#PrivateLink
🆕 AWS IAM outbound identity federation now supports VPC endpoints for OIDC discovery, enabling private access to OIDC metadata and JWKS keys within VPCs without public internet access, enhancing network security. Available in all commercial regions, no…

#AWS #AwsIdentityAndAccessManagement #AwsIam
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery
AWS Identity and Access Management (IAM) outbound identity federation now supports Amazon Virtual Private Cloud (VPC) endpoints for the OpenID Connect (OIDC) discovery APIs. You can now access the OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints from within your VPC using AWS PrivateLink, without requiring traffic to traverse the public internet. IAM outbound identity federation eliminates the need to use long-lived credentials when your AWS workloads access external services. Instead, your workloads request short-lived JSON Web Tokens (JWTs) from AWS Security Token Service (AWS STS). External services verify these tokens using public verification keys and metadata available at OIDC discovery endpoints. Previously, the OIDC discovery endpoints were only reachable over the public internet, so a verifying workload running in a VPC without internet access could not retrieve them. With this launch, you can create an interface VPC endpoint to reach these endpoints privately, keeping the verification key retrieval traffic within the AWS network. This capability helps you meet network security requirements for workloads that operate in VPCs with restricted internet access, while still enabling external services to verify JWTs. This feature is available in all commercial AWS Regions, the AWS GovCloud (US) Regions, and China Regions. There is no additional charge for this feature beyond standard AWS PrivateLink pricing. To learn more, see the IAM User Guide.
aws.amazon.com
September 25, 2026 at 10:10 PM
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery

https://aws.amazon.com/identity/federation/outbound-federation/ now supports Amazon Virtual Private Cloud (VPC) endpoints for the OpenID Connect (OIDC) disco...

#AWS #AwsIdentityAndAccessManagement #AwsIam
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery
https://aws.amazon.com/identity/federation/outbound-federation/ now supports Amazon Virtual Private Cloud (VPC) endpoints for the OpenID Connect (OIDC) discovery APIs. You can now access the OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints from within your VPC using https://aws.amazon.com/privatelink/, without requiring traffic to traverse the public internet. IAM outbound identity federation eliminates the need to use long-lived credentials when your AWS workloads access external services. Instead, your workloads request short-lived JSON Web Tokens (JWTs) from AWS Security Token Service (AWS STS). External services verify these tokens using public verification keys and metadata available at OIDC discovery endpoints. Previously, the OIDC discovery endpoints were only reachable over the public internet, so a verifying workload running in a VPC without internet access could not retrieve them. With this launch, you can create an interface VPC endpoint to reach these endpoints privately, keeping the verification key retrieval traffic within the AWS network. This capability helps you meet network security requirements for workloads that operate in VPCs with restricted internet access, while still enabling external services to verify JWTs. This feature is available in all commercial AWS Regions, the AWS GovCloud (US) Regions, and China Regions. There is no additional charge for this feature beyond standard https://aws.amazon.com/privatelink/pricing/. To learn more, see the https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sts_oidc_vpc_endpoint_create.html.
aws.amazon.com
September 25, 2026 at 10:05 PM
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery
AWS Identity and Access Management (IAM) outbound identity federation now supports Amazon Virtual Private Cloud (VPC) endpoints for the OpenID Connect (OIDC) discovery APIs. You can now access the OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints from within your VPC using AWS PrivateLink, without requiring traffic to traverse the public internet. IAM outbound identity federation eliminates the need to use long-lived credentials when your AWS workloads access external services. Instead, your workloads request short-lived JSON Web Tokens (JWTs) from AWS Security Token Service (AWS STS). External services verify these tokens using public verification keys and metadata available at OIDC discovery endpoints. Previously, the OIDC discovery endpoints were only reachable over the public internet, so a verifying workload running in a VPC without internet access could not retrieve them. With this launch, you can create an interface VPC endpoint to reach these endpoints privately, keeping the verification key retrieval traffic within the AWS network. This capability helps you meet network security requirements for workloads that operate in VPCs with restricted internet access, while still enabling external services to verify JWTs. This feature is available in all commercial AWS Regions, the AWS GovCloud (US) Regions, and China Regions. There is no additional charge for this feature beyond standard AWS PrivateLink pricing. To learn more, see the IAM User Guide.
dlvr.it
September 25, 2026 at 9:48 PM
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery

AWS now lets you pay PrivateLink fees to access free OIDC metadata without touching the scary public internet. Because nothing says "security" like adding billable services to retrieve public keys.
September 25, 2026 at 9:44 PM
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery

AWS IAM outbound federation now supports VPC endpoints for OIDC discovery APIs. External services can verify JWTs using PrivateLink without internet access, keeping traffic within AWS network.
September 25, 2026 at 9:44 PM
Private AI coding agents are now practical: open weight models on Bedrock keep your code inside AWS with IAM and PrivateLink controls, cutting batch refactor costs by 50%. https://aws.amazon.com/blogs/machine-learning/use-open-weight-models-as-your-ai-coding-agent-with-amazon-bedrock
September 24, 2026 at 6:05 AM
📰 New article by Frank Scarfo, Ben Freiberg

Adding custom domains to AWS Lambda MicroVMs with Application Load Balancer

#AWS #Compute
Adding custom domains to AWS Lambda MicroVMs with Application Load Balancer
Many teams want to expose their AWS Lambda MicroVMs under a custom domain they own, and satisfy CORS for browser clients, without changing the application. This post shows how, using an Application Load Balancer that rewrites the Host header and forwards over AWS PrivateLink, deployed with the AWS CDK.
aws.amazon.com
September 22, 2026 at 4:56 PM
VPC PeeringとPrivateLinkでできること
・VPC間で通信ができる
・オンプレ環境とVPCやAWSのサービスとを直結できる
・せっかく粗結合にしたVPCやAWSアカウントを別ちがたく結びつけることができる
・ハブ&スポークという理想を蜘蛛の巣に変容させることができる
・同じCIDRを持つVPC同士を直結してカオスと地獄を招き入れることができる ← new!
September 22, 2026 at 5:14 AM
【図解】CIDR単位で別アカウントに接続できるPrivateLinkトンネルエンドポイントの仕組み

#AWS #PrivateLink
【図解】CIDR単位で別アカウントに接続できるPrivateLinkトンネルエンドポイントの仕組み - Qiita
概要 VPCエンドポイントのトンネルエンドポイントがリリースされました。 これまでのリソースエンドポイントは、Resource Configurationをリソース単位で作成する方式でした。トンネルエンドポイントではResource ConfigurationにCIDR範...
qiita.com
September 21, 2026 at 5:20 PM
AWS PrivateLink announces Tunnel Endpoints to access network segments

https://aws.amazon.com/about-aws/whats-new/2026/9/privatelink-tunnel-endpoint/
September 18, 2026 at 10:28 PM
🆕 AWS PrivateLink's Tunnel Endpoints offer secure, private access to VPC segments across accounts using GENEVE encapsulation for scalable, high-availability. Available in multiple regions; see AWS PrivateLink for pricing.

#AWS #AwsPrivatelink
AWS PrivateLink announces Tunnel Endpoints to access network segments
AWS PrivateLink customers can now use VPC endpoint to privately and securely access network segments in another VPC/account. They can use a ‘tunnel’ endpoint, a new type of VPC endpoint, to tunnel into the network segment and access resources located within it. AWS PrivateLink is a highly available and scalable technology that enables private access across VPC and account boundaries to load balanced services, appliances, and resources such as databases and domains. Prior to this launch, customers who wanted to share their resources with another party such as an external vendor had to do it one at a time by creating a Resource Configuration for every resource. Now, customers can create a Resource Configuration to represent a CIDR range in their network, and share it with a vendor via AWS Resource Access Manager (RAM). The vendor can then create a tunnel endpoint and use GENEVE encapsulation to tunnel through it into the customer’s VPC to access resources located in CIDR range specified by the customer. There is an hourly charge for the tunnel endpoint and a per-GB charge for data processed through it. Please refer to the pricing page for AWS PrivateLink.   The capability is available in the following AWS Regions: US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon), Africa (Cape Town), Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Jakarta), Asia Pacific (Malaysia), Asia Pacific (Melbourne), Asia Pacific (Mumbai), Asia Pacific (Osaka), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Canada (Central), Canada West (Calgary), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Milan), Europe (Paris), Europe (Spain), Europe (Stockholm), Europe (Zurich), Mexico (Central), South America (São Paulo). To learn more about this capability and get started, please refer to the AWS PrivateLink documentation.
aws.amazon.com
September 18, 2026 at 9:10 PM
AWS PrivateLink announces Tunnel Endpoints to access network segments

