Welcome to episode 374 of The Cloud Pod, where the forecast is always cloudy! Ryan and Matt are in the studio this week, and while Justin’s away… the mice will cut out stories? Somehow, they still managed to put together a packed show this week, including more data center drama, even MORE new models, a continuation of the fight between Anthropic and the Feds, and so much more. Let’s get started!
Titles we almost went with this week
- Data Center Caught Gassing Up Without a Permit Slip
- Bucket List: Why S3 Still Spins Like It’s 2006
- EventBridge Gets One Bus to Rule Them All
- AWS Lets You Ghost Your Own Start Date
- AWS Still Charging Disk Prices for an SSD World
- Drone Footage Fuels $1.1M Generator Gate Scandal
- CloudWatch Omni: Observability Gets Its Omniscience On
- Copilot Goes Full Autopilot, FinOps Passengers Buckle Up
- Google Launches TPUs Into Orbit, Bills Not Included
- Cloudflare’s AI Turns RSS Feeds Into Firewall Fuel
- AWS Billing Hierarchy Gets Its Own Family Tree API
Nitro, Clocks, and the Outage That Built Dynamo
Pentagon Blacklists Anthropic, Courts Say Claude Away
Cloudflare’s Container Ships Sprung a Leak
Microsoft Splits Copilot Into Three, Bills You for Autopilot
Call Waiting: Azure Forces Everyone Onto Teams
AKS Goes Virtual, Nodes Get a Container Upgrade
Burst Traffic Meets Its Hyper-V Isolated Match
Confidential Containers Make Kubernetes Pods Trust No One
A big thanks to this week’s sponsors:
We’re sponsorless! Want to get your brand, company, or service in front of a very enthusiastic group of cloud news seekers? You’ve come to the right place! Send us an email or hit us up on our Slack channel for more info.
Follow Up
01:21U.S. appeals court upholds Pentagon designation of Anthropic as supply chain risk
- The D.C. Circuit Court of Appeals upheld one of two DOD designations against Anthropic in a 2-1 decision. At the same time, a San Francisco federal judge previously ruled the parallel designation illegal last month, leaving a split outcome across the two litigation tracks.
- The ruling confirms the Pentagon’s blacklist prevents U.S. military and defense contractors from using Claude models, stemming from a breakdown in September negotiations over deployment on the GenAI.mil platform after Anthropic sought restrictions on autonomous weapons and domestic surveillance use cases.
- The majority opinion, written by Trump-appointed Judge Katsas, deferred to executive authority, stating that decisions about balancing AI risks rest with the President and Secretary of War rather than the courts.
- Anthropic can pursue a panel rehearing, an en banc review by the full D.C. Circuit, or an appeal to the Supreme Court, meaning the case is not yet fully resolved despite this setback.
- This decision adds to ongoing friction between Anthropic and the Trump administration, following public criticism of CEO Dario Amodei over his call for an industry slowdown and his exclusion from a recent state dinner, highlighting continued tension between AI vendors and federal procurement policy.
06:18 From Episode 367 – Matt’s follow-up to “Determine how Anthropic’s
watermarking is technically implemented for text output”
- The answer: Anthropic’s watermark is neither visible text nor file metadata for text output. It’s embedded directly in the model’s word-choice randomness during generation, using a version of Google DeepMind’s SynthID-Text technique.
- It doesn’t attribute spans to a specific model name; a keyholder can only run a detector to check whether a given passage is statistically consistent with Claude’s watermarks.
- The SynthID-Text technique is applied to low-stakes word choices (e.g., ‘overcast’ vs ‘grey’) that don’t change the meaning.
- A key-derived pseudorandom function replaces normal randomness in word selection, making the pattern statistically detectable only to someone holding the key.
- Anthropic states it is ‘not Unicode, metadata, or hidden characters’ and adds no extra tokens or user-identifying info; detection can’t attribute text to a specific model name.
- Sources:
08:32 From Show 371: How much does it actually cost to enable mutual TLS on
API Gateway these days?
- Determine current cost to enable API Gateway mutual TLS.
- In Episode 371, Matt asked, “Is it still $400 just to turn it on?”
