大数跨境

AWS 2025:你以为你懂,其实早OUT了!

AWS 2025:你以为你懂,其实早OUT了! 雨神汇
2025-08-22
3
导读:别再用老黄历看AWS了,AWS 2025 早就变天了!”* “AWS更新速度比我掉头发的速度还快!一不留神,就感觉自己活在上个世纪。”* “出海企业想要玩转AWS,光靠抠成本是不够的,效率才是

点击蓝字关注雨生


AWS 2025:你以为你懂,其实早OUT了!


**副标题:别再用十年前的姿势玩云了!雨生带你避开那些年踩过的坑,弯道超车,走向人生巅峰!**

**导语:**还在用老黄历看AWS?还在为那些过时的“最佳实践”烧钱踩坑?醒醒吧!AWS 2025 早就变天了!今天,雨生就来扒一扒那些你以为你懂,其实早就错了的AWS知识点,让你少走弯路,把钱花在刀刃上!文末有惊喜,助你出海无忧!

---

嘿,大家好,我是雨生,一个在云计算圈摸爬滚打了二十年的老兵。最近读了Corey Quinn大佬的这篇《AWS in 2025: The Stuff You Think You Know That’s Now Wrong》,简直是深有同感!

AWS这玩意儿,更新速度比我掉头发的速度还快!一不留神,就感觉自己活在上个世纪。今天就来聊聊那些年,我们一起误解的AWS。

**雨生视角:AWS的“昨日重现”和“明日之星”**

Corey Quinn 这厮,一针见血地指出了AWS的尴尬:一方面,它已经是个“老家伙”了,另一方面,它又时刻在变。这就导致很多“老司机”还在用老方法开车,结果一脚踩进坑里。

比如,以前EC2改个安全组都要停机,现在直接热更新;S3以前是“最终一致性”,现在是“读写一致性”;以前Glacier恢复数据慢到你想哭,现在嗖嗖的。

这些变化,对于新玩家来说可能没什么感觉,但对于老玩家来说,简直是降维打击!

**深度解读:AWS底层逻辑的变迁**

这些变化背后,其实是AWS底层逻辑的变迁。

*   **从“不稳定”到“稳定”:** 以前AWS的各种服务,动不动就挂掉,现在稳定性大大提升,甚至可以不用担心可用区的问题。
*   **从“手动挡”到“自动挡”:** 以前各种配置都要手动调整,现在AWS提供了越来越多的自动化工具,比如Compute Optimizer,可以帮你优化成本
*   **从“省钱是王道”到“效率是关键”:** 以前大家都在抠成本,现在更注重效率,用更高的配置换取更快的速度。

**行动指南:出海企业如何玩转AWS 2025**

对于出海企业来说,了解这些变化至关重要。

1.  **拥抱新工具:** 别再用老一套的监控和告警系统了,试试AWS的Cost Anomaly Detector,可以帮你及时发现异常消费。
2.  **优化架构:** 别再死守着Dedicated Instances了, Savings Plans更灵活,更省钱。
3.  **提升效率:** Lambda函数别再设置5分钟超时了,直接拉满15分钟,用Docker镜像,跑起来更快更稳。

**互动环节:**

*   你在使用AWS的过程中,遇到过哪些“时代变迁”?
*   你觉得AWS未来还会有哪些变化?
*   对于出海企业来说,AWS还有哪些坑需要注意?

欢迎在评论区分享你的观点和经验,雨生等你来聊!

**雨生的VIP朋友们:出海路上的灯塔**

当然,想要玩转AWS,光靠看文章是不够的。你需要一个高质量的出海社群,一个可以随时提问、交流经验、获取最新资讯的平台。

这就是我创建“雨生的VIP朋友们”知识星球的初衷。在这里,你可以:

*   **获取独家报告:** 深入了解AWS最新趋势和最佳实践。
*   **参与专家问答:** 向雨生和其他行业大咖提问,解决你的实际问题。
*   **加入社群交流:** 和其他出海精英交流经验,拓展人脉。

现在加入,即可享受**3天免费试用**! 更有机会获得**专属折扣**! 别犹豫了,赶紧加入吧! \[放上知识星球链接或二维码]


**结尾:**

AWS的世界变化莫测,但只要你紧跟趋势,不断学习,就能在这个充满机遇的时代里脱颖而出。雨生愿与你一同成长,共同探索出海的无限可能!

