In short
AWS Podcast Episode #719 Summary
Episode Overview
- Title: AWS News: Amazon Q Developer brings powerful new AI capabilities to GitLab Duo
- Release Date: May 5th, 2025
- Hosts: Alicia, Gillian Ford
- Description: An exploration of the new Amazon Q Developer integration with GitLab Duo for automating code generation and review, alongside other AWS updates.
---
Key Topics Discussed
- SWE Polybench: AI Coding Agent Benchmark
- Overview:
- Introduced as an industry benchmark for evaluating AI coding agents.
- Contains rich metrics for assessing AI performance in real-world scenarios.
- Key Features:
- Evaluates agents across various programming languages (Java, JavaScript, TypeScript, Python).
- Offers a leaderboard showcasing agent performance across specific tasks like bug fixes, feature requests, and refactoring.
- Amazon Q Developer and GitLab Duo Integration
- Functionality:
- Enables automated code generation, issue analysis, and code reviews within GitLab.
- Aims to enhance security and code quality checks, especially for startups where security may often be deprioritized.
- AWS Updates Across Various Domains
- Analytics:
- Amazon Redshift introduces zero ETL integrations with major third-party applications.
- Launch of serverless reservations for cost optimization on Amazon Redshift.
- Application Integration:
- Amazon SQS now supports IPv6 for API requests.
- Artificial Intelligence:
- Launch of a Well-Architected generative AI lens providing guidance for implementing generative AI workloads.
- Amazon Bedrock enhancements for better document processing and prompt optimization.
- Compute:
- Release of new EC2 instances (C8GD, M8GD, R8GD) with improved performance.
- Introduction of AWS Thinkbox Deadline 10.4.1 for managing render jobs.
- Security:
- Updates to AWS security services, including IAM-based account name updates, and enhancements to AWS STS for regional processing.
- Notable AWS Features and Updates
- Amazon Connect Updates:
- Enhancements to the agent workspace and case management capabilities for contact centers.
- Database Improvements:
- Support for serverless automatic storage scaling in Amazon DMS.
- Networking:
- Introduction of Anycast static IPs for Amazon CloudFront.
---
Key Takeaways
- The new SWE Polybench benchmark will help assess AI coding agents' capabilities, crucial for developers leveraging AI in their coding workflows.
- The integration of Amazon Q Developer with GitLab Duo can significantly streamline coding processes and enforce better security practices.
- AWS continues to enhance their services across various domains, from analytics to security, with a focus on providing developers with powerful tools for automation and efficiency.
Conclusion The episode highlighted significant advancements and integrations within the AWS ecosystem, particularly focusing on AI capabilities in software development, cost optimization, and security enhancements. The integration of Amazon Q Developer with GitLab Duo represents a pivotal shift towards automating and streamlining code management processes for developers.
For more details, listeners are encouraged to check the [Episode Shownotes](https://d29iemol7wxagg.cloudfront.net/719ExtendedShownotes.html).
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00This is episode 719 of the AWS podcast released on May 5th, 2025.
0:09Hello, everyone, and welcome back to the AWS Podcast. I'm Alicia with you. Great to have you back. A little under the weather, as you can tell, but it's adding bass to the voice, which is okay. But we have multi-AZs. We don't have Shruti today, but we do have Gillian Ford. G'day, Gillian. How are you doing? I'm feeling well. I don't have a radio voice like you do right now, but I'm always excited for - I know. I need a filter that brings this all the time without the feeling terrible part. So there's lots of cool new stuff that's happening this time around, and we're going to start with one that's a little different, which is a new benchmark.
0:39This is called the SWE Polybench, which is a multilingual benchmark for AI coding agents. And it answers the interesting question of how do you know how good your agent is in doing the coding work you're asking? So Jillian, what's this giving us? What's it bringing to the table? Wow, it is like super cool. So this is the first industry benchmark to evaluate AI coding agents' ability to navigate and understand complex code bases. So that also includes rich metrics to advance AI performance. And these are in real-world scenarios. So I think this is totally applicable to customers that really want to be able to start using this today.
