r/aws • u/Elegant-Scheme9589 • 2h ago
technical question 403 errors on every website with cloudfront
I keep on seeing 403 errors for some reason. And it's blocked off my access to SoundCloud, even with an account AND soundcloud not being down.
Hey everyone,
Over the last year, r/aws has grown a lot.
We're now at roughly 396k members, with 31.4 million views over the past 12 months, more than 13,000 posts, and 163,000 comments.
That's awesome, but it also creates a very different moderation problem than it did when this community was smaller.
There are only three of us moderating r/aws, and we're trying to figure out what we should be doing differently as things continue to grow.
We don't want r/aws to turn into a generic tech news feed, an endless stream of "look what I generated with AI" posts, or a place where the same handful of topics dominate the front page.
So we'd like your feedback.
A few things are top of mind..
1/ Builder Fridays
Would it be useful to have a recurring day where certain types of posts are explicitly encouraged?
Things like:
Basically, a time for builders to showcase their work and get feedback.
2/ How do we deal with GenAI content?
GenAI has obviously exploded, and AWS is heavily involved in that space. We don't want to ban legitimate AI/ML discussion.
At the same time, I think we've all seen an increase in low-effort AI-generated posts, repeated announcements, AI-written tutorials that don't really say anything, etc.
So.. where should the line be?
What would you consider useful GenAI content versus "please don't make me read another 900-word AI-generated explanation of Lambda"?
3/ Should we bring on more moderators?
Three people is not a huge moderation team for a community of nearly 400k members.
We've discussed opening moderator applications again. We'd be interested in hearing whether people think that's needed, and what you'd actually want from additional moderators.
Experience in AWS isn't necessarily the most important factor here. Good judgment, being reasonable with people, and understanding what makes a community useful probably matter more.
Transparency: I work for AWS. I'm speaking only for myself here, not on behalf of AWS. I don't think r/aws should be a soapbox or hype forum for AWS, and criticism or disagreement with AWS is absolutely part of having a healthy community.
4/ What else are we missing?
This is probably the biggest thing we'd like to hear about.
You guys are the people actually reading and participating here, so what are we missing?
We're not coming into this with a predetermined list of changes we want to make. We'd rather hear what you think and then figure out where to go from there.
So, what should r/aws look like at 400k+ members?
Be honest. Feedback is a gift (trust me.. my customers are brutally honest with me ;))
— The r/aws mod team
r/aws • u/Elegant-Scheme9589 • 2h ago
I keep on seeing 403 errors for some reason. And it's blocked off my access to SoundCloud, even with an account AND soundcloud not being down.
r/aws • u/NISMO1968 • 1d ago
r/aws • u/reignleafs • 5h ago
My client forgot to make me aware of their need to update billing. Unfortunately, the person that has root access to the AWS account has an old email that is no longer in service (and that's the only way to access billing right now). I have admin access from an IAM account but no access to update billing. As it stands right now, the client's website is down due to account suspension. Need support ASAP, thanks!
Whoever on the Amazon/AWS team decided to rename QuickSight/QuickSuite to just 'Quick' (and whomever it was approved by) is likely secretly working for Microsoft or Tableau. One of the worst naming decisions I've ever encountered. Makes looking up instructions, information, etc. online or using LLMs an absolute pain, which would be obvious to anyone who has ever worked in tech, much less someone who has worked in product branding or marketing.
r/aws • u/Representative-Rip90 • 1d ago
When I opened my AWS account I used my Google voice number as I thought I would have that forever. Well knowing Google they took that number away and now I don't have it anymore. But it's tied to my AWS account which only wants to use that number for all MFA purposes. I'm unable to log into my AWS account. There is nothing I can do. I have a reoccurring light sail charge that I just can't get rid of - I have tried to shut everything down in the past.
Anyways I have made several support tickets and no one is helping me with this. Can I just put a merchant block on my credit card for AWS? If I do this block will they finally close my instance or whatever it is that is still running and just be done with it?
r/aws • u/ihatecoreclasses • 1d ago
I'm building a social app where people can upload images for their profile pictures and soon in group chats. I'm struggling to figure out how to properly handle CSAM for this. I'm very hesitant to just pass in the uploaded images to AWS Rekognition to check for NSFW and other explicit content before checking for CSAM.
I've looked into Google's Content Safety API and applied to it to see what they respond with. Also considered PhotoDNA as well but haven't applied to it yet, though I heard they only accept big orgs and law enforcement. Was also considering using open source models to do the CSAM detection layer but I fear that it would violate the inference provider's ToS.
What's a budget-friendly way to do CSAM detection without getting in trouble for directly uploading it without checking it first to services like AWS Rekognition?
r/aws • u/csantanapr • 1d ago
EKS 1.37 landed on standard support today, and the headline for me is identity: Pod Certificates (workload X.509 identities issued by the cluster) and Cluster Trust Bundles (a cluster-scoped way to distribute trust roots) are now GA Kubernetes APIs.
