# 366: You just can’t kill a good JWT Duration: 61 minutes Speakers: Matt, Justin Date: 2026-08-12 ## Transcript [00:07] Matt: Welcome to The Cloud Pod, where the forecast is always cloudy. We talk weekly about all things AWS, GCP, and Azure. [00:14] Justin: We are your hosts, Justin, Jonathan, Ryan, and Matt. [00:18] Matt: Episode 366 recorded for August 4th, 2026. You can't, you just can't kill a good JOT. Good evening, Ryan. How you doing? I'm doing well. [00:28] Justin: Good. Took a few episodes off, kind of bouncing in and out of vacations and work travel. [00:34] Matt: But I mean, I have so lost track of your guys's who's here and who's not here. Like you were like earlier, like I wasn't here for a few weeks. I was like, you weren't? [00:40] Justin: You weren't? Yeah. No, time is merely a construct that I no longer follow or pay attention to anymore anyway. [00:46] Matt: So yeah, it's like we, we show up on Tuesday if you're here or not, we record and you know, we, we move on with our life cuz trying to coordinate cats to get this recording done is too much work. [00:55] Justin: It is really funny how that's the hard work of the podcast. You've auto— [00:59] Matt: you've automated everything else away. Yeah, it was just me doing it, you know, back in the Peter days. And then, you know, Matt joined and Matt feels like responsible and like he should be something. So he also likes to chase you guys down, which I think is great. Like, I love this cuz I'm not the only one nagging you two, which is hilarious. And then, uh, but he's, uh, he's on business trip this week, so he was like, I can't. [01:18] Justin: He's off the hook. [01:19] Matt: Yeah, he's off the hook. So anyways, though, we got, uh, we got news to cover, and, uh, unfortunately we're gonna start it out strong with earnings, which I'm sure you'll have lots of value to add to this. Big numbers go big. [01:38] Justin: Oh yeah. [01:39] Matt: Uh, all right, let's start with Google, who announced their earnings first. Uh, Google Cloud revenue grew 82% year over year to $24.8 billion, the standout number in an otherwise mixed earnings report and beat Wall Street's overall revenue expectations of $116.93 billion with $119.8 billion. Hey, $3 billion, nothing to sneeze at. [01:59] Justin: Nope. [02:00] Matt: Alphabet raises its 2026 CapEx guidance to $195 to $205 billion, up from the $180 to $190 billion forecast given just last quarter, with Q2 CapEx alone up 100% year over year to $44.9 billion. That's a lot of GPUs. Yeah, it is. CFO Anant Ashokanazi— I don't even know who that is. Cited continued supply constraints and strong demand for both external cloud customers and internal AI workloads. We gotta feed the Gemini beast. Despite the cloud growth, and remember the beat, stock dropped in after-hours trading, suggesting investors are more focused on the scale of AI infrastructure spending than current cloud performance gains. Google said their Antigravity AI coding tool reported 2.4 million weekly active users, which, that's impossible, because no one uses it. And the Gemini app has scaled to 950 million monthly active users, processing 22 billion tokens per minute. Are they counting the Google search users in that number, do you think? Uh, but they do say competitive pressure is mounting from Chinese overweight models pushing token costs down, prompting Google to release 3 cheaper Gemini models this week, uh, which we talked about actually last week. [02:58] Justin: So yeah, I mean, someone's got to be using Google Anthropic Gravity. I, I don't know who, because I don't know anyone firsthand, but I keep seeing it come up in like agent definitions and other workflows, and I do hear it mentioned in the news. But sort of surprising. [03:13] Matt: I tried to use it a couple times, but I apparently don't have the correct AI subscription to make it work with the SaaS LLM Cloud Pod. Um, yeah, you know, one. So I, I don't know, man. Like I, I would like to try it. [03:26] Justin: I just can't. So I have my own workflows. I don't need another one. [03:30] Matt: Yeah. I mean, like I'm pretty happy with Cloud Code. I plug in some Kyma, K2, you know, K27 and Kyma 3 behind it. And I'm very happy with Cloud Code as the harness. I also use Claude models as well. And you know what, I, every time I ever try to go use Cortex or I go try to use the other ones, I'm just like, yeah, this is nice, but I just kind of like, I like my warm blanket of Claude code. I just, I like it. I know how it works. I know how its idiosyncrasies, I know how to make it work and bend to my will. So yeah, I don't know. I try to use OpenCode as well. Like again, cause like why am I locking myself into Anthropic? So at least the fact that Anthropic can use any model, that does help out quite a bit. [04:02] Justin: Yeah, it does. Once they made that change, it's nice. [04:04] Matt: Yeah, I do really wish I could get like some type of proxy, like a Bifrost proxy that would like look at what my request is and then pick between Claude and OpenModels and which is the best of the bunch. I gotta look into that. I bet there's a way, I just don't know how to do it, so. [04:19] Justin: I know the Copilot plugin in VS Code will do that for you if you configure it, which is, you know. [04:26] Matt: Pretty handy, yeah. [04:27] Justin: It is pretty handy. [04:29] Matt: All right, well I'll check that out. I'll report back. Up next, AWS reported 37% revenue growth to $42.23 billion in Q2, beating analyst estimates of $40.54 billion and accelerating from 28% growth in Q1, its strongest quarter since 2021. Which I was thinking about that, I was like, yeah, every time we talked about AWS earnings, we talked about the shrinking growth number because, you know, we always said the laws of big numbers makes it hard to hit those percentages. But apparently even in a business the size of Amazon, you can go the other direction. So good job, Amazon. AI and chip products each surpassed $25 billion in annualized revenue, more than doubling year over year, showing customer demand is translating into concrete revenue rather than just capacity buildouts. All three cloud providers actually had reported accelerated growth, with Azure at 43%, Google at 82%, as we just talked about, and now Amazon at 37%. Though AWS remains the largest by absolute revenue at $148.4 billion. Uh, AWS operating margin came in at 36.8%, slightly ahead of Google Cloud's 35.6%, and the segment now accounts for nearly 61% of Amazon's total operating profit. Underscoring how central cloud has become to Amazon's overall profitability. If you have dreams of splitting the store from the web host, never going to happen. [05:37] Justin: Yep. [05:38] Matt: Nope. Capital expenditures jumped 68% to $54.21 billion for the quarter, reflecting continued heavy investment in AI data center capacity and chip infrastructure to meet demand. Uh, they're— I don't remember their earnings the next day, but I'm pretty sure they were up the next day. I don't know where they're at this week because Iran's in trouble. Uh, so yeah, stock market's been all over the place this week. Yeah, but, uh, you know, at least, uh, it looks like over the last week or so it's up $47. So Amazon's not hurting. [06:03] Justin: No, I mean, it is interesting 'cause I think AWS is, you know, they're growing their capital expenditures with the data center expansion and I think that's, you know, they've always been sort of expensive, but they've offset the profit, you know, so much, uh, that they've always helped the store margins. But I think they're sort of equal, not equalizing, but going in that direction. And so it is sort of interesting to see how that continues with the growth because it is expensive and it is ballooning. [06:29] Matt: It is. And then finally, Microsoft wraps us up with beating their Q4 expectations with $90.1 billion revenue, up 18% year over year, and $0.74 adjusted EPS, earnings per share, uh, versus $4.24. So 50-cent beat on earnings per share. Uh, their shares up 8% after hours trading. Net income of $35.77 billion was boosted by a $3.2 billion gain from the Anthropic investment. So they're also making money on their investments, which is great. Azure specifically, revenue grew, growth accelerated to 43% year over year, up from 40% the prior quarter. And Azure surpassed $100 billion in annual revenue for the first time, up 41% for the fiscal year. This keeps Azure behind AWS but ahead of Google Cloud. So they are a solid number 2. Uh, capital expenditures and finance leases jumped 69% to $41 billion for the quarter. The CFO, Amy Hood, extending the useful life of data center and office buildings from 15 to 25 years. And shifting more future leases to operating lease treatment. This accounting change could lead to a projected $175 billion in CapEx and finance leases for 2026, which is just money playing with it. Microsoft 365 Copilot reached over 30 million paid seats, up from 20 million in April, and GitHub Copilot now has 50 million users, indicating continued enterprise adoption of AI-assisted productivity tools. I can tell you that I now have access to Microsoft 365 Copilot. I've had it for 2 days. Uh, I don't hate it. I don't love it. It's definitely better than Gemini Enterprise. I'll let you, I'll report back. [07:50] Justin: Hmm. [07:50] Matt: Still experimentation is still early, but I'm like, it's not bad. Not bad. That's a, which for me is high praise. [07:57] Justin: That is high praise. Uh, I'm, I am not sure about your assessment of better than Gemini Enterprise, but, uh, cause I don't like it that much. [08:04] Matt: Well, I mean, we're a Microsoft shop with Copilot versus other day jobs that I used to be at, which were Microsoft shops with Gemini Enterprise, which I think is the wrong combination. I think if you are a Google shop, you should be on Gemini Enterprise. I think if you're a Microsoft shop, you should probably be on Copilot, I think is my, my general feel at this exact moment. [08:23] Justin: All right. [08:24] Matt: I wonder if this is an implementation thing, 'cause it also could be an implementation thing. 