Good Morning!
This Thursday I’m going to try livestreaming whatever interests me at 10AM; I’ll be on Twitch, LinkedIn, and Twitter; come heckle, throw comments at me, or just watch me embarrass myself if you’d like. See you there!
Things I Found on the Internet
Amazon gets salty and posts a blog post about the FTC’s lawsuit regarding Sponsored Ads. The entire internet basically disagrees with them, as do the Attorneys General of 20 states, so… yeah. It’s times like this that I’m glad I stay on the AWS side of the fence.
AWS likes to trumpet its wins constantly, but I have to go digging to find its occasional losses, like this one: a Swiss minister prevented a secret Amazon deal.
On the happy path, Jeff Barr posted his Leadership Principles for AWS News Bloggers a while back, and I think it’s why I always found myself responding well to / trusting his writing. I still do; I wish he wrote more.
What AWS Has For Us This Time
AWS Lambda now supports SnapStart for container image functions
I’m amused that the URL slug for this release is dated back in July. I wonder why it was held back?
Amazon CloudWatch now supports warm-up periods for alarms
It took seventeen years, but finally CloudWatch won’t start off screaming for help before it checks the metrics it’s supposed to alert on. Good work!
Amazon Kinesis Data Streams announces data delivery to general purpose Amazon S3 buckets
Finally, a feature whose value proposition is “stop paying us for an intermediate product to stuff the data where you’re obviously going to put it anyway.” We’ve only been asking for this for how long again?
Amazon Linux 2027 is now available in public preview
This is a big change to everyone’s provisioning process: namely, you’ll have to explicitly disable SELinux as part of your cloud-init configurations. “You shouldn’t do that” yes you are correct Eugene, but it’s still the most widely disabled Linux configuration on the planet so let’s keep this shit semi-real, shall we?
Amazon CloudFront announces API support for flat-rate pricing plans
Finally; I’m not at all clear on how pricing plans for CloudFront (which are great, even if only as a cost mitigation for unexpected virality) were able to ship WITHOUT API support, but here we are.
AAA games on a $35 stick: How Luna removes the hardware barrier with AWS
What this clearly AI-written slop post neglects to mention is that as per Wikipedia, “In April 2026, Amazon announced significant changes to the platform, including the removal of previously purchased games and third-party subscriptions, giving users until 10 June 2026 to access titles bought before 10 April, after which they would be removed from libraries without refunds.” So who exactly is going to trust this thing as anything other than a cautionary tale?
How t54 built a trust layer with Amazon Bedrock AgentCore payments
They continue to tie themselves in knots trying to avoid saying “cryptocurrency” but that’s exactly what this is, and is a solution to a problem I have never once heard a customer articulate. This shit beclowns the rest of Bedrock every time it comes up.
Introducing Claude Fable 5.1 on AWS
That’s right, a new top tier model from the most sanctimonious AI lab is available on your AWS bill.
Tokenomics at scale: How Jamf built real-time spend enforcement for Amazon Bedrock
I like the downgrade to Haiku as punishment for exceeding your budget. Note, as of this writing Haiku hasn’t seen an update in a year. I kinda wonder why they don’t cut even further and use a Nova model; as one of the only customers in the world to use it they’d both save money and probably get a keynote speaking slot out of it. The only concern is how well this is gonna age as AWS inevitably solves this problem globally for everyone.
How PGA TOUR automated live profanity detection with AWS using Amazon Transcribe
I’m tickled by the idea that golfers apparently swear enough to make this an important thing to build. I suppose that tracks; I don’t play golf myself, preferring instead “the AWS bill” for my “lowest score wins” endeavors.
AWS and Microsoft Azure collaborate to expand multicloud networking
This is huge, just because like the other multicloud interconnect options, it charges for port speed, not per gigabyte flowing through it. This represents a data transfer charging sea change.
We invited a direct competitor into Security Hub Extended. Here’s why.
Because customers demanded it and you like to make money, presumably.
Detect stalled Amazon S3 live replication to prevent unexpected storage costs
Instead of strapping together a bunch of services as an AWS “Solution,” here’s a novel idea: how about S3 fixes live replication so it does this for you? This could alternately be called “making the product function as described.”
It’s once again security time. We start with a path traversal that turns least privilege into root, where scoping ssm:SendCommand to the one approved document, aka “the containment AWS itself recommended,” apparently doesn’t bloody work. No workaround, and a manual upgrade on an agent marketed under the banner of agentless management is depressingly on-brand. Nearly as good: an HMAC key stored inside the thing it signs, so DescribePipeline became execute-as-your-coworker, and upgrading the SDK does nothing until you go re-upsert every pipeline by hand so get cracking. From there the genre turns nostalgic, with Java deserialization hiding in cursor pagination confirming that page two costs extra, stack exhaustion in a parser for a self-describing format whose flagship service AWS already shut down, and scaffolding tooling a bit too eager to run shell commands. Then reconfigurable silicon gets undone by a temp file in a sloppy directory. FPGAs, defeated by /tmp.
… and that’s what happened Last Week in AWS.

