AWS News - 2026-08-11

2026-08-11
最終更新: 2026-08-20 08:18:27 JST

AI による概要

21 記事

この日は開発者ワークフローへのセキュリティ統合が目立ちました。AWS が Anthropic および OpenAI と協業し、AWS Continuum for code vulnerabilities がプレビューとして Claude Code・Codex・Kiro の開発者ワークフローへ直接統合され、既存のワークフローの中で脆弱性を発見できるようになりました。SageMaker JumpStart には GLM-5.2 FP8、Nemotron-Nano-12B-v2、GLM-OCR、Mellum2、LightOnOCR-2-1B、FLUX.2-small-decoder、gemma-4-12B-it と多数のモデルが追加されています。ストリーミングでは Amazon MSK が Apache ZooKeeper から KRaft へのインプレース移行に対応しました。EC2 にはアプリケーションレベルの問題を検知するアプリケーションステータスチェックが追加され、IAM には workforce ユーザーへの IAM ロール割り当てを効率化する account access manager が登場しています。コンプライアンスでは 2026 年の CyberVadis 評価を最高スコアで完了し、ロンドンリージョンが PASF 認定を更新しました。

主要トピック
  • セキュリティ統合: AWS Continuum for code vulnerabilities が Claude Code・Codex・Kiro のワークフローに直接統合 (プレビュー)

  • モデル拡充: SageMaker JumpStart に GLM-5.2 FP8、Nemotron-Nano-12B-v2、GLM-OCR、Mellum2、LightOnOCR、FLUX.2 など多数追加

  • ストリーミング: Amazon MSK が ZooKeeper から KRaft へのインプレース移行をサポート

  • EC2 運用: アプリケーションレベルの問題を検知するアプリケーションステータスチェックを追加

  • IAM: account access manager により workforce ユーザーへの IAM ロール割り当てを効率化

  • コンプライアンス: 2026 CyberVadis 評価を最高スコアで完了、ロンドンリージョンが PASF 認定を更新

  • 事例: nOps が Clara FinOps エージェントを AgentCore へ移行し 75% 速く出荷

AI (Claude Opus 5) が生成 · 2026-08-28 09:29:54 JST

AWS What's New

Amazon OpenSearch Serverless now supports up to 10,000 collections per collection group

The next generation of Amazon OpenSearch Serverless now supports up to 10,000 collections within a single collection group, increased from the previous limit of 1,500. Collection groups organize multiple collections and enable them to share OpenSearch Compute Units (OCUs), even when the collections are encrypted with different AWS KMS keys. With this higher limit, you can consolidate significantly more collections into a single collection group and manage them under a shared set of capacity limits.

Customers use collection groups to reduce costs by sharing compute across many collections rather than provisioning separate OCUs for each KMS key, while still maintaining collection-level security and access controls. As customer workloads have grown, particularly for multi-tenant applications that provision a collection per tenant, the previous limit of 1,500 collections per group constrained how many tenants could benefit from a shared compute pool. Raising the limit to 10,000 collections on the next generation of Amazon OpenSearch Serverless lets you scale these workloads further, improve compute utilization, and lower per-collection cost, without creating and operating additional collection groups. The higher limit applies automatically to new and existing nextgen collection groups.

The increased limit is available on the next generation of Amazon OpenSearch Serverless in all AWS Regions where it is available. To learn more, see Amazon OpenSearch Serverless technical documentation and quotas.

 

Amazon MSK now supports in-place migration from Apache ZooKeeper to KRaft

Amazon Managed Streaming for Apache Kafka (Amazon MSK) now supports in-place migration from Apache ZooKeeper to KRaft, enabling customers to migrate existing clusters to KRaft without provisioning new infrastructure, migrating data, or reconfiguring client applications.

