AWS News - 2026-07-09

2026-07-09
最終更新: 2026-07-15 04:13:08 JST

AI による概要

22 記事

この日はエージェント運用の統制とセキュリティの将来対応が目立ちました。Claude apps gateway for AWS が発表され、Claude Code と Claude Desktop のアクセス・コスト・ポリシーを単一のセルフホスト型コントロールプレーンで統制できるようになりました。Bedrock AgentCore Runtime を AWS WAF で保護する 2 つのアーキテクチャパターンも示されています。セキュリティブログでは耐量子暗号への移行を CISO 視点で整理した記事と、生成 AI アプリのシステムプロンプト漏洩を前提とした緩和策が公開されました。サービス更新では Aurora DSQL の変更データキャプチャが一般提供となり Kinesis Data Streams への変更ストリーミングが可能に、Security Hub は公開到達可能なリソースを特定する Network Scanning を追加、AWS Config は 191 のマネージドルールを追加しています。国内では井村屋グループが SageMaker Canvas によるチルド製品の需要予測で業務工数 90% 削減を達成した事例が紹介されました。

主要トピック
  • エージェント統制: Claude apps gateway for AWS がアクセス・コスト・ポリシーの単一コントロールプレーンを提供

  • エージェント保護: Bedrock AgentCore Runtime を ALB + AWS WAF と VPC インターフェースエンドポイントで保護する 2 パターン

  • 将来対応: 耐量子暗号 (PQC) 移行の CISO 向けガイドと、システムプロンプト漏洩を前提とした設計・緩和策

  • データ連携: Aurora DSQL の変更データキャプチャ (CDC) が GA、Kinesis Data Streams への変更ストリーミングに対応

  • セキュリティ運用: Security Hub の Network Scanning が公開インターネットから到達可能なリソースを特定

  • ガバナンス: AWS Config が Bedrock・SageMaker・ECS・EKS など主要サービスで 191 のマネージドルールを追加

  • 国内事例: 井村屋グループが SageMaker Canvas によるチルド製品の AI 需要予測で業務工数 90% 削減

AI (Claude Opus 5) が生成 · 2026-08-28 09:24:12 JST

AWS What's New

AWS Neuron 2.31.0 now available with NKI 0.5.0 and UltraServer Operator

AWS Neuron 2.31.0 is now available, introducing NKI 0.5.0 with new MX FP8 scale dtype support, tensor indirection on compute operations for fewer instructions in indexed access patterns, and new NkiTensor view APIs for zero-cost tensor layout transformations. This release also introduces the Neuron UltraServer Operator for Amazon EKS in public beta, automating UltraServer discovery, workload allocation, and resource claim generation for Trainium UltraServer workloads on Amazon EKS.

The Neuron Compiler includes a redesigned code generation backend now enabled by default on Trn2 and Trn3, delivering improved performance. The Neuron Runtime adds contiguous shared scratchpad support, simplifying device configuration by eliminating the need to manually set scratchpad page sizes. The NKI Library adds 14 new experimental kernels covering MoE training collectives, deformable attention, DeepSeek MLA projection, and ring attention, alongside PyTorch reference implementations. Neuron Explorer adds System Trace Viewer source code linking and updated default grouping for improved workload debugging.

To get started, see the following resources:

Amazon Connect Customer now supports forecasting, planning, and scheduling for Tasks and Emails

Amazon Connect Customer now supports forecasting, capacity planning, and scheduling for Tasks and Emails, enabling you to plan and optimize your workforce across all workloads (Voice, Chat, Tasks, Emails). Connect Customer accounts for the unique characteristics of each channel, including concurrent work handling, duration of work from minutes to months, and distinct service level requirements, so your forecasts and schedules reflect how your operation actually runs. For example, if your agents handle email inquiries or tasks such as case processing alongside voice calls, you can now generate a unified forecast that accounts for all of these workloads and create schedules that efficiently allocate agents across channels. Thus enabling end-to-end workforce optimization within a single solution and ensuring consistent service levels across all customer interaction channels.

This feature is available in all AWS Regions where Amazon Connect Customer agent scheduling is available. To learn more about Amazon Connect Customer agent scheduling, click here.

