Shared posts

22 Oct 21:15

Una cordobesa a la que le detectaron bultos en el pecho lleva casi dos años sin ser citada pese a que le recomendaron revisiones semestrales

by luspagnolu

La afectada se ha unido a la plataforma de afectadas creada por FACUA por la negligencia del Servicio Andaluz de Salud en la gestión de las mamografías para denunciar que, 22 meses después, sigue sin recibir ninguna comunicación.

etiquetas: cordobesa, bultos, pechos, dos, años, sin, citas, revisiones, semestrales

» noticia original (facua.org)

22 Oct 21:14

Todas las cartas o paquetes que se envían entre pueblos de Menorca deben salir primero a Valencia

by iveldie

Todas las cartas o paquetes que se envían entre pueblos de Menorca deben salir primero a Valencia, para luego volver a la Isla y ser repartidos por el cartero, es surrealista.

etiquetas: menorca, correos, valencia, cartas, surrealismo

» noticia original (www.menorca.info)

22 Oct 21:14

Telegram intensifica su colaboración con las autoridades en España, facilitando IP y teléfono de 3.482 usuarios de la app

by Alaplancha

Telegram publicó por primera vez en octubre de 2024 información sobre el número de solicitudes que recibe de las fuerzas de seguridad, con las que los diversos países donde opera buscan identificar a usuarios de la plataforma. Unos meses antes, su fundador, Pável Dúrov, había sido detenido por las autoridades francesas. Tras su liberación, la app añadió a sus condiciones de uso una cláusula que advertía que podía facilitar información como la IP o el número de teléfono de los usuarios involucrados en "actividades delictivas".

etiquetas: telegram, españa

» noticia original (bandaancha.eu)

22 Oct 21:14

Julian Casanova, historiador: "A partir del 39 no hay muertos de posguerra asesinados por republicanos"

by autonomator

Entrevista La Noche en 24 H al historiador Julián Casanovas, que asegura que el golpe de Estado de julio de 1936 "inaugura un periodo sin ley donde las armas sustituyen a la política y la vida no importa nada" en la que ambos bandos se aprovecharon de la situación de descontrol, aunque con diferencias en ambas partes. Ahora bien, "a partir del 39 no hay muertos de posguerra asesinados por los republicanos"."Se podría decir que hay 100.000 asesinados, fusilados, durante la Guerra Civil y 45.000, que podrían llegar a 50.000, en la posguerra"

etiquetas: franquismo, represión, asesinatos, fosas, especial rtve, españa, posguerra

» noticia original (www.rtve.es)

22 Oct 21:14

El consejero andaluz de Salud compara la desaparición de mamografías con la caída de la venta de entradas de La Oreja de Van Gogh

by jodere
“Lamento evidentemente esa incidencia de caída, pero el día anterior lo tuvo Amazon”, ha reconocido
22 Oct 21:13

Cazan a un diputado de la extrema izquierda francesa quitándose un reloj de lujo antes de cargar contra los ricos

by Hastaloseggs

La izquierda caviar cabalgando contradicciones.

etiquetas: francia, política, hipocresía, video viral

» noticia original (www.vozpopuli.com)

22 Oct 21:13

Más problemas para el campo: las naranjas de Sudáfrica entran en la Unión Europea con cero aranceles y arrinconan a los agricultores

by macarty

Sudáfrica está ganando terreno en los lineales europeos y erosionando la rentabilidad de los citricultores españoles. Lo que hace apenas una década se percibía como una oportunidad comercial, hoy se ha convertido en una seria amenaza para el campo español. El desembarco masivo de naranjas sudafricanas coincide con el inicio de la campaña nacional, empujando los precios hacia abajo y dejando a muchos agricultores en una situación límite.

etiquetas: dumping, ue, agricultura

» noticia original (gaceta.es)

22 Oct 21:13

Etiopía: Crímenes de lesa humanidad en Tigré Occidental

by GrofTheGuard

Las fuerzas de seguridad de Amhara y las autoridades civiles de Tigré Occidental han cometido abusos generalizados contra los derechos humanos de la población tigriana desde noviembre de 2020 que constituyen crímenes de guerra y crímenes contra la humanidad; así lo afirman Amnistía Internacional y Human Rights Watch en un nuevo informe que han publicado hoy.

etiquetas: etiopía, tigré occidental, limpieza étnica

» noticia original (www.amnesty.org)

22 Oct 21:12

Loca pelea de STAR WARS en un centro comercial. [ENG]

by VolandoVoyVolandoVengo

Esto es lo que pasa cuando decides recrear tu escena favorita de Star Wars..

etiquetas: star wars, pelea de sables, centro comercial

» noticia original (www.youtube.com)

22 Oct 21:11

El Supremo obliga a la Comunidad de Madrid a hacer públicas las cuentas del chiringuito de Ayuso desde el que se pagaba a Montoro

by LágrimasdeFacha

El alto tribunal ha ratificado que la Comunidad de Madrid debe entregar las memorias anuales de la entidad creada bajo el Gobierno de Esperanza Aguirre

etiquetas: transparencia, madrid network, isabel díaz ayuso, fondos públicos

» noticia original (www.elplural.com)

22 Oct 20:59

El Verdadero Motivo de que Continúe la GUERRA en UCRANIA

by El Canal del Coronel

Hablamos con Juan Antonio Aguilar sobre el escándalo de Boris Johnson, a quien le pagaron un millón de libras para impedir la paz en Ucrania.
22 Oct 20:57

Algo MUY RARO está pasando con Corea del Norte

by Lord Draugr

Este vídeo ha sido patrocinado por la suite de Proton, una de las empresas más respetadas del mundo de la ciberseguridad. Consigue todos los servicios de Proton: su VPN, gestor de contraseñas, almacenamiento en la nube, calendario... Todo cifrado y respetando tu privacidad:
https://proton.me/ceodeproton


Edición: Martivideo
Guion: Diego Alonso Sousa, Íñigo Astiazarán y Lord Draugr
Narración: Lord Draugr

----------------------Aprende a hacer vídeos como yo----------------------
https://blog.foroclickbait.com/
22 Oct 20:57

📈 Las 5 inversiones que todo el mundo debería conocer en 2025.

by Javi Linares

#inversion #javilinares #invertir #finanzaspersonales #finanzas #economia

══════════════

*MIS PLATAFORMAS PARA INVERTIR*

✅ Mi plataforma favorita para invertir en fondos indexados:
Enlace a MyInvestor: https://bit.ly/MyInvestorIndexados

✅ Mi Plataforma favorita para invertir en ETFs con cuenta remunerada para saldo en efectivo:
Enlace a Trade Republic: https://trade.re/linares-interes

✅ Plataforma que uso para invertir en BTC y Cryptos:
Enlace a Kraken: https://bit.ly/krakenYT

══════════════

¿QUIERES APRENDER A INVERTIR y MEJORAR TUS FINANZAS PERSONALES?