KRaft is Apache Kafka's consensus protocol that eliminates the dependency on Apache ZooKeeper for metadata management. KRaft shifts metadata management from external ZooKeeper nodes to a group of controllers within Kafka itself, allowing metadata to be stored and replicated as topics within Kafka brokers, resulting in faster metadata propagation, improved scalability, and a simplified cluster architecture. Kafka 3.9.x is the last version to support ZooKeeper, and Kafka 4.x only supports KRaft. This in-place migration gives customers an easy path to move to KRaft on their existing clusters and upgrade to Kafka 4.x.

To get started, customers first upgrade to Kafka 3.9.x if they are on an older version, then customers can initiate the migration and the cluster remains available throughout the process. All steps can be performed through the MSK console, AWS CLI, or APIs. The in-place migration from Apache Zookeeper to Kraft is available today across all AWS regions where Amazon MSK provisioned is offered except European Sovereign Cloud (Germany). To learn how to get started, see the Amazon MSK Developer Guide.

Amazon EC2 introduces application status checks

Amazon EC2 introduces application status checks, a new status check that helps customers detect and respond to application-level issues on their EC2 instances. With application status checks, EC2 monitors applications to detect issues such as a web server that has stopped accepting requests, a Docker daemon that is not running, an incorrect networking configuration, or a network interface that is no longer passing traffic.

Customers rely on EC2 status checks today to receive alerts when an instance or the underlying system is unreachable. However, to monitor application issues, customers had to build and maintain their own monitoring solution. Now, with application status checks customers can monitor the status of their applications running on EC2 instances alongside existing EC2 instance and system status checks. Customers create a check by specifying the protocol, port, and path to monitor, along with the response codes that indicate a healthy application. After customers associate the check with their instances by instance ID or tag, Amazon EC2 sends HTTP or HTTPS requests to that port and path and reports on the application’s status every 60 seconds. Auto Scaling groups act on application status, initiating recovery by replacing instances when their applications report unhealthy.

Application status checks are available in all commercial AWS Regions and AWS GovCloud (US) Regions.

To get started with application status checks and review pricing, see the Amazon EC2 User Guide.

AWS Identity and Access Management streamlines assignment of IAM roles to workforce users with account access manager

AWS Identity and Access Management (IAM) launched account access manager, a feature that streamlines assignment of IAM roles to workforce users. Administrators use account access manager to assign the IAM roles in their AWS accounts to the workforce users and groups in AWS IAM Identity Center. The feature brings together permissions management flexibility, user awareness, and a single point of federation. It is accessible through the AWS IAM console, the AWS SDK, and CloudFormation/CDK.

Previously, customers granting workforce access to AWS accounts could use one of two alternative access management approaches. They could federate users separately into each AWS account and define user permissions narrowly using the IAM roles in each AWS account. Alternatively, they could federate users once through IAM Identity Center, and tailor and manage their access centrally by adjusting and provisioning AWS managed permission sets. The newly released account access manager offers a solution for customers who want the single federation point and user awareness of IAM Identity Center together with the flexibility of IAM roles. 

Account access manager is provided at no additional cost and available in all AWS Commercial Regions enabled by default. To learn more and get started, visit the AWS Identity and Access Management User Guide.

AWS Marketplace now supports category-based notification subscriptions and multi-channel delivery for buyers

詳細を表示

AWS Marketplace buyers can now configure category-based notifications and multi-channel delivery through AWS User Notifications. Previously, buyer email notifications were limited to the AWS account root email with no way to choose which categories you received or route them to different teams. This meant teams responsible for procurement, renewals, or cost management either missed critical notifications or had to rely on email forwarding. With this launch, buyers can choose which notification categories they receive and how they're delivered.

Four notification categories are available. Products and Solutions notifications cover product version updates, instance type changes, and availability restrictions. Agreements and Subscriptions notifications cover agreement lifecycle events including starts, cancellations, renewals, and payment failures. Private Offers notifications cover new private offers and acceptance confirmations. Pricing Changes notifications cover hourly, monthly, and usage-based price increases for products you subscribe to. By default, all categories are enabled and delivered via email to the account's root address. You can add more recipients, through additional email addresses, distribution lists, the AWS Console Mobile Application, or team channels in Slack and Microsoft Teams, and tailor each to receive only the notification categories relevant to their role. In January 2027, AWS Marketplace will automatically enable these category and delivery controls for all customers. Your existing notifications will continue unchanged. Opt in now to start customizing sooner.