1:24Yeah, I think what's interesting is it's trying to sort of figure out what does good look like? So for example, you know, if you're using Java, this benchmark does 165 different tasks. There's over a thousand JavaScript tasks, over 700 typescript tasks, almost 200 Python tasks. And what it's done is sort of try to apply a variety of different things like fixing a bug or doing a feature request or doing some code refactoring, et cetera. And then it creates a leaderboard that lets you actually see, well, what's good at doing what things and how good is it and what fits better. And I think this is what's really reflecting the fact that it depends, continues to be the primary answer to all solutions to all things, which is, you know, which model do I use and which agent works better with which particular language.
2:13Just because something works really well when you're using JavaScript, so front-end coding, doesn't mean it'll work well if you're doing, let's say, Python on the back end, for example. So I think this is going to be really interesting to see how the data set builds out over time. Yeah, it is. And I think one thing that stood out to me was this task specialization. Like these different agents, they show strengths in various task categories. So bug fixes, feature requests, refactoring. And now this is just like one finding that you're able to utilize within these coding agents. Yeah, it's a very powerful thing.
2:51And continuing on with the theme of agents making software development better. And look, lots of people have opinions on whether AI coding and software development this way is better or worse or how you assess it. I'll give you my personal take. It's like speaking with a megaphone. So you still have to speak, but when you're holding a megaphone up, it reaches further and you can get a lot more coverage done. And so I'm finding it as an accelerant. And one of the things we want to talk about is GitLab Duo with Amazon Q. So this means that you can now use the agents within that GitLab quick action space.
3:27I know a lot of my customers use GitLab. It's a very popular thing, certainly over here in Australia. And you can have it analyze your entire code base. You can generate code. You can look into issues. You can provide context on sources. You can do code reviews as well. It can really help with that. There's a bunch of stuff here, Gillian, to really get your teeth into it. Yeah, I'm really excited about the automated security vulnerability and code quality checks. Especially, I work with startups, I get it, security oftentimes becomes a less of a priority thing because you've got to go quickly to market.
4:02And I just love anything that can kind of help really automate it and make it much faster to implement best practices. Yeah, everyone wants to go quickly and skip security till something goes wrong. That's right. everything stops. And so it's like, you know, that's why the grisly old heads go, well, you do security for goodness sake at the start. But this, again, this makes it easier to at least get a good run at it and to have at least got the basics done. You know, we still see code out there that, you know, has SQL injection vulnerabilities and all this other stuff that, you know, if you don't know, you don't know.
4:31So the LLMs know and can help us with that. Absolutely. So let's talk about some things that have been happening out there. Let's start with the world of analytics. Amazon Redshift now supports history mode for zero ETL integrations with eight third-party applications, including Salesforce, ServiceNow, and SAP. In summary, this means that you can now do historically-based analytics without any multi-copies of data and lots of different processing. It makes life a lot easier, which is very cool. We're also announcing serverless reservations which is a new discounted pricing option for Amazon Redshift serverless.
5:10So if you have consistent workloads or a baseline workload you know you can now save up to 24 % on your cost allocation and you can commit to a number of processing units and you can have a no out front option that gives you a 20 % discount or an all out front option that gives you a 24 % discount. Again the pay as you go pay for what you use model is great it's my preferred model but if you have an understanding of base load, you should always go for these prepaid options because you will save money off the bat if you know what it is. We're also happy to introduce a guided visual pipeline builder for Amazon OpenSearch ingestion.
5:46So this is an enhancement to allow you to have automatic permission creation, enhanced real-time validation to just make that pipeline processing easier to set up. And the Amazon OpenSearch service also now supports SAML single sign-on for OpenSearch UI as well. Amazon Kinesis Data Streams has increased the default shard limits up to 20 ,000 per AWS account. That's up from 500. So it's a pretty significant thing. This is for provision capacity mode and it applies for US East, US West Oregon and Europe Island as well. And Amazon MSK has added support for Apache Kafka version 3.9. So this specifically allows you to retain tiered data when disabling tiered storage at the topic level.