Amazon Aurora DSQL change data capture (CDC) Is now generally available

Amazon Aurora DSQL change data capture (CDC) is now generally available, enabling you to stream real-time database changes to Amazon Kinesis Data Streams for event-driven architectures and data integration workflows.

Aurora DSQL CDC automatically captures the results of insert, update, and delete operations as change events and delivers them to Kinesis Data Streams with no infrastructure to manage. You can use CDC to synchronize data across microservices, trigger AWS Lambda functions, or deliver changes to Amazon S3, Amazon Redshift, and Amazon OpenSearch Service via Amazon Data Firehose. CDC streaming is designed to have zero impact on your database workload performance.

CDC streaming is available in all AWS Regions where Aurora DSQL is available. Get started with Aurora DSQL for free with the AWS Free Tier. To learn more about CDC in Aurora DSQL, visit the documentation page.

Amazon Redshift RG instances now available on the trailing track

Amazon Redshift now supports Graviton-based RG instances on the trailing track. Starting July 7, 2026, rg.4xlarge and rg.xlarge instance types are available for customers running workloads on the trailing track (P201).

The trailing track is designed for customers who prioritize stability for production workloads, running on a version already validated through the leading track. With RG instances now available on both tracks, customers can take advantage of AWS Graviton-powered performance - delivering up to 2.4x faster query performance than RA3 instances at 30% lower price per vCPU.

To get started, customers can provision a new cluster or resize an existing cluster to an rg.4xlarge or rg.xlarge instance type on the trailing track (P201) in the AWS Management Console, AWS CLI, or AWS SDKs.

For more information, see Amazon Redshift cluster versions.

Amazon EC2 M8gd and R8gd instances are now available in additional AWS Regions

Amazon Elastic Compute Cloud (Amazon EC2) M8gd and R8gd instances are available in additional AWS regions. EC2 M8gd and R8gd instances are available in Europe (Paris) and Asia Pacific (Mumbai). Additionally, EC2 R8gd instances are available in Europe (Stockholm, Milan) and Asia Pacific (Osaka, Melbourne, Singapore, Taipei) Regions.

These instances feature up to 11.4 TB of local NVMe-based SSD block-level storage and are powered by AWS Graviton4 processors, delivering up to 30% better performance over Graviton3-based instances. These instances are built on the AWS Nitro System and are a great fit for applications that need access to high-speed, low latency local storage.

Each instance is available in 12 different sizes. They provide up to 50 Gbps of network bandwidth and up to 40 Gbps of bandwidth to the Amazon Elastic Block Store (Amazon EBS). Additionally, customers can now adjust the network and
Amazon EBS bandwidth on these instances by 25% using EC2 instance bandwidth weighting configuration, providing greater flexibility with the allocation of bandwidth resources to better optimize workloads. These instances offer Elastic Fabric Adapter (EFA) networking on 24xlarge, 48xlarge, metal-24xl, and metal-48xl sizes.

To learn more, see M8gd instances or R8gd instances. To explore how to migrate your workloads to Graviton-based instances, see AWS Graviton Fast Start program. To get started, see the AWS Management Console.

AWS Security Hub now offers Network Scanning to identify publicly reachable resources

Today, AWS Security Hub introduces Network Scanning, a capability that identifies resources in your environment that are reachable from the public internet.  Network Scanning probes your resources from the internet to detect actual reachability, not just what could be reachable based on security group rules and route tables. It discovers public IP addresses, virtual machines, and load balancers across your AWS and Azure environments, identifies reachable ports, and determines what services are running behind them. This complements Security Hub’s existing network reachability findings, which identify configurations that could make a resource reachable from the internet.  Network Scanning confirms actual reachability from the internet. Each reachable port generates a Security Hub finding with evidence of the port and service discovered. Security Hub Exposures then automatically correlates these findings with other findings and resource configurations to determine broader risk.

