Starting today, your IPv6 AWS resources in Amazon Virtual Private Cloud (VPC) can use NAT64 (on AWS NAT Gateway) and DNS64 (on Amazon Route 53 Resolver) to communicate with IPv4 services. As you transition your workloads to IPv6 networks, they would continue to need access to IPv4 network and services. With NAT64 and DNS64, your IPv6 resources can communicate with IPv4 services within the same VPC or connected VPCs, your on-premises networks, or the Internet.
AWS WAF adds support for Captcha
AWS today announced AWS WAF Captcha to help block unwanted bot traffic by requiring users to successfully complete challenges before their web request are allowed to reach AWS WAF protected resources. Captcha is an acronym for Completely Automated Public Turing test to tell Computers and Humans Apart and is commonly used to distinguish between robotic and human visitors to prevent activity like web scraping, credential stuffing, and spam. You can configure AWS WAF rules to require WAF Captcha challenges to be solved for specific resources that are frequently targeted by bots such as login, search, and form submissions. You can also require WAF Captcha challenges for suspicious requests based on the rate, attributes, or labels generated from AWS Managed Rules, such as AWS WAF Bot Control or the Amazon IP Reputation list. WAF Captcha challenges are simple for humans while remaining effective against bots. WAF Captcha includes an audio version and is designed to meet WCAG accessibility requirements.
Amazon EC2 Auto Scaling Now Supports Predictive Scaling with Custom Metrics
With Amazon EC2 Auto Scaling’s new predictive scaling policy, you can now use custom metrics to predict the EC2 instance capacity needed by an Auto Scaling group. Predictive scaling proactively increases the capacity of an Auto Scaling group to meet predicted demand. For workloads that experience recurring, steep demand changes, predictive scaling can help improve your application’s responsiveness without having to overprovision capacity, resulting in lower EC2 costs. Custom metrics are useful when the predefined metrics (CPU Utilization, Network I/O, and ALB Request Count) are not sufficient to capture the load on your application. Previously, you could only use custom metrics with step scaling and target tracking, but you can now use them with predictive scaling as well.
EC2 Image Builder enables sharing Amazon Machine Images (AMIs) with AWS Organizations and Organization Units
Now on EC2 Image Builder, customers can share their Amazon Machine Images (AMIs) with AWS Organizations and Organizational Units (OUs) in the image distribution phase of their build process. As their organization structure changes, customers no longer have to manually update AMI permissions for individual AWS accounts in their organization. Customers can create OUs within AWS Organizations and manage AMI permissions for AWS accounts within those OUs.
Amazon Managed Grafana adds support for Amazon Athena and Amazon Redshift data sources and Geomap visualization
Amazon Managed Grafana announces new data source plugins for Amazon Athena and Amazon Redshift, enabling customers to query, visualize, and alert on their Athena and Redshift data from Amazon Managed Grafana workspaces. Amazon Managed Grafana now also supports CloudFlare, Zabbix, and Splunk Infrastructure Monitoring data sources as well as the Geomap panel visualization and open source Grafana version 8.2.
Announcing new performance enhancements for Amazon Redshift data sharing
Amazon Redshift data sharing allows you to share live, transactionally consistent data across different Redshift clusters without the complexity and delays associated with data copies and data movement. Data sharing now adds several performance enhancements including result caching, and concurrency scaling allowing you to support broader set of analytics applications and meet critical performance SLAs when querying shared data.
AWS price reduction for data transfers out to the internet
Effective December 1, 2021, AWS is making two pricing changes for data transfer out to the internet. Each month, the first terabyte of data transfer out of Amazon Cloudfront, the first 10 million HTTP/S requests, and the first 2 million CloudFront Functions invocations will be free. Free data transfer out of CloudFront is no longer limited to the first 12 months. In addition, the first 100 gigabytes per month of data transfer out from all AWS Regions (except China and GovCoud) will be free. Free data transfer out from AWS Regions is also no longer limited to the first 12 months. These changes will replace the existing data transfer and CloudFront AWS Free Tier offerings, and AWS customers will see these changes automatically reflected in their AWS bills going forward. All AWS customers will benefit from these pricing changes, and millions of customers will see no data transfer charges as a result.
AWS Lambda now supports event filtering for Amazon SQS, Amazon DynamoDB, and Amazon Kinesis as event sources
AWS Lambda now provides content filtering options for SQS, DynamoDB and Kinesis as event sources. With event pattern content filtering, customers can write complex rules so that their Lambda function is only triggered by SQS, DynamoDB, or Kinesis under filtering criteria you specify. This helps reduce traffic to customers’ Lambda functions, simplifies code, and reduces overall cost.
AWS Single Sign-On is now in scope for AWS SOC reporting
AWS Single Sign-On (AWS SSO) is now in scope for AWS SOC 1 , SOC 2, and SOC 3 reports. You can now use AWS SSO in applications requiring audited evidence of the controls in our System and Organization Controls (SOC) reporting. For example, if you use AWS to manage access to accounts and applications, you can use the SOC reports to help meet your compliance requirements for those use cases. AWS SOC reports are independent third-party examination reports that demonstrate how AWS achieves key compliance controls and objectives.
AWS App2Container now supports Jenkins for setting up a CI/CD pipeline
AWS App2Container(A2C) now supports Jenkins for setting up a CI/CD pipeline to automate building and deploying application in containers on AWS. With this new integration, customers can configure their existing Jenkins pipeline in the current Jenkins environment for managing automated build and deployment of containerized applications.