Lesson 395 · AWS Learning Path

AWS 395: Cross-account and cross-Region observability architecture

· Published · 4 min read

Labelled process diagram for AWS 395: Versioned intent to Automated validation to Controlled AWS change to Observed result and retained evidence, with decision, proof and rejection evidence.

Why this lesson matters

Central observability must improve investigation without creating one unrestricted surveillance account or one failure domain. CloudWatch cross-account observability uses regional OAM sinks and source links to view shared telemetry while source data remains owned in source accounts. Cross-Region visibility, durable security archives, and operational access are separate designs.

Architecture choices

PatternStrengthBoundary
OAM cross-account viewQuery/view metrics, logs, traces and supported application data across linked accountsSink and links are Regional; sharing scope and quotas apply
Cross-account/Region dashboardUnified metric/alarm visualizationDoes not replace log/trace regional design
Central log copyIndependent archive/search/retentionDuplicated ingestion, transfer, privacy and replay
Regional monitoring accountsData residency/failure isolationMore tooling, federation and global coordination
External/SIEM streamSpecialized detection and long retentionVendor path, egress, schema and custody

Use a dedicated monitoring account for operations and a separately controlled security archive when duties differ. OAM monitoring accounts create one sink per Region; source accounts create links to the sink and choose resource types such as metrics, log groups, traces, Application Signals services/SLOs, Application Insights or Internet Monitor according to current support. Sink policy can permit account IDs or organization paths/IDs, but each source still needs an explicit link.

Identity and governance

Separate sink administrator, source-link administrator, dashboard/alarm author, investigator, security analyst and archive custodian. Federate humans through approved identity and least-privilege roles. Restrict link creation to approved sink/resource types and detect unauthorized links. An organization-wide sink policy is an invitation boundary, not automatic least privilege.

Classify telemetry because logs/traces can contain customer data, URLs, SQL, tokens, headers and topology. Redact at source, encrypt with controlled keys, limit query/export, log access, set retention/legal hold, and define cross-border rules. Central access must not let operators mutate workloads.

Source-account telemetry ownership remains important: collectors, log groups, metric namespaces, trace sampling and retention can fail locally. A monitoring account outage or OAM link deletion must not disable local alarms or workload recovery. Maintain regional/local minimum alarms and break-glass investigation.

Define onboarding as code: create source telemetry and retention, validate redaction, create approved link, confirm resource filters, run synthetic metric/log/trace probes, verify central and local views, test investigator access, and record owner/cost. Offboarding must retain legally required evidence, remove links and roles, revoke access, archive or delete data by policy, and verify no dashboards/alarms silently depend on the departed account.

Cross-Region and failure design

OAM linking is Regional, so repeat approved sinks/links per Region. Global operations can use cross-account/cross-Region metric dashboards, federated regional views, or copied/streamed data for approved use cases. Do not claim a single Logs Insights/X-Ray query crosses unsupported regional boundaries without verifying current capability.

Define behavior for source account suspended/closed, account moves OUs, link/sink deleted, organization trust changed, Region unavailable, KMS deny, telemetry quota/throttle, delayed ingestion, central account compromise and DNS/identity outage. Infrastructure and telemetry deployment pipelines need canaries and rollback.

Monitor the observability plane itself: expected links by account/Region, sink-policy drift, last telemetry freshness by type, collector failures, query errors, archive lag, access anomalies, cost/cardinality changes and local alarm delivery. Keep this monitoring outside a single central dependency where feasible. A green central dashboard with a broken source link is absence of evidence, not evidence of health.

Read-only inspection and workshop

aws oam list-sinks --region ap-south-1
aws oam get-sink-policy --sink-identifier SINK_ARN --region ap-south-1
aws oam list-links --region ap-south-1
aws oam get-link --link-identifier LINK_ARN --region ap-south-1
aws logs describe-log-groups --include-linked-accounts --region ap-south-1
aws cloudwatch list-metrics --include-linked-accounts --region ap-south-1

Design observability for 80 workload accounts, security/log-archive accounts, development/production OUs, and three Regions. Provide sinks/links/resource filters, identity/RACI, local versus central alarms, privacy/retention, regional query path, durable archive, quotas, onboarding/offboarding, cost allocation, and outage procedures.

Trace one request across three accounts without copying secrets. Specify service/release/trace identity, sampling, source retention, query role, UTC timeline and evidence custody. Test 18 failures: wrong sink policy, source link missing, resource type omitted, namespace/log filter excludes signal, OU move, unauthorized second monitoring account, source KMS deny, Region mismatch, quota, central dashboard wrong Region, central role overprivileged, sensitive field exposed, sampling gap, account closed, sink deleted, monitoring Region outage, archive delivery lag, and central compromise.

Cost and acceptance

Price source telemetry, cross-account trace copies/current rules, dashboards/alarms, query scans, metric streams/subscriptions, cross-Region transfer, copied storage/search, KMS and third-party egress. Confirm current OAM pricing. This lesson creates nothing.

Submit pattern decision, regional topology, sink/link/IAM policies, telemetry classification, account lifecycle, local-survival design, 18 failures, query evidence, cost and decommission. Pass requires regional accuracy, least-privilege access, source redaction, no central control dependency for recovery, and independently protected archives where required.

Official sources

Advertisement