Amazon SageMaker Unified Studio Workflows now supports operators for Amazon Bedrock, S3 Tables, S3 Vectors, and Glue Catalog

Amazon SageMaker Unified Studio Workflows now supports 19 new operators for Amazon Bedrock, Amazon S3 Tables, Amazon S3 Vectors, AWS Glue Data Catalog, and Amazon MWAA Serverless. With these operators, customers can add new tasks using the visual workflow creator to orchestrate these services without writing custom integration code.
With this launch, data workers and builders can create workflows that manage Bedrock guardrails, provision and delete S3 Tables and S3 Vectors resources, manage Glue Data Catalog tables and databases, and trigger MWAA Serverless workflow runs. This expands the breadth of AWS services you can orchestrate from SageMaker Unified Studio Workflows, reducing the need to switch between consoles or write custom DAG code.
This feature is available in all AWS Regions where Amazon SageMaker Unified Studio is available. For more information, see the AWS Region table.
To learn more, see Supported operators for Amazon MWAA Serverless workflows. To get started, see Serverless visual workflows in the Amazon SageMaker Unified Studio User Guide.

AWS Builder Center Now Offers Free Sandbox Environments

AWS Builder Center now lets builders request free, time-limited sandbox environments directly from eligible workshops, eliminating the need for a personal AWS account, credit card, or concerns about unexpected charges. Previously, workshops could only be completed using a builder's own AWS account. With sandbox environments, builders of all skill levels can safely deploy resources, write code, and experiment in a pre-provisioned AWS account.

Free sandbox environments are ideal for builders who want to gain practical AWS experience without setting up an account. Each sandbox provides 8 hours of access from activation, with automatic cleanup afterward. Builders can request one sandbox per week (resetting every Sunday), and most environments are ready within 15 minutes. Sandboxes are available for select workshops at launch, with more being enabled over time.

To get started, visit Workshops on AWS Builder Center.

AWS Config now supports 191 additional managed rules

詳細を表示

AWS Config now supports 191 additional managed rules across key services including Amazon Bedrock, Amazon SageMaker, Amazon ECS, Amazon EKS, Amazon RDS, Amazon Redshift, Amazon S3, and Amazon CloudTrail. This expansion increases built-in governance coverage across AI workloads and core cloud infrastructure. Examples of the new managed rules include evaluating resource configurations for encryption, logging, public access, network security, data protection, and other operational best practices across AWS services. 

With this launch, you can deploy these new managed rules individually or as part of a conformance pack in the AWS Regions where the corresponding AWS services are available. 

 

