In short
AWS Podcast Episode #727: Summary and Key Insights
Episode Information
- Title: AWS News: AWS Shield Network Security Director, Amazon GuardDuty for EKS, and more
- Release Date: June 30, 2025
- Hosts: Simon Elisha, Jillian Ford
Episode Overview In this episode of the AWS Podcast, Simon and Jillian recap significant security announcements made during the AWS re:Inforce conference, highlighting new features, tools, and price reductions aimed at enhancing cloud security and operational efficiency.
---
Key Announcements and Features
AWS Shield Network Security Director
- Preview Feature: This tool identifies network security vulnerabilities before they can be exploited.
- Key Functions:
- Visualizes network topology.
- Compares the environment against AWS best practices.
- Automates remediation instructions using natural language queries.
AWS IAM Access Analyzer
- New Capability:
- Identify which IAM roles and users have access to critical resources.
- Benefits:
- Provides real-time insights into permissions and security posture.
- Integrates with EventBridge for enhanced monitoring and automation.
Amazon GuardDuty for EKS
- Extended Threat Detection:
- Now available for Amazon EKS clusters, aiding in multi-stage attack detection.
- Functionality:
- Correlates various data sources (audit logs, runtime behaviors, etc.) to identify potential threats.
---
Analytics and Application Integration Updates
- Amazon Managed Streaming for Apache Kafka: Now supports Kafka version 3.8.
- Amazon OpenSearch Ingestion: Can now ingest data from Atlassian Jira and Confluence.
- API Model Definitions: AWS has made AWS API model definitions available through an open-source GitHub repository, improving accessibility for developers.
---
Price Reductions and New Capabilities in AI
- Amazon SageMaker: Up to 45% price reduction on AI instances to facilitate cost-effective generative AI model development.
- New Instance Support: Introduction of M7i, C7i, and R7i for improved performance.
- Amazon Lex Enhancements: Improved conversational accuracy and natural language understanding capabilities.
---
Compute and Storage Enhancements
- Amazon EC2 Auto Scaling: New parameter to filter instance details, improving API response times.
- Amazon S3 Updates:
- Supports renaming objects with the new Rename Object API.
- Enhanced error messages for 403 access denied errors, making security troubleshooting easier.
---
Security, Identity, and Compliance Enhancements
- AWS Security Hub: New features for risk prioritization and response, including attack path visualization and automated workflows.
- AWS Certificate Manager: Now allows exportable public certificates for use outside AWS.
- MFA Enforcement: Multi-factor authentication is mandatory for root access across all account types.
---
Closing Remarks
- Ergonomics Focus: This episode highlights numerous updates aimed at improving user experience and security posture in AWS environments.
- Community Engagement: Listeners are encouraged to reach out via LinkedIn or through the AWS podcast website for feedback and inquiries.
---
Conclusion The episode encapsulates the ongoing evolution of AWS with a strong focus on security, operational efficiency, and user accessibility. The advancements discussed provide developers and IT professionals with powerful tools to enhance their cloud environments.
---
Note: For further insights and detailed updates, listeners can check the full transcript or visit the official AWS Podcast website.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00This is episode 727 of the AWS podcast, released on June 30th, 2025. five.
0:10Hello, everyone, and welcome back to the A2Best podcast. So I'm Liz here with you. Great to have you back. Good to be back, actually. And I'm joined by one of my two amazing co-hosts, Jillian Ford. G'day, Jillian. How are you going? Fantastic. But if we count your dog on the couch that no one can see right now, maybe that's co-host number four. Yeah, Chewy is the backup, backup co-host. Chewy is like maybe, I don't know, an outpost? not an az but maybe an outpost passive you should sleep around the couch you know exactly so there has been as always lots going on and we just had the adavis reinforce conference in philadelphia and this is the sort of big event where we all come together and talk all things security there's been some there's some cool things there jillian i think um the new um network security director is interesting.
