Publicado el Deja un comentario

Amazon RDS for SQL Server now supports restoring TDE databases on Mult-AZ instances

Amazon Relational Database Service (Amazon RDS) for SQL Server now supports restoring Transparent Data Encryption (TDE)-enabled SQL Server databases on Multi-AZ instances and instances configured with a read replica in the same region, using native backup and restore. Previously, TDE-enabled database restore was available only for Single-AZ instances, requiring you to disable TDE or migrate to a Single-AZ configuration before restoring encrypted databases.

You can restore TDE-enabled database backups directly to Amazon RDS for SQL Server Multi-AZ instances and instances configured with a read replica in the same region. Back up your existing TDE certificate, store it in Amazon S3, and restore it to your Amazon RDS instance with the TDE option enabled. Then, restore your TDE-enabled database backup from Amazon S3 using Amazon RDS native backup and restore. This simplifies your migration and recovery workflows when you require both encryption at rest with TDE and the high availability of Multi-AZ deployments.

This feature is available in all AWS Regions where Amazon RDS for SQL Server is supported. To learn more, see the Amazon RDS for SQL Server User Guide.

 

​Amazon Relational Database Service (Amazon RDS) for SQL Server now supports restoring Transparent Data Encryption (TDE)-enabled SQL Server databases on Multi-AZ instances and instances configured with a read replica in the same region, using native backup and restore. Previously, TDE-enabled database restore was available only for Single-AZ instances, requiring you to disable TDE or migrate to a Single-AZ configuration before restoring encrypted databases. You can restore TDE-enabled database backups directly to Amazon RDS for SQL Server Multi-AZ instances and instances configured with a read replica in the same region. Back up your existing TDE certificate, store it in Amazon S3, and restore it to your Amazon RDS instance with the TDE option enabled. Then, restore your TDE-enabled database backup from Amazon S3 using Amazon RDS native backup and restore. This simplifies your migration and recovery workflows when you require both encryption at rest with TDE and the high availability of Multi-AZ deployments. This feature is available in all AWS Regions where Amazon RDS for SQL Server is supported. To learn more, see the Amazon RDS for SQL Server User Guide.  

Publicado el Deja un comentario

Amazon GameLift Streams now supports Custom Aspect Ratio and Dynamic Resolution

Amazon GameLift Streams now supports Custom Aspect Ratio and Dynamic Resolution, giving you greater control over the streaming experience across diverse player devices and network conditions.

With Custom Aspect Ratio, you can configure a specific resolution per stream session to match your player’s device — including portrait, landscape, ultra-wide, and square aspect ratios. This eliminates letterboxing or pillarboxing, delivering native full-screen experiences on mobile phones, tablets, and non-standard displays. Specify any resolution from 320 to 4096 pixels per dimension (up to 1080p total pixel budget) using the DisplayConfiguration parameter in the StartStreamSession API. You can also try custom resolution from the AWS Console.

Dynamic Resolution automatically adapts stream quality when a player’s network bandwidth fluctuates. When bandwidth drops, the stream gracefully reduces resolution to maintain smooth playback without frame drops or disconnections — and automatically recovers to full quality when conditions improve. Dynamic Resolution is enabled by default for all new stream groups with no configuration required. Customers will need to download the new Web SDK.

Both features are available in all AWS Regions where Amazon GameLift Streams is offered. To learn more, see Custom stream resolution in the Amazon GameLift Streams Developer Guide. 
 
https://docs.aws.amazon.com/gameliftstreams/latest/developerguide/custom-stream-resolution.html

 

​Amazon GameLift Streams now supports Custom Aspect Ratio and Dynamic Resolution, giving you greater control over the streaming experience across diverse player devices and network conditions.
With Custom Aspect Ratio, you can configure a specific resolution per stream session to match your player’s device — including portrait, landscape, ultra-wide, and square aspect ratios. This eliminates letterboxing or pillarboxing, delivering native full-screen experiences on mobile phones, tablets, and non-standard displays. Specify any resolution from 320 to 4096 pixels per dimension (up to 1080p total pixel budget) using the DisplayConfiguration parameter in the StartStreamSession API. You can also try custom resolution from the AWS Console.
Dynamic Resolution automatically adapts stream quality when a player’s network bandwidth fluctuates. When bandwidth drops, the stream gracefully reduces resolution to maintain smooth playback without frame drops or disconnections — and automatically recovers to full quality when conditions improve. Dynamic Resolution is enabled by default for all new stream groups with no configuration required. Customers will need to download the new Web SDK.
Both features are available in all AWS Regions where Amazon GameLift Streams is offered. To learn more, see Custom stream resolution in the Amazon GameLift Streams Developer Guide.    https://docs.aws.amazon.com/gameliftstreams/latest/developerguide/custom-stream-resolution.html  

