In brief: AWS cannot restore access to its damaged infrastructure in Bahrain or to one of three zones in the United Arab Emirates. In Bahrain, physical damage extended across multiple Availability Zones. This is the rare failure class that Multi-AZ alone cannot cover.
An entire region, not a single zone
The key sentence appears in AWS's September 14 status update: damage affected multiple Availability Zones and exceeded what regional and multi-AZ services are designed to withstand. Reuters reported on September 15 that AWS is helping affected Bahrain customers rebuild operations in other regions.
Availability Zones comprise one or more data centres within the same region. Multi-AZ services distribute data and workloads across them. That design handles a site outage or isolated infrastructure failure. Simultaneous physical damage across several zones is a correlated regional event, not a routine fault.
The infrastructure had already been damaged in March during the war with Iran. AWS then reported structural damage, disrupted power delivery and additional water damage from fire suppression. In April, the company still expected restoration to take several months. The latest statement is more severe: access to the named locations cannot be restored.
Pandorex Analysis
Multi-AZ is useful, but it is not a substitute for cross-region disaster recovery. Critical systems need tested recovery in a second region, remote backups, and realistic recovery-point and recovery-time objectives.
The hardest dependencies are often outside the virtual machines. Identity, key management, DNS, configuration data and regional services must also remain available beyond the primary region. Regulated workloads add data-residency constraints and extra latency. An architecture that examines these limits only during a regional outage may have redundancy on paper without a dependable recovery plan.
