AWS's September 2026 Retirement Wave: Managed Blockchain, DevOps Guru, Backint for SAP ASE and Infrastructure Composer Get End Dates
On September 29, 2026, AWS posted its latest AWS Service Availability Updates notice, the low-key format it now uses instead of blog posts. Four services entered sunset, the stage where AWS names the day it will end operations and support: Amazon Managed Blockchain, Amazon DevOps Guru, AWS Backint Agent for SAP ASE and the standalone AWS Infrastructure Composer console. Two more, Amazon Chime SDK SIP media applications and Amazon WorkSpaces Secure Browser, moved to maintenance. Every one of them closes to new customers on October 29, 2026.
What AWS announced
The post sorts the changes into AWS's three lifecycle stages. For the two maintenance entries, AWS's wording is that the services "will no longer be accessible to new customers starting October 29, 2026", that existing customers can keep using them, and that AWS "will continue to operate and support these services and features". No end date exists for either. AWS's own page for the Chime SDK SIP media applications points new telephony work at Amazon Connect Customer; the WorkSpaces Secure Browser page offers Amazon WorkSpaces Applications with a self-managed Chrome image, or an enterprise secure browser.
The four sunset entries are the substance of the announcement, and they are what the rest of this guide covers. The post also lists Amazon Mechanical Turk as already at end of support; AWS's two summary tables print different days for it and we have not read a Mechanical Turk service page, so this guide does not print one.
The table below gives, for each sunset service, the date on its own AWS end-of-support page and the date in AWS's services-in-sunset table. They should be the same. For two of the four they are not.
| Service | What AWS announced | New customers blocked | End of support (service page) | Sunset table says | Source |
|---|---|---|---|---|---|
| Amazon Managed Blockchain | Sunset; access to all AMB functionality ends | October 29, 2026 | September 29, 2027 | September 29, 2027 | AWS page |
| Amazon DevOps Guru | Sunset; console, API and CloudFormation resource types withdrawn | October 29, 2026 | September 30, 2027 | September 29, 2027 (one day earlier than the service page) | AWS page |
| AWS Backint Agent for SAP ASE | Sunset; downloads and support end, agent not guaranteed to work | October 29, 2026 | September 29, 2027 | September 29, 2027 | AWS page |
| AWS Infrastructure Composer | Sunset of the standalone console; VS Code toolkit version continues | October 29, 2026 | December 7, 2026 | September 29, 2027 (the service page and the post both say the console shuts in 2026) | AWS page |
Service by service
Amazon Managed Blockchain
What it did: managed Hyperledger Fabric networks (AMB Access Hyperledger Fabric), managed node and RPC access to Ethereum, Bitcoin and Polygon (AMB Access), and an indexed blockchain-data API (AMB Query).
What replaces it, per AWS: for the Ethereum, Bitcoin and Polygon node products, self-managed nodes on AWS using the open-source AWS Blockchain Node Runners blueprints, or a third-party blockchain infrastructure provider. For AMB Query, a managed blockchain data provider; AWS warns that this is "not an endpoint-only change" because a standard node does not offer indexed queries. For Hyperledger Fabric, another managed Fabric network, self-managed Fabric on Amazon EC2 or Amazon EKS, or an AWS database if you need the historical data but not a ledger.
What happens on the end date, per AWS: "After September 29, 2027, you will no longer be able to access Amazon Managed Blockchain (AMB) functionality." The Fabric guidance is the one to read twice: AWS says the destination is a new network with its own identities, so "network state and identities are still rebuilt rather than copied", the source network has to be paused for extraction, and the work needs coordination across every participating organisation. AWS tells Fabric customers to contact Support or their account team and "begin planning as soon as possible".
Amazon DevOps Guru
What it did: machine-learning anomaly detection over your AWS resources, surfaced as operational "insights" with recommendations, plus notification channels and two CloudFormation resource types.
What replaces it, per AWS: Amazon CloudWatch for metric anomaly detection and alarming, and Amazon DevOps Agent for AI-assisted investigation and insight enrichment. AWS's page splits the choice by how you use the service: alerting goes to CloudWatch, investigation goes to DevOps Agent.
