Warm standby rather than active-active. Metadata reads tolerate a 30-minute RTO, and dual-region write consistency for a versioned store is not worth its cost or its failure modes.
The ingestion agent runs inside restricted networks and connects outbound only. No inbound route into a source estate is ever required.
Three availability zones in the primary region; every stateful component has a quorum across them.
Numbers
99.9% read-path availability, RTO 30 min, RPO 5 min.
Aurora global replication lag under 1 minute to the standby region.
Steady state roughly 40 vCPU and 160 GB across the service tier; the graph and index dominate cost, not compute.
Data residency
Both regions are in the EU. A second residency zone would be a separate deployment with its own stores, not a shared multi-region cluster — metadata carries column names and classifications and is treated as regulated content (view 20).