4 ms·
(I used to work at aws) The control API (i.e. adding/removing roles, modifying policies, etc.) is available out of us-east-1. However, the bits of IAM that rel
by dastbe 5y ago
(I used to work at aws)
The control API (i.e. adding/removing roles, modifying policies, etc.) is available out of us-east-1. However, the bits of IAM that relate to distributing credentials to instances/tasks/lambdas and STS are all regionalized and isolated.
- dboreham 5y agoSo...parent is correct.
- dastbe 5y agono, because most applications don't have an online dependency for creating roles and modifying policies. what they do typically have an online dependency for is provisioning credentials from those roles, which is architected to be regionally independent.
- t0mas88 5y agoNot really. The parts that can take your app down are distributed.
- sharpy 5y agoDisclaimer: Former AWS engineer, never worked on IAM directly. AWS is divided into multiple partitions. For the vast majority of users, there is one partition - the regular commercial - other partitions being China, GovCloud, etc. Within each partition, there is a primary region that needs to be available for creation/mutation of credentials and policies. However, that data is replicated to other regions within the partition. That means the use of credentials that exist does NOT depend on the primary region being available. The replication is something that is closed monitored, and SLA breaches will result in pages.
- gkop 5y agoHow about credential revocation, is that dependent on the health of the primary region?