AWS Builder Center is the official home for builders on AWS. Share and read what others are working on, follow people who inspire you, explore training and workshops, and find tools to support what you're building.
Security, Identity, & Compliance
Recent questions
see all- I have configured PassKey (WebAuthn/FIDO2) authentication in my Amazon Cognito User Pool using the Choice-based sign-in flow (ALLOW_USER_AUTH). However, the Managed Login UI still shows a "Use passwo...
- I'm hitting a persistent account-level Bedrock restriction that's affecting all model providers, not just one. Error: ValidationException: Access to Bedrock models is not allowed for this account Co...
- Account Status: ACTIVE (confirmed) Account Created: September 10, 2026 Account ID: Will share privately with AWS staff only Country: India PROBLEM: My account shows ACTIVE but every time I try to acc...
- I'm building a FastAPI service that redirects authenticated users into the MWAA Airflow UI, scoped to the DAGs their team should see. I want to confirm the right IAM structure before building it out. ...
- I'm trying to get access to Anthropic Claude models on Amazon Bedrock and I'm blocked at two related points: Bedrock Playground error: When I try to invoke any model in the Bedrock console Playground...
- An on-demand Linux CodeBuild project attached to a private VPC subnet fails in QUEUED with: `UNAUTHORIZED_OPERATION_DELETE_NETWORK_INTERFACE` The service role contains an Allow for `ec2:DeleteNetwor...
- I really don’t understand why AWS still auto-approves SES access for some accounts. Email sending is one of the easiest areas to abuse, and giving immediate production access without any meaningful re...
- Our company AWS account (Account ID: 0582-6449-5999) has been suspended for more than 3 days due to a suspected suspicious activity flag. All console access (including root sign-in) is blocked with th...
- I am writing this out of absolute distress and extreme frustration. It has now been over a week of continuous correspondence on this case, and weeks overall, with zero resolution. To reiterate the fa...
- Hello, My AWS account was placed on hold pending identity verification. I uploaded all requested documents through the secure AWS upload link on September 8, 2026, and received confirmation that all 3...
- I followed the walkthrough in this AWS Big Data Blog post to connect the Apache Spark Troubleshooting Agent for Amazon EMR to AWS DevOps Agent as an MCP capability provider: https://aws.amazon.com/blo...
- Hello AWS Community, I am unable to invoke Amazon Nova Pro using Amazon Bedrock Runtime. Environment: * AWS CLI: 2.33.30 * OS: Windows 11 * Primary region tested: us-east-2 Model: * amazon.nova-p...
- I am reviewing a least-privilege CloudFormation execution role that creates application IAM roles with required ownership tags. This is a pre-deployment review; no role-creation test has been performe...
- Hi, I'm a final-year engineering student at ESPRIT (Tunisia), and I'm trying to verify my student status for the AWS Builder Center Student Rewards program (builder.aws.com) using my AWS Builder ID. ...
- We have built a working CI/CD auto-remediation pipeline using AWS DevOps Agent and the GitHub MCP Server, based on the blog "Automate CI/CD troubleshooting with AWS DevOps Agent and GitHub". Our cu...
- I am reviewing least-privilege permissions for a CloudFormation execution role that creates an AWS::RDS::DBInstance with six required application ownership tags. The RDS service authorization referen...
- My AWS account has been suspended and I have an open support case (Case ID: ***************) with Urgent severity, but have not received any response yet. Production workloads are currently down. I...
- My account had a security restriction applied on 2026-09-09 at ~16:16 UTC following an automated review that flagged possible third-party access. I have completed all the remediation steps AWS asked f...
Recent Knowledge Center content
see allRecent articles
see allMario SagethEXPERT
published 7 hours ago0 votes20 views
For semiconductor teams, design IP and ingested third-party/vendor datasets are both high-value and high-risk. AWS Backup protects design-data buckets with point-in-time and long-retention recovery, w...published 5 days ago0 votes41 views
A financial-services SRE team connected its self-managed APM to AWS DevOps Agent, then hit the real problem: the managed, AWS-hosted model reads that telemetry — and it holds regulated data. The artic...JuhiEXPERT
published 5 days ago0 votes60 views
This article walks through creating an Amazon CloudWatch telemetry pipeline that ingests Okta system logs using the okta_sso source, processes them through the OCSF processor, and delivers them to a C...Rosa LlorenteEXPERT
published 7 days ago0 votes75 views
Centralized traffic inspection with Transit Gateway and Network Firewall often inspects far more than necessary, and per-GB charges dominate at scale. This post shows how three Transit Gateway feature...Abdullah KaramanEXPERT
published 12 days ago0 votes175 views
AWS DevOps Agent's native code integration covers GitHub, GitLab, and Azure DevOps, but not Bitbucket at this time. This article shows how to register the Atlassian Rovo MCP server as a capability pro...N_AgarwalEXPERT
published 18 days ago0 votes99 views
AWS Continuum launched in June 2026 as the new umbrella for AWS's security capabilities — yet no community guide exists on re:Post to help practitioners understand which capability to use when or how ...SaurabhEXPERT
published 20 days ago1 votes107 views
This article shows how AWS DevOps Agent autonomously diagnoses Amazon MWAA (Airflow) pipeline failures such as broken DAGs, task exceptions, and retry exhaustion by correlating CloudWatch alarms, metr...Ogawa_FSUPPORT ENGINEER
published 23 days ago0 votes349 views
This article provides guidance for Kiro administrators on Kiro concepts, key considerations for operating Kiro in accordance with organizational governance requirements, and how to set up and operate ...naveen-awsEXPERT
published a month ago0 votes85 views
Adopting Amazon DevOps Agent across multiple AWS accounts requires deploying an IAM role and creating an association for each secondary account. StackSets automates the IAM role but cannot create asso...Dipesh PEXPERT
published a month ago0 votes119 views
This article shows you how to use AWS DevOps Agent to build an automated end-of-support monitoring pipeline for Amazon RDS engine versions and Amazon EKS Kubernetes versions. It walks through creating...- AWS OFFICIALUpdated a month ago0 votes225 viewsThis article shows you how to use Amazon CloudWatch and AWS DevOps Agent to build an automated cost spike detection pipeline for Amazon Bedrock.