Publicado el Deja un comentario

AWS Security Hub MCP App brings exposure findings into your AI-assisted workflow (Preview)

AWS announces the preview of the AWS Security Hub MCP App, a local Model Context Protocol (MCP) server that brings your Security Hub exposure findings directly into Claude Desktop.  This capability can help accelerates your security investigations by reducing context switching and manual triage, letting you explore and act on your exposures without leaving your AI-assisted workflow.

With the Security Hub MCP App, you can investigate your security posture in natural language: view your top exposure findings, drill into a finding’s attack path and expanded network path, examine correlated findings and affected resource configurations, and get remediation recommendations. Each tool call returns both a text summary for your AI agent to reason overover and an interactive visualization for you to verify in the same conversation. The MCP server runs locally on your machine using your existing AWS credentials, and every tool is read-only,– no changes are made to your environment.

The Security Hub MCP App is available at no additional cost to Security Hub customers. This feature is available in preview in all AWS commercial Regions that support Security Hub. To learn more, see the AWS Security Hub User Guide and the AWS Security Hub product page. For the full list of Regions, see the AWS Regional Services List.

 

​AWS announces the preview of the AWS Security Hub MCP App, a local Model Context Protocol (MCP) server that brings your Security Hub exposure findings directly into Claude Desktop.  This capability can help accelerates your security investigations by reducing context switching and manual triage, letting you explore and act on your exposures without leaving your AI-assisted workflow.
With the Security Hub MCP App, you can investigate your security posture in natural language: view your top exposure findings, drill into a finding’s attack path and expanded network path, examine correlated findings and affected resource configurations, and get remediation recommendations. Each tool call returns both a text summary for your AI agent to reason overover and an interactive visualization for you to verify in the same conversation. The MCP server runs locally on your machine using your existing AWS credentials, and every tool is read-only,– no changes are made to your environment.
The Security Hub MCP App is available at no additional cost to Security Hub customers. This feature is available in preview in all AWS commercial Regions that support Security Hub. To learn more, see the AWS Security Hub User Guide and the AWS Security Hub product page. For the full list of Regions, see the AWS Regional Services List.  

Publicado el Deja un comentario

Replantear la seguridad para la era de la IA

Replantear la seguridad para la era de la IA

Gráfico con el encabezado "La física de la ciberseguridad está cambiando" en inglés. La palabra "física" aparece en texto blanco dentro de un rectángulo redondeado con degradado de azul a verde azulado, mientras que el resto del encabezado se muestra en texto negro sobre un fondo blanco. Detrás del encabezado se aprecia un tenue collage de ecuaciones escritas a mano, fórmulas matemáticas, gráficos, diagramas y cálculos científicos, lo que sugiere una conexión entre la ciberseguridad y los principios de la física y el análisis de sistemas.

Por: Hayete Gallot, vicepresidenta ejecutiva, Microsoft Security.

Por qué la seguridad necesita una nueva pila cibernética Presentamos Project Perception

La física de la ciberseguridad ha comenzado a cambiar. Los sistemas autónomos ahora pueden razonar, adaptarse y operar de manera continua. Al mismo tiempo, el coste de la ofensiva disminuye, mientras que el volumen, la velocidad y la complejidad de lo que debe asegurarse siguen su crecimiento. Los atacantes pueden generar exploits (código que aprovecha vulnerabilidades) más rápido, escalar campañas aún más y operar con una eficiencia sin precedentes. Los enfoques diseñados para un mundo de actores humanos no pueden seguir el ritmo de un mundo de IA, agentes y ataques a velocidad de máquina.

