In short
AWS Podcast Episode #736 Summary: New Amazon Bedrock APIs, New EC2 Instance Types, and Lots More
Release Date: September 8, 2025 Hosts: Simon Elisha
Episode Overview In this episode of the AWS Podcast, host Simon Elisha discusses a variety of significant updates and new features introduced by AWS. From enhancements in data management to advancements in artificial intelligence, the episode covers a broad spectrum of topics relevant to developers and IT professionals.
Key Updates and Features
Amazon EMR (Elastic MapReduce)
- Apache Spark Fine-Grained Access Control: Enhanced data security and simplified access management through Lake Formation.
- S3A as Default Connector: Optimized performance for Apache workloads, improving efficiency in processing large-scale data.
Amazon OpenSearch
- Support for Attribute-Based Access Control (ABAC): Easier management of access controls.
- Introduction of i8g Instances: New storage-optimized instances for better performance on storage-intensive workloads.
AWS Graviton 4 Processors
- Performance Improvements: 60% better compute performance compared to the previous generation, supporting local NVMe storage and improved latency.
Amazon SageMaker
- Lakehouse Architecture Enhancements: Supports tag-based access control for federated catalogs, facilitating easier permission management.
- HyperPod Support for EBS CSI Driver: Simplifies persistent storage management through Kubernetes.
Application Integration
- End-User Messaging Enhancement: International SMS capabilities for US toll-free numbers to over 150 countries.
- Amazon Managed Service for Prometheus: Direct integration with PageDuty for easier monitoring setups.
Artificial Intelligence
- Count Tokens API in Amazon Bedrock: Helps users determine token counts before inference, improving cost projection and usage transparency.
- New OpenAI Models Available: Integration of OpenAI's models into Amazon Bedrock for easier access.
Amazon Connect
- Generative Text-to-Speech Voices: 20 different enhanced voices available for natural interactions.
- Multi-User Video Calling: Supports collaborative conversations among multiple users.
Compute Updates
- AWS Batch Default Instance Type Options: Allows automatic selection of cost-effective instances for different workloads.
- New EC2 Instance Types (M8i, RAI): Higher performance and memory bandwidth options for various applications.
Database Improvements
- Amazon RDS for MariaDB: Now supports MariaDB 11.8 with vector support.
- Delayed Read Replicas for PostgreSQL: Helps protect against data loss from human errors by creating lagged replicas.
Networking and Security Enhancements
- AWS Network Firewall Metrics: New metrics for monitoring incoming traffic bytes.
- Integration with ITSM tools: Enhanced incident response through synchronization with platforms like Jira and ServiceNow.
Storage Innovations
- Amazon S3 Batch Operations: Improved ability to verify the integrity of stored data sets efficiently.
- Snapshot Copy for AWS Local Zones: Enhances data backup processes.
Conclusion The episode highlights how AWS continually evolves its services to enhance performance, security, and usability across a range of use cases. Whether through improved instance types, enhanced AI capabilities, or better database management, AWS is providing tools to help developers and IT professionals optimize their workflows and leverage cloud technology effectively.
Feedback Listeners are encouraged to provide feedback through the podcast's communication channels.
Note: Stay tuned for more updates in the next episode to continue building your knowledge of AWS services.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00This is episode 736 of the AWS podcast, released on September 8th, 2025. Hello everyone and welcome back to the AWS Podcast. Simon Leesha here with you. Great to have you back flying solo today. Gillian is on vacation and Shruti has moved on to another opportunity. She's doing some cool things elsewhere. So we of course thank Shruti for all the great work she did on the podcast and we wish her well. Now she'll be a listener rather than a host, but I'm sure she'll still be into the podcast. lots and lots of updates this week so let's get going amazon emr on ec2 has added apache spark native fine-grained access control via lake formation and support for adabus glue data catalog views now this means you can improve your data security simplify your access management and make sharing a lot easier across your environment amazon emr has also announced s3a as the default connector.
1:01Now this optimizes performance for Apache Hadoop, Apache Spark and Apache Hive workloads on Amazon EMR. Now this enhances the open source S3A architecture with AWS specific optimizations to help organizations process large-scale data more efficiently. So this is good in terms of performance, in terms of support and lots of other cool features. Amazon OpenSearch Serverless now supports attribute-based access control or ABAC for the data plan APIs, which means it's easy to manage access control across the board. Are you detecting a trend so far? AWS Cleanrooms now supports error message configurations for PySpark analysis.