关注“雨生云计算”公众号,获取更多出海干货!

---

**金句海报(示例):**

*   “别再用老黄历看AWS了,AWS 2025 早就变天了!”
*   “AWS更新速度比我掉头发的速度还快!一不留神,就感觉自己活在上个世纪。”
*   “出海企业想要玩转AWS,光靠抠成本是不够的,效率才是关键!”

\[海报上醒目位置添加公众号二维码]

**话题标签:**

\#雨生云计算# \#出海必读# \#知识星球# \#AWS# \#云计算# \#出海#

**邀请关注有礼活动方案:**

邀请1位好友关注“雨生云计算”公众号,即可获得知识星球**7天免费体验券**!

邀请3位好友关注,即可参与抽奖,赢取知识星球**年度VIP会员**(原价550元/年)!

**朋友圈文案模板:**

1.  “雨生大佬的最新AWS解读,出海必读!强烈推荐加入知识星球“雨生的VIP朋友们”,干货满满!\[文章链接]”
2.  “还在为AWS的各种坑苦恼?看看雨生这篇文章,让你少走弯路!知识星球更有大咖坐镇,助你出海无忧!\[文章链接]”
3.  “AWS变化太快了!感谢雨生大佬的总结,让我又学到了新知识!强烈推荐关注“雨生云计算”公众号!\[文章链接]”

**新闻原文中英文对照版本:**

**AWS in 2025: The Stuff You Think You Know That’s Now Wrong**

AWS 2025:你以为你懂,其实早OUT了!

**By Corey Quinn**

作者:Corey Quinn

**One of the neat things about AWS is that it's almost twenty years old. One of the unfortunate things about AWS is... that it's almost twenty years old**

AWS最酷的事情之一是它已经快二十年了。 AWS不幸的事情之一是……它也快二十年了。

**If you’ve been using the platform for a while, it can be hard to notice the pace of change in the underlying “foundational” services. More worryingly, even if you’re not an old saw at AWS scrying, it’s still easy to stumble upon outdated blog posts that speak to the way things used to be, rather than the way they are now. I’ve gathered some of these evolutions that may help you out if you find yourself confused.**

如果您使用该平台已有一段时间,您可能很难注意到底层“基础”服务的变化速度。 更令人担忧的是,即使您不是 AWS 方面的老手,仍然很容易偶然发现过时的博客文章,这些文章讲述的是过去的样子,而不是现在的样子。 我收集了一些演变,如果您感到困惑,这些演变可能会对您有所帮助。

**EC2**

EC2

**In EC2, you can now change security groups and IAM roles without shutting the instance down to do it.**

在 EC2 中,您现在可以更改安全组和 IAM 角色,而无需关闭实例。

**You can also resize, attach, or detach EBS volumes from running instances.**

您还可以从正在运行的实例调整大小、附加或分离 EBS 卷。

**As of very recently, you can also force EC2 instances to stop or terminate without waiting for a clean shutdown or a ridiculous timeout, which is great for things you’re never going to spin back up.**

最近,您还可以强制 EC2 实例停止或终止,而无需等待干净的关机或荒谬的超时,这对于您永远不会重新启动的事情来说非常有用。

**They also added the ability to live-migrate instances to other physical hosts; this manifests as it being much rarer nowadays to see an instance degradation notice.**

他们还增加了将实例实时迁移到其他物理主机的能力; 这体现在现在看到实例降级通知的情况要少得多。

**Similarly, instances have gone from a “expect this to disappear out from under you at any time” level of reliability to that being almost unheard of in the modern era.**

同样,实例的可靠性已从“预计随时从您身下消失”的级别转变为在现代几乎闻所未闻的级别。

**Spot instances used to be much more of a bidding war / marketplace. These days the shifts are way more gradual, and you get to feel a little bit less like an investment banker watching the numbers move on your dashboards in realtime.**

Spot 实例过去更像是一场竞价战/市场。 如今,这种变化要渐进得多,您感觉自己像一个投资银行家一样,实时观看仪表板上的数字移动的情况要少一些。

**You almost never need dedicated instances for anything. It’s been nearly a decade since they weren’t needed for HIPAA BAAs.**

