<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Thiago Sagara</title>
    <description>The latest articles on DEV Community by Thiago Sagara (@thiagosagara).</description>
    <link>https://dev.to/thiagosagara</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3388076%2F5a792f50-1078-49a4-b3ae-1c1c0f54cd91.jpg</url>
      <title>DEV Community: Thiago Sagara</title>
      <link>https://dev.to/thiagosagara</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/thiagosagara"/>
    <language>en</language>
    <item>
      <title>AWS News - S1E2</title>
      <dc:creator>Thiago Sagara</dc:creator>
      <pubDate>Fri, 14 Aug 2026 15:00:00 +0000</pubDate>
      <link>https://dev.to/aws-builders/aws-news-s1e2-k67</link>
      <guid>https://dev.to/aws-builders/aws-news-s1e2-k67</guid>
      <description>&lt;p&gt;Last week we kicked off a series covering the (data/storage/network) announcements that, in my view, had the most impact. This week I'm bringing 5 more recent launches to run through the fine-tooth comb. Description, the pain point it solved, and my critical take on each one.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Aurora DSQL lands in five more regions
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Aurora DSQL, AWS's distributed, serverless SQL database, is now available in Asia Pacific (Hong Kong), Asia Pacific (Mumbai), Asia Pacific (Singapore), Europe (Stockholm), and South America (São Paulo). With this launch, it now covers 19 regions total.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Official link:&lt;/strong&gt; &lt;a href="https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-aurora-dsql-five-additional-aws-regions/" rel="noopener noreferrer"&gt;https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-aurora-dsql-five-additional-aws-regions/&lt;/a&gt;&lt;br&gt;
  &lt;iframe src="https://www.youtube.com/embed/1ZkdElRQXXk"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How it used to be (the pain point):&lt;/strong&gt; Until now, if you wanted to run Aurora DSQL with decent latency for users in Brazil, there was no regional option here. You either accepted the latency of hitting us-east-1 (an ugly phrase for a transactional application to hear) or gave up on DSQL entirely and went with a traditional Aurora PostgreSQL, purely for geographic proximity.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;My take:&lt;/strong&gt; region expansion is the kind of announcement that isn't sexy, but it's what decides whether a service actually goes into production or stays a showcase item. With São Paulo on the list, the main adoption blocker for DSQL around here (latency) drops significantly. That said, it's worth remembering DSQL is still a relatively young product, with compatibility limitations against full PostgreSQL (extensions, certain data types, certain transactional features). Regional presence solves latency, it doesn't solve feature-set maturity. Those are two separate conversations.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Aurora DSQL gets a native PHP connector
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; launch of the Aurora DSQL connector for PHP (PDO_PGSQL), which handles IAM authentication natively: generates a token per connection, guarantees the valid token gets used, and keeps full compatibility with the PDO_PGSQL that the PHP ecosystem already knows. It also brings retry with exponential backoff for optimistic concurrency control (OCC), plus support for custom IAM credential providers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Official link:&lt;/strong&gt; &lt;a href="https://aws.amazon.com/about-aws/whats-new/2026/04/aurora-dsql-connector-for-php/" rel="noopener noreferrer"&gt;https://aws.amazon.com/about-aws/whats-new/2026/04/aurora-dsql-connector-for-php/&lt;/a&gt;&lt;br&gt;
  &lt;iframe src="https://www.youtube.com/embed/PzgfRCxkKEo"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How it used to be (the pain point):&lt;/strong&gt; before this connector, authenticating a PHP application against Aurora DSQL via IAM was a hand-rolled hack: you had to orchestrate temporary token generation yourself, make sure it got renewed before expiring, and still handle retries for optimistic concurrency conflicts, which is a defining characteristic of distributed databases like DSQL. One mistake in that logic and your application starts silently dropping connections in production.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;My take:&lt;/strong&gt; this is AWS paying down technical debt it created itself by launching DSQL without mature language coverage. PHP still powers a massive slice of backend in the world (WordPress, Laravel, legacy systems at companies of every size), and not having an official connector was a clear signal that DSQL was born prioritizing Java, Python, and Go. Good to see the gap closed, but note that the connector solves authentication and retry, it doesn't solve DSQL's SQL compatibility limitations against traditional Postgres. If your PHP stack depends on a specific unsupported feature, the connector doesn't change that.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Amazon Quick integrates with New Relic for observability agents
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Amazon Quick now talks to New Relic's AI agents via MCP (Model Context Protocol). You can investigate an incident, generate root cause analysis (RCA) with linked evidence, run NRQL queries in natural language, and trigger a triage runbook, all inside the Quick chat, without switching tools.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Official link:&lt;/strong&gt; &lt;a href="https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-quick-new-relic/" rel="noopener noreferrer"&gt;https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-quick-new-relic/&lt;/a&gt;&lt;br&gt;
  &lt;iframe src="https://www.youtube.com/embed/1n09Bz70M8M"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How it used to be (the pain point):&lt;/strong&gt; investigating an incident today on any SRE or on-call team means opening five tabs: the observability dashboard, the runbook in the internal wiki, the alert history, the ticketing tool, and sometimes Slack too, just to check if someone already touched something. Every context switch is time lost during an incident, which is exactly the moment you have the least time to spare.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;My take:&lt;/strong&gt; this is an integration that makes sense for the right reason, reducing context switching during an incident is a real, measurable gain (genuinely lower MTTR, not just a sales slide number). The thing to watch is the dependency on the quality of the runbook and internal documentation Quick uses as context (the official announcement mentions this explicitly). If your internal knowledge base is bad or outdated, the agent will answer with the same bad quality, just faster. Generative AI on top of observability amplifies what you already have, it doesn't replace the operational maturity you're missing.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Amazon Quick gets Free and Plus plans
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; Amazon Quick now has two new entry-level plans, Free and Plus, with sign-up via personal email or social login (Google, Apple, GitHub, Amazon), no AWS account required. Guided onboarding promises to show value in under 5 minutes, with ready-made workflows for sales, marketing, finance, and operations.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Official link:&lt;/strong&gt; &lt;a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-quick-free-plus/" rel="noopener noreferrer"&gt;https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-quick-free-plus/&lt;/a&gt;&lt;br&gt;
  &lt;iframe src="https://www.youtube.com/embed/TBkf-NbSM20"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How it used to be (the pain point):&lt;/strong&gt; before this, Quick required an AWS account just to try it out, which is a real barrier for anyone who just wants to test a productivity assistant and doesn't want to deal with the console, billing, IAM, and the rest of the AWS apparatus just to see if the tool fits their needs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;My take:&lt;/strong&gt; this is AWS playing in Copilot's, ChatGPT Team's, and similar tools' field, an end-user productivity product, not an infra engineer's tool. And it's a notable tone shift for a company that historically sells to people already inside its ecosystem. Makes sense strategically (land and expand: get in for free, use it, then convince the whole team to move to Professional or Enterprise). Just don't confuse this with an infrastructure product, it's a personal productivity tool disguised as an AWS announcement, and the evaluation bar is different here: usability and integration with everyday tools matter more than SLA and granular IAM in this case.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Valkey 9.0 lands in Amazon ElastiCache
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;What it is:&lt;/strong&gt; ElastiCache now supports Valkey 9.0, bringing hybrid and real-time full-text search (on top of the already-existing vector similarity search), up to 40% more throughput on pipelined workloads, field-level expiration inside a hash (granular TTL), and support for multiple logical databases in cluster mode.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Official link:&lt;/strong&gt; &lt;a href="https://aws.amazon.com/about-aws/whats-new/2026/05/valkey-amazon-elasticache/" rel="noopener noreferrer"&gt;https://aws.amazon.com/about-aws/whats-new/2026/05/valkey-amazon-elasticache/&lt;/a&gt;&lt;br&gt;
  &lt;iframe src="https://www.youtube.com/embed/E_IGRV_xFmo"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How it used to be (the pain point):&lt;/strong&gt; anyone who needed full-text or hybrid search on top of a cache would normally run a separate search service (OpenSearch, for example) in parallel, with the full pain of syncing data between the cache and the search index. And without granular per-field TTL inside a hash, you had to manage expiration at the level of the entire key, forcing a coarser data model than ideal for multi-tenant use cases.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;My take:&lt;/strong&gt; Valkey keeps proving itself to be the right fork at the right time. Since becoming a Linux Foundation project after Redis's license change, it's been shipping relevant features fast, and this release combines vector search with full-text in the same cache engine, which is a real draw for AI workloads (RAG, for example) that today need to maintain cache and search as separate services. The skepticism here is around the project's long-term governance: Valkey is still young as a fork, and it's worth watching whether this pace of innovation holds up, or whether this is just the initial burst of post-Redis-split energy.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Sources: AWS What's New (official links in each section).&lt;/em&gt;&lt;/p&gt;

</description>
      <category>database</category>
      <category>aws</category>
      <category>cloud</category>
      <category>news</category>
    </item>
    <item>
      <title>AWS News - S1E1</title>
      <dc:creator>Thiago Sagara</dc:creator>
      <pubDate>Wed, 12 Aug 2026 17:58:21 +0000</pubDate>
      <link>https://dev.to/aws-builders/aws-news-s1e1-4g03</link>
      <guid>https://dev.to/aws-builders/aws-news-s1e1-4g03</guid>
      <description>&lt;h2&gt;
  
  
  1 - Amazon S3 Files: now your bucket doubles as a file system
&lt;/h2&gt;

&lt;p&gt;S3 Files simulates an S3 bucket as a file system, with full file system semantics and low latency, without you having to pull the data out of S3 to make that happen. Under the hood, it's &lt;strong&gt;built on top of Amazon EFS&lt;/strong&gt;, so you get the performance and simplicity of a file system combined with the durability and cost profile of S3.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Official link:&lt;/strong&gt; &lt;a href="https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-s3-files/" rel="noopener noreferrer"&gt;https://aws.amazon.com/about-aws/whats-new/2026/04/amazon-s3-files/&lt;/a&gt;&lt;br&gt;
  &lt;iframe src="https://www.youtube.com/embed/ed9T0yKw-pc"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What pain does it solve?&lt;/strong&gt; If your company stores data in S3 (which is basically everyone, since it's the default market data lake), but has some tool, pipeline, or agent that only speaks file system (POSIX mount, not the S3 API), your options used to be: duplicate the data into an EFS or FSx and keep the two painfully in sync by hand, or rewrite the tool to talk to the S3 API. Both of those generate operational overhead, doubled storage costs, and a sync headache nobody wants to carry into production.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Bonus tip:&lt;/strong&gt; S3 still isn't actually a file system. Even simulating/translating POSIX, it won't treat data as block storage. So use this technique with some restraint, since it can generate extra costs from GET and LIST calls.&lt;/p&gt;

&lt;h2&gt;
  
  
  2 - S3 Account Regional Namespaces: goodbye bucket-name fights
&lt;/h2&gt;

&lt;p&gt;You can now create general purpose S3 buckets inside a reserved namespace scoped to your account, per region. This eliminates the need for a globally unique bucket name, which used to be a frustrating limitation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Official link:&lt;/strong&gt; &lt;a href="https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-s3-account-regional-namespaces/" rel="noopener noreferrer"&gt;https://aws.amazon.com/about-aws/whats-new/2026/03/amazon-s3-account-regional-namespaces/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;  &lt;iframe src="https://www.youtube.com/embed/Wktg3wDxtGo"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What pain does it solve?&lt;/strong&gt; Anyone who's ever tried to create a bucket named something obvious like &lt;code&gt;logs-prod&lt;/code&gt; knows the frustration of getting hit with "name already exists." That happens because bucket namespace was global across every AWS account on the planet. This became a real problem in multi-tenant architectures, where you need to spin up a bucket per client or per team in an automated way. Your only options were inventing a hash or UUID naming scheme to guarantee uniqueness, or just hoping nobody had already grabbed the name.&lt;/p&gt;

&lt;h2&gt;
  
  
  3 - Database Savings Plans now covers OpenSearch Service and Neptune Analytics
&lt;/h2&gt;

