JUL 24, 2026
EngBrief
Search⌘K
LatestTopicsSourcesSaved
Eng&Brief

Engineering insights from the world's best tech companies, curated and summarized.

Weekly brief

Browse

TopicsSourcesFavorites

More

SearchRSS Feed
© 2026 EngBriefUpdated every 4 hours
← Sources
aws.amazon.com icon
Cloud Architecture

AWS Architecture Blog

66 articles on EngBrief

The AWS Architecture Blog provides guidance on building well-architected solutions on Amazon Web Services. Posts cover cloud design patterns, reference architectures, cost optimization strategies, and best practices for reliability, security, and performance across AWS services.

Cloud ArchitectureServerlessCost OptimizationReliability
Visit blog →

Latest Articles

AWS1d ago

Building a serverless AI assistant at Pelago: concept to care in two weeks

The Pelago engineering team built a serverless AI assistant in two weeks using AWS services such as Amazon Bedrock and AWS Lambda, enabling contextually aware suggested considerations for the care team. The event-driven architecture separates concerns, allowing the AI assistant to process messages asynchronously without blocking the user experience. The system generates pre-generated suggestions, stored in a database, and retrieves them instantly when a care team member opens a conversation. The team used Amazon SNS for message fan-out and decoupled processing, adding the AI Chat Assistant feature without modifying existing message-handling code. This architecture also enabled organic scaling with each Lambda function scaling horizontally based on current traffic.

CloudArchitecture
1 min
AWS1d ago

Building multi-Region resiliency for AWS CloudFormation custom resource deployment

Here is a concise 3-sentence summary of the engineering blog post: A team at AWS designed an active-active multi-Region architecture to provide resiliency for AWS CloudFormation custom resource deployment, addressing native gaps in fan-out, execution, and failover mechanisms. The solution utilizes Amazon DynamoDB Global Tables for distributed locking, idempotency, and state tracking, along with Amazon Application Recovery Controller for automated failover and Amazon SNS for cross-Region event fan-out. This architecture enables mission-critical workloads to handle regional failures, achieving high availability and preventing duplicate processing risks in multi-Region custom resource designs.

CloudArchitecture
1 min
AWS1d ago

Architecting offline-first generative AI applications for edge deployments using AWS services

Here's a 3-sentence summary of the blog post: A reference architecture for offline-first generative AI applications at the edge is presented, using AWS services including Amazon Bedrock, SageMaker AI, AWS IoT Greengrass, and Strands Agents. The architecture addresses the challenge of customizing large-scale AI models for reliability and scalability, using a hybrid approach that combines fine-tuning, continued pre-training, and retrieval-augmented generation (RAG) to optimize performance and accuracy. The design involves careful coordination across multiple AWS services and deliberate trade-offs between model capability, hardware constraints, and operational complexity to achieve a cost-effective and scalable edge-deployment of generative AI applications.

CloudArchitecture
1 min
AWS1d ago

Automate custom PII detection at scale with Amazon Macie and Step Functions

Here is a 3-sentence summary of the engineering blog post: A fully automated pipeline detects custom personally identifiable information (PII) at scale using Amazon Macie and Step Functions, enabling real-time PII detection and minimizing manual intervention in regulated industries. The pipeline triggers Macie classification jobs for each object, using built-in and custom data identifiers, and generates compliance reports with timestamps in CSV and JSON formats. The solution also publishes real-time notifications through SNS for high-severity findings and implements a three-bucket pattern for clear data lineage, making it suitable for organizations handling sensitive data.

CloudArchitecture
1 min
AWS6d ago

Eclipse Dataspace Components on AWS: Cost optimization strategies

Here's a summary of the engineering blog post in 2-3 concise sentences: The AWS Architecture blog series provides a cost optimization strategy for deploying Eclipse Dataspace Components (EDC) connectors on AWS, which can reduce spending by up to 58%. The main cost drivers identified in business-critical deployments are database (Amazon Aurora PostgreSQL) and compute resources (Amazon ECS with AWS Fargate), while non-critical deployments can reduce costs through rightsizing and Amazon EC2 Spot capacity. By understanding cost drivers and optimizing resource utilization, EDC connector deployments on AWS can achieve performance efficiency while controlling costs.

