Skip to content Skip to footer

Release & Changelog Watcher — August 5, 2026

What Happened

  • AWS Network Firewall — explicit proxy reintroduced: AWS reintroduced an explicit forward proxy as built‑in Network Firewall functionality using a “no‑source‑preservation” deployment that shares your existing Firewall policy across proxy and transparent modes. The proxy supports managed rule groups, active threat defense, Geo‑IP and URL/domain category filtering, and container attribute–based rules for Amazon EKS and ECS. The feature is in public preview and available to try in US East (Ohio) and is free during preview [1]. (Original proxy preview was introduced Nov 25, 2025) [1].
  • Amazon Connect — CSV export for Cases: Agents can now export selected Cases to CSV directly from the agent workspace, choose which fields to include, and administrators control export rights via a security profile permission. Cases is available in multiple regions (including N. Virginia, Oregon, Frankfurt, London, Seoul, Singapore, Sydney, Tokyo, Canada Central, Cape Town) [2].
  • Amazon Connect — finer interval capacity planning: Connect Customer now supports capacity plans at 15‑ or 30‑minute intervals across Voice, Chat, Task and Email, with per‑interval shrinkage and available headcount settings; available in all regions where Connect agent scheduling is offered [4].
  • Amazon S3 Vectors — Germany (European Sovereign Cloud) availability: Amazon S3 Vectors (purpose‑built vector storage for agents, RAG, semantic search at billion‑vector scale) is now available in the AWS European Sovereign Cloud (Germany) Region, providing S3‑like durability and dedicated vector APIs [3].

Why It Matters to Businesses

  • Policy consolidation and simpler edge security: Reintroducing the explicit proxy as a mode of Network Firewall lets security teams use a single firewall policy for both proxy and transparent deployments, reducing policy drift and audit surface [1].
  • Faster AI feature deployment with local vector storage: S3 Vectors in the German sovereign region reduces latency for EU workloads, simplifies compliance with data‑residency requirements, and scales vector storage without provisioning custom infra for RAG and semantic search [3].
  • Operational efficiency in contact centers: CSV export speeds integrations with vendors, legal and analytics teams by removing manual extracts, and 15/30‑minute interval planning improves staffing accuracy for intra‑day demand variation—both reduce overstaffing and service‑level shortfalls [2][4].
  • Testing and migration windows: Network Firewall proxy is in preview (Ohio) and free during preview—an opportunity to validate traffic flows and policy parity before full production adoption [1].

Kimbodo Engineering Perspective

We view these changes as pragmatic infrastructure improvements that reduce integration friction but raise operational trade‑offs that need engineering attention.

  • Network Firewall proxy trade‑offs: Consolidating policies reduces management overhead, but the no‑source‑preservation proxy mode changes source IP visibility and may affect existing logging, authentication, and IP‑based controls. You must validate end‑to‑end telemetry and update SIEM/IDS rules. Preview availability (Ohio) is the right staging ground for phased rollout [1].
  • Sovereign vector storage trade‑offs: S3 Vectors in the German sovereign region solves residency and latency concerns for EU customers, but expect vendor‑specific semantics for vector APIs and potential lock‑in for index/query behavior. Design your abstraction layer to allow fallback to other vector stores if needed [3].
  • Contact center features trade‑offs: CSV export adds convenience but increases data‑exfiltration risk; export permissions must be integrated into existing RBAC and DLP workflows. Finer interval staffing improves accuracy but increases data granularity and forecasting complexity—ensure models and tooling ingest interval‑level forecasts efficiently [2][4].

