Networking & Content Delivery
Cross-account canary routing with Amazon VPC Lattice and Amazon API Gateway
Modernizing a monolith into microservices may require placing each new service in its own AWS account for isolation, independent scaling, and clear ownership. During that migration you hit a hard question: how do you shift a small, precise slice of live traffic from the monolith to a new service in a different account? You need […]
Provisioning AWS Interconnect – multicloud with the Kiro agentic IDE
Multicloud is no longer an edge case. Workloads end up spanning AWS and Google Cloud, Microsoft Azure, or Oracle Cloud Infrastructure after an acquisition, through a footprint that predates any consolidation decision, or because a key vendor operates on the other cloud. Sooner or later a network engineer gets the task: connect two environments privately […]
Powering predictable costs with AWS Direct Connect flat-rate pricing
In a traditional on-premises network, predictable costs have always been central to network connectivity budgets. Organizations relied on leased lines, Multiprotocol Label Switching (MPLS) links, and dedicated cross-connects. No matter how much data they moved, the bill stayed the same. As they rebuilt their architecture in the cloud, they gained the flexibility of pay-as-you-go pricing. […]
Protect MCP Endpoints at the Edge with Amazon CloudFront and AWS WAF
AWS WAF gives you a practical way to secure and observe Model Context Protocol (MCP) endpoints at the edge. MCP has quickly become the standard way AI agents communicate to tools and data. Originally, it was a stateful protocol built around long-running sessions, persistent connections, and client-to-server-instance binding. The 2026-07-28 MCP revision redesigned MCP as […]
Simplify VPC Flow Logs with EC2 resource tags and next-hop metadata
In this post, we show you how to use Amazon Elastic Compute Cloud (Amazon EC2) resource tags and next-hop metadata, two new capabilities in Version 11 of Amazon Virtual Private Cloud (Amazon VPC) Flow Logs. These fields let you simplify network traffic analysis without building custom enrichment pipelines. Since the introduction of VPC Flow Logs […]
Routing UDP to on-premises Network Load Balancer targets
On-premises migrations to AWS rarely finish in one wave. Dependencies and competing priorities keep some workloads on premises: a virtual desktop gateway, an IPsec VPN headend, applications awaiting modernization. Those workloads can still use the AWS global network. Assume your users are in India and their virtual desktops live in North America. That is a […]
AI best practices for AWS network operations with AI agents and MCP
This post is for platform and SRE teams running 24/7 network operations who want AI Agents and Model Context Protocol (MCP) for intelligent, automated event response, and for individual engineers who want agentic diagnostics during development and triage. If you are in the first group, focus on AWS DevOps Agent, Amazon Bedrock AgentCore, and the […]
Choosing the right inspection architecture for AWS Network Firewall
Networking teams operating multi-VPC, multi-account environments need a consistent inspection architecture for compliance, threat detection, and traffic filtering. With the three deployment patterns now available for AWS Network Firewall (Traditional Inspection Amazon Virtual Private Cloud (Amazon VPC), Multiple VPC Endpoints launched May 2025, and Transit Gateway Native Attachment launched July 2025), a common question emerges: […]
When and how to centralize AWS PrivateLink Interface endpoints with Amazon VPC Lattice
In large multi-account AWS environments, teams need to centralize AWS PrivateLink interface endpoints for services by often provisioning the same endpoints separately in each Amazon Virtual Private Cloud (Amazon VPC). As the number of VPC and accounts grow, this leads to added endpoint costs, inconsistent endpoint policies and operational overhead. With centralized endpoints, you provision […]
Reduce Traffic Interruptions with Gateway Load Balancer TCP Reset
When a firewall or security appliance behind your Gateway Load Balancer (GWLB) fails, what happens to the TCP connections flowing through it, and how long do those traffic interruptions last? Until today, they could hang while TCP retry mechanisms and exponential backoff ran their course, sometimes for minutes. For mission-critical applications, every second of interruption […]