'Cause I also, uh, have been exposed to a whole new Teams world and like, if you know how to actually manage Teams properly, it's not as bad. [08:35] Justin: Got it. [08:35] Matt: 5% better than I thought about it before. 5%. That's all I can give you. [08:40] Justin: Still prefer Slack every day of the week, but I still think that's high praise. [08:44] Matt: Yeah, very, very possible. Only negative really was two things inside of Microsoft's earnings. Uh, analysts, uh, were— said there's a lot of concentrated risk tied to the OpenAI relationship with 45% of Microsoft's $625 billion commercial remaining performance obligations linked to OpenAI as of January. Uh, so that puts some risk for future earnings. Uh, then Xbox revenue— Xbox is on the ropes, man. So is PlayStation too. So neither Sony or Microsoft is, uh, very happy in the gaming space. Uh, their revenue declined 10% following job cuts and a spin-off of 4 Studios, you know. So overall, personal computing segment also fell 4.4%. Uh, so overall, no one's buying hardware right now because it's way too expensive. [09:22] Justin: Too expensive to buy memory. [09:24] Matt: And if you have a computer that's working just fine right now, like, I'd love to buy a new MacBook Pro this fall for my personal stuff, to get more memory, or even I was looking at buying maybe the StudioTron models and I'm just like, I don't think I'm gonna do that. Cause I don't know that I wanna mortgage my house to, uh, get it. [09:39] Justin: So yeah, I finally replaced my ancient computer and I bought a much smaller computer than I wanted to because I just couldn't justify the cost. Yeah. And I, I definitely hit memory limitations all the time. Like it sucks. [09:51] Matt: Yep. Well, the worst kept secret in AI, uh, has finally arrived. Uh, MCP, the new spec has finally shipped. Uh, some of your MCPs have already been moving to this over the last few months with the early draft spec, but now it is officially official. MCP has moved from a stateful bidirectional protocol to a stateless request-response core, removing the requirement that requests be tied to a specific server instance session. This is the largest spec update since MCP launched and directly targets enterprise scalability concerns and security. The stateless design addresses reliability and scaling issues that developers had flagged as high priority, since server instances no longer need to maintain session state for individual clients, simplifying load balancing and horizontal scaling. Additional updates included multi-round-trip requests, header-based routing, cacheable list results, authorization hardening, and a formal extensions framework and updated tier 1 SDK, expanding both the security posture and the developer tooling. For teams out there building your AI agents or tool integrations, the shift to stateless architecture should make MZP servers easier to deploy behind standard Load Balancers and serverless or containerized environments, similar to typical stateless API design patterns. The update is maintained by Anthropic engineers David Soryapara and Dan Delavarsky. But to continue investment in MCP as infrastructure for AI tool calling standards across the industry, not just with Anthropic's own products. I thought they were going to donate MCP. Didn't they donate it? I guess not yet. No, it is, it is part of the Linux Foundation. It was donated into— yeah, it was donated in, in December, but they, they clearly still have the control. [11:17] Justin: Invested interest in it. Yeah. Yeah. I mean, this is great. I haven't really used MCP at a scale big enough where I hit any of these cases, but like you can see naturally this is where you are going to get bottlenecked is you'd be tied to single resources for MCP sessions. So this is a good move there. I also like the move to tokens issued from an IDP rather than sort of client secret, sort of maintaining of static credentials and then requesting refresh tokens. [11:44] Matt: I'm torn on it because, uh, most of the invitations I see are OAuth 2.0 and they're just like, you have to reauthenticate every couple of days. And I'm like, this is just annoying because I'll open up Claude and it'll be like, you have 7 MCPs you need to reauthenticate. I'm like, I'm like, come on, man. [11:57] Justin: Yeah, that, that, that can be a little frustrating for sure. [12:00] Matt: I need to figure out how to script that. I, it's one of those projects I have on the sideburns. Like, oh, there's gotta be a way to script this so that when I see it, I can just, you know, I'm like, 'cause even for like my AWS tokens for my Amazon accounts, I have a script I run when I need to get to them and it authenticates, you know, with the single sign-on commands and all that. So I don't have to think about it so much, but I just need something similar for the MCPs that way. I, 'cause I, I don't, I don't disapprove of the short-term credential. Yeah, I just disapprove of the method to having to log in on a website for OAuth 2 and come back. [12:28] Justin: For sure. No, I've always hated that model, but it's also sort of, I don't, you know, and with all the things and the amount of like phishing and other exploits, like it's sort of, I don't, you know, the balance between developer productivity and ease of use and security is taking a hit here. [12:46] Matt: Yeah. [12:47] Justin: Um, it is interesting though, how big of a change this is. Like if you're, if you already have an application out there, this is a big rewrite. You cannot just drop this in. It's very breaking. [12:58] Matt: Yeah, it's a breaking change, but it's a breaking change for all the right reasons, uh, versus, you know, Gemini, you know, end-of-lifing a legacy model, you know, for no reason other than they need the hardware for new other models. Yeah, those have— [13:09] Justin: yes, no, agreed. [13:11] Matt: We really don't have a great place for this to go, so it's here in AI is how LLM makes money. But Amazon apparently didn't make much money as they spent apparently $1.8 million using Claude for menial coding tasks went 860% over budget, and it was a catastrophically expensive coding blunder discovered in internal Amazon AI usage metrics. This comes from Tom's Hardware. Amazon's internal report revealed a Claude-signed deployment for matching author details to product listings went 860% over its allocated budget, resulting in a $1.8 million overrun that took 5 months to detect. Additional cost overruns included $541,000 on a financial auditing tool project and $134,000 on logistics delivery time optimization system, both attributed to unexpected AI token consumption. [13:50] Justin: Consumptions. [13:51] Matt: The core issue stems from agentic AI workflows consuming tokens at a much higher rate than traditional coding methods, turning previously low-cost tasks into significantly expensive expenses when left unmonitored. Amazon's response characterized these as isolated learning examples rather than systemic problems, and in context, the overruns represent a small fraction of the company's monthly revenue. The story highlights the need for cost monitoring and guardrails when deploying an AI agent at scale. I mean, if Amazon can't do it right, how am I going to do it right? [14:15] Justin: Yeah, well, this is interesting, uh, because I To me anyway, cuz I, I, I've been playing a lot with my workflows and trying different sort of developer sort of tasks. And I realized that I had sort of unintentionally sort of put a similar sort of system in place where I was, I turned like my developer workflow into this like constant evaluation judgment where it was just burning tokens hand over fist. And I sort of had to, you know, look at that at a, you know, a different angle because I, you know, I had the best intentions of trying to get these, you know, coding agents to sort of self-govern and run autonomously and and, you know, complete bugs without me needing to be in the loop all the time, which is my constant battle. 