---
title: "You Owe Your Country’s GDP to AWS"
id: "15422"
type: "newsletter"
slug: "you-owe-your-country-s-gdp-to-aws"
published_at: "2026-07-20T05:30:00+00:00"
modified_at: "2026-07-20T05:30:00+00:00"
url: "https://www.lastweekinaws.com/newsletter/you-owe-your-country-s-gdp-to-aws/"
markdown_url: "https://www.lastweekinaws.com/newsletter/you-owe-your-country-s-gdp-to-aws.md"
excerpt: "On Friday AWS decided to give a fair number of us heart attacks before coffee, blasting out bill estimates in the multiple-trillions-of-dollars range. I checked mine, briefly considered whether I now owed a small nation's GDP in NAT Gateway charges,..."
---

About the Author Corey is the Chief Cloud Economist at Duckbill, where he specializes in helping companies improve their AWS bills by making them smaller and less horrifying. He also hosts the "Screaming in the Cloud" and "AWS Morning Brief" podcasts; and curates "Last Week in AWS," a weekly newsletter summarizing the latest in AWS news, blogs, and tools, sprinkled with snark and thoughtful analysis in roughly equal measure.

Sign up for the Newsletter  Stay up to date on the latest AWS news, opinions, and tools, all lovingly sprinkled with a bit of snark. "*" indicates required fields

## [Good Morning](https://x.com/QuinnyPig/status/2077946616070516902) !

On Friday AWS decided to give a fair number of us heart attacks before coffee, blasting out bill estimates in the multiple-trillions-of-dollars range. I checked mine, briefly considered whether I now owed a small nation’s GDP in NAT Gateway charges, and then remembered that I do this for a living and the number was itself obvious nonsense. For anyone who doesn’t stare at Cost Explorer as a hobby, though, that email was like getting mugged on the subway.

Nobody’s card got charged, no invoices went out, and by the time you read this the whole thing will be a footnote. But watching the billing system that AWS treats as sacred scripture fat-finger a figure with that many commas in it is the funniest thing to happen to a relatively dull space in a while. Hugs to the folks on that team. And slap whomever on the social media accounts team who apparently didn’t realize just how seriously some customers take this.

Anyway, the actual invoices will be along shortly, and they’ll be smaller but no less creative. Let’s dig in.

## Things I Found on the Internet

A vibe-coded app that [shows what your bill would have been](https://aws.mccullough.dev/)
 during AWS’s departure from sanity.

Rupert Goodwins nails why moving 900 apps off AWS is the easy part. [The real bind is Microsoft](https://www.theregister.com/columnists/2026/07/20/airbus-takes-flight-from-aws-what-happens-next-is-critical/5274109)
: 17,998 of Airbus’s 18,000 suppliers live there, and no European vendor can bid on an Office replacement nobody’s ever built. Sovereignty works for cloud tenders. Desktop and productivity? Nowhere to go yet.

A former water sustainability manager FOIA’d the utility bills and found AWS’s numbers don’t match its PR. AWS touted a 42 percent water reduction, but Prince William Water’s records show 0.8 and 32.1 percent, never 42. When your own ex-employee sues over the math, [the receipts get interesting](https://www.theregister.com/on-prem/2026/07/15/aws-sustainability-claims-dont-hold-water-lawsuit-alleges/5269723)
.

I wrote this one myself, so consider the recommendation appropriately biased. Dave Brown’s departure after 19 years is a massive loss of institutional depth and breadth, but the fun part is imagining what happens when [an Amazon Retail lifer inherits EC2](https://www.theregister.com/paas-and-iaas/2026/07/15/aws-ec2-leadership-change-dave-treadwell-replaces-brown/5272154)
. Spoiler: “Customers who launched m7i.large also launched…” feels uncomfortably plausible.

AWS shipped Lambda MicroVMs for the AI agent customers, but [stuffing a GitHub Actions runner inside one](https://mkdev.me/posts/using-lambda-microvms-as-github-actions-runners)
 is the practical use case for the rest of us. Per-second billing, 8-hour runtime, Firecracker underneath, not dog-slow, a fair sight more cost effective (and reliable) than GitHub’s own hosted runners… the advantages accrue. The writeup walks the webhook-plus-runner setup without pretending it’s harder than it is.

