Publicado el Deja un comentario

Amazon RDS for SQL Server now supports Microsoft SQL Server 2025

Amazon Relational Database Service (Amazon RDS) for SQL Server now supports Microsoft SQL Server 2025 for Enterprise, Standard, and Developer editions.

SQL Server 2025 brings AI integration directly into the database engine, enabling customers to invoke external REST endpoints from T-SQL without additional middleware. Customers running RDS for SQL Server can use this capability to integrate existing database workloads securely with AWS services such as Amazon Bedrock, Amazon SageMaker, Amazon S3, and AWS Lambda, without re-architecting applications. This enables scenarios such as AI-powered query advisor, automated performance analysis, event-driven workflows, and calling custom web services on Amazon EC2.

SQL Server 2025 introduces a new free edition for development and testing without licensing costs (Standard Developer Edition, or Dev-SE), and significant Standard Edition capacity increases up to 32 cores and 256 GB buffer pool memory. Standard Edition also gains Resource Governor, previously exclusive to Enterprise Edition. SQL Server 2025 also introduces a native vector data type for storing and querying vector embeddings directly within the database.

Customers running earlier SQL Server versions on RDS can upgrade to SQL Server 2025 by modifying the DB engine version, and customers running SQL Server on premises can migrate to take advantage of these capabilities with fully managed infrastructure. For more information, see the Amazon RDS for SQL Server User Guide. See Amazon RDS for SQL Server Pricing for up-to-date pricing and regional availability.

 

​Amazon Relational Database Service (Amazon RDS) for SQL Server now supports Microsoft SQL Server 2025 for Enterprise, Standard, and Developer editions. SQL Server 2025 brings AI integration directly into the database engine, enabling customers to invoke external REST endpoints from T-SQL without additional middleware. Customers running RDS for SQL Server can use this capability to integrate existing database workloads securely with AWS services such as Amazon Bedrock, Amazon SageMaker, Amazon S3, and AWS Lambda, without re-architecting applications. This enables scenarios such as AI-powered query advisor, automated performance analysis, event-driven workflows, and calling custom web services on Amazon EC2. SQL Server 2025 introduces a new free edition for development and testing without licensing costs (Standard Developer Edition, or Dev-SE), and significant Standard Edition capacity increases up to 32 cores and 256 GB buffer pool memory. Standard Edition also gains Resource Governor, previously exclusive to Enterprise Edition. SQL Server 2025 also introduces a native vector data type for storing and querying vector embeddings directly within the database. Customers running earlier SQL Server versions on RDS can upgrade to SQL Server 2025 by modifying the DB engine version, and customers running SQL Server on premises can migrate to take advantage of these capabilities with fully managed infrastructure. For more information, see the Amazon RDS for SQL Server User Guide. See Amazon RDS for SQL Server Pricing for up-to-date pricing and regional availability.  

Publicado el Deja un comentario

Amazon ECS now provides Action Logs for deployment and orchestration visibility

Today, Amazon Elastic Container Service (Amazon ECS) introduces Action Logs, a new observability feature that delivers detailed, timestamped records of the actions Amazon ECS performs on behalf of customers during service deployments and ECS Managed Daemon updates. By surfacing service-side operations that were previously invisible, Action Logs help you monitor and troubleshoot your workloads directly, without contacting AWS Support or manually correlating data from multiple sources.

With Action Logs, you gain visibility into key deployment state transitions of service deployments, Managed Daemon updates. Each log entry includes the event name, log level(INFO, WARN, OR ERROR), relevant resource ARNs, and a status reason, helping you reduce mean time to resolution when issues arise. You can opt in at the cluster level through the Amazon ECS console or by using Amazon CloudWatch vended logs APIs, and choose to deliver logs to Amazon CloudWatch Logs, Amazon S3, or Amazon Kinesis Data Firehose depending on your operational needs. At launch, Amazon Q in the Amazon ECS console integrates with Action Logs to automatically detect deployment issues such as circuit breaker rollbacks and unstable service revisions, providing customers with root cause analysis, resource-level comparisons, and step-by-step remediation guidance without leaving the console. Standard CloudWatch Logs, Amazon S3, or Amazon Data Firehose pricing applies for log ingestion and storage. For pricing details, see Amazon CloudWatch Pricing.

Amazon ECS Action Logs are available in all AWS Regions, including the AWS GovCloud (US) Regions. To learn more, refer Monitor Amazon ECS operations with Action Logs in Amazon ECS Developer Guide.