您几乎永远不需要任何专用实例。 自 HIPAA BAA 不需要它们以来已经近十年了。

**AMI Block Public Access is now default for new accounts, and was turned on for any accounts that hadn’t owned a public AMI for 90 days back in 2023.**

AMI 阻止公共访问现在是新帐户的默认设置,并且在 2023 年为任何 90 天内未拥有公共 AMI 的帐户启用。

**S3**

S3

**S3 isn’t eventually consistent anymore–it’s read-after-write consistent.**

S3 不再是最终一致的,而是读后写一致的。

**You don’t have to randomize the first part of your object keys to ensure they get spread around and avoid hotspots.**

您不必随机化对象键的第一部分,以确保它们分散开来并避免热点。

**ACLs are deprecated and off by default on new buckets.**

ACL 已被弃用,并且默认情况下在新存储桶上处于关闭状态。

**Block Public Access is now enabled by default on new buckets.**

默认情况下,现在对新存储桶启用阻止公共访问。

**New buckets are transparently encrypted at rest.**

新存储桶在静态时进行透明加密。

**Once upon a time Glacier was its own service that had nothing to do with S3. If you look closely (hi, billing data!) you can see vestiges of how this used to be, before the S3 team absorbed it as a series of storage classes.**

很久以前,Glacier 是一项独立的服务,与 S3 无关。 如果您仔细观察(嗨,账单数据!),您可以看到在 S3 团队将其作为一系列存储类吸收之前,这种情况是如何发生的。

**Similarly, there used to be truly horrifying restore fees for Glacier that were also very hard to predict. That got fixed early on, but the scary stories left scars to the point where I still encounter folks who think restores are both fiendishly expensive as well as confusing. They are not.**

同样,过去 Glacier 的恢复费用确实令人恐惧,而且也很难预测。 这在早期就得到了修复,但可怕的故事留下了伤痕,以至于我仍然遇到一些人认为恢复既非常昂贵又令人困惑。 它们不是。

**Glacier restores are also no longer painfully slow.**

Glacier 的恢复也不再令人痛苦地缓慢。

**Networking**

网络

**Obviously EC2-classic is gone, but that was a long time ago. One caveat that does come up a lot is that public v4 IP addresses are no longer free; they cost the same as Elastic IP addresses.**

显然 EC2-classic 已经消失了,但那是很久以前的事了。 经常出现的一个警告是,公共 v4 IP 地址不再是免费的; 它们的价格与弹性 IP 地址相同。

**VPC peering used to be annoying; now there are better options like Transit Gateway, VPC sharing between accounts, resource sharing between accounts, and Cloud WAN.**

VPC 对等互连过去很烦人; 现在有更好的选择,例如 Transit Gateway、帐户之间的 VPC 共享、帐户之间的资源共享和 Cloud WAN。

**VPC Lattice exists as a way for things to talk to one another and basically ignore a bunch of AWS networking gotchas. So does Tailscale.**

VPC Lattice 是一种让事物相互通信并基本上忽略一堆 AWS 网络陷阱的方式。 Tailscale 也是如此。

**CloudFront isn’t networking but it has been in the AWS “networking” section for ages so you can deal with it: it used to take ~45 minutes for an update, which was terrible. Nowadays it’s closer to 5 minutes—which still feels like 45 when you’re waiting for CloudFormation to finish a deployment.**

CloudFront 不是网络,但它已经在 AWS “网络”部分存在了很长时间,因此您可以处理它:过去更新需要大约 45 分钟,这太糟糕了。 如今,它接近 5 分钟——当您等待 CloudFormation 完成部署时,仍然感觉像是 45 分钟。

**ELB Classic (“classic” means “deprecated” in AWS land) used to charge cross AZ data transfer in addition to the load balancer “data has passed through me” fee to send to backends on a different availability zone.**

ELB Classic(“classic”在 AWS 领域中意味着“已弃用”)过去除了负载均衡器“数据已通过我”的费用外,还会收取跨 AZ 数据传输费用,以发送到不同可用区上的后端。

**ALBs with automatic zone load balancing do not charge additional data transfer fees for cross-AZ traffic, just their LCU fees. The same is true for Classic Load Balancers, but be warned: Network Load Balancers still charge cross-AZ fees!**

具有自动区域负载平衡的 ALB 不会收取跨 AZ 流量的额外数据传输费用,只需收取其 LCU 费用。 经典负载均衡器也是如此,但请注意:网络负载均衡器仍然收取跨 AZ 费用!