1:00This is in preview part of the AWS Shield capability. Now, what this is, is it discovers network security issues before they can be exploited. So I don't know about you, Jillian, but I like to find out problems before they hurt me. That's a good thing. That's a good idea. It kind of is. And what this does is just, it makes it easy to understand what's going on in your environment. It compares it against best practices as well. You can see the network topology i'm a visual learner i like to see stuff uh it does a whole bunch of automation of course it integrates with amazon queue developer so natural language queries is a thing um it's kind of neat i think so too um i mean i like anything that just makes things a lot more simple and uh security at least for me i think can feel complicated and scary at times um i like the step-by-step remediation instructions um anything that's just now we're so used to everything just being like wanting to write in natural language to be able to get some interesting insights back um and i think that's pretty cool as something that is also included as well um in this new feature within shield yeah i think it's it's super important related to that is uh and there were lots of releases that reinforce but another one that we thought was really interesting is the new capability in the AWS IAM Access Analyzer, which lets you verify which IAM roles and users have access to critical resources.
2:31Now, this is really important because it's not just saying you're secure, it's being able to prove you're secure. And in the past, I don't know about you, but I've been involved in a lot of sort of, you know, paper-based audits and that sort of stuff. And it's just not, it's never accurate. It's never right. And this is, This is real stuff going through and actually finding who has access to your S3 buckets, your Donovan DB tables, your RDS snapshots in a dashboard in one place with EventBridge integration. And we know as developers that once you have EventBridge integration, the world is yours.
3:04You can do whatever you want. It's pretty cool. So true. Yeah, I'm super excited for this because I know this is a theme that I hear a lot with the customers I work with is just trying to get a handle of who has access to what and that being a great like a major starting point to improve your security posture. So super excited to see customers start using this. Yeah, yeah. And if you're a Kubernetes user and a lot of our customers out there do use Kubernetes, we now have Amazon GuardDuty extended threat detection coverage for Amazon EKS clusters. So this is really useful for your sort of very sophisticated multi-stage attacks that do take place.
3:42So it correlates and use the algorithms to correlate attack sequences across different audit logs, runtime behaviors, malware execution, API activity. So it really can tell what's going on in the environment and automatically detect and show you what's going on and allow you to take action and to intervene. Sounds super useful to me, Simon. Yeah, more security is a good thing. So, Jillian, what's been going on in the world of analytics? So, Amazon Managed Streaming for Apache Kafka now supports Kafka version 3.8 on Express Brokers. Amazon OpenSearch Ingestion now allows you to ingest data from Atlassian Jira and Confluence and seamlessly index it in Amazon OpenSearch Managed Clusters and Serverless Collections.
4:36We've got one update in application integration. AWS announces an official source for AWS API model definition files and service model packages. This provides developers with access to API definitions for all AWS services. We now publish daily updates of these API models to an open source GitHub repository in Smithy format. I didn't even know what Smithy format is. so much easier to do. You know what we're like in IT. There's a million different formats. And if we don't like the ones we have, we make new ones. And Smithy is one of them, but Smithy is good. We use that internally too. I did not know that either.
5:16Pretty cool. So these AWS public service models, they enable developers to take advantage of the same service model definition that AWS uses for live services. These API models can be pulled into integrated development environments using the new packages available in Maven, and it can be used for developer tools' use cases like mock testing or evolving MCP server needs. So by utilizing open source Smithy code generators, you can also generate purpose-built AWS SDKs. This sounds really cool. Yeah, this is really powerful, particularly in this new world of MCPs. And we'll be talking a lot more about MCPs in the future.
5:58Oh, yeah. Some cool stuff cooking. Speaking of EBCPs, let's talk artificial intelligence. And if there's one topic I like talking about for our listeners, it's a price cut. And so we are really happy to announce a up to 45 % price reduction for Amazon SageMaker AI instances to enable more cost-effective generative AI model development. So these price reductions happen automatically, and this is a great way to get more training done at less cost. and Amazon SageMaker AI also now supports the M7i, C7i and R7i for SageMaker model training and model processing so these give you 15 % better price performance compared to the previous generations and so this is always a reminder that in general wherever possible use the latest generation of a particular instance type because that's going to help you get the best bang for your buck.