1:41So this means it's easier for you to develop and test sophisticated analytics faster in a collaboration. So you can now specify how much information appears in error messages for analyses that use PySpark and the Python API for Apache Spark. Because if you think about it, log messages can share a lot of information. You may want that, you may not. You get to choose. The Amazon OpenSearch service now supports i8g instances. This is the latest generation of storage-optimized instances with the best performance for storage-intensive workloads. AWS Graviton 4 processors, they have 60 % better compute performance compared to the previous generation i4g.
2:23They use the latest third generation Adibus Nitro Solid State Discs, local NVMe storage that give you up to 65 % better real-time storage performance per terabyte, whilst up to 50 % lower storage IO latency and 60 % lower storage IO latency variability. Have a look at this. I always recommend that when a new instance type is supported, you run some tests, check your configuration and in most cases, you're going to want to swap. The Amazon SageMaker Lakehouse architecture now supports tag-based access control for federated catalogs. So T-back enables simplified permission management by logically grouping catalog resources using tags, which allows scaling permissions across data sets with a minimum set of permissions.
3:05It also facilitates data sharing across different accounts, so it just makes things easier. Amazon QuickSight now supports connectivity to Google Sheets, so there is now a connector to get straight into that. And Amazon QuickSight has also expanded limits on calculated fields. So the limits are now increased for the number of calculated fields allowed in an analysis from 500 to 2000 and from 200 to 500 per data set. So more analysis. Amazon Managed Service for Apache Flink now supports customer managed keys. And Amazon Managed Workflows for Apache Airflow now supports downgrading to minor versions as well.
3:40So this means you can do upgrades and downgrades automatically. Let's talk about application integration. AWS end-user messaging now supports international sending for US toll-free numbers. So now you can send SMS messages to over 150 country destinations, including Canada, using your US toll-free number. So this means you can have a single number to send to any supported country. An Amazon managed service for Prometheus now adds direct page duty integration. So you don't have to create your custom Lambda function to connect into that capability. Let's talk artificial intelligence. The Count Tokens API is now available in Amazon Bedrock, enabling you to determine the token count for a given prompt or input sent to a particular model ID prior to performing any inference.
4:26By servicing a prompt's token count, the Count Tokens API allows you to more accurately project your costs and gives you better transparency and control over your AI model usage. At launch, the Count Tokens API will support clawed models with the functionality available in all regions where these models are supported and of course more models will be coming up. Amazon Bedrock now provides simplified access to OpenAI open weight models. So these are two new OpenAI models with open weights in Amazon Bedrock. So if you want to use OpenAI's GPT-OSS-120B and GPT-OSS-20B models without having to manually access anything, you can do it.
5:05Amazon Poly has launched more synthetic generative voices in English, French, Polish and Dutch. And we're also announcing the AWS Billing and Cost Management MCP Server. Now MCP servers are super useful for getting stuff done. This is now available in the AWS Labs GitHub repository. And this allows customers to analyze their historical spending, find cost optimization opportunities, and eliminate costs of new workloads using the AI agent or assistant of your choice. Amazon SageMaker has introduced account agnostic reusable project profiles. This means that administrators can define project configurations once and reuse them across multiple AWS accounts and regions so they're no longer tied to a specific AWS account or region.
5:50Amazon Q Developer now supports MCP Admin Control. This provides organizations with the granular control needed to manage external resources safely and effectively. With this launch, an admin has the ability to enable or disable the MCP functionality for all the QDeveloper clients in that organization. So this means if an administrator disabled the functionality, then the users won't be able to add any MCP servers, nor will any previously defined servers be initialized. QDeveloper checks and applies admin settings at the start of each session and also every 24 hours when the client is running.
6:23And Amazon Bedrock Data Automation or BDA now supports five additional languages for document workloads in addition to English. So we've got Portuguese, French, Italian, Spanish, and German. With this launch, customers can process documents in these new languages and create blueprint prompts and instructions in these new languages when using BDA custom output for documents. AWS Health Omics now supports task-level timeout controls for NextFlow workloads. So with this launch, customers can now set fine-grained controls for the NextFlow workflow tasks and enable automated run cancellation if specific tasks take longer than expected.