## What AWS Has For Us This Time

[Amazon CloudWatch Logs announces intelligent tiering for storage](https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-cloudwatch-intelligent-tiering/)

S3 got Intelligent-Tiering ten years ago, so CloudWatch Logs finally borrowing the concept feels less like innovation and more like AWS discovering its own back catalog. Three tiers, automatic demotion after 30 and 90 days, and the same eye-watering per-GB ingest fee that made you want to filter these logs out in the first place. Tread carefully.

[Amazon Cognito now supports importing users with password hashes](https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-cognito-password-hash-import/)

Migrating to Cognito used to mean forcing every user to reset their password on day one, a great way to teach customers that your new login flow is broken while also triggering fears of a data breach. Now you can import the hashes and skip the mass-reset apology email.

[Introducing Amazon GuardDuty AI Protection for AWS AI workloads](https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-guardduty-ai-protection-aws/)

“Cost harvesting attacks” is a lovely euphemism for someone running up your Bedrock bill, which, honestly, AWS already does for “free.” Now GuardDuty watches for prompt injection too, at a price revealed only after the 30-day trial ends and your finance team stops smiling.

[AWS Organizations now applies account departure security controls by default for new organizations created via AWS Organizations console](https://aws.amazon.com/about-aws/whats-new/2026/07/aws-organizations-security-controls-new-orgs-console)

Secure defaults that stop accounts from wandering off into the forest, applied only to organizations born after this announcement. Everyone else’s existing sprawl remains as escape-prone as ever. The controls are “intentionally lightweight,” which is AWS-speak for “we didn’t want the support tickets.” A rare freebie that costs nothing except your ability to leave.

[AWS Lambda announces self-managed code storage](https://aws.amazon.com/about-aws/whats-new/2026/07/lambda-self-managed-code-storage/)

“No additional Lambda charges apply,” which is kind, given you’re now paying S3 storage plus cross-Region transfer to solve a limit AWS invented. The 75GB quota that spawned a thousand support tickets also quadrupled to 300GB too. That’s a significant expansion to the “PackratDB” school of thought: stuff things into every free nook and cranny you can in an AWS account.

[Amazon S3 removes 30-day minimum for transitions to S3 Standard-IA and S3 One Zone-IA](https://aws.amazon.com/about-aws/whats-new/2026/07/s3-removes-30-day-transitions-standard-ia-one-zone-ia)

A decade of forcing everyone to babysit data for 30 arbitrary days before demoting it, and now that albatross necklace vanishes. Great for cold logs and backups, sure. Just remember the 30-day minimum *charge* still applies, so transitioning at day zero means paying for storage tiers you’re barely using. Progress, technically.

[Amazon SQS turns 20: Two decades of reliable messaging at scale](https://aws.amazon.com/blogs/aws/amazon-sqs-turns-20-two-decades-of-reliable-messaging-at-scale/)

Twenty years old, and the “Simple” in Simple Queue Service still means you’ll spend an afternoon learning what a dead-letter redrive is. Credit where due: SQS is one of the few AWS services that just works and rarely appears in my inbox at 3am. Happy birthday to the quiet one. You’re a goddamned champion.

[Announcing Lambda MicroVMs: serverless compute environments with VM-level isolation and near-instant startup](https://aws.amazon.com/blogs/compute/announcing-lambda-microvms-serverless-compute-environments-with-vm-level-isolation-and-near-instant-startup/)

So Lambda finally admits it was virtual machines all along, then sells you the machines it was hiding under the abstraction. A decade of “don’t think about servers,” now available as: here’s your server, per user, with a Dockerfile.

[Eliminating Java cold starts with AWS Lambda Managed Instances](https://aws.amazon.com/blogs/compute/eliminating-java-cold-starts-with-aws-lambda-managed-instances/)

The fix for Lambda cold starts is running Lambda on EC2 instances you pay to keep warm. So, servers. We’ve eliminated serverless from serverless and rediscovered the machine that never turns off. Congratulations to Java, the language that finally billed its way back to the mainframe.

[Introducing open source Bulk Executor for Amazon DynamoDB](https://aws.amazon.com/blogs/database/introducing-open-source-bulk-executor-for-amazon-dynamodb/)

“No coding required,” says the tool that spins up hundreds of Glue machines behind your terminal prompt. The command line utility runs locally while your bill runs distributed. Handy for bulk deletes and cross-account copies, sure. Just remember Glue meters every one of those hidden workers you’re not thinking about.

