Skip to content

AWS What's New — Networking

Networking-related items from AWS What's New, automatically summarized every weekday morning. Follow each link for the original announcement. Most recent items appear first.

2026-07-29 · Daily update

  • Amazon EKS Now Supports AWS PrivateLink for the Cluster OIDC Endpoint — Amazon EKS now allows the cluster OIDC discovery and JWKS endpoints used by IAM Roles for Service Accounts (IRSA) to be reached privately from within a VPC via AWS PrivateLink, eliminating the need for internet egress. Tools such as eksctl, Terraform, or custom token validators can access the OIDC discovery document and JWKS by creating an interface VPC endpoint.

2026-07-28 · Daily update

  • Amazon Neptune Now Supports Tag-Based Access Control for IAM — Amazon Neptune Database now supports tag-based access control (TBAC) for IAM, allowing administrators to use AWS resource tags and IAM principal tags as conditions in IAM policies and SCPs to govern data-plane access. This enables dynamic, attribute-based enforcement of organizational access boundaries across multiple clusters at scale without enumerating individual cluster ARNs.

2026-07-24 · Daily update

  • Amazon CloudWatch Logs Now Supports Application Load Balancer Logs — Amazon CloudWatch Logs now supports ALB access, connection, and health check logs as vended logs, enabling direct analysis of traffic patterns and target health within CloudWatch. Telemetry enablement rules allow automatic logging configuration for both existing and newly created ALB resources, streamlining network troubleshooting.
  • Amazon EVS Now Available in Additional Regions — Amazon Elastic VMware Service (Amazon EVS) is now available in the Asia Pacific (Seoul), Europe (Zurich), and Europe (Stockholm) Regions, expanding options for running VMware Cloud Foundation directly within Amazon VPC on AWS Nitro-powered EC2 bare-metal instances. This regional expansion enables faster VMware workload migration to AWS in more geographies.
  • G7e Instances on SageMaker AI Inference Expand to Additional Regions — Amazon EC2 G7e instances are now available for Amazon SageMaker AI inference in Asia Pacific (Seoul), Europe (London), and Asia Pacific (Tokyo), offering up to 1,600 Gbps of Elastic Fabric Adapter networking bandwidth and up to 2.3x inference performance over previous-generation G6e instances. This expansion allows customers to deploy inference endpoints closer to end users across Asia and Europe.
  • Amazon SageMaker AI Inference Now Supports G7 Instances — Amazon SageMaker AI inference now supports G7 instances powered by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs, delivering up to 4.6x AI inference performance compared to previous-generation G6 instances. With 32 GB of GPU memory per GPU, G7 instances enable cost-effective serving of medium-to-large generative AI models without over-provisioning or model quantization.

2026-07-23 · Daily update

  • AWS Network Load Balancer Now Supports Listener Rules for Custom Traffic Routing — Network Load Balancer (NLB) now supports listener rules that route connections to different target groups based on source IP address type. A single dual-stack NLB can direct IPv6 client traffic to IPv6 targets and IPv4 client traffic to IPv4 targets, preserving the original client IP address end-to-end for both address families.
  • Amazon EKS Now Supports EFA and Placement Groups on EKS Auto Mode and Karpenter — Amazon EKS now supports EC2 placement groups and Elastic Fabric Adapter (EFA) network device configuration for node pools on EKS Auto Mode and the open-source Karpenter project. This enables fine-grained control over network interface configuration and physical instance placement, optimizing distributed training and inference workloads for performance and availability.
  • AWS Direct Connect Announces 100G Expansion in Lima, Peru — AWS has expanded 100 Gbps dedicated connections at the existing AWS Direct Connect location in the Cirion data center in Lima, Peru. This marks the first Direct Connect location in Peru to offer 100 Gbps connections with MACsec encryption, providing private network access to all public AWS Regions (excluding China), AWS GovCloud Regions, and AWS Local Zones.

