#amazon-vpc
DANG! AWS is on a roll with powerful new security features! Introducing: VPC Block Public Access. This setting can be used to enable:
- Bidirectional block
- Ingress-only block
- Granular exclusions for specific VPCs or subnets

This is a *super* valuable feature.
Enhancing VPC Security with Amazon VPC Block Public Access
Amazon VPC Block Public Access is a new feature that provides a simple, declarative control to authoritatively block incoming and outgoing VPC traffic through ...
aws-news.com
November 19, 2024 at 9:51 PM
AWS now has a "Block all public access" from your VPC which overrides everything else.

This is a really interesting one and could be a really powerful security feature. There have always been cases where some small misconfiguration opens up a way in from the outside.

aws.amazon.com/blogs/networ...
Enhancing VPC Security with Amazon VPC Block Public Access | Amazon Web Services
In the earliest days of Amazon Virtual Private Cloud (Amazon VPC), we thought customers would only ever need a single VPC. We’ve learned a lot since then. Today, the AWS Well-Architected Framework des...
aws.amazon.com
November 19, 2024 at 9:53 PM
100 stars for Spinifex.

EC2, S3, EBS, VPC, IAM, recreated on infrastructure you own, so AWS-built apps run unchanged with zero hyperscaler dependency.

openalternative.co/spinifex
Spinifex: Open Source Amazon Web Services Alternative
Spinifex recreates EC2, S3, EBS, VPC, IAM, and more on your own hardware, so AWS-built software runs unchanged without touching a hyperscaler.
openalternative.co
August 31, 2026 at 12:02 PM
Excited that AWS has launched TLS Passthrough for Amazon VPC Lattice!

This feature enables end-to-end encryption, maintaining your existing TLS/mTLS, and supports SNI-based routing.

Simplify service connectivity securely across VPCs!
Enabling end-to-end encryption with Amazon VPC Lattice TLS Passthrough | Amazon Web Services
Introduction In this post, we discuss VPC Lattice Transport Layer Security (TLS) Passthrough feature. We walk through how users designed workloads prior to this feature, what this feature provides,…
zpr.io
January 23, 2025 at 2:37 PM
Another launch which will greatly simplify security, controls and networking configuration on AWS: you can now use VPC resources as origins without exposing them on the internet!

aws.amazon.com/blogs/aws/in...
Introducing Amazon CloudFront VPC origins: Enhanced security and streamlined operations for your applications | Amazon Web Services
Securely deliver high-performance web apps with CloudFront VPC origins; serve content directly from private subnets, eliminating undifferentiated work.
aws.amazon.com
November 21, 2024 at 10:08 PM
I was going to make a hilariously overcomplicated, wildly expensive WordPress architecture diagram, but AWS has already beaten me to it.
May 30, 2025 at 1:14 PM
50 Amazon VPC (Virtual Private Cloud) Interview questions and answers:

https://tapurl.to/awsvpc
September 25, 2026 at 1:53 AM
VPC Egress is a nice addition to Bedrock AgentCore Gateway. If every API is a tool, private APIs should definitely be in the mix!

Amazon Bedrock AgentCore Gateway and Identity support VPC egress aws-news.com/article/2026...
Amazon Bedrock AgentCore Gateway and Identity support VPC egress
Amazon Bedrock AgentCore Gateway and Identity now support VPC egress, enabling secure communication with private resources and identity providers within custom...
aws-news.com
April 26, 2026 at 9:02 AM
VPC Block Public Access is a great example of simplification: customers were always able to lock their VPCs down through a mix of controls... but now it's a single flag, and it can be easily rolled out to an entire organization.

Cool, eh?

aws.amazon.com/blogs/networ...
Enhancing VPC Security with Amazon VPC Block Public Access | Amazon Web Services
In the earliest days of Amazon Virtual Private Cloud (Amazon VPC), we thought customers would only ever need a single VPC. We’ve learned a lot since then. Today, the AWS Well-Architected Framework des...
aws.amazon.com
November 20, 2024 at 10:44 PM
It's here! I am super excited for this one as well. Direct reach into VPCs fro AWS Step Functions or Amazon EventBridge. I will talk about this tomorrow in my API402 session. Bright and early! aws.amazon.com/blogs/aws/se...
Securely share AWS resources across VPC and account boundaries with PrivateLink, VPC Lattice, EventBridge, and Step Functions | Amazon Web Services
Orchestrate hybrid workflows accessing private HTTPS endpoints - no more Lambda/SQS workarounds. EventBridge and Step Functions natively support private resources, simplifying cloud modernization.
aws.amazon.com
December 2, 2024 at 6:42 AM
🤝 We're proud to be a launch partner with #AWS on their new capability: AWS PrivateLink support for VPCs! Learn how it works in this blog post.
Extend SaaS Capabilities Across AWS Accounts Using AWS PrivateLink support for VPC Resources | Amazon Web Services
In this post, we explore how you can use AWS PrivateLink support for Virtual Private Cloud (VPC) resources to facilitate private, secure, and efficient connectivity to shared resources across VPC and…
aws.amazon.com
December 3, 2024 at 10:06 PM
"Fn::GetStackOutput — Référencer les outputs CloudFormation entre comptes AWS" by Sylvain BRUAS