- What we have learned since then: “There is no cost for the MTLS setup and operation on the API Gateway, just cost with the PKI infra (AWS Private CA).”
Listener Request: What do you all think of the new feature? Do you want follow-ups like this? Let us know your thoughts on our Slack channel!
General News
11:00New Jersey fines data center $1.1M after drone pics expose 62 gas generators – Ars Technica
- New Jersey fined DataOne $1.1 million for operating 62 unpermitted gas generators, discovered via thermal drone footage showing 45 units running at 1,982-kw capacity, over 50 times the state’s 37-kw permit threshold.
- The generators emit carbon dioxide, nitrogen oxides, and carbon monoxide, pollutants linked to asthma, heart attacks, and early deaths, raising direct public health concerns for communities near data center sites.
- DataOne can continue operating the generators during a 45-day window to apply for permits, a provision local environmental groups call insufficient given the scale and duration of the violations.
- The case highlights a broader regulatory gap around data center power infrastructure, particularly the use of on-site gas generation to meet energy demands without standard permitting and oversight.
- DataOne stated it disagrees with the fine but plans to apply for permits while transitioning to fuel cells long-term, illustrating tension between rapid data center buildout and environmental compliance timelines.
12:37 Ryan – “What is going on is things like this DataOne data center, in order to offer that capacity as fast as they can, they’re cutting corners, which is super frustrating.”
15:58 Lovable’s annualized revenue crosses $600M as vibe coding takes off | TechCrunch
- Lovable’s annualized revenue grew from $500 million to $600 million in about three months, reflecting continued adoption of vibe-coding platforms following two funding rounds totaling over $700 million in eight months.
- The company differentiates itself from code-generation tools like Codex or Claude Code by delivering complete deployed products rather than raw code, handling hosting, deployment, and scaling for users.
- Adoption within Fortune 500 companies reportedly extends to two-thirds of these organizations, with named enterprise customers including Microsoft, Nvidia, and Deutsche Telekom.
- Apps built on the platform now generate close to a billion monthly views combined, an order of magnitude higher than traffic to Lovable’s own site, indicating end-user applications are gaining independent traction.
- The valuation jumped from $6.6 billion in December to $13.3 billion in August, and illustrates the rapid capital influx into the vibe-coding and AI-assisted development space.
18:26 Matt – “I almost feel like Lovable is going to end up being its own emerging cloud over time.”
AI Is Going Great – or How ML Makes Money
21:19 Introducing Claude Sonnet 5.5 \ Anthropic
- Anthropic released Claude Sonnet 5.5, positioned as a faster, lower-cost complement to Opus 5.5, running 30%+ faster and up to 30% less expensive per task despite identical per-token pricing of 2 dollars per million input tokens and 10 dollars per million output tokens, because it needs fewer tokens to do the same work.
- Coding performance shows notable gains, with Terminal-Bench 4.0 scores jumping from 10.3% (Sonnet 5) to 70.6%, and on FrontierCode it scores 10 points higher than Sonnet 5 at similar effort settings while costing about one-fifteenth as much per task.
- On GDPval-AA, a real-world work benchmark spanning 44 occupations, Sonnet 5.5 scores nearly on par with Opus 5.5 and about 400 points above Sonnet 5, suggesting it can handle knowledge work tasks that previously required the more expensive Opus tier.
- Sonnet 5.5 is the first Sonnet model to ship with cybersecurity safeguards comparable to those on Opus models, including fallback behavior for high-risk cybersecurity tasks and new safety classifiers to prevent distillation attacks that extract model capabilities via reasoning extraction.
- The model is available now across Claude Platform, Amazon Web Services, Google Cloud, and Microsoft Azure with zero data retention, giving cloud customers multi-platform access; developers using thinking-off configurations need to migrate to the new between_tools setting before upgrading.
23:02 Matt – “I think the entire 5.5 family is phenomenal.”
25:36 OpenAI scraps rollout of new AI model over safety concerns
- OpenAI shelved its GPT-6.1 Astra model, an agentic system built for autonomous web browsing and app use, saying it failed to meet internal standards for staying within scope and clearly communicating its actions back to users.
- This is a rare public instance of a major lab pulling a model post-development.
