CheatCoders

AWS Systems Manager Parameter Store: Hierarchical Config Coding Agents Must Not Hardcode

Coding agents love hardcoding model IDs, tool toggles, and repo allowlists — until prod and staging diverge and nobody knows which binary is lying. AWS Systems Manager Parameter Store gives you a hierarchical `/env/app/agent/...` config tree with SecureString, IAM path scoping, and dynamic reads. Distinct from Secrets Manager rotation (secret lifecycle), AppConfig feature flags (kill switches / deploy-time flags), and SSM Session Manager (shell access): this is hierarchical config agents must not hardcode.

Amazon Cognito Identity Pools: Federate Coding-Agent Tool Callers Without Long-Lived Keys

Browser UIs and thin agent gateways need temporary AWS credentials to call tool APIs — without shipping long-lived access keys in the SPA. Amazon Cognito Identity Pools (federated identities) exchange IdP tokens for STS creds scoped by IAM roles. Distinct from IAM Roles Anywhere (cert/on-prem machine identity), AppSync Cognito user-pool auth for GraphQL, and VPC Lattice service auth: this is federated identity → temporary AWS creds for human/UI/agent callers.

Amazon Athena: Query Coding-Agent Tool Audit Logs Without a Warehouse

Coding-agent tool calls leave JSON trails in S3 — who invoked apply_patch, which tenant, how many Bedrock tokens, which PR. You do not need a warehouse to ask those questions. Amazon Athena (plus Glue) SQL-queries the files in place for forensics and cost. Distinct from CloudTrail Lake (org CloudTrail events), CloudWatch Logs Insights (log-group search), and Detective (investigation graphs): this is cheap SQL over your own agent audit objects.

AWS Batch: Overnight Parallel Coding-Agent Jobs Without Babysitting EC2

Overnight you need fifty coding agents reviewing PRs and scanning repos — not one long Lambda that times out, and not a hand-babysat EC2 fleet. AWS Batch compute environments + job queues fan out parallel agent jobs with retries, fair-share, and Spot without you SSH-ing at 2am. Distinct from Fargate Spot sandboxes (interactive ephemeral), EventBridge Scheduler (time trigger only), CodeBuild sandboxes (buildspec-shaped), and FIS chaos: this is managed batch parallelism for overnight agent fleets.

Amazon Bedrock Prompt Management: Version and A/B Test Coding-Agent System Prompts

Coding-agent system prompts rot in git as copy-pasted strings — no version history the runtime can pin, no A/B variants, no safe rollback when a "helpful" edit tanks tool-call quality. Amazon Bedrock Prompt Management stores versioned prompt assets (and variants) you invoke by ARN so agents get the exact system/tool prompt you shipped. Distinct from Prompt Caching (token reuse), Intelligent Prompt Routing (model pick), Model Evaluation (scoring outputs), and Custom Model Import (weights): this is prompt-as-asset lifecycle for coding agents.

Amazon Bedrock Custom Model Import: Host Fine-Tuned Coding Models Inside Your Account

You fine-tuned a coding model on your house style and unit-test quirks — then someone asks you to run a GPU cluster forever. Amazon Bedrock Custom Model Import lets you bring compatible fine-tuned weights into Bedrock and invoke them with the same Converse/Invoke APIs your agents already use. Distinct from Provisioned Throughput, Model Evaluation, Intelligent Prompt Routing, and Prompt Management: this is importing custom weights into Bedrock, not buying capacity or scoring outputs.

AWS Systems Manager Session Manager: Audited Break-Glass Shell into Coding-Agent Sandboxes

When a coding-agent sandbox wedges mid-refactor, humans still need a break-glass shell — without scattering SSH keys or bastion snowflakes. AWS Systems Manager Session Manager opens audited interactive sessions to EC2/Fargate-compatible targets with CloudTrail and optional S3/CloudWatch session logs. Distinct from Network Firewall egress filtering and IAM Roles Anywhere — this is human break-glass access with forensics, not network policy or cert-based machine identity.

Amazon S3 Express One Zone: Sub-Millisecond Scratch for Coding-Agent Tool Artifacts

Mid-turn coding-agent tools write lint logs, build caches, and hunk diffs that die with the turn — but classic S3 latency and request pricing make hot scratch feel sticky. Amazon S3 Express One Zone directory buckets give sub-millisecond first-byte for ephemeral tool artifacts in a single AZ. Distinct from S3 Object Lock (immutability) and EFS shared workspaces — this is latency/throughput for short-lived tool I/O.

AWS AppSync GraphQL Subscriptions: Push Live Coding-Agent Progress Without Polling

Polling a coding-agent job every 500ms wastes API calls and still feels laggy. AWS AppSync GraphQL subscriptions push plan/tool/diff progress events to the UI over managed WebSockets with Cognito/IAM auth — without you operating an API Gateway WebSocket fleet. Distinct from API Gateway WebSockets and Lambda response streaming: AppSync is managed GraphQL + subscriptions for progress fan-out.

Amazon Neptune: Graph Memory for Code Dependency Reasoning in Coding Agents

Flat RAG chunks lose the edges that matter for coding agents: who calls whom, which package pins which CVE, and how a symbol rename ripples. Amazon Neptune stores call graphs and dependency graphs so tools traverse vertices and edges with Gremlin or openCypher instead of hoping vector similarity reconstructs structure. Distinct from OpenSearch Serverless semantic scratch and GraphRAG bootcamp posts — this is managed graph DB + agent tool design for dependency reasoning.