What happens on the end date, per AWS: until September 30, 2027 the service keeps running with security patches, critical bug fixes and AWS Support, but no new features. After that day the console and API operations are gone, the resource types AWS::DevOpsGuru::ResourceCollection and AWS::DevOpsGuru::NotificationChannel are withdrawn so that CloudFormation and CLI operations on them fail, and previously generated insights "will no longer be retrievable". AWS calls the infrastructure-as-code impact "the highest-severity impact" because a single failed resource can block a whole stack operation. Your workloads keep running: DevOps Guru observes resources, it does not host them.
The date disagreement: the DevOps Guru page and the announcement post both say September 30, 2027. AWS's services-in-sunset table prints September 29, 2027 for the same service. One day, but a day that matters if a compliance calendar is built from the table.
AWS Backint Agent for SAP ASE
What it did: an AWS-built agent that backed up SAP Adaptive Server Enterprise databases to Amazon S3 through SAP's Backup Server Archive API. The SAP HANA agent is a separate product and, in AWS's words, "is not affected by this change and continues to be supported until further notice".
What replaces it, per AWS: three options, in AWS's order of preference. First, SAP ASE 16.1's native Amazon S3 backup (syb_aws as the external API endpoint in dump and load), which needs no agent; AWS notes a known limitation that buckets in us-east-1 fail with a hostname error, so use another Region. Second, an Amazon S3 File Gateway presenting an NFS share that existing dump scripts can target. Third, an SAP-certified enterprise backup product.
What happens on the end date, per AWS: downloads end, existing installations are unsupported, and backup and restore operations "might not function as expected". The warning that matters comes earlier on the page, in bold: backups the agent wrote to S3 "cannot be restored using the alternatives". The data stays in your bucket and keeps costing storage, but only the retiring agent can read it. AWS's instruction is to restore any backup you need for compliance while the agent is still supported, take new full backups with the replacement during the migration period, and "do not rely on backups that were created with the agent for recovery after the end of support date".
The download change comes first: on October 29, 2026 the agent's download bucket switches from public to allowlisted-accounts-only and unauthenticated downloads stop. AWS says existing customer accounts are allowlisted automatically, but "scripts that rely on an unauthenticated download stop working" on that day "even for allowlisted accounts", so installation runbooks that fetch the agent over a plain URL need to move to aws s3 cp with credentials before then.
AWS Infrastructure Composer
What it did: a drag-and-drop canvas for composing AWS CloudFormation and AWS SAM templates, available as a standalone console, embedded in the CloudFormation console, and inside the AWS Toolkit for Visual Studio Code.
What replaces it, per AWS: the same experience in the AWS Toolkit for Visual Studio Code, which AWS says "retains the full Infrastructure Composer visual authoring experience with no changes". The embedded version in the CloudFormation console is being replaced by a new visual editor there. The "Export to Infrastructure Composer" buttons in the Lambda and Step Functions consoles are being removed.
What happens on the end date, per AWS: "The standalone Infrastructure Composer console will be shut down on December 7, 2026." The standalone URL stops resolving; templates saved to S3 or local disk, existing stacks and deployments are unaffected; there are no customer-facing APIs to decommission. This is the short fuse of the wave: the console closes a little over two months after the announcement, not the twelve months AWS's table intro calls typical.
The date disagreement: AWS's services-in-sunset table prints September 29, 2027 for Infrastructure Composer, a date that appears nowhere on the service page or in the announcement post. If you plan from the table you will miss the real shutdown by nearly ten months. AWS's own FAQ on the page also answers "Is there a blog post about this change?" with "No. Per AWS policy, blog posts are not used to communicate service availability changes."
The pattern
This is the third coordinated AWS retirement notice we have covered this year. The June announcement moved around twenty services and features into maintenance and five into sunset; the October 7 sunset ends five services that were announced a year earlier. Set side by side, four things are now consistent:
- Thirty days to the new-customer cutoff. Every service in this wave closes to new sign-ups exactly a month after the post. If you were evaluating any of them, the decision has been made for you.
- Sunset is "typically 12 months", except when it is not. AWS's own table intro says sunset timelines are typically twelve months. Three of the four fit. The Infrastructure Composer console does not, and nothing in the post's formatting flags it as different.
