shiichan

Amazon MWAA Serverless now works with shared VPC subnets!

Hey there, it's Shiichan! Today I've got a small but handy update for AWS's serverless Apache Airflow service.

AWS What's New aws.amazon.com

What was announced?

According to AWS's What's New, Amazon MWAA Serverless now supports shared VPC configurations. Specifically, subnets shared from another account through AWS Resource Access Manager (AWS RAM) now work directly with MWAA Serverless workflows.

The story so far

Before this, if you tried to create an MWAA Serverless workflow using a subnet shared via AWS RAM, you'd hit a validation error. Using a shared VPC meant reaching for workarounds, which was a bit of a hassle.

What changes

With this update, MWAA Serverless correctly validates subnet ownership in shared VPC configurations, the same behavior as MWAA Provisioned environments.

Sharing VPC subnets across accounts with AWS RAM is a common pattern in multi-account landing zone architectures. Organizations that centrally manage networking can now launch MWAA Serverless workflows in member accounts using shared subnets, with no workarounds needed.

Dive Deep

If you use Amazon SageMaker Unified Studio Workflows, you also benefit from this update when your projects are configured with shared VPC networking.

It's available in all AWS Regions where Amazon MWAA Serverless is supported. You can check the subnet requirements in the Networking docs.

Wrap-up

  • MWAA Serverless now supports shared VPC subnets via AWS RAM
  • The old validation error is gone, so you can create workflows without workarounds
  • It matches MWAA Provisioned behavior, and SageMaker Unified Studio Workflows benefits too
  • Perfect for teams that centrally manage networking across multiple accounts