← AWS Solutions Architect Professional: complex decisions
03 / 8 · 40 MIN

Resilience, state, and releases

Prepare service recovery and compatibility during changes.

Concept and mechanism

RTO describes the service recovery time objective; RPO concerns tolerable data loss. An 18-minute restore followed by eight minutes of configuration and ten of validation takes 36 minutes if stages are sequential. It cannot be presented as meeting a 30-minute RTO just because data returned quickly. Include identity, quotas, capacity, and dependencies. Warm standby maintains a functional application at reduced capacity; pilot light retains essential elements but still requires activating more components. Labels help compare design and cost, but do not guarantee actual timings for your service.

Guided application

With Aurora Global Database, distinguish planned switchover with healthy Regions from failover after disaster. Emergency promotion may involve loss associated with asynchronous replication; the last lag measurement does not prove exactly which transactions were lost. Prepare write authority and reconciliation. In blue/green releases, shifting traffic does not reverse destructive schema changes. Expansion, compatible code, migration, and later removal can preserve alternatives during transition when rehearsed. For a replicated logical deletion, the second Region may contain the same error. A recoverable historical point and validated restoration method are needed, not merely another copy of current state.

IN PRACTICE

Blue remains available, but green deleted a column blue uses. Returning traffic does not restore that column.

Common pitfalls

Replication as historical backup; lag as exact loss; promotion as complete readiness; traffic rollback as data rollback.

Related topics: Security, performance, and cost in design · Operations, evidence, and remediation

Take this idea with you

Design and rehearse state and service recovery with explicit decision criteria.

Create account

Reference: Disaster recovery options on AWS · SAP-C02