AWS Backup's tamper-resistant vaults now reach 6 more regions!
Hey there, it's Shiichan! Today I found a security-focused update from AWS Backup, so let me walk you through it. This one's for anyone who wants their backups locked down tight!
AWS What's NewWhat was announced?
Over on AWS What's New, AWS announced that AWS Backup's logically air-gapped vault is now available in six additional AWS Regions.
The newly supported regions are:
- Asia Pacific (Taipei)
- Asia Pacific (Malaysia)
- Asia Pacific (New Zealand)
- Asia Pacific (Thailand)
- Mexico (Central)
- Canada West (Calgary)
Why it matters
A logically air-gapped vault stores immutable, isolated backups that can't be tampered with. It's locked by default and can be encrypted with AWS owned keys or customer-managed keys. It's meant to be the last line of defense for backups against ransomware and disaster recovery scenarios.
Features like this only help if they're available where you actually operate, so expanding regional coverage directly translates into more places you can actually use it.
What changes
In these newly supported regions, you can now:
- Back up directly to a vault
- Copy backups across accounts and regions
- Share vaults for recovery using AWS Resource Access Manager (RAM)
- Safeguard vault access during account compromise with Multi-party approval
You can get started from the AWS Backup console, AWS CLI, or AWS SDKs. Check the AWS Backup documentation and pricing page for the full list of supported regions, features, and costs.
Wrap-up
- Logically air-gapped vaults now support Taipei, Malaysia, New Zealand, Thailand, Mexico (Central), and Canada West (Calgary)
- You get immutable, isolated backups that are locked and encrypted by default
- Cross-account/cross-region copy, RAM sharing, and Multi-party approval are all available too
This update is worth checking out if you run workloads globally and are looking at isolating backups as part of your ransomware defense!