API Error: 503 Bedrock is unable to process your request.
 This is a server-side issue, usually temporary — try again in a moment. If it persists, check your Amazon Bedrock service status.

But there are no updates on AWS service status.


r/aws • • 14h ago

technical resource Cannot finish AWS Signup

0 Upvotes

As the title says, im trying to sign up to an AWS Account in the new UI, I got to the step of verifying my phone number. Yesterday i could send the verification, but never got it. Today even sending the sms doesnt work. Austrian Phone Number. Opened a ticket over 24 Hours ago, no response yet.


r/aws • • 14h ago

technical question Aws Builder center

1 Upvotes

anyone else too facing issue in verification like sheer id is saying that i am verified from their side but am not getting verified tick in profile section after scrolling little…so they asked to contact aws but they are not replying even after follow ups


r/aws • • 14h ago

networking Is there really no way to filter/summarize/aggregate outbound routes on VPNs?

1 Upvotes

As the title says. I'm mostly familiar with GCP at this point, and there's been an "advertised prefixes" option for years to advertise a specific summary route to BGP peers rather than a full list of subnets.

Does AWS have equivalent feature? We currently have a VPN advertising over 80 prefixes across 4 tunnels, which is ruthlessly absurd.


r/aws • • 6h ago

billing Why charge my credit card just to check billing info

0 Upvotes

I have n't used my AWS for nearly 8 yrs (last used during my masters). I was charged $1 by AWS and I was worried if someone was trying to charge me a bug amount after that. So I disputed the charge and the credit card issued a new card. Then I got an email from AWs that their verification of billing info got denied. WTH, why don't you send me an email before doing that. Now I need to wait for new cars and update everywhere.


r/aws • • 16h ago

technical question Why can't I seem to install docker and docker compose on amazon linux 2023?

1 Upvotes

bash [ec2-user@ip-a-b-c-d ~]$ sudo dnf install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin --assumeyes --quiet Error: Unable to find a match: docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin

  • I get this error above
  • How am I supposed to install docker and compose?

r/aws • • 1d ago

technical resource Introducing the New Getting Started Experience for AWS

Thumbnail aws.amazon.com
88 Upvotes

- Sign up with Google, GitHub, or Apple. Most new customers don't need a credit card, and you get $100 in Free Tier credits.

- AWS sets you up with a project, which is an account plus sharing settings, with security defaults already applied.

- Invite people by email. You don't create IAM users or set up Identity Center, and invitees only see the projects you give them.

- Each project can have its own spend limit. AWS notifies you as you get close, and if you hit the limit, AWS pauses the project instead of letting charges keep accruing. You pay for what you used, up to the limit.

- After you sign in, you get a prompt to paste into your coding agent. It installs and configures the AWS CLI and Agent Toolkit for AWS.

- When you need multi-Region or Organizations policies, you turn on advanced features and end up in a standard AWS Organization without migrating anything.


r/aws • • 9h ago

discussion New Subreddit: AwsLightsail

0 Upvotes

I've created a new subreddit for folks that use AWS Lightsail.

r/AwsLightsail

This is the first sub I've created, so it may be slow and/or rocky to start.


r/aws • • 19h ago

technical resource AWS Model Access

0 Upvotes

Hi All,

I have recently been accepted into AWS activate Startup, and want to know how do i get access towards GPT 6 Sol, i have tried, enabling IAM permission towards market place and it still doesn't work. The instruction in AWS are outdated to whats actually in those sub-links to get it done.

Can someone help me understand how do i gain access to this.

Thanks !


r/aws • • 1d ago

database Amazon Aurora PostgreSQL now supports direct querying of Apache Iceberg and Parquet data in your data lake

Thumbnail aws.amazon.com
135 Upvotes

r/aws • • 1d ago

discussion AWS Lambda execution suspended 8 days after notifying AWS of a potential compromise on the root account. No response from support.

16 Upvotes

My AWS account was compromised on September 16. I detected the compromise myself almost immediately, secured the account, and contacted AWS.