 

​Today, Amazon Elastic Container Service (Amazon ECS) introduces Action Logs, a new observability feature that delivers detailed, timestamped records of the actions Amazon ECS performs on behalf of customers during service deployments and ECS Managed Daemon updates. By surfacing service-side operations that were previously invisible, Action Logs help you monitor and troubleshoot your workloads directly, without contacting AWS Support or manually correlating data from multiple sources.
With Action Logs, you gain visibility into key deployment state transitions of service deployments, Managed Daemon updates. Each log entry includes the event name, log level(INFO, WARN, OR ERROR), relevant resource ARNs, and a status reason, helping you reduce mean time to resolution when issues arise. You can opt in at the cluster level through the Amazon ECS console or by using Amazon CloudWatch vended logs APIs, and choose to deliver logs to Amazon CloudWatch Logs, Amazon S3, or Amazon Kinesis Data Firehose depending on your operational needs. At launch, Amazon Q in the Amazon ECS console integrates with Action Logs to automatically detect deployment issues such as circuit breaker rollbacks and unstable service revisions, providing customers with root cause analysis, resource-level comparisons, and step-by-step remediation guidance without leaving the console. Standard CloudWatch Logs, Amazon S3, or Amazon Data Firehose pricing applies for log ingestion and storage. For pricing details, see Amazon CloudWatch Pricing.
Amazon ECS Action Logs are available in all AWS Regions, including the AWS GovCloud (US) Regions. To learn more, refer Monitor Amazon ECS operations with Action Logs in Amazon ECS Developer Guide.  

Publicado el Deja un comentario

AWS Data Exports now provides standardized Amazon Bedrock product metadata

Today, AWS announces standardized product metadata for Amazon Bedrock in AWS Data Exports (Cost and Usage Report), giving FinOps teams and cloud administrators consistent, structured attributes to understand  Bedrock costs. AWS Data Exports lets you create customized exports of your AWS cost and usage data and deliver them to Amazon S3 for querying with Amazon Athena or loading into your data warehouse. With these attributes, you can attribute Bedrock spend without building custom logic to parse various product metadata in CUR 2.0.

The standardized attributes include model provider, model name, pricing unit, inference type (such as input tokens or output tokens), and feature (the inference serving mode, such as On-Demand or Batch), along with a unified «Amazon Bedrock» product family name that consolidates all Bedrock costs. In CUR 2.0, the model provider, model name, inference type, and feature attributes are available in the product map column, and pricing unit is available as a column. The standardized fields are available by default, at no additional cost, to Amazon Bedrock customers using AWS Data Exports.

To learn more, visit the Amazon Bedrock product page, and see Product columns in the AWS Data Exports User Guide for the standardized product attributes.

 

​Today, AWS announces standardized product metadata for Amazon Bedrock in AWS Data Exports (Cost and Usage Report), giving FinOps teams and cloud administrators consistent, structured attributes to understand  Bedrock costs. AWS Data Exports lets you create customized exports of your AWS cost and usage data and deliver them to Amazon S3 for querying with Amazon Athena or loading into your data warehouse. With these attributes, you can attribute Bedrock spend without building custom logic to parse various product metadata in CUR 2.0.
The standardized attributes include model provider, model name, pricing unit, inference type (such as input tokens or output tokens), and feature (the inference serving mode, such as On-Demand or Batch), along with a unified «Amazon Bedrock» product family name that consolidates all Bedrock costs. In CUR 2.0, the model provider, model name, inference type, and feature attributes are available in the product map column, and pricing unit is available as a column. The standardized fields are available by default, at no additional cost, to Amazon Bedrock customers using AWS Data Exports.
To learn more, visit the Amazon Bedrock product page, and see Product columns in the AWS Data Exports User Guide for the standardized product attributes.  

Publicado el Deja un comentario

Amazon EC2 R8i and R8i-flex instances are now available in additional regions

Starting today, Amazon Elastic Compute Cloud (Amazon EC2) R8i and R8i-flex instances are available in the Europe (Stockholm, Zurich) regions. These instances are powered by custom Intel Xeon 6 processors, available only on AWS, delivering the highest performance and fastest memory bandwidth among comparable Intel processors in the cloud. The R8i and R8i-flex instances offer up to 15% better price-performance, and 2.5x more memory bandwidth compared to previous generation Intel-based instances. They deliver 20% higher performance than R7i instances, with even higher gains for specific workloads. They are up to 30% faster for PostgreSQL databases, up to 60% faster for NGINX web applications, and up to 40% faster for AI deep learning recommendation models compared to R7i.