To learn more, see  AWS Marketplace buyer notifications  in the AWS Marketplace Buyer Guide. To enable managed notifications, visit the  AWS User Notifications console .

AWS Marketplace managed buyer notifications are available in all AWS Commercial Regions where AWS Marketplace is available.

 

Amazon GameLift Streams Now Offers Service-managed Shader Caching

Amazon GameLift Streams now manages shader cache capture and distribution for your applications. You capture a shader cache from a stream session, and the service automatically makes it available for future sessions across your streaming locations. No application changes are required.

Capturing shader caches can help reduce loading times and visual stuttering, during the session. With service-managed shader caching, you designate a stream session for capture and run your application to generate the cache. Amazon GameLift Streams then replicates the cache to compatible stream groups and locations, and loads it automatically in future sessions.

You can monitor shader cache status and storage size using the ListApplicationShaderCaches API or the Amazon GameLift Streams console. The feature supports Linux (Ubuntu 22.04), Proton, and Windows Server 2022 runtimes.

You are charged for storage of the latest version of each shader cache. For pricing details, visit the Amazon GameLift Streams pricing page. For supported Regions, see the AWS Region table.

Amazon EC2 High Memory U7i instances now available in AWS South America (São Paulo) region

Amazon EC2 High Memory U7in-24TB instances (u7in-24tb.224xlarge) are now available in AWS South America (São Paulo) region. U7i instances are part of the AWS 7th generation and are powered by custom fourth-generation Intel Xeon Scalable processors (Sapphire Rapids). U7in-24TB instances offer 24 TiB of DDR5 memory, enabling customers to scale transaction processing throughput in a fast-growing data environment.

U7in-24TB instances deliver 896 vCPUs and support up to 100 Gbps of Amazon EBS bandwidth for faster data loading and backups, 200 Gbps of network bandwidth, and ENA Express. U7i instances are ideal for customers running mission-critical in-memory databases like SAP HANA, Oracle, and SQL Server.

To learn more about U7i instances, visit the High Memory instances page.

GLM-5.2 FP8, NVIDIA-Nemotron-Nano-12B-v2 and GLM-OCR models now available on Amazon SageMaker JumpStart

詳細を表示

Z.ai's GLM-5.2 FP8, NVIDIA's Nemotron-Nano-12B-v2, and Z.ai's GLM-OCR models are now available on Amazon SageMaker JumpStart, expanding the portfolio of foundation models available to AWS customers. These three models bring specialized capabilities spanning long-horizon agentic engineering, efficient hybrid reasoning, and advanced document understanding, enabling customers to deploy high-performance, scalable AI solutions on AWS infrastructure.

GLM-5.2 FP8 is optimized for long-horizon tasks and agentic engineering workflows such as full-cycle software development from requirements to deployment. It delivers a substantial leap in long-horizon task capability over its predecessor GLM-5.1 and, for the first time, provides a truly usable 1M-token context window, enabling it to handle project-level engineering context, execute long-running tasks reliably, follow engineering standards consistently, and complete full development workflows in a single task.

NVIDIA-Nemotron-Nano-12B-v2 excels in unified reasoning and non-reasoning tasks with high inference throughput, making it ideal for enterprise applications requiring both accuracy and efficiency. It uses a hybrid Mamba-2 and Transformer architecture with a 128K context length, generating reasoning traces before concluding with final responses. Its compact 12B parameter design achieves comparable or better accuracy than leading open models while delivering up to 6x higher inference throughput.

GLM-OCR provides accurate, fast, and comprehensive document understanding for complex real-world materials including scanned PDFs, handwritten notes, dense academic papers with formulas, multi-column tables, code documentation, and multilingual text. This 0.9B-parameter multimodal model reconstructs structure, tables, and formulas into clean Markdown, JSON, or LaTeX, with latency low enough for real-time services and edge devices—ideal for large-scale document processing and invoice extraction workflows.

