AWS Blogs 06月24日 00:29
AWS Weekly Roundup: re:Inforce re:Cap, Valkey GLIDE 2.0, Avro and Protobuf or MCP Servers on Lambda, and more (June 23, 2025)
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

本文总结了AWS re:Inforce安全会议的主要发布,并重点介绍了几个关键的新功能和更新。其中包括增强的IAM Access Analyzer功能、针对根用户的MFA强制执行、与AWS Network Firewall的威胁情报集成等安全创新。此外,文章还提到了AWS Certificate Manager的可导出SSL/TLS证书、简化的AWS WAF控制台体验,以及用于主动网络安全的新AWS Shield功能。文章还介绍了Amazon Verified Permissions团队发布的Express.js开源包,简化了API的授权集成。最后,文章还提到了AWS Lambda对Avro和Protobuf格式的Kafka事件的本地支持,以及Amazon S3 Express One Zone对对象原子重命名的支持,以及Valkey GLIDE 2.0的发布。

🛡️ AWS re:Inforce大会发布了多项安全相关的新功能,包括增强的IAM Access Analyzer、针对根用户的MFA强制执行以及与AWS Network Firewall的威胁情报集成,旨在提升云安全防护能力。

🔑 Amazon Verified Permissions团队发布了Express.js的开源包,简化了Web应用程序API的授权集成,降低了代码复杂性,提高了应用程序的安全性,开发者可以更容易地实现细粒度的授权控制。

💡 AWS Lambda增加了对Avro和Protobuf格式的Kafka事件的本地支持,方便用户处理Kafka数据,减少了自定义代码编写的需求,并支持与GSR、CCSR和SCSR的集成,简化了Kafka应用的开发流程。

🚀 Amazon S3 Express One Zone现在支持通过单个API调用对对象进行原子重命名,简化了数据管理,可以更快地重命名对象,例如大型日志文件,从而加速应用程序并降低成本。

⚙️ Valkey推出了GLIDE 2.0,增加了对Go语言的支持,改进了可观测性,并优化了高吞吐量工作负载的性能,通过支持OpenTelemetry和批处理功能,提高了Valkey客户端的效率。