R8i-flex, our first memory-optimized Flex instances, are the easiest way to get price performance benefits for a majority of memory-intensive workloads. They offer the most common sizes, from large to 16xlarge, and are a great first choice for applications that don’t fully utilize all compute resources.

R8i instances are a great choice for all memory-intensive workloads, especially for workloads that need the largest instance sizes or continuous high CPU usage. R8i instances offer 13 sizes including 2 bare metal sizes and the new 96xlarge size for the largest applications. R8i instances are SAP-certified and deliver 142,100 aSAPS, delivering exceptional performance for mission-critical SAP workloads.

To get started, sign in to the AWS Management Console. For more information about the R8i and R8i-flex instances visit the AWS News blog.

 

​Starting today, Amazon Elastic Compute Cloud (Amazon EC2) R8i and R8i-flex instances are available in the Europe (Stockholm, Zurich) regions. These instances are powered by custom Intel Xeon 6 processors, available only on AWS, delivering the highest performance and fastest memory bandwidth among comparable Intel processors in the cloud. The R8i and R8i-flex instances offer up to 15% better price-performance, and 2.5x more memory bandwidth compared to previous generation Intel-based instances. They deliver 20% higher performance than R7i instances, with even higher gains for specific workloads. They are up to 30% faster for PostgreSQL databases, up to 60% faster for NGINX web applications, and up to 40% faster for AI deep learning recommendation models compared to R7i. R8i-flex, our first memory-optimized Flex instances, are the easiest way to get price performance benefits for a majority of memory-intensive workloads. They offer the most common sizes, from large to 16xlarge, and are a great first choice for applications that don’t fully utilize all compute resources. R8i instances are a great choice for all memory-intensive workloads, especially for workloads that need the largest instance sizes or continuous high CPU usage. R8i instances offer 13 sizes including 2 bare metal sizes and the new 96xlarge size for the largest applications. R8i instances are SAP-certified and deliver 142,100 aSAPS, delivering exceptional performance for mission-critical SAP workloads. To get started, sign in to the AWS Management Console. For more information about the R8i and R8i-flex instances visit the AWS News blog.  

Publicado el Deja un comentario

Amazon EC2 I8ge instances are now available in AWS GovCloud (US) Regions

Amazon Web Services (AWS) announces the availability of Amazon EC2 I8ge instances in AWS GovCloud (US-East, US-West) regions. I8ge instances are powered by AWS Graviton4 processors and deliver up to 60% better compute performance compared to previous generation Graviton2-based storage optimized Amazon EC2 instances. I8ge instances use the third generation AWS Nitro SSDs, local NVMe storage, and deliver up to 55% better real-time storage performance per TB compared to previous generation Amazon EC2 Im4gn instances. They offer up to 60% lower storage I/O latency and up to 75% lower storage I/O latency variability compared to Im4gn instances.

I8ge instances are storage-optimized instances, and offer up to 120TB of local NVMe storage. They are ideal for workloads that demand rapid local storage with high random read/write performance and consistently low latency for accessing large datasets. These versatile instances are offered in eleven different sizes including two metal sizes, providing flexibility to match customers’ computational needs. They deliver up to 180 Gbps of network performance bandwidth and 60 Gbps of dedicated bandwidth for Amazon Elastic Block Store (EBS), ensuring fast and efficient data transfer for the most demanding applications.

To begin your Graviton journey, visit the Level up your compute with AWS Graviton page. To get started, see AWS Management Console, AWS Command Line Interface (AWS CLI), and AWS SDKs. To learn more, visit the I8ge instances page

 

​Amazon Web Services (AWS) announces the availability of Amazon EC2 I8ge instances in AWS GovCloud (US-East, US-West) regions. I8ge instances are powered by AWS Graviton4 processors and deliver up to 60% better compute performance compared to previous generation Graviton2-based storage optimized Amazon EC2 instances. I8ge instances use the third generation AWS Nitro SSDs, local NVMe storage, and deliver up to 55% better real-time storage performance per TB compared to previous generation Amazon EC2 Im4gn instances. They offer up to 60% lower storage I/O latency and up to 75% lower storage I/O latency variability compared to Im4gn instances.
I8ge instances are storage-optimized instances, and offer up to 120TB of local NVMe storage. They are ideal for workloads that demand rapid local storage with high random read/write performance and consistently low latency for accessing large datasets. These versatile instances are offered in eleven different sizes including two metal sizes, providing flexibility to match customers’ computational needs. They deliver up to 180 Gbps of network performance bandwidth and 60 Gbps of dedicated bandwidth for Amazon Elastic Block Store (EBS), ensuring fast and efficient data transfer for the most demanding applications.
To begin your Graviton journey, visit the Level up your compute with AWS Graviton page. To get started, see AWS Management Console, AWS Command Line Interface (AWS CLI), and AWS SDKs. To learn more, visit the I8ge instances page.   