6:30So it's kind of an important thing, plus various bug fixes and improvements. And I think it's one of the few times this week, I'll be able to remind you to patch your stuff. If you're not keeping up to date with things, please do. It makes life better for everyone. It never gets old when you tell people to patch your stuff. Well, because I know for a fact, there's always going to be one listener that goes, oh, damn it, he's right. I think that's a good thing. Yeah, on to application integration. Amazon SQS now supports IPv6 for API requests, enabling you to communicate with SQS using IPv6, IPv4, or dual stack clients using public endpoints.
7:12Amazon announces quarterly security and critical updates for Amazon Coreto long-term supported and feature release versions of OpenJDK. Next topic is artificial intelligence. Now we've got the well-architected generative AI lens. Super exciting. So this new lens is a powerful addition to the well-architected framework. It's designed to guide organizations through the complexities of implementing generative AI workloads. It provides structured prescriptive guidance covering the entire generative AI lifecycle, whether that's from the initial impact scoping to model selection, customization, integration, deployment, and continuous iteration.
7:56The lens offers several key benefits, including cloud agnostic guidance applicable across various environments and AI tools. And it covers all six well-architected pillars and its flexible application for organizations at any stage of their AI journey. It enables thorough assessment of architectures using LLMs, large language models, and helps business leaders and data scientists navigate critical decisions in general AI implementation. Definitely recommend it. so you can check it out in the lens catalog of the AWS Well-Architected tool. If you've actually never used the Well-Architected tool, you literally just go into the AWS console, do a search for Well-Architected, and there's a number of different lenses.
8:40There's the good old-fashioned Well-Architected that is timeless, and then there's a bunch of different lenses for a wide variety of use cases, such as SAS, for one example. So you definitely want to check that out as you're thinking about well-architected best practices and maybe for specific areas like generative AI. Never gets old. Next up, Amazon Bedrock Data Automation now supports modality enablement, modality routing by file type, extraction of embedded hyperlinks when processing documents and standard output, and an increased overall document page limit of 3 ,000 pages. These new features give you more control over how your multimodal content is process and improve Bedrock Data Automation's overall document extraction capabilities.
9:28Prompt optimization in Amazon Bedrock is now generally available. With prompt optimization in Amazon Bedrock, you can now automatically rewrite prompts for better performance and more concise responses on Anthropic, Llama, Nova, DeepSeek, Mistral, and Titan models. You can compare optimized prompts against original versions without deployment and save them in and Amazon Bedrock Prompt Management for prompt lifecycle management. You can also use prompt optimization in the Bedrock Playground or directly via API. Amazon Bedrock Intelligent Prompt Routing is now generally available. So Intelligent Prompt Routing, this is going to be able to allow you to configure your router by choosing any two models from a model family and setting the routing criteria for your router.
10:16Prompt Routing also adds support for new models and now supports the following. So the Anthropic Claude model, so Haiku, Haiku 3.5, Claude Son at 3.5 version 1, and Claude Son at 3.5 version 2. The Meta Llama family model, so Llama 3.1 8b, 70b, 3.2 11b, 90b, and 3.3 70b. And the Amazon Noma family, the Nova Pro, and the Nova Lite. Amazon Bedrock, RAG, and model evaluations now support custom metrics. Bedrock Evaluations offers human-based evals, programmatic evals such as bird score, F1, and other exact match metrics, as well as LLM as a judge for both model and rag evaluation. For both model and rag evaluation with LLM as a judge, customers can select from an extensive list of built-in metrics such as correctness, completeness, faithfulness, hallucination detection, as well as responsible AI metrics such as answer refusal, harmfulness, and stereotyping.
11:20Amazon SageMaker Lakehouse now supports attribute-based access control using AWS Identity and Access Management principle and session tags to simplify data access, grant creation, and maintenance. AWS announces upgrades to Amazon QBusiness integrations for Microsoft 365 Word and Outlook. AWS announces the update of Amazon Q developer's software development agent. This new agent achieves state-of-the-art performance on industry benchmark SWT Bench Verified and sits among the top ranking models on SWT Bench Verified. The agent has access to tools for planning and reasoning that use the capacity of advanced models to their fullest.