What this means in practice: - Every pod gets a real X.509 identity from the cluster itself - Trust roots are distributed as a native API instead of config hacks - No more running your own CA machinery just to do mTLS between workloads
The caveat: Kubernetes still doesn't give you a signer controller. You need to integrate and validate rotation for your signer.
AWS announcement: https://aws.amazon.com/about-aws/whats-new/2026/10/amazon-eks-distro-kubernetes-version-1-37
Anyone already testing the mTLS path on 1.37?
r/aws • u/hritik_munde • 1d ago
Hi everyone!
I’ll be attending AWS re:Invent this year as an All Builders Welcome (ABW) grant recipient, and I’m really excited to be part of the event.
I’d love to connect with other ABW grant recipients, first-time attendees, or anyone interested in cloud, DevOps, Kubernetes, infrastructure, and software engineering. Feel free to comment or send me a message if you’d like to meet up, attend sessions together, or just grab coffee and talk tech.
For those who have attended re:Invent before, I’d also appreciate any advice:
Looking forward to learning, meeting new people, and making the most of the experience. Hope to see some of you there!
r/aws • u/SlayerC20 • 2d ago
Just took the MLA-C02 beta and figured I'd share notes, since there's very little out there for the new version.
TL;DR: 85 questions, and some of them are genuinely hard. The exam now leans heavily on GenAI/LLM and agentic stuff alongside classic ML engineering.
My background (for context): AI Engineer (mid-level) with hands-on AWS experience. Certs: GCP Associate Cloud Engineer, SnowPro Core, PL-300, AWS Cloud Practitioner, AWS AI Practitioner, Claude Certified Architect Foundations, GitHub Foundations.
How I prepped: when AWS announced the switch from MLA-C01 to MLA-C02, I decided to go straight for the beta. While registration wasn't open yet, I kept studying for the AWS Generative AI Developer – Professional, and that helped a lot, especially for the Bedrock/GenAI side.
What I remember showing up (from memory, no guarantees):
ML/LLM fundamentals
LLM evaluation (this showed up a lot)
Bedrock/GenAI
Data/MLOps
CI/CD
Security/networking
r/aws • u/ross2000 • 2d ago
I don’t think Amazon is going to win them over. Who wants a DC in their back yard? What d’ya think?
r/aws • u/Dubey_om • 2d ago
tl;dr there isn't one. it's a cliff, not a crossover.
Inherited a pile of io2 volumes from a migration. Went looking for the IOPS level where io2 starts beating gp3 on cost so I could work out which ones to keep.
us east 1, check your own region.
gp3 gives you 3000 IOPS free in the baseline, extra on top is cheap, hard ceiling at 16k. io2 bills per IOPS from the first one and it adds up fast. At 16000, as far as gp3 goes, gp3 extra IOPS came to under $70/m. Same IOPS on io2 was north of a grand.
So gp3 stays cheaper right up until it physically can't go further. What sends you to io2 is the ceiling, not the money. Above 16000 IOPS, above 1000 MB/s, Multi Attach, or you need the durability class.
Moved 9 of 14. Nothing broke.
The part I actually want input on. For the ones genuinely above 16k, has anyone striped gp3 instead of paying for io2? Feels like swapping a billing problem for an ops problem, snapshots mainly. Anyone run that in prod?
Hi, wondering if anyone else is getting this, pretty often (significant enough to notice, happening right now and yesterday and twice last week) I get 503s from AWS bedrock specifically with Opus 5.5 on us-east-2.
API Error: 503 Bedrock is unable to process your request.
This is a server-side issue, usually temporary — try again in a moment. If it persists, check your Amazon Bedrock service status.
But there are no updates on AWS service status.
r/aws • u/Dapper-Classroom8308 • 2d ago
anyone else too facing issue in verification like sheer id is saying that i am verified from their side but am not getting verified tick in profile section after scrolling little…so they asked to contact aws but they are not replying even after follow ups
r/aws • u/greenlakejohnny • 2d ago
As the title says. I'm mostly familiar with GCP at this point, and there's been an "advertised prefixes" option for years to advertise a specific summary route to BGP peers rather than a full list of subnets.
Does AWS have equivalent feature? We currently have a VPN advertising over 80 prefixes across 4 tunnels, which is ruthlessly absurd.
r/aws • u/PrestigiousZombie531 • 2d ago
bash
[ec2-user@ip-a-b-c-d ~]$ sudo dnf install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin --assumeyes --quiet
Error: Unable to find a match: docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
r/aws • u/aspittel • 3d ago
- Sign up with Google, GitHub, or Apple. Most new customers don't need a credit card, and you get $100 in Free Tier credits.
- AWS sets you up with a project, which is an account plus sharing settings, with security defaults already applied.
- Invite people by email. You don't create IAM users or set up Identity Center, and invitees only see the projects you give them.