**Network Load Balancers didn’t used to support security groups, but they do now.**

网络负载均衡器过去不支持安全组,但现在支持。

**Availability Zones used to be randomized between accounts (my us-east-1a was your us-east-1c); you can now use Resource Access Manager to get zone IDs to ensure you’re aligned between any given accounts.**

可用区过去在帐户之间是随机的(我的 us-east-1a 是您的 us-east-1c); 现在您可以使用 Resource Access Manager 来获取区域 ID,以确保您在任何给定帐户之间保持一致。

**Lambda**

Lambda

**Originally Lambda had a 5 minute timeout and didn’t support container images. Now you can run them for up to 15 minutes, use Docker images, use shared storage with EFS, give them up to 10GB of RAM (for which CPU scales accordingly and invisibly), and give /tmp up to 10GB of storage instead of just half a gig.**

最初 Lambda 的超时时间为 5 分钟,并且不支持容器镜像。 现在您可以运行它们长达 15 分钟,使用 Docker 镜像,使用 EFS 共享存储,为它们提供高达 10GB 的 RAM(CPU 会相应地且不可见地进行扩展),并为 /tmp 提供高达 10GB 的存储空间,而不是仅仅半个GB。

**Invoking a Lambda in a VPC is no longer dog-slow.**

在 VPC 中调用 Lambda 不再像狗一样慢。

**Lambda cold-starts are no longer as big of a problem as they were originally.**

Lambda 冷启动不再像最初那样成为一个大问题。

**EFS**

EFS

**You no longer have to put a big pile of useless data on an EFS volume to get your IO allotment to something usable; you can adjust that separately from capacity now that they’ve added a second knob.**

您不再需要在 EFS 卷上放置大量无用的数据,才能使您的 IO 分配达到可用的水平; 现在他们添加了第二个旋钮,您可以将其与容量分开调整。

**EBS**

EBS

**You get full performance on new EBS volumes that are empty. If you create an EBS volume from a snapshot, you’ll want to read the entire disk with dd or similar because it lazy-loads snapshot data from S3 and the first read of a block will be very slow. If you’re in a hurry, there are more expensive and complicated options.**

您可以在新的空 EBS 卷上获得全部性能。 如果您从快照创建 EBS 卷,您会想要使用 dd 或类似工具读取整个磁盘,因为它会从 S3 惰性加载快照数据,并且第一次读取块会非常慢。 如果您赶时间,还有更昂贵和复杂的选择。

**EBS volumes can be attached to multiple EC2 instances at the same time (assuming io1), but you almost certainly don’t want to do this.**

EBS 卷可以同时附加到多个 EC2 实例(假设 io1),但您几乎肯定不想这样做。

**DynamoDB**

DynamoDB

**You can now have empty fields (the newsletter publication system for “Last Week in AWS” STILL uses a field designator of empty because it predates that change) in an item.**

您现在可以在项目中使用空字段(“Last Week in AWS”的通讯发布系统仍然使用空字段指示符,因为它早于该更改)。

**Performance has gotten a lot more reliable, to the point where you don’t need to use support-only tools locked behind NDAs to see what your hot key problems look like.**

性能变得更加可靠,以至于您无需使用锁定在 NDA 之后的仅支持工具来查看您的热键问题是什么样的。

**With pricing changes, you almost certainly want to run everything On Demand unless you’re in a very particular space.**

随着定价的变化,除非您处于非常特殊的空间,否则您几乎肯定希望按需运行所有内容。

**Cost Savings Vehicles**

节省成本的工具

**Reserved Instances are going away for EC2, slowly but surely. Savings Plans are the path forward. The savings rates on these have diverged, to the point where they no longer offer as deep of a discount as RIs once did, which is offset by their additional flexibility. Pay attention!**

预留实例正在逐渐消失,EC2 也是如此。 Savings Plans 是前进的方向。 这些的节省率已经不同,以至于它们不再像 RI 曾经那样提供那么深的折扣,这被它们额外的灵活性所抵消。 注意!