12:05Yeah, I've been making this one do a lot of heavy lifting for me, let me tell you. Ooh, like what? Well, it's interesting. I'm building more things I'm not using. Oh. Now, that sounds counterintuitive, but what it means is I'm able to try more ideas with lower overhead. In fact, as a step beyond a vibe coding, which I'm not a fan of, I'm now doing background coding. So during a meeting, if the meeting is maybe a little inefficient in terms of the use of my time. It's a good choice of words. It may be happening in the back end that I'm also having a dialogue with my trusty Q agent that is building something that I thought might be an interesting idea and just seeing how far I can go and what it can come up with and if it makes sense or if I run into any bumps and edges.
12:53So if you think about in the classic sort of real agile view of the world where you spike ideas and try things, et cetera, this allows me to do that at very low opportunity cost. So yes. Background, background. And then I tried to use it to build me something that would actually do it in the background for me automatically using voice, which I think I may have mentioned in the last episode. And it didn't work. And I'm okay with that because I didn't spend four weeks trying to make the thing work. It was literally a few hours and not dedicated hours to just test it out. time. I think we're going to have so many listeners in the background that are going to be having their AI agent doing some things along the tap in the background now from hearing your inspiration.
13:39I'm not authorizing this as a production grade development process. I'm simply saying often as technologists, we have a lot of bright, interesting ideas. We think, oh, it'd be great to have time. And I don't know about you, but I end up spending the weekend or the night doing that. And on the one hand, that's great, but it gets kind of old after a while. So So it's like, well, if I can do it while something else is happening and have it do it, because you need focus to code and you need flow and that doesn't go away. But if you kind of know what you're trying to get to, you can kind of have the bot go do it for you.
14:08And then you can just assess the results and go, it looks pretty good. It might be worth me actually spending some time on this. Just a perspective. I think a lot of people are inspired. And speaking of more inspiring things, AWS Health Omics announces workflow versioning support. AWS Health Omics now supports elastic throughput for dynamic run storage. Let's talk about compute. A lot of AI things, but there's also lots of compute things happening as well. We're happy to announce the general availability of the EC2C8GD instances, the M8GD instances, and the R8GD instances. These have up to 11.4 terabytes of local NVMe-based SSD blockable storage.
14:51I'm sorry I'm old. I still find these numbers insane. That used to be what I called an enterprise database, and now it's the internal RAM of an SSD device. These have AWS Graviton 4 processors, so up to 30 % better price performance over Graviton 3. And so you're already getting a benefit there, and up to 40 % higher performance for IO-intensive workloads and 20 % faster query results as well compared to AWS Graviton 3. They use Nitro, which is all kinds of goodness, 12 different instance types. They're currently available in US East, Ohio and North Virginia and US West Oregon. If you're in those regions and you use this type of compute, you should definitely assess this to see if it's an improvement.
15:33This is again, one of the best ways to get benefit is to reassess your EC2 instances. AWS Thinkbox Deadline 10.4.1 is now generally available with support for managing Deadline Cloud usage-based licensing together with your existing floating licenses. And AWS Deadline Cloud now provides a macOS installer for submitters. So this is a fully managed service that simplifies render management for teams creating computer generated graphics and visual effects. And yes, having a macOS installer for integrated submitters is a good thing for them. The AWS Console mobile application adds support for Amazon LightSail.
16:11So if you need to manage your LightSail instances, that is the place to do it. And AWS Batch now supports Amazon Elastic your Container Service Exec and Adabuse FireLens Log Router. So now you can track the progress of your application and troubleshoot issues by running interactive commands against the containers in your Adabuse batch job. I can see that would be very useful. And Adabuse FireLens, I've not come across that myself, allows you to stream logs from your Adabuse batch jobs to your chosen destinations, including Amazon CloudWatch, S3, OpenSearch Service, Redshift, and also partners like Splunk and many more.