How We Would Implement It

Network Firewall Proxy (no‑source‑preservation)

  • Stage: pilot in US East (Ohio) preview environment to validate policy parity and traffic flows [1].
  • Architecture: deploy Network Firewall in no‑source‑preservation proxy mode in a transit VPC or shared services VPC; route egress through the firewall via VPC route tables and VPC endpoints where appropriate.
  • Policy & rules: import existing managed rule groups and enable Geo‑IP, URL/domain category and container attribute rules. Create a canonical policy baseline and run automated policy diff tests between proxy and transparent modes.
  • Observability: enable Network Firewall logging to S3 and CloudWatch; forward logs to SIEM and run integration tests verifying source IP handling, X‑Forwarded‑For headers, and IDS signatures.
  • Validation steps: synthetic traffic tests across EKS/ECS pods with container attribute rules, end‑to‑end latency and throughput benchmarks, and roll back plan to transparent mode if authentication or logging breaks.

S3 Vectors — Germany (European Sovereign Cloud)

  • Provision: create S3 Vectors buckets in the DE sovereign region and enable KMS customer‑managed keys in that region for encryption at rest [3].
  • Integration: abstract vector store behind an internal SDK to decouple application code from vendor vector semantics; use regional endpoints and VPC Gateway/Interface endpoints for private connectivity.
  • Data governance: enforce IAM/STS roles, fine‑grained bucket policies, and per‑project encryption keys. Implement lifecycle policies and backups (periodic snapshots of vectors/metadata) and audit access with CloudTrail.
  • Operationalization: design for sharding and batching at ingest, use approximate nearest neighbor (ANN) tuning parameters in CI to control recall/latency trade‑offs, and load‑test to expected billion‑vector scale before production roll‑out.

Amazon Connect — CSV Export & Interval Capacity Planning

  • Enablement: grant CSV export permission through Connect security profiles only to approved roles; add DLP scanning for exported files stored in S3 or shared outside the org [2].
  • Workforce integration: switch capacity planning to 15/30‑minute intervals in staging, backfill historical data to retrain forecasting models, and update WFM ingestion pipelines to accept interval‑level schedules and shrinkage assumptions [4].
  • Automation: wire exports into an automated ETL pipeline (e.g., EventBridge → Lambda → S3 → Redshift) for downstream analytics and vendor sharing with enforced retention and access controls.

Risks, Costs and Security

  • Logging and observability risks: no‑source‑preservation proxy changes source visibility; missing changes to logging/headers may break authentication, fraud detection, and incident response—test SIEM correlations and update parsers [1].
  • Data‑exfiltration and governance: CSV exports increase leakage risk; enforce RBAC, DLP, and S3 lifecycle and access logging. Audit exports regularly and limit the fields available for export [2].
  • Vendor lock‑in and portability: S3 Vectors uses dedicated vector APIs—maintain an abstraction layer and export/ingest tooling to mitigate lock‑in and to allow migration to other vector stores if needed [3].
  • Cost considerations: preview usage of Network Firewall proxy is free during preview, but production proxy and managed rule usage will incur charges. S3 Vectors will have storage and query costs—benchmark expected vector counts and query patterns to model costs. Finer interval staffing increases data storage and compute for forecasting systems [1][3][4].
  • Compliance and residency: S3 Vectors in the German sovereign region reduces cross‑border concerns, but verify replication, backups, and third‑party integrations do not export data unintentionally [3].
  • Operational complexity: enabling container attribute rules and interval staffing increases configuration surface—use IaC, policy as code, and CI pipelines to validate changes before deployment.

Where Kimbodo Comes In

Kimbodo builds and operates this in production for businesses — see our AI Application Development practice. Wondering what it would cost for your organization? Get a preliminary range, timeline and architecture in about a minute.

Estimate My AI Application

Sources

  1. [1] [Preview Announcement] Re-introducing Forward Proxy as AWS Network Firewall Functionality
  2. [2] Amazon Connect Customer now lets you export cases to CSV from the agent workspace
  3. [3] Amazon S3 Vectors is now available in the AWS European Sovereign Cloud (Germany) Region
  4. [4] Amazon Connect Customer now supports capacity planning in 15 or 30 minute intervals

Leave a comment

0.0/5