**EC2 charges by the second now, so spinning one up for five minutes over and over again no longer costs you an hour each time.**

EC2 现在按秒收费,因此一次又一次地旋转五分钟不再每次都花费您一个小时。

**The Cost Anomaly Detector has gotten very good at flagging sudden changes in spend patterns. It is free.**

成本异常检测器非常擅长标记支出模式的突然变化。 它是免费的。

**The Compute Optimizer also does EBS volumes and other things. Its recommendations are trustworthy, unlike “Trusted” Advisor’s various suggestions.**

Compute Optimizer 也处理 EBS 卷和其他事情。 与“受信任”顾问的各种建议不同,它的建议是值得信赖的。

**The Trusted Advisor recommendations remain sketchy and self-contradictory at best, though some of their cost checks can now route through Compute Optimizer.**

Trusted Advisor 的建议充其量仍然是粗略的和自相矛盾的,尽管他们的一些成本检查现在可以通过 Compute Optimizer 进行路由。

**Authentication**

验证

**IAM roles are where permissions should live. IAM users are strictly for legacy applications rather than humans. The IAM Identity Center is the replacement for “AWS SSO” and it’s how humans should engage with their AWS accounts. This does cause some friction at times.**

IAM 角色是权限应该存在的地方。 IAM 用户严格用于传统应用程序,而不是人类。 IAM Identity Center 是“AWS SSO”的替代品,也是人类应该如何与他们的 AWS 帐户互动的方式。 这确实有时会引起一些摩擦。

**You can have multiple MFA devices configured for the root account.**

您可以为根帐户配置多个 MFA 设备。

**You also do not need to have root credentials configured for organization member accounts.**

您也不需要为组织成员帐户配置根凭据。

**Miscellaneous**

杂项

**us-east-1 is no longer a merrily burning dumpster fire of sadness and regret. This is further true across the board; things are a lot more durable these days, to the point where outages are noteworthy rather than “it’s another given Tuesday afternoon.”**

us-east-1 不再是充满悲伤和遗憾的快乐燃烧的垃圾箱。 这在各个方面都是如此; 如今,事物更加耐用,以至于中断值得注意,而不是“又是某个给定的星期二下午”。

**While deprecations remain rare, they’re definitely on the rise; if an AWS service sounds relatively niche or goofy, consider your exodus plan before building atop it. None of the services mentioned thus far qualify.**

虽然弃用仍然很少见,但它们肯定在上升; 如果一项 AWS 服务听起来相对小众或愚蠢,请在构建其之上之前考虑您的迁移计划。 迄今为止提到的所有服务都不符合条件。

**CloudWatch doesn’t have the last datapoint being super low due to data inconsistency anymore, so if your graphs suddenly drop to zero for the last datapoint your app just shit itself.**

CloudWatch 不再由于数据不一致而导致最后一个数据点非常低,因此如果您的图形突然下降到零,则您的应用程序只是把自己搞砸了。

**You can close AWS accounts in your organization from the root account rather than having to log into each member account as their root user.**

您可以从根帐户关闭组织中的 AWS 帐户,而不必以每个成员帐户的根用户身份登录。

原文链接:[https://www.lastweekinaws.com/blog/aws-in-2025-the-stuff-you-think-you-know-thats-now-wrong/](https://www.lastweekinaws.com/blog/aws-in-2025-the-stuff-you-think-you-know-thats-now-wrong/)

雨生云计算 is signing off! 希望这篇“不正经”的AWS解读能帮到你!记住,出海路上,有雨生与你同行!

雨生课程


现在单一云增长乏力,想实战的。《多云价值管理与增长》新课程出炉,雨生和SRE刘老师联袂授课,欢迎学友们关注!


雅菲奥朗《多云价值管理与增长》课程深度解析AI时代多云战略的价值重构路径,聚焦甲方多云管理能力升级与乙方增长模式创新。通过 “2天线下认知构建+1天线上实战验证” 混合模式,结合外资云与内资云商业画布演练、聚合云模式PK等前沿实验,输出可落地的多云价值管理框架与增长引擎。




报名链接见二维码



雨生云计算

微信号:FinOpsCFM



【声明】内容源于网络
0
0
雨神汇
1234
内容 918
粉丝 0
雨神汇 1234
总阅读63
粉丝0
内容918