📚 Conoce el Método LINVEST, mi programa con soporte 1 a 1 para crear tu cartera de inversión y plan financiero personalizado: https://javilinares.com/metodo-linvest/?utm_source=youtube&utm_medium=organic&utm_campaign=video-short

══════════════

¿QUIERES COMPRARTE UN PISO, CASA O INMUEBLE?

🏠 Broker Hipotecario AQUEOS: Te ayudamos a encontrar la mejor hipoteca para tu propiedad: https://javilinares.com/broker-hipotecario/?utm_source=youtube&utm_medium=organic&utm_campaign=video-short

══════════════

*SECCIONES DEL CANAL*

https://www.youtube.com/playlist?list=PLa--ADK-E7IuKhNjd4uwu3EUMmxOSFQfQ

https://www.youtube.com/playlist?list=PLa--ADK-E7Iu-r16mxAkXNoeoLwd16rmh

https://www.youtube.com/playlist?list=PLa--ADK-E7IutcqRJCjql5IRYMjuc5T5v

https://www.youtube.com/playlist?list=PLa--ADK-E7IsV4CoFE4bezEwgxyOC18-5

https://www.youtube.com/playlist?list=PLa--ADK-E7It2VIDNSKDjM512ypXx1_vf

══════════════

*SÍGUEME EN REDES SOCIALES*

👉🏻 Notificamos de nuevos vídeos en mi Canal en Telegram: https://t.me/LasInversionesDeJavi

👉🏻 Mi Instagram: https://www.instagram.com/soyjavilinares/

👉🏻 Mi Twitter: https://twitter.com/soyJaviLinares

══════════════

Javier Linares Fernández

- Asesor financiero certificado EIP (nº 37391)

══════════════

DISCLAIMER: el contenido de este Canal de YouTube tiene fines únicamente educativos y en ningún caso suponen recomendaciones de inversión o asesoramiento financiero. Por favor consulta con detalle los documentos oficiales de los fondos de inversión y ETFs antes de realizar cualquier inversión y asegúrate que dichos productos cumplen con tus objetivos de inversión.

Recuerda que la inversión siempre debe ser entendida a largo plazo e invertir un dinero que puedas permitirte perder. Antes de invertir es imprescindible entender los datos de los fondos y sobre todo tener un fondo de emergencia de al menos 3 meses de tus costes de vida.

Invierte solo en bancos y brokers regulados y huye de rentabilidades astronómicas, dinero rápido o demás eslóganes de inversión

Javi Linares mantiene relaciones comerciales con MyInvestor y Trade Republic y la referencia a sus productos y servicios se considera publicidad conforme a la normativa vigente.

══════════════
22 Oct 20:56

CEO Vanguard explica cómo invertir con éxito a largo plazo

by Javi Linares

Empieza ahora a proteger y a multiplicar tu dinero con Método Linvest. Agenda tu llamada gratuita con alguien de mi equipo y juntos analizaremos tu situación y veremos si podemos ayudarte a acelerar tu camino hacia la tranquilidad financiera: https://calendly.com/d/cnhy-sns-jwc/sesion-de-acceso-al-metodo-linvest/?utm_source=youtube&utm_medium=organic&utm_campaign=podcast-ceo-vanguard

══════════════

En este nuevo episodio de LINVEST TALKS me acompañan Pablo Bernal y Antón Díez para analizar cómo nació el primer fondo indexado de John Bogle y por qué revolucionó la inversión. Hablamos del impacto de los costes, los riesgos de concentración en los índices y las previsiones a largo plazo de Vanguard.

══════════════

¿QUIERES APRENDER A INVERTIR y MEJORAR TUS FINANZAS PERSONALES?
📚 Conoce Método LINVEST, mi programa con soporte 1 a 1 para crear tu cartera de inversión y plan financiero personalizado: https://javilinares.com/metodo-linvest/?utm_source=youtube&utm_medium=seo&utm_campaign=podcast-ceo-vanguard

══════════════

*SECCIONES DEL CANAL*

https://www.youtube.com/playlist?list=PLa--ADK-E7IuKhNjd4uwu3EUMmxOSFQfQ

https://www.youtube.com/playlist?list=PLa--ADK-E7Iu-r16mxAkXNoeoLwd16rmh

https://www.youtube.com/playlist?list=PLa--ADK-E7IutcqRJCjql5IRYMjuc5T5v

https://www.youtube.com/playlist?list=PLa--ADK-E7IsV4CoFE4bezEwgxyOC18-5

https://www.youtube.com/playlist?list=PLa--ADK-E7It2VIDNSKDjM512ypXx1_vf

══════════════

*SÍGUEME EN REDES SOCIALES*

👉🏻 Notificamos de nuevos vídeos en mi Canal en Telegram: https://t.me/LasInversionesDeJavi

👉🏻 Mi Instagram: https://www.instagram.com/soyjavilinares/

👉🏻 Mi Twitter: https://twitter.com/soyJaviLinares

══════════════

ÍNDICE

00:00:00 A continuación…
00:02:00 Presentación de Pablo Bernal y Antón Díez
00:02:46 Los primeros 50 años de Vanguard
00:06:50 Qué es "Boglehead"
00:19:18 Método Linvest
00:20:29 Tips clave para invertir
00:23:40 Diversificación e índices representativos
00:37:27 Renta fija vs renta variable
00:41:50 Gestores de Vanguard
00:46:39 Servicios Vanguard
01:01:22 Gestión patrimonial según tu perfil
01:08:24 Predicción Vanguard
01:13:25 Evolución de los expertos

══════════════

Javier Linares Fernández

- Asesor financiero certificado EIP (nº 37391)

══════════════

DISCLAIMER: el contenido de este Canal de YouTube tiene fines únicamente educativos y en ningún caso suponen recomendaciones de inversión o asesoramiento financiero. Por favor consulta con detalle los documentos oficiales de los fondos de inversión y ETFs antes de realizar cualquier inversión y asegúrate que dichos productos cumplen con tus objetivos de inversión.

