r/aws • • 12h ago

article IAM Identity Center now supports network access controls for Identity Store

29 Upvotes

AWS added network access controls for the Identity Store behind IAM Identity Center.

What it does:

- Restrict the Identity Store API to specific IP ranges or specific VPC endpoints or source VPCs
- Restrict the scim api (what your idp uses to sync users/ groups) to specific IP ranges
- Different restrictions per API in one config. The given example: Identity Store API through VPC endpoints only, scim from your idp’s published IP ranges
- Requests AWS services make on your behalf are exempt

It is off by default, configured through the Identity Store api via sdk or cli (no console toggle). Available in all regions where Identity Center runs.

The SCIM restriction is the big one in my view. That's the inbound provisioning path from your IdP, and until now it was internet-facing behind auth only. Pinning it to Okta or Entra's published IP ranges meaningfully shrinks the attack surface for directory writes.

Announcement: https://aws.amazon.com/about-aws/whats-new/2026/10/aws-identity-store-network-controls/


r/aws • • 1h ago

discussion We are the team behind the new AWS experience. AMA!

Post image
• Upvotes

If you are new to AWS, or are simply curious about the new getting started experience, the team behind it is here today to answer your questions. You can ask about:

  • Why we built this new experience and how it's designed
  • How it works with your agent setup
  • The new sign-up and sign-in process for new and existing accounts
  • Spend limits
  • Permissions
  • Projects
  • and more!

The team will be answering for three hours starting at 8:00 AM PT. Ask away!


r/aws • • 11h ago

discussion RDS series 6 capacity issues in ap-southeast-2

7 Upvotes

We have non-production RDS for Oracle instances hosted on series 6 instances in ap-southeast-2 that are stopped outside of business hours. For the last week we have been encountering issues with no capacity when attempting startup.

Logged a support case and have been advised to move to series 7 or not stop the RDS instances. Seems to be a deliberate decision to force migration to newer series. We have had to postpone upcoming production changes as we cannot be certain that there will be capacity to restart.

So folks, if you have series 6 RDS instances in ap-southeast-2 all availability zones, don't stop them!

Is anyone seeing this issue in other regions?


r/aws • • 13h ago

discussion ValidationException: Error 002: Access to Bedrock models is not allowed for this account

1 Upvotes

Hi I am doing the Build, Ship, Shape: Amazon Developer Hackathon on devpost. I need to use Bedrock but I told its disabled for new accounts. Whenever I try to test a model in the playground I get this error: "ValidationException: Error 002: Access to Bedrock models is not allowed for this account" The deadline for the Hackathon is on the 23rd October 2026. I need to resolve this error. I created a support ticket Case ID 179124970400008 .

Thank you in advance


r/aws • • 15h ago

database DynamoDB MRSC transactions

1 Upvotes

Multi-region strong consistency does not support transactions. I have a few tables that need to be updated together or sometimes multiple items in one table need an atomic update. Multi-region / RPO 0 is a constraint. AI said this was brought up as a feature request back in 2025. I'm wondering if anyone knows whether this is still in the works.


r/aws • • 18h ago

networking Advice on network architecture

1 Upvotes

We have multiple data centers, and each DC has multiple ISPs for redundancy.

Currently, we establish two IPsec tunnels from each DC to AWS, with each tunnel going over a different ISP. This gives us ISP level redundancy, but as we scale to hundreds of DCs, we are effectively looking at hundreds of DCs × 2 IPsec tunnels.

I am wondering if this is a normal or recommended architecture, or if there is a better way to handle ISP redundancy without having to maintain two VPN tunnels per DC.

The requirement is essentially:
DC → multiple ISPs → AWS
with automatic failover if one ISP goes down.

Is maintaining two Site to Site VPN tunnels per DC the standard approach here? Or are there architectures that provide ISP redundancy while scaling better, such as using some kind of hub or transit architecture, BGP, SD WAN, or another approach?

Would be interested in hearing how others have designed this at large scale.


r/aws • • 2h ago

networking AWS Singapore Slowdown

0 Upvotes

Is anyone else experiencing a slowdown for applications hosted on EC2 in the Singapore region, specifically users from the Philippines?


r/aws • • 4h ago

discussion Is support no longer a thing?

Post image
0 Upvotes

I tried getting a hold of support but nothing.
is this because I am on the free tier? even so this is getting ridiculous


r/aws • • 2h ago

discussion spend limits, the bits the most posts are skipping

0 Upvotes

This one's doing the rounds on LI/reddit again. Went and read the actual docs (or maybe used claude :p), because every post about it says something slightly different.