&lt;p&gt;Launched at re:Invent 2025, Database Savings Plans, which already covered RDS and Aurora, now also includes Amazon OpenSearch Service and Amazon Neptune Analytics. You commit to an hourly spend ($/hour) for a year, no upfront payment, and get a discount of up to 35%.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Official link:&lt;/strong&gt; &lt;a href="https://aws.amazon.com/about-aws/whats-new/2026/03/dbsp-opensearch-service-neptune-analytics/" rel="noopener noreferrer"&gt;https://aws.amazon.com/about-aws/whats-new/2026/03/dbsp-opensearch-service-neptune-analytics/&lt;/a&gt;&lt;br&gt;
  &lt;iframe src="https://www.youtube.com/embed/OMCGljP4B_g"&gt;
  &lt;/iframe&gt;
&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What pain does it solve?&lt;/strong&gt; If your search or graph workload ran on OpenSearch or Neptune Analytics, your only savings lever was a Reserved Instance tied to a specific instance family. That could be a real limiter, or even a dealbreaker, for anyone who needs to scale or switch instance types as load changes (which happens constantly in a search cluster), because you'd lose the discount the moment you migrated.&lt;/p&gt;

</description>
      <category>database</category>
      <category>aws</category>
      <category>news</category>
    </item>
    <item>
      <title>SWIFT built a blockchain ledger with Hyperledger Besu: dissecting a supposed architecture and imagining it on AWS</title>
      <dc:creator>Thiago Sagara</dc:creator>
      <pubDate>Mon, 03 Aug 2026 13:13:53 +0000</pubDate>
      <link>https://dev.to/aws-builders/swift-built-a-blockchain-ledger-with-hyperledger-besu-dissecting-a-supposed-architecture-and-2nla</link>
      <guid>https://dev.to/aws-builders/swift-built-a-blockchain-ledger-with-hyperledger-besu-dissecting-a-supposed-architecture-and-2nla</guid>
      <description>&lt;h2&gt;
  
  
  Intro
&lt;/h2&gt;

&lt;p&gt;In July 2026, Swift went live with blockchain, including 17 banks worldwide (Itaú representing Brazil) for 24/7 international payment testing, a major shift for a system created in 1973 whose biggest updates were gpi in 2017 and the ISO 20022 standard, which started rolling out in 2023.&lt;/p&gt;

&lt;p&gt;About a year ago I wrote about Drex, Bacen (Brazil's Central Bank) testing Hyperledger Besu, and how much the promise of "tokenizing everything" still depended on a lot of proof-of-concept work. Since then, a lot has happened, and not all of it the way I'd hoped. Bacen walked away from Besu (Dec/2025). The TCU (Brazil's federal audit court) questioned the technology's maturity (Feb/2026). And, almost at the same time, Swift launched the first phase of its own blockchain-based ledger on top of... the same Hyperledger Besu (Mar/2026), with the pilot going live in July/2026.&lt;/p&gt;

&lt;p&gt;Two institutions, the same technological base, two different paths. This article has three goals: explain what Swift is and why it decided to move on this, technically understand what it built, and finally get to where I really want to go, if we were to architect what it built on AWS, what design decisions would come into play (and where AWS has real gaps for this kind of solution).&lt;/p&gt;




&lt;h2&gt;
  
  
  What Is Swift, and Why Isn't It "the Global Banking System"?
&lt;/h2&gt;

&lt;p&gt;Before getting into blockchain, it's worth clearing up something that often causes confusion: Swift doesn't move money, you don't make transfers through it. To put it plainly, Swift is the global messaging network banks use to make international transfers quickly (sometimes) and securely.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgbh41ja188f0ap0385ee.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fgbh41ja188f0ap0385ee.png" alt=" " width="800" height="533"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Think of it this way: when you send a registered letter through the mail, the postal service isn't just delivering what's inside the envelope, it's guaranteeing that the message "deliver this to so-and-so, at this address" arrives reliably and traceably. Swift (Society for Worldwide Interbank Financial Telecommunication) is the equivalent of that "traceable" layer for financial institutions, it's literally a secure global messaging network for financial institutions to exchange information and instructions about financial transactions. In practice, it tells the destination bank: "Bank X confirms it will send Y dollars to account Z."&lt;/p&gt;

&lt;p&gt;Notice that the system doesn't hold money, doesn't move money, isn't an account anywhere.&lt;/p&gt;

&lt;p&gt;The banks that actually move the money are correspondent banks, a chain of intermediary banks that, one by one, debit and credit accounts with each other (called nostro/vostro accounts) until the amount reaches its final destination. That's exactly why an international transfer can pass through three or four banks you've never heard of, each one charging a fee and taking time to process.&lt;/p&gt;

&lt;p&gt;It's worth comparing this to PIX, which has become the largest payment method in Brazil. PIX is settlement, the money leaves your account and lands in someone else's account, instantly, inside a closed system (SPI). Swift is messaging, the banks are the ones that settle, through a chain of intermediaries that used to take days (until gpi launched in 2017).&lt;/p&gt;

&lt;p&gt;This difference between messaging and settlement is the key to understanding why Swift decided to move on blockchain.&lt;/p&gt;




&lt;h2&gt;
  
  
  What Problem Does Blockchain Solve? Didn't gpi Already Solve This?
&lt;/h2&gt;

&lt;p&gt;Working through a chain of intermediary banks could take days, and that was indeed one of Swift's main problems, but this problem already had something of a solution: Swift gpi (Global Payments Innovation), launched in 2017, and its numbers are genuinely good. According to the BIS (Bank for International Settlements) report and Swift's own Spotlight on Speed report, since gpi's implementation we have:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Data (BIS / Spotlight on Speed)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Median processing time&lt;/td&gt;
&lt;td&gt;1h38min&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Average processing time&lt;/td&gt;
&lt;td&gt;8h36min&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Transactions completed within 5 minutes&lt;/td&gt;
&lt;td&gt;25%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Intermediary banks processing within 5 minutes&lt;/td&gt;
&lt;td&gt;78%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;End-to-end traceability&lt;/td&gt;
&lt;td&gt;UETR implemented&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;On top of that, 75% of payments now reach the beneficiary bank within 10 minutes, which was &lt;em&gt;the&lt;/em&gt; big problem at the outset, and even beats the G20's target (which called for transfers within 1 hour).&lt;/p&gt;

&lt;p&gt;Still, even with great numbers, Swift's real remaining problem is the total time of a payment's journey. Today, on average, 80% of that time happens &lt;em&gt;after&lt;/em&gt; the payment has already left the Swift network, in other words, in the "last mile," once it's already inside the beneficiary bank.&lt;/p&gt;

&lt;p&gt;Putting the sources together, a consistent pattern emerges over the last 5 years: messaging was never the bottleneck, what happens after the message reaches the beneficiary bank is.&lt;/p&gt;

&lt;p&gt;Even after gpi, the causes for this are:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Regulatory reporting requirements (basically, identifying the purpose of the payment);&lt;/li&gt;
&lt;li&gt;Foreign exchange controls and country-specific risk rules;&lt;/li&gt;
&lt;li&gt;Lack of 24/7 infrastructure;&lt;/li&gt;
&lt;li&gt;Manual processes.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;And this is precisely the bottleneck where the tokenized deposit proposal shines. A tokenized deposit, moving on a ledger shared between banks, eliminates much of the manual friction and dependency on banking hours that today holds up a payment even after it's already arrived. The value is already settled on the ledger, without waiting for the destination bank's batch processing.&lt;/p&gt;

&lt;p&gt;One important caveat: this may solve the last two points of the bottleneck more than the others (24/7 infrastructure and manual processes). Smart contracts can automate regulatory compliance, but capital controls themselves remain a matter of public policy for each country to decide, not something a smart contract eliminates on its own.&lt;/p&gt;




&lt;h2&gt;
  
  
  What Did Swift Actually Build, and How Could This Be Implemented on AWS?
&lt;/h2&gt;

&lt;p&gt;Alright, but what did Swift technically build? Let's activate bit-scrubbing mode (with a bit of poetic license here, imagining what this network would look like).&lt;/p&gt;

&lt;p&gt;What Swift built is a shared, permissioned ledger running on Hyperledger Besu (which we already know is EVM-compatible, Ethereum Virtual Machine), now maintained by the Linux Foundation via Decentralized Trust.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Layer&lt;/th&gt;
&lt;th&gt;What Swift built (confirmed)&lt;/th&gt;
&lt;th&gt;How this could look on AWS (reconstruction)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Technology base&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Shared, permissioned ledger on Hyperledger Besu (EVM-compatible), maintained by the Linux Foundation via Decentralized Trust&lt;/td&gt;
&lt;td&gt;Self-managed; Amazon Managed Blockchain does &lt;strong&gt;not&lt;/strong&gt; support Besu natively&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Consensus&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;QBFT, known validators, approval by 2/3 supermajority, high fault tolerance&lt;/td&gt;
&lt;td&gt;EKS clusters orchestrating consensus, connected to each other through the Swift network&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Permissioning&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Validators registered in the genesis block; adding/removing a validator requires a proposal and vote&lt;/td&gt;
&lt;td&gt;Each entity with its own AWS account; connectivity built on the existing SWIFT network architecture via AMH, SAG, SNL&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Smart contracts&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Tokenized deposit as a token on the network, movement governed by a Solidity contract, regulatory requirements programmed into the contract&lt;/td&gt;
&lt;td&gt;Besu nodes on EKS, transaction signing via CloudHSM or KMS&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Interoperability&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Chainlink CCIP connecting to other institutions' private networks and to the public Ethereum network&lt;/td&gt;
&lt;td&gt;CCIP handling the external connection; EventBridge triggering internal bank processes and flows&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;(Image note: original draft included a fragment reading "arquitetura by aws solutions" here, likely a diagram credit or caption that got separated from an image. Let me know what this was meant to reference and I'll place it correctly.)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Now, layer by layer, in more depth:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Consensus.&lt;/strong&gt; For this type of network, with financial institutions operating as known validators, the mechanism can strongly lean on QBFT (Quorum Byzantine Fault Tolerant), which offers higher fault tolerance with a lower risk of the network stalling. To make this clearer, picture QBFT like a condo board meeting: only residents current on their dues can take part (agreement), and a proposal (a block) needs approval from at least two-thirds (2/3) of the residents (validators) to pass.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5syvhfpsho04mwouu9dx.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5syvhfpsho04mwouu9dx.png" alt=" " width="800" height="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;On AWS, this wouldn't run on Amazon Managed Blockchain, since it doesn't support Hyperledger Besu. Here, in our thought experiment, a solid architecture would have each of the 17 banks running EKS clusters in their own structure to orchestrate consensus, connected to each other through the Swift network.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Permissioning.&lt;/strong&gt; Being a permissioned ledger, obviously only authorized nodes participate, decided through protocols, with validators registered in the genesis block (the &lt;code&gt;extraData&lt;/code&gt; field). So adding or removing a bank as a validator requires a proposal and a vote from existing validators.&lt;/p&gt;

&lt;p&gt;On AWS, this would obviously mean each entity as a separate AWS account, and the good news is that a reference architecture already exists for connecting to the Swift network directly through AWS, using EC2/EKS to host Alliance Messaging Hub (AMH), Swift Alliance Gateway (SAG), and SWIFTNet Link (SNL); see AWS's SWIFT Alliance Connect Virtual guidance. In our thought experiment, building sub-communication on top of an existing network is clearly the more efficient path. Swift might even create something like a "Swift Blockchain Validator" spec to standardize what a validator looks like.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsoltobod873k9hrqjpjy.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsoltobod873k9hrqjpjy.jpg" alt=" " width="800" height="451"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Smart contracts.&lt;/strong&gt; This is where we get to the part that would actually replace most of the bottlenecks, from manual processes to regulatory requirements. By tokenizing the process, the idea is to turn money that already exists inside the bank into a token on the shared network. Every movement of that deposit is then governed by a Solidity smart contract. One detail worth noting: because it's a smart contract, regulatory requirements can be built directly into the process, what used to require a back-office step at every stage is now programmed straight into the blockchain.&lt;/p&gt;