CloudArchitecture
1 min
AWS6d ago

Eclipse Dataspace Components on AWS: Architecture patterns in production

Here is a 3-sentence summary of the blog post on Eclipse Dataspace Components on AWS: To deploy Eclipse Dataspace Components (EDC) connectors in production on AWS, a deliberate architecture is required around isolation, managed services, and security layering, using AWS services such as Amazon S3 for data storage and AWS Secrets Manager for credentials management. The recommended architecture pattern involves container orchestration with Amazon ECS and AWS Fargate, persistence with AWS Secrets Manager and Amazon Aurora, and secure data storage with Amazon S3, and can be automated using AWS Cloud Development Kit (CDK). This architecture pattern ensures operational excellence, security, and reliability through principles such as Observability as a First-Class Concern, Managed Services Over Self-Managed Infrastructure, and Fail Fast, Recover Automatically.

CloudArchitecture
1 min
AWS6d ago

Eclipse Dataspace Components on AWS: Data sharing fundamentals

To implement Eclipse Dataspace Components (EDC) on AWS, developers can utilize AWS services like Amazon Elastic Container Service (Amazon ECS), Amazon Aurora, and Amazon API Gateway for production-ready deployment patterns. The EDC architecture is based on the International Data Spaces Association (IDSA) standards and the Dataspace Protocol (DSP), allowing for decentralized identity verification using the Decentralized Claims Protocol (DCP). The EDC connector has a modular, plugin-based architecture that enables customization for native AWS service integration, such as connecting to Amazon S3 for data storage and AWS Secrets Manager for credentials management.

CloudArchitecture
1 min
AWS7d ago

Prioritize your AWS Health alerts using AWS User Notifications

AWS Architecture provides a solution to prioritize AWS Health alerts using AWS User Notifications, addressing the issue of overwhelming operational teams with alerts of varying urgency. The solution filters health events to only notify about monitored services, then separates the remaining events into two priority tiers: Critical and Informational. Critical events are sent immediately, while Informational events are batched and delivered in a five-minute window. This solution uses a lightweight approach, deploying a single AWS CloudFormation template with four deployment modes: Linked (single account), Payer (organization-wide), Combined (single account with custom email), and PayerCombined (organization-wide with custom email). Deploying the template creates a prioritized notification system for AWS Health alerts, ensuring targeted alerting and faster response times for operations teams.

CloudArchitecture
1 min
AWS8d ago

How bitdrift scaled to 121 million concurrent gRPC connections on Amazon CloudFront for live telemetry sporting events

Bitdrift, a mobile observability platform, scaled to handle 121 million concurrent gRPC connections on Amazon CloudFront for live telemetry sporting events. They resolved a DNS resolution imbalance issue under peak load by switching from weighted to multi-value answer routing in Route 53. This change distributed the load across multiple Network Load Balancers (NLBs), eliminating the single-origin bottleneck and resulting in zero server-side errors.

CloudArchitecture
1 min
AWS11d ago

Unlocking the future of video March Networks cloud storage on AWS

March Networks built a scalable cloud architecture on AWS to support large-scale enterprise video storage and analytics, leveraging Amazon S3 and Amazon S3 Glacier to manage long-term video retention. This solution enables organizations to cost-effectively store petabyte-scale video data while accelerating investigations and operational insights. By integrating with additional AWS services, the architecture provides secure ingestion, lifecycle management, monitoring, and access control. The March Networks Cloud Storage solution is designed for distributed enterprise environments, offering multiple deployment models that allow organizations to adopt cloud storage at their own pace. The platform supports automatic scaling of storage capacity based on customer needs, eliminating the need for hardware planning or infrastructure expansion. By leveraging AWS cloud infrastructure and March Networks' video surveillance expertise, organizations can modernize video retention strategies while maintaining operational flexibility.