Recuerda que la inversión siempre debe ser entendida a largo plazo e invertir un dinero que puedas permitirte perder. Antes de invertir es imprescindible entender los datos de los fondos y sobre todo tener un fondo de emergencia de al menos 3 meses de tus costes de vida.

Invierte solo en bancos y brokers regulados y huye de rentabilidades astronómicas, dinero rápido o demás eslóganes de inversión

Javi Linares mantiene relaciones comerciales con MyInvestor y Trade Republic y la referencia a sus productos y servicios se considera publicidad conforme a la normativa vigente.

══════════════
22 Oct 20:54

Lo que debes saber y nadie te cuenta sobre lo que de verdad sucede en el mundo

by El Canal del Coronel

Programa especial con Ariel Umpiérrez analizando todas las últimas noticias internacionales más inquietantes del momento.
Un programa imprescindible para entender lo que de verdad está sucediendo en el mundo.
22 Oct 20:54

🟢 El hombre de los hombros de pájaro o el cuidado que te debes a ti mismo

by Fabián C. Barrio

Este vídeo podría regalarte algunos años más de vida.
22 Oct 20:54

BASF Digital Farming builds a STAC-based solution on Amazon EKS

by Kevin S. Ridolfi

This post was co-written with Frederic Haase and Julian Blau with BASF Digital Farming GmbH.

At xarvio – BASF Digital Farming, our mission is to empower farmers around the world with cutting-edge digital agronomic decision-making tools. Central to this mission is our crop optimization platform, xarvio FIELD MANAGER, which delivers actionable insights through a range of geospatial assets, including satellite imagery, drone data, and application maps from sprayers.

In this post, we show you how we built a scalable geospatial data solution on AWS to efficiently catalog, manage, and visualize both raster and vector datasets through the web. We walk you through our solution based on the SpatioTemporal Asset Catalog (STAC) specification and the open source eoAPI ecosystem, detailing the solution architecture, key technologies, and lessons learned during deployment. This builds upon a previous post on efficient satellite imagery ingestion using AWS Serverless, extending our discussion to the full lifecycle of geospatial data management at scale.

Requirements for our geospatial data solution

BASF Digital Farming’s xarvio FIELD MANAGER platform operates at exceptional scale in the geospatial data ecosystem, processing hundreds of millions of satellite images that translate into STAC items, which further decompose into billions of individual geospatial artifacts. Unlike traditional satellite data providers such as European Space Agency (ESA) who work with predictable, structured data flows, we operate in an inherently dynamic agricultural environment where we ingest near-daily satellite imagery per field from a diverse array of sensors and providers globally. Our mission to support farmers worldwide with advanced digital agronomic decision advice demands a reliable, cloud-based infrastructure capable of handling this massive data velocity and volume and applying advanced quality assurance processes including cloud detection and anomaly detection algorithms. The platform’s true value emerges through our machine learning (ML) pipelines that transform raw satellite data into actionable insights. For example, estimating accurate absolute biomass such as Leaf Area Index (LAI) helps farmers make precise, data-driven agronomic decisions that optimize crop yield and resource utilization across fields worldwide.

STAC and eoAPI ecosystem

To efficiently manage our growing archive of geospatial data, we adopted the Spatio Temporal Asset Catalog (STAC) specification, an open standard that provides a common language to describe and catalog raster and vector datasets. With STAC, we can standardize metadata across diverse sources like satellite imagery, UAV datasets, and prescription maps, making it straightforward to search, filter, and retrieve assets across our platform. We built our platform using the eoAPI ecosystem, an integrated suite of open source tools designed to handle the full lifecycle of geospatial data on the cloud. At its core is pgSTAC, which provides a performant PostGIS-backed STAC API implementation. With pgSTAC, we can index millions of STACi Items efficiently, with support for spatial, temporal, and attribute-based filtering at scale. On top of that, we use Tiles in PostGIS (TiPG) to serve tiled vector data directly from our PostGIS database. This enables real-time visualization of field boundaries, management zones, and application histories as lightweight Mapbox Vector Tiles (MVT), without requiring an external tile server. For raster assets, including satellite and drone imagery, we rely on TiTiler, a modern dynamic tile server built for Cloud Optimized GeoTIFFs (COGs). With TiTiler, we can stream imagery on-demand as WMTS or XYZ tiles, perform dynamic rendering (such as NDVI or false color composites), and integrate seamlessly into web maps and mobile apps.

Solution overview

The following architecture diagram shows how we implemented our geospatial data platform on AWS. In this section, we explain each component of the architecture and how they work together to process millions of satellite images and geospatial assets daily. The solution uses Amazon Elastic Kubernetes Service (Amazon EKS) as the core computing platform, with Amazon Simple Storage Service (Amazon S3) for storage and Amazon Relational Database Service (Amazon RDS) for metadata management. We break down the architecture into four main layers: core services, storage, database, and ingestion.

A detailed AWS Cloud architecture visualization showcasing a complete geospatial data processing system across four distinct layers. The database layer features an EKS Cluster managing STAC, raster, and vector services, all connected to Amazon RDS through a proxy instance. The client layer supports both desktop and mobile access via Amazon API Gateway. The ingestion layer processes geospatial data streams through a STAC ingestor, feeding into a robust storage layer utilizing Cloud Optimized GeoTIFF and FlatGeobuf technologies. The architecture emphasizes scalability and efficient spatial data handling through PostgreSQL with pgstac extension, enabling seamless integration of various geospatial services and data formats.

Core services layer

The solution uses an EKS cluster hosting three key services:

  • stac-service – Implements the STAC API specification to catalog and serve metadata for both raster and vector datasets
  • raster-service – Powered by TiTiler, this service dynamically renders and tiles cloud-optimized raster data (for example, COGs) for seamless integration into web and mobile maps
  • vector-service – Built with TiPG, this component serves vector data (for example, boundaries or application zones) as tiled MVT layers directly from the database or from Amazon S3

These services are containerized and orchestrated within Kubernetes, allowing for high availability, modular separation, and simplified continuous integration and delivery (CI/CD) workflows.