2026-07-22 · Daily update

  • Amazon EC2 R6in and R6idn Instances Now Available in Additional Regions — Amazon EC2 R6in and R6idn instances are now available in the Europe (Paris) and Canada (Central) regions. These sixth-generation network-optimized instances deliver up to 200 Gbps of network bandwidth and up to 2x higher packet-processing performance compared to fifth-generation equivalents.
  • Amazon EC2 C6in Instances Now Available in Asia Pacific (Taipei) Region — Amazon EC2 C6in instances are now available in the Asia Pacific (Taipei) region, offering up to 200 Gbps of network bandwidth—2x more than comparable fifth-generation instances. These sixth-generation network-optimized instances are suited for workloads such as network virtual appliances, Telco 5G UPF, and high-performance data analytics.
  • Amazon EC2 M6in and M6idn Instances Now Available in Additional Regions — Amazon EC2 M6in and M6idn instances are now available in the Asia Pacific (Hyderabad) and South America (São Paulo) regions. These sixth-generation network-optimized instances provide up to 200 Gbps of network bandwidth, doubling the throughput of fifth-generation instances for network-intensive workloads.
  • Amazon ECS Advanced Deployment Strategies Now Available in AWS European Sovereign Cloud — Amazon ECS now supports built-in blue/green, linear, and canary deployment strategies in the AWS European Sovereign Cloud, enabling safer and faster updates for containerized applications. These capabilities eliminate the need for custom deployment tooling by providing production-ready controls such as deployment lifecycle hooks, bake time, and quick rollback.

2026-07-21 · Daily update

  • Selectively Log Network Activity Events by Identity in AWS CloudTrail — AWS CloudTrail now supports IAM user identity-based filtering for VPC endpoint network activity events. This allows customers to log only relevant events—such as access denied attempts from unknown identities—reducing logging costs and noise while maintaining visibility into unauthorized access.
  • Announcing General Availability of a New AWS Local Zone in Athens, Greece — AWS has launched a new Local Zone in Athens, Greece—the second in EMEA to support Amazon S3 and Amazon EBS Local Snapshots—enabling customers to store and process data within Greece to meet local data residency requirements. The zone supports Amazon EC2 with C7i, M7i, and R7i instances along with Amazon S3 and Amazon EBS storage options.
  • Introducing KNFSD File Cache – Now in Preview — AWS has released KNFSD File Cache in preview, an open-source (Apache 2.0) solution for deploying a scalable, high-speed NFS cache on AWS. It mounts exports from on-premises filers, other AWS Availability Zones or Regions, or multicloud environments via AWS Interconnect, and re-exports them to NFS clients within AWS to improve file access performance.

2026-07-17 · Daily update

  • Amazon CloudWatch Logs Insights Adds 25 New Query Commands and Functions — Amazon CloudWatch Logs Insights now supports 25 new commands and functions, including type conversion and encoding functions (hexToAscii, decToHex), date/time functions (parseDate, formatDate), statistical aggregation, null handling, time-window comparison, outlier detection, and lookup-based event enrichment. These additions significantly improve log analysis capabilities, enhancing observability for networking operations.

2026-07-16 · Daily update

  • Amazon EC2 G7e Instances Now Available in Additional Regions — Amazon EC2 G7e instances powered by NVIDIA RTX PRO 6000 Blackwell Server Edition GPUs are now available in the Europe (Frankfurt, Stockholm) and Asia Pacific (Mumbai) regions. They deliver up to 2.3x inference performance over G6e, supporting LLM, generative AI, and spatial computing workloads.
  • Amazon RDS and Aurora Now Support R8g and M8g Database Instances in Additional AWS Regions — AWS Graviton4-based R8g and M8g database instances are now generally available for Amazon Aurora and Amazon RDS across additional regions, including Asia Pacific, Europe, South America, and AWS GovCloud. This expansion gives more customers access to Graviton4's improved performance and cost efficiency for database workloads.
  • AWS Elastic Disaster Recovery Reduces Recovery Time for AWS-to-AWS Workloads — AWS Elastic Disaster Recovery (AWS DRS) now skips unnecessary preparation steps for source servers running on Amazon EC2, reducing recovery time by up to 65% for Windows and up to 40% for Linux. Since AWS-based workloads already include compatible drivers and configurations, applications can be brought back online faster during a disaster or drill.
  • Amazon CloudWatch Announces Lookup Processor for Log Enrichment — Amazon CloudWatch now supports a lookup processor that enriches log events by matching log fields against a CSV-based lookup table within a CloudWatch Pipeline. For example, customers can automatically tag VPC Flow Logs with team ownership information by uploading a CSV that maps IP addresses to application teams.
  • Amazon EC2 M8in, M8idn, M8ib, M8idb Instances Now Available in Additional Regions — Amazon EC2 M8in and M8idn network-optimized instances, along with M8ib and M8idb EBS-optimized instances, are now available in the US East (Ohio), Europe (Ireland), and Asia Pacific (Tokyo) regions. Powered by sixth-generation Intel Xeon Scalable processors and the latest AWS Nitro cards, M8in and M8idn deliver up to 600 Gbps network bandwidth and up to 43% higher performance than previous-generation instances.