La seguridad necesita una nueva pila cibernética. Una nueva Cyber Stack debe percibir de manera continua el riesgo en todo el ámbito digital, razonar a través de grandes cantidades de contexto y actuar a la velocidad de la máquina. Debe aprender y adaptarse a medida que evolucionan los entornos, para ayudar a las organizaciones a mantenerse por delante de las amenazas. Y dado que la seguridad es, en última instancia, una misión humana, debe amplificar a los defensores con mejores conocimientos y formas más poderosas de actuar. La característica definitoria de la próxima generación de sistemas de seguridad no será su capacidad para generar más alertas. Será su capacidad para percibir, razonar y actuar de manera continua.

Esa visión nos llevó a crear Project Perception. Un nuevo sistema de seguridad agéntico diseñado para las realidades de la IA. Convierte las señales en protecciones en tiempo real a través de IA para defenderse de ella.

Project Perception reúne señales, contexto, modelos y agentes especializados en un sistema de defensa en aprendizaje continuo. Puede razonar, priorizar y actuar a velocidad de máquina mientras mantiene a los humanos, con firmeza, bajo control y les empodera con nuevos y potentes flujos de trabajo.

Project Perception se basa en una idea sencilla: una defensa eficaz requiere un entendimiento continuo de cómo un atacante ve el mundo, cómo un defensor evalúa el riesgo y cómo mejoran las protecciones con el tiempo. Para lograrlo, Perception coordina tres clases de agentes especializados. Los agentes del equipo rojo identifican posibles caminos de compromiso antes de que un atacante pueda explotarlos. Los agentes del equipo azul investigan, razonan sobre el contexto y determinan qué representa un riesgo significativo. Los agentes del equipo verde toman medidas correctivas y refuerzan las defensas en todo el entorno. Al trabajar juntos, estos agentes forman un sistema de circuito cerrado que descubre, evalúa y mejora de manera continua la postura de seguridad de una organización.

Diagrama titulado "Project Perception: Equipos de agentes". Se muestran tres equipos de agentes interconectados en una secuencia horizontal: los agentes del equipo rojo, representados por un ícono de insecto, simulan ataques; los agentes del equipo azul, representados por un ícono de escudo, detectan y clasifican amenazas; y los agentes del equipo verde, representados por un ícono de llave inglesa, corrigen y remedian problemas. Los signos de suma entre los equipos indican colaboración y coordinación entre los grupos de agentes como parte de un flujo de trabajo continuo de ciberseguridad.

Un sistema como Project Perception solo es tan efectivo como la visibilidad que tiene, las acciones que puede tomar, la experiencia de los equipos que lo construyen y los modelos que puede utilizar. Microsoft reúne los cuatro.

Vemos a través de identidades, endpoints, aplicaciones, datos, nubes y sistemas de IA, lo que proporciona una amplia visibilidad en todo el entorno digital. Por igual de importante, podemos ayudar a los clientes a actuar en esos entornos. Combinadas con décadas de investigación en seguridad, inteligencia de amenazas y experiencia operativa real para defender organizaciones, estas capacidades moldean cómo Project Perception razona, prioriza y responde.

La seguridad es una misión 24/7. Las organizaciones necesitan una protección de una alta eficacia, disponible de manera continua y asequible a gran escala. Eso requiere más que acceso al modelo más capaz. Requiere aplicar el modelo adecuado a la tarea adecuada. Project Perception adopta una arquitectura multimodelo que combina modelos cibernéticos de vanguardia y especializados, lo que optimiza tanto la calidad como el coste.

Como parte de esta estrategia multimodelo, estamos comprometidos a ofrecer a los clientes los mejores modelos para cada tarea de seguridad, incluido innovar con nuestros propios modelos especializados. El primer escenario es la gestión de vulnerabilidades de software, al incorporar MAI-Cyber-1-Flash dentro de MDASH, nuestro equipo de agentes multimodelo de vulnerabilidades de software. MDASH con MAI-Cyber-1-Flash ofrece un 96% sobre CyberGym, un referente líder en la industria, +12 puntos por encima de Mythos. Y esta misma configuración ofrece casi un 50% de ahorro respecto a la configuración actual de MDASH en el mercado. Esa es la potencia de un sistema bien ajustado y multimodelo, con acceso a datos históricos de entrenamiento únicos y ricos. A continuación, Project Perception aprovechará MAI-Cyber-1-Flash para muchos más flujos de trabajo de seguridad, más allá del escenario de vulnerabilidad de software.