- The summary table is not the source of truth. Two of four rows in this wave disagree with the service pages they link to, and AWS's two summary tables also print different days for the Mechanical Turk entry from the June wave. Read the page the row points at.
- No blog post, no keynote, no email you will notice. AWS says in writing that it does not use blog posts for availability changes. The channels are the What's New feed, the Product Lifecycle page and AWS Health notifications. If none of those feed your change process, these dates arrive as a surprise.
The cloud difference still applies. When on-premises software reaches end of life it keeps running without patches; when a managed service reaches its end date it stops existing. There is no extended-support market for Managed Blockchain. The only mitigation is to migrate before the day.
What to do
- Census first. Cost Explorer grouped by service, then IaC repositories for
AWS::DevOpsGuru::resource types,managedblockchainAPI calls and any runbook that downloads the Backint agent from a public URL. - Before October 29, 2026: if you might ever need one of these services in a new account, sign up now; after that day the allowlist decides. Move Backint download automation to authenticated
aws s3 cp. - Before December 7, 2026: install the AWS Toolkit for Visual Studio Code and confirm every Infrastructure Composer template you care about is in S3 or source control, not only in the console.
- DevOps Guru: stand up the equivalent CloudWatch alarms, remove the two resource types from templates through a deploy rather than out of band, and export insights you want to keep through an SNS channel and the API. Set analysis coverage to None once the export is done to stop charges.
- Backint for SAP ASE: restore any backup you need for audit or compliance while the agent is supported, switch to native SAP ASE S3 backup or a File Gateway share, take new full backups, then delete agent-format backups you no longer need.
- Managed Blockchain on Hyperledger Fabric: this is a multi-organisation project with a quiesce-and-replay step in the middle. Get every participating organisation into the planning now; AWS's own guidance is to start immediately and to involve Support.
We track lifecycle deadlines like these across 500+ products, including AWS Lambda runtimes and AWS App Mesh. Check any version in seconds, scan your whole stack, or see what else is reaching end of life this half; how we verify dates explains which are vendor-read and which come from upstream.
Frequently Asked Questions
Which AWS services entered sunset on September 29, 2026, and when does each end?
Four. Amazon Managed Blockchain ends September 29, 2027. Amazon DevOps Guru ends September 30, 2027. AWS Backint Agent for SAP ASE ends September 29, 2027. The standalone AWS Infrastructure Composer console shuts down December 7, 2026; the Infrastructure Composer experience inside the AWS Toolkit for Visual Studio Code continues. Each date is read from the service's own AWS end-of-support page.
When do the four services stop accepting new customers?
October 29, 2026 for all four, thirty days after the announcement. AWS's Infrastructure Composer FAQ calls that day a target and says new sign-ups are blocked by allowlist. For the Backint Agent the same day also ends unauthenticated downloads: existing customers must fetch the agent with the AWS CLI or an SDK from an allowlisted account, and scripts that pull it from a public URL stop working.
Why do AWS's pages show two different end dates for DevOps Guru and Infrastructure Composer?
AWS's services-in-sunset table prints September 29, 2027 for both, one year after the announcement. The DevOps Guru end-of-support page says September 30, 2027, and the Infrastructure Composer page says December 7, 2026, as does the announcement post itself. The service pages carry the detailed shutdown behaviour, so this guide follows them and notes the table.
What happens to my data when these services end?
It depends on the service, and AWS's pages are specific. Managed Blockchain functionality becomes inaccessible, and AWS says Hyperledger Fabric network state and identities are rebuilt rather than copied, so migration is the only way to keep them. DevOps Guru insights are not retrievable after September 30, 2027; AWS recommends exporting them through an SNS notification channel and the API first. Backint Agent backups stay in your S3 bucket, but AWS says their format cannot be restored by any of the recommended alternatives. Infrastructure Composer templates saved to S3 or your local disk are not affected.
Does the Backint Agent retirement affect SAP HANA backups?
No. AWS's page says AWS Backint Agent for SAP HANA is not affected and continues to be supported until further notice. Only the SAP ASE agent ends on September 29, 2027.