6:55And I think this is one of the things that's different again. Now, if I think about things that are different in the cloud to the old days, in the old days, you bought your server and you just used it and that's what you had. And you couldn't change it easily. Now it's the reverse. It's like you should be, if you're not changing your server type every six to 12 months, you're probably leaving performance on the table. And I don't want you to do that. Amazon SageMaker AI training jobs have announced general availability of the P6 B200 instances powered by NVIDIA B200 GPUs. Now these are 2x performance compared to P5 EN instances for AR training.
7:32So again, more power is what people are seeking these days. Amazon SageMaker now offers an upgrade experience that lets you transition from SageMaker Studio to the SageMaker Unified Studio whilst preserving all your existing resources and keeping your controls. This means it's easy to use the new upgraded experience without having to do a whole lot of work. Amazon Bedrock custom model import now supports the QIN models. So these are things like QIN 2.5 Coder, which I've had a bit of luck with running myself. These are useful for a wide range of different modalities. QIN 2.5 Coder obviously is optimized for code generation understanding.
8:10So it's really useful for things like code completion and bug fixing, etc. Amazon Lex has improved its conversational accuracy with LLM assisted natural language understanding. So this means that it can do things like interpreting complex or lengthy utterances, maintaining accuracy despite spelling errors, not that I'd ever make a spelling error, extracting slots from verbose inputs and delivering better results with minimal training. And it doesn't need, does not need any changes to permissions or integration settings. Amazon Nervasonic, I know a lot of people have been using this lately. It's pretty cool.
8:43It's a state-of-the-art speech-to-text foundation model. It now supports the Spanish language. So now you have natural real-time voice conversations to more users and developers worldwide. So this builds upon its existing support for English, and it has both American and British accents. And it has two additional masculine and feminine sounding expressive voices in Spanish. Still no Aussie voice. Petition for me to be the voice or Amazon Nova Sonic. I think people would start using it if they knew it was your voice. You can now extend Amazon Q developer ID plugins with MCP tools. So these are model context protocol tools.
9:21So you can now augment the list of built-in tools with any MCP server that supports the STDIO transport layers, that I O as I always call it. And these can be managed using the Q developer using user interface, which is way easier than editing the JSON file. I don't know why I keep editing the JSON file. I should not be doing that. I should just be using the tool makes it a lot easier. Amazon Q developers introduced pro tier upgrades for builder IDs. So this gives you higher usage limits in your IDs and the command line interface as well, because capacity starts to become a thing you start doing more and you want bigger limits and amazon q developer has launched java upgrade selective transformation in the cli this is in preview and this will do the selection of steps for a transformation plan and a breakdown of a transformation job for granular code reviews and for first party and third party dependencies the libraries and their versions you would like q developer to upgrade during the jdk version upgrades will also be analyzed as well so this is a pretty cool thing to, I guess, overcome that chore of having to keep things up to date.
10:27It's nice if you're going to have to. Next up, we've got Compute. Amazon EC2 Auto Scaling now offers the ability to filter out instance details from the Describe Auto Scaling Groups API with a new parameter. With include instances set to false, you can quickly access metadata and configurations about your auto scaling groups without the overhead of instance details reducing the size of the api response and improving api response time and if you're still not using auto scaling i definitely recommend it what do you think simon i don't know what to tell you if you if auto scaling is not a part of your life if you're using ec2 instances then um talk to your friendly essays that's in all seriousness it's still it really is yes it's one of the coolest features it has so many capabilities it lets you do things before the instances start, after the instances stop.
11:18It lets you do rolling upgrades. It is the secret source of maintaining a highly available instance-based architecture. Absolutely. I could not have said it any better myself. And we are also announcing the job completion metadata logging for AWS Parallel Computing Service. So with this launch, Parallel Computing Service can be configured to emit job completion logs to Amazon CloudWatch logs, S3, and Amazon Data Firehose. AWS Compute Optimizer now identifies idle EC2 autoscaling groups with GPU instances. As AI development accelerates, organizations are creating more autoscaling groups with the G and P instance types for training and inference workloads.