AWS Certificate Manager 

  • ACM_CERTIFICATE_RSA_CHECK  

Amazon API Gateway 

  • API_GWV2_ACCESS_LOGS_ENABLED  

AWS AppSync 

  • APPSYNC_AUTHORIZATION_CHECK  

  • APPSYNC_LOGGING_ENABLED  

Amazon Athena 

  • ATHENA_WORKGROUP_ENCRYPTED_AT_REST  

  • ATHENA_WORKGROUP_LOGGING_ENABLED  

Amazon Aurora 

  • AURORA_MYSQL_CLUSTER_AUDIT_LOGGING  

Amazon Bedrock 

  • BEDROCKAGENTCORE_BROWSERCUSTOM_NETWORK_MODE_NOT_PUBLIC  

  • BEDROCKAGENTCORE_BROWSERCUSTOM_RECORDING_ENABLED  

  • BEDROCKAGENTCORE_CODEINTERPRETER_NETWORKMODE_CHECK  

  • BEDROCKAGENTCORE_GATEWAY_AUTHORIZER_ENABLED  

  • BEDROCKAGENTCORE_GATEWAY_ENCRYPTION_ENABLED  

  • BEDROCKAGENTCORE_RUNTIME_PRIVATE_NETWORK_REQUIRED  

  • BEDROCK_AGENTCORE_MEMORY_ENCRYPTION_ENABLED  

  • BEDROCK_AGENTCORE_MEMORY_EVENT_EXPIRY_DURATION  

  • BEDROCK_DATA_SOURCE_ENCRYPTION_ENABLED  

AWS CloudFormation 

  • CLOUDFORMATION_STACK_SERVICE_ROLE_CHECK  

  • CLOUDFORMATION_TERMINATION_PROTECTION_CHECK  

AWS CloudTrail 

  • CLOUDTRAIL_ALL_READ_S3_DATA_EVENT_CHECK  

  • CLOUDTRAIL_ALL_WRITE_S3_DATA_EVENT_CHECK  

  • CLOUDTRAIL_S3_BUCKET_ACCESS_LOGGING  

  • CLOUDTRAIL_S3_BUCKET_PUBLIC_ACCESS_PROHIBITED  

  • EVENT_DATA_STORE_CMK_ENCRYPTION_ENABLED  

Amazon CloudWatch 

  • CLOUDWATCH_ALARM_ACTION_ENABLED_CHECK  

Amazon Cognito 

  • COGNITO_IDENTITY_POOL_UNAUTH_ACCESS_CHECK  

  • COGNITO_USERPOOL_CUST_AUTH_THREAT_FULL_CHECK  

  • COGNITO_USER_POOL_ADVANCED_SECURITY_ENABLED  

  • COGNITO_USER_POOL_MFA_ENABLED  

  • COGNITO_USER_POOL_PASSWORD_POLICY_CHECK  

AWS CodeBuild 

  • CODEBUILD_PROJECT_ARTIFACT_ENCRYPTION  

  • CODEBUILD_PROJECT_ENVIRONMENT_PRIVILEGED_CHECK  

  • CODEBUILD_PROJECT_LOGGING_ENABLED  

  • CODEBUILD_PROJECT_S3_LOGS_ENCRYPTED  

AWS DataSync 

  • DATASYNC_TASK_LOGGING_ENABLED  

AWS Database Migration Service (DMS) 