With SageMaker JumpStart, customers can deploy any of these models with just a few clicks to address their specific AI use cases.

To get started with these models, navigate to the SageMaker JumpStart model catalog in the SageMaker console or use the SageMaker Python SDK to deploy the models to your AWS account. For more information about deploying and using foundation models in SageMaker JumpStart, see the Amazon SageMaker JumpStart documentation.

langcache-embed-v3-small, Mellum2-12B-A2.5B-Thinking, and LightOnOCR-2-1B models now available on Amazon SageMaker JumpStart

詳細を表示

Redis's langcache-embed-v3-small, JetBrains' Mellum2-12B-A2.5B-Thinking, and LightOn's LightOnOCR-2-1B models are now available on Amazon SageMaker JumpStart, expanding the portfolio of foundation models available to AWS customers. These three models bring specialized capabilities spanning semantic caching optimization, code-focused reasoning, and end-to-end document OCR, enabling customers to deploy high-performance, scalable AI solutions on AWS infrastructure.

langcache-embed-v3-small is optimized for semantic caching in LLM applications. It maps sentences and paragraphs into a dense vector space purpose-built for identifying semantically equivalent queries regardless of phrasing, enabling intelligent cache hits that reduce redundant LLM calls and accelerate response times in high-volume inference workloads.

Mellum2-12B-A2.5B-Thinking excels in code generation, debugging, multi-step reasoning, and agentic coding workflows. It uses a Mixture-of-Experts architecture (64 experts, 8 activated per token), activating only 2.5B of its 12B total parameters per forward pass with a 131,072-token context length. It emits explicit chain-of-thought reasoning traces before final answers, delivering high-throughput, low-latency inference ideal for routing, RAG, sub-agents, and private deployments.

LightOnOCR-2-1B provides end-to-end multilingual document-to-text conversion for PDFs, scans, and images without brittle OCR pipelines. This 1B-parameter vision-language model directly transduces page images into clean, naturally ordered text, achieving state-of-the-art performance on OlmOCR-Bench while being ~9× smaller and significantly faster than competing approaches.

With SageMaker JumpStart, customers can deploy any of these models with just a few clicks to address their specific AI use cases.

To get started with these models, navigate to the SageMaker JumpStart model catalog in the SageMaker console or use the SageMaker Python SDK to deploy the models to your AWS account. For more information about deploying and using foundation models in SageMaker JumpStart, see the Amazon SageMaker JumpStart documentation.

FLUX.2-small-decoder and gemma-4-12B-it models now available on Amazon SageMaker JumpStart

Black Forest Labs' FLUX.2-small-decoder and Google's gemma-4-12B-it models are now available on Amazon SageMaker JumpStart, expanding the portfolio of foundation models available to AWS customers. These two models bring specialized capabilities spanning efficient image generation decoding and unified multimodal understanding, enabling customers to deploy high-performance, scalable AI solutions on AWS infrastructure.

FLUX.2-small-decoder is optimized for faster image decoding with lower VRAM usage in FLUX.2 image generation pipelines. It is a distilled VAE decoder that serves as a drop-in replacement for the standard FLUX.2 decoder, delivering approximately 1.4× faster decoding speed at 1.4× lower VRAM consumption with minimal to zero quality loss. Benefits increase at higher resolutions where the decoder processes more pixels, making it ideal for production-grade image generation workloads at scale.

gemma-4-12B-it excels in unified multimodal understanding across text, image, and audio inputs with native support for function calling and agentic workflows. It features an encoder-free architecture where all modalities flow directly into a single decoder-only transformer, delivering performance nearing Google's larger 26B MoE model at less than half the memory footprint. Compact enough to run on 16GB of RAM, it enables powerful multimodal and agentic experiences for enterprise deployments.

With SageMaker JumpStart, customers can deploy any of these models with just a few clicks to address their specific AI use cases.