'Cause then they do dumb things and I don't like it. But, you know, being in the review cycle is fatiguing 'cause there's a lot of code. But yeah, so I feel a little better 'cause if Amazon can't do it, then it justifies my own sort of explosion of credit usage that I did a better job catching. But that's 'cause I hog out on my usage 'cause I hate running out of tokens. [15:17] Matt: Yeah. I mean, I, this is where I feel Anthropic is really the tooling on the backend of Anthropic. I mean, they have amazing models, but the enterprise tools, the enterprise controls, the focus billing data, like all of it is so weak. Yeah. And it's like, you know, a lot of the stuff is in the data they have. Like, you know, if you're, if a tool's creating a PR, you should be able to output how many PRs did the tool create? Um, or as, as an event into, you know, cuz they insist on you using OpenTelemetry for everything. And I just, I, it frustrates me that like, please Anthropic, hire me and I will help you figure out how to write this for enterprise because you guys desperately need to make this better. And I'll, I, you know, I wouldn't mind some Anthropic equity before IP. No, it'd be fine. You know? No. So I, I mean, I would definitely consider it. I mean, I, I think you would consider, I'd be a janitor there, to be honest, at this point. Uh, if it included equity. [16:05] Justin: Yeah. If you want to, if you want me to fetch coffee and just, you know, be hopefully the personality hire. I'm all gay. Yeah. [16:12] Matt: You bring the personality higher and that's, that's a culture that— [16:15] Justin: not all personalities have to be good. [16:18] Matt: That's true. That's true. Uh, but yeah, no, I, uh, I always joke about it all the time. Like, uh, hey, Anthropic, call tomorrow. It's like, you can be a janitor here. I'd be like, yes, I could. If you have equity involved in it. Um, yeah, I can be that story in the Wall Street Journal about the, you know, the chef who ran the kitchen, you know, the, the lunchroom is now a bajillionaire. You know, I'm fine with that story. Yeah. Why does that have to be me? You know, or someone else, you know, could be me. I mean, I don't deserve it, but it's fine. All right. So we want to secure— Call us Anthropic. Exactly. All right. Let's move on to security. So 2 weeks ago, we talked about Patch Tuesday, which was a disaster of like 700-some-odd vulnerabilities from Microsoft. Thank you very much. And then last week we talked about the Linux kernel and their 543-some-odd vulnerabilities. Vulnerabilities, and this week Apple is here with their vulnerabilities. They've apparently capped the number of open bug bounty submissions per researcher and added a 30-day cool-off period implemented in June in response to a surge of AI-generated vulnerability reports. Researchers, researchers can request quota increases for critical findings, of course. The change reflects an industry-wide problem. LLMs are now capable of finding, chaining, and exploiting vulnerabilities at a volume that outpaces manual review teams, forcing companies to rate limit submissions rather than review capacity. Apple recently accelerated security patches, uh, specifically due to AI-assisted vulnerability discovery, and has credited researchers using tools from OpenAI, Anthropic, and Z.AI in the security release notes. The policy has trade-offs. Binario, a small security firm, had legitimate submissions blocked under the new cap, including a privilege escalation exploit chain with full Mac takeover potential, and Apple's now reviewing these findings, uh, after press scrutiny. GitHub introduced a similar tiered bug bounty system days before this report, suggesting the industry is converging on verification-based triage to distinguish credential Researchers from high-volume AI-assisted or low-quality submissions. I mean, the thing is, fight fire with fire. If, if your researchers are able to use AI to do this, why can't you have a red team internally do the exact same thing? You know, it seems like a really easy way to start solving this problem. And then the other side of it is, I do think you have to determine what the impact of the report is, right? Which I thought most of these bug bounty programs do. Like, if you give them a high severity one,, you know, maybe you make $5,000 versus if you, you know, submit to them something small, a small privilege escalation that's in some minor unknown library, then you'll probably only get a couple hundred bucks. You know, I think there's the tiering of that as well, but to just totally cap getting them at all just seems like a really silly way to try to control this problem. [18:43] Justin: Yeah. Well, and it's funny because it doesn't seem like they're capping because they're like, don't want to spend the money on, on bounties or paying out bounties. Like it's, it's literally they can't validate the validity of these things, which, you know, being on the other side of a bug bounty, a lot of them reported aren't, aren't true or real, right? Like it's, you have to do sort of a review of these things. [19:03] Matt: They don't understand the mitigating controls. They're just like, well, this, you know, you have this version of operating system. And so then therefore you don't have this patch. That means you have this vulnerability. We're reporting it. Okay. That's correct. I do not have that patched on this port, but that port is not open to the internet. So it does not matter. So I'm glad you figured out that I'm running Windows Server 2022 and this version of IIS, but doesn't matter because that port isn't open. [19:27] Justin: Right. It's not a legitimate thing that they were able to get to, but they still report it. And so like, that's, that's exactly the type of thing that you sort of have to review. And you know, like, I think, I imagine that this will get better because just like everything else, they'll add AI agent review to test the validity of these things and put sort of, you know, again, fight fire with fire. But, you know, it is sort of tricky and how to, how to maintain that. But you know who's not putting caps on these things? It's just people trying to exploit these things for, for negative gain. [19:55] Matt: So yeah, yeah, the, uh, threat actors are benefiting greatly from these models for sure. Speaking of which, Amazon Threat Intelligence has linked 4 separate npm package compromises— the Axios one, the debug, the chalk, and the typo crypto— to a single DPRK-linked threat actor tracked as Sapphire Sleet, or Stardust Kalima, or Blue Noroff, making the first public connection between these incidents. The Axios package alone has over 100 million weekly downloads, illustrating the scale of potential exposures. Attackers gained access primarily through social engineering of trusted package maintainers, then pushed malicious updates that were automatically pulled by downstream organizations. Wiz research found that roughly 1 in 10 cloud environments were affected by the debug and chalk compromise within a 2-hour window. Oof. Attacker tradecraft is evolving beyond single malicious packages towards fragment-level attacks where malicious behavior is split across multiple benign-looking packages and toward decoupled behavior where clean package fetch malicious logic from attacker-controlled server post-install, evading static code scans. Generative AI is reshaping the threat landscape on both sides, with attackers using AI to generate convincing documentation and code with no stable signature for pattern matching and beginning to embed prompt injection content in packages designed to trick AI-based code reviewers into approving malicious code. Uh, AWS response included sharing indicators through Amazon GuardDuty and reporting malware to the OSB database and refining Amazon Inspector detection logic. And AWS has also joined Linux Foundation's EKS Rights Initiative and contributed up to $12.5 million joint investment defending open source against AI-driven attacks. [21:23] Justin: Yeah. [21:23] Matt: Thanks, Amazon, for doing something good. [21:25] Justin: No kidding. And I mean, if you're not like a big, you know, mega company, like you, you're sort of beholden to these threat intel feeds. So it's great for, for Amazon. Because I can subscribe to that and it'll be in their tooling. I don't have to necessarily subscribe to it directly. And it's, you know, like, 'cause I don't know how, like, I don't know how, you know, we win in this sort of new world with all these attacks. And you think about like the sophistication where they're, you know, they're spreading out the malicious code across multiple packages. Like how in the world are you supposed to scan that or secure from it? So at least with a, you know, threat intel, you know that these versions are compromised and go look for those things and look for indicators. But yikes, man, like, it's a rough time to be in security and not like lose sleep. [22:15] Matt: I mean, it's a rough time to be in a lot of these industries right now. It's, you know, there's a lot of pressure from AI, and everyone wants AI, but then they don't want AI. And, you know, the legal teams are all freaking out about AI. Like, everyone, everyone's in panic. From all kinds of different aspects of it. And so it's just, uh, one of those things you got to continue to be careful about. [22:33] Justin: And it's just so fast, right? Like, you know, it's just quick. [22:38] Matt: Yeah. Well, moving on to cloud tools, GitHub has released stacked pull requests now in preview, letting developers break large changes into an ordered series of small focus PRs that each build on the layer below, addressing the common problem of oversized PRs that are difficult and slow to review. Each layer can be reviewed independently and in parallel by different teammates, with