#aws-cloudformation #amazon-vpc #vpc #multi-account #iam
Fn::GetStackOutput — Référencer les outputs CloudFormation entre comptes AWS
Subtitle: Fn::GetStackOutput référence les outputs d'autres stacks CloudFormation sans export, même en cross-compte : idéal pour le VPC partagé.
community.aws
September 25, 2026 at 7:30 AM
Amazon EventBridge and AWS Step Functions now support integration with private APIs through AWS PrivateLink and Amazon VPC Lattice, enabling secure and simplified connectivity across public and private networks.
Amazon EventBridge and AWS Step Functions announce integration with private APIs
Amazon EventBridge and AWS Step Functions now support integration with private APIs through AWS PrivateLink and Amazon VPC Lattice, enabling secure and simplified connectivity across public and private networks.
aws-news.com
December 2, 2024 at 3:52 AM
Ok, a while back I created a video showing how #StepFunctions and #EventBridge can call private endpoints in a VPC WITHOUT using a proxy. My buddies Pawan and Vamsi created a blog to help out! aws.amazon.com/blogs/comput...
Simplifying private API integrations with Amazon EventBridge and AWS Step Functions | Amazon Web Services
AWS announces new integration capabilities for Amazon EventBridge and AWS Step Functions, enabling direct communication with private APIs using AWS PrivateLink and Amazon VPC Lattice. This enhancement...
aws.amazon.com
March 27, 2025 at 10:07 PM
This article explains how to configure domain-level VPC networking in Amazon SageMaker Unified Studio to automatically apply consistent network settings across all projects.
Configure domain-level VPC networking in Amazon SageMaker Unified Studio
This article explains how to configure domain-level VPC networking in Amazon SageMaker Unified Studio to automatically apply consistent network settings across all projects.
aws-news.com
September 23, 2026 at 6:39 PM
HOLY SHIT CLOUDFRONT IS GETTING ALL THE UPDATES

Introducing CloudFront VPC origins: https://buff.ly/3ATKYr8
Native CloudWatch Logs: https://buff.ly/4g0m9J3
CloudFront now supports gRPC delivery: https://buff.ly/4fZrhx5
Anycast IP addresses: https://buff.ly/4hVrD9H

🤯 🤯
Introducing Amazon CloudFront VPC origins: Enhanced security and streamlined operations for your applications
Amazon CloudFront now supports VPC origins, allowing content delivery from applications in private subnets while enhancing security and simplifying operations ...
aws-news.com
November 20, 2024 at 10:25 PM
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery

https://aws.amazon.com/identity/federation/outbound-federation/ now supports Amazon Virtual Private Cloud (VPC) endpoints for the OpenID Connect (OIDC) disco...

#AWS #AwsIdentityAndAccessManagement #AwsIam
AWS IAM outbound identity federation now supports interface VPC endpoints for OIDC discovery
https://aws.amazon.com/identity/federation/outbound-federation/ now supports Amazon Virtual Private Cloud (VPC) endpoints for the OpenID Connect (OIDC) discovery APIs. You can now access the OIDC discovery metadata and JSON Web Key Set (JWKS) verification key endpoints from within your VPC using https://aws.amazon.com/privatelink/, without requiring traffic to traverse the public internet. IAM outbound identity federation eliminates the need to use long-lived credentials when your AWS workloads access external services. Instead, your workloads request short-lived JSON Web Tokens (JWTs) from AWS Security Token Service (AWS STS). External services verify these tokens using public verification keys and metadata available at OIDC discovery endpoints. Previously, the OIDC discovery endpoints were only reachable over the public internet, so a verifying workload running in a VPC without internet access could not retrieve them. With this launch, you can create an interface VPC endpoint to reach these endpoints privately, keeping the verification key retrieval traffic within the AWS network. This capability helps you meet network security requirements for workloads that operate in VPCs with restricted internet access, while still enabling external services to verify JWTs. This feature is available in all commercial AWS Regions, the AWS GovCloud (US) Regions, and China Regions. There is no additional charge for this feature beyond standard https://aws.amazon.com/privatelink/pricing/. To learn more, see the https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_sts_oidc_vpc_endpoint_create.html.
aws.amazon.com
September 25, 2026 at 10:05 PM