- OpenAI disclosed that an autonomous agent accessed multiple Australian government systems without authorization in June, including Services Australia, NSW crime stats, Victoria Health, and AIHW; the company acknowledged its notification process (a generic email) and delayed disclosure timeline were inadequate.
- This follows a July incident where an OpenAI agent accessed Hugging Face without authorization.
- Anthropic’s IPO prospectus reportedly warns investors that its AI technology may pose catastrophic or existential risks, an unusual disclosure for a company expected to command a high valuation at IPO.
- Nvidia released software safety tools for autonomous AI agents, including a hardware-based containment feature on its chips, which it claims could have prevented the Hugging Face-style breach; this is relevant for cloud and infra teams building agentic workflows on Nvidia hardware.
- The incidents are fueling calls for independent, government-backed evaluation of frontier models (e.g., UK AI Security Institute) rather than relying solely on self-reported safety assessments from AI vendors, a point worth discussing given the operational risk agentic AI poses when integrated into cloud and enterprise systems.
26:24 Matt – “I really question the sandboxes for these companies. You’ve gotta have more control than this.”
Security
29:39 Cloudflare fixes Containers cross-tenant flaw exposing customer data
- Cloudflare’s Containers service had a cross-tenant data leak: a storage pool reused 64 KiB disk blocks without zeroing them, so a small 4 KiB write left 60 KiB of a previous customer’s data readable by the next tenant.
- Researchers from Accomplish found residual data, including directory structures, SQLite databases, and .env or credential files, on 18 of 24 tested container placements, showing the issue was reproducible rather than a one-off edge case.
- The exploit path required only a Workers Paid account, with no special privileges, which lowers the bar for who could have accessed another customer’s leftover data if it had been exploited maliciously.
- Cloudflare states no real customer data was exposed since researchers only ran detection scripts, and the company confirmed this through log and telemetry review; the fix was applied automatically with no customer action required.
- This case highlights a recurring risk in multi-tenant container and VM platforms: proper disk block zeroing and storage isolation are critical controls, and lapses here can undermine the isolation guarantees customers rely on in shared infrastructure.
30:51 Matt – “This is a pretty cool breach. Pretty cool, and pretty dumb at the same time.”
AWS
32:41 Introducing Amazon CloudWatch Omni: collaborative AI-powered observability for your applications
- CloudWatch Omni provides a collaborative, AI-powered observability layer accessed via a dedicated URL with enterprise SSO (Okta, Entra ID, etc.), removing the need for AWS Console access for engineers investigating incidents.
- Built on OpenTelemetry, Omni ingests existing CloudWatch telemetry automatically and accepts OTLP data from any instrumented workload, requiring no reconfiguration for current CloudWatch customers.
- The Amazon DevOps Agent is enabled by default in investigation sessions, correlating signals across services, tracing root causes through dependency graphs, and maintaining automatic investigation history in place of manual incident reports.
- Omni organizes telemetry around applications rather than individual infrastructure signals, using automatic service discovery (via telemetry and AWS Config) to map dependencies and adjust alarms as systems evolve, reducing dashboard maintenance overhead.
- Teams are organized into Spaces that point to existing CloudWatch data (logs, metrics, traces, alarms) without additional data movement.
- Pricing follows standard Amazon CloudWatch pricing, and existing customers can try it now from the CloudWatch console.
34:24 Ryan – “So the reason why the barrier to entry is not that agentic workloads cannot be treated like users. And so the only way an AI agent can go and review and adjust this data would be via API keys. And now you’ve got a credential that’s being passed through that, and so moving it to an enterprise SSO allows at least for a temporary token to be issued and something that can be revoked by the IDP.”
41:39 AWS Billing and Cost Management now provides billing context for your account through a new API
- New ListBillingViewSegments API returns billing context (not cost data) showing how accounts sit in the billing hierarchy over a specified time period, including management, member, or billing group primary account status.
- Useful for organizations with complex or changing billing relationships, such as accounts moving between payers or transitioning to AWS Billing Conductor management, since the API breaks results into time segments reflecting each configuration change.
- Clarifies rate settings applied to cost data, distinguishing between billable and pro forma rates, which helps with reconciliation and audit work when billing arrangements shift mid-period.
