Slide 21
Slide 21 text
Multi-Account/Region Gotchas
AWS
2
1
• When deploying robust, fault-tolerant infra across accounts
and regions be aware of secrets and encryption
• To use Secret Manager secrets across accounts, specific
policies on the secret must be set
• This is cumbersome
• To use secrets across regions in the same account, Secret
Manager secret replication is ideal
• When encrypting in multiple accounts/regions, KMS keys
must be managed.
• Each account/region has it’s own master keys, which is
used in many instances as the default KMS key to
encrypt with