AWS Disaster Recovery Plan: Safeguarding KMS, Certificate Manager, and Route 53 Data in the Event of a Region Failure ?

0

In case of a whole aws region lost, what would happen our records in KMS, Certificate Manager and Route 53?

  • Will we able to use them from another region even the regions we created them is lost? or they will be lost together with region?
  • Since we can't backup KMS keys, what would be the action to mitigate the risk of loosing whole region?
2개 답변
0

Hello.

Route 53 is a global resource, so it can probably be used even if there is a region-level failure.
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/disaster-recovery-resiliency.html

KMS and ACM are region-level resources, so if a region failure occurs, they will no longer be available in the region where the failure occurs.
https://docs.aws.amazon.com/kms/latest/developerguide/disaster-recovery-resiliency.html
https://docs.aws.amazon.com/acm/latest/userguide/disaster-recovery-resiliency.html

In the case of KMS, I think multi-region keys are a good measure against region failures.
https://docs.aws.amazon.com/kms/latest/developerguide/multi-region-keys-overview.html

profile picture
전문가
답변함 8달 전
profile pictureAWS
전문가
검토됨 8달 전
0

Hi,

In addition to multi-region keys suggested by Riku, you can also create keys based on imported material under your control. See https://docs.aws.amazon.com/kms/latest/developerguide/importing-keys.html

So, you can re-use same material in a different region after failure to recreate KMS keys.

Best,

Didier

profile pictureAWS
전문가
답변함 8달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