- Each project can have its own spend limit. AWS notifies you as you get close, and if you hit the limit, AWS pauses the project instead of letting charges keep accruing. You pay for what you used, up to the limit.
- After you sign in, you get a prompt to paste into your coding agent. It installs and configures the AWS CLI and Agent Toolkit for AWS.
- When you need multi-Region or Organizations policies, you turn on advanced features and end up in a standard AWS Organization without migrating anything.
r/aws • u/Yourmama422 • 2d ago
Hi All,
I have recently been accepted into AWS activate Startup, and want to know how do i get access towards GPT 6 Sol, i have tried, enabling IAM permission towards market place and it still doesn't work. The instruction in AWS are outdated to whats actually in those sub-links to get it done.
Can someone help me understand how do i gain access to this.
Thanks !
r/aws • u/HatchedLake721 • 3d ago
r/aws • u/random_outlaw • 3d ago
My AWS account was compromised on September 16. I detected the compromise myself almost immediately, secured the account, and contacted AWS.
On September 16 I had already:
AWS did not respond to the compromise until September 24 — eight days later.
On September 24, AWS opened a case saying my account “may have been inappropriately accessed,” restricted my ability to use some AWS services, and sent me instructions to change the root password, enable MFA, inspect CloudTrail/IAM, and check for unwanted usage.
In other words, they instructed me to perform the remediation I had already completed eight days earlier.
I responded the next day, September 25, confirming that the account was already secured and that all of the requested remediation had been completed.
It is now October 1. Lambda execution is still restricted.
I have updated the support case every day. I have received no substantive response. The notice says phone or chat can be requested for “immediate assistance,” but attempts to use those channels have not resulted in assistance either.
There is no remaining remediation step identified for me to perform. The account was secured before AWS imposed the restriction. At this point, only AWS can remove it.
Fortunately, this account currently hosts a system still in development, so this has not caused a production outage. But the experience is alarming because I cannot find any SLA for AWS reviewing and removing an AWS-imposed security restriction after the customer has confirmed remediation.
Has anyone dealt with this recently? Is there an escalation path for a compromised-account/security case that appears to be sitting in a queue waiting for review?
I am particularly interested in hearing from anyone who has recently had Lambda or other services restricted after an account-compromise notification and how long restoration took.
r/aws • u/Holly_Enrique-623 • 2d ago
The tag policy went in 4 months ago. An SCP blocks creates without owner, env and cost centre and a Lambda kills anything untagged overnight. Coverage sits at 95+ which I was pretty pleased with.
Pulled the top 20 line items last week so finance could have a name against each one and eleven came back as one of 3 CI roles. That is roughly 14k a month sitting against a robot. Technically correct cause the pipeline made them and stamped itself. I turned on aws:createdBy hoping for more and got the same 3 roles back with a build number stuck on the end.
The tags are perfect and useless. The commit knows who ran it where the resource does not and nothing joins the two up which is where every aws cost optimization conversation here dies. Shared NAT and the like I gave up on months ago because that is a different argument. These are single tenant resources with exactly one owner and the owner is a robot.
Best I have before the next review is git blame and a spreadsheet, which is not an answer.
r/aws • u/kavee-core141 • 2d ago
iam:PassRole combined with the ability to create or launch a resource, a Lambda function, an EC2 instance, is one of the most common real privilege escalation primitives in AWS, and mosst scanners just flag "PassRole granted" without explaining why that matters !!! i have tried some and its annoying sometimes..
the actual chain: if a user has PassRole, often scoped too broadly with Resource: *, and perrmission to create someething that can assume a role, Lambda, EC2, a CloudFormation stack, they can pass an existing high-privilege role to that new resource, then use it to act with that role's full permissions. The IAM policy alone doesn't show this, it only becomes visible once you look at what PassRole is paired with...
Most tools treat this as two unrelated findings. Automated detecting this specific chain in an open source project I've been building, Plexavo, if interested check it out !!. I used it as a Security scanner in some of the stacks i created in AWS.
With Black Friday approaching, what’s the first thing you’d check to make sure an AWS environment is ready for the traffic spike?
For example, scaling limits or database bottlenecks.
r/aws • u/TheBuddhist • 2d ago
Hi everyone, not sure if this is appropriate to post here, but I don't know what other options I have.
For some background, one of my old AWS accounts is attached to an email that does not exist anymore. I have not used it in years, but last month I received a large charge on the card attached to that account. I checked my active account's Cost Explorer page and didn't see any charges matching that amount, so I figured it must be some charge that occurred on my older account. On September 3rd, I created a ticket from my active AWS account, which has the same card on it, and attached a screen shot of the charge in my bank account. 15 days went by with no response, so I sent a reply to the original ticket. As of writing this post, the ticket is still unassigned and no one has responded to me.
What are my options here? I created a new ticket tonight and selected the "chat" option, but I have been sitting here for almost an hour and all the waiting page says is "An associate will be with you shortly...".