6:58And AWS Health Omics now also supports third-party container registries for private workloads. So this is enabled through the Elastic Container Registry, ECR, and allows you to automatically translate third-party container URIs to ECR URIs. So this means you can more easily access containerized tools from popular third-party registries without having to manually migrate them to a private ECR registry or make any changes to the workflow definition. Amazon SageMaker HyperPod now supports Amazon EBS CSI driver for persistent storage. This capability allows customers to create, attach, and manage EBS volumes through Kubernetes persistent volume claims, providing storage that persist across pod restarts and node replacements.
7:44Now, obviously, when you're building models, testing models, etc., it's long-running workflows, stuff breaks along the way. This makes it a lot easier to manage in your environment. Amazon SageMaker Unified Studio has added S3 file sharing options to projects. So this is a simplified file storage option, giving data workers an easier way to collaborate with their analytics and machine learning workflows without depending on Git. So now you can choose between Git repositories, so GitHub, GitLab, or Bitbucket Cloud, or Amazon Simple Storage Service buckets for sharing code files between various members of a project.
8:19SageMaker HyperPod now supports customer managed KMS keys for EBS volumes so you can have full control over the encryption keys while having your high performance compute capabilities. And Amazon Bedrock now supports a batch inference for Anthropic Claude Sonnet 4 and OpenAI GPT OSS models. So with batch inference you can run multiple inference requests asynchronously improving performance on large data sets at 50 % of the on-demand inference pricing. So choosing your workflow and your workload is really important and some things work better in batch. And if you've got batch stuff, this is the way to do it.
8:55Let's talk business applications. Amazon Connect now offers a generative text-to-speech voices. So this allows you to deliver natural, human-like and expressive conversations with your customers. You have access to 20 different generative enhanced voices across languages like English, French, Spanish, German and Italian. Amazon Connect now provides out-of-the-box embedding of tasks and emails into your websites and applications. So there's a nice Amazon Connect communications widget. So this means that customers can do things like submit a callback request outside business hours or send an email through web forms.
9:29Just means you have to develop that yourself. Amazon Connect now supports multi-user web in-app and video calling. So now multiple users can join the same session with an agent for a web browser or mobile applications. And you can also dynamically add participants during a live call or multiple participants can join a scheduled session with the same agent. So this is really useful to support things like joint financial planning between people, family medical conversations and consultations, legal representation, all that stuff where you've got to get people together. And Amazon Connect now supports recurring activities in agent schedules.
10:04So you can now schedule activities like a daily stand up at 8am or a team meeting every Monday at 9. Things that automatically get added to the schedule. AWS B2B Data Interchange now supports custom validation rules for X12 EDI documents, enabling you to expand and alter the validation logic of the X12 ANSI standard to align with customer agreements with your trading partners. This now enables the automated validation, transformation, and generation of electronic data interchange EDI documents that really still run the world in many places. So this lets you have far more control over what you're doing.
10:39Let's talk about compute. AWS Batch now supports default instance type options. So you can now set two new default instance types options of default x86-64, which is the default default, and default ARM64. And this will automatically select the most cost-effective instance type across different generations based upon your job queue requirements, where previously you could only get the optimal instance type, now you get like a family of instance types. AWS Deadline Cloud now supports Cinema 4D and Redshift on Linux service managed fleets. Now, AWS Deadline Cloud is a fully managed service that simplifies render management for teams creating computer-generated graphics and visual effects for things like films, television, and web content, etc.
11:20Previously, it was only available on Windows fleets. Now, you can have Linux-managed fleets as well, which is very exciting. AWS AppRunner expands support for IPv6 compatibility. So, if you're on the IPv6 train, this one has joined you at the station. Amazon EKS enables namespace configuration for AWS and community add-ons. With the namespace configuration, you can now specify a custom namespace during add-on installation, enabling better organization and isolation of add-on objects within your EKS cluster. Amazon EC2 Mac dedicated hosts now support host recovery and reboot-based host maintenance.