  • DMS_REPLICATION_TASK_SOURCEDB_LOGGING  

  • DMS_REPLICATION_TASK_TARGETDB_LOGGING  

Amazon DocumentDB 

  • DOCDB_CLUSTER_AUDIT_LOGGING_ENABLED  

  • DOCDB_CLUSTER_DELETION_PROTECTION_ENABLED  

  • DOCDB_CLUSTER_ENCRYPTED_IN_TRANSIT  

  • DOCDB_CLUSTER_SNAPSHOT_PUBLIC_PROHIBITED  

Amazon DynamoDB 

  • DYNAMODB_TABLE_DELETION_PROTECTION_ENABLED  

Amazon EC2 

  • EC2_ENIS_SOURCE_DESTINATION_CHECK_ENABLED  

  • EC2_INSTANCE_LAUNCHED_WITH_ALLOWED_AMI  

  • EC2_LAUNCH_TEMPLATES_EBS_VOLUME_ENCRYPTED  

  • EC2_LAUNCH_TEMPLATE_IMDSV2_CHECK  

  • EC2_LAUNCH_TEMPLATE_PUBLIC_IP_DISABLED  

  • EC2_SECURITY_GROUP_ATTACHED_TO_ENI  

  • EC2_SPOT_FLEET_REQUEST_CT_ENCRYPTION_AT_REST  

  • EC2_STOPPED_INSTANCE_DAYS_CHECK_PVT  

  • EC2_TRANSIT_GATEWAY_AUTO_VPC_ATTACH_DISABLED  

  • EC2_VPN_CONNECTION_IKE_VERSION_CHECK  

  • EC2_VPN_CONNECTION_LOGGING_ENABLED  

  • INSTANCES_IN_VPC  

Amazon EC2 Auto Scaling 

  • AUTOSCALING_LAUNCH_TEMPLATE  

  • AUTOSCALING_MULTIPLE_AZ  

  • AUTOSCALING_MULTIPLE_INSTANCE_TYPES  

Amazon ECR 

  • ECR_PRIVATE_IMAGE_SCANNING_ENABLED  

  • ECR_PRIVATE_LIFECYCLE_POLICY_CONFIGURED  

  • ECR_PRIVATE_TAG_IMMUTABILITY_ENABLED  

  • ECR_REPOSITORY_CMK_ENCRYPTION_ENABLED  

Amazon ECS 

  • ECS_CONTAINERS_NONPRIVILEGED  

  • ECS_CONTAINERS_READONLY_ACCESS  

  • ECS_CONTAINER_INSIGHTS_ENABLED  

  • ECS_FARGATE_LATEST_PLATFORM_VERSION  

  • ECS_NO_ENVIRONMENT_SECRETS  

  • ECS_TASK_DEFINITION_EFS_ENCRYPTION_ENABLED  

  • ECS_TASK_DEFINITION_LINUX_USER_NON_ROOT  

  • ECS_TASK_DEFINITION_LOG_CONFIGURATION  

  • ECS_TASK_DEFINITION_NETWORK_MODE_NOT_HOST  

  • ECS_TASK_DEFINITION_PID_MODE_CHECK  

  • ECS_TASK_DEFINITION_USER_FOR_HOST_MODE_CHECK  

  • ECS_TASK_DEFINITION_WINDOWS_USER_NON_ADMIN  

Amazon EFS 

  • EFS_ACCESS_POINT_ENFORCE_ROOT_DIRECTORY  

  • EFS_ACCESS_POINT_ENFORCE_USER_IDENTITY  

  • EFS_AUTOMATIC_BACKUPS_ENABLED  

  • EFS_FILESYSTEM_CT_ENCRYPTED  

  • EFS_MOUNT_TARGET_PUBLIC_ACCESSIBLE  

Amazon EKS 

  • EKS_NODEGROUP_SUPPORTED_VERSION_CHECK  

AWS Elastic Beanstalk  

  • BEANSTALK_ENHANCED_HEALTH_REPORTING_ENABLED 

Amazon ElastiCache 

  • ELASTICACHE_AUTOMATIC_BACKUP_CHECK_ENABLED  

  • ELASTICACHE_AUTO_MINOR_VERSION_UPGRADE_CHECK  

  • ELASTICACHE_REPL_GRP_AUTO_FAILOVER_ENABLED  

  • ELASTICACHE_REPL_GRP_ENCRYPTED_AT_REST  

  • ELASTICACHE_SUBNET_GROUP_CHECK  

  • ELASTICACHE_SUPPORTED_ENGINE_VERSION  

Elastic Load Balancing 

  • ALB_DESYNC_MODE_CHECK  

  • CLB_DESYNC_MODE_CHECK  

  • CLB_MULTIPLE_AZ  

  • ELBV2_LISTENER_ENCRYPTION_IN_TRANSIT  

  • ELBV2_MULTIPLE_AZ  

  • ELBV2_PREDEFINED_SECURITY_POLICY_SSL_CHECK  