<section class="blog-post-content lb-rtxt"><table id="amazon-polly-audio-table"><tbody><tr><td id="amazon-polly-audio-tab"><p></p></td></tr></tbody></table><p>Last week’s hallmark event was the security-focused <a href="https://reinforce.awsevents.com/&quot;&gt;AWS re:Inforce conference</a>.</p><table class="c7"><tbody><tr><td class="c6"><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/06/22/1000061483.jpg&quot;&gt;&lt;br /><img class="wp-image-97401" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/06/22/1000061483-300x226.jpg&quot; alt="AWS re:Inforce 2025" width="300" height="226" /><br /></a></td><td class="c6"><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/06/22/1000061408.jpg&quot;&gt;&lt;br /><img class="wp-image-97400" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/06/22/1000061408-300x225.jpg&quot; alt="AWS re:Inforce 2025" width="300" height="225" /><br /></a></td></tr></tbody></table><p>Now a tradition, the blog team wrote <a href="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-aws-reinforce-2025-aws-waf-aws-control-tower-and-more-june-16-2025/&quot;&gt;a re:Cap post to summarize the announcements and link to some of the top blog posts</a>.</p><p>To further summarize, several new security innovations were announced, including <a href="https://aws.amazon.com/blogs/aws/verify-internal-access-to-critical-aws-resources-with-new-iam-access-analyzer-capabilities&quot;&gt;enhanced IAM Access Analyzer capabilities</a>, <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/aws-iam-mfa-root-users-across-all-account-types/&quot;&gt;MFA enforcement for root users</a>, and <a href="https://aws.amazon.com/blogs/security/improve-your-security-posture-using-amazon-threat-intelligence-on-aws-network-firewall/&quot;&gt;threat intelligence integration with AWS Network Firewall</a>. Other notable updates include <a href="https://aws.amazon.com/blogs/aws/aws-certificate-manager-introduces-exportable-public-ssl-tls-certificates-to-use-anywhere&quot;&gt;exportable public SSL/TLS certificates from AWS Certificate Manager</a>, a <a href="https://aws.amazon.com/about-aws/whats-new/2025/06/aws-waf-web-application-security-configuration-steps-expert-level-protection/&quot;&gt;simplified AWS WAF console experience</a>, and a new <a href="https://aws.amazon.com/blogs/aws/new-aws-shield-feature-discovers-network-security-issues-before-they-can-be-exploited-preview&quot;&gt;AWS Shield feature for proactive network security</a> (in preview). Additionally, <a href="https://aws.amazon.com/blogs/aws/unify-your-security-with-the-new-aws-security-hub-for-risk-prioritization-and-response-at-scale-preview/&quot;&gt;AWS Security Hub has been enhanced for risk prioritization</a> (Preview), and <a href="https://aws.amazon.com/blogs/aws/amazon-guardduty-expands-extended-threat-detection-coverage-to-amazon-eks-clusters/&quot;&gt;Amazon GuardDuty now supports Amazon EKS clusters</a>.</p><p>But my favorite announcement came from the <a href="https://aws.amazon.com/verified-permissions/&quot;&gt;Amazon Verified Permissions</a> team. They released an open source package for <a href="https://expressjs.com/&quot;&gt;Express.js&lt;/a&gt;, <a href="https://github.com/cedar-policy/authorization-for-expressjs&quot;&gt;enabling developers to implement external fine-grained authorization for web application API</a>s. This simplifies authorization integration, reducing code complexity and improving application security.</p><p>The team also published a blog post that outlines <a href="https://aws.amazon.com/blogs/security/secure-your-express-application-apis-in-minutes-with-amazon-verified-permissions/&quot;&gt;how to create a Verified Permissions policy store, add Cedar and Verified Permissions authorisation middleware to your app, create and deploy a Cedar schema, and create and deploy Cedar policies</a>. The Cedar schema is generated from an OpenAPI specification and formatted for use with the <a href="https://aws.amazon.com/cli/&quot;&gt;AWS Command Line Interface</a> (CLI).</p><p>Let’s look at last week’s other new announcements.</p><p><strong>Last week’s launches</strong><br />Apart from re:Inforce, here are the launches that got my attention.</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2025/06/aws-lambda-native-support-avro-protobuf-kafka-events/&quot;&gt;AWS Lambda announces native support for Avro and Protobuf formatted Kafka events</a> — <a href="https://aws.amazon.com/lambda/&quot;&gt;AWS Lambda</a> now provides native support for <a href="https://avro.apache.org/&quot;&gt;Avro&lt;/a&gt; and <a href="https://protobuf.dev/&quot;&gt;Protobuf&lt;/a&gt; formatted Kafka events with Apache Kafka’s event-source-mapping (ESM). This integration allows you to validate your schema, filter events, and process them using open source Kafka consumer interfaces. You can also use <a href="https://docs.powertools.aws.dev/lambda/python/latest/&quot;&gt;Powertools for AWS Lambda</a> to process your Kafka events without writing custom deserialization code, making it easier to build your Kafka applications with AWS Lambda.</li></ul><p class="c8">Kafka customers use Avro and Protobuf formats for efficient data storage, fast serialization and deserialization, schema evolution support, and interoperability between different programming languages. They utilize schema registries to manage, evolve, and validate schemas before data enters processing pipelines. Previously, you were required to write custom code within your Lambda function to validate, deserialize, and filter events when using these data formats. With this launch, Lambda natively supports Avro and Protobuf, as well as integration with GSR, CCSR, and SCSR. This enables you to process your Kafka events using these data formats without writing custom code. Additionally, you can optimize costs through event filtering to prevent unnecessary function invocations.</p><ul><li><a href="https://aws.amazon.com/about-aws/whats-new/2025/06/amazon-s3-express-one-zone-atomic-renaming-objects-api/&quot;&gt;Amazon S3 Express One Zone now supports atomic renaming of objects with a single API call</a> – The <code>RenameObject</code> API simplifies data management in S3 directory buckets by transforming a multi-step rename operation into a single API call. This means you can now rename objects in S3 Express One Zone by specifying an existing object’s name as the source and the new name as the destination within the same S3 directory bucket. With no data movement involved, this capability accelerates applications like log file management, media processing, and data analytics, while also lowering costs. For instance, renaming a 1-terabyte log file can now complete in milliseconds, instead of hours, significantly accelerating applications and reducing costs.