AWS PrivateLink customers can now use VPC endpoint to privately and securely access network segments in another VPC/account. They can use a ‘tunnel’ endpoint, a new type of VPC endpoint, to tunnel into th...

#AWS #AwsPrivatelink
AWS PrivateLink announces Tunnel Endpoints to access network segments
AWS PrivateLink customers can now use VPC endpoint to privately and securely access network segments in another VPC/account. They can use a ‘tunnel’ endpoint, a new type of VPC endpoint, to tunnel into the network segment and access resources located within it. AWS PrivateLink is a highly available and scalable technology that enables private access across VPC and account boundaries to load balanced services, appliances, and resources such as databases and domains. Prior to this launch, customers who wanted to share their resources with another party such as an external vendor had to do it one at a time by creating a Resource Configuration for every resource. Now, customers can create a Resource Configuration to represent a CIDR range in their network, and share it with a vendor via AWS Resource Access Manager (RAM). The vendor can then create a tunnel endpoint and use GENEVE encapsulation to tunnel through it into the customer’s VPC to access resources located in CIDR range specified by the customer. There is an hourly charge for the tunnel endpoint and a per-GB charge for data processed through it. Please refer to the pricing page for https://aws.amazon.com/privatelink/pricing/.   The capability is available in the following https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/: US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon), Africa (Cape Town), Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Jakarta), Asia Pacific (Malaysia), Asia Pacific (Melbourne), Asia Pacific (Mumbai), Asia Pacific (Osaka), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Canada (Central), Canada West (Calgary), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Milan), Europe (Paris), Europe (Spain), Europe (Stockholm), Europe (Zurich), Mexico (Central), South America (São Paulo). To learn more about this capability and get started, please refer to the https://docs.aws.amazon.com/vpc/latest/privatelink/what-is-privatelink.html.
aws.amazon.com
September 18, 2026 at 9:05 PM
AWS PrivateLink announces Tunnel Endpoints to access network segments
AWS PrivateLink customers can now use VPC endpoint to privately and securely access network segments in another VPC/account. They can use a ‘tunnel’ endpoint, a new type of VPC endpoint, to tunnel into the network segment and access resources located within it. AWS PrivateLink is a highly available and scalable technology that enables private access across VPC and account boundaries to load balanced services, appliances, and resources such as databases and domains. Prior to this launch, customers who wanted to share their resources with another party such as an external vendor had to do it one at a time by creating a Resource Configuration for every resource. Now, customers can create a Resource Configuration to represent a CIDR range in their network, and share it with a vendor via AWS Resource Access Manager (RAM). The vendor can then create a tunnel endpoint and use GENEVE encapsulation to tunnel through it into the customer’s VPC to access resources located in CIDR range specified by the customer. There is an hourly charge for the tunnel endpoint and a per-GB charge for data processed through it. Please refer to the pricing page for AWS PrivateLink.   The capability is available in the following AWS Regions: US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon), Africa (Cape Town), Asia Pacific (Hong Kong), Asia Pacific (Hyderabad), Asia Pacific (Jakarta), Asia Pacific (Malaysia), Asia Pacific (Melbourne), Asia Pacific (Mumbai), Asia Pacific (Osaka), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Canada (Central), Canada West (Calgary), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Milan), Europe (Paris), Europe (Spain), Europe (Stockholm), Europe (Zurich), Mexico (Central), South America (São Paulo). To learn more about this capability and get started, please refer to the AWS PrivateLink documentation.
dlvr.it
September 18, 2026 at 9:05 PM
AWS PrivateLink announces Tunnel Endpoints to access network segments