a stack map showing how individual PRs fit into the larger change, while existing branch protections and required checks still apply. Merging is flexible, with teams can land the entire stack in one operation or merge only lower layers while upper layers automatically rebase and retarget, reducing manual branch management overhead. The feature integrates with existing GitHub tooling, including the CLI, the mobile app, merge queue, and coding agents like GitHub Copilot through the dedicated skill. Early adopters include Vercel, TEDx, Whoop, jQuery's creator, a report that the feature helps manage PR volume increases from AI-assisted development and improves review speed and accuracy, with the merge queue support for stacks still rolling out progressively. [23:32] Justin: I'm a little unsure how this is used for AI-assisted development, right? Like, it's— I get it that you can, you take a branch, you separate it out to multiple PRs, you can fan out the, the review of that, but it's also like multiple agents coding against the thing, like merge collisions and all that stuff makes this very difficult to do in, in practice. [23:53] Matt: I think I, at least how I interpreted this, and, and I could be wrong. I'm flat out tell you, 'cause I haven't used it either. Right. So we're guessing. Yeah. But like when you get into work trees and you're dealing with lots of work trees, and if each agent is doing a work tree, bringing them all back to a single PR point is sort of complicated and it's a lot, it's, it's a bit messy. So if I can have each work tree submit its own PR, into basically a stacked set of PRs, then I can re— I can review and then I can assess from the worktree side without having to rebase all of the code for each worktree. I kind of see the value of it, but that's not really how they talk about it in the articles. That's where it's— that's how I like mentally model it. [24:32] Justin: That's the tool I want for sure, what you just mentioned. But then when I read through this, I'm like, why did they do it this way? Like now I'm, I'm having to pick and choose from the other direction. Like I don't want to do that. [24:41] Matt: And I also, I mean, keeping a large change moving by reviewing short, narrowly scoped pull requests, I feel like also where you invoke additional additional risk into the process because what if the change you're making over there is calling the API function over here and this API function is in a small part of it and you see that you change something here, then, oh, when I look at that, I see they actually increase the rate they're actually gonna call the API. And so this change actually is gonna bottleneck somewhere else. And so like, there's not quite sure what they're trying to do. I, I, I like that they're trying to do something. I just, it does feel like it's the opposite direction of what I want it. Yeah. [25:14] Justin: And I wonder if this is somehow like, uh, like why we don't understand it is cuz it's to combat sort of the increased load of AI code contribution in a way that I don't quite understand. Right. Cause I'm not, I don't know the GitHub stack. [25:27] Matt: I mean, I, I, I guess in some companies, do you do really large PRs for an entire release? And then you basically have one PR that you're working on together as a, you know, as a shared PR branch. And then basically each person's submitting their little parts of it, or at least a little AI agent is. And so this is how you avoid, you know, being able to review one huge massive PR at the end. But then, but then to me, that just feels like, like you're doing Git wrong. Right. [25:54] Justin: Yeah. Or continuous delivery wrong, right? Where, you know, like, which I think is common, right? Like, I think it is one of those things where it is a very common pattern because it is, you know, like you have to automate a whole lot of the stack to make continuous delivery work. And if you got legacy stuff, it doesn't play well. [26:10] Matt: Well, if someone has a really great use case for this and wants to send us a note, please do. Pod@thecloudpod.net or just hit our contact form and send us a note. Tell Ryan and I why we're idiots. We would appreciate it. So we do, you know, anything to make us smarter is always good for everybody. So just remember that. All right, let's move on to AWS. Swamy Siva Subramanian's org is being renamed to Agentic AI and Emerging Technologies. Which will expand his mandate beyond Juntic AI to include neuro-symbolic AI, however the hell that is, and AWS Context, a service that builds knowledge graphs from company data for AI agents to query. He continues leading QIRO, Amazon Quick, and AWS Transform, while his team, uh, has operated as a startup-style test case within Amazon, shipping products in months rather than typical year-long cycle. This move is separate from Amazon's AGI reorganization, which included layoffs, the closure of its San Francisco AGI site, and a reported wind-down of its most in-house Nova models. The expansion follows the May hire of former Microsoft exec Sean Beist to lead AWS's Automated Reasoning Group, which uses mathematical verification techniques to confirm AI agents behave as intended, signaling AWS's continued investment in agent reliability and governance. For AWS customers, this signals more concentrated leadership over emerging AI tooling and infrastructure decisions worth watching for how AWS context and neuro-symbolic AI initiatives eventually surface in the product lineup. [27:26] Justin: I'm still stuck on trying to figure out what a neurosymbolic AI is and like, is it different than general AI? Is it, or AGI, like, um, are they rebranding a thing to change the org chart? It's kind of a weird, weird sort of thing. And, but I guess it's, you know, quick research. It looks like it's an established thing where it's— [27:48] Matt: Yeah. So a Gemini, uh, summary on Google tells me that neurosymbolic, neurosymbolic AI is a field of artificial intelligence that combines deep neural networks, which excel at learning and pattern recognition from data. With symbolic AI, which uses logic, rules, and structured reasoning, this hybrid approach aims to make AI systems more accurate, transparent, and capable of logical problem solving. Apparently IBM invented the words. So basically, uh, neural networks is the perception of the data, symbolic logic is the cognition of the data, and together those two things, uh, produce a hybrid result that apparently has benefits such as there's no hallucinations, it's fully explainable, and it's efficient. So there you go. Yeah. Be big in finance and law and healthcare and robotics apparently is the big areas of focus for that, which makes sense based on, you know, Amazon's healthcare business is pretty strong. [28:37] Justin: So yeah, I guess, uh, it's a step to AGI, or at least considered some people, some people think it's unnecessary step, but which I think is kind of an interesting, I mean, AI that hallucinates is probably not great. [28:49] Matt: So if they can avoid, if this can solve hallucination, I think that's probably a good stepping stone. Just personally. [28:53] Justin: Counterpoint, I hallucinate all the time. [28:56] Matt: Well, if you are a fan of JWTs and you thought your days were numbered in AI, I can tell you that you can now authenticate with private key JWTs using Amazon Bedrock Agent Core Identities from Amazon. This lets agents authenticate to identity providers using a single signed JWT instead of a shared OAuth2 client secret, removing a common credential leakage risk. The private key never leaves AWS KMS. Agent Core Identity calls KMS Sign to generate the assertion, and the only public key is registered with identity provider supporting RS256, PS256, and ES256 algorithms. The feature works across all three major grant flows: machine-to-machine, on-behalf-of, and user-delegated access, covering most enterprise agent-to-API scenarios. Every signing operation and token request logged in AWS CloudTrail, giving teams an audit trail for compliance and security review without exposing token contents. And we've been doing it for decades. So yeah, this is a pretty stable, secure method that we've tested multiple times until an AI figured out how to break it. Uh, to get this set up, you do require creating an asymmetric KMS signing key, registering the public key with a provider like Okta or Microsoft Entra ID, and configuring credential provider through the agent core console. And they have a sample of an end-to-end implementation on the AWS GitHub samples repo. [30:07] Justin: Yeah. So while GCP is moving towards OAuth and client secrets, this is moving away. You know, I do think that this is, this pattern I think is is good because of the, the rate of which we're going to have to authenticate, especially at the agent layer where there's gonna be a lot of evaluation of what an agent can and can't do and the permissions and scoping across those credentials. I think the scale is gonna get quickly a little hard to keep unless you use this pattern, which has been built to scale and has been tested over years. [30:40] Matt: Yeah. And has been for decades, right? Yeah. And I, I think the thing that jumped out to me about this feature that I was like, oh, cuz the big problem when you're talking