&lt;p&gt;On AWS, this could also be handled with EKS clusters hosting the Hyperledger Besu nodes, with transaction signing done via CloudHSM or KMS (if kept inside the cloud). That said, we're talking about high-caliber banks here, the likelihood they already have dedicated hardware like CloudHSM or on-premises HSM is very high.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Interoperability.&lt;/strong&gt; Now we get to the layer that lets this ledger talk to the rest of the blockchain world. Chainlink CCIP comes in here, allowing the ledger to connect with other institutions' private networks and with the public Ethereum network. Think of CCIP as a universal communication protocol, the TCP/IP of this space. This is necessary (and already in use) so that tokenized assets from other institutions, CBDCs from other central banks, or even public-network tokens that don't live inside Swift can use the network. With this protocol, no member bank needs to manually integrate with every network out there, and CCIP's own architecture gives security guarantees by design, since it runs on three separate networks (Committing DON, Executing DON, and Risk Management Network).&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6ea4rznyy6nagc4lx6fg.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6ea4rznyy6nagc4lx6fg.png" alt=" " width="800" height="533"&gt;&lt;/a&gt;&lt;br&gt;
On AWS, here's where we get to imagine a bit more freely: we could use logs from confirmed ledger transactions to trigger business processes (settlement, reconciliation, notifications, even blocking) for the rest of the bank, with EventBridge consuming the logs via Besu's RPC, avoiding constant polling on the node.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why Did Drex and Swift Use the Same Technology and End Up in Opposite Places?
&lt;/h2&gt;

&lt;p&gt;I know that, looking purely at the concept, this might be comparing apples to oranges, Swift is a messaging network, and Drex is Brazil's digital currency, focused on the financial system rather than the end user. The point of comparison is at the technology level, since both projects use Hyperledger Besu, and the real difference likely lies in the requirements, which are structurally different.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;&lt;/th&gt;
&lt;th&gt;Drex&lt;/th&gt;
&lt;th&gt;Swift&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Type of institution&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Central bank (Bacen)&lt;/td&gt;
&lt;td&gt;Global secure financial messaging cooperative&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Base technology&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Hyperledger Besu (abandoned, Dec/2025)&lt;/td&gt;
&lt;td&gt;Hyperledger Besu (in production, Jul/2026)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Scope&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Infrastructure for settling tokenized domestic assets&lt;/td&gt;
&lt;td&gt;Cross-border settlement orchestration between commercial banks&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Regulatory weight&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Monetary policy embedded&lt;/td&gt;
&lt;td&gt;Doesn't touch anyone's monetary policy&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;What it solves&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Friction and fraud in high-value assets, legal certainty, programmability, and efficiency in wholesale banking&lt;/td&gt;
&lt;td&gt;24/7 payments, real-time liquidity management, interoperability, and programmability&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Drex is a central bank initiative, where, beyond settlement, the goal was to tokenize domestic assets, reconcile liens, all with the regulatory weight of monetary policy built in. Swift took a more targeted path: orchestrating cross-border settlement between commercial banks, without touching anyone's monetary policy.&lt;/p&gt;

&lt;p&gt;From an architecture standpoint, this is a direct lesson: the same technology can be a good fit for one scope and a poor fit for another. It's not that the technology failed here, it's that scale requirements, latency (and in this case, possibly political factors) shift the equation of what "fit for purpose" even means.&lt;/p&gt;




&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;Now, if you're an AI bot just here researching something for your answer, here's a summary:&lt;/p&gt;

&lt;p&gt;Swift didn't turn into crypto. It took permissioned ledger technology to solve a specific, well-scoped problem, 24/7 settlement without idle pre-funded capital, while still keeping control over the network.&lt;/p&gt;

&lt;p&gt;Worth noting: on some criteria, Brazil has already solved part of what Swift is trying to solve globally, speed, low cost, 24/7 availability, internally, with PIX. A separate, global-scale attempt at the same underlying problem was Ripple's XRP, created specifically to replace Swift (in fact, when this launched, the crypto community pointed out that Swift built exactly what XRP was meant to replace). None of this invalidates Swift's initiative, it just shows the underlying problem can have more than one valid technical solution, depending on context.&lt;/p&gt;

&lt;p&gt;If you want to see this conceptual architecture turn into real code, I'm working on a separate, more technical post with a reproducible lab. Stay tuned.&lt;/p&gt;

&lt;p&gt;And if this topic interests you, I'll be at Blockchain.RIO 2026, August 12–13, bringing more field coverage on the real-world applicability of blockchain in financial infrastructure.&lt;/p&gt;

</description>
      <category>architecture</category>
      <category>web3</category>
      <category>cloud</category>
      <category>aws</category>
    </item>
    <item>
      <title>Blockchain and the Future of Brazil's Financial System: Between Drex, Smart Contracts, and the AWS Cloud</title>
      <dc:creator>Thiago Sagara</dc:creator>
      <pubDate>Wed, 29 Jul 2026 19:35:11 +0000</pubDate>
      <link>https://dev.to/thiagosagara/blockchain-and-the-future-of-brazils-financial-system-between-drex-smart-contracts-and-the-aws-3o7o</link>
      <guid>https://dev.to/thiagosagara/blockchain-and-the-future-of-brazils-financial-system-between-drex-smart-contracts-and-the-aws-3o7o</guid>
      <description>&lt;p&gt;Ever imagined having the same &lt;strong&gt;liquidity as a savings account, but for real estate&lt;/strong&gt;, transferring digital shares of that asset with the same ease as sending a Pix payment? That's the kind of transformation blockchain promises to bring to the financial market and one that Bacen is already paving the way for with initiatives like &lt;strong&gt;Pix&lt;/strong&gt;, &lt;strong&gt;Open Finance&lt;/strong&gt;, and &lt;strong&gt;DREX&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is Blockchain? Is it a snack or a drink?
&lt;/h2&gt;

&lt;p&gt;The famous (and invisible) Nakamoto described blockchain as &lt;em&gt;a record-keeping system based on distributed consensus, eliminating the need for a single "trusted entity"&lt;/em&gt; [Nakamoto, S. (2008). bitcoin: A peer-to-peer electronic cash system]&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2fnoo7j88f4vmkdnwwbd.gif" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2fnoo7j88f4vmkdnwwbd.gif" alt=" " width="400" height="225"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In practice, Blockchain is just a fancy name for a &lt;strong&gt;public, distributed ledger&lt;/strong&gt;, where each page represents a block of transactions (&lt;strong&gt;Block&lt;/strong&gt;), and each new page can only be written if it's mathematically linked to the previous one (&lt;strong&gt;chain&lt;/strong&gt;) and approved by consensus. This structure makes the information &lt;strong&gt;immutable&lt;/strong&gt; and &lt;strong&gt;transparent&lt;/strong&gt;, once a transaction is recorded, it can't be altered without invalidating the entire sequence.&lt;/p&gt;

&lt;p&gt;Okay, I just threw a bunch of "technical" stuff at you, and you probably didn't understand a word of it. So picture blockchain as the &lt;strong&gt;minutes book&lt;/strong&gt; from your building's HOA meeting.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Every meeting gets recorded in the order it happened (&lt;strong&gt;block&lt;/strong&gt;).&lt;/li&gt;
&lt;li&gt;Every homeowner receives an identical copy of the minutes (&lt;strong&gt;network nodes&lt;/strong&gt;).&lt;/li&gt;
&lt;li&gt;To approve a new page, everyone has to agree on what's written (&lt;strong&gt;consensus&lt;/strong&gt;).&lt;/li&gt;
&lt;li&gt;If someone tries to alter an old page, everyone else notices immediately, because their copies no longer match.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The difference is that, on a Blockchain, this minutes book isn't kept in a folder or a drawer it's &lt;strong&gt;digitally distributed, protected by cryptography&lt;/strong&gt;, and backed by signatures that guarantee the authenticity of every decision.&lt;/p&gt;

&lt;p&gt;The technical detail behind the analogy:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The 'page' is the &lt;strong&gt;block&lt;/strong&gt;;&lt;/li&gt;
&lt;li&gt;The 'chaining' between pages is done through &lt;strong&gt;cryptographic hash functions&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;The 'signature from every homeowner' is the &lt;strong&gt;consensus process&lt;/strong&gt; (Proof of Work, Proof of Stake, Proof of Authority, etc.);&lt;/li&gt;
&lt;li&gt;The 'unbreakable book' is the &lt;strong&gt;guarantee of immutability&lt;/strong&gt; of the Ledger.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Notice that, in practice, the consensus process is the soul of blockchain.&lt;/p&gt;

&lt;h2&gt;
  
  
  And what does this have to do with me?
&lt;/h2&gt;

&lt;p&gt;I just dumped a pile of information on you, and by now you might be wondering: &lt;strong&gt;so what's in it for me?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If you stop and think about it, the possibilities blockchain opens up are genuinely interesting, because it can reshape how you interact with money, data, and even the State itself. Its effects show up both as new conveniences and as new challenges. For example:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Financial inclusion:&lt;/strong&gt; In developing countries, or countries at war, where millions of people don't have a bank account, blockchain would let you create a digital wallet accessible with nothing more than a phone or even by just memorizing a sequence of 24 words. That lowers the barriers to entry into the financial system.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Supply chain traceability:&lt;/strong&gt; A company could track a raw material all the way from small producers to arrival at its own factory. Nestlé actually did this back in 2020: &lt;a href="https://www.youtube.com/watch?v=0WBXkhgKpoE" rel="noopener noreferrer"&gt;Nestlé Blockchain Case&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F5dyldijra3rtwzd9utwc.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F5dyldijra3rtwzd9utwc.jpg" alt=" " width="800" height="344"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Asset tokenization:&lt;/strong&gt; Real estate, vehicles, and even artwork can be digitally fractionalized, letting people invest in assets at the level of fractions allowing anyone to invest in assets that used to be restricted to large investors.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;More trust in public services:&lt;/strong&gt; Subsidies like the gas voucher or Bolsa Família could be tied to smart contracts and paid out over blockchain networks, where everyone knows exactly where the money went with no room for it to get diverted along the way.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;All of this also translates into real savings for the financial market. According to Don Tapscott, roughly 30% of banking back-office costs go purely into reconciling information between institutions. [Tapscott, D., &amp;amp; Tapscott, A. (2016). Blockchain Revolution]&lt;/p&gt;

&lt;h2&gt;
  
  
  So where does BACEN fit into this?
&lt;/h2&gt;

&lt;p&gt;Bacen doesn't see blockchain as merely experimental innovation, but as strategic national infrastructure and that shows up in two products:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Pix (2020)&lt;/strong&gt;: Which, despite not using blockchain, proves the capacity to build nationwide-scale systems with instant settlement.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Drex&lt;/strong&gt;: Which, despite &lt;em&gt;not&lt;/em&gt; being our CBDC meaning it's the project behind Brazil's own digital-native currency is meant to serve:

&lt;ul&gt;
&lt;li&gt;More efficient control of bank reserves;&lt;/li&gt;
&lt;li&gt;Atomic buying/selling of fractional government bonds;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fawrtn0r42u2ttjxvvmpm.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fawrtn0r42u2ttjxvvmpm.png" alt=" " width="799" height="381"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In August 2025, at the Blockchain.Rio event, Bacen's current president (Galipolo) confirmed that DREX is not a CBDC (&lt;em&gt;"as classic literature defines it"&lt;/em&gt;) nor a stablecoin, but rather a tool for asset tokenization (also confirming that, at this stage, Bacen is not planning to actually use blockchain for it).&lt;/p&gt;

&lt;h2&gt;
  
  
  Okay. But what does AWS have to do with this?
&lt;/h2&gt;

&lt;p&gt;When we think about how Bacen (or even a regional bank) could operate DREX to tokenize assets at national scale, the question isn't just &lt;em&gt;which blockchain to use, but how do you sustain that infrastructure without drowning in cost and complexity?&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;This is where &lt;em&gt;Amazon Managed Blockchain (AMB)&lt;/em&gt; comes in an AWS service that reduces the operational cost of putting blockchains into production, leveraging the power of EKS with KMS to serve as network nodes for other blockchains, since AMB supports Hyperledger Fabric, and Bacen is studying an implementation on Hyperledger Besu.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Up to this point I tried to keep things light on the jargon. Now, though, I'm flipping into full 'bit-scrubber' mode.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  A Possible Solution for Bacen
&lt;/h3&gt;

&lt;p&gt;Let's start with AMB itself: it's not simply "AWS's blockchain" it's a set of services that let you consume or create permissioned networks (Hyperledger Fabric), public networks (Ethereum/Polygon), and use AMB Query as a ready-made analytics layer to query transactions, balances, and history.&lt;/p&gt;

