AWS Cloud Operations Blog

Category: Management & Governance

Scaling AWS Governance: How Moeve reduced response times with automated notifications

Moeve, formerly known as Cepsa, is a global integrated energy company with over 90 years of experience and more than 11,000 employees. Moeve is committed to driving Europe’s energy transition and accelerating decarbonization efforts. The company has embraced digital transformation to enhance energy efficiency, safety, and sustainability, focusing on investments in green hydrogen, second-generation biofuels, […]

Simplify AWS Control Tower governance with enhanced AWS CloudFormation Hooks

Introduction Organizations using AWS Control Tower to govern their multi-account environments face a persistent challenge: when AWS CloudFormation deployments fail due to proactive control violations, teams receive minimal information about why the failure occurred or how to fix it. This lack of visibility leads to: Delayed deployments as developers struggle to understand cryptic error messages […]

Featured image for the blog post Deploying custom Terraform to LZA-Managed Accounts with AFT

Deploying custom Terraform to LZA-Managed Accounts with AFT

As organizations scale their AWS environments, managing infrastructure consistently while enabling team autonomy becomes increasingly challenging. Landing Zone Accelerator on AWS (LZA) and AWS Account Factory for Terraform (AFT) both extend AWS Control Tower to help customers manage AWS environments at scale, offering complementary strengths. Many AWS customers struggle to balance centralized security governance with […]

Investigating Service Issues with Amazon CloudWatch Application Signals Custom Metrics

Investigating Service Issues with Amazon CloudWatch Application Signals Custom Metrics

When a critical service fails, you need to know how much revenue you’re losing, not just that latency has increased. This post shows you how to integrate business metrics with CloudWatch Application Signals to see both technical performance and business impact in one unified view. With CloudWatch Application Signals, you can view metrics, traces, and […]

CrossRegionPrivateLinkNetworkSyntheticMonitor

Cross-Region AWS PrivateLink monitoring with Amazon CloudWatch Network Synthetic Monitor

Introduction Global, distributed AWS architectures are the backbone for customers seeking high availability, resilience, and regulatory compliance. Workloads are commonly deployed across multiple AWS Regions and Availability Zones (AZs), often using AWS PrivateLink to connect services securely and privately across Amazon Virtual Private Cloud (Amazon VPC) networks. This approach enhances security and separation while requiring […]

Search and discover governance controls with Control Catalog in AWS Control Tower

Search and discover governance controls with Control Catalog in AWS Control Tower

As you scale your AWS environment from hundreds to thousands of AWS accounts, maintaining consistent governance standards across this expanded infrastructure requires a strategic approach. Governance controls—the automated policies and rules that enforce standards across your cloud infrastructure—are essential for managing this scale, but implementing them presents two fundamental challenges. First, without proper controls, a […]

Troubleshoot AWS Tagging Compliance with AWS Resource Explorer

With AWS Resource Explorer’s immediate resource discovery launch on October 13, 2025, customers can now discover resources from their very first search in Unified Search in the AWS Management Console or the Resource Explorer console. Operations like troubleshooting and problem resolution, making resource changes, investigating resource dependencies, identifying security risks, and optimizing costs are critical […]

Amazon CloudWatch RUM now supports mobile application monitoring

Amazon CloudWatch RUM now supports iOS and Android applications, expanding real user monitoring beyond web applications. Developers and SREs can now quickly isolate mobile application issues and improve end-user experience, with visibility into performance metrics such as screen load times, crash rates, and API latencies.

Announcing AWS CloudTrail Event Aggregation and Insights for Data Events

AWS CloudTrail records API calls and events for your AWS account, providing audit trails for governance, compliance, and operational troubleshooting. Customers can also enable data events in CloudTrail to gain deeper visibility into resource-level operations. These include Amazon S3 object-level operations (such as GetObject/PutObject) or AWS Lambda function invocations. Data events help detect unauthorized access, […]

Enforce consistent tagging across IaC deployments with AWS Organizations Tag Policies

Enforce consistent tagging across IaC deployments with AWS Organizations Tag Policies

Organizations manage thousands of AWS resources across multiple accounts and Regions to support their business operations. They want consistent tagging to support essential workflows such as attribute-based-access-controls (ABAC), cost allocation, organizing resources by project/application/owner/environment, and triggering automated processes based on tag criteria. Many customers use Infrastructure as Code (IaC) tools like AWS CloudFormation, Terraform, and […]