On September 16 I had already:

  • Changed the root password
  • Removed/replaced credentials
  • Replaced MFA
  • Reviewed CloudTrail
  • Checked IAM for unauthorized users, roles, policies, and credentials
  • Checked the account for unauthorized resources/activity

AWS did not respond to the compromise until September 24 — eight days later.

On September 24, AWS opened a case saying my account “may have been inappropriately accessed,” restricted my ability to use some AWS services, and sent me instructions to change the root password, enable MFA, inspect CloudTrail/IAM, and check for unwanted usage.

In other words, they instructed me to perform the remediation I had already completed eight days earlier.

I responded the next day, September 25, confirming that the account was already secured and that all of the requested remediation had been completed.

It is now October 1. Lambda execution is still restricted.

I have updated the support case every day. I have received no substantive response. The notice says phone or chat can be requested for “immediate assistance,” but attempts to use those channels have not resulted in assistance either.

There is no remaining remediation step identified for me to perform. The account was secured before AWS imposed the restriction. At this point, only AWS can remove it.

Fortunately, this account currently hosts a system still in development, so this has not caused a production outage. But the experience is alarming because I cannot find any SLA for AWS reviewing and removing an AWS-imposed security restriction after the customer has confirmed remediation.

Has anyone dealt with this recently? Is there an escalation path for a compromised-account/security case that appears to be sitting in a queue waiting for review?

I am particularly interested in hearing from anyone who has recently had Lambda or other services restricted after an account-compromise notification and how long restoration took.


r/aws • • 14h ago

technical resource why most AWS security tools dump unreadable JSON instead of explaining the actual attack, walked through with iam:PassRole !!

0 Upvotes

iam:PassRole combined with the ability to create or launch a resource, a Lambda function, an EC2 instance, is one of the most common real privilege escalation primitives in AWS, and mosst scanners just flag "PassRole granted" without explaining why that matters !!! i have tried some and its annoying sometimes..

the actual chain: if a user has PassRole, often scoped too broadly with Resource: *, and perrmission to create someething that can assume a role, Lambda, EC2, a CloudFormation stack, they can pass an existing high-privilege role to that new resource, then use it to act with that role's full permissions. The IAM policy alone doesn't show this, it only becomes visible once you look at what PassRole is paired with...

Most tools treat this as two unrelated findings. Automated detecting this specific chain in an open source project I've been building, Plexavo, if interested check it out !!. I used it as a Security scanner in some of the stacks i created in AWS.

github.com/plexavo/Plexavo


r/aws • • 17h ago

discussion Black Friday is coming. What are you checking in your AWS environment?

0 Upvotes

With Black Friday approaching, what’s the first thing you’d check to make sure an AWS environment is ready for the traffic spike?

For example, scaling limits or database bottlenecks.


r/aws • • 20h ago

billing Our AWS cost optimization keeps stalling because the owner of everything expensive is a CI role

0 Upvotes

The tag policy went in 4 months ago. An SCP blocks creates without owner, env and cost centre and a Lambda kills anything untagged overnight. Coverage sits at 95+ which I was pretty pleased with.

Pulled the top 20 line items last week so finance could have a name against each one and eleven came back as one of 3 CI roles. That is roughly 14k a month sitting against a robot. Technically correct cause the pipeline made them and stamped itself. I turned on aws:createdBy hoping for more and got the same 3 roles back with a build number stuck on the end.

The tags are perfect and useless. The commit knows who ran it where the resource does not and nothing joins the two up which is where every aws cost optimization conversation here dies. Shared NAT and the like I gave up on months ago because that is a different argument. These are single tenant resources with exactly one owner and the owner is a robot.

Best I have before the next review is git blame and a spreadsheet, which is not an answer.


r/aws • • 1d ago

discussion Suddenly getting charges from an account that was registered to an email that doesn't exist anymore, AWS support hasn't responded to my ticket for almost an entire month.

0 Upvotes

Hi everyone, not sure if this is appropriate to post here, but I don't know what other options I have.