12:09So now with the NVIDIA CloudWatch agent, Compute optimizer analyzes utilization data and identifies groups that have completed jobs and are made idle during your specified lookback period making it easier to identify and prevent waste on these high cost instance types this is definitely one that you definitely want to bookmark if you are going to be using any of those instances you definitely want to make sure that you're using the right amount of compute you're turning off those instances when you're not using them Yeah, we have all the tools are there to help you not use stuff. That's the beautiful thing.
12:45It's like, we don't want you to use too much. Use just enough. Just the right amount. That's right. AWS Deadline Cloud Monitor now includes a worker dashboard that makes it easy to monitor the performance of your workers. AWS is expanding access to Amazon Elastic VMware service through public preview. This builds on the momentum of the initial private preview announcement that happened back at reInvent in 2024. So customers who want to run VMware Cloud Foundation-based workloads, they can do that within their VPC. Let's talk contact center. Amazon Connect has enhanced communication limits for outband campaigns, so you can do more.
13:29Amazon Connect customer profiles for travel and hospitality can now allow you to more seamlessly ingest and map data from your industry-specific source systems into your customer profiles so you get a better view. It now has industry-specific mapping from over 75 source systems. So you can use things like Amadeus, which is even a travel system I know of, to integrate data. So integration of data is always a challenge. We want to make sure we have that there. Amazon Connect customer profiles now offer a profile explorer so you can access a unified customized view of all of your customer profiles.
14:05And Amazon Connect has enhanced hold duration tracking for multi-party calls. So this new field allows contact center managers to gain insights into hold patterns at the individual agent level during customer interaction. And it also gives other benefits like better agent performance management and how to improve stuff. You know, let's face it. None of us want to be kept on hold too long. This allows that feedback loop to go. What's not working here that everyone's on hold for a long time? I like it. Because remember, your call is important to us. And last one for this one, Amazon Connect introduces enhanced calculated attributes.
14:42So this gives you timestamp controls, historical data backfill, and improved limits to help you transform your customer data into actionable insights. You can now specify timestamps on your data, including future dated events, and you can process historical data with increased limits. So this gives you the ability to do things like tracking upcoming appointments, analyzing long-term customer behavior patterns, evaluating customer lifetime value, and making sure your agents are prepared with relevant context before customer interactions. I tell you, the Amazon Connect team, they just keep pushing out great capabilities for customers.
15:16It's good to see. They really do. Yeah, I'm definitely excited. I'm seeing so much interest now with being able to have these call center types of workflows using AI. So I'm definitely excited to see how Connect can help more customers be able to do that. and now let's talk about containers amazon eks pod identity now provides a simplified experience for configuring application permissions to access adbis resources in separate accounts with enhancements to eks pod identity apis you can now seamlessly configure access to resources across adbis accounts by providing the resource account iam details during the creation of the Pod Identity Association.
16:03Amazon ECS now supports updating capacity providers for an existing ECS service. With this enhancement, customers can seamlessly update the underlying compute configuration for their ECS services without incurring operational overhead or potential disruption from needing to recreate their services. Now we've got databases. Amazon RDS for MySQL now supports Community MySQL Innovation Release 9.3 in the Amazon RDS database preview environment. This allows you to evaluate the latest innovation release on Amazon RDS for MySQL. Amazon RDS for DB2 now supports cross-region standby replicas. This is a new feature that helps customers reduce database downtime during disaster recovery.
16:55Amazon RDS Custom for SQL Server now supports Qtative Update 18 for Microsoft SQL Server 2022. Jillian, could this be an opportunity for me to remind people to patch your stuff? I was waiting for you to do that. Oh, my God. Yes. It never gets old. Patch your stuff. This update is available for SQL Server Developer, Web Standard, and Enterprise Editions. and hopefully you're just now motivated because of Simon. AWS announces the open sourcing of PG Active, a Postgres extension for active-active replication. Ooh, I love all these resiliency, disaster recovery updates. This is a cool one too because this one brings it to the next level of failover capability.