  • NLB_CROSS_ZONE_LOAD_BALANCING_ENABLED  

Amazon EMR 

  • EMR_BLOCK_PUBLIC_ACCESS  

Amazon EventBridge 

  • CUSTOM_EVENTBUS_POLICY_ATTACHED  

Amazon FSx 

  • FSX_LUSTRE_COPY_TAGS_TO_BACKUPS  

  • FSX_OPENZFS_COPY_TAGS_ENABLED  

  • FSX_OPENZFS_DEPLOYMENT_TYPE_CHECK  

  • FSX_WINDOWS_AUDIT_LOG_CONFIGURED  

  • FSX_WINDOWS_DEPLOYMENT_TYPE_CHECK  

AWS Glue 

  • GLUE_ML_TRANSFORM_ENCRYPTED_AT_REST  

Amazon GuardDuty 

  • GUARDDUTY_ECS_PROTECTION_RUNTIME_ENABLED  

  • GUARDDUTY_EKS_PROTECTION_AUDIT_ENABLED  

  • GUARDDUTY_LAMBDA_PROTECTION_ENABLED  

  • GUARDDUTY_MALWARE_PROTECTION_ENABLED  

  • GUARDDUTY_RUNTIME_MONITORING_ENABLED  

  • GUARDDUTY_S3_PROTECTION_ENABLED  

IAM 

  • IAM_EXTERNAL_ACCESS_ANALYZER_ENABLED  

  • IAM_SERVER_CERTIFICATE_EXPIRATION_CHECK  

Amazon Kendra 

  • KENDRA_INDEX_TAGGED  

Amazon Kinesis 

  • KINESIS_FIREHOSE_DELIVERY_STREAM_ENCRYPTED  

  • KINESIS_STREAM_BACKUP_RETENTION_CHECK  

  • KINESIS_STREAM_ENCRYPTED  

AWS KMS 

  • KMS_KEY_POLICY_NO_PUBLIC_ACCESS  

AWS Lambda 

  • LAMBDA_FUNCTION_XRAY_ENABLED  

  • LAMBDA_VPC_MULTI_AZ_CHECK  

Amazon Neptune 

  • NEPTUNE_CLUSTER_BACKUP_RETENTION_CHECK  

  • NEPTUNE_CLUSTER_COPY_TAGS_TO_SNAPSHOT_ENABLED  

  • NEPTUNE_CLUSTER_DELETION_PROTECTION_ENABLED  

  • NEPTUNE_CLUSTER_ENCRYPTED  

  • NEPTUNE_CLUSTER_IAM_DATABASE_AUTHENTICATION  

  • NEPTUNE_CLUSTER_MULTI_AZ_ENABLED  

  • NEPTUNE_CLUSTER_SNAPSHOT_ENCRYPTED  

  • NEPTUNE_CLUSTER_SNAPSHOT_PUBLIC_PROHIBITED  

AWS Network Firewall 

  • NETFW_LOGGING_ENABLED  

  • NETFW_SUBNET_CHANGE_PROTECTION_ENABLED  

Amazon OpenSearch Service 

  • OPENSEARCH_ENCRYPTED_AT_REST  

  • OPENSEARCH_HTTPS_REQUIRED  

  • OPENSEARCH_NODE_TO_NODE_ENCRYPTION_CHECK  

Amazon RDS 

  • MARIADB_PUBLISH_LOGS_TO_CLOUDWATCH_LOGS  

  • RDS_AURORA_MYSQL_AUDIT_LOGGING_ENABLED  

  • RDS_AURORA_POSTGRESQL_LOGS_TO_CLOUDWATCH  

  • RDS_CLUSTER_DEFAULT_ADMIN_CHECK  

  • RDS_CLUSTER_ENCRYPTED_AT_REST  

  • RDS_GLOBAL_CLUSTER_AURORA_POSTGRESQL_SUPPORTED_VERSION  

  • RDS_INSTANCE_DEFAULT_ADMIN_CHECK  

  • RDS_INSTANCE_SUBNET_IGW_CHECK  

  • RDS_MARIADB_INSTANCE_ENCRYPTED_IN_TRANSIT  

  • RDS_MYSQL_INSTANCE_ENCRYPTED_IN_TRANSIT  

  • RDS_PGSQL_CLUSTER_COPY_TAGS_TO_SNAPSHOT_CHECK  

  • RDS_POSTGRESQL_LOGS_TO_CLOUDWATCH  

  • RDS_POSTGRES_INSTANCE_ENCRYPTED_IN_TRANSIT  

  • RDS_PROXY_TLS_ENCRYPTION  

  • RDS_SNAPSHOT_ENCRYPTED 

  • RDS_SQLSERVER_ENCRYPTED_IN_TRANSIT  

  • RDS_SQL_SERVER_LOGS_TO_CLOUDWATCH  

Amazon Redshift 

  • REDSHIFT_CLUSTER_MULTI_AZ_ENABLED  

  • REDSHIFT_CLUSTER_SUBNET_GROUP_MULTI_AZ  

  • REDSHIFT_DEFAULT_ADMIN_CHECK  