</li><li><a href="https://aws.amazon.com/about-aws/whats-new/2025/06/valkey-glide-2-0-go-opentelemetry-pipeline-batching/&quot;&gt;Valkey introduces GLIDE 2.0 with support for Go, OpenTelemetry, and pipeline batching</a> – AWS, in partnership with Google and the Valkey community, announces the general availability of General Language Independent Driver for the Enterprise (GLIDE) 2.0. This is the latest release of one of AWS’s official open-source Valkey client libraries. <a href="https://valkey.io/&quot;&gt;Valkey&lt;/a&gt;, the most permissive open-source alternative to Redis, is stewarded by the <a href="https://www.linuxfoundation.org/&quot;&gt;Linux Foundation</a> and will always remain open-source. Valkey GLIDE is a reliable, high-performance, multi-language client that supports all Valkey commands</li></ul><table class="c11"><tbody><tr><td class="c9"><p class="c8">GLIDE 2.0 introduces new capabilities that expand developer support, improve observability, and optimise performance for high-throughput workloads. Valkey GLIDE 2.0 extends its multi-language support to Go (contributed by Google), joining Java, Python, and Node.js to provide a consistent, fully compatible API experience across all four languages. More language support is on the way. With this release, Valkey GLIDE now supports OpenTelemetry, an open-source, vendor-neutral framework that enables developers to generate, collect, and export telemetry data and critical client-side performance insights. Additionally, GLIDE 2.0 introduces batching capabilities, reducing network overhead and latency for high-frequency use cases by allowing multiple commands to be grouped and executed as a single operation.</p><p class="c8">You can discover more about Valkey GLIDE in this recent episode of the <a href="https://developers.podcast.go-aws.com/web/index.html&quot;&gt;AWS Developers Podcast</a>: <a href="https://developers.podcast.go-aws.com/web/episodes/165/index.html&quot;&gt;Inside Valkey GLIDE: building a next-gen Valkey client library with Rust</a>.</p></td><td class="c10"><a href="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/06/21/165.png&quot;&gt;&lt;img class="aligncenter size-medium wp-image-97387" src="https://d2908q01vomqb2.cloudfront.net/da4b9237bacccdf19c0760cab7aec4a8359010b0/2025/06/21/165-300x300.png&quot; alt="Podcast episode on Valkey Glide" width="300" height="300" /></a></td></tr></tbody></table><a href="https://aws.amazon.com/new/&quot;&gt;For a full list of AWS announcements, be sure to keep an eye on the What's New at AWS page.</a><p><strong>Some other reading<br /></strong> My Belgian compatriot <a href="https://www.linkedin.com/in/apdf/&quot;&gt;Alexis&lt;/a&gt; has written the first article of a two-part series explaining <a href="https://community.aws/content/2s44xHTSbQgo2Ws2bJr6hZsECGr/building-a-serverless-remote-mcp-server-on-aws-part-1&quot;&gt;how to develop an MCP Tool server with a streamable HTTP transport and deploy it on Lambda and API Gateway</a>. This is a must-read for anyone implementing MCP servers on AWS. I’m eagerly looking forward to the second part, where Alexis will discuss authentication and authorization for remote MCP servers.</p><p><strong>Other AWS events</strong><br />Check your calendar and sign up for upcoming AWS events.</p><p><a href="https://aws.amazon.com/startups/lp/aws-gen-ai-lofts&quot;&gt;AWS GenAI Lofts</a> are collaborative spaces and immersive experiences that showcase AWS expertise in cloud computing and AI. They provide startups and developers with hands-on access to AI products and services, exclusive sessions with industry leaders, and valuable networking opportunities with investors and peers. <a href="https://aws.amazon.com/startups/lp/aws-gen-ai-lofts#locations&quot;&gt;Find a GenAI Loft location near you</a> and don’t forget to register.</p><p><a href="https://aws.amazon.com/events/summits/&quot;&gt;AWS Summits</a> are free online and in-person events that bring the cloud computing community together to connect, collaborate, and learn about AWS. Register in your nearest city: <a href="https://aws.amazon.com/jp/summits/japan/&quot;&gt;Japan&lt;/a&gt; (this week June 25 – 26), <a href="https://aws.amazon.com/events/summits/india/?trk=3368c877-be3a-40af-a52b-a7d03bf147ad&amp;amp;sc_channel=el&quot;&gt;Online in India</a> (June 26), <a href="https://aws.amazon.com/events/summits/new-york?trk=c3966d3c-23de-4937-89f8-3d5f25e808c6&amp;amp;utm_custom=c3966d3c-23de-4937-89f8-3d5f25e808c6&amp;amp;sc_channel=el&quot;&gt;New-York City</a> (July 16).</p><p>Save the date for <a href="https://aws.amazon.com/events/summits&quot;&gt;these upcoming Summits in July and August</a>: Taipei (July 29), Jakarta (August 7), Mexico (August 8), São Paulo (August 13), and Johannesburg (August 20) (and more to come in September and October).</p><p>Browse all upcoming <a href="https://aws.amazon.com/events/explore-aws-events/&quot;&gt;AWS led in-person and virtual events here</a>.</p><p>That’s all for this week. Check back next Monday for another Weekly Roundup!</p><a href="https://linktr.ee/sebsto&quot;&gt;— seb</a><p><em>This post is part of our <a href="https://aws.amazon.com/blogs/aws/tag/week-in-review/&quot;&gt;Weekly Roundup</a> series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p></section><aside id="Comments" class="blog-comments"><div data-lb-comp="aws-blog:cosmic-comments" data-env="prod" data-content-id="3bb66810-c136-4791-ab69-1ab2a05f2fa2" data-title="AWS Weekly Roundup: re:Inforce re:Cap, Valkey GLIDE 2.0, Avro and Protobuf or MCP Servers on Lambda, and more (June 23, 2025)" data-url="https://aws.amazon.com/blogs/aws/aws-weekly-roundup-reinforce-recap-valkey-glide-2-0-avro-and-protobuf-or-mcp-servers-on-lambda-and-more-june-23-2025/&quot;&gt;&lt;p data-failed-message="Comments cannot be loaded… Please refresh and try again.">Loading comments…</p></div></aside>

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

AWS re:Inforce 安全 Lambda S3 Valkey
相关文章