17:46It's very cool. Yeah. So PG Active lets you use asynchronous active-active replication for streaming data between database instances to provide additional resiliency and flexibility in moving data between database instances, including writers located in different regions. And so this helps maintain for availability operations like switching write traffic to a different instance. pg-active builds on the foundation of postgres logical replication features such as bidirectional replication between tables starting in postgres 16 and this is open source so i i'm excited about this one i think more and more customers i'm sure like whether it's regulatory maybe just for that high availability their business is growing they're just looking at more opportunities to be able to expand globally and having active active.
18:47So this is super cool that there's just even open source support for it. Amazon DynamoDB Streams adds support for Kinesis Client Library 3.0. Valky introduces Glide 2.0 with support for Go, OpenTelemetry, and Pipeline batching. So Glide stands for the General Language Independent Driver for the Enterprise, which is the latest release of one of its official open source Valky client libraries. And if you're not familiar with Valky, this is the most permissive open source alternative to Redis stewarded by the Linux Foundation. So it's meant to always be open source. And Glide is a reliable, high performance, multi-language client that supports all the Valky commands.
19:37Nice, you can glide. Let's glide. Let's talk front-end web and mobile. Adibus AppSync enhances security with default encryption for GraphQL API caching, so it will automatically enable encryption at rest and in transit for all new API caching configurations, and this means that your posture is better. Management and governance. AWS console mobile application has added support for CloudWatch log insights. So this is really cool if you need to search and analyze log data while on the go. And let's face it, we've all had those weekends where things aren't going well. You're out of pocket. You're not near your laptop, et cetera.
20:19Well, AWS console mobile app has your back. AWS, yeah, yeah. AWS marketplace now supports the private marketplace and management in the console. so you can now manage things that are private to your organizational unit only. The Amazon CloudWatch agent has added support for EBS detailed performance statistics, so this gives you more granular visibility into your volumes I.O. performance, so you can understand what's going on and why things are going wrong. You can track performance trends, you can crack custom dashboards, you can set up alarms. This is a good thing. And AWS Control Tower now supports a service-linked AWS Config managed config rule, That's hard to say.
21:03But basically, a service-linked AWS Config rule is managed entirely by AWS services and cannot be edited or deleted by users. To maintain consistency, prevent configuration drift, or simplify the user experience, you can update these rules only through AWS Control Tower. We've got a few updates. Actually, no, not a few. There's a couple in networking and content delivery. In fact, I think technically there's more than a couple because there's more than two. So it's now a few. Oh, you know what? I didn't really know what the definition of a couple is. Yeah, remedial meth tutor for Jillian Ford.
21:41Remedial meth tutor for Jillian Ford. Well, I don't need it. There's AI now. Of course, yes, it could do the thinking for you. It could do the thinking. All right. Well, now we've got AWS Network Firewall. They've now launched support for active threat defense. This is a new security feature that helps you protect your Amazon virtual private cloud workloads against threat activities observed across AWS global infrastructure using Amazon threat intelligence. So network firewall with active threat defense. This provides automated intelligence driven protection against dynamic ongoing threat activities observed across the infrastructure within AWS.
22:22So you configure the managed rule groups in your firewall. And this is going to automatically block suspicious traffic, such as command and control communication, embedded URLs, malicious domains. This sounds super useful. It is a big deal. And this actually builds upon a technology we talked about in the past called MadPot. There's also some great blog posts about that. And this is AWS's global threat detection system where we have hundreds of thousands of instances out there pretending to be targets. so that the miscreants attack it. And then we interpret what they do with the attacks. And then that starts to inform how to protect.
23:02And so we're seeing in real, real time what's going on there out there. And then we're putting in place defenses immediately to counteract those. So it's, yeah, it's very cool and extensive technology that really tightens up the feedback loop of the threats emerging and then actually mitigating against those threats, rather than waiting for a new rule set to be published or someone to put out a CV, etc. Another one from AWS Network Firewall, they now support AWS Transit Gateway native integration. This capability is available in five AWS regions, and if you are new to Transit Gateway, This interconnects your VPC and on-premises networks, while AWS Network Firewall provides comprehensive security controls for those VPCs.