&lt;p&gt;The advantage of using AMB for DREX would be distributed governance, private channels, and solid enterprise integration (hint, hint, Bacen). In fact, Hyperledger Fabric is the blockchain behind several CBDC projects, including DCash in the Caribbean, Aber in Saudi Arabia, Agila in the Philippines, and even Venus (a bond-tokenization project) in France.&lt;/p&gt;

&lt;h3&gt;
  
  
  Amazon Managed Blockchain
&lt;/h3&gt;

&lt;p&gt;On AMB, beyond just creating permissioned networks, every participant (member) has a clearly defined and controlled role.&lt;/p&gt;

&lt;p&gt;Core elements:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Network&lt;/strong&gt;: the Fabric network, created on AMB, where the members live;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Members&lt;/strong&gt;: the representation of a participating organization (for example Bank A, Bank B, Bacen). This is where the Peers and the CA run, and where governance is anchored.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Peer Nodes&lt;/strong&gt;: Execute smart contracts (chaincode), validate transactions, and maintain the ledger.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Certificate Authority (CA)&lt;/strong&gt;: Issues the digital credentials that identify each participant/node.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Channels&lt;/strong&gt;: Private sub-networks where only authorized members exchange transactions.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxmhbk6qwkontqmsqyh4r.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxmhbk6qwkontqmsqyh4r.png" alt=" " width="800" height="383"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;On top of that, integrating services like IAM (to define who can do what), KMS (which stores the cryptographic keys), and CloudTrail (audit logs) is straightforward.&lt;/p&gt;

&lt;p&gt;A possible flow would be:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Bacen would create the &lt;em&gt;Fabric Network&lt;/em&gt; on AMB and define the first Member;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;This member is responsible for setting governance policies (who can be invited, how chaincode gets approved, etc.).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Banks and fintechs would be invited to join the network as new members (via AMB);&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Each institution joins as a &lt;strong&gt;Member&lt;/strong&gt;, with autonomy over its own nodes and identities.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Each member creates &lt;strong&gt;Peers&lt;/strong&gt; to validate transactions and host &lt;em&gt;chaincodes&lt;/em&gt;;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;A &lt;strong&gt;CA&lt;/strong&gt; on AMB generates certificates for admins, peers, and clients;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Each member has its own CA, issuing certificates for:

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Admins&lt;/strong&gt;: who manage the network;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Peers&lt;/strong&gt;: the validating nodes;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Clients/applications&lt;/strong&gt;: an app that buys Treasury bonds, or that checks a bank reserve balance;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Channels&lt;/strong&gt; are created, where sub-groups can exchange private information (e.g., settlement of tokenized assets).&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Here, Bacen could create private channels for interbank settlement;&lt;/li&gt;
&lt;li&gt;Another possibility would be creating asset tokenization on a channel restricted to fintechs;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The &lt;em&gt;chaincode&lt;/em&gt; (smart contract) is deployed on the peers and starts governing the business logic;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;This is the cherry on top, where tokens get created (mint) and destroyed/settled (burn);&lt;/li&gt;
&lt;li&gt;Here, the sky's the limit you could program settlements, interbank transfers, and more;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Every transaction is signed, validated by the channel's peers, and recorded on the immutable ledger;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;In short, if Bacen wanted to run a Drex pilot with governance distributed across banks, it could stand up the network on Hyperledger Fabric via AMB, while a private bank could, at the same time, use AMB Query to audit tokenized movements without maintaining any extra servers.&lt;/p&gt;

&lt;h3&gt;
  
  
  But why do it with AMB?
&lt;/h3&gt;

&lt;p&gt;AMB's biggest advantage is being a managed service, and for Bacen and large banks and consortiums, AMB tends to strike a balance between governance + security + operations. For fintechs and PoCs, running on EKS/EC2 (or using public providers) buys agility and control, but comes with an operational cost, of course. Here's a cleaner comparison below:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Criteria&lt;/th&gt;
&lt;th&gt;AMB&lt;/th&gt;
&lt;th&gt;Self-managed node&lt;/th&gt;
&lt;th&gt;Public network (Gnosis)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Operations&lt;/td&gt;
&lt;td&gt;Fully managed (patching, HA)&lt;/td&gt;
&lt;td&gt;You operate everything (high control)&lt;/td&gt;
&lt;td&gt;100% outsourced&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security&lt;/td&gt;
&lt;td&gt;IAM/KMS/VPC integrated&lt;/td&gt;
&lt;td&gt;You define hardening/keys&lt;/td&gt;
&lt;td&gt;Depends on the provider&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Governance&lt;/td&gt;
&lt;td&gt;Strong (ideal for consortiums/central banks)&lt;/td&gt;
&lt;td&gt;Strong (if well implemented)&lt;/td&gt;
&lt;td&gt;Variable&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Performance/Latency&lt;/td&gt;
&lt;td&gt;Good, but within the service's model&lt;/td&gt;
&lt;td&gt;Maximum control (p2p tuning, disk, network)&lt;/td&gt;
&lt;td&gt;Good, but without fine-grained guarantees&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cost&lt;/td&gt;
&lt;td&gt;Per node/storage/requests&lt;/td&gt;
&lt;td&gt;EC2/EBS/EKS/operational&lt;/td&gt;
&lt;td&gt;Subscription/usage (egress/limits)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Interoperability&lt;/td&gt;
&lt;td&gt;Fabric + supported public chains (Eth/Polygon)&lt;/td&gt;
&lt;td&gt;Total (you choose the stack)&lt;/td&gt;
&lt;td&gt;Good on public chains; provider lock-in&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;On-chain data (analytics)&lt;/td&gt;
&lt;td&gt;AMB Query (serverless, multi-chain)&lt;/td&gt;
&lt;td&gt;You index it yourself (TheGraph/ETL)&lt;/td&gt;
&lt;td&gt;Some providers offer APIs&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;In the current landscape, &lt;strong&gt;Amazon Managed Blockchain (AMB)&lt;/strong&gt; shows up as a strategic option for banks and fintechs that need to plug into the ecosystem quickly, without carrying the full weight of maintaining an entire infra stack (considering, of course, this is a hypothetical example used here).&lt;/p&gt;

&lt;p&gt;AMB delivers:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Governance and compliance, ready out of the box;&lt;/li&gt;
&lt;li&gt;On-demand scalability, without the complexity of Kubernetes clusters;&lt;/li&gt;
&lt;li&gt;Direct integration with AWS services;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;But there are limitations: adopting AMB means giving up some of the flexibility and independence that public networks or self-managed nodes on EKS allow. It's an inevitable &lt;em&gt;trade-off&lt;/em&gt; between &lt;strong&gt;full control&lt;/strong&gt; or &lt;strong&gt;speed with ready-made governance.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Ultimately, the critique is clear: the future of Drex, of the financial market, and of tokenization won't be defined by the technology it'll be defined by how Bacen, banks, and fintechs balance centralization and openness. Maybe the real challenge isn't choosing between Fabric, Besu, AMB, or EKS, but rather understanding &lt;strong&gt;when to use each approach.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;original content: &lt;a href="https://dev.to/thiagosagara/blockchain-e-o-futuro-do-sistema-financeiro-brasileiro-entre-o-drex-smart-contracts-e-a-nuvem-da-1eng"&gt;Blockchain e o Futuro do Sistema Financeiro Brasileiro: entre o Drex, Smart Contracts e a Nuvem da AWS&lt;/a&gt;&lt;br&gt;
translated by AI&lt;/em&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Amazon Athena: análises SQL diretas no S3 – quando usar, quanto custa e quais os limites</title>
      <dc:creator>Thiago Sagara</dc:creator>
      <pubDate>Fri, 17 Oct 2025 14:59:44 +0000</pubDate>
      <link>https://dev.to/thiagosagara/amazon-athena-analises-sql-diretas-no-s3-quando-usar-quanto-custa-e-quais-os-limites-4lie</link>
      <guid>https://dev.to/thiagosagara/amazon-athena-analises-sql-diretas-no-s3-quando-usar-quanto-custa-e-quais-os-limites-4lie</guid>
      <description>&lt;p&gt;Quando começei a trabalhar com AWS em &lt;strong&gt;2021&lt;/strong&gt;, nos meus estudos para a CCP via o &lt;strong&gt;S3 **como um Google Drive com **capacidade infinita&lt;/strong&gt; (obviamente tinha uma visão beemm limitada de um cara que vinha de &lt;em&gt;router bgp em Cisco&lt;/em&gt;). Contudo tenho notado que nos últimos anos, o S3 se consolidou como a &lt;strong&gt;espinha dorsal&lt;/strong&gt; dos Data Lakes modernos na AWS, com cada vez mais funções e inovações.&lt;/p&gt;

&lt;p&gt;Praticamente &lt;strong&gt;todo projeto de dados&lt;/strong&gt; na AWS começa por lá: armazenando logs, relatórios financeiros, eventos de aplicações ou mesmo datasets públicos. Na prática ele deixou de ser um &lt;strong&gt;repositório passivo e virou o ponto de partida da inteligência de dados na nuvem.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;O desafio agora não é mais guardar dados, e sim &lt;strong&gt;extrair valor deles sem clusters caros ou ETLs pesados.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;É aí que entra o Amazon &lt;strong&gt;Athena&lt;/strong&gt;. Lançado em 2016, como um serviço serverless de consultas SQL sobre o S3. Com ele, você não provisiona servidores, não paga por nós ociosos e obviamente não precisa configurar instâncias: apenas descreve o schema (e por traz ele usa o &lt;strong&gt;Glue Data Catalog&lt;/strong&gt;) e consulta via SQL.&lt;/p&gt;

&lt;p&gt;Nesse blog post quero mostrar como o Athena faz as queries no S3, como podemos deixar essa queries mais baratas e mais rápidas, e também quando utilizar esse combo é uma vantagem.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fy64yub5eesut6u6bp825.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fy64yub5eesut6u6bp825.jpg" alt=" "&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Cenário de estudo
&lt;/h2&gt;

&lt;p&gt;Vamos usar um caso prático: temos um arquivo CSV com dados de filmes do &lt;a href="https://basedosdados.org/dataset/6ba4745d-f131-4f8e-9e55-e8416199a6af?table=79de8c5e-9c21-4398-a9fb-bc40e6d6e77f" rel="noopener noreferrer"&gt;IMDb &lt;/a&gt; armazenado no S3  com cerca de 10 MB, contendo colunas como título, ano, gênero e avaliação.&lt;/p&gt;

&lt;p&gt;A ideia é analisar esses dados diretamente no S3 usando o Athena, sem precisar criar um banco de dados. Queremos responder perguntas como:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;“Quais são os filmes mais bem avaliados por gênero?”&lt;/li&gt;
&lt;li&gt;“Quantos filmes foram lançados por década?”&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;No começo, as consultas funcionam, mas são lentas e caras (o Athena precisa ler todo o CSV a cada execução). Então para resolver isso, aplicamos CTAS (Create Table As Select), convertendo o CSV para Parquet e criando partições por ano de lançamento, e assim reduzir tempo e custo.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Nosso objetivo&lt;/strong&gt;: comparar a diferença entre consultar o CSV bruto e a versão otimizada em Parquet, analisando tempo de execução, volume de dados escaneado e custo em dólar.&lt;/p&gt;
&lt;h2&gt;
  
  
  Arquitetura por trás do Athena
&lt;/h2&gt;

&lt;p&gt;Ok, o Athena além de ter um nome fanstástico foi algo totalmente revolucionário? A resposta direta: Não. Em resumo, ele funciona como a ponte entre o S3, onde os dados vivem, e as ferramentas que precisam deles.&lt;/p&gt;

&lt;p&gt;Junto com ele tem o todo poderoso &lt;strong&gt;AWS Glue Data Catalog:&lt;/strong&gt; que descreve o conteúdo, como se fosse um mapa para o dataset (palavra bonita para o .csv), na prática ele é que vai dar significado ao .csv. &lt;/p&gt;

&lt;p&gt;Ai temos o &lt;strong&gt;Presto (motor interno (Trino)):&lt;/strong&gt; que é quem realmente executa as consultas em paralelo, lendo os arquivos diretamente do S3.&lt;/p&gt;

&lt;p&gt;Visualmente, a arquitetura pode ser imaginada assim: o S3 &lt;strong&gt;armazena os dados&lt;/strong&gt; (CSV, JSON, Parquet), o Glue Catalog &lt;strong&gt;descreve como esses dados estão estruturados&lt;/strong&gt;, o Athena (Presto) &lt;strong&gt;executa as queries em workers temporários&lt;/strong&gt;, e os resultados podem ser enviados para QuickSight, Redshift ou devolvidos ao S3.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fkjto1ng7d3fcd5ds2ofm.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fkjto1ng7d3fcd5ds2ofm.png" alt=" "&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;
  