2026-07-15 · Daily update

  • Amazon Managed Service for Apache Flink Now Offers AI Agent Skills for Building and Operating Flink Applications — Amazon Managed Service for Apache Flink has launched AI Agent Skills that provide AI coding assistants with expert, up-to-date guidance for common tasks such as application creation, troubleshooting, scaling, monitoring, networking configuration, and cost optimization. The skills also simplify upgrades to the latest Apache Flink versions, including Flink 2.2.
  • Amazon CloudFront Functions Now Supports Logging to CloudFront Access Logs — Amazon CloudFront Functions now allows custom data to be written directly into CloudFront access logs via the new cf.logCustomData() helper method, available in viewer request and viewer response functions. This eliminates the need to correlate function decisions across separate logging systems, as function log data no longer needs to be cross-referenced with CloudWatch Logs.

2026-07-11 · Daily update

  • Amazon EC2 R8in, R8ib, R8idn, and R8idb Instances Now Available in Additional Regions — Amazon EC2 R8in, R8ib, R8idn, and R8idb instances are now available in the Asia Pacific (Tokyo) and Europe (Frankfurt, Ireland) regions. Notably, R8in and R8idn instances offer 600 Gbps network bandwidth, the highest among enhanced networking EC2 instances.
  • Amazon EC2 G7 Instances Now Available in the AWS US East (N. Virginia) Region — Amazon EC2 G7 instances, powered by NVIDIA RTX PRO 4500 Blackwell Server Edition GPUs, are now available in the US East (N. Virginia) Region. They deliver up to 4.6x AI inference performance and up to 2.1x graphics performance compared to G6 instances, making them suitable for AI model deployment and GPU-accelerated workloads.
  • AWS DMS Schema Conversion Now Supports Offline SQL Server Conversion — AWS DMS Schema Conversion now supports offline source conversion for Microsoft SQL Server, allowing schema migrations without direct connectivity to source databases. This removes the need for security reviews, firewall changes, or VPN setup, making it well-suited for organizations with strict security policies.
  • Amazon EC2 I8g Instances Now Available in AWS GovCloud (US) Regions — Amazon EC2 Storage Optimized I8g instances are now generally available in AWS GovCloud (US East and US West) regions. Powered by AWS Graviton4 processors and third-generation AWS Nitro SSDs, they deliver up to 60% better compute performance and up to 50% lower storage I/O latency compared to the previous-generation I4g instances.

2026-07-10 · Daily update

  • AWS Client VPN Expands Availability to Four Additional AWS Regions — AWS Client VPN is now available in four new regions: Canada West (Calgary), Mexico (Central), Asia Pacific (New Zealand), and Asia Pacific (Taipei). This fully managed service allows remote workforces to securely connect to AWS and on-premises resources without requiring hardware VPN appliances.
  • AWS Config Now Supports 191 Additional Managed Rules — AWS Config has added 191 new managed rules covering key services such as Amazon Bedrock, Amazon SageMaker, Amazon ECS, Amazon EKS, and Amazon RDS. The new rules evaluate resource configurations for encryption, logging, public access, network security, and data protection, broadening governance coverage across AI workloads and core cloud infrastructure.

2026-07-09 · Daily update

  • AWS Security Hub Now Offers Network Scanning to Identify Publicly Reachable Resources — AWS Security Hub has introduced Network Scanning, a capability that actively probes resources from the internet to detect actual public reachability—going beyond analysis based on security group rules and route tables. It identifies exposed public IPs, virtual machines, load balancers, open ports, and running services across AWS and Azure environments.

2026-07-08 · Daily update

  • Amazon EC2 C8ine Instances Now Available in AWS Europe (Frankfurt) Region — Amazon EC2 C8ine instances are now available in the AWS Europe (Frankfurt) region, powered by custom sixth-generation Intel Xeon Scalable processors and the latest AWS Nitro cards. They deliver up to 43% higher performance than the previous C6in generation, with up to 2.5x better packet performance per vCPU and up to 2x higher network throughput for internet gateway traffic.
  • AWS Introduces Declarative Controls for VPC Encryption Controls — AWS now supports declarative policies to enable VPC Encryption Controls in monitor or enforce mode across all VPCs, allowing centralized management at the account, organization, or organizational unit level. This simplifies auditing and enforcement of in-transit encryption within and across Amazon VPCs, helping demonstrate compliance with standards such as HIPAA, FedRAMP, and PCI.