about a Gentec identity, and this is something we were working on in a prior life, you know, on behalf of versus user delegated is so complicated when you're trying to implement it at the SAML provider and inside of, inside of the single sign-on. And you know, if you think about JWT tokens have been used from machine to machine forever. So if you can solve this problem with the JWT token that can handle all three of those use cases, it's actually a much simpler implementation. [31:11] Justin: Very simple. Yeah. I was thinking the exact same thing. Like this is, which I mean, it just makes sense. And so I expect that this is going to catch on for sure. [31:20] Matt: And then maybe, maybe GCP version next will adopt this. So then I don't have to reauthenticate all the time. [31:26] Justin: And then it's not that. [31:27] Matt: Yeah. Yeah. [31:28] Justin: Here's hoping. [31:29] Matt: Here's hoping. Well, thanks Amazon. Uh, I will keep a close eye on this one because I am curious. And even though I thought we were done with JWTs, but apparently we're not. [31:36] Justin: No, they'll never die. [31:38] Matt: Never die. Alright, Balance Speed and Safety: A New Control Framework for AI Coding Agents. This is a blog post from the security blog, so it's dry as usual. Azure Security Blog outlines a two-pillar control framework for AI coding agents like Hero and Claude Code, addressing 7 key risks including prompt injection, data disclosure, and supply chain vulnerabilities relevant as agents now open dozens of PRs autonomously by MCP integrations. The framework splits controls into author time, IDE-based steering documents, specs, and build time pipeline scanning, quality gates, AI-assisted reviews using AWS services like Quero, CodeBuild, and CodePipeline as the reference implementations. Key technical distinction: deterministic controls like SAST, secret detection, policies code enforce hard rules consistency, while non-deterministic controls like LLM judge-review specification compliance checks catch context-dependent issues that pattern match, uh, that pattern matching misses. AWS recommends layering both since AI-generated code can pass all deterministic checks yet remain functionally wrong. Notable guidance on human review. AWS explicitly warns against routing every change to human reviewers, citing consent fatigue, where reviewers approve by reflex. Instead, they recommend scaling review depth to risk level and reserving human judgment for security-sensitive or high-blast-radius changes. Practical limitation tools mentioned, including the open-source Automated Security Helper and Project CodeGuard, both free and available now for teams to adopt without waiting on new AWS service releases. [33:01] Justin: Yeah, we, we sort of debated including this into the show because it's sort of a snooze fest, but I argued to, to keep it in and you know, it's, there's only two of us, so I won for once. But, uh, it, you know, the, the important parts of this are like the, I, the sort of anti-trend that I'm seeing in a lot of enterprises. I'm seeing, you know, stuff like trying to figure out, you know, having the human in the loop and, and really enforcing things that from an organizational layer where you can't use like the, the auto-approve rules and for agentic workflows. And I, I think it is causing fatigue. I know I'm fatigued by it. Um, and so I really do like the sort of the model they're splitting out here where it's having, you know, the, the human review the things it needs to, and you can have a human on the loop, meaning you should have access and full transparency across all the things. And, but I, and I think it's important to have sort of the, the ability to define, uh, allow lists in terms of You know, risk and, you know, defining sensitive actions that you never want. You always want to have a human approve. And I think that's important versus just knee-jerking to having everything be reviewed by a human. 'Cause it's, it's just not, I don't know, it's not working for me anyway. It's, it's a struggle. [34:15] Matt: Okay. I'm, I'm going to everything reviewed by my, my Ryan agent tech agent that I created of you. And he's a, he's a jerk. I can't get a jerk. [34:22] Justin: He's a jerk, right? And then it goes go and it goes back into developer lifecycle and the human doesn't have to, it until, until Ryan flexes, oh my God, this is so, so wrong. Pants-wettingly bad. Gah. You know? [34:32] Matt: Yep. And normally he, he, he's very contradictory though in his advice. Like he'll start one way and then he changes his mind halfway through. And then, and then Claude gets mad. He's like, I just faced it all this time. And I'm like, I know he's a dick. I, I don't know what to tell you. [34:46] Justin: It's, you really have captured me very well in my essence. I, I, I agree. [34:51] Matt: Yeah. Uh, all right, uh, AWS WAF is now normalizing raw query strings before parsing, closing HTTP parameter pollution and parser differential evasion gaps that attackers use to bypass detection rules. The 10 new text transformations add standard options like uppercase, trim, remove whitespace, and SHA-256, plus OS-aware command line and JavaScript decoding functions built by the Amazon Threat Research team. Rules can chain up to 10 pre-parsed transformations including URL decode and combining duplicate query arguments. Then layer standard post-process transformations within the same rule statement for more precise inspection logic. Each new transformation consumes 10 WCUs with no added fee beyond standard AWS WAF pricing, and the feature is available in all AWS regions at launch. It addresses a gap, uh, that I've seen, but also like, I will say WAF has just continued to get more and more complicated from Amazon, and, uh, I desperately would like you to add more AWS AI capabilities to this feature because it hurts my brain and it's very expensive if you fuck it up. Oh yeah. [35:51] Justin: No, I mean, I, and I think that that's, you know, I think it's really these cloud-native WAFs, actually all WAFs are becoming very super complicated and I don't think application owners can delegate sort of WAF to a security team or an ops team anymore. [36:04] Matt: Right. [36:05] Justin: You, I, you know, like used to sort of handle a lot of these use cases with input sanitation and, and you had that, the ability to test that through the SLDC and, and be able to surface issues that way. But the minute you roll these things out and abstract them into a WAF, which is, you know, even more complex than those things, you sort of lose that ability to find things. And I'm, you know, it's scary if you delegate this out to a security or a network team or whoever, because you roll out a change, it can completely break everything and be very difficult to troubleshoot. But it's also, you want to expose these things at the edge so you don't have to do them so much at the, application layer and you can sort of rely on that. And so it's this weird mix where I think that the application developers need to be very aware of what's going on at that network edge layer. So as we shift left, I think that that'll help out, you know, like it's kind of tricky to implement. [36:59] Matt: Yeah, I, uh, I messed it up, like I said, multiple times. [37:02] Justin: Yep. [37:03] Matt: But yeah, I mean, I definitely think, well, we were talking about last week, uh, Azure actually released a bunch of updates to their WAF to let it make it easier to have more knobs. And that's one of the things I feel the knobs on Amazon WAF are particularly, um, broad. It's, it's really bypass or don't, like block or bypass. Like those are your two choices. Or then you can, you can like force things to like do other verification that they're humans or in the bot control. Um, which is nice, but like, but really it's, it's so much more complicated than that. And, and, you know, they, when you're in monitor mode on Amazon WAF, like they should be able to feed that data into an AI. That helps you determine like, hey, you can turn these rules on safely. I see these things here. We might have to write custom rules for this because this is how your application works, or is this not supposed to be how your application works? And this is a problem. I do just think there's, there's WAF configuration on Cloudflare and on AWS has opportunity. Yeah. [37:56] Justin: And you know, like I agree with you because I think that in monitor mode, the dataset's too large for a human to go through and parse it intelligently. Right? Like it's, there's so much request randomly. [38:06] Matt: And you have so many edge cases, right? It's, you know, like, oh, well, yeah, the normal 12 flows, we've got those locked down pretty well. But then when this one user who comes in once a month to do this one function hits this one API, that's like 5 years too old. It does a POST and oh, POSTs are blocked. And you're now you're host and it's now it's an incident and now you're on a call and everyone's like, how did you not know this? I'm like, cuz the user only does it once a month and, or once a quarter, even worse. Or maybe, maybe only once in a blue moon, you know, super periodically. And so then, you know, you'll have this issue that comes out of implementation 3 months later and everyone's like, how did this get