KEDA-based automatic scaling

We use Kubernetes Event-Driven Autoscaling (KEDA) to scale our platform services dynamically based on real-time workloads. With KEDA, we can scale individual pods based on precise event-driven metrics such as the STAC ingestion queue depth or visualization request load. This supports responsive performance during peak activity while maintaining lean resource usage during idle periods, aligning perfectly with our need for elasticity in a data-intensive, variable-load environment.

Geospatial asset storage layer

The platform stores all raw and processed geospatial assets in S3 buckets, optimized for performance and durability. This layer holds COGs for raster imagery and FlatGeobuf or similar formats for vector data. These formats are chosen for their support of streaming access, indexing, and cloud-based performance.

Database layer

The metadata backbone of the system is a PostgreSQL database hosted on Amazon RDS, extended with the pgSTAC plugin. This setup enables efficient indexing and querying of millions of STAC items and collections. An RDS proxy sits in front of the database, providing connection pooling and resiliency, especially under bursty or concurrent access patterns common in geospatial applications.

Ingestion layer

An independent ingestion component handles batch or streaming geospatial data inputs. This component processes satellite imagery, drone data, or prescription maps and pushes relevant metadata into the STAC API and storage assets into Amazon S3. The ingestion engine is decoupled from serving infrastructure, enabling asynchronous and large-scale data loading.

Amazon API Gateway and clients

Public access to the platform is handled through Amazon API Gateway, allowing clients—whether browser-based or mobile—to interact securely with the services. The API gateway provides a unified entrypoint and is used for applying rate limiting, authorization, and routing policies.

Solution benefits

The solution offers the following benefits:

  • Rapid onboarding with STAC standardization – By aligning with the STAC specification, we’ve significantly reduced the time to onboard new data domains like sprayer application maps. Compared to previous approaches in our legacy system, metadata modeling and integration are now both standardized and automated, so we can expose new geospatial data products to clients in days instead of weeks or months.
  • Optimized storage with COGs and Amazon S3 – Storing raster and vector assets in Amazon S3 using cloud-optimized formats (such as COGs for imagery or FlatGeobuff for vectors) reduces storage costs while enabling low-latency, streaming access. This avoids the need for preprocessing or extract, transform, and load (ETL)-heavy pipelines and simplifies client delivery.
  • Large-scale ingestion with a batch STAC ingestor – Our custom STAC ingestor supports both real-time and batch-mode operations. This has made it possible to onboard satellite constellations, drone imagery, and historical datasets in bulk without disrupting running services. The ingestion service uses optimized database ingestion functions, capable of ingesting thousands of items per second, providing high-throughput and reliable data integration at scale.
  • PostgreSQL, pgSTAC, and Amazon RDS Proxy for a scalable metadata backbone – With pgSTAC and Amazon RDS Proxy, we benefit from advanced spatial-temporal querying while making sure database connection management is handled gracefully, even under high concurrency. This combination offers reliability without compromising performance.
  • Scalable deployment with Amazon EKS – Hosting the solution on Amazon EKS provides full control over deployments, resource tuning, and service orchestration. Combined with automatic scaling, we dynamically adjust compute capacity based on demand, facilitating resilience and cost-efficiency.

Learnings

As part of building this solution, we learned the following:

  • RDS Proxy is essential for automatically scaled environments – Given our use of automatic scaling pods in Amazon EKS, we found that RDS Proxy is critical. It handles connection pooling efficiently and protects the underlying PostgreSQL database from connection exhaustion during sudden scale-up events. Without it, we encountered spiky load failures and blocked connections during high-ingest periods.
  • Batch STAC ingestor is a core component – Our custom STAC ingestor proved to be an indispensable piece of the system. It interfaces directly with pgSTAC to perform large-scale, automated ingestions of geospatial metadata from streams and archives. Without this tool, onboarding data providers or processing legacy imagery at scale would have been labor-intensive and error-prone.
  • COGs are non-negotiable – For fast, scalable visualization of large raster datasets, COGs are essential, particularly if raster datasets exceed several gigabytes. They enable efficient HTTP range requests, alleviate the need for preprocessing, and work seamlessly with TiTiler for real-time tile rendering. Non-COG formats led to noticeably slower performance and weren’t suitable for cloud-based visualization.
  • Serverless-compliant, optimized for Amazon EKS (for now) – Although the architecture is designed to be serverless-compatible, we opted for an Amazon EKS first approach due to the nature of our other application landscape. Components like TiTiler and TiPG benefit from persistent, memory-tuned environments that are harder to achieve in a serverless runtime. However, the solution remains modular and stateless by design, and certain subsystems (such as ingestion triggers, notifications, or monitoring) are already candidates for future serverless migration to further improve elasticity and reduce operational overhead.

Conclusion

BASF Digital Farming GmbH has successfully implemented a STAC-based geospatial data platform on Amazon EKS, enabling efficient management and visualization of satellite imagery, drone data, and application maps. This architecture helps us onboard new data sources within weeks rather than months. The new platform also processes twice as much data in a single day while cutting costs by 50%, thanks to reduced data handling through the STAC schema and the efficiencies of automatic scaling. By adopting the STAC standard, the architecture improves data discoverability, reduces search latency, and supports more efficient analytic workflows.

Organizations looking to build similar geospatial data solutions can use AWS services like Amazon EKS, Amazon S3, and Amazon RDS along with open source tools like STAC and eoAPI to create scalable, cost-effective solutions. Learn more about building containerized applications on AWS at Containers on AWS.

22 Oct 20:53

How to choose the right AWS service for managing secrets and configurations

by Zachary Miller

When building applications on AWS, you often need to manage various types of configuration data, including sensitive values such as API tokens or database credentials. From environment variables and API keys to passwords and endpoints, this configuration data helps determine application behavior. AWS offers managed services that you can use for different aspects of managing secrets and configuration data, in addition to feature flags to adjust application behavior without requiring full code deployments. This post explores AWS Secrets Manager, AWS Systems Manager Parameter Store, and AWS AppConfig, and provides guidance on selecting the right service to help meet your requirements. To summarize: AWS recommends you use AWS Secrets Manager for secrets, Parameter Store for simple storage of key-value pairs, and AWS AppConfig for feature flags and advanced dynamic configuration.

Overview of relevant AWS services

Let’s begin by examining the core services that manage customer secrets and configurations: Secrets Manager, Systems Manager Parameter Store, and AWS AppConfig.