CloudArchitecture
1 min
AWS11d ago

How MAPFRE USA modernized fraud claims with Amazon EMR Serverless

MAPFRE USA leveraged Amazon EMR Serverless, Neo4j, and AWS services to modernize its fraud claims detection, increasing efficiency and accuracy. The solution integrated graph-based features with machine learning models to identify complex relationships and hidden networks involved in fraudulent claims. The architecture, called Atenea, enabled elastic, cost-efficient compute, and robust orchestration, with a layered lakehouse design supporting flexibility and scalability. The Atenea platform processed batch data, enriched graphs, trained and scored ML models, and performed CI/CD operations on Amazon EMR Serverless. It integrated with Guidewire Claims, automatically creating fraud alerts with explanations for front-line adjusters, and securely stored credentials and tokens using AWS Secrets Manager. The solution also implemented monitoring and reliability using Amazon CloudWatch and Amazon SNS. MAPFRE's solution closed the loop between ML predictions and claims handling by integrating with Guidewire Claims, enabling automatic creation of Guidewire activities with fraud explanations for investigators. The integration used

CloudArchitecture
1 min
AWS14d ago

Specification-driven composition for flexible data workflows

Specification-driven composition separates workflow intent from implementation, making data pipelines more scalable and easier to manage. This approach reduces duplication, shortens onboarding time for new datasets, and improves consistency across workflows. Key components include a specification document (in JSON or YAML format) that describes workflow intent, a composer that assembles the workflow from reusable capabilities, a capability registry that stores metadata about transformation functions, and a pipeline that runs a sequence of transformation steps.

CloudArchitecture
1 min
AWS16d ago

S&P Global’s innovative disaster recovery strategy using Amazon FSx for NetApp ONTAP snapshots

S&P Global implemented a disaster recovery solution for their Capital IQ platform using Amazon FSx for NetApp ONTAP, enabling immediate failover to a read-only mode in a secondary region within 15 minutes. The solution leverages SnapMirror replication and FlexClone technology to maintain data consistency and reduce failover time, facilitating business continuity without compromising data integrity. Key benefits include sub-15-minute recovery, storage efficiency, and data consistency, making it suitable for global financial operations with strict Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).

CloudArchitecture
1 min
AWS24d ago

Lessons learned from scaling to 1 million Lambda functions

Here is a 3-sentence summary of the engineering blog post: ProGlove, a SaaS platform, scaled from 0 to 1 million AWS Lambda functions, pushing the limits of serverless architecture. Key lessons learned included the importance of true scale-to-zero, quota management, and engaging AWS service teams early to prevent outages. To scale efficiently, the team reevaluated practices such as serverless best practices, observability, and architectural patterns, adopting centralized solutions like AWS CloudFormation StackSets and a dedicated observability platform to reduce costs and improve performance.

CloudArchitecture
1 min
AWS24d ago

Preventing data exfiltration in machine learning environments with Amazon SageMaker AI

Here is a 3-sentence summary of the blog post: iBusiness, an AI-driven fintech organization, implemented a three-layered security architecture using Amazon SageMaker AI and AWS services to prevent data exfiltration while maintaining data scientist productivity. The solution comprised securing access through Amazon WorkSpaces Secure Browser, restricting browser activity and cross-account access, and securing the SageMaker AI environment itself to prevent data exfiltration through the development environment's terminal and IDE access. By implementing this architecture, the organization achieved an 80% cost reduction and transformed IT operations, reducing provisioning time and eliminating ongoing desktop maintenance overhead.