[Automating CIDR expansion: Reducing IP exhaustion downtime](https://aws.amazon.com/blogs/networking-and-content-delivery/automating-cidr-expansion-reducing-ip-exhaustion-downtime/)

Running out of IP addresses and not being able to expand contiguously is the natural consequence of forgetting how subnets work, and now you can automate your way out of it with five services stitched together. Step Functions, Lambda, DynamoDB, CloudWatch, and IPAM, all conspiring to fix a problem that proper planning solved for free, had you but thought to do it. Serverless duct tape, but functional.

[Setting up Layer 2 Networking on Amazon EC2](https://aws.amazon.com/blogs/networking-and-content-delivery/setting-up-layer-2-networking-on-amazon-ec2/)

The solution to “VPC won’t do Layer 2” is apparently “run a VPN from a Japanese university to trick Nitro into cooperating.” Four architectural patterns, nested virtualization on an m8i.4xlarge, and apparently a tunnel so your legacy MAC address based authentication protocol from hell can pretend it’s 2004. Cloud-native, baby.

[Security Hub adds AI workload protection and multicloud support for Microsoft Azure](https://aws.amazon.com/blogs/security/security-hub-adds-ai-workload-protection-and-multicloud-support-for-microsoft-azure/)

Amazon just launched security monitoring for Azure, which is at least one of: A, heartwarming multicloud maturity; B, a very polite way of following your workloads to the exit; C, a tacit admission that Microsoft isn’t ever going to fix Azure’s security because *by god* are those crayons delicious. My favorite detail: the customer who discovered a compromised account only because finance flagged the bill. I’m not going to give exact numbers of engagements I’ve had that were AWS focused that turned into a Surprise Security Discovery, but it’s greater than one.

This week’s security bulletin drop reads like a field guide to what happens when you bolt LLMs onto everything and hope for the best, starting with an observability tool that overshared by dumping raw prompts and full responses into CloudWatch for anyone with read access, because the AgentCore SDK decided your users’ secrets belonged in a log group. Then there’s the Strands memory tool that mails your API key wherever an LLM feels like sending it, which is what you get for handing a chatbot your Elasticsearch credential and asking it nicely not to gossip, and the HealthLake MCP server that forwards your temporary creds to whoever crafts the right pagination token, in case you wanted an SSRF sitting between attackers and your FHIR records. Not to be outdone by the AI crowd, the Load Balancer Controller sorted its rules by route type instead of specificity, letting any tenant hijack the neighbor’s gRPC traffic and turning multi-tenancy into the group project nobody consented to, while the diff tool built to catch breaking changes will run shell commands if you pass the right arguments, patched alongside the timeless advice to “only let trusted actors control the input,” which is security guidance on par with “don’t get hacked.” Five patches, four of them born from wiring agents to credentials and praying, and one plain old command injection just to remind you the classics never went anywhere. Rotate everything.

… and that’s what happened ***Last Week in AWS.***

## You might also like

[More Newsletter Issues](https://www.lastweekinaws.com/newsletter/)

Issue No.482

### [New Tools, Ancient Failures, Same Old AWS](https://www.lastweekinaws.com/newsletter/new-tools-ancient-failures-same-old-aws/)

[Read More about New Tools, Ancient Failures, Same Old AWS](https://www.lastweekinaws.com/newsletter/new-tools-ancient-failures-same-old-aws/)

Issue No.480

### [United Solved IP Exhaustion, You Won’t Believe How](https://www.lastweekinaws.com/newsletter/united-solved-ip-exhaustion-you-won-t-believe-how/)

[Read More about United Solved IP Exhaustion, You Won’t Believe How](https://www.lastweekinaws.com/newsletter/united-solved-ip-exhaustion-you-won-t-believe-how/)

Issue No.479

### [AWS Discovers ACME Isn’t Just Roadrunner Stuff](https://www.lastweekinaws.com/newsletter/aws-discovers-acme-isn-t-just-roadrunner-stuff/)

[Read More about AWS Discovers ACME Isn’t Just Roadrunner Stuff](https://www.lastweekinaws.com/newsletter/aws-discovers-acme-isn-t-just-roadrunner-stuff/)

Issue No.478

### [Open Governance for MySQL: Plot Twist](https://www.lastweekinaws.com/newsletter/open-governance-for-mysql-plot-twist/)

[Read More about Open Governance for MySQL: Plot Twist](https://www.lastweekinaws.com/newsletter/open-governance-for-mysql-plot-twist/)