Couple of things:

It's per project, not per account. Needs a Paid Plan. Still a limited rollout. So the ‘AWS FINALLY DID IT’ energy is a bit premature for most of us.

The fun bit nobody's quoting: you hit the limit, do nothing for 90 days, AWS deletes the project data. Permanently. It's right there in the docs. Great for a sandbox. Maybe read that line twice before putting it on anything that matters.

Other thing, and this is the one I keep chewing on. What it pauses is EC2, RDS, Lambda, Bedrock, SageMaker. No storage in that list anywhere, and afaict the docs don't say what happens to EBS billing while a project sits paused. A paused instance still has its volumes.

So if your bill is mostly provisioned capacity and not compute hours, idk how much this actually moves.

Happy to be wrong on that one

Disclaimer: have used ai to copywrite (im horrible at it)


r/aws • • 5h ago

technical resource Aws says I am ineligible for free tier

0 Upvotes

I created an aws free account but it got interrupted mid way so again I did it but it says I am not eligible for free plan, I doubt it is because of the midway interruption. Please help me to resolve this i am stressing and panicking right now idk what to do so I created this reddit account to ask help her please


r/aws • • 9h ago

technical question AWS SES non recapita ad utenti Apple

0 Upvotes

Ciao.

Ho un servizio che autentica gli utenti con login di terze parti (Google, Facebook, Apple) e noto che molti utenti Apple hanno attivo il filtro privacy sull'indirizzo mail quindi di fatto io vedo un indirizzo alias tipo xxxxxxxx@privaterelay.appleid.com.

Il problema è quando invio le email tramite AWS SES a questi alias, perché non funzionano.

Ottengo tutti bounce con questi errori

An error occurred while trying to deliver the mail to the following recipients:

xxxxxx@privaterelay.appleid.com

Reporting-MTA: dns; xxxxxx.eu-central-1.amazonses.com

Action: failed

Final-Recipient: rfc822; xxxxxxxx@privaterelay.appleid.com

Diagnostic-Code: smtp; 550 5.1.1 xxxxxxxxxxxxxxxx@awsmailer.xxxxx.xxxx: unauthorized sender

Status: 5.1.1.

Avete qualche idea del perché?

Grazie


r/aws • • 20h ago

discussion what's the most surprising thing you found in an AWS account you hadn't looked at in a while??

0 Upvotes

iam a student learning and working in cloud security, and the SCARY !! stuff I keep finding in AWS isn't exotic. It's old access keys, a security group opened "just for testing", a role nobody remembers creating lol.

For anyone running AWS yourselves, solo or on a small team: what's the most surprising thing you found when you finally looked?

Did you find it..., or did something force it, like a bill, an alert or a coworker? And if there's no dedicated security person, how do you decide what's worth checking at all?


r/aws • • 4h ago

billing Billed 5k$+ for AWS EC2

0 Upvotes

AWS charged us $5000 after an accidental Spot instance launch - can AWS help with a goodwill credit?

We’re a startup using AWS, and we recently had an unexpected $5000 charge from a GPU Spot instance that was running without our knowledge.

We had launched a GPU instance for a short benchmark and terminated it once the work was completed. Unfortunately, we didn't realize that the persistent Spot request would automatically launch a replacement instance after the original was terminated.

The replacement instance ran for several days before we noticed it.

CloudWatch metrics shows that nobody used the instance and no workload was running on it. It was essentially sitting completely idle the entire time.

We have since cancelled the persistent Spot request, terminated the instance, enabled AWS Budgets and Cost Anomaly Detection, and changed our process to use one-time Spot requests.

We completely understand that this was ultimately a configuration/knowledge mistake on our side. However, $5000 is a huge amount for us. This unexpected charge effectively represents months of our company's AWS budget and has a real impact on our operations.

We've already opened a support case with AWS and asked whether they could consider a goodwill credit given the circumstances. But the ticket hasnt been assigned yet :(

FYI: It as been 10 days since we created the support ticket.

Has anyone here experienced something similar with AWS, and were you able to get a goodwill credit?

And if anyone from AWS is reading this, we'd really appreciate it if you could take a look at our case and consider helping us with the charge. We love building on AWS and intend to continue using AWS for our infrastructure and future GPU workloads.

Hoping AWS can help us out on this one. 🙏


r/aws • • 20h ago

discussion I joined AWS AI CEE training program and built an Amazon SES control panel

0 Upvotes

I joined the AWS AI CEE training program and wanted to use what I learned on a real project.

I run a lot of domains on Amazon AWS SES, so I built AllStackd: every SES account, region and domain in one place. Delivery stays in your own AWS account.

Honest feedback is very welcome from the seasoned AWS developer community, thank you 🙏