Building blocks
Design goal
Keep recoverable copies available even when production credentials, accounts, or a Region are affected, while making retention and restore responsibilities explicit.
Success criteria
- Centralize backup policy
- Use Vault Lock where immutability is required
- Separate recovery copies by account or Region
- Test restore and access procedures
Architecture
Apply AWS Backup plans to supported resources, store recovery points in encrypted vaults, use Vault Lock for governance or compliance immutability, and create supported cross-account or cross-Region copies when required.
Architecture flow
- AWS workloads
- Backup plan
- Primary vault
- Vault Lock
- Recovery copy vault
- Restore test
Architecture decisions
Choose governance versus compliance mode deliberately
WhyGovernance mode can be changed by sufficiently privileged users, while compliance mode becomes immutable after its grace period and requires careful retention planning.
Trade-offCompliance mode provides stronger immutability but removes operational flexibility after the grace period; governance mode is easier to change but relies more heavily on privileged-access controls.
Use independent copies for broader failure isolation
WhyCross-account or cross-Region copies can reduce dependence on the production account or Region, subject to feature support for the protected resource.
Trade-offCross-account or cross-Region copies improve isolation but add storage, transfer, key-management, and restore-access complexity.
Security
Protect the control and data paths deliberately. Use dedicated backup roles, KMS controls, AWS Organizations policies where appropriate, and destination-vault permissions that prevent workload administrators from deleting independent recovery copies.
Availability
Design for the failure domain that must be survived. Backup copies should be placed across the account or regional failure boundaries that the recovery requirement is intended to survive.
Disaster recovery
Treat regional recovery as a separate operating state. AWS Backup provides recovery data protection; application failover orchestration and service-specific replication may still be required for low RTO/RPO workloads.
Cost drivers
- Backup storage and retention
- Cross-Region data transfer and copy storage
- Cross-account recovery design
- KMS usage
- Restore testing frequency
Design assumptions
- Resource types support the selected AWS Backup copy and retention features
- Compliance-mode retention is approved before the grace period expires
Implementation plan
- Define recovery tiers, backup frequency, retention, and copy requirements before creating policies.
- Create encrypted backup vaults with administration separated from workload operators where the recovery model requires it.
- Configure Vault Lock retention bounds and move to the intended governance or compliance mode only after the policy has been tested.
- Create cross-account or cross-Region copies only where the required failure scope justifies the additional storage and transfer cost.
- Centralize failed-job alerts, vault activity, and compliance reporting, then schedule representative restore tests.
Validate the design
- Confirm Vault Lock state and retention bounds match the approved policy.
- Attempt a controlled prohibited deletion or retention change and confirm the vault blocks it as expected.
- Restore a representative workload from the independent copy and verify the recovered data is usable.
- Simulate loss of the primary account or Region and confirm the recovery team can still access the intended copy.