HN user

TonyCoffman

18 karma
Posts0
Comments9
View on HN
No posts found.

The Route53 control plane is in us-east-1, with an optional temporary auto-failover to us-west-2 during outages. The data plane for public zones is globally distributed and highly resilient, with a 100% SLA. It continues to serve DNS records during regular control plane outages in us-east-1, but access to make changes is lost during outages.

CloudFront CDN has a similar setup. The SSL certificate and key have to be hosted in us-east-1 for control plane operations but once deployed, the public data plane is globally or regionally dispersed. There is no auto failover for the cert dependency yet. The SLA is only three 9s. Also depends on Route53.

The elephant in the room for hyperscalers is the potential for rogue employees or a cyber attack on a control plane. Considering the high stakes and economic criticality of these platforms, both are inevitable and both have likely already happened.

This is an artifact of how the Japanese system works. In a nutshell, they track households (families) with individuals as sub records of the family record.

Everybody on the family register record shares the same surname. Non-citizens are listed as distrinct references (for foreign spouses and the like) and they may have a different surname from the household record.

There is more to it than this but that is the key thing to know about the system.

AWS us-east-1 down 3 years ago

December 22, 2021 was the last partial impact we had in us-east-1 for EC2 instances. They had power issues in USE1-AZ4 that took a while to sort out.

Eucalyptus built a clone. It wasn’t one click but it also wasn’t hard to deploy. It really never made much of a dent.

I’m pretty sure it ended up where all software goes to die: HP.