AWS Compute Blog
Category: Advanced (300)
Implementing customer managed keys for AWS Lambda durable functions with Terraform
Lambda durable functions checkpoint execution state to durable storage, and for regulated payment workloads that data is sensitive. This post shows how to configure a customer managed key in AWS KMS to encrypt durable execution data, define a least-privilege key policy, and verify encryption through AWS CloudTrail, all deployed with Terraform.
Frozen package management for air-gapped RHEL-family AMIs
Learn a serverless, two-account pattern for running regulated, air-gapped RHEL-family fleets on AWS. It separates connected package ingestion from the air-gapped workload, adds explicit human approval for package changes, and keeps EC2 Image Builder AMIs and Patch Manager on one frozen Amazon S3 repository snapshot.
Building event-driven applications at scale with Amazon EventBridge
Amazon EventBridge relaunched the Custom event bus so a platform team can share one governed bus across the organization while application teams publish and subscribe from their own accounts. See how retention, ordering, open formats, transformation, and direct target delivery change what one bus can carry.
Adding custom domains to AWS Lambda MicroVMs with Application Load Balancer
Many teams want to expose their AWS Lambda MicroVMs under a custom domain they own, and satisfy CORS for browser clients, without changing the application. This post shows how, using an Application Load Balancer that rewrites the Host header and forwards over AWS PrivateLink, deployed with the AWS CDK.
Running self-hosted AI agent sandboxes with AWS Lambda MicroVMs
Learn how to run AI agent tool calls in secure, isolated sandboxes using AWS Lambda MicroVMs. This post shows how to architect a self-hosted control plane that launches a fresh, VM-isolated MicroVM for each agent session, keeping credentials, networking, and governance entirely within your own AWS account.
Multi-modal autoscaling with Amazon EC2 Auto Scaling: adding signals for faster, more reliable scaling
Multi-modal autoscaling with Amazon EC2 Auto Scaling combines infrastructure metrics like CPU with application-level signals, so a group scales on the demand its users create. In this post, we show you how to implement it, with code samples and results from a controlled test.
Deploying regulated workloads on AWS Local Zones and AWS Outposts
AWS Local Zones and AWS Outposts help you keep regulated workloads within specific geographic boundaries. This post presents a framework of technologies, including the AWS Nitro System, AWS Organizations SCPs with AWS Control Tower, and Amazon VPC Traffic Mirroring, to help you build auditable, secure architectures for data residency.
Planning for disaster recovery using AWS Local Zones and AWS Outposts racks
Build highly available architectures that span two AWS Outposts racks, or an Outpost rack and an AWS Local Zone, without single points of failure. This post covers three disaster recovery approaches: DNS-based failover, active/active load balancing, and hybrid database replication, with the RTO/RPO trade-offs of each.
Architecting SASE solutions using AWS Local Zones
Organizations with geographically distributed workforces face a trade-off between security and low-latency access. This post explores how to use AWS Local Zones and Secure Access Service Edge (SASE) solutions to deploy virtual security appliances closer to end users, covering key design principles, capacity planning, and traffic routing.
Scheduling email campaigns at scale with Amazon EventBridge Scheduler
Learn how to use Amazon EventBridge Scheduler to deliver email campaigns at per-recipient optimal send times. This post shows how to create one schedule per recipient with zero idle compute cost, scale schedule creation with AWS Step Functions Distributed Map, and deliver through Amazon SES.