Jiwon JungEXPERT
published a month ago2 votes127 views
A member account needs to be migrated to another AWS Organization. This account consumes resources shared by another account through AWS RAM. Because organization-scoped resource shares are automatica...Lucky IkaniSUPPORT ENGINEER
published a month ago3 votes309 views
I want to use multiple AWS Client VPN endpoints in different AWS accounts with the same Microsoft Entra ID (Azure AD) tenant for SAML authentication. When I create a second enterprise application in E...SapirEXPERT
published a month ago2 votes190 views
A step-by-step guide to connecting AWS DevOps Agent to a self-managed, privately hosted GitLab using a Private Connection over Amazon VPC Lattice - so you can have the agent investigate your repositor...Vamsi KrishnaEXPERT
published a month ago0 votes173 views
This article guides AWS Enterprise Support customers in education and government on how to strengthen their security posture using four AWS capabilities — Security Agent (prevent), Security Hub Unifie...Chirag_REXPERT
published a month ago0 votes151 views
This article will help customers using AWS Devops Agent with resources in Azure to integrate the Azure Devops/Cloud environment to have a streamlined tool.Manish MishraEXPERT
published a month ago0 votes243 views
You DM the bot in Teams (or @mention it in a channel). DevOps Agent responds directly in the conversation. If it kicks off an investigation, the results come back in the same thread when it's done. Fo...- AWS OFFICIALUpdated a month ago0 votes154 viewsIf you build or operate a service on AWS where users can share, generate, process, distribute, or store imagery, you might encounter non-consensual intimate imagery (NCII) or other forms of image-base...
Recent selections
see allAWS OfficialMODERATOR
published 2 months ago1 votes290 views
This spotlight on AWS Certificate Manager (ACM) equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated 5 months ago1 votes309 viewsAWS Official content is created by a team of technical experts, professional writers, and editors within AWS. They work together to make sure that the information is clear, comprehensive, and aligned ...
AWS OfficialMODERATOR
published 5 months ago0 votes262 views
This spotlight on AWS IAM equips you with skills and troubleshooting best practices to secure and manage access to your AWS resources effectively.AWS OfficialMODERATOR
published a year ago1 votes432 views
This spotlight on Amazon Cognito equips you with the skills and troubleshooting best practices to get the most out of this cost effective service.AWS OfficialEXPERT
published 2 years ago0 votes1K views
This spotlight on IAM equips you with the skills and troubleshooting tips to get the most out of a powerful service.- AWS OFFICIALUpdated a month ago14 votes41K viewsThe AWS Trust & Safety Center provides curated knowledge of AWS resources that can assist you in your cloud journey.
Osvaldo MarteEXPERT
published 2 years ago2 votes18.7K views
This selection focuses on the essential AWS networking services, providing a comprehensive overview of tools and technologies available to build and manage secure, scalable, and high-performing networ...Antonio LagrotteriaEXPERT
published 2 years ago4 votes28.4K views
A selection of architectural patterns and tips to leverage secure cross-account APIs, showing ingress, egress and inspection reference architecturesJonathan_DEXPERT
published 3 years ago4 votes12.5K views
Do you have critical workloads running in AWS? Review these handpicked resources to find ways to ensure your applications are resilient to failures.- AWS OFFICIALUpdated 3 years ago0 votes123 viewsThis selection includes content and solutions supporting FSI related compliance and requirements covering security, immutable storage, and general guidance.
- AWS OFFICIALUpdated 3 years ago0 votes330 viewsAs a best practice, AWS recommends that you use AWS Identity and Access Management (IAM) roles instead of IAM users with long-term credentials such as access keys.
- AWS OFFICIALUpdated 3 years ago0 votes68 viewsAccelerate your business transformation goals with a managed service that combines compute, network and storage capabilities in a fully supported, ready-to-run service from VMware and AWS.
- AWS OFFICIALUpdated 3 years ago0 votes8.3K viewsAre you getting 403 Access Denied errors with your Amazon Simple Storage Service (Amazon S3) operations? Review this list of handpicked resources to identify the root cause and troubleshooting instruc...
Riku_Kobayashi
EXPERTGary Mclean
EXPERTsecondabhi_aws
EXPERTOleksii Bebych
EXPERTKidd Ip
EXPERTGreg
EXPERTFlorian Turnwald
EXPERTOsvaldo Marte
EXPERTIsaac Behrens
EXPERTSedat SALMAN
EXPERTAdeleke Adebowale .J.
EXPERTTushar Jagdale
EXPERTMatt Barbieri
EXPERTAWS-User-alantam
EXPERTIndranil Banerjee AWS
EXPERTTakahito Iwasa
EXPERTMassimilianoAWS
EXPERTGK
EXPERT