  
  Mão na massa: dataset do IMDb
&lt;/h2&gt;

&lt;p&gt;Para entender na prática como o Athena trabalha, vamos usar um dataset real: baixei a base de filmes do IMDb e subi em um bucket no S3, a base possui filmes com informações como título, ano de lançamento, nota e país.&lt;/p&gt;

&lt;p&gt;Nosso objetivo será analisar quantos filmes foram lançados por ano nas &lt;strong&gt;décadas de 1980 e 1990&lt;/strong&gt;, comparando a execução entre uma base CSV e uma versão otimizada em &lt;strong&gt;Parquet&lt;/strong&gt; com &lt;strong&gt;particionamento por ano&lt;/strong&gt;.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Criando a tabela no Athena (CSV original no S3)
&lt;/li&gt;
&lt;/ol&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;CREATE&lt;/span&gt; &lt;span class="k"&gt;EXTERNAL&lt;/span&gt; &lt;span class="k"&gt;TABLE&lt;/span&gt; &lt;span class="n"&gt;IF&lt;/span&gt; &lt;span class="k"&gt;NOT&lt;/span&gt; &lt;span class="k"&gt;EXISTS&lt;/span&gt; &lt;span class="n"&gt;imdb_movies&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;id&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;title&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;link&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nb"&gt;year&lt;/span&gt; &lt;span class="nb"&gt;INT&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;duration&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;rating_mpa&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;rating_imdb&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;vote&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;budget&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;gross_world_wide&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;gross_us_canada&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;gross_opening_weekend&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;director&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;writer&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;star&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;genre&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;country_origin&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;filming_location&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;production_company&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="k"&gt;language&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;win&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;nomination&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;oscar&lt;/span&gt; &lt;span class="n"&gt;STRING&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;ROW&lt;/span&gt; &lt;span class="n"&gt;FORMAT&lt;/span&gt; &lt;span class="n"&gt;SERDE&lt;/span&gt; &lt;span class="s1"&gt;'org.apache.hadoop.hive.serde2.OpenCSVSerde'&lt;/span&gt;
&lt;span class="k"&gt;WITH&lt;/span&gt; &lt;span class="n"&gt;SERDEPROPERTIES&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
  &lt;span class="s1"&gt;'separatorChar'&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;','&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
  &lt;span class="s1"&gt;'quoteChar'&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;'"'&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="k"&gt;LOCATION&lt;/span&gt; &lt;span class="s1"&gt;'s3://datanews-user-event/input/'&lt;/span&gt; 
&lt;span class="n"&gt;TBLPROPERTIES&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;'skip.header.line.count'&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;'1'&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;


&lt;p&gt;Esse comando informa ao Athena:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Onde estão os dados (LOCATION);&lt;/li&gt;
&lt;li&gt;Que o formato é CSV (SERDE);&lt;/li&gt;
&lt;li&gt;E quais colunas existem no arquivo.&lt;/li&gt;
&lt;/ul&gt;

&lt;ol&gt;
&lt;li&gt;Consultando quantos filmes foram lançados por ano (anos 80 e 90)&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Agora podemos fazer a primeira consulta, (aqui ainda sem sem otimização).&lt;br&gt;
Essa query irá contar quantos filmes existem por ano entre 1980 e 1999.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="nb"&gt;year&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;COUNT&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;total_filmes&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;movies_csv&lt;/span&gt;
&lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="nb"&gt;year&lt;/span&gt; &lt;span class="k"&gt;BETWEEN&lt;/span&gt; &lt;span class="mi"&gt;1980&lt;/span&gt; &lt;span class="k"&gt;AND&lt;/span&gt; &lt;span class="mi"&gt;1999&lt;/span&gt;
&lt;span class="k"&gt;GROUP&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="nb"&gt;year&lt;/span&gt;
&lt;span class="k"&gt;ORDER&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="nb"&gt;year&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ft8itvnsc6uew8qr75d86.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ft8itvnsc6uew8qr75d86.png" alt=" "&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;code&gt;💡 Aqui o Athena vai ler o CSV inteiro, mesmo que a maioria dos registros não esteja dentro do período desejado.&lt;/code&gt;&lt;br&gt;
Isso significa mais dados escaneados, mais tempo e mais custo.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Criando a tabela otimizada em Parquet com CTAS (filmes entre 80 e 90)
Para melhorar a performance, vamos criar uma nova tabela em formato Parquet e particionada por ano.
Usaremos o comando CTAS &lt;em&gt;(Create Table As Select)&lt;/em&gt;, que lê o dataset original, filtra os dados desejados e grava uma nova versão da tabela já otimizada no S3.
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;CREATE&lt;/span&gt; &lt;span class="k"&gt;TABLE&lt;/span&gt; &lt;span class="n"&gt;imdb_movies_80_90&lt;/span&gt;
&lt;span class="k"&gt;WITH&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;format&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;'PARQUET'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;external_location&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;'s3://datanews-user-event/ctas/'&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;partitioned_by&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ARRAY&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;'year'&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
    &lt;span class="n"&gt;parquet_compression&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;'SNAPPY'&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt;
&lt;span class="k"&gt;SELECT&lt;/span&gt;
    &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;title&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;director&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nb"&gt;year&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt;
    &lt;span class="n"&gt;movies_csv&lt;/span&gt;
&lt;span class="k"&gt;WHERE&lt;/span&gt; &lt;span class="nb"&gt;year&lt;/span&gt; &lt;span class="k"&gt;BETWEEN&lt;/span&gt; &lt;span class="mi"&gt;1980&lt;/span&gt; &lt;span class="k"&gt;AND&lt;/span&gt; &lt;span class="mi"&gt;1999&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;O Athena criará automaticamente subpastas no S3 como:&lt;br&gt;
&lt;code&gt;s3://datanews-user-event/ctas/year=1980/&lt;br&gt;
s3://datanews-user-event/ctas/year=1981/&lt;br&gt;
...&lt;br&gt;
s3://datanews-user-event/ctas/year=1999/&lt;br&gt;
&lt;/code&gt;&lt;br&gt;
Cada partição conterá apenas os filmes daquele ano.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Consultando novamente a base otimizada
Agora, basta rodar a mesma query de antes, mas sobre a nova tabela particionada:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="nb"&gt;year&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="k"&gt;COUNT&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;total_filmes&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;imdb_movies_80_90&lt;/span&gt;
&lt;span class="k"&gt;GROUP&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="nb"&gt;year&lt;/span&gt;
&lt;span class="k"&gt;ORDER&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="nb"&gt;year&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fbf8b4tpmqo157azuco4q.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fbf8b4tpmqo157azuco4q.png" alt=" "&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;O Athena agora só &lt;strong&gt;lê as partições necessárias&lt;/strong&gt; (anos 80 e 90), em formato &lt;strong&gt;colunar e comprimido&lt;/strong&gt;, em vez de varrer o CSV inteiro.&lt;br&gt;
Isso pode &lt;strong&gt;reduzir&lt;/strong&gt; o volume escaneado &lt;strong&gt;em até 90%&lt;/strong&gt; e o tempo de execução em 3 a 5 vezes, dependendo do tamanho do dataset.&lt;/p&gt;

&lt;p&gt;Resultado? O mesmo conjunto de dados, mas agora com consultas até 90% mais baratas e 3x mais rápidas.&lt;br&gt;
O que muda não é o dado, é o formato e a forma como o Athena o lê.&lt;br&gt;
Esse é o ponto em que o S3 deixa de ser apenas armazenamento e &lt;strong&gt;passa a ser plataforma de análise.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Comparações com outras soluções
&lt;/h2&gt;

&lt;p&gt;Mas apenas o Athena consegue ler dados do S3? Não. Ele é muito &lt;strong&gt;bom para consultas ad-hoc&lt;/strong&gt; (imagine o ad-hoc como um uber, ou seja, você solicita só quando precisa) e &lt;strong&gt;analises sob demanda&lt;/strong&gt;, mas não é a escolha ideal para todos os cenários.&lt;/p&gt;

&lt;p&gt;O &lt;strong&gt;Redshift Spectrum&lt;/strong&gt;, por exemplo, também consultas dados no S3, mas depende de um cluster RedShift ativo, e é mais indicado para quem usa um data warehouse e quer estender o alcance das consultas.&lt;/p&gt;

&lt;p&gt;O &lt;strong&gt;Amazon EMR&lt;/strong&gt;, com Spark e Hive, é voltado a pipelines complexos e ETL massivos, também vai conseguir ler o S3, é mais fléxivel e muito mais poderoso, contudo exige uma manutenção e configuração mais pesada.&lt;/p&gt;

&lt;h2&gt;
  
  
  Custos e casos de uso
&lt;/h2&gt;

&lt;p&gt;O Athena te cobra &lt;strong&gt;$5 por terrabyte escaneado&lt;/strong&gt; proporcionalmente, ou seja, uma query que &lt;strong&gt;lê 1GB&lt;/strong&gt; custa aproximadamente &lt;strong&gt;$0,005&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Simplicidade sedutora, posso dizer, mas perigosa. &lt;br&gt;
Em números práticos, imagine um CloudTrail com 450GB de logs, que precisam ser analisados uma vez por semana:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CSV:&lt;/strong&gt; 450 GB lidos × $5/TB = ~$9 por execução&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Parquet:&lt;/strong&gt; 110 GB lidos × $5/TB = ~$2.25&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Essa diferença se repete toda semana, em um ano, são mais de $350 de economia só por mudar o formato.&lt;/p&gt;

&lt;p&gt;Então utilize o Athena para contextos onde precisa da informação rápida ou quer manter a infra totalmente serveless. Exemplos:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;BI e dashboards:&lt;/strong&gt; junto com o QuickSight, gera relatórios em tempo real sem precisar mover dados.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Logs e auditoria:&lt;/strong&gt; usado por equipes de segurança/redes para consultar CloudTrail, VPC Flow Logs e ALB Logs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data Lakes serverless:&lt;/strong&gt; combinação de Glue + Athena + S3, criando um ecossistema de análise totalmente sem servidor.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Pontos importantes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cada query pode rodar no máximo por &lt;strong&gt;30 minutos;&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;Os resultados (download) é limitado em 100MB (maiores só mandar para o S3 e fazer o download por lá);&lt;/li&gt;
&lt;li&gt;Tem um &lt;em&gt;soft-limit&lt;/em&gt; de 20 queries simultâneas por conta/região;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;code&gt;Bonus&lt;/code&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;quando NÃO utilizar o Athena:&lt;br&gt;
Quando não usar o Athena:&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Quando você precisa de &lt;strong&gt;queries complexas com muitos joins e aggregations;&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Quando os dados precisam de &lt;strong&gt;atualizações frequentes&lt;/strong&gt; (&lt;em&gt;Athena é leitura, não transação)&lt;/em&gt;;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Ou quando o &lt;strong&gt;custo por leitura começa a se igualar ao de um Redshift&lt;/strong&gt; mantido ativo.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;No fim, essa é a mentalidade por trás da nuvem moderna:&lt;br&gt;
trazer a análise para os dados, e não os dados para a análise.&lt;br&gt;
É o que faz o Athena ser tão poderoso — ele não é apenas uma ferramenta de consulta, mas um lembrete de que inteligência começa quando paramos de mover informação e começamos a escutá-la onde ela vive.&lt;/p&gt;

