7 comments

[ 0.32 ms ] story [ 22.9 ms ] thread
This seems like a pretty catastrophic failure on Amazon’s part. It seems pretty incompetent actually. You should have multiple copies of your customer’s data across multiple locations.

And these multiple locations should be in different parts of the world. Not concentrated in one highly volatile region.

All this seems like common sense to me honestly. Anyone with more knowledge than me know why Amazon didn’t do this?

AWS go to great lengths to explain what Az replication Vs geo replication means in clouds. "All the AZ zones get knocked out" is down to the end user to decide if they want to pay the extra for geo replication and do the paperwork etc to address that risk.

This will definitely surface which people were serious when they said "YAGNI"

> And these multiple locations should be in different parts of the world. Not concentrated in one highly volatile region

AWS can't make that call unilaterally while also keeping to promises of data hosting and legal sovereignty.

It's definitely a long tail event of full data loss/the kind of thing people make jokes about over paranoid resilience planning "what if someone nukes Virginia though?" but it's 99.99999% likely in the Ts & C's

multi region data distribution is available for customers, but it costs more

I put this on the users

You have to pay for that. Some people want to pay less to not have that.
So I literally have a better backup system at home than Amazon?
Your home can survive multiple drone strikes? Wow :)
If AWS eu-west-1 and my house get bombed at the same time, I guess data loss will be the least of my problems. And the really important stuff has copies on DropBox, iCloud, and a physical copy in Brazil.

If all that gets nuked at the same time, humans the survivors won’t need the data.