8/7/2026, 12:00:00 AM ~ 8/10/2026, 12:00:00 AM (UTC)

Recent Announcements

Amazon Timestream for InfluxDB now supports backup and restore

Amazon Timestream for InfluxDB now lets you create and manage your own backups and restore your data on demand. You can trigger one-time, on-demand backups, schedule automated recurring backups at the frequency and retention you choose, and restore a backup to a new resource or in place of an existing one. This capability is available for both the InfluxDB 2 and InfluxDB 3 engines through the AWS Management Console, the AWS CLI, and the Timestream for InfluxDB API.\n With this capability, you control your data protection strategy. You can take an on-demand backup before a risky migration or configuration change. You can also define up to four automated backup configurations per resource using hourly, daily, weekly, monthly, or custom schedules, each with its own retention period. The first backup captures a full copy of your database, and subsequent backups are incremental, reducing the performance impact of ongoing backups. When you restore a backup, you can create a new resource that inherits the source configuration or replace an existing resource. If the source resource uses a Customer Managed key (KMS), its backups use the same key.

Customer-driven backup and restore is available in all AWS Regions where Amazon Timestream for InfluxDB is available. To get started, open the Amazon Timestream console. For more information, see the Amazon Timestream for InfluxDB documentation and pricing page.

Amazon Cognito now available as a skill in the Agent Toolkit for AWS

Amazon Cognito is now available as a core skill (aws-auth) in the Agent Toolkit for AWS. AI coding agents using the toolkit can now set up, configure, secure, and troubleshoot Amazon Cognito using best-practice workflows, helping developers implement secure sign-in flows for users, AI agents, and microservices faster.\n  

The Amazon Cognito (aws-auth) skill covers user pool and app client configuration, managed login and OAuth 2.0 flows, token management, JWT authorizers, passkey/WebAuthn enrollment, threat protection, Lambda trigger wiring, and identity pools. When paired with the AWS MCP Server, agents execute AWS CLI commands with IAM-based guardrails and CloudTrail audit logging. The skill also works standalone via the AWS CLI.

 

The Amazon Cognito (aws-auth) skill is available as part of the Agent Toolkit for AWS. To get started, see the Amazon Cognito aws-auth skill on GitHub or browse the Agent Toolkit Quick Start guide. For more information about Amazon Cognito, see the Amazon Cognito Developer Guide.

AWS IAM Identity Center supports one-click multi-Region option for new organization instances

AWS IAM Identity Center now makes it easier to enable multi-Region support when creating a new organization instance. Previously, enabling multi-Region support required multiple steps including creating a customer managed KMS key, configuring key policies, and manually adding Regions. Now, customers creating a new IAM Identity Center instance in supported Regions can enable multi-Region in one click.\n When enabling a new organization instance, you can choose from three instance configuration options: single-Region instance, multi-Region instance, or custom instance. The multi-Region instance option automatically creates a customer managed multi-Region KMS key in your account and replicates your instance to an additional Region. This enables resilient AWS account and application access — your workforce can continue to access their AWS accounts even if IAM Identity Center experiences a disruption in the primary Region. The custom instance option lets you configure your Region settings individually, including the ability to use an existing customer managed KMS key from your account.

Instance configuration options are available in 17 enabled-by-default commercial AWS Regions for organization instances of IAM Identity Center. Standard AWS KMS charges apply for the customer managed key created with the multi-Region instance option. IAM Identity Center is provided at no additional cost.

To get started, see the IAM Identity Center User Guide. To learn more about multi-Region support, see Using IAM Identity Center across multiple AWS Regions. To learn more about IAM Identity Center, visit the product detail page.

Amazon Bedrock AgentCore adds memory, policy, and harness in AWS GovCloud (US-West)

Today, Amazon Bedrock AgentCore introduces new capabilities in AWS GovCloud (US-West). AgentCore is the platform to build, connect, and optimize agents. With these capabilities, teams operating in regulated environments can build context-aware agents and take them from prototype to production faster, with the controls needed to scale across their organization. \n AgentCore memory gives agents short-term memory for immediate conversation context and long-term memory that extracts persistent insights and preferences across sessions. Agents deliver more intelligent, personalized experiences without teams needing to manage complex memory infrastructure.

Policy in AgentCore provides centralized, fine-grained controls for agent-tool interactions that operate outside agent code. Teams author policies in natural language that automatically convert to Cedar, the AWS open-source policy language. Policies attach them to an AgentCore gateway that evaluates each request before allowing or denying tool access. 

The managed harness lets developers declare an agent’s model, tools, and instructions through configuration and run it in just a few API calls without writing orchestration code, while AgentCore handles the environment, compute, memory, identity, and observability.    To learn more about AgentCore capabilities, visit the AgentCore product page. For a deeper walkthrough of AgentCore concepts and best practices, see the AgentCore Documentation to get started.