16:44Now we'll talk about contact senders, also known as the Amazon Connect update segment. I'm just naming that right now because there's always so many things from the Amazon Connect team every time. They're always busy. They really are. Such as the agent workspace, which now supports additional capabilities for third-party applications, including the ability to make outbound calls, accept, transfer, and clear contacts, and update agent status. This. Amazon Connect Cases now provides capabilities to help contact centers track and meet SLAs on cases. Amazon Connect Contact Lens dashboards now supports the ability for contact center administrators to enforce granular access control based on a specific agent hierarchy.
17:31We've got one quick update in containers. Amazon ECS is introducing a new account setting, default log driver mode, which allows you to define whether tasks in your account use blocking or non-blocking log driver mode by default when you do not specify or omit it in your application's task definitions. Let's talk about databases. We're happy to announce Adibus DMS serverless automatic storage scaling. So now you never have to worry about exceeding the DMS serverless 100 gig default replication storage capacity limit because it handles it for you. So now basically there is no storage capacity limit.
18:11It just happens for you. Well done team. I like this one. This is a good one for customers. Amazon MemoryDB now supports IPv6. So you can use it for IPv6 and IPv4 as well. So the year of IPv6 continues to march on. Let's have a quick update for front-end web and mobile. Adibus AppSync Events now supports data source integrations for channel namespaces. So this is a fully managed service for serverless web socket APIs with full connection management, and it now supports those data source integrations. So you can associate AWS Lambda functions, AWS DynamoDB tables, Aurora databases, and other data sources with channel namespace handlers to process published events and subscription requests.
18:53Developers can now connect directly to Lambda functions without writing code and leverage both request response and event modes for synchronous and asynchronous operations. This is actually really useful. And I could have used this about a month ago. Next up, management and governance. AWS AppConfig now supports dual stack endpoints, facilitating connectivity through IPv6. Amazon CloudWatch agent support for Red Hat OpenShift service on AWS enables monitoring of applications and infrastructure using familiar CloudWatch tools such as container insights and application signals. Amazon CloudWatch agent adds support for SE Linux, or security-enhanced Linux environments, through a pre-configured security policy that allows monitoring in systems where security enforcement is required.
19:46Amazon Managed Service for Prometheus now supports label-based Active Series limits. AWS now allows customers in Europe to pay for their usage in advance. How exciting! AWS announced three updates to enhance your experience with the Customer Carbon Footprint tool. These updates include easier access to carbon emissions data, visibility into emissions by AWS region, and an updated independently verified methodology. We've got one topic in migration and transfer. AWS Transfer Family introduces Terraform Module for deploying SFTP server endpoints. Now on to networking and content delivery, where we've also got one quick update.
20:30Amazon CloudFront announces Anycast static IPs support for Apex donates. This is a big deal in terms of the fact that previously you had to have 21 IP addresses to make this work, and now you have three. Oh, wow. network managers of the world unite let's celebrate let's talk about security identity and compliance adibus resource groups now supports 160 more resource types and yes i will not read them all to you now if you don't have news adibus resource groups it lets you model manage and automate tasks on large numbers of adibus resources using tags remember those to logically group your resources.
21:12So it really helps you operate at scale. And AWS Resource Explorer now supports AWS PrivateLink. So it means you can operate across and within your virtual private cloud without traversing the public internet. AWS Account Management now supports IAM-based account name updates. Oh, this is a good one. So this is a new API that's added to the Account Management API that lets AWS organizations customers to centrally and programmatically manage primary email addresses, primary contact information, alternate contact information, and AWS regions for their accounts. With using this new API, you no longer need root access to manage your account names.
21:48You'll be able to authorize IAM principles within the account, and you can also use it to manage delegated accounts and create basically a centralized way of working. I'm unreasonably excited about this change because I know this has been what I would call a significant paper cut for a lot of customers for a long time, and this is now fixing that which is fantastic. Amazon Cognito now supports refresh token rotation for user pool clients. So refresh tokens are long-lived tokens that allow applications to obtain new access tokens without requiring users to sign in again. You can now configure it to automatically replace your existing refresh tokens with a new one at regular intervals which can improve your application security posture.
