Networking & Content Delivery

Salman Ahmed

Author: Salman Ahmed

Salman Ahmed is a Senior Technical Account Manager at AWS, specializing in helping customers design, implement, and optimize their AWS environments. He combines deep networking expertise with a passion for exploring emerging technologies to help organizations get the most out of their cloud investments. Outside of work, he enjoys photography, traveling, and watching his favorite sports teams.

Private AI agent with WebSocket streaming over CloudFront VPC Origins and the next generation of OpenSearch Serverless for knowledge retrieval

Reviewing partner contracts by hand is slow and repetitive, so teams want an AI agent to do the first pass. In the example used throughout this post, a company called Example Corp reviews incoming partner agreements against its own standard operating procedures. A partner uploads an agreement, the agent checks it against those procedures, and […]

Extending AWS DevOps Agent network investigations with S3 logs and custom MCP on Amazon Bedrock AgentCore

Your on-call engineer sees a 502 error on the AWS Application Load Balancer (ALB). The Amazon Elastic Compute Cloud (Amazon EC2) instance is running, status checks pass, and AWS CloudTrail shows no infrastructure changes. In this post, you learn how to extend AWS DevOps Agent investigations beyond API-level failures. You connect it to Amazon Simple […]

FeaturedImage-Automated network incident response with AWS DevOps Agent

Automated network incident response with AWS DevOps Agent

Your on-call engineer gets paged at 2 AM. A payment service in Workload Account cannot reach a shared database in Shared Services Account. The Amazon CloudWatch alarm fired eight minutes ago. The engineer starts by checking route tables across two accounts, Amazon Virtual Private Cloud (Amazon VPC) attachment states, security group rules on both sides, […]

Featured Image - Deploy VPC Block Public Access across AWS Organizations

Deploy VPC Block Public Access across AWS Organizations

Managing security configurations across hundreds or thousands of Amazon Web Services (AWS) accounts present significant challenges for enterprise organizations. Without centralized control, you face manual configuration across accounts, inconsistent security posture, and ongoing maintenance overhead when new accounts are created. When Amazon Virtual Private Cloud (Amazon VPC) introduced VPC Block Public Access (BPA) in November […]

Using cross-account CloudFront VPC origins for multi-account private API Gateway architecture

In November 2025, Amazon CloudFront introduced cross-account support for Virtual Private Cloud (VPC) origins, which allows you to keep Amazon VPC origins and CloudFront distributions in separate Amazon Web Services (AWS) accounts. In turn, organizations with multi-account strategies can use VPC origins while maintaining their desired account structure. This enables a new architectural pattern for […]

Introducing cross-account support for Amazon CloudFront Virtual Private Cloud (VPC) origins

In November 2024, Amazon CloudFront introduced CloudFront Virtual Private Cloud (VPC) origins, a security feature that allowed customers to deliver content from applications hosted in private subnets. In addition, we are now introducing cross-account support for Amazon CloudFront VPC origins, enabling network traffic flow between Amazon CloudFront and Application Load Balancers (ALBs), Network Load Balancers […]

Secure internet-based access to SaaS PrivateLink endpoints using AWS Verified Access

Introduction As cloud adoption grows, software-as-a-service (SaaS) providers on AWS are increasingly using Amazon Web Services (AWS) PrivateLink to securely deliver services to their customers. PrivateLink enables seamless, private connectivity between VPCs without exposing applications to the public internet, which makes sure of strong security and consistent network performance. However, what if you want to offer this […]

Streamlining multi-VPC DNS management with Amazon Route 53 Profiles and interface VPC endpoint integration

Managing DNS configurations across multiple VPCs and accounts requires thoughtful architectural planning, especially for organizations leveraging AWS PrivateLink interface endpoints for various AWS services. Organizations are continuously looking for ways to streamline these configurations while maintaining operational efficiency and security. For enterprises using Amazon Web Services (AWS) PrivateLink interface endpoints (such as AWS Lambda, Amazon […]

Introducing dual-stack and IPv6-only support for Amazon Route 53 Resolver Endpoints

Organizations are adopting IPv6 because of public IPv4 address and private IPv4 address (RFC1918) space exhaustion caused by the ongoing growth of the internet, particularly in the fields of mobile applications, Internet of Things (IoT), and application modernization. This is motivating many AWS customers to transition from IPv4-only to dual-stack (IPv4 and IPv6) and IPv6-only […]

Centralized outbound inspection architecture in AWS Cloud WAN

An update was made on October 15, 2024: With the release of Service Insertion for AWS Cloud WAN, customers can now create centralized inspection architectures without the need for static routes. Refer to the AWS Cloud WAN service documentation for service insertion for details. AWS Cloud WAN helps you build a unified network that connects […]