Secrets Manager

Secrets Manager specializes in protecting access to applications, services, and IT resources by managing the lifecycle of secrets. Secrets Manager helps you rotate, manage, and retrieve credentials for databases, API keys, OAuth tokens, JSON Web Tokens (JWTs) and other secrets, securing resources in the AWS Cloud, on-premises, or in multi-cloud environments. Secrets Manager was designed specifically for sensitive credentials such as database passwords and can be used to replicate secrets to other AWS Regions and rotate passwords automatically based on a configurable schedule. Secrets Manager integrates with AWS Key Management Service (AWS KMS) to encrypt secrets you create with a KMS key you own and control—this encryption of secrets cannot be disabled. Additionally, Secrets Manager supports Post-Quantum TLS (PQ TLS) by default for API communications, with select client SDKs also offering PQ TLS protection.

Parameter Store

Parameter Store, a capability within Systems Manager, offers secure, hierarchical storage for configuration data and secure strings. You can store various types of data—from passwords and database strings to AMI IDs and license codes—as parameter values. These values can be stored as either plain text or encrypted data and referenced using unique names. Parameter Store also offers encryption using AWS KMS, but only for a specific parameter type, known as SecureString parameters. SecureString parameters must be encrypted with AWS KMS, but other parameter types can be stored unencrypted.

AWS AppConfig

AWS AppConfig facilitates the creation, management, and deployment of feature flags and application configuration data. It’s designed to support applications of different sizes with controlled deployments and includes robust validation mechanisms and monitoring capabilities. AWS AppConfig works seamlessly with various deployment targets, including Amazon Elastic Compute Cloud (Amazon EC2) instances, AWS Lambda functions, containers, mobile applications, and Internet of Things (IoT) devices. While AWS AppConfig can store configuration data either in its own datastore, using Parameter Store, or using Secrets Manager, it’s primarily designed to help you speed up software release frequency, improve application resiliency, and address emergent issues more quickly using feature flags and dynamic configuration as a powerful DevOps tool.

Service similarities

These services share several common capabilities while maintaining distinct specializations. All three support comprehensive logging through AWS CloudTrail and monitoring through Amazon CloudWatch, can be governed through granular AWS Identity and Access Management (IAM) permissions and service control policies (SCPs), and are available across the commercial Regions. They can store configuration data, though each excels in different scenarios. Parameter Store should be used to store and manage non-sensitive configuration data that doesn’t require frequent rotation or replication across Regions. Secrets Manager focuses on storing and automatically rotating sensitive credentials, offering features like the Secrets Manager Agent for secret caching and retrieval, and integrations with services like Amazon Relational Database Service (Amazon RDS) to reduce the operational overhead of managing admin passwords for databases. AWS AppConfig specializes in managing application configuration and feature flags with deployment safety controls and can be used in conjunction with Parameter Store or Secrets Manager to store and manage sensitive credentials. AWS AppConfig also uses a caching agent for performance and resiliency.

All three services can be used to encrypt your configuration data using AWS KMS. You can use IAM permissions in conjunction with AWS KMS to control access to encrypted values. Parameter Store and Secrets Manager also support resource policies for secrets and parameters that can be used to grant cross-account access and provide another layer of access control in addition to IAM policies.

The services also share an integration with AWS CloudFormation, enabling references to configuration data within templates instead of hardcoding sensitive information. This integration helps maintain security in infrastructure-as-code practices by helping prevent exposure of sensitive data. Additionally, all three services support versioning, though they implement it differently: Secrets Manager creates new versions during rotation or value changes, Parameter Store maintains versions when parameters are edited, and AWS AppConfig tracks versions through configuration profiles and its hosted configuration store.

Service differences

A primary differentiator between these three services is their approach to access control and permissions management. Secrets Manager offers the most comprehensive security controls through multiple layers: resource-based policies (RBPs), resource control policies (RCPs), service control policies (SCPs), attribute-based access control (ABAC), and AWS KMS key policies. By using this multi-layered approach, organizations can implement defense-in-depth strategies and can meet stringent compliance requirements. Additionally, the integration of Secrets Manager with Amazon GuardDuty provides automated secret-specific threat detection, including alerts for potentially malicious API calls or unauthorized access attempts. The direct integration of Secrets Manager with AWS Config and AWS Security Hub enables automated compliance monitoring and reporting across multiple compliance frameworks (such as PCI DSS, HIPAA, and SOC), with built-in controls and continuous assessment capabilities. These comprehensive security and compliance features make Secrets Manager particularly suitable for regulated industries requiring detailed audit trails and compliance reporting.

Another key difference is the ability to replicate secrets and parameters across Regions and automatically rotate secrets to reduce the impact radius of a compromised credential. The built-in automatic rotation functionality of Secrets Manager—using Lambda functions to handle rotation logic with customizable intervals—sets it apart from other services. The service maintains previous versions during rotation to help facilitate system stability. While Parameter Store and AWS AppConfig don’t offer native rotation capabilities, you can reference secrets stored in Secrets Manager as configuration sources, enabling a complementary approach to secrets management.

The services also differ in their logging and observability capabilities. While all three services integrate with CloudTrail for API activity logging, Secrets Manager provides additional detailed logging through CloudWatch Logs for rotation events and secret access patterns. It also offers enhanced monitoring through CloudWatch metrics for tracking secret versions, rotation status, and API usage patterns, providing deeper operational insights compared to Parameter Store and AWS AppConfig.

In terms of resilience, all three services are highly available within a Region, but only Secrets Manager supports the ability to automatically replicate secret values across Regions. For example, if you have a requirement to replicate database passwords to multiple Regions for a global application (or disaster recovery), you can use secret replicas to keep secret values in sync with each other, even when the primary version of the secret is rotated automatically. Parameter Store lacks multi-Region support and only provides cross-account access through resource-based policies, limiting its use to single-Region deployments. This makes Parameter Store suitable for Regional configuration management.

AWS AppConfig distinguishes itself through comprehensive deployment safety mechanisms. It employs validators to help make sure configuration updates are both syntactically and semantically correct, supporting both JSON schema and custom Lambda function validators. The service implements gradual deployment strategies to control configuration change rates and includes automatic rollback capabilities triggered by CloudWatch (and other APM provider) alarms. These features help limit the potential impact of configuration changes, while Parameter Store and Secrets Manager focus primarily on secure storage and retrieval of credentials.

