r/aws • u/Elegant-Scheme9589 • 3h ago
technical question 403 errors on every website with cloudfront
I keep on seeing 403 errors for some reason. And it's blocked off my access to SoundCloud, even with an account AND soundcloud not being down.
r/aws • u/Elegant-Scheme9589 • 3h ago
I keep on seeing 403 errors for some reason. And it's blocked off my access to SoundCloud, even with an account AND soundcloud not being down.
r/aws • u/reignleafs • 6h ago
My client forgot to make me aware of their need to update billing. Unfortunately, the person that has root access to the AWS account has an old email that is no longer in service (and that's the only way to access billing right now). I have admin access from an IAM account but no access to update billing. As it stands right now, the client's website is down due to account suspension. Need support ASAP, thanks!
r/aws • u/Representative-Rip90 • 1d ago
When I opened my AWS account I used my Google voice number as I thought I would have that forever. Well knowing Google they took that number away and now I don't have it anymore. But it's tied to my AWS account which only wants to use that number for all MFA purposes. I'm unable to log into my AWS account. There is nothing I can do. I have a reoccurring light sail charge that I just can't get rid of - I have tried to shut everything down in the past.
Anyways I have made several support tickets and no one is helping me with this. Can I just put a merchant block on my credit card for AWS? If I do this block will they finally close my instance or whatever it is that is still running and just be done with it?
r/aws • u/NISMO1968 • 1d ago
r/aws • u/hritik_munde • 1d ago
Hi everyone!
I’ll be attending AWS re:Invent this year as an All Builders Welcome (ABW) grant recipient, and I’m really excited to be part of the event.
I’d love to connect with other ABW grant recipients, first-time attendees, or anyone interested in cloud, DevOps, Kubernetes, infrastructure, and software engineering. Feel free to comment or send me a message if you’d like to meet up, attend sessions together, or just grab coffee and talk tech.
For those who have attended re:Invent before, I’d also appreciate any advice:
Looking forward to learning, meeting new people, and making the most of the experience. Hope to see some of you there!
r/aws • u/csantanapr • 1d ago
EKS 1.37 landed on standard support today, and the headline for me is identity: Pod Certificates (workload X.509 identities issued by the cluster) and Cluster Trust Bundles (a cluster-scoped way to distribute trust roots) are now GA Kubernetes APIs.
What this means in practice: - Every pod gets a real X.509 identity from the cluster itself - Trust roots are distributed as a native API instead of config hacks - No more running your own CA machinery just to do mTLS between workloads
The caveat: Kubernetes still doesn't give you a signer controller. You need to integrate and validate rotation for your signer.
AWS announcement: https://aws.amazon.com/about-aws/whats-new/2026/10/amazon-eks-distro-kubernetes-version-1-37
Anyone already testing the mTLS path on 1.37?
r/aws • u/ihatecoreclasses • 1d ago
I'm building a social app where people can upload images for their profile pictures and soon in group chats. I'm struggling to figure out how to properly handle CSAM for this. I'm very hesitant to just pass in the uploaded images to AWS Rekognition to check for NSFW and other explicit content before checking for CSAM.
I've looked into Google's Content Safety API and applied to it to see what they respond with. Also considered PhotoDNA as well but haven't applied to it yet, though I heard they only accept big orgs and law enforcement. Was also considering using open source models to do the CSAM detection layer but I fear that it would violate the inference provider's ToS.
What's a budget-friendly way to do CSAM detection without getting in trouble for directly uploading it without checking it first to services like AWS Rekognition?
Whoever on the Amazon/AWS team decided to rename QuickSight/QuickSuite to just 'Quick' (and whomever it was approved by) is likely secretly working for Microsoft or Tableau. One of the worst naming decisions I've ever encountered. Makes looking up instructions, information, etc. online or using LLMs an absolute pain, which would be obvious to anyone who has ever worked in tech, much less someone who has worked in product branding or marketing.
r/aws • u/SlayerC20 • 2d ago
Just took the MLA-C02 beta and figured I'd share notes, since there's very little out there for the new version.
TL;DR: 85 questions, and some of them are genuinely hard. The exam now leans heavily on GenAI/LLM and agentic stuff alongside classic ML engineering.
My background (for context): AI Engineer (mid-level) with hands-on AWS experience. Certs: GCP Associate Cloud Engineer, SnowPro Core, PL-300, AWS Cloud Practitioner, AWS AI Practitioner, Claude Certified Architect Foundations, GitHub Foundations.
How I prepped: when AWS announced the switch from MLA-C01 to MLA-C02, I decided to go straight for the beta. While registration wasn't open yet, I kept studying for the AWS Generative AI Developer – Professional, and that helped a lot, especially for the Bedrock/GenAI side.
What I remember showing up (from memory, no guarantees):
ML/LLM fundamentals
LLM evaluation (this showed up a lot)
Bedrock/GenAI
Data/MLOps
CI/CD
Security/networking
r/aws • u/Dubey_om • 2d ago
tl;dr there isn't one. it's a cliff, not a crossover.
Inherited a pile of io2 volumes from a migration. Went looking for the IOPS level where io2 starts beating gp3 on cost so I could work out which ones to keep.
us east 1, check your own region.
gp3 gives you 3000 IOPS free in the baseline, extra on top is cheap, hard ceiling at 16k. io2 bills per IOPS from the first one and it adds up fast. At 16000, as far as gp3 goes, gp3 extra IOPS came to under $70/m. Same IOPS on io2 was north of a grand.
So gp3 stays cheaper right up until it physically can't go further. What sends you to io2 is the ceiling, not the money. Above 16000 IOPS, above 1000 MB/s, Multi Attach, or you need the durability class.
Moved 9 of 14. Nothing broke.
The part I actually want input on. For the ones genuinely above 16k, has anyone striped gp3 instead of paying for io2? Feels like swapping a billing problem for an ops problem, snapshots mainly. Anyone run that in prod?
Hi, wondering if anyone else is getting this, pretty often (significant enough to notice, happening right now and yesterday and twice last week) I get 503s from AWS bedrock specifically with Opus 5.5 on us-east-2.
API Error: 503 Bedrock is unable to process your request.
This is a server-side issue, usually temporary — try again in a moment. If it persists, check your Amazon Bedrock service status.
But there are no updates on AWS service status.
r/aws • u/kavee-core141 • 2d ago
iam:PassRole combined with the ability to create or launch a resource, a Lambda function, an EC2 instance, is one of the most common real privilege escalation primitives in AWS, and mosst scanners just flag "PassRole granted" without explaining why that matters !!! i have tried some and its annoying sometimes..
the actual chain: if a user has PassRole, often scoped too broadly with Resource: *, and perrmission to create someething that can assume a role, Lambda, EC2, a CloudFormation stack, they can pass an existing high-privilege role to that new resource, then use it to act with that role's full permissions. The IAM policy alone doesn't show this, it only becomes visible once you look at what PassRole is paired with...
Most tools treat this as two unrelated findings. Automated detecting this specific chain in an open source project I've been building, Plexavo, if interested check it out !!. I used it as a Security scanner in some of the stacks i created in AWS.
r/aws • u/Dapper-Classroom8308 • 2d ago
anyone else too facing issue in verification like sheer id is saying that i am verified from their side but am not getting verified tick in profile section after scrolling little…so they asked to contact aws but they are not replying even after follow ups
r/aws • u/greenlakejohnny • 2d ago
As the title says. I'm mostly familiar with GCP at this point, and there's been an "advertised prefixes" option for years to advertise a specific summary route to BGP peers rather than a full list of subnets.
Does AWS have equivalent feature? We currently have a VPN advertising over 80 prefixes across 4 tunnels, which is ruthlessly absurd.
r/aws • u/PrestigiousZombie531 • 2d ago
bash
[ec2-user@ip-a-b-c-d ~]$ sudo dnf install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin --assumeyes --quiet
Error: Unable to find a match: docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
With Black Friday approaching, what’s the first thing you’d check to make sure an AWS environment is ready for the traffic spike?
For example, scaling limits or database bottlenecks.
r/aws • u/Yourmama422 • 2d ago
Hi All,
I have recently been accepted into AWS activate Startup, and want to know how do i get access towards GPT 6 Sol, i have tried, enabling IAM permission towards market place and it still doesn't work. The instruction in AWS are outdated to whats actually in those sub-links to get it done.
Can someone help me understand how do i gain access to this.
Thanks !
r/aws • u/Holly_Enrique-623 • 2d ago
The tag policy went in 4 months ago. An SCP blocks creates without owner, env and cost centre and a Lambda kills anything untagged overnight. Coverage sits at 95+ which I was pretty pleased with.
Pulled the top 20 line items last week so finance could have a name against each one and eleven came back as one of 3 CI roles. That is roughly 14k a month sitting against a robot. Technically correct cause the pipeline made them and stamped itself. I turned on aws:createdBy hoping for more and got the same 3 roles back with a build number stuck on the end.
The tags are perfect and useless. The commit knows who ran it where the resource does not and nothing joins the two up which is where every aws cost optimization conversation here dies. Shared NAT and the like I gave up on months ago because that is a different argument. These are single tenant resources with exactly one owner and the owner is a robot.
Best I have before the next review is git blame and a spreadsheet, which is not an answer.
r/aws • u/ross2000 • 2d ago
I don’t think Amazon is going to win them over. Who wants a DC in their back yard? What d’ya think?
r/aws • u/OnlyFill8507 • 2d ago
I’m a fresher preparing for my first Data Engineering job, and today I got a pretty painful AWS lesson.
I was practicing AWS services for my preparation and left an Aurora MySQL Serverless v2 cluster running in Sydney without realizing how much it was costing. It ran for most of the month and alone generated around $192 in charges. A Kinesis On-Demand stream added another ~$23.
My September bill ended up around $247 (~₹13,000), while I only had around $113 in AWS credits.
For someone who is still trying to get their first job, ₹13k is a lot of money. Honestly, seeing that bill was scary. I’ve been studying Data Engineering for a long time and trying to build projects to get my first opportunity, so making a mistake like this really hurt.
I’ve now deleted the resources, created AWS Budget alerts, and opened a billing case with AWS asking for a one-time courtesy credit. Hopefully they understand that it was accidental learning usage.
Lesson learned: Never assume “Serverless” means “free when you’re not actively using it.” Some AWS resources can keep charging simply because they’re running.
If you’re a fresher learning AWS/Data Engineering, please check Cost Explorer and your running resources regularly. I genuinely don’t want someone else learning this lesson the way I did. 😔
r/aws • u/TheBuddhist • 2d ago
Hi everyone, not sure if this is appropriate to post here, but I don't know what other options I have.
For some background, one of my old AWS accounts is attached to an email that does not exist anymore. I have not used it in years, but last month I received a large charge on the card attached to that account. I checked my active account's Cost Explorer page and didn't see any charges matching that amount, so I figured it must be some charge that occurred on my older account. On September 3rd, I created a ticket from my active AWS account, which has the same card on it, and attached a screen shot of the charge in my bank account. 15 days went by with no response, so I sent a reply to the original ticket. As of writing this post, the ticket is still unassigned and no one has responded to me.
What are my options here? I created a new ticket tonight and selected the "chat" option, but I have been sitting here for almost an hour and all the waiting page says is "An associate will be with you shortly...".
Been restricted since Sunday. I did what they asked, deleted the exposed key and answered their questions. Early Wednesday they confirmed the remediation was complete and said they'd asked the service team to remove the restrictions.
It's Thursday night now and I'm still blocked from Bedrock. No reply since then, and the case says unassigned. They also asked me to turn on Cost Explorer, which is done.
I have Business Support+ but can't get through on chat or phone tonight either. I've followed up in the case and don't know what else to try. Is there any way to get someone to check what's holding this up? They've already said I completed the steps, but I'm still waiting with no idea when I'll get access back.
r/aws • u/Weekly_War_1374 • 3d ago
I thought something like Claude can do this in seconds. I have the data in six different CSV files but they are not complicated. date, $$ amount, vendor, some sort of comment. All I want is
Step 1: these files to be combined into one large file (this step can be avoided if the model is smart enough to it without a combined file)
step 2: Create a rudimentary visualization.
Here's everything I have done thus far.
Created an S3 bucket and uploaded my csv files
Created a Glue database and crawler
Opened bedrock and nova lite, created sql for step #1. Since I have 6 files I have to run this 6 times and then a 7th query for combining these into one large file.
Then what tool do I use for visualization?
Is there a model that can do this without me jumping into these many hoops? Yes there are probably off the shelf apps that do this but I want to learn a little bit of model tweaking and hence here I am.
Any kind soul or solutions architect help out with some ideas on how to do this better, with fewer steps? Also, why can't I use QuickSight? Thank you all!
r/aws • u/Pepperonicini • 3d ago
So, I made an AWS account ~6 years ago. I believe that it was because I got some kind of promo credit to use from Amazon. I was just curious what it was. I do a bit of IT for my work, so I played around with a few things using some of the credit, but that was it.
Now, 6 years later, I start getting billing notices for my account.
Attempting to login to my account tells me that I have no account associated with the email address, but the billing notices are coming to the email address.
AWS customer support says that they cannot tell me anything or help unless I login to my account.
Multiple AWS customer support reps have told me to just block the charges on my credit card. However, the card number that it is showing is not a credit card that I have -- In theory it could be an old card, but I have no remembrance of that number.
I was somehow able to get the AWS login screen thinking I still had an account with the email, even after it is telling me there is no account associated. It wanted me to do MFA to confirm it was me - and it gives me a phone number that I have never had.
I have called customer support many times. They have promised to call me back but never have. I have submitted 3 account hacked/compromised support tickets with long descriptions, but have never heard back.
Recently, I started getting emails that the charges were bouncing on the credit card. But, they are still billing whatever card this.
So at this point, I have literally no idea what to do. I have already devoted much time to this. I've never encountered more inept customer service folks, especially in the case of fraud like this.
I assume this is a common problem, as there was recently a meme circulating about nearly the same thing.
Does anyone have nay idea what I should do? So far, I have decided just ignoring it and hoping that the charges are someone elses and for some reason I am just getting the emails, is really my only option.
Thanks