Llevamos esta visión a clientes de todo el mundo a través de Project Perception, que se presenta en vista previa pública el 3 de agosto.

Una pila cibernética diseñada para la seguridad agéntica

Ofrecer seguridad agéntica requiere mucho más que añadir agentes a flujos de trabajo existentes. Requiere una nueva pila cibernética, diseñada desde cero.

La pila comienza con señales y sensores que proporcionan conciencia en todo el espacio digital. El contexto de seguridad transforma esas señales en una comprensión eficiente para el token que los agentes pueden utilizar. Los modelos proporcionan inteligencia y razonamiento. Un harness coordina modelos y agentes a través de flujos de trabajo de seguridad. Los agentes aplican esa inteligencia a través de los flujos de trabajo de seguridad y los actuadores traducen las decisiones en protección. Juntas, estas capas crean un sistema de aprendizaje continuo que puede comprender el riesgo, adaptarse a condiciones cambiantes y mejorar los resultados de seguridad con el tiempo.

Diagrama titulado "La nueva pila de ciberseguridad". Muestra seis capas de una arquitectura de ciberseguridad impulsada por IA. De abajo hacia arriba, las capas son: Señales y sensores (visibilidad en endpoints, identidades, datos, nubes, aplicaciones e IA); Contexto (inteligencia enriquecida continuamente que proporciona contexto operativo); Modelos (un enfoque multimodelo para razonar sobre amenazas); Orquestación (un marco que coordina agentes y modelos); Agentes (agentes especializados de los equipos rojo, azul y verde que realizan una defensa continua); y Accionadores (mecanismos que convierten las decisiones de los agentes en acciones en el mundo real). Las capas se muestran como bandas horizontales apiladas dentro de un marco rectangular con esquinas redondeadas, ilustrando cómo los datos de seguridad se transforman en acciones defensivas automatizadas.

Aunque cada capa proporciona capacidades importantes, el poder del Project Perception proviene de cómo trabajan juntos.

Contexto de seguridad construido para IA

El razonamiento efectivo requiere más que señales en bruto. Los agentes necesitan contexto.

Microsoft transforma su amplitud de visibilidad, inteligencia de amenazas y experiencia en seguridad en un contexto de seguridad que conecta datos, conocimientos y semántica de seguridad a lo largo del ámbito digital. El resultado es una representación actualizada de manera continua de los activos, identidades, relaciones, riesgos y actividades de una organización que proporciona a los agentes una comprensión compartida y casi en tiempo real del entorno que ayudan a defender.

Diagrama de estilo Sankey que muestra cómo los datos de seguridad fluyen desde Sensores y señales hacia Contexto de seguridad, Modelos y Agentes. Las fuentes de datos, entre ellas Microsoft Defender for Endpoint, Microsoft Entra ID, Microsoft Sentinel, Microsoft Defender, Azure Resource Manager, Análisis del comportamiento de usuarios y entidades (UEBA), Administración de la superficie de exposición e Inteligencia de amenazas, alimentan categorías de eventos y telemetría como dispositivos, identidades, alertas, correo electrónico, recursos, comportamiento, grafo de exposición y datos de operaciones del equipo rojo.

Estas señales se enriquecen para crear capas de contexto de seguridad que incluyen Grafo, Grafo de ataque, Movimiento lateral, Árbol de procesos, Grafo de identidades, Grafo de exposición, Exposición de agentes, Clasificación de alertas, Amenazas por correo electrónico, Infraestructura, Operaciones del equipo rojo y Detección de anomalías.

Posteriormente, el contexto fluye hacia los resultados de los agentes del equipo rojo, equipo azul y equipo verde, ilustrando cómo la telemetría de seguridad conectada respalda flujos de trabajo coordinados de agentes de IA para la simulación de ataques, la detección de amenazas y la remediación.