From a pricing perspective, the services have different cost models aligned with their capabilities. Parameter Store offers standard parameters at no additional charge, while advanced parameters cost $0.05 per parameter per month plus API interaction costs. Advanced parameters support larger parameter values (up to 8 KB) and parameter policies, using envelope encryption with the AWS Encryption SDK for SecureString parameters. Secrets Manager charges $0.40 per secret stored plus API calls, reflecting its additional capabilities such as secret replication, automatic rotation, and native integrations with AWS services like Amazon RDS. Its pricing model is designed for storing sensitive credentials that require these advanced features. It maintains versions of secrets throughout their lifecycle, particularly during rotation, and you can retrieve specific versions as needed. AWS AppConfig is priced based on configurations received ($0.0008 per configuration) and configuration requests ($0.0000002 per request), with the flexibility to store configurations directly or reference them from Parameter Store or Secrets Manager. This pricing structure makes Parameter Store optimal for non-sensitive configuration data, Secrets Manager for sensitive credentials requiring rotation, and AWS AppConfig for managing application configurations with deployment controls.

Use case examples

Let’s explore a few common use cases to illustrate when each service proves most valuable.

Non-sensitive key/value pairs that don’t require advanced features

For non-sensitive key/value pairs in applications that don’t require regular rotation, compliance monitoring, or resilience across multiple Regions, Parameter Store will likely be the best choice for most customers. Consider a scenario where an application needs to store a license key for a database, or an AMI ID. Parameter Store is a good choice because the use case doesn’t require rotation or multi-Region replication, the data structure is straightforward, and cost efficiency matters for high-volume retrieval. Encryption with AWS KMS is supported if needed for parameters that might be for internal use only but don’t contain personally identifiable information (PII) or credentials used for authentication. With Parameter Store, you can efficiently manage large sets of parameters while maintaining security controls and organizational structure. Retrieving the values from Parameter Store is straightforward for developers, as shown in the following example (Python):

import boto3 
ssm = boto3.client('ssm') 
response = ssm.get_parameter(     
	Name='/myapp/dev/api-endpoint',     
    WithDecryption=False 
) 
api_endpoint = response['Parameter']['Value']

Database credentials with rotation and multi-Region requirements

For database credentials requiring rotation and multi-Region capabilities, Secrets Manager is the clear choice. Its automatic rotation functionality, multi-Region replication support, and native integration with Amazon RDS and other AWS services make it well-suited for managing complex database credential scenarios. Similarly, you should choose Secrets Manager for sensitive items like API keys and other types of credentials used for authentication. In the following diagram, you can see an example application architecture using Lambda to retrieve database credentials from Secrets Manager, which will be used to authenticate and query information from an RDS instance. Because the RDS instance has a cross-Region read replica, you can replicate the secret to the secondary Region (us-west-2), allowing the Lambda function in us-west-2 to get the secret value and query the read replica, even if the secret in the primary Region (us-east-1) cannot be accessed.

Secrets Manager also makes it straightforward for developers to retrieve secrets in their application, as shown in the following code sample:

import boto3 

secrets = boto3.client('secretsmanager') 
response = secrets.get_secret_value(
	SecretId='myapp/dev/db-credentials' 
)

While you can directly call the Secrets Manager APIs to retrieve a secret (as shown in the preceding example), Secrets Manager also has a number of features and integrations to improve the developer experience further, including the AWS Secrets Manager Agent, native integrations with Amazon Elastic Container Service (Amazon ECS), and the AWS Secrets and Configuration Provider (ASCP), which complements the CSI Driver utility in Kubernetes.

Secure password generation in CI/CD pipelines

When building applications, you might need to securely generate a password or other type of secret in your continuous integration and delivery (CI/CD) pipeline, without that secret value being exposed to developers or other human users. The ability of Secrets Manager to generate and manage secure passwords without human intervention, combined with its automated rotation capabilities and CI/CD tool integration, makes it the optimal solution. In the following sample, the Secrets Manager API GetRandomPassword is used to securely generate a password with a specific, configurable length without that value being exposed to a human or written to application logs or pipeline artifacts.

import boto3 

secrets = boto3.client('secretsmanager') 
response = secrets.get_random_password(     
	PasswordLength=32,     
    ExcludeCharacters='/@"\'\\',     
    ExcludePunctuation=True 
)

Configurable deployment controls

AWS AppConfig shines in scenarios requiring sophisticated deployment controls and validation for configuration changes. Its validation mechanisms, gradual deployment capabilities, and automatic rollback features make it ideal for managing feature flags and application configurations where controlled deployment is crucial. For instance, you might have a configuration file that contains an Allowlist of network environments that should be able to access and use your application; or you could have feature flags that enable use of AI for recommendations, or live-chat with support.

These examples aren’t necessarily sensitive values that require strong access control, encryption, and automatic rotation to reduce the impact radius of a lost credential. This means Secrets Manager wouldn’t be the most cost-effective choice to store these parameters: the additional value provided by features like automatic rotation aren’t needed for this use case. Also, AWS AppConfig is designed to help you validate your configuration changes and deploy them in a controlled way. For a more concrete example, see the following configuration files, which outline a network allowlist and AI configuration data for an example application.

(YAML) 

AllowList.yml 
# AllowList.yml 

# Network Access Controls 
ip_allowlists:   
	internal_networks:     
    - "10.0.0.0/8"     # Internal corporate network     
    - "172.16.0.0/12"  # VPC network range     
    - "192.168.1.0/24" # Development network 
    
# Domain Allowlist 
domain_allowlist:   
	api_consumers:     
    	- "api.partner1.com"     
        - "services.partner2.com"     
        - "*.trusted-client.com"

(JSON) 

GenAIModels.json

{
	"models": {
		"claude-3-sonnet": {
			"provider": "bedrock",
			"model_id": "anthropic.claude-3-sonnet-20240229-v1:0",
			"temperature": 0.3,
			"region": "us-east-1"
		},
		"claude-3-haiku": {
			"provider": "bedrock",
			"model_id": "anthropic.claude-3-haiku-20240307-v1:0",
			"temperature": 0.5,
			"region": "us-east-1"
		},
		"titan-text": {
			"provider": "bedrock",
			"model_id": "amazon.titan-text-express-v1",
			"temperature": 0.4,
			"region": "us-east-1"
		},
		"llama2-70b": {
			"provider": "bedrock",
			"model_id": "meta.llama2-70b-chat-v1",
			"temperature": 0.6,
			"region": "us-west-2"
		}
	},
	"default_model": "claude-3-sonnet",
	"fallback_model": "claude-3-haiku",
	"timeout": 60,
	"retry_attempts": 3
}

Conclusion

Selecting the appropriate service depends on your specific requirements. Choose Parameter Store when managing basic configuration data, secure strings, or a large volume of secrets that don’t require rotation or multi-Region replication, particularly when cost optimization is important. Opt for Secrets Manager when handling sensitive credentials requiring rotation and cross-account or multi-Region resilience. Select AWS AppConfig when sophisticated deployment controls and validation for configuration changes are essential; and remember that you can use Parameter Store or Secrets Manager to store the actual configuration data, instead of or in addition to the default configuration datastore provided by AWS AppConfig.