11:57So reboot-based host maintenance automatically stops and restarts instances on replacement hosts when scheduled maintenance events occur, which means you don't need to manually manage your planned windows, your maintenance windows. and this type of stuff just enhances the reliability and manageability particularly when you're running a fleet of these things for your testing and your management etc. Amazon EKS has introduced on-demand insights refresh so you get on-demand refresh of cluster insights which allows customers to more efficiently test and validate if applied recommendations have successfully taken effect.
12:29We're happy to announce the general availability of new general purpose Amazon EC2 M8i and M8i Flex instances. These are powered by custom Intel Xeon 6 processors only available on AWS and they give you the highest performance and fastest memory bandwidth among comparable Intel processors in the cloud. Again, always test your workloads against some of these latest instances because you can get great performance increases and price increases. There are also new memory optimized Amazon EC2 RAI and RAI Flex instances as well. So those might also suit your particular workload. Now let's talk about databases.
13:08Amazon RDS for MariaDB now supports MariaDB 11.8 with MariaDB vector support. Vectors are all the thing when you're doing AI and RAG and stuff like that. So that is now builty. Amazon RDS for SQL Server now supports Kerberos authentication with self-managed Active Directory. We're also happy to announce the Amazon Aurora MySQL 3.10 as the long-term support or LTS release. So this means that database users that use this LTS release can stay on the same minor version for at least three years or until the end of this standard support for the major version, whichever is sooner. Amazon RDS Custom for SQL Server now supports new general distribution releases for Microsoft SQL Server 2019 and 2022.
13:51Amazon RDS for Oracle now supports a new certificate authority and cipher suites for SSL and OEM agent options. And Amazon RDS for Postgres SQL now supports delayed read replicas. So this means you can specify a minimum time period that a replica database lags behind a source database. Now, why might you do this? This feature creates a time buffer that helps protect against data loss from human errors like accidental table drops or unintended data modifications. Not that you would ever do such a thing, but it's nice to know it's there. Amazon RDS for Oracle now supports redo transport compression.
14:25So this is a feature that compresses redo data before it's transmitted to a standby database. So this improves the redo transport performance because you're moving less data. Aurora DSQL now supports resilience testing with Adibus fault injection service. So this means you can now simulate real world scenarios that disrupt your connections to Aurora DSQL clusters, things like regional failures, etc. So you can see what would happen. Always good to test in advance. Amazon RDS for DB2 now supports read replicas. You can add up to three of these read replicas and these support read-only applications without overloading the primary database instances.
15:04Amazon Neptune Analytics now introduces a stop start capability. This is a new capability that you pause and resume your graph workload on demand, meaning you can reduce costs during idle periods without losing data or configuration. This is really interesting because many customers use Neptune Analytics for periodic graph workloads like fraud detection, recommendation engines or research simulations that just run periodically. So instead of having to leave it running, you can now actually stop it and then you can restart it. IDS Data API now supports IPv6, another step in the year of IPv6 that we're going through.
15:39Amazon Neptune now supports a bring your own knowledge graph for retrieval augmented generation rag. So this capability allows customers to connect their existing knowledge graphs to large language models, meaning you can get more accurate, content rich and explainable responses. A quick update on the topic of gaming. Amazon GameLift Streams now offers enhanced flexibility with default applications. You can now create new stream groups without specifying a default application and modify or remove the default application in the existing stream group. Let's talk Internet of Things. Adibus IoT Core now supports customer managed keys for the key management service.
16:18So again, bring your own keys. And Adibus IoT ExpressLink technical specification v1.3 has been announced. The updated specification provides hardware manufacturers who design IoT devices, new features for Bluetooth low energy communication and a new group of commands that give host processors control of the module I.O. pins. Using the Bluetooth low energy expanded feature set, AWS IoT Express thing makes it easier to advertise the device's presence and its capabilities and pair securely with other devices in a local personal area network. Let's talk management and governance. Amazon VPC IPAM has added in-console CloudWatch alarm management, so it means you can just be in the same place and take action straight away.
17:01Amazon CloudWatch has expanded region support for natural language query results summarization and query generation. So 15 new regions now let you interactively search and analyze your logs with the Log Insights query language, the OpenSearch piped processing language, and the OpenSearch service structured query language. So lots of ways you can get into your logs and figure out how you want to run things. This is a nice small one, but a useful one. Adabuse Management Console now supports assigning a color to an AWS account for easier identification. So AWS customers now have an easy way to identify their accounts at a glance using the account color settings.