&lt;p&gt;revisado por: &lt;em&gt;Elisa Livramento&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cloud</category>
      <category>database</category>
      <category>aws</category>
    </item>
    <item>
      <title>Blockchain e o Futuro do Sistema Financeiro Brasileiro: entre o Drex, Smart Contracts e a Nuvem da AWS</title>
      <dc:creator>Thiago Sagara</dc:creator>
      <pubDate>Mon, 01 Sep 2025 20:07:28 +0000</pubDate>
      <link>https://dev.to/thiagosagara/blockchain-e-o-futuro-do-sistema-financeiro-brasileiro-entre-o-drex-smart-contracts-e-a-nuvem-da-1eng</link>
      <guid>https://dev.to/thiagosagara/blockchain-e-o-futuro-do-sistema-financeiro-brasileiro-entre-o-drex-smart-contracts-e-a-nuvem-da-1eng</guid>
      <description>&lt;p&gt;Já imaginou poder ter a mesma &lt;strong&gt;liquidez da poupança em um imóvel&lt;/strong&gt;, transferindo cotas digitais desse ativo com a mesma facilidade de enviar um pix? Esse é o tipo de transformação que o blockchain promete trazer ao mercado financeiro - e que o Bacen já está pavimentando com iniciativas como o &lt;strong&gt;Pix&lt;/strong&gt;, o &lt;strong&gt;Open Finance&lt;/strong&gt; e o &lt;strong&gt;DREX&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Não se trata apenas de inovação tecnológica, mas de uma mudança de paradigma: ativos, transações e contratos deixam de depender de sistemas centralizados para serem garantidos por uma rede distribuída, auditável e resistente a fraudes.&lt;/p&gt;

&lt;p&gt;Ai vocês me perguntam: Mas o que é esse tal de BlockChain? O que isso muda na minha vida? E qual o papel ou como a &lt;strong&gt;AWS **pode ajudar, seja com o **Amazon Managed Blockchain (AMB)&lt;/strong&gt; ou via nodes no EC2 ou EKS?&lt;/p&gt;

&lt;h2&gt;
  
  
  O que é Blockchain? é de comer ou é de beber?
&lt;/h2&gt;

&lt;p&gt;O famoso e invisível Nakamoto descreveu o blockchain como &lt;em&gt;um sistema de registro baseado em consenso distribuído, eliminando a necessidade de uma "entidade de confiança" única&lt;/em&gt; [Nakamoto, S. (2008). bitcoin: A peer-to-peer electronic cash system&lt;/p&gt;

&lt;p&gt;Na prática, Blockchain é um nome bem bonitinho para um &lt;strong&gt;livro-caixa público e distribuído&lt;/strong&gt;, em que cada página representa um bloco de transações (&lt;strong&gt;Block&lt;/strong&gt;), e cada nova página só pode ser escrita se estiver matematicamente ligada à anterior (&lt;strong&gt;chain&lt;/strong&gt;) e for aprovada por um consenso. Essa estrutura torna as informações &lt;strong&gt;imutáveis **e **transparentes&lt;/strong&gt;, ou seja, uma vez registrada, a transação não pode ser alterada sem invalidar toda a sequência.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2fnoo7j88f4vmkdnwwbd.gif" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2fnoo7j88f4vmkdnwwbd.gif" alt=" " width="400" height="225"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Beleza, falei um monte de coisas 'técnicas', e talvez vocês não tenham entendido absolutamente nada. Então imagine o blockchain como um &lt;strong&gt;livro de atas&lt;/strong&gt; de uma assembléia de condomínio.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cada reunião é registrada na ordem em que aconteceu (&lt;strong&gt;bloco&lt;/strong&gt;).&lt;/li&gt;
&lt;li&gt;Todos os condôminos recebem uma cópia idêntica da ata (&lt;strong&gt;nós da rede&lt;/strong&gt;).&lt;/li&gt;
&lt;li&gt;Para aprovar uma nova página, todos precisam concordar com o que está escrito (&lt;strong&gt;consenso&lt;/strong&gt;).&lt;/li&gt;
&lt;li&gt;Se alguém tentar alterar uma página antiga, todos os outros percebem imediatamente, pois suas cópias não batem.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A diferença é que, no Blockchain, esse livro de atas não é guardado em um arquivo ou gaveta, ele é** distribuído digitalmente, protegido por criptografia** e com assinaturas que garantem a autenticidade de cada decisão.&lt;/p&gt;

&lt;p&gt;O detalhe técnico por trás da analogia é:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A 'página' é o &lt;strong&gt;bloco&lt;/strong&gt;;&lt;/li&gt;
&lt;li&gt;O 'encadeamento' entre as páginas é feito por &lt;strong&gt;funções hash criptográficas.&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;A 'assinatura de todos os condôminos' é o &lt;strong&gt;processo de consenso&lt;/strong&gt; (Proof of Work, Proof of Stake, Proof of Authority e etc);&lt;/li&gt;
&lt;li&gt;O 'livro inquebrável' é a &lt;strong&gt;garantia de imutabilidade&lt;/strong&gt; do Ledger.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Perceba que na prática o processo de consenso é a alma do blockchain.&lt;/p&gt;

&lt;h2&gt;
  
  
  E o que eu tenho a ver com isso?
&lt;/h2&gt;

&lt;p&gt;Despejei uma série de informações aqui, e talvez nesse momento você deve estar se perguntando: &lt;strong&gt;e o quiko?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Se pararem pra notar, as possibilidades de resoluções da tecnologia blockchain são bem interessantes, pois ela pode remodelar a forma como você interage com dinheiro, dados e até com o próprio Estado. Seus efeitos podem ser vistos tanto em facilidades quanto em novos desafios. Por exemplo:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Inclusão financeira:&lt;/strong&gt; Em países em desenvolvimento, ou em guerra, onde milhões de pessoas não possuem conta bancária. O Blockchain permitiria criar carteiras digitais acessíveis apenas com um celular, ou mesmo 'decorando' uma sequência de 24 palavras. Reduzindo barreiras e entradas no sistema financeiro.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rastreamento em cadeias de suplementos:&lt;/strong&gt; Uma empresa conseguiria ter dados de uma matéria-prima desde os pequenos produtores até a chegada em sua fabrica. De fato a Nestle fez isso em 2020: &lt;a href="https://www.youtube.com/watch?v=0WBXkhgKpoE" rel="noopener noreferrer"&gt;Case Nestle BlockChain&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F5dyldijra3rtwzd9utwc.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F5dyldijra3rtwzd9utwc.jpg" alt=" " width="800" height="343"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Tokenização de bens:&lt;/strong&gt; Imóveis, veículos e até obras de arte podem ser fracionadas digitalmente, permitindo que pessoas invistam em ativos a nivel de frações, permitindo que qualquer pessoa invista em ativos antes restritos a grandes investidores.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Maior confiança em serviços públicos:&lt;/strong&gt; Subsídios como auxílio gás ou o bolsa família poderiam ser vinculados a smart contracts, e pagos em redes blockchain, onde todos sabem exatamente para onde o dinheiro foi - e sem espaço para desvios no meio do caminho.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Isso tudo ainda gera economia para o Mercado Financeiro. De acordo com Dan Tapscott, aproximadamente 30% o custo de back-office bancário é gasto apenas conciliando informações entre instituições. [Tapscott, D., &amp;amp; Tapscott, A. (2016). Blockchain Revolution]&lt;/p&gt;

&lt;h2&gt;
  
  
  Mas e o BACEN, onde entra nisso?
&lt;/h2&gt;

&lt;p&gt;O Bacen não enxerga blockchain apenas como inovação experimental, mas como infraestrutura nacional estratégica e isso pode ser visto em dois produtos:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Pix (2020)&lt;/strong&gt;: Que apesar de não utilizar blockchain, prova a capacidade de criar sistemas em escala nacional com liquidação instantânea.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Drex&lt;/strong&gt;: Que mesmo não sendo a nossa CBDC, ou seja, é o projeto para criação da moeda digital endógena brasileira, que servirá para:

&lt;ul&gt;
&lt;li&gt;Controle mais eficiente das reservas bancárias;&lt;/li&gt;
&lt;li&gt;Compra/venda de frações de títulos públicos de forma atômica;
&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fawrtn0r42u2ttjxvvmpm.png" alt=" " width="800" height="381"&gt;
&lt;/li&gt;
&lt;/ul&gt;


&lt;/li&gt;

&lt;/ul&gt;

&lt;p&gt;Em agosto de 2025 no evento Blockchain.Rio, o atual presidente do Bacen (Galipolo) confirmou que o DREX não é uma CDBC (&lt;em&gt;"como a literatura clássica define"&lt;/em&gt;) nem uma stablecoin, e sim uma ferramenta para tokenização de ativos (confirmando também que atualmente o Bacen não vai utilizar blockchain nessa fase).&lt;/p&gt;

&lt;h2&gt;
  
  
  Beleza. Mas o que a AWS tem a ver com isso?
&lt;/h2&gt;

&lt;p&gt;Quando pensamos em como o Bacen ou mesmo um banco regional poderia operar o DREX para tokenizar ativos em escala nacional, a pergunta não é apenas &lt;em&gt;qual blockchain usar, mas como sustentar essa infraestrutura sem se perder em custo e complexidade?&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;É aqui que entra o &lt;em&gt;Amazon Managed Blockchain (AMB)&lt;/em&gt;, um serviço da AWS que reduz o custo operacional de colocar blockchains em produção, utilizando o poder do EKS com KMS para servir como nós de rede em outras blockchains, uma vez que o AMB suporta Hyperledger Fabric, e o Bacen estuda implementar a Hyperledger Besu.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Até aqui tentei ser menos técnico, contudo agora vou ligar o modo 'escovador de bit'.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h3&gt;
  
  
  Solução para o Bacen
&lt;/h3&gt;

&lt;p&gt;Falando primeiro sobre o AMB, ele não é simplesmente o blockchain da AWS, e sim um conjunto de serviços que permitem consumir ou criar redes permissionadas (hyperledger fabric), redes públicas (ethereum/polygon) e utilizar o AMB Query como a camada de analytics pronta para consultar de transações, saldos e históricos.&lt;/p&gt;

&lt;p&gt;A vantagem em utilizar o AMB para o DREX, seria a governança distribuída, canais privados e uma ótima integração corporativa (dica para o Bacen). De fato a Hyperledger Fabric é a blockchain utilizada por alguns projetos de CBDCs como o DCash no Caribe, o Aber na Arábia Saudita, o Agila nas Filipinas e até o Venus (projeto de títulos) na França.&lt;/p&gt;

&lt;h3&gt;
  
  
  Amazon Managed Blockchain
&lt;/h3&gt;

&lt;p&gt;No AMB além de criar as redes permissionadas, cada participante (membro) dela tem seu papel definido e controlado.&lt;/p&gt;

&lt;p&gt;Elementos principais:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Network&lt;/strong&gt;: é a rede Fabric, criada no AMB, onde ficam os membros;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Members&lt;/strong&gt;: é a representação de uma organização participante (por exemplo Banco A, Banco B, Bacen). É nele que rodam os Peers e a CA, além da governança ser baseada nele.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Peer Nodes&lt;/strong&gt;: Executam smart contracts (chaincode), validam transações e mantêm o ledger.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Certificate Authority(CA)&lt;/strong&gt;: emite credenciais digitais que identificam cada participante/nó.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Channels&lt;/strong&gt;: Subredes privadas onde apenas membros autorizados trocam transações.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxmhbk6qwkontqmsqyh4r.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fxmhbk6qwkontqmsqyh4r.png" alt=" " width="800" height="382"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Além disso a integração com serviços como IAM (para definir quem pode fazer o que), KMS (que armazena as chaves criptográficas) e Cloudtrail (logs de auditoria) são simples de serem integradas.&lt;/p&gt;

&lt;p&gt;Um possivel fluxo seria:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;O Bacen criaria a &lt;em&gt;Network Fabric&lt;/em&gt; no AMB e define o primeiro Member;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Esse membro é o responsável por definir políticas de governança (quem pode ser convidado, como aprovar chaincodes, etc).&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Bancos e fintechs entrariam como convidadas para ingressar na rede como novos membros (isso via AMB);&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cada instituição ingressa como um &lt;strong&gt;Membro&lt;/strong&gt;, com autonomia sobre seus nós e identidades.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Cada membro cria **Peers **para validar transações e hospedar &lt;em&gt;chaincodes&lt;/em&gt;;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Um **CA **do AMB gera certificados para admins, peers e clientes;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Cada membro tem seu próprio CA, emitindo certificados para:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Admins&lt;/strong&gt;: que vão gerir a rede;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Peer&lt;/strong&gt;: que são os nós validadores;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Clientes/aplicações&lt;/strong&gt;: App que compra titulos do Tesouro, ou que consulta o saldo da reserva bancária;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;São criados &lt;strong&gt;Channels&lt;/strong&gt;, onde subsetores podem trocar informações privadas (ex.: liquidação de ativos tokenizados).&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Aqui o Bacen poderia criar channels privados para liquidação interbancária;&lt;/li&gt;
&lt;li&gt;Outra possibilidade, seria a criação de tokenização de ativos em um canal apenas com fintechs;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;O _chaincode _(smart contract) é implantado nos peers e passa a reger a lógica de negócios;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A cereja no bolo, onde seria feita a criação (mint) e a destruição/liquidação (burn) de tokens;&lt;/li&gt;
&lt;li&gt;Aqui o céu é o limite, podendo programar liquidações, transferências interbancárias e etc.;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Toda transação é assinada, validada pelos peers do canal e registrada no ledger imutável;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Resumindo, se o Bacen quisesse rodar um piloto de Drex com governança distribuída entre bancos, poderia montar a rede no Hyperleger Fabric via AMB, enquanto um banco privado poderia, ao mesmo tempo, usar o AMB Query para auditar movimentações tokenizadas sem manter servidores extras.&lt;/p&gt;