CloudArchitecture
1 min
AWS24d ago

Dual-token authentication for Nakama game servers with Amazon Cognito on AWS

Engineers can implement a dual-token authentication system for Nakama game servers on AWS using Amazon Cognito. This approach ensures secure authentication by issuing a JWT from Cognito and validating it in the game server while maintaining a separate Nakama session token. The system consists of four layers: client, CloudFront, Application Load Balancer (ALB), and Network Load Balancer (NLB), each performing specific functions to authenticate players and route traffic securely. Key components include the Cognito User Pool for SRP-based client authentication, a Go runtime hook for validating Cognito JWTs and bridging player identity to Nakama sessions, and a default-closed routing layer using Amazon CloudFront, ALB, and NLB. This architecture enables a seamless player experience by authenticating players without interrupting gameplay. The proposed solution consists of five main steps: client authentication with Amazon Cognito, validation of the Cognito JWT in the Go hook, retrieval of the Nakama session token, routing of traffic

CloudArchitecture
1 min
AWSJun 22, 2026

Secure multi-tenant RAG with Amazon Bedrock and Verified Permissions

Engineers faced a challenge in controlling access to corporate documents in a shared generative AI application. To solve this, they used Amazon Bedrock's Knowledge Base, which enables retrieval, and Amazon Verified Permissions for dynamic access control. This setup allows a single RAG (Retrieval Augmented Generation) application to serve multiple departments while maintaining document isolation between groups. The solution uses a two-layer authorization pattern, with Amazon Verified Permissions managing granular, intra-tenant access control through Cedar policies, and Amazon Bedrock's metadata filtering ensuring documents are isolated at retrieval time. This setup reduces costs and operational overhead, making it ideal for organizations that need to control access to documents across departments, teams, or roles within a single organization.

CloudArchitecture
1 min
AWSJun 22, 2026

Modernizing financial analytics with Amazon SageMaker Unified Studio

Avanse Financial Services migrated from a two-application model to a cloud-native lakehouse architecture using Amazon SageMaker Unified Studio. This move eliminated synchronization bottlenecks, enabled usage-based pricing, and improved auditability by unifying data engineering, analytics, and AI workflows. The new architecture consists of a data layer on Amazon S3, a compute layer with project-based workspaces, and a governance layer with IAM Identity Center and SageMaker Catalog. The migration journey consisted of five phases, including technical validation, data migration and storage optimization, compute modernization, governance implementation, and production deployment. Avanse achieved significant cost savings, eliminated the need for custom-built pipelines, and improved analytics and AI capabilities through native integration with their existing AWS services. The result is a unified data environment that streamlines data discovery, eliminates data silos, and provides real-time analytics and AI capabilities, enabling Avanse to make data-driven decisions with up-to-date information.

CloudArchitecture
1 min
AWSJun 22, 2026

Architecting AI-powered resilience framework on AWS

Here's a 2-3 sentence summary of the blog post: To ensure system resilience and prevent costly outages, a five-layer AI-powered framework is proposed, which combines AWS Resilience Hub, Fault Injection Service, Amazon Bedrock AgentCore, and Systems Manager to automatically discover infrastructure dependencies, generate targeted experiments, and integrate with CI/CD pipelines. This framework aims to reduce the expertise barrier that hinders resilience testing and provides a continuous validation loop to ensure the system's ability to withstand turbulent conditions. By automating resilience testing, organizations can reduce MTTR by approximately 50% and achieve cost savings of up to 58% per event.

CloudArchitecture
1 min
AWSJun 17, 2026

Reducing SMS OTP fraud with Vonage network-powered solutions and Amazon Cognito

Here's a summary of the blog post in 2-3 concise sentences: Vonage network-powered solutions, combined with Amazon Cognito, enhance mobile-first use cases by providing stronger identity assurance and a smoother experience through real-time mobile operator intelligence and silent authentication. The solutions, comprising Identity Insights, Verify, and Fraud Defender, enable enterprises to detect and prevent SIM swaps, account takeovers, and other types of fraud, alleviating the friction tax associated with traditional SMS OTP flows. This results in significant cost savings and revenue gain for enterprises, with Vonage customers saving over $3M in SMS-related fraud costs since deployment.

CloudArchitecture
1 min