  • REDSHIFT_SERVERLESS_DEFAULT_ADMIN_CHECK  

  • REDSHIFT_SERVERLESS_NAMESPACE_CMK_ENCRYPTION  

  • REDSHIFT_SERVERLESS_PUBLISH_LOGS_TO_CLOUDWATCH  

  • REDSHIFT_SERVERLESS_WORKGROUP_ENCRYPTED_IN_TRANSIT  

  • REDSHIFT_SERVERLESS_WORKGROUP_NO_PUBLIC_ACCESS  

  • REDSHIFT_SERVERLESS_WORKGROUP_ROUTES_WITHIN_VPC  

  • REDSHIFT_UNRESTRICTED_PORT_ACCESS  

Amazon S3 

  • S3_ACCESS_POINT_IN_VPC_ONLY  

  • S3_ACCESS_POINT_PUBLIC_ACCESS_BLOCKS  

  • S3_BUCKET_ACL_PROHIBITED  

  • S3_BUCKET_CROSS_REGION_REPLICATION_ENABLED  

  • S3_BUCKET_MFA_DELETE_ENABLED  

  • S3_EVENT_NOTIFICATIONS_ENABLED  

  • S3_LIFECYCLE_POLICY_CHECK  

  • S3_VERSION_LIFECYCLE_POLICY_CHECK  

Amazon SageMaker 

  • SAGEMAKER_ENDPOINT_CONFIG_KMS_KEY_REQUIRED  

  • SAGEMAKER_FEATUREGROUP_ENCRYPTION_AT_REST  

  • SAGEMAKER_FEATUREGROUP_ONLINE_STORE_ENCRYPTION  

  • SAGEMAKER_INF_EXPERIMENT_DATA_STORAGE_KMS_ENCRYPTED  

  • SAGEMAKER_INF_EXPERIMENT_INSTANCE_STORAGE_KMS_ENCRYPTED  

  • SAGEMAKER_MODEL_EXPLAINABILITY_JOB_NETWORK_ISOLATION  

  • SAGEMAKER_MODEL_MULTICONTAINER_PRIVATE_REGISTRY  

  • SAGEMAKER_MODEL_PRIVATE_REGISTRY_REQUIRED  

  • SAGEMAKER_MODEL_QUALITY_JOB_DEFINITION_ISOLATION  

  • SAGEMAKER_MONITORING_SCHEDULE_TRAFFIC_ENCRYPTION  

  • SAGEMAKER_NOTEBOOK_INSTANCE_INSIDE_VPC  

  • SAGEMAKER_NOTEBOOK_INSTANCE_ROOT_ACCESS_CHECK  

  • SAGEMAKER_NOTEBOOK_INSTANCE_STORAGE_VOL_KMS_ENCRYPTED  

AWS Account Management 

  • SECURITY_ACCOUNT_INFORMATION_PROVIDED  

Amazon SNS 

  • SNS_TOPIC_MESSAGE_DELIVERY_NOTIFICATION_ENABLED  

  • SNS_TOPIC_NO_PUBLIC_ACCESS  

Amazon SQS 

  • SQS_QUEUE_DLQ_CHECK  

  • SQS_QUEUE_NO_PUBLIC_ACCESS  

  • SQS_QUEUE_POLICY_FULL_ACCESS_CHECK  

AWS Systems Manager 

  • SSM_AUTOMATION_BLOCK_PUBLIC_SHARING  

  • SSM_AUTOMATION_LOGGING_ENABLED  

AWS Transfer Family 

  • TRANSFER_CONNECTOR_LOGGING_ENABLED  

Amazon VPC 

  • NACL_NO_UNRESTRICTED_SSH_RDP  

  • VPC_ENDPOINT_ENABLED  

  • VPC_PEERING_DNS_RESOLUTION_CHECK  

  • VPC_SG_PORT_RESTRICTION_CHECK  

AWS WAF 

  • WAFV2_RULEGROUP_LOGGING_ENABLED  

  • WAFV2_WEBACL_NOT_EMPTY 

AWS Japan Blog

Amazon EVS への VCF 9.1 エンドツーエンド自動化デプロイ

Amazon EVS のセルフデプロイモードで VCF 9.1 を自動デプロイする 3 フェーズの自動化ツールキットを解説します。Terraform で AWS 基盤を構築し、Python (boto3) で EVS 環境とベアメタルホストをプロビジョニングし、VCF Python SDK で VCF bringup から NSX Edge Cluster 設定までを完全自動化します。

Amazon Bedrock のゼロデータ保持の強制方法

本記事では、Amazon Bedrock のデータ保持モード (none、default、inherit、provider_data_share) の仕組みと、設定したモードが保持の上限として機能する動作を解説します。Amazon Bedrock Projects による保持要件が異なるワークロードの分離、サービスコントロールポリシー (SCP) を使用して組織全体でモデルプロバイダーとのデータ共有を防止しゼロデータ保持を強制する方法、クロスリージョン推論プロファイルとの相互作用、AWS CLI や API による設定の検証手順を紹介します。