missed in testing? Because it's clearly not a common use case because we would have found it a lot sooner if it had been. [38:45] Justin: And not all testing goes out through the public gateway, you know, doorway to run tests, right? So it's like, yeah, hopefully you're rolling out your WAF changes through a staged sort of thing. [38:54] Matt: Heaven forbid your dev environment be open to the internet in a way that the WAF would use it. Yeah, yeah, those are issues. AWS Organizations customers can now check their maximum account quota and current usage directly in the service quotas console, eliminating the need to contact Ava support or account teams for the most basic of information. The feature supports proactive capacity planning, letting organizations monitor quota utilization and request increases before hitting limits that could block new account creation. Access is always available two ways through the service quotas console when logged into the management account or programmatically via the Get Services Quota API for automation and monitoring workflows. Uh, this is currently limited to the US East, uh, region, so multi-region organizations will need to check documentation for their specific setup until wider availability rolls out. But this is a small but practical operational improvement. Uh, I remember when organizations were held out and you didn't do anything. No, now it's just a pain in the butt, if that sounds like. [39:44] Justin: So yeah, well, I mean, quotas are a pain in the butt to begin with, but I guess, uh, with, you know, supply chain and, and and infrastructure shortages, they're sort of forced to roll out quotas like Amazon. I have, you know, I don't use Amazon day-to-day anymore, but it used to be great 'cause it was like you did have hard limits on certain things that you had, but it, there wasn't a bunch of service quotas and we're seeing a lot more service quotas being introduced in AWS. And I can only imagine that as you do that, if you have a bunch of Amazon accounts, like how do you manage that and how do you,, you know, provide the visibility and non-blocking sort of things. Like you have an auto-scaling workload that gets blocked because of scaling, that's a problem. Or quotas, that's a problem. [40:27] Matt: Yep. Well, and, uh, you know, these are problems that we had on Google and Azure and everywhere else. And so, uh, now Amazon joins the bunch. [40:33] Justin: Now Amazon. [40:34] Matt: Yeah. [40:34] Justin: Especially with the— [40:36] Matt: I, I started laughing thinking back to the earnings we talked about earlier and like they're spending $45 billion in CapEx. I'm like, would you please just get some basic capacity? Like, I know you're spending it all on GPUs, but could you just gimme some basic capacity? Complexity too. [40:48] Justin: Yeah, yeah, maybe some uniformity in which machines are available in which regions. Like, is that so hard? Like, come on, doesn't have to be all of them, just some uniform, just some basics I can, I can rely on. Yeah. [41:00] Matt: Well, then AWS is launching one last feature this week for Lambda on Bedrock: a web search, a native server-side tool that grounds foundational model responses in current web knowledge, eliminating the need to integrate and maintain third-party search providers. The feature combines a continually refreshed web index of billions of documents with a built-in knowledge graph to improve factual accuracy on things like dates, authorship, and events, while using semantic snippet extraction to keep token usage efficient. Enablement is a single parameter added to an existing OpenAI-compatible API call through Bedrock's Responses API, with authentication handled via existing AWS IAM credentials rather than separate API keys. Compliance-focused design includes zero data egress by default, in-region processing, and CloudFront integration that logs calls' identity and access decisions without recording query text, URLs, or page content, which should appeal to regulated industries needing audit trails. Availability is currently limited to the US with in-region query handling in us-east-1, us-east-2, and us-west-2, and only indexed web retrieval supported at launch with live web fetch planned for a future update. So I'm very happy this exists because one of the problems you have with Bedrock agents is that they don't know anything about the web. They don't know what the date it is. And so you have to provide it a bunch of updated information and context if you need it to be anything current. And so the fact that it has some ability to do this, uh, maybe not completely what you need, But at least it's heading in the right direction. I'm very happy about this. [42:16] Justin: That's interesting, actually. I didn't, you know, like, because I read through this and I got lost quick because it's saying the first two features make sense to me, but it also feels like you're maintaining your own web index, which is a lot. [42:28] Matt: I don't think you're maintaining your own. I think Amazon's maintaining a web index that this taps into. [42:33] Justin: Oh, okay. [42:34] Matt: As like a grounding model. [42:35] Justin: Yeah. [42:36] Matt: So Amazon's now coming to try to compete with Google. [42:39] Justin: Right. [42:40] Matt: Yeah. So that's, that's really more of the concern. [42:42] Justin: That's more of the concern. Yeah. But then the, all the compliance controls and the, you know, the availability of just the US made me really sort of like, what? Like, what am I, what am I focused on? Like, if it's Amazon's managed index, then why am I so worried about data loss prevention and in-region processing? Like, hmm, I don't get it. I don't know. There's something I don't understand here about this release. [43:04] Matt: Yep. It's a mystery. [43:07] Justin: Mm-hmm. [43:07] Matt: Uh, but no, I mean, if you are using Bedrock agents, uh, not being able to access the web is a bit of a problem. [43:13] Justin: Like everything, everything I do needs access to the web. [43:15] Matt: Well, and you run into it like on the dumbest things. Like, you, you know, someone asks like, hey, I ordered something yesterday and I need to know when it's gonna ship. [43:21] Justin: Mm-hmm. [43:21] Matt: Uh, and it's like, well, yesterday was, uh, you know, June 12th. And you're like, no, no, yesterday was August 3rd. [43:27] Justin: Yes. [43:27] Matt: And you had to correct it and all that. And so it's annoying. [43:29] Justin: Yeah. [43:30] Matt: So now that you have that ability, at for some things, uh, I appreciate that. [43:34] Justin: Yeah. [43:35] Matt: All right, moving on to GCP, and first up, there's a thought piece from Google Cloud's Office of the CISO. They're pushing AI threat defense as a board-level governance topic, framing security as a business enabler rather than a cost center, arguing that AI adoption requires automated machine-speed defense rather than manual processes. I mean, leave it to security to come up with whatever process, uh, thing you could build that will basically make everyone panic to buy more software. Just saying, just saying. Uh-huh, uh-huh. The piece outlines 5 governance for questions for boards to ask leadership covering business enablement, remediation cycle or MTTR, tool consolidation, contextual prioritization of vulnerabilities, and AI safety policies for shadow AI and internal pipelines. Codebender's Google AI Code Security Agent is now in preview through Agent Platform and AI Threat Defense. We talked about it 2 episodes ago. And Cloud KMS is expanding its post-quantum cryptography digital signature support to include MLDSA and SLH-DSA algorithms. Relevant for organizations planning long-term data integrity strategies against future quantum threats. AlloyDB added IAM group authentication in preview, giving enterprises identity-driven access control for database workloads and AI agents. So thanks Google for scaring the board and then giving us some new tools. Appreciate it. [44:49] Justin: Well, it's funny, it's phrased from the words like questions to ask the board because I think this is like questions the board is asking, right? You know, that's how it's always having to answer these questions. [45:00] Matt: If you're a CISO, look forward to your board asking you these questions. That's how it should be worded. [45:04] Justin: Right. Because it's, and it's, you know, like you have to have answers for these, these questions, because they're important for business. And I know in my day job, I've had to absolutely gather data and answer questions like this so I can pass on. And so like, you have to have these kinds of things, but I, you know, it is sort of an interesting framing of, you know, security as a business enabler, which has been my argument forever. So I, I like this, you know, I don't like being labeled as sort of a cost center. That's just a drag on the business. Like, I, I do really feel it's not revenue generating, sure, but it's revenue saving, and it can definitely help a business. So these things are, you know, questions customers ask, uh, ask. And, you know, the more answers you have on how you're securing your environment, especially with AI workloads, good. [45:49] Matt: Well, I look forward to, uh, a future board meeting. All right, Google is announcing the borderless