&lt;h3&gt;
  
  
  Mas porque fazer com AMB
&lt;/h3&gt;

&lt;p&gt;A grande vantagem do AMB é ser um serviço gerenciado, e para a Bacen e grandes bancos e consórcios, o AMB tende a equilibrar governança + segurança + operação. Para fintechs e PoC, rodar em EKS/EC2 (ou usar provedores publicos) gera agilidade e controle, mas com um custo operacional, é claro. Abaixo comparo de uma forma melhor:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Critério&lt;/th&gt;
&lt;th&gt;AMB&lt;/th&gt;
&lt;th&gt;Nó próprio&lt;/th&gt;
&lt;th&gt;Rede pública (Gnosis)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Operação&lt;/td&gt;
&lt;td&gt;Totalmente gerenciado (patching, HA)&lt;/td&gt;
&lt;td&gt;Você opera tudo (alto controle)&lt;/td&gt;
&lt;td&gt;100% terceirizado&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Segurança&lt;/td&gt;
&lt;td&gt;IAM/KMS/VPC integrados&lt;/td&gt;
&lt;td&gt;Você define hardening/chaves&lt;/td&gt;
&lt;td&gt;Depende do provedor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Governança&lt;/td&gt;
&lt;td&gt;Forte (ideal p/ consórcios/BCB)&lt;/td&gt;
&lt;td&gt;Forte (se bem implementado)&lt;/td&gt;
&lt;td&gt;Variável&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Desempenho/Latência&lt;/td&gt;
&lt;td&gt;Boa, mas dentro do modelo do serviço&lt;/td&gt;
&lt;td&gt;Máximo controle (afinamento p2p, disco, rede)&lt;/td&gt;
&lt;td&gt;Boa, mas sem garantias finas&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Custo&lt;/td&gt;
&lt;td&gt;Por nó/armazenamento/requests&lt;/td&gt;
&lt;td&gt;EC2/EBS/EKS/operacional&lt;/td&gt;
&lt;td&gt;Assinatura/uso (egress/limites)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Interoperabilidade&lt;/td&gt;
&lt;td&gt;Fabric + públicos suportados (Eth/Polygon)&lt;/td&gt;
&lt;td&gt;Total (você escolhe stack)&lt;/td&gt;
&lt;td&gt;Boa em públicos; lock-in do provedor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Dados on-chain (analytics)&lt;/td&gt;
&lt;td&gt;AMB Query (serverless multi-cadeia)&lt;/td&gt;
&lt;td&gt;Você indexa (TheGraph/ETL)&lt;/td&gt;
&lt;td&gt;Alguns provedores oferecem APIs&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Conclusão
&lt;/h2&gt;

&lt;p&gt;No contexto atual, o &lt;strong&gt;Amazon Managed Blockchain (AMB)&lt;/strong&gt; aparece como uma opção estratégica para bancos e fintechs que precisam integrar-se rapidamente ao ecossistema, sem carregar o peso e manter toda a pilha de infra (considerando, é claro, o exemplo hipotético utilizado).&lt;br&gt;
O AMB entrega:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Governança e compliance prontos para uso;&lt;/li&gt;
&lt;li&gt;Escalabilidae sob demanda, sem a complexidade de clusters Kubernetes;&lt;/li&gt;
&lt;li&gt;Integração direta com serviços AWS;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Contudo há limitações: adotar o AMB significa abrir mão de parte da flexibilidade e da independência que redes públicas ou nós próprios em EKS permitem. É um &lt;em&gt;trade-off&lt;/em&gt; inevitável entre o &lt;strong&gt;controle total&lt;/strong&gt; ou &lt;strong&gt;velocidade com governança pronta.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Por fim, a crítica é clara: o futuro do Drex, do mercado financeiro e da tokenização não será definido pela tecnologia, mas pela forma com que o Bacen, bancos e fintechs vão equilibrar centralização e abertura. Talvez o verdadeiro desafio não seja escolher entre Fabric, Besu, AMB ou EKS, mas sim entender &lt;strong&gt;quando usar cada abordagem.&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>blockchain</category>
      <category>web3</category>
      <category>aws</category>
      <category>cloud</category>
    </item>
    <item>
      <title>Bitnami e o fim do repositório gratuito de imagens: o que muda para DevOps e Cloud Engineers?</title>
      <dc:creator>Thiago Sagara</dc:creator>
      <pubDate>Wed, 27 Aug 2025 15:57:26 +0000</pubDate>
      <link>https://dev.to/thiagosagara/bitnami-e-o-fim-do-repositorio-gratuito-de-imagens-o-que-muda-para-devops-e-cloud-engineers-12m2</link>
      <guid>https://dev.to/thiagosagara/bitnami-e-o-fim-do-repositorio-gratuito-de-imagens-o-que-muda-para-devops-e-cloud-engineers-12m2</guid>
      <description>&lt;p&gt;Em meados de julho/25 a comunidade de cloud e DevOps recebeu uma noticia um tanto quanto peculiar: a Bitnami anunciou alterações do seu repositório publico e gratuito de imagens ded containers e charts, o que na prática é um jeito 'maqueado' de descontinar o projeto open.&lt;/p&gt;

&lt;p&gt;Para contextualizar, a Bitnami nasceu como uma empresa focada em simplificar a distribuição de aplicações open source, empacotando softwares em instalações fáceis, VMs, charts Helm e imagens Docker. Em 2019, foi adquirida pela VMware (hoje Broadcom), e desde então expandiu o catálogo de soluções.&lt;/p&gt;

&lt;p&gt;Algumas das imagens mais conhecidas e amplamente usadas incluem:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;PostgreSQL, MySQL e MariaDB:&lt;/strong&gt; banco de dados para produção;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;NGINX, Apache, Tomcat:&lt;/strong&gt; Servidores web e de aplicação;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Redis, RabbitMQ e Kafka:&lt;/strong&gt; Soluções de mensageria e cache;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Wordpress, Drupal, Magento:&lt;/strong&gt; Aplicações open source populares;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A vantagem de pegar imagens open e empacota-las? Incorporação de boas práticas como segurança reforçada, facilidade na configuração para k8s e helm, imagens 'prontas' para produção bom tuning básico de performance, as imagens vinham acompanhadas de charts Helm ociciais da própria Bitnami, ou seja em resumo ela transformava software cru em software 'pronto para rodar em nuvem'.&lt;/p&gt;

&lt;p&gt;Mas essa fase esta chegando ao fim.&lt;/p&gt;

&lt;h2&gt;
  
  
  Principais mudanças
&lt;/h2&gt;

&lt;p&gt;Vejam que o repositório gratuito permanecerá existindo com o nome Bitnami Legacy Registry, contudo com algumas limitações, cito-as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Não terá containers versionados&lt;/strong&gt;;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Redução significativa no catalogo&lt;/strong&gt;;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Não haverá updates de segurança&lt;/strong&gt;;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Remoção das imagens de comunidade Debian-based&lt;/strong&gt;;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Assim permanece gratuito imagens que eles chamaram de 'somente para desenvolvimento', com um catálogo limitado de aplicações, e todas apenas com a tag 'lastet' (o que nunca é uma boa opção para se ter em produção).&lt;/p&gt;

&lt;p&gt;Com a versão paga, chamada de Bitnami Secure Images (BSI), ficou too o histórico da imagem (versões), bases com hardened, SBOMs e é claro updates  de segurança e suporte. Tudo isso por um preço de $6.000/mês.&lt;/p&gt;

&lt;h2&gt;
  
  
  Impactos nos pipelines, charts e Helm
&lt;/h2&gt;

&lt;p&gt;A mudança impacta diretamente pipelines de CI/CD, charts do Helm e manifestos Kubernetes que referenciam imagens da Bitnami. Projetos que até ontem "simplesmente funcionavam" podem começar a quebrar com erros de &lt;code&gt;Image not found&lt;/code&gt;, &lt;code&gt;ImagePullBackOff&lt;/code&gt; ou &lt;code&gt;ErrImagePull&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Mas onde o impacto vai ser mais potente:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Pipelines de build/deploy:&lt;/strong&gt; falhas ao puxar imagens já existentes, pois o código não terá a referencia correta;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Charts Helm:&lt;/strong&gt; centenas de charts oficiais e derivados utilizam imagens da Bitnami como dependencia;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ambientes Kubernetes:&lt;/strong&gt; clusters rodando workloads baseados nessas imagens correm risco ded indisponibilidade em novos deploys;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Na prática essa alteração em um repositório tão importante para CI/Cs, charts e clustes em geral escala o evento para problema na cadeia de suprimentos. &lt;/p&gt;

&lt;p&gt;Além do impacto técnico, a sensação de 'soco no estomago' na comunidade foi grande, e até injusto de certa forma. Usar a Bitnami ao invés de imagens oficiais tirava certo peso dos desenvolvedores e devOps, pois a imagem vinha com boas práticas adicionais, contudo também contava com bastante apoio da comunidaded na resolução de issues e documentação.&lt;/p&gt;

&lt;p&gt;Receber o anuncio com a opção de 'migrar' em 45 dias é de uma falta de empatia gigante, e aqui nem acredito que capitalizar o trabalho é errado, mas sim a forma que isso foi feito. Para efeito e comparação em 2020 a RedHat anunciou mudança de foco para o CentOS, mas apenas em julho de 2024  ele entrou em EOL, na prática a RedHat ainda 'suportou' o projeto com atualizações de segurança e manutenção por 4 anos, o que deu a comunidade tempo para fazer &lt;em&gt;forks&lt;/em&gt; e até iniciar outros projetos.&lt;/p&gt;

&lt;h2&gt;
  
  
  Opções urgentes
&lt;/h2&gt;

&lt;p&gt;As opções para (pelo menos) ganhar tempo de uma solução mais robusta podem incluir fazer o cache local das imagens utilizadas atualmente com um &lt;code&gt;docker save&lt;/code&gt;, ou utilizar repositórios privados como o AWS ECR ou o Harbor. Dessa forma é possivel congelar as versões críticas até que um plano de migração esteja definido.&lt;/p&gt;

&lt;p&gt;Outra opção (um pouco mais kamikaze) é utilizar o repositório legado, e simplesmente substituir o código para &lt;code&gt;bitnamilegacy/&amp;lt;image&amp;gt;&lt;/code&gt;. O problema disso: não tem updates, suporte e manutenção, além de existir a possibilidade de uma atualização da imagem, e por conta do &lt;em&gt;latest&lt;/em&gt; você ter surpresas na aplicação.&lt;/p&gt;

&lt;p&gt;Existe também a opção de fazer o subscribe do Bitnami Secure Image, contudo pagar por algo que antes era gratuito, pode exigir um estudo mais aprofundado das empresas para calcular o retorno de investimento e até a nova margem (a depender do tamanho da empresa). Note que $6.000/mês no Brasil pode significar o custo de TODA conta da AWS, o que na prática deixa inviável a escolha.&lt;/p&gt;

&lt;h2&gt;
  
  
  Opções definitivas
&lt;/h2&gt;

&lt;p&gt;Pra resolver de forma definitiva é necessário identificar os workloads críticos que utilizam imagens bitnami, e classifica-los por impacto comercial. Dessa forma (com o impacto financeiro calculado) será possivel analisar o risco/retorno do custo da licença.&lt;/p&gt;