Publicado el Deja un comentario

Selectively log network activity events by identity in AWS CloudTrail

Today, AWS launches enhanced event filtering for network activity events for VPC end points, a CloudTrail event type that captures actions transmitted through a Virtual Private Cloud Endpoint. Customers can now control which network activity events are logged based on the IAM user identity making the API call. For example, you can configure selectors to log only access denied events when the calling user identity is not on a known safe list. This lets you capture unauthorized access attempts while excluding routine traffic from trusted identities, reducing both logging costs and noise.

With UserIdentity filtering, customers building a data perimeter strategy can focus on network activity event logging for scenarios that matter most in security. You can configure selectors to log only VpceAccessDenied events from identities outside a trusted set of IAM roles. This enables detection of potential data exfiltration attempts through VPC endpoints without the cost of logging every successful API call from approved principals. You can combine UserIdentity conditions with existing fields like eventName or vpcEndpointId for fine-grained control over what gets recorded.

You can use this feature via the AWS Management Console, AWS Command Line Interface, and AWS SDKs. This feature is available in all AWS Regions where CloudTrail network activity events are supported. To learn more about Network Activity events, visit the AWS CloudTrail user guide or read AWS Blog on how to enable Network Activity Events.

 

 

​Today, AWS launches enhanced event filtering for network activity events for VPC end points, a CloudTrail event type that captures actions transmitted through a Virtual Private Cloud Endpoint. Customers can now control which network activity events are logged based on the IAM user identity making the API call. For example, you can configure selectors to log only access denied events when the calling user identity is not on a known safe list. This lets you capture unauthorized access attempts while excluding routine traffic from trusted identities, reducing both logging costs and noise.
With UserIdentity filtering, customers building a data perimeter strategy can focus on network activity event logging for scenarios that matter most in security. You can configure selectors to log only VpceAccessDenied events from identities outside a trusted set of IAM roles. This enables detection of potential data exfiltration attempts through VPC endpoints without the cost of logging every successful API call from approved principals. You can combine UserIdentity conditions with existing fields like eventName or vpcEndpointId for fine-grained control over what gets recorded.
You can use this feature via the AWS Management Console, AWS Command Line Interface, and AWS SDKs. This feature is available in all AWS Regions where CloudTrail network activity events are supported. To learn more about Network Activity events, visit the AWS CloudTrail user guide or read AWS Blog on how to enable Network Activity Events.
   

Publicado el Deja un comentario

Amazon Connect delivers more natural agentic voice experiences with expanded language support and speech controls

Amazon Connect customers can now deliver more natural, human-sounding agentic voice experiences with expanded support across 50+ languages including Spanish, French, Italian, Japanese, Korean, Portuguese, and Thai, over 100 new voice options, and conversational improvements that make AI interactions sound more fluid and responsive.

Amazon Connect’s agentic self-service capabilities enable AI agents to understand, reason, and take action across voice and digital channels, adapting responses to match customer tone and sentiment while maintaining natural conversational pace. With this launch, you can deliver smoother conversations with seamless response pacing that fills natural pauses so interactions feel immediate rather than halting, more accurate turn-taking so agents and customers don’t talk over each other, and speech controls that let you adjust speed, volume, and emotion to match your brand’s tone.

To learn more about this feature, see the Amazon Connect Customer Administrator Guide. For the full list of supported languages and voices, see Supported Languages. For region availability, please see the availability of Amazon Connect Customer features by Region. To learn more about Amazon Connect Customer, an agentic AI solution that helps enterprises deliver exceptional customer experiences visit the Amazon Connect Customer website.