23:56AWS Cloud WAN announces the general availability for security group referencing an enhanced domain name system across VPCs connected by Cloud WAN. So with SG, which is the security group referencing, these customers can simplify management of security groups and gain a better security posture for cross VPC connectivity via Cloud WAN. So with enhanced DNS support, customers can enable the resolution of public DNS host names to private IP addresses for DNS queries from VPCs attached to Cloud WAN. Amazon CloudFront introduces a new console experience that simplifies the delivery of secure, high-performance applications to users on the internet.
24:45AWS WAF reduces web application security configuration steps and provides expert-level protection. That's the kind of protection I want, expert-level. Not basic level, I want expert-level. Let's talk security, identity, and compliance. We touched on a few security things early on, but there's more. AWS KMS has launched on-demand key rotation for imported keys. So that means you can meet your compliance requirements by keeping your keys rolling. Amazon ECR enhanced scanning now surfaces image use status. So now you can understand the last use date, the number of clusters that the image was used in, and the cluster ARNs as well.
25:22We talked also about the AWS Shield improvements, but we're now also happy to introduce AWS Security Hub for risk prioritization and response at scale. this is in preview as well. This is a good one because this basically transforms correlated security signals into actionable insights through visualizations and contextual analytics. So it means you can identify critical patterns and trends. You can centralize your security ops. So for example, it detects and correlates scenarios where publicly exposed resources with highly exploitable vulnerabilities have access to storage with sensitive data.
25:55So this means you can get a better risk context so you can make more informed decisions about immediate action on security issues. So enhanced capabilities include exposure findings, security focused asset inventory, attack path visualization, that one's pretty cool, and automated response workflows with ticketing and system integration so you can action things super super quick. Wow I really like that for Yeah, for especially for leaner teams where I see it often where like leaner security teams, they look at maybe security hub and it can feel a bit overwhelming because there's so many different things.
26:33You don't really know what necessarily to prioritize. And how do you do that when you're also responsible for building out features? So now I just love that these automated response workflows and the prioritization just helps them to be able to actually take baby steps at being able to improve their security posture. That is a great call out. Great call out. AWS Certificate Manager or ACM has announced exportable public certificates that you can use on any workload that requires a public TLS certificate, whether within AWS or outside. This is very, very cool. because now you can issue public certificates that you can export and access to securely terminate TLS traffic on anything, including institutes, containers, and on-premises as well.
27:20Now, this helps you, you know, you could, before you could do this all within AWS, but now you can use them anywhere. And the nice thing is the exportable public certificates are valid for 395 days, and they cost just$15 per fully qualified domain name and$149 per wildcard name. You don't need to sign up for bulk issuance contracts. You pay once through the lifetime of a certificate. You can monitor and automate the use of those certificates as well. I think this is going to make easy, easier implementation of certificates, which is nice. Speaking of nice and having good things, Adamus I am now enforces MFA for root access across all account types.
28:00I think you need one of your sound effects for this one. I know. Sorry. Let me think about what we're going to go with on this one. Sorry. See, I wasn't ready. I wasn't ready for the need to actually do this. I think I've got one that's appropriate, but we'll see if you like it. Hang on. Here we go. That's what exactly I was thinking. That's appropriate. Perfect. Okay. Here we go. So the new MFA enforcement is a significant milestone. Basically, it's a high bar for a customer security defense posture because basically it means you have to have an MFA. And you can register up to eight MFA devices per root an IM user.
28:41So this is really useful as well on those distributed teams, et cetera, where you still need to provide that access. You're not sort of fighting over the one MFA device. If you don't have MFA, and this is a Simon tip, the internet is a scary place. If you don't have MFA on everything you log into in your life, that's your homework. Yes. Go ahead. You need multi-factor authentication. Passwords, they're so 1990. You've got to have it. And now we have it across everything, which is great. Speaking about scariness, AWS KMS adds support for post-quantum MLDSA digital signatures. So this is a quantum-resistant digital signature algorithm designed to help organizations address emerging quantum computing threats.