Esta comprensión compartida es fundamental para el funcionamiento de Project Perception. En lugar de obligar a los agentes a recopilar, correlacionar y reconstruir de manera continua el contexto a partir de señales en bruto, les proporciona acceso inmediato y eficiente en tokens a la información que necesitan para razonar sobre el riesgo, priorizar acciones y tomar decisiones. Al fundamentar cada interacción en este rico contexto de seguridad, Project Perception mejora la precisión y coherencia del razonamiento, al tiempo que reduce el tiempo, el cálculo y el coste necesarios para operar a gran escala.

Una arquitectura multimodelo diseñada para la seguridad

Ningún modelo único será óptimo para todas las tareas de seguridad. Una defensa cibernética eficaz requiere aplicar el modelo adecuado al problema adecuado en el momento adecuado.

Para Project Perception, el modelo adecuado se determina por la combinación de calidad, fiabilidad, latencia y coste. En lugar de depender de un solo modelo, Project Perception adopta una arquitectura multimodelo que selecciona de manera continua las capacidades más adecuadas para la tarea, para optimizar tanto la eficacia como la economía. Dado que la seguridad es una misión constante, la economía sostenible es esencial para operar la protección a gran escala.

Este enfoque se basa en la investigación continua, la evaluación y el benchmarking a través de modelos pioneros y especializados. Nuestros investigadores en seguridad evalúan de manera continua los modelos frente a flujos de trabajo reales de seguridad, lo que nos permite emparejar cada tarea con el modelo que ofrece el mejor resultado. Esto permite a los clientes beneficiarse de los avances en IA sin estar atados a ningún modelo único.

Actuadores — información sobre las acciones

Los equipos de seguridad no necesitan más información. Necesitan mejores resultados.

Por eso los actuadores son una parte fundamental del Cyber Stack. Project Perception está integrado a profundidad en los productos de Microsoft Security, lo que permite a los agentes conectar información de valor con acciones. Las organizaciones pueden reducir de manera continua el riesgo en lugar de limitarse a identificarlo, para ayudar a los defensores a fortalecer la seguridad mientras mantienen el control.

Construido con la seguridad primero

En cada capa de la Cyber Stack hay una base de confianza. Project Perception está construido en línea con los principios de IA responsable de Microsoft y hereda los controles de seguridad, cumplimiento, gobernanza y operativos en los que nuestros clientes ya dependen. Esto garantiza que estas capacidades se entreguen con el mismo rigor, responsabilidad y preparación empresarial que los clientes esperan.

El futuro de la seguridad

La seguridad siempre ha sido una carrera entre atacantes y defensores. La IA cambia la velocidad, la escala y la economía de esa carrera. Los defensores necesitan sistemas que puedan percibir, razonar y actuar de manera continua junto a ellos.

El Project Perception es como empezamos a construir ese futuro.

Para saber más sobre las soluciones de seguridad de Microsoft, visiten nuestra página web. Agreguen a Favoritos el blog de Seguridad para estar al día con nuestra cobertura experta sobre temas de seguridad. Además, síganos en LinkedIn (Microsoft Security) y X (@MSFTSecurity) para las últimas noticias y actualizaciones sobre ciberseguridad.

Hayete Gallot lidera el trabajo de Microsoft para ayudar a las organizaciones a operar de manera segura en un mundo impulsado por la IA. Su ámbito incluye identidad, protección contra amenazas, cumplimiento normativo y seguridad de datos a escala global.

The post Replantear la seguridad para la era de la IA appeared first on Source LATAM.

 

​The post Replantear la seguridad para la era de la IA appeared first on Source LATAM.  

Publicado el Deja un comentario

AWS Elemental MediaTailor adds configurable ad timeout and concurrency controls for improved ad fill and faster startup

AWS Elemental MediaTailor now gives you direct control over ad decision server (ADS) timeout. Previously, changing these settings required contacting AWS Support. You can now configure individual HTTP ad request timeouts, total ad personalization time budgets for live, VOD, and live ad prefetch, and enable parallel ADS requests.

These settings allow you to optimize ad delivery performance for your specific workflows. For example, you can increase the personalization time budget for live events to improve ad fill rates or enable parallel ADS requests in VOD workflows to reduce overall response time for faster video startup. New prefetch-specific timeout settings give you additional granularity for livestream ad retrieval.