 

​Amazon Connect customers can now deliver more natural, human-sounding agentic voice experiences with expanded support across 50+ languages including Spanish, French, Italian, Japanese, Korean, Portuguese, and Thai, over 100 new voice options, and conversational improvements that make AI interactions sound more fluid and responsive.
Amazon Connect’s agentic self-service capabilities enable AI agents to understand, reason, and take action across voice and digital channels, adapting responses to match customer tone and sentiment while maintaining natural conversational pace. With this launch, you can deliver smoother conversations with seamless response pacing that fills natural pauses so interactions feel immediate rather than halting, more accurate turn-taking so agents and customers don’t talk over each other, and speech controls that let you adjust speed, volume, and emotion to match your brand’s tone.
To learn more about this feature, see the Amazon Connect Customer Administrator Guide. For the full list of supported languages and voices, see Supported Languages. For region availability, please see the availability of Amazon Connect Customer features by Region. To learn more about Amazon Connect Customer, an agentic AI solution that helps enterprises deliver exceptional customer experiences visit the Amazon Connect Customer website.  

Publicado el Deja un comentario

Amazon Managed Service for Apache Flink now supports Apache Flink 2.3

Amazon Managed Service for Apache Flink now supports Apache Flink version 2.3. This release includes adaptive partition selection for improved backpressure handling, so applications run more smoothly under uneven load. It also introduces better handling of out-of-order updates in change data capture (CDC) pipelines that improves data correctness, and new SQL functions make it easier to convert between changelog and standard streams. For a full list of improvements, see the Amazon Managed Service for Apache Flink release notes.

Amazon Managed Service for Apache Flink makes it easier to transform and analyze streaming data in real time, by simplifying the setup, operation, and scaling of Apache Flink applications. Developers and data engineers can focus on building and running their streaming applications without managing the underlying infrastructure.

To get started, create a new application on Apache Flink 2.3, or use in-place version upgrades to move compatible applications to the Flink 2.3 runtime for a simpler and faster upgrade. Apache Flink 2.3 is available across all AWS Regions where Amazon Managed Service for Apache Flink is offered. To learn more, see the Amazon Managed Service for Apache Flink Developer Guide.

 

​Amazon Managed Service for Apache Flink now supports Apache Flink version 2.3. This release includes adaptive partition selection for improved backpressure handling, so applications run more smoothly under uneven load. It also introduces better handling of out-of-order updates in change data capture (CDC) pipelines that improves data correctness, and new SQL functions make it easier to convert between changelog and standard streams. For a full list of improvements, see the Amazon Managed Service for Apache Flink release notes. Amazon Managed Service for Apache Flink makes it easier to transform and analyze streaming data in real time, by simplifying the setup, operation, and scaling of Apache Flink applications. Developers and data engineers can focus on building and running their streaming applications without managing the underlying infrastructure. To get started, create a new application on Apache Flink 2.3, or use in-place version upgrades to move compatible applications to the Flink 2.3 runtime for a simpler and faster upgrade. Apache Flink 2.3 is available across all AWS Regions where Amazon Managed Service for Apache Flink is offered. To learn more, see the Amazon Managed Service for Apache Flink Developer Guide.  

Publicado el Deja un comentario

Introducing KNFSD File Cache – Now in Preview

Today, AWS announces the availability of KNFSD File Cache, an open-source, Apache-2.0 licensed solution for deploying a scalable, high-speed Network File System (NFS) cache on AWS. KNFSD File Cache mounts exports from one or more source NFS servers, whether on-premises, in another AWS Availability Zone or Region, or in another cloud over AWS Interconnect – multicloud, and re-exports them to NFS clients in AWS. You can front multiple on-premises filers, in-cloud file systems such as Amazon FSx for OpenZFS and Amazon FSx for NetApp ONTAP, and any other NFS v3, v4.1, or v4.2 compliant filer. Frequently read data is cached in memory and on local NVMe storage, so files cross the high-latency link to the source once and are then served to large compute fleets at local VPC speed. The solution is designed for read-heavy burst compute workloads such as visual effects rendering, simulation, financial services, health and life sciences, microprocessor design, weather forecasting, and energy.

KNFSD File Cache builds on standard Linux kernel technology: nfs-kernel-server provides NFS re-export, and FS-Cache provides the persistent disk cache. Because it uses the native NFS stack, it fully supports the NFS client-server protocol, including byte-range reads and writes, synchronous and asynchronous writes, and both write-through and write-around modes. You build the cache Amazon Machine Image (AMI) with Packer, then deploy the cluster with the included Terraform module. Cache nodes run in an Amazon Elastic Compute Cloud (Amazon EC2) Auto Scaling group on AMD, Intel, or AWS Graviton instances, with client traffic distributed by DNS round-robin or a Network Load Balancer, and optional automatic scaling based on the number of active NFS client connections. An Amazon CloudWatch dashboard provides more than 70 metrics through an OpenTelemetry-based agent, which can also publish to third-party tools such as Prometheus and Grafana.