AWS Weekly Roundup: AWS での Claude Sonnet 5、AI エージェント向けの Amazon WorkSpaces、AWS サービスの可用性アップデートなど (2026 年 7 月 6 日)

数回前の号で、スタートアップと仕事をすることがどれほど活力になるかについて書きました。2026 年 6 月 2 […]

井村屋グループ様:Amazon SageMaker Canvas を活用したチルド製品の AI 需要予測で、業務工数 90% 削減と熟練者同等の予測精度を実現

本ブログは井村屋グループ株式会社様、株式会社 Hashup 様、Amazon Web Services Jap […]

AWS Security Blog

The CISO’s guide to post-quantum mandates and migrations

Over a dozen major economies have now published post-quantum cryptography (PQC) adoption guidance. As a CISO, you’re probably well into your migration plan and know the most difficult part has little to do with changing algorithms. The real leadership challenge is driving coordinated change across a large, complex organization where asymmetric cryptography is embedded in […]

Designing for the inevitable: System prompt leakage and mitigations in generative AI applications

System prompts form the foundation of generative AI applications. A system prompt is a collection of instructions and operational context provided to a large language model (LLM) that shapes how the model behaves and interacts with users and tools. System prompts often contain proprietary information, including role definitions, behavioral guidelines, tool descriptions and usage instructions, […]

AWS Machine Learning Blog

Manage AI applications on Mac with Jamf’s AI Governance and Amazon Bedrock

In this post, we show how you can use Jamf’s AI Governance with Amazon Bedrock to configure, deploy, and validate managed settings for AI applications across a Mac fleet.

Securing Amazon Bedrock AgentCore Runtime with AWS WAF

This post shows you two architecture patterns that address this problem. Both use an internet-facing ALB with AWS WAF and route traffic through a VPC Interface Endpoint to AgentCore Runtime. Pattern 1 places an AWS Lambda proxy between the ALB and the VPC Endpoint, giving you full control over request transformation. Pattern 2 targets the VPC Endpoint ENI IP addresses directly from the ALB, removing the Lambda hop entirely. You also learn how to close the direct-access backdoor with a resource policy so that traffic flows through AWS WAF only. Both patterns have been tested end-to-end with SigV4 and OAuth (Amazon Cognito JWT) authentication.

Building and connecting a production-ready ecommerce MCP server using Amazon Bedrock AgentCore and Mistral AI Studio

In this post, you build and connect that server end to end. You will implement MCP tools, set up two-layer JSON Web Token (JWT) authentication, deploy with AWS Cloud Development Kit (AWS CDK), and connect the result to Mistral AI’s Vibe. The post also covers prerequisites, solution architecture, best practices for MCP servers and Vibe connectors, and resource cleanup. The ecommerce server that you build supports product search, order placement, review submission, and returns processing using Amazon DynamoDB for data and Amazon Cognito for identity management.

Automatically sort and prioritize your mailboxes by using Amazon Bedrock

In this post, we show how organizations in the public sector can automate their email management using a generative AI solution powered by Amazon Bedrock.

Powering scientific discovery: BYOKG and GraphRAG for intelligent pharmaceutical research

In this post, we explore how Graph-based Retrieval Augmented Generation (GraphRAG) is transforming scientific research by combining graph databases with generative AI. With this approach, you can accelerate discovery processes without compromising scientific integrity.

Introducing Claude apps gateway for AWS

Today, we're announcing the Claude apps gateway for AWS, a self-hosted control plane that gives organizations a single point of control over access, cost, and policy for Claude Code and Claude Desktop. In this post, we show how to set up and run Claude apps gateway for AWS with Amazon Bedrock and Claude Platform on AWS.

AWS Compute Blog

Accelerate multiplayer game hosting with AWS m8azn instances

Online multiplayer gaming continues to grow, with players demanding lower latency, higher concurrency, and more immersive experiences than ever before. For game studios hosting dedicated multiplayer servers on AWS, infrastructure decisions directly impact player experience and retention, server tick rates, and ultimately, revenue. Games are becoming more computationally demanding while offering richer gameplay experiences. Studios […]