Amazon GameLift Servers now supports 21 new EC2 instance types

Amazon GameLift Servers now supports 21 additional Amazon EC2 instance types for managed EC2 fleets and managed container fleets. Amazon GameLift Servers is a fully managed service that enables game developers and studios to deploy, operate, and scale dedicated game servers in the cloud. This expansion gives customer access to the latest compute-optimized and general-purpose instance families.\n The newly supported instance types span six families across two series: compute-optimized C-series (C8a, C8i, C9g) and general-purpose M-series (M8a, M8i, M9g). Customers can now choose between x86 and Arm architectures, selecting from 5th-generation AMD EPYC, custom Intel Xeon 6, or AWS Graviton5 processors to optimize game server workloads for performance, cost, and engine compatibility. Use cases include running CPU-intensive multiplayer game server logic on C-series instances and scaling general-purpose fleets cost-effectively using Graviton5-powered M9g instances.

These instance types are available in Amazon GameLift Servers supported regions, except AWS China. For more information on launching fleets with these EC2 instances, visit the Amazon GameLift Servers documentation.

Amazon OpenSearch Service announces additional upgrade runway for existing domains and support dates for additional versions

In November 2024, Amazon OpenSearch Service announced Extended Support for legacy Elasticsearch and OpenSearch engine versions (see also the detailed blog post). Since that announcement, many customers have upgraded to newer versions. However, some customers need more time to plan and complete their migrations. To provide this flexibility, we are continuing security and operating system patch coverage for these versions for an additional 12 months, through November 7, 2027, at an updated support rate.\n Continuing security and operating system patch coverage for version presently on Extended Support: Security and operating system patch coverage for Elasticsearch versions 1.5 to 7.8 (less Elasticsearch version 5.6 which already has extended support till November 7, 2028), OpenSearch versions 1.0 to 1.2, and OpenSearch versions 2.3 to 2.9 is being continued for an additional 12 months through November 7, 2027. Domains on these versions will not be isolated. From November 7, 2026, the Extended Support surcharge will be equal to your instance pricing for these versions. Storage costs are not affected. For Elasticsearch version 5.6, the existing extended support charges will continue. 

Extended Support dates for additional versions: Amazon OpenSearch Service now announces Standard and Extended Support dates for Elasticsearch versions 6.8, 7.9, and 7.10, OpenSearch version 1.3, and OpenSearch versions 2.11 to 2.19. Elasticsearch versions 6.8 and 7.10 and OpenSearch versions 1.3 and 2.19 will receive 3 years of Extended Support. Elasticsearch version 7.9 and OpenSearch versions 2.11 to 2.17 will receive 1 year of Extended Support. The Extended Support charge for these versions is $0.0065 per Normalized Instance Hour (NIH) in US East (N. Virginia). For exact region pricing see pricing page.

We recommend that customers upgrade to the latest available OpenSearch version for improved performance, security, and new features. For more details, see the blog post , Extended Support documentation, and pricing page.

AWS Parallel Computing Service is now in scope for FedRAMP, SOC, ISO, CSA STAR, and PCI

AWS Parallel Computing Service (PCS), a managed service that simplifies running and scaling high performance computing (HPC) workloads on AWS using Slurm, has expanded its security and compliance coverage. Federal agencies, public sector organizations, and enterprises in regulated industries can now use PCS to run sensitive and mission-critical HPC workloads while meeting their governance, security, and compliance obligations.\n PCS is now in scope for FedRAMP Class C (formerly Moderate baseline) in the US East (Ohio), US East (N. Virginia), and US West (Oregon) Regions, and FedRAMP Class D (formerly High baseline) in the AWS GovCloud (US) Regions. PCS is included in the System and Organization Controls (SOC) 1, 2, and 3 reports, which provide independent third-party assurance over the effectiveness of its controls. PCS is certified under International Organization for Standardization (ISO). PCS holds Cloud Security Alliance Security, Trust & Assurance Registry (CSA STAR) certification under CCM 4.0. PCS is included in the AWS PCI DSS and PCI 3DS attestations of compliance for workloads that handle payment card data. PCS is also HIPAA eligible.

To learn more, review the AWS services in scope by compliance program for FedRAMP, SOC, ISO , CSA STAR, PCI, and HIPAA. For more information about PCS and how to get started, visit the product page and review the documentation.

AWS Blogs

AWS Japan Blog (Japanese)

AWS Big Data Blog

AWS Contact Center

AWS for Industries

Artificial Intelligence

AWS Security Blog

Open Source Project

AWS CLI