KNFSD File Cache (preview) is available in all AWS Regions. There are no licensing costs; you pay only for the AWS resources you consume.

To get started, visit the KNFSD File Cache GitHub repository, launch blog, and AWS Solutions Guidance. For detailed deployment and configuration guidance, see the GitHub documentation.

 

​Today, AWS announces the availability of KNFSD File Cache, an open-source, Apache-2.0 licensed solution for deploying a scalable, high-speed Network File System (NFS) cache on AWS. KNFSD File Cache mounts exports from one or more source NFS servers, whether on-premises, in another AWS Availability Zone or Region, or in another cloud over AWS Interconnect – multicloud, and re-exports them to NFS clients in AWS. You can front multiple on-premises filers, in-cloud file systems such as Amazon FSx for OpenZFS and Amazon FSx for NetApp ONTAP, and any other NFS v3, v4.1, or v4.2 compliant filer. Frequently read data is cached in memory and on local NVMe storage, so files cross the high-latency link to the source once and are then served to large compute fleets at local VPC speed. The solution is designed for read-heavy burst compute workloads such as visual effects rendering, simulation, financial services, health and life sciences, microprocessor design, weather forecasting, and energy.
KNFSD File Cache builds on standard Linux kernel technology: nfs-kernel-server provides NFS re-export, and FS-Cache provides the persistent disk cache. Because it uses the native NFS stack, it fully supports the NFS client-server protocol, including byte-range reads and writes, synchronous and asynchronous writes, and both write-through and write-around modes. You build the cache Amazon Machine Image (AMI) with Packer, then deploy the cluster with the included Terraform module. Cache nodes run in an Amazon Elastic Compute Cloud (Amazon EC2) Auto Scaling group on AMD, Intel, or AWS Graviton instances, with client traffic distributed by DNS round-robin or a Network Load Balancer, and optional automatic scaling based on the number of active NFS client connections. An Amazon CloudWatch dashboard provides more than 70 metrics through an OpenTelemetry-based agent, which can also publish to third-party tools such as Prometheus and Grafana.
KNFSD File Cache (preview) is available in all AWS Regions. There are no licensing costs; you pay only for the AWS resources you consume.
To get started, visit the KNFSD File Cache GitHub repository, launch blog, and AWS Solutions Guidance. For detailed deployment and configuration guidance, see the GitHub documentation.  

Publicado el Deja un comentario

Amazon CloudWatch Synthetics now supports customer managed encryption keys

Amazon CloudWatch Synthetics now supports customer managed AWS Key Management Service (KMS) keys for encrypting canary environment variables, giving you full control over the encryption of sensitive configuration data such as API keys, credentials, and tokens. Previously, environment variables were encrypted at rest using only an AWS owned key. Now, in addition to the default AWS owned key, you can specify your own symmetric KMS key for encryption at rest, and you can also encrypt individual values client-side before they are stored.

With encryption at rest, you specify a customer managed KMS key when creating or updating a canary, and CloudWatch Synthetics uses a grant on the key to handle encryption and decryption transparently. With client-side encryption, you encrypt values before storage, and your canary script decrypts them at runtime using the AWS KMS Decrypt API. This benefits teams in regulated industries that require organizational key management policies, auditability, or key rotation controls across all services.

Amazon CloudWatch Synthetics customer managed key encryption is available in all commercial AWS Regions. Multi-location canaries can use a different KMS key per replica Region.

To learn more, see Encrypting environment variables in the Amazon CloudWatch User Guide.

 

​Amazon CloudWatch Synthetics now supports customer managed AWS Key Management Service (KMS) keys for encrypting canary environment variables, giving you full control over the encryption of sensitive configuration data such as API keys, credentials, and tokens. Previously, environment variables were encrypted at rest using only an AWS owned key. Now, in addition to the default AWS owned key, you can specify your own symmetric KMS key for encryption at rest, and you can also encrypt individual values client-side before they are stored.
With encryption at rest, you specify a customer managed KMS key when creating or updating a canary, and CloudWatch Synthetics uses a grant on the key to handle encryption and decryption transparently. With client-side encryption, you encrypt values before storage, and your canary script decrypts them at runtime using the AWS KMS Decrypt API. This benefits teams in regulated industries that require organizational key management policies, auditability, or key rotation controls across all services.
Amazon CloudWatch Synthetics customer managed key encryption is available in all commercial AWS Regions. Multi-location canaries can use a different KMS key per replica Region.
To learn more, see Encrypting environment variables in the Amazon CloudWatch User Guide.