You can configure these settings through the AWS Elemental MediaTailor console, AWS CLI, or AWS SDKs using the new AdsPersonalizationTimeouts and AdsPersonalizationConcurrency parameters on your playback configurations.

This feature is available in all AWS Regions where AWS Elemental MediaTailor is available. 

To learn more about configuring ADS request timeouts, personalization time budgets, and concurrency, see Advanced settings in the AWS Elemental MediaTailor User Guide.

 

​AWS Elemental MediaTailor now gives you direct control over ad decision server (ADS) timeout. Previously, changing these settings required contacting AWS Support. You can now configure individual HTTP ad request timeouts, total ad personalization time budgets for live, VOD, and live ad prefetch, and enable parallel ADS requests.
These settings allow you to optimize ad delivery performance for your specific workflows. For example, you can increase the personalization time budget for live events to improve ad fill rates or enable parallel ADS requests in VOD workflows to reduce overall response time for faster video startup. New prefetch-specific timeout settings give you additional granularity for livestream ad retrieval.
You can configure these settings through the AWS Elemental MediaTailor console, AWS CLI, or AWS SDKs using the new AdsPersonalizationTimeouts and AdsPersonalizationConcurrency parameters on your playback configurations.
This feature is available in all AWS Regions where AWS Elemental MediaTailor is available. 
To learn more about configuring ADS request timeouts, personalization time budgets, and concurrency, see Advanced settings in the AWS Elemental MediaTailor User Guide.  

Publicado el Deja un comentario

Amazon Connect now supports audio optimization for Azure Virtual Desktop and Windows 365 Cloud PC

Agents using Microsoft Azure Virtual Desktop (AVD) or Windows 365 Cloud PC can now take calls directly from their virtual desktop session with audio optimization enabled. To get started, IT administrators need to complete a one-time setup for their virtual desktop environment. Once configured, media is redirected from the virtual desktop to the agent’s local device, improving audio quality.

Agents simply log into their Azure Virtual Desktop or Windows 365 Cloud PC session and start accepting calls using the Amazon Connect Customer agent workspace or a custom agent interface built with the Amazon Connect Customer open-source JavaScript libraries. This support is in addition to existing audio optimization for Amazon WorkSpaces, Citrix cloud desktops, and Omnissa cloud desktops.

This feature is available in all AWS Regions where Amazon Connect Customer is offered, except AWS GovCloud (US-West). To learn more, see the Amazon Connect Customer Administrator Guide.

 

​Agents using Microsoft Azure Virtual Desktop (AVD) or Windows 365 Cloud PC can now take calls directly from their virtual desktop session with audio optimization enabled. To get started, IT administrators need to complete a one-time setup for their virtual desktop environment. Once configured, media is redirected from the virtual desktop to the agent’s local device, improving audio quality. Agents simply log into their Azure Virtual Desktop or Windows 365 Cloud PC session and start accepting calls using the Amazon Connect Customer agent workspace or a custom agent interface built with the Amazon Connect Customer open-source JavaScript libraries. This support is in addition to existing audio optimization for Amazon WorkSpaces, Citrix cloud desktops, and Omnissa cloud desktops. This feature is available in all AWS Regions where Amazon Connect Customer is offered, except AWS GovCloud (US-West). To learn more, see the Amazon Connect Customer Administrator Guide.  

Publicado el Deja un comentario

Amazon MWAA now supports Apache Airflow version 2.11.2

Amazon Managed Workflows for Apache Airflow (MWAA) now supports Apache Airflow version 2.11.2. Amazon MWAA is a managed service that runs Apache Airflow at scale without the operational overhead of managing the underlying infrastructure. Apache Airflow 2.11.2 is a maintenance release that includes security improvements, bug fixes, and dependency upgrades.

This release upgrades core dependencies with security patches and stability improvements to the Airflow webserver and task execution layers. It also includes fixes to task lifecycle management for queued tasks, enhanced secrets masking in logs, UI corrections in the Task Instances list view, and provider package updates for S3 and CloudWatch log delivery.

You can create a new Apache Airflow 2.11.2 environment on Amazon MWAA or upgrade your existing environments with a few clicks in the AWS Management Console in all currently available Amazon MWAA regions. To learn more, visit the Amazon MWAA documentation, review the Apache Airflow 2.11.2 release notes, and explore the list of available Airflow versions on MWAA.

