AWS Compute Blog

Implementing customer managed keys for AWS Lambda durable functions with Terraform

Implementing customer managed keys for AWS Lambda durable functions with Terraform

Lambda durable functions checkpoint execution state to durable storage, and for regulated payment workloads that data is sensitive. This post shows how to configure a customer managed key in AWS KMS to encrypt durable execution data, define a least-privilege key policy, and verify encryption through AWS CloudTrail, all deployed with Terraform.

Simplify AMI discovery with Amazon EC2 and SSM Parameter Store

Simplify AMI discovery with Amazon EC2 and SSM Parameter Store

Managing Amazon EC2 AMIs at scale means constantly mapping AMI IDs to their AWS Systems Manager parameter paths by hand. A recent enhancement to the DescribeImages API returns the associated SSM parameter directly. This post shows how to use it across the AWS CLI, AWS CloudFormation, Terraform, and Auto Scaling launch templates.

Building event-driven applications at scale with Amazon EventBridge

Building event-driven applications at scale with Amazon EventBridge

Amazon EventBridge relaunched the Custom event bus so a platform team can share one governed bus across the organization while application teams publish and subscribe from their own accounts. See how retention, ordering, open formats, transformation, and direct target delivery change what one bus can carry.

Multi-modal autoscaling with Amazon EC2 Auto Scaling: adding signals for faster, more reliable scaling

Multi-modal autoscaling with Amazon EC2 Auto Scaling: adding signals for faster, more reliable scaling

Multi-modal autoscaling with Amazon EC2 Auto Scaling combines infrastructure metrics like CPU with application-level signals, so a group scales on the demand its users create. In this post, we show you how to implement it, with code samples and results from a controlled test.

Deploying regulated workloads on AWS Local Zones and AWS Outposts

Deploying regulated workloads on AWS Local Zones and AWS Outposts

AWS Local Zones and AWS Outposts help you keep regulated workloads within specific geographic boundaries. This post presents a framework of technologies, including the AWS Nitro System, AWS Organizations SCPs with AWS Control Tower, and Amazon VPC Traffic Mirroring, to help you build auditable, secure architectures for data residency.

Planning for disaster recovery using AWS Local Zones and AWS Outposts racks

Planning for disaster recovery using AWS Local Zones and AWS Outposts racks

Build highly available architectures that span two AWS Outposts racks, or an Outpost rack and an AWS Local Zone, without single points of failure. This post covers three disaster recovery approaches: DNS-based failover, active/active load balancing, and hybrid database replication, with the RTO/RPO trade-offs of each.