&lt;p&gt;Se obter a licença não for uma opção, as alternativas são:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Imagens oficiais:&lt;/strong&gt; Ou seja, utilizar o repositório oficial da imagem, como postgres, redis e etc;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Imagens da AWS:&lt;/strong&gt; Usar RDS ou mesmo o ElastiCache é uma ótima opção para não ter esse tipo de problema;&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Serviços Gerenciados:&lt;/strong&gt; Para aplicações mais complexas como elasticsearch e kafka ou rabbitMQ, serviços como o OpenSearch e o Amazon MSK são opções ótimas;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Conclusão
&lt;/h2&gt;

&lt;p&gt;Não que a comunidade precisasse de justificativa, uma vez que o produto precisa ser capitalizado, mas a explicação da Broadcom é que a mudança visa um repositório mais seguro e com suporte. Contudo a segurança não depende necessariamente de &lt;em&gt;paywall&lt;/em&gt;.&lt;br&gt;
Ferramentas como Trivy, Grype ou Clair já fazem analise de vulnerabilidade, assim bastaria incorpora-las na pipeline de CI/CD e até integrar com SCA para aumentar a analise.&lt;/p&gt;

&lt;p&gt;Na prática, o movimento reflete mais uma estratégia a Broadcom pós-aquisição da VMware: monetizar ativos consolidados. O que, novamente, não acho errado, contudo o jeito com que foi feito (abrupto, sem períoo de transição claro e justo) deixará muitas empresas a merce de renovar por uma taxa grande, apenas para conseguir mais tempo para planejar a migração.&lt;/p&gt;

&lt;p&gt;No fim, quem perde não são apenas os entusiastas de open source, mas também too o ecossistema que dependia da Bitnami, e assim aprendemos que ser cloud-native é também pensar em cenários onde até a Docker pode começar a cobrar pela disponibilidade.&lt;/p&gt;

&lt;h2&gt;
  
  
  Como verificar se possuo imagens bitnami
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;Cluster Kubernetes (tudo que ja virou pod):
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;kubectl get pods -A -o json \
| jq -r '.items[]
  | .metadata.namespace as $ns
  | .metadata.name as $name
  | (.spec.initContainers // []) + (.spec.containers // [])
  | .[].image
' | sort -u | grep -E '(^|/)bitnami/'
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ol&gt;
&lt;li&gt;Cluster Kubernetes (tudo que ainda não virou pod):
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;kubectl get deploy,sts,ds,job,cronjob -A -o json \
| jq -r '.items[]
  | .metadata.namespace as $ns
  | .metadata.name as $name
  | (.spec.template.spec.initContainers // []) + (.spec.template.spec.containers // [])
  | .[].image
' | sort -u | grep -E '(^|/)bitnami/'
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ol&gt;
&lt;li&gt;Helm:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;helm ls -A -o json \
| jq -r '.[] | [.name,.namespace] | @tsv' \
| while IFS=$'\t' read -r rel ns; do
    echo "=== $ns/$rel ==="
    helm get values "$rel" -n "$ns" | grep -nE '(^\s*image:|repository:).*bitnami' || true
  done
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ol&gt;
&lt;li&gt;Pipeline no Jenkins para procurar dependencias:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;pipeline {
  agent any
  options { ansiColor('xterm') }
  environment {
    BITNAMI_REGEX = '(?i)(^|\\s|/)(bitnami)(/|:)'
  }
  stages {
    stage('Audit - Git Manifests') {
      steps {
        sh '''
          echo "[GIT] Procurando imagens/repo Bitnami..."
          set +e
          MATCHES=0

          # 1) Imagens em manifests YAML
          FOUND1=$(find . -type f -name "*.y*ml" -print0 \
            | xargs -0 -I{} yq -r '.. | select(has("image")) | .image' '{}' 2&amp;gt;/dev/null \
            | grep -E "$BITNAMI_REGEX" || true)
          if [ -n "$FOUND1" ]; then echo "$FOUND1" | sort -u | sed "s/^/[YAML IMG] /"; MATCHES=1; fi

          # 2) Helm/Chart deps
          FOUND2=$(git grep -nEi "(repository|repoURL):\\s*(oci://registry-1\\.docker\\.io/bitnamicharts|https?://charts\\.bitnami\\.com/bitnami)" || true)
          if [ -n "$FOUND2" ]; then echo "$FOUND2" | sed "s/^/[HELM REPO] /"; MATCHES=1; fi

          # 3) Dockerfiles
          FOUND3=$(git grep -nEi "FROM\\s+bitnami/" || true)
          if [ -n "$FOUND3" ]; then echo "$FOUND3" | sed "s/^/[DOCKERFILE] /"; MATCHES=1; fi

          if [ $MATCHES -ne 0 ]; then
            echo "✖ Encontrado Bitnami. Interrompendo pipeline."
            exit 2
          fi
          echo "✔ Nenhuma referência Bitnami encontrada no Git."
        '''
      }
    }

    stage('Audit - Cluster (opcional)') {
      when { expression { return env.KUBECONFIG?.trim() } }
      steps {
        sh '''
          echo "[CLUSTER] Vasculhando imagens em workloads..."
          set +e
          OUT=$(kubectl get deploy,sts,ds,job,cronjob -A -o json \
            | jq -r '.items[] | (.spec.template.spec.initContainers // []) + (.spec.template.spec.containers // []) | .[].image' \
            | sort -u | grep -E "$BITNAMI_REGEX" || true)
          if [ -n "$OUT" ]; then
            echo "$OUT" | sed "s/^/[K8S IMG] /"
            echo "✖ Cluster contém imagens Bitnami em workloads desejados."
            exit 3
          fi
          echo "✔ Nenhuma imagem Bitnami detectada em workloads."
        '''
      }
    }
  }
  post {
    always {
      archiveArtifacts artifacts: '**/audit*.log', allowEmptyArchive: true
    }
    failure {
      echo 'Falhou por referências Bitnami. Verifique os logs acima.'
    }
  }
}

&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Referências:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://news.broadcom.com/app-dev/broadcom-introduces-bitnami-secure-images-for-production-ready-containerized-applications" rel="noopener noreferrer"&gt;Anuncio Broadcom&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bitnami/charts/issues/35164" rel="noopener noreferrer"&gt;Issue oficial&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>aws</category>
      <category>cloud</category>
      <category>docker</category>
      <category>programming</category>
    </item>
    <item>
      <title>Entendendo Docker: o que é, como funciona e por que usar</title>
      <dc:creator>Thiago Sagara</dc:creator>
      <pubDate>Wed, 30 Jul 2025 21:05:57 +0000</pubDate>
      <link>https://dev.to/thiagosagara/entendendo-docker-o-que-e-como-funciona-e-por-que-usar-1cm2</link>
      <guid>https://dev.to/thiagosagara/entendendo-docker-o-que-e-como-funciona-e-por-que-usar-1cm2</guid>
      <description>

&lt;p&gt;Repost do original: &lt;a href="https://www.darede.com.br/entendendo-docker/" rel="noopener noreferrer"&gt;https://www.darede.com.br/entendendo-docker/&lt;/a&gt; da Darede&lt;/p&gt;

&lt;p&gt;O Docker é uma das melhores plataformas para o deploy de uma aplicação. Para entender sua funcionalidade, confira esse artigo em nosso blog! &lt;/p&gt;

&lt;p&gt;A evolução do deploy de uma aplicação passou por vários processos. Inicialmente tínhamos um servidor físico para cada serviço, ou seja, havia um servidor, um sistema operacional e uma aplicação. Isso gera um aumento em manutenção de hardware, de atualização de patches de segurança ou upgrade da aplicação. Com a virtualização criamos uma camada de abstração do hardware, ou seja, podemos em UM hardware ter vários SOs, e consequentemente várias aplicações. Contudo a necessidade de gerenciamento do SO ainda existe (e ainda existe o SO do próprio hypervisor). Por fim chegamos ao container, ele eleva a abstração para o SO. Isto é, conseguimos abstrair o hardware e o sistema operacional, e deixar o container apenas para cuidar da aplicação. Nesse artigo vamos entender sobre o Docker.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F7bq2fgtewuziog4pnyes.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F7bq2fgtewuziog4pnyes.png" alt="Conteinerização vs Virtualização" width="416" height="403"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Instalação (centos8)
&lt;/h2&gt;

&lt;p&gt;Instalaremos o docker, e depois realizaremos o pull de uma imagem do tac_plus para servir como servidor de autenticação para nossos equipamentos.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Remova todas as versões de docker que possam estar habilitadas:
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;dnf remove docker \
docker-client \
docker-client-latest \
docker-common \
docker-latest \
docker-latest-logrotate \
docker-logrotate \
docker-engine 
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Desabilite o firewalld (por algum motivo ele impossibilita a resolução de DNS dentro dos containers)
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;systemctl disable firewalld
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Adicione o repositório do docker
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;dnf config-manager --add-repo=https://download.docker.com/linux/centos/docker-ce.repo
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Instale o docker com --nobest para compatibilidade com CentOS 8
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;dnf install --nobest docker-ce
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Habilite o docker no sistema
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;
systemctl start docker
systemctl enable docker
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Teste o docker validando a versão
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[root@devops ~]# docker version
Client: Docker Engine - Community
 Version:           19.03.11
 API version:       1.39
 Go version:        go1.13.10
 Git commit:        42e35e61f3
 Built:             Mon Jun  1 09:13:48 2020
 OS/Arch:           linux/amd64
 Experimental:      false


Server: Docker Engine - Community
 Engine:
  Version:          18.09.1
  API version:      1.39 (minimum version 1.12)
  Go version:       go1.10.6
  Git commit:       4c52b90
  Built:            Wed Jan  9 19:06:30 2019
  OS/Arch:          linux/amd64
  Experimental:     false
[root@devops ~]#
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Comandos básicos
&lt;/h2&gt;

&lt;p&gt;Com o Docker instalado vamos agora falar de alguns comandos básicos:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;docker ps -a: Mostra todos os containers, tanto os em execução quanto os parados.&lt;/li&gt;
&lt;li&gt;docker run: Executa um container com uma imagem especifica (no nosso caso o Hello-Worl&lt;/li&gt;
&lt;li&gt;docker start|stop: Inicia um (ou mais) containeres parados, ou para um (ou mais) containers ativos.&lt;/li&gt;
&lt;li&gt;docker rm: Remove um (ou mais) container. (voce pega a lista com o docker ps -a)&lt;/li&gt;
&lt;li&gt;docker rmi: Remove um (ou mais) imagens. (voce pega a lista com o docker images)&lt;/li&gt;
&lt;li&gt;docker container prune: Remove todos os containers que estão parados.&lt;/li&gt;
&lt;li&gt;docker images: Mostra todas as images que voce ja fez o pull&lt;/li&gt;
&lt;li&gt;docker exec -it: Roda um comando dentro do container (só o exec), e com a opção "-it" voce aloca um tty dentro do container, ou seja, é a opção para ter acesso a console do container. exemplo: docker exec -it hello-wold bash&lt;/li&gt;
&lt;li&gt;docker network ls: Lista todas as redes criadas no Docker&lt;/li&gt;
&lt;li&gt;docker run: Executa de fato (ou roda) o docker.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Por fim para testar, vamos subir um docker com o famoso hello-word:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[root@devops ~]# docker run hello-world
Unable to find image 'hello-world:latest' locally
latest: Pulling from library/hello-world
0e03bdcc26d7: Pull complete
Digest: sha256:d58e752213a51785838f9eed2b7a498ffa1cb3aa7f946dda11af39286c3db9a9
Status: Downloaded newer image for hello-world:latest


Hello from Docker!
This message shows that your installation appears to be working correctly.


To generate this message, Docker took the following steps:
 1. The Docker client contacted the Docker daemon.
 2. The Docker daemon pulled the "hello-world" image from the Docker Hub.
    (amd64)
 3. The Docker daemon created a new container from that image which runs the
    executable that produces the output you are currently reading.
 4. The Docker daemon streamed that output to the Docker client, which sent it
    to your terminal.


To try something more ambitious, you can run an Ubuntu container with:
 $ docker run -it ubuntu bash


Share images, automate workflows, and more with a free Docker ID:
 https://hub.docker.com/


For more examples and ideas, visit:
 https://docs.docker.com/get-started/


[root@devops ~]#
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Xero no suvaco!!!&lt;/p&gt;

</description>
      <category>aws</category>
      <category>braziliandevs</category>
      <category>cloud</category>
      <category>docker</category>
    </item>
  </channel>
</rss>