AWS just announced you can now pay hourly + per-GB to do what VPNs have done for decades, but with more steps and a proprietary protocol. They call it a "tunnel endpoint" because "expensive hole" didn't test well with marketing.
September 18, 2026 at 9:04 PM
AWS PrivateLink announces Tunnel Endpoints to access network segments

AWS PrivateLink now supports 'tunnel' VPC endpoints, enabling private access to entire network segments across VPCs/accounts using GENEVE encapsulation. Instead of sharing resources individually, customers can share CIDR ranges.
September 18, 2026 at 9:04 PM
AWS PrivateLink introduces Tunnel Endpoints, enabling secure access to network segments across VPCs and accounts using GENEVE encapsulation.
AWS PrivateLink announces Tunnel Endpoints to access network segments
AWS PrivateLink introduces Tunnel Endpoints, enabling secure access to network segments across VPCs and accounts using GENEVE encapsulation.
aws-news.com
September 18, 2026 at 8:23 PM
AWS Storage Gateway now supports FIPS-compliant private connectivity for Amazon S3 File Gateway

https://aws.amazon.com/about-aws/whats-new/2026/09/storage-gateway-fips-privatelink-s3/
September 10, 2026 at 10:42 PM
🆕 AWS Storage Gateway now provides FIPS-compliant private access for Amazon S3 File Gateway via AWS PrivateLink, boosting compliance for regulated workloads. Available in eight regions. For more, see the AWS Storage Gateway User Guide.

#AWS #AwsStorageGateway #AwsPrivatelink #AmazonS3
AWS Storage Gateway now supports FIPS-compliant private connectivity for Amazon S3 File Gateway
AWS Storage Gateway now supports FIPS 140-3 validated endpoints over AWS PrivateLink for Amazon S3 File Gateway. Previously, FIPS endpoints for File Gateway were available only over the public internet. Now you can keep FIPS-compliant traffic on the private AWS network, making it easier to use Storage Gateway for regulated workloads. With this launch, your File Gateway can reach the Storage Gateway service endpoints privately through a FIPS interface VPC endpoint in your VPC. You can also create NFS and SMB file shares that reach Amazon S3 through an S3 FIPS interface endpoint, enabling FIPS-compliant private connectivity for your end-to-end file transfer workloads. To get started, create FIPS interface endpoints for Storage Gateway and Amazon S3 in your VPC, then choose the FIPS VPC endpoint option when activating your gateway and configuring your file shares. To activate a gateway with a FIPS PrivateLink endpoint, your gateway must be running software version 3.2.7 or later. This launch is available in the eight AWS Regions where Storage Gateway offers FIPS endpoints: US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon), Canada (Central), Canada West (Calgary), AWS GovCloud (US-East), and AWS GovCloud (US-West). To learn more, visit the AWS Storage Gateway User Guide or the product page.
aws.amazon.com
September 10, 2026 at 9:11 PM
AWS Storage Gateway now supports FIPS-compliant private connectivity for Amazon S3 File Gateway
AWS Storage Gateway now supports FIPS 140-3 validated endpoints over AWS PrivateLink for Amazon S3 File Gateway. Previously, FIPS endpoints for File Gateway were available only over the public internet. Now you can keep FIPS-compliant traffic on the private AWS network, making it easier to use Storage Gateway for regulated workloads. With this launch, your File Gateway can reach the Storage Gateway service endpoints privately through a FIPS interface VPC endpoint in your VPC. You can also create NFS and SMB file shares that reach Amazon S3 through an S3 FIPS interface endpoint, enabling FIPS-compliant private connectivity for your end-to-end file transfer workloads. To get started, create FIPS interface endpoints for Storage Gateway and Amazon S3 in your VPC, then choose the FIPS VPC endpoint option when activating your gateway and configuring your file shares. To activate a gateway with a FIPS PrivateLink endpoint, your gateway must be running software version 3.2.7 or later. This launch is available in the eight AWS Regions where Storage Gateway offers FIPS endpoints: US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon), Canada (Central), Canada West (Calgary), AWS GovCloud (US-East), and AWS GovCloud (US-West). To learn more, visit the AWS Storage Gateway User Guide or the product page.
dlvr.it
September 10, 2026 at 9:08 PM