17:36You can assign a color to your AWS account, so like red for production or yellow for testing. And it appears in the console's navigation bar for all authorized users in that account, which gives you a quick visual cue, which is kind of nice. AWS billing and cost management now provides customizable dashboards. So now you can visualize and analyze your AWS spending in one consolidated view. So this combines data from AWS Cost Explorer and Savings Plan and Reserved Instance Coverage and Utilization Reports in the workplace. Let's talk migration and transfer. AWS Transfer Family Terraform Module now supports deployment of SFTP connectors to transfer files between Amazon S3 and a remote SFTP service.
18:18So this adds the existing support for deploying the SFTP endpoints using Terraform, so you can infrastructure as code your transfers. and adabestransform4.net has added support for Azure repos and artifacts feeds for NuGet packages so you can connect your repositories directly. A few updates for networking and content delivery adabestclientvpn now supports connectivity to IPv6 resources it's all happening people adabestclientvpn has extended OS support to Windows ARM64 with version 5.3.0 and adabestim has launched new VPC endpoint condition keys for network perimeter controls. This is an interesting one.
18:56It's new global condition keys. There are things like VPC accounts, VPC org paths, VPC org IDs, etc. that help you ensure that request your AWS resources or buy your identities are made through your VPC endpoints. And we have now extended traffic mirroring support to new instance types. So Amazon VPC traffic mirroring lets you replicate the network traffic from EC2 instances within your VPC to security monitoring appliances. So you can do content inspection, threat monitoring, et cetera. Basically, anything that is a Nitro V4 instance can now support this as well. Let's talk quantum technologies.
19:34Amazon Bracket has introduced a local device emulator for verbatim circuits. This feature accelerates development by providing early feedback on circuit compatibility and expected behavior under realistic noise conditions, helping customers validate their quantum programs and develop noise-aware algorithms without incurring hardware costs. It's pretty cool. Some updates for security, identity, and compliance. The AWS Network Firewall has launched a receive bytes metric for stateless and stateful engines. This new feature lets customers monitor the total incoming traffic bytes inspected by firewalls, giving you valuable insights into your traffic patterns.
20:11You can understand what's going on. Are things changing? What's my capacity planning looking like? Can I reduce costs? All that good stuff. AWS Security Incident Response has introduced integration with the ITSM, so tools like Jira and ServiceNow, which means you can respond faster. These integrations provide bidirectional synchronization, allowing you to create, update, and delete issues in either platform with automatic data replication into AWS Security Incident Response cases. And speaking of AWS Security Incident Response, it is now Health Information Trust Alliance Commercy Theory Framework certified, so high trust certification, which means it matches stringent security and privacy requirements established by high trust for managing sensitive data.
20:53Amazon verified permissions now supports CEDA 4.5. This allows you to use the latest CEDA features, including the is operator, which lets you grant access based on resource types. This also helps you catch potential type related errors early in policy development. Lots of other changes to CEDA on the CEDA release pages, so check it out. And now let's talk storage. Amazon EBS has launched Snapshot Copy for AWS local zones. So Snapshot copies a point in time snapshot of an EBS volume and stores it in Amazon S3 in the region or to another local zone. Amazon S3 has improved AWS CloudFormation and AWS CDK support for S3 tables.
21:32So you could now do a lot more and consistently deploy and manage them. And Amazon S3 has introduced a new way to verify the content of stored data sets. You can efficiently verify billions of objects and automatically generate integrity reports to prove that your data sets remain intact over time using S3 batch operations. Now this capability works with any object stored in S3 regardless of storage class or object size without the need to restore or download data. Whether you're verifying objects for data preservation or doing accuracy checks, etc. This saves a lot of time. So basically with S3 batch operations, you can create a compute checksum for your objects and very easy to get started.
22:12And this complements S3's built-in validation, meaning that you can independently verify your stored data at any time. And Amazon S3 Express One Zone now supports resilience testing with adverse fault injection service. So again, you can verify that the things you put in place will work on those failure conditions. so lots of cool and interesting updates there i hope there was something for you as always we do love to get your feedback awspodcast.adamsland.com is the place to do it and until next time keep on building
From the publisher
Simon takes you through a big list of cool new things - something for everyone.