 

​Amazon Managed Workflows for Apache Airflow (MWAA) now supports Apache Airflow version 2.11.2. Amazon MWAA is a managed service that runs Apache Airflow at scale without the operational overhead of managing the underlying infrastructure. Apache Airflow 2.11.2 is a maintenance release that includes security improvements, bug fixes, and dependency upgrades. This release upgrades core dependencies with security patches and stability improvements to the Airflow webserver and task execution layers. It also includes fixes to task lifecycle management for queued tasks, enhanced secrets masking in logs, UI corrections in the Task Instances list view, and provider package updates for S3 and CloudWatch log delivery. You can create a new Apache Airflow 2.11.2 environment on Amazon MWAA or upgrade your existing environments with a few clicks in the AWS Management Console in all currently available Amazon MWAA regions. To learn more, visit the Amazon MWAA documentation, review the Apache Airflow 2.11.2 release notes, and explore the list of available Airflow versions on MWAA.  

Publicado el Deja un comentario

Amazon EC2 Dedicated Hosts now support host resource groups without self-managed licenses

Starting today, customers can create Host Resource Groups (HRGs) for EC2 Dedicated Hosts without the previously required step of creating Self-Managed Licenses (SMLs) and associating AMIs through AWS License Manager.

This flexibility is particularly valuable for EC2 Mac Instance customers and for customers who need Dedicated Hosts for hardware-level isolation rather than Bring Your Own License (BYOL). Customers with BYOL workloads can continue to create HRGs with SMLs to ensure that only instances from associated AMIs can be launched on the host and track host-level license consumption.

To create an HRG without SML, uncheck the «Restrict to AMIs associated with self-managed license» option when creating a Host Resource Group in the EC2 Console, or set instance-launch-option to license-configuration-required via the AWS CLI.

This feature is available in all AWS Regions where Host Resource Groups are supported. To learn more, visit the Host Resource Group User Guide

 

​Starting today, customers can create Host Resource Groups (HRGs) for EC2 Dedicated Hosts without the previously required step of creating Self-Managed Licenses (SMLs) and associating AMIs through AWS License Manager.
This flexibility is particularly valuable for EC2 Mac Instance customers and for customers who need Dedicated Hosts for hardware-level isolation rather than Bring Your Own License (BYOL). Customers with BYOL workloads can continue to create HRGs with SMLs to ensure that only instances from associated AMIs can be launched on the host and track host-level license consumption.
To create an HRG without SML, uncheck the «Restrict to AMIs associated with self-managed license» option when creating a Host Resource Group in the EC2 Console, or set instance-launch-option to license-configuration-required via the AWS CLI.
This feature is available in all AWS Regions where Host Resource Groups are supported. To learn more, visit the Host Resource Group User Guide  

Publicado el Deja un comentario

Amazon Kinesis Data Streams now supports scaling down ingest capacity with warm throughput

Amazon Kinesis Data Streams is a serverless streaming data service that makes it easy to capture, process, and store data streams at any scale. On-demand streams automatically increase ingest capacity in response to rising data ingest usage. With On-demand Advantage mode, you can proactively manage stream capacity using warm throughput to prepare streams for sudden changes in data traffic. We are extending warm throughput with the ability to also scale down ingest capacity, giving you full control to scale your stream’s write throughput up or down.

To scale down, simply set a lower warm throughput value on your on-demand stream. The stream adjusts to the requested capacity or the amount needed to support peak data ingest usage in the last hour, whichever is higher. This ensures your stream always retains sufficient capacity for current traffic while releasing excess capacity you no longer need. As a result, you get optimal stream-processing performance and cost efficiency. 

Warm throughput scale-down is available at no additional cost for all on-demand streams with On-demand Advantage mode enabled.  For more information about On-demand Advantage, see Choose the right mode to stream in in the Amazon Kinesis Data Streams Developer Guide. To get started with the feature, see Update a stream. For pricing details, see Amazon Kinesis Data Streams pricing.

The feature is available in all AWS Regions where Amazon Kinesis Data Streams On-demand Advantage is supported. 

