8 ms·
Disclaimer: Former AWS engineer, never worked on IAM directly. AWS is divided into multiple partitions. For the vast majority of users, there is one partition
by sharpy 5y ago
Disclaimer: Former AWS engineer, never worked on IAM directly.
AWS is divided into multiple partitions. For the vast majority of users, there is one partition - the regular commercial - other partitions being China, GovCloud, etc.
Within each partition, there is a primary region that needs to be available for creation/mutation of credentials and policies. However, that data is replicated to other regions within the partition. That means the use of credentials that exist does NOT depend on the primary region being available. The replication is something that is closed monitored, and SLA breaches will result in pages.
- gkop 5y agoHow about credential revocation, is that dependent on the health of the primary region?