Runtime instances: persistent compute for production AI agents on Amazon Bedrock AgentCore
TutoSartup excerpt from this article:
When you move AI agents from prototype to production, the infrastructure challenges multiply... Your agents need to persist state across multi-step workflows that run for hours or days... They need to coordinate with other agents, share context, and sometimes access GPUs for specialized tasks... Some workloads also benefit from dedicated, larger-capacity environments — for example, when agents n...
When you move AI agents from prototype to production, the infrastructure challenges multiply... Your agents need to persist state across multi-step workflows that run for hours or days... They need to coordinate with other agents, share context, and sometimes access GPUs for specialized tasks... Some workloads also benefit from dedicated, larger-capacity environments — for example, when agents n...
Automate certificates with ACME support in AWS Certificate Manager
TutoSartup excerpt from this article:
Customers that are using third-party certificate authorities (CAs) can point their existing ACME-compatible clients at ACM instead of their current CA, with minimal reconfiguration... This launch brings the ACM automation model to that same infrastructure, using the standard ACME protocol with AWS managed certificate endpoints... How it works The feature introduces a new centrally provisio...
Customers that are using third-party certificate authorities (CAs) can point their existing ACME-compatible clients at ACM instead of their current CA, with minimal reconfiguration... This launch brings the ACM automation model to that same infrastructure, using the standard ACME protocol with AWS managed certificate endpoints... How it works The feature introduces a new centrally provisio...
Route Amazon Bedrock Guardrails interventions to Amazon Security Lake
TutoSartup excerpt from this article:
It transforms matching events into OCSF-compliant Detection Finding records (class_uid 2004) and delivers them to Security Lake as Parquet files... Guardrail interventions are detection events: the guardrail detected and blocked prohibited content, so OCSF class 2004 (Detection Finding) under the Findings category is the appropriate classification... The Lambda function transforms each interven...
It transforms matching events into OCSF-compliant Detection Finding records (class_uid 2004) and delivers them to Security Lake as Parquet files... Guardrail interventions are detection events: the guardrail detected and blocked prohibited content, so OCSF class 2004 (Detection Finding) under the Findings category is the appropriate classification... The Lambda function transforms each interven...
Securing AI agents with temporal policies in Amazon Bedrock AgentCore
TutoSartup excerpt from this article:
Before AI agents, it was generally sufficient for access controls to treat each action as an independent event... AI agents behave in fundamentally different ways than traditional applications... That flexibility, combined with increasingly intelligent models, makes agents equal measures capable and challenging to control... The question then becomes, how do you enforce authorization rules that ac...
Before AI agents, it was generally sufficient for access controls to treat each action as an independent event... AI agents behave in fundamentally different ways than traditional applications... That flexibility, combined with increasingly intelligent models, makes agents equal measures capable and challenging to control... The question then becomes, how do you enforce authorization rules that ac...
Configure rate limits for AI traffic on AgentCore gateway
TutoSartup excerpt from this article:
Today, we are announcing support for rate limiting on AgentCore gateway, giving you fine-grained control over how much traffic individual users can consume through your gateway... Rate limiting in AgentCore gateway gives you per-user control over how users consume your tools, inference models, and agents... Centralized rate limiting for AI traffic with AgentCore gateway AgentCore gateway provi...
Today, we are announcing support for rate limiting on AgentCore gateway, giving you fine-grained control over how much traffic individual users can consume through your gateway... Rate limiting in AgentCore gateway gives you per-user control over how users consume your tools, inference models, and agents... Centralized rate limiting for AI traffic with AgentCore gateway AgentCore gateway provi...
Control agent behaviors and cost beyond a single action: new capabilities in Amazon Bedrock AgentCore
TutoSartup excerpt from this article:
According to McKinsey, roughly 80% of organizations have already encountered risky behavior from AI agents... As a result, security and risk concerns are the leading barrier to scaling agentic AI (McKinsey’s State of AI Trust in 2026, and Trust in the age of AI agents 2026)... That makes trust the pacing factor for agent innovation and adoption... We believe that investment in trust and securi...
According to McKinsey, roughly 80% of organizations have already encountered risky behavior from AI agents... As a result, security and risk concerns are the leading barrier to scaling agentic AI (McKinsey’s State of AI Trust in 2026, and Trust in the age of AI agents 2026)... That makes trust the pacing factor for agent innovation and adoption... We believe that investment in trust and securi...
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
TutoSartup excerpt from this article:
By rethinking how they cache encryption keys, they reduced their AWS Key Management Service (AWS KMS) costs by 77% while maintaining strict security guarantees and per-tenant encryption isolation... In this post, we explore the cache stampede problem that emerges when envelope encryption meets high-concurrency, multi-tenant architectures... The cache stampede problem Envelope encryption r...
By rethinking how they cache encryption keys, they reduced their AWS Key Management Service (AWS KMS) costs by 77% while maintaining strict security guarantees and per-tenant encryption isolation... In this post, we explore the cache stampede problem that emerges when envelope encryption meets high-concurrency, multi-tenant architectures... The cache stampede problem Envelope encryption r...