Networking & Content Delivery
How AWS unified its routing control plane to improve network availability and performance
Why the routing control plane matters Every time you make an API call to an AWS service, stream video through Amazon CloudFront, or resolve a domain name through Amazon Route 53, your traffic traverses AWS’s border network. Spanning 39 Regions, 123 Availability Zones, and over 750 Points of Presence across six continents at the time […]
When and how to centralize AWS PrivateLink Interface endpoints with Amazon VPC Lattice
In large multi-account AWS environments, teams need to centralize AWS PrivateLink interface endpoints for services by often provisioning the same endpoints separately in each Amazon Virtual Private Cloud (Amazon VPC). As the number of VPC and accounts grow, this leads to added endpoint costs, inconsistent endpoint policies and operational overhead. With centralized endpoints, you provision […]
Reduce Traffic Interruptions with Gateway Load Balancer TCP Reset
When a firewall or security appliance behind your Gateway Load Balancer (GWLB) fails, what happens to the TCP connections flowing through it, and how long do those traffic interruptions last? Until today, they could hang while TCP retry mechanisms and exponential backoff ran their course, sometimes for minutes. For mission-critical applications, every second of interruption […]
Implementing encryption in transit across connectivity patterns with VPC Encryption Controls
Security and compliance teams managing modern cloud environments often ask us: “How do we enforce encryption in transit across every network path? Can we put in place policies that restrict teams from sending unencrypted traffic between any two nodes?”. Your environment likely includes a mixed fleet of Amazon Elastic Compute Cloud (Amazon EC2) instances across […]
AWS and Microsoft Azure collaborate to expand multicloud networking
As organizations embrace multicloud strategies at an accelerating pace, the ability to move workloads seamlessly between cloud providers has become essential. Yet establishing resilient, high-performance private connectivity between clouds has historically required customers to navigate complex and diverse physical infrastructure, multiple connectivity providers, and invest weeks or months of manual provisioning. Starting today, customers can […]
Building Multi-Region Active-Active Architectures with CloudFront VPC origins and Advanced Routing
Introduction Building a multi-region active-active architecture with Amazon CloudFront requires careful coordination of traffic routing to address performance, traffic management, and session consistency requirements, along with automated failover to maintain availability during regional events. In November 2024, AWS released Amazon CloudFront VPC origins, which provides direct connectivity to private resources within your Amazon VPC without […]
CloudFront Functions Unified Logging
CloudFront Functions (CF2) lets you run lightweight code inside Amazon CloudFront Points-of-Presences (POPs) to analyze and manipulate viewer requests and responses at scale. Until now, gaining visibility into the decisions your functions made such as the result of a token validation or logging a header returned from origin required collecting the header from CloudFront Realtime […]
Shared DNS views for multi-account environments with Amazon Route 53 Global Resolver
DNS views in Amazon Route 53 Global Resolver give networking teams centralized control over shared name resolution, but application teams still need the freedom to manage their own DNS records. Striking that balance gets harder with multi-account architecture and as services grow. Amazon Route 53 Global Resolver addresses centralized resolution piece by delivering a single […]
Gain visibility into client-side network failures with NEL
When your user experiences a connectivity issue visiting your website, it’s unlikely that you’ll see a trace of it in your server logs. DNS resolution failures happen before your user ever connects to your server. TCP timeouts, on shared infrastructure such as Content Delivery Networks (CDNs), are difficult to attribute to a specific origin. Even […]
Zero-trust networking for agentic AI with Amazon VPC Lattice
Your most sensitive data—patient records, financial data, classified documents—lives in a private Amazon Virtual Private Cloud (Amazon VPC) with no internet access, and for good reason. That network isolation is a deliberate security posture, not an oversight. The problem is that your AI agents need to reason over that data, and traditional networking approaches force […]