2026-07-07 · Daily update

  • Amazon EVS Now Supports VCF 9.0 and 9.1 — Amazon Elastic VMware Service (EVS) now supports VMware Cloud Foundation (VCF) 9.0 and 9.1, allowing customers to run the latest VCF software directly within their Amazon VPC on EC2 bare-metal instances. Users can manage their VCF environments using the same tools and processes they already use in their on-premises data centers.

2026-07-03 · Daily update

  • AWS Config Now Supports 8 New Resource Types — AWS Config expands its coverage with 8 additional resource types across Amazon API Gateway, Amazon EC2, and Amazon S3 Vectors, enabling broader discovery, assessment, auditing, and remediation. Environments with all-resource-type recording enabled will automatically track these new additions, which are also available in Config rules and Config aggregators.

2026-07-02 · Daily update

  • ECS Service Connect Now Supports Zone-Aware Routing — Amazon ECS Service Connect now supports zone-aware routing, automatically prioritizing service-to-service traffic within the same AZ to reduce cross-AZ data transfer costs and latency. Traffic weights are dynamically adjusted as endpoints scale to maintain balanced load across target services.
  • Amazon ECS Express Mode Now Supports Custom Task Definitions — Amazon ECS Express Mode now supports custom task definitions, allowing teams to reuse existing task definitions from CI/CD pipelines and IaC workflows within Express Mode's simplified deployment experience. This enables organizations to retain established operational practices while benefiting from Express Mode's streamlined infrastructure automation.
  • AWS Network Firewall Now Supports Container Attribute-Based Inspection for Amazon EKS and Amazon ECS — AWS Network Firewall now supports container attribute-based rules, enabling firewall policies to be written using native constructs such as Namespace, Cluster Name, and Labels for Amazon EKS, and Cluster Name and Container Instance Attributes for Amazon ECS. This eliminates the need to manage complex IP-based rules that break when pods scale or restart, simplifying security for containerized workloads.
  • AWS Announces AWS Interconnect - Last Mile New Partner with AT&T in Gated Preview — AWS has launched AWS Interconnect - last mile in gated preview with AT&T, a fully managed connectivity offering that lets customers connect branch offices, data centers, and remote locations to AWS with just a few clicks. Customers can instantly establish private, high-speed connections by selecting their preferred AWS Region, bandwidth, and Direct Connect Gateway, eliminating the complexity of traditional network setup.

2026-07-01 · Daily update

  • AWS CloudFormation and CDK Express Mode Speeds Up Infrastructure Deployments by Up to 4x — AWS CloudFormation and CDK express mode cuts deployment time by up to 4x by completing stack operations as soon as resource configuration is applied, skipping extended stabilization checks such as traffic readiness and region propagation. This enables faster iteration cycles for developers and AI agents building infrastructure in development environments.
  • AWS Parallel Computing Service Supports In-Place Slurm Major Version Upgrades — AWS Parallel Computing Service (PCS) now supports managed in-place Slurm major version upgrades, allowing clusters to advance up to three major versions without disrupting running jobs. PCS handles the upgrade of all managed Slurm components—controller, accounting database, and REST API—while queued jobs resume automatically once the operation completes.
  • Announcing Capability Insights for AWS, an Open-Source Solution for Regional Capabilities — AWS has launched Capability Insights, an open-source self-hosted dashboard that lets organizations deploy regional capabilities data inside their own Amazon VPC. The solution is designed for teams with data residency requirements, compliance reporting needs, or multi-Region expansion and recovery planning.
  • AWS Security Hub CSPM Launches AI Security Best Practices Standard with 31 Automated Controls — AWS Security Hub CSPM has introduced the AI Security Best Practices standard, comprising 31 automated controls that continuously evaluate Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker workloads against recommended security configurations. The standard covers critical domains including network isolation and encryption, eliminating the need for manual assessments or custom rule authoring.

2026-06-30 · Daily update

  • Amazon MWAA Serverless Now Supports Shared VPC Configurations — Amazon MWAA Serverless now supports VPC subnets shared via AWS RAM, resolving a validation error that previously blocked workflow creation in shared VPC setups. This enables organizations using centralized networking in multi-account landing zone architectures to deploy MWAA Serverless workflows on shared subnets, consistent with MWAA Provisioned environments.

2026-06-23 · Daily update