Lakehouse enhancements at Next Tokyo, using catalog federation via Iceberg REST to connect BigQuery with AWS Glue, Databricks Unity, and Snowflake Horizon in preview, allowing queries to queries across clouds without data movement or ETL pipelines. I mean, it's funny to me they mention everyone but Azure in that. Cross-Cloud Interconnect now offers zero variable egress cost when pulling data from AWS with partner Cross-Cloud Interconnect pricing, providing flat subscription-based rates from 1 gig to 100 gigs instead of unpredictable per-gigabyte egress fees. Although you will still pay for hourly interconnection service fees, and they're not cheap. Uh, the Knowledge Catalog acts as the governance context layer, automatically syncing metadata from AWS Glue, Databricks Unity Catalog, and Snowflake Horizon to translate schemas into business terms and lineage, aiming to reduce AI agent hallucinations and enforce access controls at the table level. Zero-copy integrations extend to SaaS platforms like SAP, Salesforce, and Workday, letting BigQuery query live application data directly, letting those platforms run BigQuery AI functions in place, which Google says has driven up 230x, uh, reduction in token consumption for some of their customers. Spanner Omni and Lakehouse Federation for DynamoDB extend this model to transactional databases, letting operational systems query lakehouse data directly. Oh, the Data Agent Kit plus Conversational Analytics API let developers build custom agents in Gemini Enterprise using natural language over its federated data estate. [47:14] Justin: Yeah, I mean, this is one of those enterprise enablers that Google Cloud is doing to sort you know, lure workloads out of other clouds, I think. 'Cause if you can, if you can query data across clouds like this, then you're going to run all that compute for the query in BigQuery. And so it's interesting. I wonder if the egress costs across that, like, does Amazon charge you but Google doesn't? I don't know, but probably not. Maybe. Uh, it's sort of an interesting thing, you know, but I like the idea of being able to query data where it lives and, and having an easy option for that. Especially, you know, as a security professional, like I don't do data warehousing for application data, but I do it for security logs. And so having a big old data lake for security logging that you can pipe through a SIEM and so on is great. [47:57] Matt: So, well, I mean, I think this is one of the ways you're going to have to be green if you want to be sustainable. You can't just copy this data between clouds willy-nilly, like, great, you know, that's not a very sustainable method to copy it to 3 different data lakes. So your 3 different applications on 3 different clouds can do this. So it's nice to be able to say, look, we're going to use Google's Lakehouse as our data lake and we're going to connect it to our other, you know, data puddles, if you will, and basically make it one unified interface that everyone understands. And then you can put Looker on top of it or heaven forbid, something better than Looker, which is anything. And so, you know, and so, you know, you get that benefit with being able to take advantage of BigQuery and some of the other are really great technologies that Google has. This is one of the areas Google is really strong at. [48:42] Justin: It is. [48:43] Matt: You know, it, you know, much better than I think Amazon's tools in the space. Sorry, Amazon. [48:48] Justin: No, I agree. I mean, I just, I do happen to like the Google tooling better. I wish there was a little bit more tie-in between some of the security tooling because they're kind of an ant— they're going away from this where they're not going towards— [48:59] Matt: because security people don't like to share. I know. You know it. I do. [49:05] Justin: I do. I know. Like it's, it's, and it's, you know, like I do like, you know, like the, the use of like, you know, generalized formatting. You know, I, I think Iceberg storing your data in a format that can be used in crossplaces is great. And yes, I know you can't do as much data enrichment and indexing as, as that for investigations, but gotta make a compromise. [49:26] Matt: Exactly. And that leaves us with our final story. Google announced two new AI agents under the Agentic Data Cloud umbrella at Cloud Next '26, the database onboarding agent for initial setup and configuration, and the database observability agent for ongoing monitoring and troubleshooting, both powered by Gemini. The observability agent correlates telemetry from Database Insights, Cloud Monitoring, Cloud Logging, and Cloud Trace to reduce root cause analysis in minutes and can suggest or execute remediation actions like enabling connection pooling pending user approval. Don't just let it do it. Coverage spans Cloud SQL, Spanner, AlloyDB, Bigtable, Firestore, and Memorystore. With access available through Gemini Chat, Cloud Assist, and the Cloud Console, IDEs and GCP servers letting teams query fleet-wide metrics like top CPU consumers across the database. Onboarding agent lets users describe application requirements in natural language and receive database service recommendations along with provisioning commands and introduce manual documentation review during day zero planning. Some capabilities include in-product investigations and validated remediations are still in preview with select customers, so full availability and pricing details are not yet quite out, but, uh, It's good to see this is continuing to evolve since we talked about it from Next. [50:29] Justin: Yeah, and I'm sort of curious, I did a little like research on like, cuz I'm like, where they're announcing these agents, but where are these agents? Where do they live? And it's, I, I guess it's just kind of behind the scenes when you interact with the, the Google Cloud Assist, like either in the console or the Cloud Workspace that I'm blanking on the name of those, and you just said it. And so that's sort of interesting that it's, you know, from a user perspective, it's just sort of underlying in these tools. And so you can ask questions and you get better answers, which I thought was kind of interesting. [50:58] Matt: Yeah, agreed. Moving on to Azure, Route Maps for Azure Route Server has now entered public preview, giving admins granular control over BGP route advertisements between on-premise networks, NVAs, ExpressRoute gateways, and VPN gateways within a virtual network. The 4 capabilities include route summarization for simplifying on-premise to Azure connections, Route control for filtering traffic direction, path selection via AS path manipulation, and route tagging using BGP community attributes. Target enterprises with complex hybrid networking setups involving multiple connection types, ExpressRoute, VPN, and VAs that need to manage routing policy without manual intervention at each peering point. This addresses a long-standing gap in Azure Route Server, which previously offered limited routing policy controls compared to on-premise BGP implementations. I mean, like, seems like you should have had this day one. It just You know, my networking is a little dated these days, but I know back then you need that stuff much, much faster. [51:51] Justin: Yeah. I mean, I, I, God, it's been so long since I've had to do any of this, which is great. Thank my stars I've made at least some wise choices. But yeah, no, I can, I can see how this is a real pain point. I'm, I guess, you know, I can understand them not having this as a release before, because this is sort of bridging together a lot of different networking types. I don't know. [52:15] Matt: Yeah. Good to see. I mean, it's, it's so data center in the cloud though, for me, I'm just like, who wants to, who wants to manage BGP? [52:23] Justin: Nobody. [52:25] Matt: Nobody. I remember it was fun back in the day. Like, this is awesome. We can just route traffic between these two providers and like magic happens. And yeah, it was cool. And now, now in 2026, I'm just like, I don't want to do that at all. [52:36] Justin: Just work. Yeah, exactly. [52:40] Matt: And finally, Azure is making Trusted Launch the default, automatically enabling Secure Boot and vTPM on new Gen2 VMs and virtual machine scale sets at no additional cost, establishing a stronger baseline security posture out of the box. Deployments via Azure Portal, CLI, and PowerShell get Trusted Launch automatically, while ARM templates get Bicep, Terraform, and SDK users need a one-time subscription registration to get the same default behavior. Existing VMs are unaffected by this change, and any previously configured security setting will continue to be honored, so there's no risk of unexpected behavior changes for current workloads. Availability spans both the x64 and ARM64 Gen2 VM sizes across Azure Public, Azure Government, and Azure China regions, giving you broad coverage for customers with compliance or sovereignty requirements. I mean, the fact that this isn't required in 2026 was kind of blowing my mind too, because how long ago was that rootkit from Sony? [53:29] Justin: Yeah, you know, right? That's what I was thinking too, that this was— I was surprised that this wasn't already default, not being an Azure user. But it's— and you know, I guess maybe