CheatCoders

Amazon Bedrock Custom Model Import: Host Fine-Tuned Coding Models Inside Your Account

You fine-tuned a coding model on your house style and unit-test quirks — then someone asks you to run a GPU cluster forever. Amazon Bedrock Custom Model Import lets you bring compatible fine-tuned weights into Bedrock and invoke them with the same Converse/Invoke APIs your agents already use. Distinct from Provisioned Throughput, Model Evaluation, Intelligent Prompt Routing, and Prompt Management: this is importing custom weights into Bedrock, not buying capacity or scoring outputs.

AWS Systems Manager Session Manager: Audited Break-Glass Shell into Coding-Agent Sandboxes

When a coding-agent sandbox wedges mid-refactor, humans still need a break-glass shell — without scattering SSH keys or bastion snowflakes. AWS Systems Manager Session Manager opens audited interactive sessions to EC2/Fargate-compatible targets with CloudTrail and optional S3/CloudWatch session logs. Distinct from Network Firewall egress filtering and IAM Roles Anywhere — this is human break-glass access with forensics, not network policy or cert-based machine identity.

Amazon S3 Express One Zone: Sub-Millisecond Scratch for Coding-Agent Tool Artifacts

Mid-turn coding-agent tools write lint logs, build caches, and hunk diffs that die with the turn — but classic S3 latency and request pricing make hot scratch feel sticky. Amazon S3 Express One Zone directory buckets give sub-millisecond first-byte for ephemeral tool artifacts in a single AZ. Distinct from S3 Object Lock (immutability) and EFS shared workspaces — this is latency/throughput for short-lived tool I/O.

AWS AppSync GraphQL Subscriptions: Push Live Coding-Agent Progress Without Polling

Polling a coding-agent job every 500ms wastes API calls and still feels laggy. AWS AppSync GraphQL subscriptions push plan/tool/diff progress events to the UI over managed WebSockets with Cognito/IAM auth — without you operating an API Gateway WebSocket fleet. Distinct from API Gateway WebSockets and Lambda response streaming: AppSync is managed GraphQL + subscriptions for progress fan-out.

Amazon Neptune: Graph Memory for Code Dependency Reasoning in Coding Agents

Flat RAG chunks lose the edges that matter for coding agents: who calls whom, which package pins which CVE, and how a symbol rename ripples. Amazon Neptune stores call graphs and dependency graphs so tools traverse vertices and edges with Gremlin or openCypher instead of hoping vector similarity reconstructs structure. Distinct from OpenSearch Serverless semantic scratch and GraphRAG bootcamp posts — this is managed graph DB + agent tool design for dependency reasoning.

AWS IAM Access Analyzer: Find Over-Privileged Coding-Agent Roles Before They Leak

Coding-agent tool roles accrete permissions until someone can s3:GetObject on every bucket "for RAG debugging." AWS IAM Access Analyzer finds unused privileges, external access, and policy issues before those roles leak into a credential incident. Distinct from GuardDuty (runtime threat) and Verified Permissions (app-level authZ): Access Analyzer is continuous IAM posture for the roles your agents assume.

Amazon CloudWatch Application Signals: SLOs and Traces for Multi-Hop Coding-Agent Tools

Multi-hop coding agents fail in the gaps between services: the planner was fine, the sandbox timed out, the RAG tool silently retried. Amazon CloudWatch Application Signals gives you service-level objectives, RED metrics, and trace correlation for those hops without hand-rolling a dozen custom dashboards. Distinct from raw Logs Insights spelunking and ad-hoc X-Ray alone: Application Signals standardizes SLOs and service maps for the agent tool graph.

AWS Config Conformance Packs: Continuous Compliance Guards for Coding-Agent Accounts

Coding-agent accounts drift: public buckets for artifacts, wildcard IAM for "just one debug session," missing encryption on scratch queues. AWS Config Conformance Packs continuously evaluate packs of managed/custom rules and report noncompliance so you catch unsafe baselines before Security Hub becomes a ticket graveyard. Distinct from CloudFormation Hooks (block at deploy) and SCPs (org hard deny): Conformance Packs are continuous compliance telemetry + optional remediation across the agent account fleet.

Amazon Bedrock Provisioned Throughput: Reserved Capacity for Coding-Agent Latency SLOs

On-demand Bedrock is fine until your coding-agent P95 spikes during standup demos and CI review bursts. Amazon Bedrock Provisioned Throughput reserves model capacity so latency SLOs stop depending on the regional on-demand pool. Distinct from Intelligent Prompt Routing (which picks a model) and Model Evaluation (which scores outputs): Provisioned Throughput is about guaranteed capacity and predictable inference latency for the models you already chose.

AWS Lambda Response Streaming: Stream Coding-Agent Tokens Without Buffering Full Completions

Buffering a full coding-agent completion before the client sees the first token adds seconds of perceived latency and blows Lambda's 6MB sync payload ceiling on long diffs. AWS Lambda response streaming (Function URL or InvokeWithResponseStream) lets you flush tokens and tool-progress events as they arrive — so the UI feels live without a separate WebSocket service. Pair with SnapStart for cold starts and Destinations for failed invokes; this post is about the response path, not orchestration.