22:29AWS Security Incident Response now supports integration with AWS PrivateLink and Amazon verified permissions now supports policy store deletion protection. So now the policy store cannot be deleted by any user. So again, you can have resilience so that your production policy stores aren't accidentally deleted during deployments, which would be bad. And AWS STS Global Endpoint now serves your request locally in regions enabled by default. So this is for the AWS security token service. And basically it will serve all requests that go to the global endpoint, which is sts.amazonaws.com, to the same AWS region as your deployed workloads.
23:07So previously would all be served from US East North Virginia. Now it will actually allow you to have significant fault isolation because requests are processed in the same region as your workloads. Now this update is available in all AWS regions that are enabled by default and you don't have to do anything. Any requests for the STS global endpoint from regions not enabled by default, so opt-in regions will continue to be served from USC's North Virginia. Let's quickly talk about serverless. AWS Lambda now supports inbound IPv6 connectivity over AWS Private Link. So we've got both the IPv6 support and the Private Link support in the same update.
23:43Well done, team. Amazon EventBridge now supports customer managed keys in API destinations connections, and the Amazon EventBridge connector for Apache Kafka Connect is now generally available. The connector includes built-in support for Kafka schema registries, which offloads large event payloads to S3, which is a good thing. And IAM role-based authentication, and it's available under the Apache 2.0 license in the Adibus GitHub organization. And finally, as we always do, let's wrap up with storage. Amazon S3 Tables now supports server-side encryption using Adibus KMS with customer-managed keys.
24:18By default, S3 Tables encrypt all objects with server-side encryption using S3 managed keys, now you can have custom managed keys to do the same thing. And Amazon EBS now supports additional resource level permissions for copying EBS snapshots. So you can copy any snapshot accessible to you, to another region or account, including snapshots created by you or shared by you. With this launch, you now have more granular controls to set resource level permissions about who can do what. And that is always a good thing. So some cool updates there, Jillian? I think it was plenty for everyone, depending on which side of the fence you sit in terms of job function, role, or interests.
24:57Absolutely. I mean, not that you were asking what my favorite was, but if you were to ask - I kind of was. If I wanted to ask that question, what would your favorite one be? Well, I think the launch of the new instances. I mean, new Graviton Florenses, C8GD now, the MAGD, the RAGD. I mean, why not always pick the most up-to-date most performant instance type, right? For the lowest cost. Yep. It's nice. And look, it's either a stop in the start of your application or it's even better, a rolling upgrade on your auto scaling group and life is better. Yeah. What about you? What stood out? Well, if you were to ask me, mine was actually the STS Global Endpoint Update.
25:37I think that's a really big deal in terms of resilience. And I'm always a big fan of resilience. And I love the fact that it's enhancing resilience and your code change level is zero. So don't have to change the end point. Don't have to do anything. It's just better and better is good. So I'm very happy with that. So there's some, some good ones there. Gillian, how do folks get in touch with you if they want to reach out? Gillian Ford on LinkedIn. Fantastic. And if you want to go old school, adspodcast.amazon.com is the place to do it as well. And until next time, keep on building.
From the publisher
Description: Learn how you can use the all new Amazon Q Developer integration with GitLab Duo to automate code generation and review, plus even more updates from AWS. 00:00:00 - Intro, 00:00:28 - SWE Holly Bench, 00:04:31 - Analytics, 00:06:49 - Application Integration, 00:07:14 - Artificial Intelligence, 00:08:53 - Amazon Bedrock Data Automation, 00:14:11 - AWS Health Omex, 00:14:21 - Compute, 00:16:37 - Contact Centers, 00:17:25 - Containers, 00:17:46 - Databases, 00:18:18 - Front end Web and Mobile, 00:18:59 - Management and Governance, 00:20:07 - Migration and Transfer, 00:20:17 - Networking and Content Delivery, 00:20:44 - Security Identity End Compliance, 00:23:24 - Serverless, 00:24:01 - Storage, 00:24:41 - Wrap up
Shownotes: https://d29iemol7wxagg.cloudfront.net/719ExtendedShownotes.html