Read the full transcript
29:28This post-quantum computing signature algorithm is one of the selected algorithms standardized by NIST to protect sensitive data well into the foreseeable future, including after the advent of cryptographically relevant quantum computers. AWS WAF now supports automatic application layer distributed denial of service protection. So this is at the layer seven level, and this automatically detects and mitigates DDoS events of any duration to ensure the applications on CloudFront, ALB and other AWS services are up and running. Amazon verified permissions reduces authorization request pricing by up to 97%.
30:09So it's much better than it was before. Express.js developers can now add authorization in minutes with Amazon verified permissions. So if you use that, this makes it super easy. And one quick update in the topic of serverless. Power tools for AWS Lambda introduces Bedrock Agents functionality utility. if you are not a power tools for adabase lander user i encourage you to be so it does a whole lot of cool stuff that are sort of in the category of stuff i really want my application to do but it takes a lot of time and effort this just does it for you you know parameter injection response formatting boilerplate code just good stuff i'm i'm a fan of power tools and speaking of other things to be a fan of let's talk about storage amazon efs now supports ipv6 for both the efs APIs and mount targets.
31:00Amazon S3 Express OneZone now supports renaming objects with the new Rename Object API. For the first time in S3, you can rename existing objects atomically with a single operation without any data movement. Adibus Backup announces support for multi-party approval in Adibus organizations for logically air-gapped vaults to enhance data recovery. The new AWS Backup feature enables customers to authorize access to backups for approved accounts in logically air-gapped vaults, even when the owning account becomes inaccessible due to inadvertent or malicious events. Multi-party approval is a new governance capability that requires multiple authorized individuals to approve critical operations before execution on AWS resources.
31:53This distributed decision-making process adds an enhanced security layer by preventing any single person from making unilateral changes. Oh, I feel so much better than that. Knowing that, you don't have to worry about making a mistake of setting a backup period for a very long time. You're like, oh my gosh, wait. The two-person rule is very handy in this situation. Yes. Especially maybe even with backup and cost optimization. If you want to retain these backups and maybe you think, oh, let me set a very long retention period and you're like, wait, but now I'm getting told by my CFO I need to reduce my costs and I've got all these backups.
32:33So I think having that extra layer so you don't make any decisions, you don't regret. You might regret, exactly. Amazon S3 now includes additional contacts in HTTP 403 access denied errors for requests made to resources in accounts within the same AWS organization. This context includes the type of policy that denied access, the reason for denial, and information on the AWS IAM user role that requested access to the resource. This is such an ergonomics improvement. Oh, my goodness. If you're trying to figure out the security policy that you put in place, that you're now bumping into this across a big estate, this is, yeah, I'm happy with this one.
33:21I mean, there's a lot of basic, I mean, I've got one more, but I mean, just all of these small updates that are like huge wins. Yeah. Yeah. And the last one, Amazon S3 adds S3 tables storage cost information for individual tables in AWS Cost Explorer and AWS Cost and Usage Reports. You can now track and analyze all S3 tables costs, including storage, API requests, and maintenance operations for each table in your data lake. This helps you make decisions about resource optimization and to attribute cost to specific projects and business units. Another one that I'm also super excited about, especially as more and more customers are using Apache Iceberg and want to be able to take advantage of S3 and being able to query it and understanding their costs as they're making better business decisions.
34:15This is another one. We've had so many of these MFA. like yeah it's been a big ergonomics uh week i think lots of lots of ergonomics things that just nice a few price reductions you know life is good life is good jillian how do folks reach out to you linkedin i am jillian ford on linkedin there you go and if you want to go old school awspodcast.amazon.com is the place to do it and of course until next time keep on building
From the publisher
Simon and Jillian take you through all the big security announcements from AWS re:Inforce plus a host of cool new features and price reductions!