To get started with these models, navigate to the SageMaker JumpStart model catalog in the SageMaker console or use the SageMaker Python SDK to deploy the models to your AWS account. For more information about deploying and using foundation models in SageMaker JumpStart, see the Amazon SageMaker JumpStart documentation.

Amazon RDS for MariaDB now supports MariaDB 12.3

詳細を表示

Starting today, Amazon RDS for MariaDB supports MariaDB major version 12.3, the latest Long-Term Support release from the MariaDB community. This release supports MariaDB 12.3.2 minor version.  

MariaDB 12.3 includes Oracle TO_DATE() function compatibility, reducing the code changes needed when migrating applications from Oracle to MariaDB. It adds an IS JSON predicate, so you can validate JSON documents natively in the database rather than in application code. The query optimizer now handles reorderable LEFT JOIN statements and ordered scans over RANGE partitions more efficiently, improving performance for these queries without application changes. For more details, refer to the MariaDB 12.3 release notes and RDS MariaDB release notes.

You can upgrade your database using Amazon RDS Blue/Green Deployments, in-place upgrade, or restore from a snapshot. Learn more about performing major version upgrades in the Amazon RDS User Guide. You can also migrate to RDS for MariaDB 12.3 from external MariaDB sources using AWS Database Migration Service.  

Amazon RDS for MariaDB makes it simple to set up, operate, and scale MariaDB deployments in the cloud. Learn more about pricing details and regional availability at Amazon RDS for MariaDB. Create or update a fully managed Amazon RDS for MariaDB database in the Amazon RDS Management Console.

AWS Clean Rooms supports exporting privacy-enhanced analysis logs for SQL

AWS Clean Rooms now supports exporting privacy-enhanced analysis logs for SQL analyses, offering customers greater optimization and troubleshooting capabilities. With this launch, you can export privacy-enhanced analysis logs to an S3 bucket for SQL queries that ran in an AWS Clean Rooms collaboration, providing insight into Spark execution details that can help you optimize and troubleshoot your queries. Collaboration owners grant a member the ability to export analysis logs when they create a collaboration or submit a change request to grant the ability to a member of an existing collaboration. After a query runs, you can export the privacy-enhanced analysis logs to your desired S3 path. For example, a third-party measurement provider collaborating with a publisher can identify an anomalous data skew that is causing a query to run slower than usual, accelerating time-to-resolution and optimizing costs. 

AWS Clean Rooms helps companies and their partners easily analyze and collaborate on their collective datasets without revealing or copying one another’s underlying data. For more information about the AWS Regions where AWS Clean Rooms is available, see the AWS Regions table. To learn more about collaborating with AWS Clean Rooms, visit AWS Clean Rooms.

Amazon Connect Customer launches performance dashboard for Cases

Amazon Connect Customer now provides a performance dashboard for cases that helps managers monitor case volume, resolution trends, and performance against service level agreement (SLA) targets. Managers can compare current and prior-period performance across metrics such as cases created, average resolution time, first-contact resolution percentage, and SLA achievement rate. They can also analyze trends across dimensions such as case template, assigned user, or assigned queue. For example, a manager can identify that the billing team missed more SLA targets for refund cases than in the prior period, investigate the causes, and prioritize process improvements.

Cases is available in the following AWS regions: US East (N. Virginia), US West (Oregon), Canada (Central), Europe (Frankfurt), Europe (London), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), and Africa (Cape Town). To learn more and get started, visit the Cases webpage and documentation.

AWS Glue adds one-click access to SageMaker Unified Studio from the AWS console

AWS Glue now provides direct access to Amazon SageMaker Unified Studio, helping data engineers and analysts move from viewing the catalog in the Glue console to querying their data, running data quality checks, and building data pipelines in SageMaker Unified Studio with a single click. This new integration helps customers who already work in the Glue console transition and access a broader set of data and AI capabilities in SageMaker Unified Studio seamlessly. With this launch, SageMaker Unified Studio can now be accessed by a single click from S3 Tables, Athena, EMR, Redshift and Glue consoles.