These services aren’t mutually exclusive; they can work together as part of a comprehensive configuration management strategy. Many organizations successfully combine Parameter Store for general configuration data, Secrets Manager for sensitive credentials, and AWS AppConfig for feature flags and application configuration deployment. By using this integrated approach, you can take advantage of the strengths of each service while maintaining security and operational efficiency.

To get started, visit the AWS Management Console. Each service discussed in this post provides detailed documentation and getting started guides to help implement the right solution for your specific use case.

Getting Started guides


If you have feedback about this post, submit comments in the Comments section below. If you have questions about this post, contact AWS Support.

Zach Miller

Zach Miller
Zach is a Principal Security Specialist Solutions Architect at AWS. His background is in data protection and security architecture, focused on a variety of security domains, including applied cryptography and secrets management. Today, he focuses on helping enterprise AWS customers adopt and operationalize AWS security services to increase security effectiveness and reduce risk.

Rochak Karki

Rochak Karki
Rochak is a Security Specialist Solutions Architect at AWS, focusing on threat detection, incident response, and data protection helping customers build secure environments. Rochak is a US Army veteran and holds a Bachelor of Science in Engineering from the University of Wyoming. Outside of work, he enjoys spending time with family and friends, hiking, and traveling.

22 Oct 20:53

I overheard my employee tell our intern that I’m “clueless”

by Ask a Manager

A reader writes:

I was on a Zoom call today with my direct report and an intern. I momentarily took off my headphones to blow my nose and put myself on mute. However, through the headphones I heard my direct report say to the intern, “He’s so clueless!”

I am struggling with the best way to respond. Not only is this unprofessional behavior, but I have spent a lot of time training the direct report and have praised her to the higher-ups, as well as recently encouraged the leadership team to give her greater responsibility. So it feels a bit as a betrayal as well. She’s a millennial and I’m the youngest of the boomers if that matters, which it shouldn’t.

What would be the best way to handle this?

First and foremost, are you absolutely sure that she was talking about you? Could it have been a reference to someone who had just been discussed on the call, or they were looking at something silly someone posted on Slack, or … anything?

But if the context made it absolutely clear that it was about you … ugh. She’s allowed to have whatever private thoughts she wants — and most people do blow off steam about their bosses at some point, even when the boss is generally a good one — but badmouthing you to an intern is terrible judgment and bad for your team, and doing it on a call you were on at the time is even worse judgment. (That last part really does make me wonder if it wasn’t about you — because anyone with any sense would know there was a chance you could still hear them.)

Anyway, here we are. Whenever you see or hear someone’s private, negative thoughts about you that they didn’t mean for you to learn about, the most constructive way to look at it is as useful information. Most people won’t tell you to your face if they find you annoying or clueless or incompetent — particularly when you’re their manager — but it can be awfully useful to know they feel that way. Ideally, when that happens, you work to get past the sting and try to reflect objectively on where their feelings might be coming from. Not because you necessarily are the thing they labeled you as, but because it’s evidence that something is going on in your relationship with them that could benefit from reflection. So it’s worth taking this as a nudge to think about the relationship from her perspective. (When I’m hiring managers, I sometimes ask candidates, “Given that even the best managers annoy the people who work for them at times, what do you think the people you manage are most likely to find annoying about you?” The answers are fascinating, as is the number of people who genuinely seem like they’ve never reflected on that before.)

But I also think it’s fair to clear the air. It’s going to be awkward for both of you, but that itself isn’t a reason not to do it. You could say, “I know this is awkward, but on our call with Jane last week, when I briefly put myself on mute I heard you say something pretty unkind about me to Jane. I have no intention of policing your thoughts, but I do want you to be more thoughtful about not venting about work frustrations to an intern, who is not a peer. And I also want you to have the opportunity to tell me if I’m doing something that’s making your job more difficult or if something else is going on that you’d like me to handle differently.”

However, you should only say this if you are absolutely 100% sure from the context that she was talking about you. If there’s any chance she wasn’t, don’t do this. In that case, you might check in with her more broadly — leaving out the part about what you overheard and just asking for feedback on how things are going, any frustrations she’s having, etc. You won’t necessarily get a candid answer, but it’s a conversation you should have regardless. And then from there, in a scenario where you really can’t be positive about what you heard, I think you’ve got to try to wipe it from your mind. That’s easier said than done, I realize, but otherwise you risk introducing real tension into your relationship with her over something that might not have happened.

The post I overheard my employee tell our intern that I’m “clueless” appeared first on Ask a Manager.

22 Oct 16:27

Sí, se puede amamantar en la estación de València (y en cualquier espacio público)

by keizal

“Humillante” y “discriminatorio”. Así describe una mujer el trato recibido en la estación València Joaquín Sorolla el pasado 5 de octubre de 2025 por parte de dos personas que identifica como empleados de la compañía Iryo. La mujer cuenta a El Salto que se encontraba sentada en un banco de un andén amamantando a su bebé de seis meses cuando un trabajador le ordenó levantarse y abandonar el lugar, argumentando que “allí no se podía estar”. Ante esta petición,

etiquetas: valencia, amamantar, espacios públicos

» noticia original (www.elsaltodiario.com)

22 Oct 16:27

Una adolescente demanda a los creadores de una app usada para ‘desnudarla’ sin consentimiento

by JanSmite

Una adolescente estadounidense víctima de una aplicación, que usa la inteligencia artificial generativa para crear un desnudo falso de cualquiera a partir de una imagen con ropa, ha demandado a los creadores por las secuelas que arrastra y por el potencial uso que estén haciendo de sus imágenes para entrenar modelos de IA, según recoge Portaltic. En 2023, compañeros de instituto de Jane Doe (nombre genérico que se usa para no identificar a la menor de edad, en este caso, de 17 años) obtuvieron y usaron imágenes de ella para cargarlas en la app…

etiquetas: ia, app, desnudo, consentimiento

» noticia original (elpais.com)

