Good Morning!
Another week has come and gone. I’ll be keynoting both O11yCon in London and SREcon in Dublin in October; what else should I spend time doing in Europe while I’m out there? I’ll have some downtime and a hankering to explore…
Things I Found on the Internet
AWS’s ExtendDB acts as a DynamoDB frontend for any data store you’d like, despite their rejecting all four of my PRs so far. Thus, I have built the inverse: ContractDB, which acts as a DNS frontend for DynamoDB.
IP to ASN Mapping & WHOIS Lookup Service | Team Cymru
EDITORIAL NOTES – NOT FOR PUBLICATION
- What happened: Team Cymru’s long-running IP-to-ASN mapping service, page refreshed with copy-pasteable examples. Three interfaces over one dataset: WHOIS on TCP/43 (bulk via netcat, thousands of IPs per session), DNS TXT lookups against origin/origin6/peer/asn.cymru.com zones, and an HTTPS form. BGP feeds from 50+ peers, refreshed every 4 hours. Verbose output is a pipe-delimited line: origin ASN, peer ASNs, prefix, country code, registry, allocation date, AS name. Page explicitly disclaims GeoIP use — country codes are RIR registry data, not geography. Free, no API key visible in the preview.
- Why it matters: Peer-ASN lookup is the underappreciated field — a one-hop upstream read without running your own BGP collector or paying for a routing-intelligence vendor. DNS transport makes it cacheable and cheap enough to sit inline in a detection pipeline, which is a different architectural posture from “call a REST API with a bearer token and a rate limit.” The 4-hour refresh sets the honest resolution ceiling: fine for enrichment and triage, wrong for hijack detection or anything needing sub-hour route change visibility. The GeoIP disclaimer is doing real work; registry country codes get misread as user location constantly, and this is upstream of a lot of bad compliance and fraud logic.
- Joke angles: Infrastructure that predates the API-key economy and still answers on port 43 — the whois daemon as living fossil that outlived several SaaS competitors. The eternal “use GNU netcat, not nc” instruction as a compressed history of Unix tool fragmentation. Registry country codes being mistaken for user geography, and the industry’s willingness to build entitlement logic on a field that just means “which filing cabinet holds the paperwork.”
- Second-order: Keeps a floor under commercial IP-enrichment pricing for the basic ASN/prefix case; vendors have to sell on freshness, history, and reputation scoring rather than the lookup itself. Lowers the bar for small security teams to add routing context to logs. Also quietly load-bearing — “dozens of public security projects already build against” it, meaning open tooling shares a dependency few of those users are budgeting for.
- Third-order: If free shared enrichment infrastructure becomes assumed baseline, the sustainability question follows the same arc as public NTP pools, key servers, and open registries: heavy automated traffic, no revenue attached, funding tied to one nonprofit’s continued willingness. Concentration of ASN context in one feed also means one refresh cadence and one set of parsing quirks propagate into a lot of downstream detection logic.
- Check before writing: Confirm current acceptable-use/rate limits and whether bulk querying still requires the documented begin/end verbose framing. Verify the 50+ peer and 4-hour figures against current docs rather than the page copy. Unclear whether the page is genuinely new or a redesign — do not frame as a launch without checking. Confirm Team Cymru’s current funding/nonprofit status. Note separately that Team Cymru has drawn criticism over its commercial netflow data business; that is a distinct product line from this free service, and conflating them would be unfair, but readers may raise it.
Speaking of shitposts that work, kube53 uses Route53 as a Kubernetes control plane somehow. My god, it’s beautiful.
We’re about to see the GA of the next version of Amazon Linux, and we’re still forced as a community to work around EPEL’s absence as a repo. Now the PostgreSQL RPM repo comes to Amazon Linux 2023.
An open source benchmark, aws-bench, has dropped; it evaluates how well agents perform AWS-centric tasks. Trouble is, I don’t see a lot of folks running this. You need a management account with permission to create an AWS Organization and member accounts. Then it takes hours to run. Finally, terminated accounts sit suspended for 90 days. This is… not something folks are gonna run casually. BUT! The way this is architected is basically a master class in what cloud agents get wrong, so… I think I like it?
What AWS Has For Us This Time
Amazon API Gateway now supports 1 MB execution logs with configurable delivery destinations
A 1MB log per event? That’s not telemetry my friends; that’s a new database.
Amazon S3 Object Lock now supports variable retention with event holds
Sweet, just so long as I still get to prank my coworkers by requiring a century retention on the big scratch bucket.
Lambda is “serverless” but is starting to look and be priced an awful lot like a server; they announced a 90-minute ceiling on Managed Instances for async and event source mapping invocations, with synchronous calls still cut off at fifteen. You can also hand-pick C9gd over M9g via capacity providers. Everyone who rebuilt around fifteen minutes in Step Functions gets to feel great about that.
Amazon EC2 now supports specifying compatible instance types on AMIs
At last, AMI owners can declare supported and/or unsupported instance types; non-permitted launches get blocked at the API. This is a free guardrail that turns a confusing kernel panic into a confusing API error instead.
Announcing second-generation single-rack AWS Outposts
Still x86_64 only; it seems that Graviton isn’t allowed to leave the AWS buildings. The names are Bmn-sf2e/Bmn-cx2/Bmn-cx3a, which is a pretty clear indicator that the naming committee has just stopped showing up to work at all these days.
How AWS thinks about FinOps Automation and Trust
“Another agent? Yes! But hear us out.” This is refreshingly self-aware of AWS, given the insane levels of agent fatigue experienced by the entire industry these days.
Introducing Amazon EBS Volume Clones across AWS accounts
When misconfigured this is a terrific new opportunity for your data to get exfiltrated. So don’t do that.
How to migrate from Amazon CloudSearch to Amazon OpenSearch Serverless
Note how it’s not actually cancelling CloudSearch, but the embedded video in the marketing page prominently features a decade-old AWS logo:
Introducing Pizza Bot, an open source inbox for AI agents that work in the background
I don’t actually hate this! I have a pending PR as of this writing, let’s see if they merge it for me.
First up, the security agent plugin skips the bucket-owner check that AWS docs nag you about in every S3 hardening guide manages to screw the pooch not once but twice, once in the agent and once in the MCP server, because agentic tooling has become a CVE delivery pipeline only with better branding. Deep Java Library contributes an integer overflow in tensor buffer validation, proving that Java’s memory-safety story might not be totally comprehensive. Then there’s the SSM Agent, the thing you installed specifically so you could retire your bastion hosts, which will now cheerfully forward a port somewhere you never asked it to. None of these come with anything like a console-side patch button. No, you find out via RSS, and the remediation is a version bump you schedule yourself, on your weekend, for code you didn’t write, because Customer Obsession.
… and that’s what happened Last Week in AWS.