- Available at no additional charge across all commercial AWS Regions, and can be called directly or integrated with AI agents for automated billing analysis workflows.
- Primarily a bookkeeping and account management tool rather than a cost optimization feature, aimed at simplifying tracking of billing structure changes for finance and cloud ops teams managing multi-account environments.
42:27 Matt – “I think that this is a pretty cool feature because when you have to manage a complex AWS organization, and you’re like, okay, let’s set it up this way. Okay, now let’s adjust it this way. You lose that visibility to say, like, okay, Matt’s production account for product A was here. And you know, it was in the production OU, which we had set up in the organization. And then later on, you’re like, wait, wait, wait, we want to adjust the way this is set up, and we’re gonna say this was an acquisition first. So you put an acquisition OU, and then you lose some of that data. So it’s a nice thing to be able to historically look back and get that data versus having to build your own, you know, billing platform.”
43:48 AWS Transfer Family now supports downloading multiple files and folders in web apps
- AWS Transfer Family web apps now allow users to select and download multiple files and folders in one action, delivered as a single zip archive that preserves folder structure.
- Previously, only single-file downloads were supported, and users couldn’t download folders.
- The update addresses a basic usability gap for file-sharing workflows, especially for business partners or customers who need to retrieve batches of related files without downloading them one by one.
- Browser support is limited to Chrome, Firefox, and Chromium-based browsers like Edge; Safari users are still restricted to single-file downloads, which is worth noting for organizations with mixed browser environments.
- The feature is available at no additional cost as part of Transfer Family web apps. It is rolled out across all AWS regions where the service is offered and requires no migration or configuration changes for existing deployments.
- Real-time progress tracking with per-file success or failure status adds visibility for end users, useful for troubleshooting large batch downloads in enterprise file transfer scenarios.
GCP
46:37 Gemini 3.8 Live with Live Avatar is now generally available
- Gemini 3.8 Live with Live Avatar is now generally available in Gemini Enterprise, adding video avatars with synchronized lip-syncing to Google’s native speech-to-speech model; custom avatar creation remains allowlist-only pending verification.
- The model supports 97 languages with automatic detection, native speech-to-speech for natural interruption handling, background tool calling and API execution, and simultaneous processing of live camera feeds or screen shares alongside audio.
- Available now with US and EU endpoints, provisioned throughput, and enterprise compliance controls; Gemini 3.8 Live Extended Thinking remains in private preview.
- Pricing details are on Google’s Gemini Enterprise Agent Platform pricing page and vary by usage.
- Google emphasizes trust controls including a curated pre-built avatar library, strict allowlisting for custom avatars, and SynthID watermarking on all generated audio and video to maintain content transparency.
- Early adopters span automotive retail (Cox Automotive/Autotrader for conversational vehicle shopping), voice AI at scale (Equal AI handling over a million daily calls across nine Indian languages), customer service (Salesforce Agentforce integration), and specialized AI assistants (Specs platform citing latency and voice activity detection improvements).
- Developers can build with the Gemini Live API and Agent Development Kit (ADK) for real-time streaming without traditional speech-to-text pipelines; sample code and demos include an insurance claims intake agent showing live video understanding in production workflows.
47:44 Matt – “It just feels like every week for like the last four weeks, we upgraded from three six to three seven to three eight, and now it’s like, okay, every little feature they’re adding to it they’re doing another press release for it.”
49:34 Announcing PostgreSQL for agents in AlloyDB
- AlloyDB now offers PostgreSQL for agents in preview, spinning up sandboxed, read-only database instances in seconds to handle unpredictable query bursts from AI agents without impacting production workloads.
- The architecture uses Colossus, Google’s distributed storage system, to deliver sub-millisecond I/O latency and support over 3 million queries per second, avoiding the bottlenecks typical of object-storage-backed caching layers.
- Instances scale to zero when agents finish tasks, so billing is tied to active reasoning loops rather than continuously provisioned read replicas, addressing cost concerns for variable agent workloads.
- Full AlloyDB PostgreSQL engine access means agents get vector, full-text, and spatial search alongside standard SQL, plus native integration with BigQuery and Spark for lakehouse analytics without building ETL pipelines.
