10/5/2026, 12:00:00 AM ~ 10/6/2026, 12:00:00 AM (UTC)
Recent Announcements
Amazon Redshift adds support for creating and refreshing Apache Iceberg materialized views
Amazon Redshift now supports the creation and refresh of Apache Iceberg materialized views. Materialized views pre-compute expensive joins and aggregations once and store the results in an Apache Iceberg table in Amazon S3 or Amazon S3 table buckets, registered in the AWS Glue Data Catalog. Materialized views are created using familiar SQL — CREATE MATERIALIZED VIEW … USING ICEBERG and the results are instantly queryable by any Iceberg-compatible engine, including Amazon Athena, Apache Spark on Amazon EMR and AWS Glue, and third-party engines such as Trino, or Snowflake. Redshift keeps them current by recomputing only what has changed with manual incremental refresh, and because the results are Iceberg tables in the Glue Data Catalog, they are governed and discovered like any other catalog table.\nData teams often build analytics in stages, stitching together different engines to clean and transform raw data before serving it. This adds pipeline orchestration overhead and can introduce semantic differences between engines. Iceberg materialized views deliver value in two ways. First, instead of hundreds of users and teams re-running the same expensive joins and aggregations, and re-scanning source tables on every query, you compute the result once and everyone reads the precomputed table. Second, you can run an end-to-end pipeline using a single engine like Apache Spark and now Amazon Redshift, and every downstream consumer shares the same open result without the overhead of orchestrating multiple engines. Either way, the output is an open Iceberg table that any engine can read without copies or conversion. You can still load these tables into Redshift Managed Storage (RMS) as native RMS materialized views for your most performance-sensitive dashboards. You can create Iceberg Materialized Views in any region where Redshift Serverless and provisioned Graviton instances are supported. To learn more, see Materialized views stored as Apache Iceberg tables in the Amazon Redshift Database Developer Guide, the CREATE MATERIALIZED VIEW command reference, and the Materialize once, query anywhere blog post.
AWS IAM Identity Center now supports network access controls for Identity Store
AWS IAM Identity Center helps you configure the single sign-on experience for your workforce to AWS accounts and applications. IAM Identity Center now supports network access controls for Identity Store, which stores your users and groups. You can restrict access to the Identity Store API and the SCIM API based on the network that requests originate from. Your custom applications and user provisioning workflows use the Identity Store API to manage and look up users and groups, and your external identity provider uses the SCIM API to synchronize users and groups.\nFor the Identity Store API, you can require that requests arrive only through allowed VPC endpoints in your account or organization, or from specific source VPCs. For both APIs, you can allow requests only from specific IP ranges. Within the same configuration, you can apply different restrictions to each API. For example, you can require that Identity Store API requests arrive only through VPC endpoints, while allowing SCIM requests from your external identity provider’s published IP ranges. Network access controls are optional and turned off by default. Requests that AWS services make on your behalf are exempt. You configure network access controls by using the Identity Store API through the AWS SDKs and AWS CLI. This capability is available in all AWS Regions where IAM Identity Center is offered. To learn more about IAM Identity Center, visit the product detail page. To get started with network access controls, see the Identity Store API Reference.
AWS Continuum for Penetration Testing now integrates continuous penetration testing directly into your CI/CD pipeline (public preview)\nAWS Continuum for Penetration Testing (formerly AWS Security Agent) already provides continuous, on-demand penetration testing without the need to contract third-party pentest vendors. Now, in public preview, Continuum for Penetration Testing shifts security testing even further left by integrating directly into your existing CI/CD systems, making penetration testing a deploy-time event. Development teams ship code daily, but even with on-demand penetration testing available, security validation often happens outside the deployment workflow. CI/CD integration closes this gap. Developers receive findings, including severity, affected endpoints, and remediation guidance, directly in pipeline output. Non-security changes complete with no meaningful delay, and the pipeline automatically re-tests and verifies fixes after remediation without requiring manual re-triggers. Getting started requires no security expertise. An auto-generated pipeline snippet can be pasted into any existing pipeline and is completable in under five minutes. Application context bootstraps automatically on the first run, with no prior full penetration test required. Continuous penetration testing is available today. To get started, visit our documentation.
AWS Advanced Ruby Driver Wrapper is generally available
The Amazon Web Services (AWS) Advanced Ruby Driver Wrapper is now generally available for use with Amazon RDS and Amazon Aurora PostgreSQL and MySQL-compatible databases. This advanced database driver reduces RDS Blue/Green switchover, Aurora Global database switchover and database failover times, improving application availability. Additionally, it supports multiple authentication mechanisms for your database, including AWS Secrets Manager authentication, and token-based authentication with AWS Identity and Access Management (IAM).\nThe AWS Advanced Ruby Driver Wrapper builds on top of the community pg (PostgreSQL), and the mysql2 (MySQL) drivers to provide enhanced functionality beyond standard database connectivity. The wrapper is natively integrated with Aurora and RDS databases, enabling it to monitor database cluster status and quickly connect to newly promoted writers during unexpected failures that trigger database failovers. Furthermore, the wrapper seamlessly integrates with the ActiveRecord through provided aws_postgresql and aws_mysql2 adapters, so you can enable it without changing your application code. The driver is available as an open-source project under the Apache 2.0 license. Refer to the instructions on the GitHub repository to get started.