people still sort of attribute Secure Boot with the UEFI, like, terrible UEFI, terrible thing you did to Windows computers. [53:45] Matt: Yeah, that thing, I'm familiar. [53:47] Justin: And it's, you know, because that's— that is, you know, awful when trying to use that, because then you can't even update stuff without breaking your computer. But yeah, no, these are not that hard to implement and generally painless and transparent. So yeah. [54:01] Matt: Yep. [54:02] Justin: Agreed. [54:03] Matt: Oracle's here this week and it's been a while since we talked about Oracle, but they're here because they're expanding their partnership with Google Cloud to embed Gemini models directly into Fusion apps, NetSuite, and the new AI Agent Studio following on from existing Gemini access via OCI Enterprise AI. This is Oracle continuing its multi-model, multi-vendor AI strategy rather than betting on a a single provider. That's nice. Can't wait to get Gemini terribleness in my Fusion apps and NetSuite. [54:30] Justin: Uh, it was already terrible. [54:32] Matt: Yeah, it was. I don't know what it is now. I'm sure it's not great. I haven't tried. [54:36] Justin: So yeah, is it, is it Oracle Cloud specific models or is it, uh, you know, have they already— [54:40] Matt: I don't think they have any. I don't, I don't think Oracle has any foundation models they built. I think everything is licensed. Uh, I think they have OpenAI models. Uh, and I think they have a bunch of like Deepseek and those, um, I know they have partnerships with all those, so I imagine it's a mix. Yeah, I think they, they've gone kind of the way that I think Amazon is now going, which is that why are we trying to make foundational models that just be the best place to run models? [55:03] Justin: And Apple too, right? I can't— [55:04] Matt: yeah, I think that's, uh, many companies may be winners because of that strategy. Yeah. And, uh, Oracle might in this case. So, yeah. All right, moving on to emerging clouds, let's talk about the Cloudflare Cloud. Uh, first of all, your agent needs a container. Nope, doesn't need a container, needs a computer. Uh, they released an open-source preview of @cloudflare/computer, an agent runtime that abstracts away whether code runs in an isolated— in isolate a container sandbox or a browser, letting agents choose the right execution environment automatically. The core problem being addressed is scale. Giving every agent its own dedicated container is not sustainable given projected demand for hundreds of millions or billions of concurrent agents. So CloudFront is pushing isolates as its more efficient default compute primitive. The architecture separates a durable SQLite-backed virtual file system from the execution runtime, allowing agents to run lightweight operations in isolates via just Bash and dynamic workers, while falling back to full Linux containers, uh, only when native barriers or heavier tooling are required. CloudFront reports that this is in testing. With Frontier models, we're able to correctly choose between the isolate and container backends based on task requirements, the stated goal of limiting container use to under 10% of total agent workloads. This approach builds on CloudFront's existing bets on workers and durable objects. I mean, isn't this what Firecracker is? Did CloudFront just invent Firecracker? [56:20] Justin: Yeah, well, I mean, it's kind of interesting because it's, you know, like, uh, one of the AWS announcements that we're not talking about was very called out in the blog of it running on the, the little micro VMs, right? And so like, it's, it's kind of interesting there where it's like these are kind of two different ways, right? Agent Core and AWS Bedrock using dedicated Firecracker VMs per session is a default. And so it's kind of funny. Yeah, I guess that's where they're going. Yeah. [56:49] Matt: What I mean, again, I, the more we've learned about agentic runtimes and agents, the more Firecracker makes a lot of sense. And I mean, it made a lot of sense for Lambda as well, but you know, it wasn't really like, how am I gonna use Firecracker in the real world? If I don't need to use Lambda? And, and the answer is like, well, you could run Knative or some other very lightweight Kubernetes platform on top of that, but then you're just running containers, you know, on top of Firecracker, which I don't know if that's even easy to do. I've never tried it. [57:15] Justin: Yeah. [57:15] Matt: Because I'm not crazy. Uh, but you know, we're talking about agentic runtimes and they need isolated sandboxes and they have very specific rules. The overhead of a container is almost like saying, oh, the overhead of a VM, it's too much. [57:27] Justin: Too much. [57:28] Matt: Yeah. And so, uh, Firecracker type style stuff makes sense. And so isolate They make a lot of sense. So I'm curious to see how that evolves and we'll keep an eye on that one. [57:35] Justin: Yeah, definitely. [57:37] Matt: They're also interested in Cloudflare Agents, which, oddly enough, run on top of these. [57:41] Justin: Weird. [57:41] Matt: I know, so weird. These are a first-class workload on its developer platform, leveraging existing building blocks like durable objects, workflows, R2, and AI Gateway, rather than introducing entirely new infrastructures. Agent tracing addresses a specific Azure gap. An agent can return HTTP 200 while still failing due to wrong tool selections. Stale context, or retry loops that traditional infrastructure telemetry wouldn't surface. And the new agent dashboard provides two debugging views: session replay for reviewing full conversation context across turns, and trace waterfalls for inspecting execution timing across model calls, tool executions, and sub-agent delegations, all correlated with workers and infrastructure like D1 and KV. Uh, support launches with OpenTelemetry-compatible harnesses, with plans to accept standard OpenTelemetry generative AI semantic convention spans directly, reducing dependency on Cloudflare-specific adapters, and allowing export to OTLP-compatible destinations. Pricing is tied to existing worker observability spans with tracing free during beta and billing starting October 1st, 2026. [58:35] Justin: So OpenTelemetry is taking over the agentic workflow. I see, you know, Anthropic's leading the way there and starting to be adopted by others, which is interesting. Yep. I mean, it's, I get it. It makes a lot of sense. It's just, it's big. [58:51] Matt: It is big. [58:51] Justin: When you start putting agentic sort of execution data in telemetry feeds, it turns into be a very big feat in my experience. [59:01] Matt: And if you've, uh, been annoyed at Cloudflare and thinking, oh man, I can't imagine running agents there because their billing is terrible, they're launching a billable usage API for self-serve accounts, giving you programmatic access to cost and usage data across workers, R2, D1 workers, AI, vectorized images, and stream in a single API call rather than relying on dashboard exports or screenshots, which is always the worst. Uh, the API format aligns with the FinOps Focus specification using familiar column names like service name, contracted cost, and charge period start. Through Cloudflare notes, does not yet have full Focus conformance, so they're working towards it. It's a step in the right direction. Data updates daily rather than in real time currently, though Cloudflare has stated finer-grained time windows and forecast capabilities are on the roadmap. And Cloudflare partnered with Vantage to help enable native integration, allowing Cloudflare spend to appear alongside other cloud providers in cost reports, budgets, and anomaly alerts, supporting cross-provider cost allocation via read-only billing read API tokens. So good job, Cloudflare. Thank you for improving your FinOps story, because it was bad. [59:58] Justin: I mean, I've never used some of the more complex features of Cloudflare, so I haven't really had to deep dive into, you know, bills in any way that's difficult to compute, or I'd, or, you know, where I'd want to see it alongside my other cloud sort of costs, but does seem a nice addition to those who have that use case. [60:18] Matt: And, uh, Ryan, that brings us to the end of another episode of The Cloud Pod. We made it. We made it. We talked earnings, we talked security. It was good. [60:26] Justin: I mean, it was good. [60:27] Matt: We covered a lot of ground this week. And so, uh, it's still, it's August finally, uh, August 4th and technically, and, uh, you know, we're in the, the hot days of summer. So I'm hoping maybe the news gets a little lighter in the next couple weeks, but something, something will happen and I'm sure it'll be all over the place. [60:42] Justin: So yeah. [60:43] Matt: But all right, man, we'll see you next week here in the cloud. [60:46] Justin: Sounds good. Bye, everybody. Another week of cloud news wrapped up. Vault will collect the news. Justin will get the notes. Jonathan will write some code. Ryan will watch the perimeter. And Matt will reluctantly watch Azure. Till next week for AI, Amazon, Google Cloud, and Azure. [61:07] Matt: And hey. [61:08] Justin: Maybe even Oracle, who knows? Check out thecloudpod.net for our newsletter. Join our Slack, message us on socials, or leave a review.