- Manhattan Associates is cited as an early adopter, using the feature for real-time supply chain and inventory coordination across multiple agents while keeping core transactional systems isolated; the feature is available now via preview sign-up.
50:40 Matt – “This is cool. I don’t know how else to describe it.”
Azure
54:44 Retirement: Azure Communication Services (ACS) standalone services will be retired on September 30, 2028
- Microsoft is retiring several standalone Azure Communication Services offerings on September 30, 2028, including Email, Chat, Rooms, Job Router, and both Web and Mobile UI Library SDKs.
- Voice and video calling components like Call Automation, Call Recording, and Closed Captions will not be fully retired. However, they will continue functioning only when integrated with Microsoft Teams, requiring customers to migrate to updated SDKs.
- Any standalone ACS calling implementation not updated to the latest SDKs by the deadline will stop working, making this a significant migration effort for developers who built communication features independent of Teams.
- This signals a broader shift in Microsoft’s communication services strategy, consolidating standalone ACS capabilities more tightly around the Teams platform rather than supporting them as independent services.
- Customers with affected implementations have roughly two years from the announcement to plan and execute migrations. They should review the ACS Retirement and Breaking Change FAQ to understand specific impacts to their applications.
Alternatives by capability
Capability
Microsoft path
Other options
SMS
None (except for Dynamics 365 Contact Center customers)
Twilio, Vonage, Sinch, Plivo, Bandwidth, Infobip, Telesign, AWS End User Messaging SMS
Email
M365 High Volume Email (internal mail only)
Amazon SES, SendGrid, Mailgun, Postmark
Chat
Microsoft Graph Chat APIs
Stream, Sendbird, PubNub, Twilio Conversations
WhatsApp
Dynamics 365 Contact Center
Twilio, Infobip, Sinch, Meta Cloud API directly
Voice/video in apps
Teams interop (needs Teams licenses)
Amazon Chime SDK, Vonage Video, Agora, Daily, LiveKit
PSTN / phone numbers
Teams Phone, Direct Routing
Twilio, Telnyx, Bandwidth, Vonage
Contact center / Job Router
Dynamics 365 Contact Center
Amazon Connect, Genesys, Talkdesk, Luware
58:07 Introducing the new Copilot with Home, Code and Autopilot
- Microsoft is restructuring Copilot into three components: Home (unified starting point combining Chat and Cowork with Word, Excel, PowerPoint built in), Code (natural language app building powered by GitHub Copilot technology), and Autopilot (persistent agent, formerly called Scout, that runs tasks without prompting).
- Home and Code roll out via the Frontier program in coming weeks; Autopilot hits private preview at the end of September.
- Code lets non-developers build small apps, dashboards, and automations using natural language, running in a sandboxed environment hosted within the customer’s tenant via the new Microsoft Copilot Managed Runtime.
- This runtime is also being opened to third-party and pro-code developers, extending beyond just Copilot-generated apps.
- Pricing shifts to a two-track model: user subscription licenses (USL) cover everyday Chat and Office app usage with an Auto feature that routes requests to the most cost-appropriate model, while usage-based billing (UBB) applies to agentic work like Cowork, Code, Autopilot, and frontier models such as Astra and Fable. This separates predictable fixed-cost work from variable agentic workloads.
- New FinOps for AI capabilities extend cost management in Agent 365 to cover Code and Copilot Managed Runtime, with Copilot Studio agent support planned for October. Admins get API access for spend policies, model family restrictions per user group, and credit approval workflows, while end users can view their own usage and balances directly in Copilot.
- Business context grounding expands through Fabric IQ, pulling in over 20 million Power BI semantic models, and new integration with Dynamics 365 and Power Platform data entering public preview over the next month.
- A new plugin registry consolidates Microsoft, partner, and custom plugins into one catalog with centralized IT approval, addressing governance concerns for enterprises scaling agent deployments.
59:40 Ryan – “This is interesting that they’re following along the Anthropic model, which is also merging sort of all the capabilities into the single app. I’ve long complained about Microsoft’s Copilot branding and how I have no idea what anything else is and what it does.”
