@0xdabbad00 I wonder given the values in sts:IdentityTokenAudience what will be kept in aws land. Easy per user token tracking in anthropic with billing tied back to aws? Models still hosted by bedrock?
@craigaloewen new WSL features look great!
Is there anything on the roadmap for this issue around mirrored networking supporting virtual NICs in WSL? https://t.co/gw8SXvEfWd
@IanColdwater@ladyleet Do you think you or the senior people would have got ahead without the extra effort that led to burnout? Is it more getting there quicker because of all the extra effort?
@ben11kehoe@pgarbe@AWSCloudFormer@spanierm42 What are all the benefits? I thought the main one was API additions to the provider as the code can be autogenerated. I feel like I'm missing something!
@__steele This also allows for extra claim checking. Normally you are limited to amr, aud, id, & sub. Using a cognito role mapper, you check arbitrary claims and map to a "deny" IAM role if they don't match.
@ben11kehoe@rchrdbyd I was trying to recreate this but you cannot change the passthrough behaviour for proxy integrations anymore. Although the problematic, unchangeable behaviour is still WHEN_NO_MATCH.
@ben11kehoe@hoo29 It's a good question. The main benefits of Cedar are:
*Verifiable/Analyzable
*Deterministic Low Latencies
*No Security Sandboxing Needed
*Ergonomic (easily readable)
*Enables parallel execution
More here: https://t.co/M4DTvvI5Hf
@ben11kehoe How does this compare to OPA? I assume it fills some gap to warrant AWS creating something new but it would have been nice to have OPA support for AWS Verified* services.