When working in the AWS Glue console to browse catalog tables or build ETL jobs, you now have one-click access to open SageMaker Unified Studio, and can immediately begin working with your data in the catalog or query your data using SageMaker Notebooks using the same IAM role. For Glue console customers who have not yet set up SageMaker Unified Studio, a new inline permissions panel helps you create and configure the required IAM policies directly within the setup workflow, without navigating to the IAM console and switching browser tabs. You can use your existing IAM role and customize the permissions in-context, reducing the steps required to get started.

This feature is available in all AWS Regions where Amazon SageMaker Unified Studio is supported. To get started, navigate to the AWS Glue console.

AWS Secrets Manager adds managed external secrets support for Jenkins and SonarQube

AWS Secrets Manager now extends its managed external secrets capability to include Jenkins API Tokens and SonarQube Tokens, enabling you to automatically rotate these third-party credentials directly from the AWS console without writing any custom rotation code.

For Jenkins, Secrets Manager mints a new token and revokes the old one only after the replacement is verified active, so your continuous integration and continuous delivery (CI/CD) jobs transition without interruption. Rotation supports both self-rotation, where the token being rotated authenticates its own replacement, and admin-assisted rotation, where a separate admin token performs the generate and revoke operations. For SonarQube, you can rotate three types of tokens — User Tokens, Global Analysis Tokens, and Project Analysis Tokens — via SonarQube's Web API. User Tokens support self-rotation, while analysis tokens are rotated using an admin token.

These integrations join existing managed external secrets support for BigID, Confluent Cloud, Datadog, GitLab, MongoDB Atlas, Okta, Paddle, Salesforce, and Snowflake.

Jenkins and SonarQube managed external secrets are available in all AWS Regions where AWS Secrets Manager managed external secrets is supported. To learn more, visit the  AWS Secrets Manager managed external secrets documentation .

AWS News Blog

AWS Weekly Roundup: AWS Heroes Summit, Web Search on Amazon Bedrock, Dogwood, Kiro Crew, and more (August 10, 2026)

Last week, we brought together AWS Heroes from around the world to connect, collaborate, and celebrate the builders who go above and beyond for the AWS community. The AWS Heroes Summit, an invite-only annual gathering, brings global experts specializing in fields like AI, serverless, and containers together for direct collaboration, technical deep-dives, and feedback sessions […]

AWS Japan Blog

AWS が Anthropic および OpenAI と協業し、AWS Continuum を開発者ワークフローに統合します

AWS は Anthropic および OpenAI との協業を発表しました。AWS Continuum for code vulnerabilities (プレビュー) が Claude Code、Codex、Kiroの開発者ワークフローに直接統合され、開発者は既存のワークフローの中で脆弱性の発見、コンテキストに基づく優先順位付け、検証、修復を行えるようになります。

AWS Security Blog

2026 AWS CyberVadis report now available for due diligence on third-party suppliers

We’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in all assessed areas. This demonstrates our continued commitment to meet the heightened expectations for cloud service providers. Customers can now use the 2026 AWS CyberVadis report and scorecard to reduce their supplier […]

AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London)

We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the PASF program. This demonstrates our continuous commitment to adhere to the heightened expectations of customers […]

AWS Machine Learning Blog

How nOps shipped FinOps agents 75% faster with Amazon Bedrock AgentCore

nOps rebuilt its Clara FinOps AI agent on Amazon Bedrock AgentCore, replacing a self-managed Amazon EKS stack running LangChain and LangGraph. The move cut time-to-production by 75% (from 10-12 months to 4 months), improved response quality, and reduced operational overhead while keeping analytics governed through Databricks Lakehouse Metric Views.

Run interactive IDEs on Amazon EKS with SageMaker AI to power up your AI workflows

The Amazon SageMaker AI Spaces add-on for Amazon EKS runs managed JupyterLab and Code Editor environments on the cluster your ML team already operates. This post shows how to install and configure the add-on, connect from the browser and from VS Code over SSH-over-SSM, and move your team to OpenID Connect sign-in with Amazon Cognito.