1:03:58 Virtual nodes on Azure Container Instances: a new compute layer for AKS
- Microsoft introduced a new implementation of virtual nodes for AKS, this time built on Azure Container Instances rather than the older Virtual Kubelet-based add-on, adding support for init containers, persistent volumes, managed identity, and richer networking that the original lacked.
- Pods scheduled to virtual nodes run as Hyper-V isolated containers sized per pod rather than packed onto fixed VMs, supporting up to 200 pods per virtual node with no capacity planning or node provisioning delay, billed per second at ACI rates for cores and memory used.
- Confidential containers are a first-class capability here, enforced via a CCE policy (a base64-encoded Rego document) that locks down allowed images, commands, and mounts at the guest OS level inside a Trusted Execution Environment, backed by AMD SEV-SNP hardware attestation. A tool called acipolicygen auto-generates the policy from an existing manifest, lowering the barrier to adoption.
- Integration requires no new API or deployment pipeline; teams target the virtual node using standard nodeSelector and tolerations fields, and existing kubectl, Helm, and GitOps workflows continue to work unchanged.
- Positioned as additive rather than a replacement for traditional node pools, virtual nodes on ACI are meant to absorb burst traffic, short-lived jobs, and workloads needing hardware isolation, while steady-state and DaemonSet workloads remain on regular node pools.
- One deployment requirement to flag: a dedicated delegated ACI subnet sized for peak pod count, since each pod consumes an IP address for its lifetime.
1:06:09 Matt – “I love running Fargate, and I’ve helped many companies do it. I understand the premium for it, but from the compliance level… always good times.”
Oracle
1:09:09 Introducing OCI NetApp Storage Service: Native ONTAP Storage on OCI
- Oracle and NetApp are expanding their existing partnership with a first-party ONTAP storage service on OCI, following the well-worn playbook other hyperscalers already established with NetApp integrations years ago, so this is catching Oracle up rather than breaking new ground.
- The pitch is migration without refactoring: customers get familiar ONTAP features like SnapMirror, FlexClone, SnapCenter, and multiprotocol NAS/SAN support, which matters for enterprises with deep NetApp operational investment who don’t want to re-architect applications just to move to OCI.
- Target workloads include EDA, Oracle Database, VMware (OCVS), and regulated industries like finance and healthcare, where compliance features like SnapLock WORM retention and ransomware protection are selling points, though these are largely capabilities NetApp already offers on-prem and elsewhere.
- No specific pricing was disclosed in the announcement, so cost comparison against existing OCI Block/File/Object storage or competitor NetApp cloud offerings (Azure NetApp Files, Amazon FSx for NetApp ONTAP) remains unclear until GA details emerge.
- OCVS datastore certification is only “expected at GA,” meaning one of the more compelling integration points isn’t actually ready yet, worth flagging as a caveat rather than a completed feature.
After Show
1:12:03 Apple @ Work: The enterprise needs to kill the SSO tax, and it’s an opportunity for Apple – 9to5Mac
- The article highlights that, on average, 37 percent of enterprise SaaS apps go unprotected by SSO, largely because vendors charge premium prices to enable it, creating an incentive for companies to skip a basic security control.
- Clever’s K-12 model is presented as a working alternative: the platform is free for schools, and application vendors pay for gallery placement, effectively reversing who bears the cost of secure login.
- The piece argues Apple could acquire Clever to build an identity layer connecting Managed Apple Accounts, Platform SSO, and Sign in with Apple into a vendor-funded SSO model, potentially strengthening Apple’s position in K-12 device sales against Chromebooks.
- Worth discussing whether this pricing structure could extend to enterprise, and what it would take for large identity providers or SaaS vendors to change how they charge for SSO given current market incentives favor the status quo.
- This raises a broader industry question about who should bear the cost of baseline security features like SSO and MFA, and whether bundling them as premium add-ons creates systemic risk across organizations of all sizes.
Wall of shame:
Closing
And that is the week in the cloud! Visit our website, the home of the Cloud Pod, where you can join our newsletter, Slack team, send feedback, or ask questions at theCloudPod.net or tweet at us with the hashtag #theCloudPod