bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Monday, August 10, 2026

AWS IAM Account Access Manager: Flexible Role Assignment Just Got Easier

AWS Identity and Access Management rolled out account access manager, letting admins assign IAM roles directly to workforce users through IAM Identity Center—no extra cost, available across all AWS Commercial Regions. This bridges the gap between centralized federation and granular IAM role flexibility, giving you the best of both worlds without the usual trade-offs.

source: [aws/whats-new]

Amazon OpenSearch Serverless Scales to 10,000 Collections Per Group

Amazon OpenSearch Serverless just bumped its collection limit from 1,500 to 10,000 per collection group, letting you pack way more multi-tenant workloads into a single shared compute pool. This means better cost efficiency and resource utilization across all AWS Regions where nextgen OpenSearch Serverless is available—perfect for scaling those tenant-per-collection architectures without spinning up extra infrastructure.

source: [aws/whats-new]

also that day:

Friday, August 7, 2026

Amazon Cognito Joins Agent Toolkit for AWS – Your AI Can Now Handle Auth

Amazon Cognito is now available as a core skill in the Agent Toolkit for AWS, letting AI coding agents set up, configure, and troubleshoot authentication workflows automatically. This means faster implementation of secure sign-in flows for users, AI agents, and microservices—with best-practice patterns baked in, including OAuth 2.0, passkeys, and threat protection.

source: [aws/whats-new]

Amazon ECS Now Lets You Slice GPUs Into Smaller Pieces

Amazon ECS now supports fractional GPU scheduling on EC2 G6f instances, letting you run AI inference and graphics workloads on GPU partitions as small as one-eighth of an NVIDIA L4 GPU (3 GB memory) by setting GPU=0.125, 0.25, or 0.5 in your task definition. This capability is live across all AWS Regions where G6f instances are available, helping you cut infrastructure costs by right-sizing containers instead of provisioning full GPUs.

source: [aws/whats-new]

also that day:

Thursday, August 6, 2026

Amazon DocumentDB MCP Server: Authorization Bypass in Aggregation Pipeline

Amazon DocumentDB MCP Server versions below 1.0.12 have a nasty authorization flaw (CVE-2026-18954). Write-capable aggregation stages like $out and $merge can bypass read-only enforcement, letting authenticated clients sneak write operations past security controls. If you're running this open-source tool, upgrade immediately—this one requires your attention.

source: [aws/security-bulletin]

also that day: