AWS CloudHSM automatically takes a backup of your HSM cluster once a day and whenever an HSM is added to or removed from your cluster. Until today, however, customers were responsible for deleting old backups. Deleting out of date backups is important to prevent inactive users and expired login credentials from being used to access sensitive data on the HSM.
Announcing Code Signing, a trust and integrity control for AWS Lambda
You can now ensure that only trusted and verified code is deployed in your AWS Lambda functions. With Code Signing for Lambda, administrators can configure Lambda functions to only accept signed code on deployment. When developers deploy signed code to such functions, Lambda checks the signatures to ensure the code is not altered or tampered. Additionally, Lambda ensures the code is signed by trusted developers before accepting the deployment.
Third-party software built for Amazon S3 is now available in the Amazon S3 Management Console, powered by AWS Marketplace
Starting today, Amazon Simple Storage Service (S3) customers can discover a curated collection of third-party software built for Amazon S3 from within the S3 Management Console. Customers can choose from free or paid software products across SaaS, AMI, CFT, and Container product types, spanning across a wide range of popular categories including Storage, Back-up and Recovery, Data Integration and Analytics, Observability and Monitoring, Security and Threat Detection, and Permissions.
Amazon EC2 Fleet and Spot Fleet now integrate with Amazon EventBridge for easier operations and monitoring
Starting today, EC2 Fleet and Spot Fleet (further referred to as Fleet) are integrated with Amazon EventBridge (formerly CloudWatch Events) to notify you about important Fleet events, state changes, and errors. This allows you to automate actions in response to Fleet state changes as well as monitor the state of your Fleet from a central place without a need to continuously poll Fleet APIs. Amazon EventBridge enables you to collect monitoring data from AWS resources and applications, and allows you to build loosely coupled and distributed event-driven architectures.
AWS License Manager allows enforcing licensing rules with shared AMIs across multiple AWS accounts
AWS License Manager allows administrators to create customized licensing rules in license configurations to emulate the terms of their vendor agreements. Administrators can use License Manager to enforce these rules by attaching license configurations to their Amazon Machine Images (AMIs). Administrators can now attach license configurations to their AMIs to make the enforcement effective across all their AWS accounts. License Manager evaluates licensing rules at the time of instance launch from AMIs to prevent overages and notify administrators in an event of any licensing rule violation. License Manager also allows administrators to track instance launches from AMIs shared with them from other AWS accounts. Administrators thus gain control and visibility of their licenses used across all AWS accounts and reduce the risk of non-compliance, misreporting, and additional costs due to licensing overages.
Amazon CloudWatch Container Insights now available in AWS GovCloud (US) Regions
AWS announces the availability of Amazon CloudWatch Container Insights, a fully managed, integrated, and pay-as-you-go container monitoring and analytics service for CloudWatch in AWS GovCloud (US). CloudWatch Container Insights enables you to explore, analyze, and visualize your container metrics, Prometheus metrics, application logs, and performance events through automated dashboards in the CloudWatch console. These dashboards summarize the performance and availability of clusters, nodes or EC2 instances, services, tasks, pods, and containers running on Amazon Elastic Containers (ECS), Amazon Elastic Kubernetes Service (EKS), AWS Fargate, and Kubernetes.
AWS Snowball is now available in the AWS Africa (Cape Town) Region
The AWS Snowball service is now available in the AWS Africa (Cape Town) Region. AWS Snowball, a member of the AWS Snow Family, is an edge computing, data migration, and edge storage device that comes in two options. Snowball Edge Storage Optimized devices provide 80 TB of Amazon S3 object storage and optional compute with 40 vCPUs. They are well suited for local storage and large-scale data transfer. Snowball Edge Compute Optimized devices provide 52 vCPUs, 7.68 TB of NVMe SSD storage, 42 TB of HDD storage, 256 GB of RAM, and an optional GPU for use cases like advanced machine learning and full motion video analysis in disconnected environments. You can use these devices for data collection, machine learning and processing, and storage in environments with intermittent connectivity (like manufacturing, industrial, and transportation) or in extremely remote locations (like military or maritime operations) before shipping the devices back to AWS. These devices may also be rack mounted and clustered together to build larger temporary installations.
AWS CodeArtifact now supports NuGet
AWS CodeArtifact now supports NuGet packages for .NET development.
Amazon DocumentDB (with MongoDB compatibility) is now available in AWS China (Ningxia) Region, Operated by NWCD
Amazon DocumentDB (with MongoDB compatibility) is now available in AWS China (Ningxia) Region, Operated by NWCD.
AWS Single Sign-On enables administrators to require users to set up MFA devices during sign-in
AWS Single Sign-On (SSO) administrators can now require users to self-enroll multi-factor authentication (MFA) devices during sign-in. For your users without a registered MFA device, you can require them to complete a self-guided MFA enrollment process following a successful password authentication. This allows administrators to secure their organization’s AWS environments with MFA without having to individually enroll and distribute authentication devices to users.