 

 

​Amazon Kinesis Data Streams is a serverless streaming data service that makes it easy to capture, process, and store data streams at any scale. On-demand streams automatically increase ingest capacity in response to rising data ingest usage. With On-demand Advantage mode, you can proactively manage stream capacity using warm throughput to prepare streams for sudden changes in data traffic. We are extending warm throughput with the ability to also scale down ingest capacity, giving you full control to scale your stream’s write throughput up or down.
To scale down, simply set a lower warm throughput value on your on-demand stream. The stream adjusts to the requested capacity or the amount needed to support peak data ingest usage in the last hour, whichever is higher. This ensures your stream always retains sufficient capacity for current traffic while releasing excess capacity you no longer need. As a result, you get optimal stream-processing performance and cost efficiency. 
Warm throughput scale-down is available at no additional cost for all on-demand streams with On-demand Advantage mode enabled.  For more information about On-demand Advantage, see Choose the right mode to stream in in the Amazon Kinesis Data Streams Developer Guide. To get started with the feature, see Update a stream. For pricing details, see Amazon Kinesis Data Streams pricing.
The feature is available in all AWS Regions where Amazon Kinesis Data Streams On-demand Advantage is supported. 
   

Publicado el Deja un comentario

AWS Lambda now publishes logs for Lambda Managed Instances capacity providers

AWS Lambda now publishes logs for Lambda Managed Instances (LMI) capacity providers to Amazon CloudWatch Logs, giving you visibility into scaling activity and instance lifecycle operations. LMI enables you to run Lambda functions on Amazon EC2 instances while maintaining serverless operational simplicity. Capacity providers are resources that let you define compute resources that Lambda provisions on your behalf. With capacity provider logs, you can monitor, troubleshoot, and optimize these managed EC2 instances, helping you quickly diagnose provisioning issues and understand scaling behavior.

Customers use LMI to operate high-volume, predictable workloads with specialized compute configurations and achieve cost efficiency through EC2 pricing options like Savings Plans and Reserved Instances. With this launch, Lambda automatically generates logs for compute resources managed by capacity providers and delivers them to CloudWatch Logs. Lambda publishes structured JSON logs capturing instance lifecycle events like launches, terminations, and health checks. This structured format lets you identify failed operations and provisioning errors through CloudWatch Logs filtering, helping you resolve issues quickly and shorten debugging cycles.

The capacity provider logs are available in all AWS Commercial Regions where LMI is available. The logs are enabled by default for all capacity providers. You can view your capacity provider logs by visiting the Lambda console’s capacity provider page. You can use the Lambda API, Lambda console, AWS CLI, AWS SAM, or AWS CloudFormation to change capacity provider log configuration. Standard Amazon CloudWatch Logs charges apply. To learn more, visit the AWS Lambda Managed Instances product page and documentation

 

​AWS Lambda now publishes logs for Lambda Managed Instances (LMI) capacity providers to Amazon CloudWatch Logs, giving you visibility into scaling activity and instance lifecycle operations. LMI enables you to run Lambda functions on Amazon EC2 instances while maintaining serverless operational simplicity. Capacity providers are resources that let you define compute resources that Lambda provisions on your behalf. With capacity provider logs, you can monitor, troubleshoot, and optimize these managed EC2 instances, helping you quickly diagnose provisioning issues and understand scaling behavior.
Customers use LMI to operate high-volume, predictable workloads with specialized compute configurations and achieve cost efficiency through EC2 pricing options like Savings Plans and Reserved Instances. With this launch, Lambda automatically generates logs for compute resources managed by capacity providers and delivers them to CloudWatch Logs. Lambda publishes structured JSON logs capturing instance lifecycle events like launches, terminations, and health checks. This structured format lets you identify failed operations and provisioning errors through CloudWatch Logs filtering, helping you resolve issues quickly and shorten debugging cycles.
The capacity provider logs are available in all AWS Commercial Regions where LMI is available. The logs are enabled by default for all capacity providers. You can view your capacity provider logs by visiting the Lambda console’s capacity provider page. You can use the Lambda API, Lambda console, AWS CLI, AWS SAM, or AWS CloudFormation to change capacity provider log configuration. Standard Amazon CloudWatch Logs charges apply. To learn more, visit the AWS Lambda Managed Instances product page and documentation.