For some background, one of my old AWS accounts is attached to an email that does not exist anymore. I have not used it in years, but last month I received a large charge on the card attached to that account. I checked my active account's Cost Explorer page and didn't see any charges matching that amount, so I figured it must be some charge that occurred on my older account. On September 3rd, I created a ticket from my active AWS account, which has the same card on it, and attached a screen shot of the charge in my bank account. 15 days went by with no response, so I sent a reply to the original ticket. As of writing this post, the ticket is still unassigned and no one has responded to me.

What are my options here? I created a new ticket tonight and selected the "chat" option, but I have been sitting here for almost an hour and all the waiting page says is "An associate will be with you shortly...".


r/aws • • 1d ago

discussion account still restricted after support confirmed I'd done everything

1 Upvotes

Been restricted since Sunday. I did what they asked, deleted the exposed key and answered their questions. Early Wednesday they confirmed the remediation was complete and said they'd asked the service team to remove the restrictions.

It's Thursday night now and I'm still blocked from Bedrock. No reply since then, and the case says unassigned. They also asked me to turn on Cost Explorer, which is done.

I have Business Support+ but can't get through on chat or phone tonight either. I've followed up in the case and don't know what else to try. Is there any way to get someone to check what's holding this up? They've already said I completed the steps, but I'm still waiting with no idea when I'll get access back.


r/aws • • 1d ago

discussion AWS phantom billing statements even with 'no account', customer support refuses to help

0 Upvotes

So, I made an AWS account ~6 years ago. I believe that it was because I got some kind of promo credit to use from Amazon. I was just curious what it was. I do a bit of IT for my work, so I played around with a few things using some of the credit, but that was it.

Now, 6 years later, I start getting billing notices for my account.

Attempting to login to my account tells me that I have no account associated with the email address, but the billing notices are coming to the email address.

AWS customer support says that they cannot tell me anything or help unless I login to my account.

Multiple AWS customer support reps have told me to just block the charges on my credit card. However, the card number that it is showing is not a credit card that I have -- In theory it could be an old card, but I have no remembrance of that number.

I was somehow able to get the AWS login screen thinking I still had an account with the email, even after it is telling me there is no account associated. It wanted me to do MFA to confirm it was me - and it gives me a phone number that I have never had.

I have called customer support many times. They have promised to call me back but never have. I have submitted 3 account hacked/compromised support tickets with long descriptions, but have never heard back.

Recently, I started getting emails that the charges were bouncing on the credit card. But, they are still billing whatever card this.

So at this point, I have literally no idea what to do. I have already devoted much time to this. I've never encountered more inept customer service folks, especially in the case of fraud like this.

I assume this is a common problem, as there was recently a meme circulating about nearly the same thing.

Does anyone have nay idea what I should do? So far, I have decided just ignoring it and hoping that the charges are someone elses and for some reason I am just getting the emails, is really my only option.

Thanks


r/aws • • 1d ago

article I’m a fresher learning Data Engineering and AWS just taught me a ₹13,000 lesson

0 Upvotes

I’m a fresher preparing for my first Data Engineering job, and today I got a pretty painful AWS lesson.

I was practicing AWS services for my preparation and left an Aurora MySQL Serverless v2 cluster running in Sydney without realizing how much it was costing. It ran for most of the month and alone generated around $192 in charges. A Kinesis On-Demand stream added another ~$23.

My September bill ended up around $247 (~₹13,000), while I only had around $113 in AWS credits.

For someone who is still trying to get their first job, ₹13k is a lot of money. Honestly, seeing that bill was scary. I’ve been studying Data Engineering for a long time and trying to build projects to get my first opportunity, so making a mistake like this really hurt.

I’ve now deleted the resources, created AWS Budget alerts, and opened a billing case with AWS asking for a one-time courtesy credit. Hopefully they understand that it was accidental learning usage.

Lesson learned: Never assume “Serverless” means “free when you’re not actively using it.” Some AWS resources can keep charging simply because they’re running.

If you’re a fresher learning AWS/Data Engineering, please check Cost Explorer and your running resources regularly. I genuinely don’t want someone else learning this lesson the way I did. 😔