22 Oct 16:27

Los doce consejeros del Tribunal de Cuentas, con un sueldo de 130.771 euros anuales, votan recuperar la tradición de llevar una medalla de 786 euros cada una

by tomeu

Los consejeros del Tribunal de Cuentas han decidido recuperar una tradición: llevar en sus actos institucionales una medalla. El órgano que se encarga de auditar la gestión económica del sector público, ha aprobado un contrato para comprar 12 medallas, una para cada consejero. Cada consejero tiene una retribución anual de 130.771,62 euros. Ninguno de ellos ha rechazado la condecaración

etiquetas: consejeros, medalla

» noticia original (www.infobae.com)

22 Oct 16:27

El acoso tan intolerable de Ndongo a Gabriel Rufián que hasta Vito Quiles lo ha calificado de "lamentable"

by eaglesight1

Lo de los agitadores mediáticos de la ultraderecha acosando a políticos y periodistas de izquierda y persiguiéndoles por la calle está sobrepasando todos los límites de lo tolerable.

etiquetas: ndongo, acoso, rufián, lamentable

» noticia original (www.publico.es)

22 Oct 16:26

Empleados federales hacen fila de una cuadra para recibir alimentos, mientras el cierre de Gobierno llega a su tercera semana

by Yorga77

Summer Kerksick esperó en la fila durante dos horas el martes para recibir una caja de productos enlatados y secos en un evento de banco de alimentos para empleados federales en medio del actual cierre del Gobierno. “Con mi alquiler venciendo la próxima semana, puedo aceptar cualquier cosa que pueda conseguir”, dijo Kerksick, contratista federal y analista de investigación de mercados en el Centro Rural de Exportación del Departamento de Comercio de EE.UU., a CNN.

etiquetas: empleados, federales, alimentos, cierre, gobierno

» noticia original (cnnespanol.cnn.com)

22 Oct 16:26

10 PRINT: un libro sobre un programa BASIC de una sola línea para Commodore 64 (ENG)

by ccguy

Los niños de los años 80 se convirtieron en programadores con facilidad porque los ordenadores de 8 bits arrancaban en un entorno de desarrollo sencillo que ejecutaba BASIC. Las revistas de informática de la época estaban repletas de programas que cualquiera con suficiente paciencia podía ejecutar, y algunos eran realmente muy largos. Pero el más famoso del Commodore 64 era solo una línea de código. Suficiente para mostrar un laberinto. Este libro (gratuito), analiza como y por qué funciona.

etiquetas: commodore, one liner, laberinto

» noticia original (10print.org)

22 Oct 16:26

El hombre que denunció la Gürtel recuerda cómo el juez Hurtado trató de salvar al PP: “Le debía mucho el PP y el partido le puso donde le podía ayudar”

by oghaio

“El juicio en el que se vio rápido que JLP era José Luis Peñas, pero M. Rajoy no fueron capaces de entender quién era". Entre otros asuntos, el juez Hurtado quedó en el recuerdo de muchos mientras juzgó la Gürtel por ser el único miembro del tribunal de este proceso que votó en contra de que Mariano Rajoy se sentara en el banquillo para declarar sobre esta causa que afectaba a su partido.

etiquetas: gürtel, juez, hurtado, salvar, pp

» noticia original (www.elplural.com)

22 Oct 16:24

Diputada de BILDU en el Parlamento Vasco: “Hoy, ser vascos y vascas también es hablar wolof, árabe, hassanía, quechua y euskera en el mismo patio de escuela”.

by Fino

Tantos años despreciando y tratando como invasores a los españoles que tenían la osadía de vivir en Euskadi, para acabar mamando de esta manera.

Los 8 apellidos vascos del futuro: Alaoui, Nazer, Laafou, Dahan, Murat, Amar, Abecassis y El Fadili.

Ver post completo: Diputada de BILDU en el Parlamento Vasco: “Hoy, ser vascos y vascas también es hablar wolof, árabe, hassanía, quechua y euskera en el mismo patio de escuela”.

22 Oct 16:24

Solo 10 contribuyentes pagan el 30% de todo el IRPF de Andorra.

by Fino

Solo 10 contribuyentes pagan el 30% de todo el IRPF de Andorra.

El presidente de Ciudadanos Comprometidos (CC) , Carles Naudi , ha afirmado que sólo diez personas concentran el 30% de toda la recaudación del impuesto sobre la renta de las personas físicas (IRPF) en Andorra. @laveulliure

Solo 10 contribuyentes pagan el 30% de todo el IRPF de Andorra.

Ver post completo: Solo 10 contribuyentes pagan el 30% de todo el IRPF de Andorra.

22 Oct 16:24

Rufián no puede hacer otra cosa que elogiar a Ábalos.

by Fino

Hola Fino, no miro mucho la tele últimamente, casi todo me informo por tu web de measentados y YouTube, pero me ha resultado curioso esta entrevista al madrileño de Rufián, podría ser la primera vez después de un año que Broncano hace un chiste de Ábalos, por cierto, un poco cutre, para lo que se podría bromear con este tema. Saludos. @Chofas.

También respondió a las preguntas clásicas.

Ver post completo: Rufián no puede hacer otra cosa que elogiar a Ábalos.

22 Oct 16:22

Virgen santa…

by Fino

Virgen santa...

Bingen Zupiria, filólogo vasco por la Universidad de Deusto, ex director de la televisión vasca y del periódico nacionalista Deia, no sabe cómo detener la nueva kale borroka en las calles vascas. Nombrado consejero de Seguridad por el lehendakari, Imanol Pradales, en julio de 2024 para acallar el descontento sindical, Zupiria ha confesado públicamente ahora que la Policía vasca debe «prestarle mayor importancia a esta violencia urbana». Los promotores de esta «violencia urbana» celebran como «victorias» sus enfrentamientos con la Policía vasca. «La victoria en Vitoria es un precedente en los conflictos que vendrán más tarde», advertía ayer Kai Karasatorre, portavoz de la plataforma radical Aske. @elmundo

Virgen santa...

Ver post completo: Virgen santa…