AWS Batch now supports Amazon EKS access entry authentication
AWS Batch now supports Amazon EKS access entry authentication for compute environments. EKS access entries provide an API-driven approach to granting IAM principals access to Kubernetes clusters, complementing the existing aws-auth ConfigMap. AWS Batch can now authenticate to your cluster through the access entry mechanism, simplifying cluster setup and authentication lifecycle management.\n CreateComputeEnvironment or UpdateComputeEnvironment APIs to set accessEntry.desiredState to ENABLED on all AWS Batch compute environments targeting your cluster. AWS Batch creates one access entry per cluster and associates the AWSBatchClusterPolicy with it. You can configure access entries through the AWS CLI, AWS SDKs, or AWS Management Console.
AWS Regions where AWS Batch is available. For more information, see Amazon EKS access entry authentication in the AWS Batch User Guide.
AWS Private CA now provides detailed certificate issuance logs
AWS Private CA announces detailed certificate issuance logs, a new AWS CloudTrail service event that records the complete certificate content, issuing CA information, requester identity, and signing status for every issuance. You can use these events for compliance auditing, certificate inventory, algorithm migration tracking, and failed-issuance monitoring. Previously, the CloudTrail management event for the IssueCertificate API confirmed that the API call succeeded by providing a certificate ARN but did not capture the certificate content, information about the CA that signed it, or issuances that failed before signing.\nThe new IssueCertificateDetails event captures the complete to-be-signed (TBS) certificate with all X.509 fields and extensions, plus convenience fields for the subject, issuer, serial number, validity period, template, and signing algorithm. Events are emitted for both successful and failed issuance, so pre-signing failures such as name constraints violations now produce a record with a failure explanation. Each event identifies the requester: the account and IAM principal for direct API callers, or the service principal for certificates issued through AWS Private CA connectors or integrated AWS services. In cross-account configurations, the event is delivered to the CA owner account. The event is delivered automatically as a CloudTrail management event, with no configuration or opt-in required and no additional cost beyond standard AWS CloudTrail pricing. Because it flows through CloudTrail, you can act on it in real time with Amazon EventBridge or query it in batch with Amazon Athena for certificate auditing, inventory, tracking, and monitoring. This feature is available in all AWS Regions where AWS Private CA is offered. To learn more, see the AWS Private CA User Guide.
AWS Blogs
AWS Japan Blog (Japanese)
- AWS Mainframe Modernization Day Tokyo 2026 [Event Report]
- [AI-Driven Modernization] “AI Modernization Flow,” which makes AI agents perform disciplined migration work, has been released
- Weekly Generative AI with AWS — Week of 2026/9/28
- Announcing the AWS Well-Architected Agent, AI-based intelligence to optimize cloud environments (preview)
- Claude Sonnet 5.5 is now available on Kiro
- AWS Weekly — 2026/9/28
AWS News Blog
AWS Architecture Blog
AWS Big Data Blog
- Materialize once, query anywhere: Introducing Iceberg materialized views in Amazon Redshift
- Run an automated operational review with the Amazon Redshift MCP server
AWS Compute Blog
AWS Database Blog
- Assess and migrate SQL Server Full-Text Search to Babelfish for Aurora PostgreSQL
- Amagi’s intelligent media operations with Amazon Neptune
AWS DevOps & Developer Productivity Blog
AWS for Industries
- How WellRithms achieved 30 times faster bill processing with AWS
- Trust-Earned Autonomy: How Texas Capital Bank demonstrates an AI agent that commits to the core banking ledger, then reverses itself
Artificial Intelligence
- Introducing GLM 5.3 on Amazon Bedrock
- Supercharge regulated workloads with Claude Code and Amazon Bedrock
- New agent skill: Amazon SageMaker optimized generative AI inference for your coding agent
- Making Amazon Quick enterprise-ready: Automated, auditable cross-account resource promotion
- Agentic retrieval with LangChain and Amazon Bedrock Knowledge Bases
- Downgrading user roles in Amazon Quick
- Evaluating multi-agent systems for explainability and helpfulness with Amazon Bedrock AgentCore
Networking & Content Delivery
- Powering predictable costs with AWS Direct Connect flat-rate pricing
- Protect MCP Endpoints at the Edge with Amazon CloudFront and AWS WAF