DRQ · data residency quarantine

Independent AWS measurement pilot — historical two-region proposal

Issue #184. Superseded by the owner's 23 September wider-coverage direction and full in-scope provisioning approval. See the expanded coverage and price assessment. The two-region scope, approval-pending statements and US$10 estimate below describe the earlier proposal, not the current delivery scope. No deployment is claimed by either proposal.

Resources and purpose

Owner direction on 22 September restricts this pilot to Sydney (ap-southeast-2) and Melbourne (ap-southeast-4). These provide Australian sources on a provider independent of Cloudflare; overseas comparisons remain with the existing Cloudflare origins and retained foreign control. A provider region identifies the execution region, not an exact server building. The earlier four-region proposal is superseded; no overseas AWS resource is included.

In each region, declare through Alchemy:

The first collection mode measures fresh synthetic R2 PUT, HEAD and full GET through the S3 API, using the retained replacement candidate and EU control. Bucket-scoped probe credentials and generated keys must restrict the configured targets; no consumer payload is read. Also measure small AWS regional S3 references with identities retained. Ten trials per target/reference are the starting limit, not a reason to erase incomplete runs.

Each schedule runs and saves its evidence in its own AWS region without calling a Cloudflare measurement Worker or requiring the DRQ ledger to be online. Duplicate schedule deliveries must reuse their slot identity; before any measurement, atomically claim that slot with a conditional S3 write. Accept only the current 15-minute slot within two minutes of its scheduled start. A claimed slot is never automatically repeated, including after an interrupted run; its missing result remains visible. Disable Lambda asynchronous retries as well as Scheduler retries. The readback reports missing slots and partial failures. Successful S3 operations and HTTP endpoint timings remain distinct from Cloudflare native-binding measurements.

First prove independent AWS-to-R2 and AWS-to-AWS capture. Then connect authenticated Cloudflare-to-AWS reference reads using these same two regional reference objects; do not add a public arbitrary-URL probe endpoint or count that path as independent of its Cloudflare caller. AWS evidence collection must keep working when that Cloudflare path is unavailable.

Existing Alchemy and Distilled APIs

Use the existing Alchemy/Distilled dependency; no second AWS client or hand-built signing layer is needed. Alchemy AWS/Region exposes the provider region, AWS/Account/Region manages opt-in, and AWS/Pricing/GetProducts with GetProductsHttp queries the price catalogue. Distilled supplies account.listRegions, account.getRegionOptStatus and pricing.getProducts for operator reads. These interfaces were read in the local canonical mirrors and confirmed in the installed dependencies. A read-only call through the installed Distilled pricing.getProducts succeeded for both Australian regions at 16:15 AEST; each returned one Lambda duration product without pagination. The raw catalogue responses remain in private evidence roadmap-184-au-distilled-pricing.json.

The shared localisation check must reject planned AWS resources whose captured live provider region is absent or outside Sydney/Melbourne, including resources not declared as public entries. The region must come from the provider registration, not the caller's ambient AWS_REGION. Read-only price queries are different: Alchemy deliberately directs its global catalogue requests to us-east-1; that does not create an overseas resource. Do not disable other account regions or alter other agents' resources.

Provider-region checking alone does not constrain cross-region replication, service-global behaviour, referenced resources or runtime calls. The pilot's concrete resource configuration and IAM permissions must separately restrict compute, schedules, evidence buckets and logs to the two Australian regions, omit replication, and allow only its fixed target/reference operations. No account-wide IAM or Organizations change is proposed.

Account readiness and executable bounds

Read-only checks at 14:54–14:57 AEST, repeated and saved at 15:00 AEST in private evidence roadmap-184-aws-account-readiness.json, confirmed both selected Australian regions are enabled, including Melbourne's opt-in (the original read-only inspection also covered the two regions subsequently removed from this proposal). Each region currently reports Lambda concurrency 10, all unreserved. AWS's reserved-concurrency requirements leave an unreserved minimum, so this plan does not depend on reserving one execution or increasing account quotas.

Use the private evidence bucket for a conditional slot claim and one final result, within the existing two-write allowance. Only the invocation that creates the claim may probe; competing deliveries return without repeating measurements. The two-minute start window and two-minute Lambda lifetime fit inside the 15-minute interval. Only the fixed schedule role may invoke the probe during normal operation; no public function URL is created. This bounds measurement work, not the number of brief duplicate Lambda invocations, so test duplicate delivery and preserve their short operational summaries.

The Alchemy Lambda resource defaults to a public function URL; explicitly disable it. Its code upload has a direct Lambda ZIP path when no asset-bucket service is supplied. The default AWS provider bundle supplies that service, so use the required resource providers without it; do not bootstrap an additional bucket. Check the planned resource list before deployment; this approval covers only the resources named above.

Monthly cost and limit

Request: approve a US$10/month pilot budget, before tax. The estimate below deliberately ignores shared free allowances and uses 31 days for the monthly ceiling calculation, although the initial schedules end after 30 days. This is a workload budget and estimate, not a promise that AWS billing is a hard-capped account.

Component Calculation / assumption Estimated US$/month
Lambda compute 2 × 96/day × 31 days × 120 seconds × 0.125 GB × $0.0000166667/GB-second 1.49
Lambda requests and scheduling 5,952 invocations; $0.20/million requests and $1/million schedules 0.01
S3 evidence writes, reference reads and storage At most two writes/slot, ten reads of two references/slot, result at most 64 KiB; under 1 GB retained after a month 0.18
CloudWatch summaries At most 8 KiB/invocation including runtime summaries, under 0.05 GB/month 0.05
Network allowance About 2 GB internet egress/month plus small cross-region reference traffic 0.33
R2 operations 119,040 PUT and 238,080 HEAD/GET/month; reserve one additional billed million of each class 4.86
Total estimate Conservative duration and R2 billing-unit rounding 6.92

The normal compute bill should be lower when rounds finish before 120 seconds. At the scheduled workload the reserved US$10 covers the estimate; increasing targets, cadence, duration, memory or public invocation surface requires a revised calculation. Existing Cloudflare-native rounds are outside this incremental AWS pilot estimate. No provisioned concurrency or paid secret-manager resource is included; use AWS-managed encryption for the limited probe configuration.

After the schedules stop, retaining this pilot's evidence costs approximately US$0.02/month at the stated size, plus its small retained log volume. Continuation is a separate cadence/budget decision, and evidence remains available for replay.

Verification before promotion

Keep this capture observational. Verify regional execution, target and reference identities, idempotent schedule slots, bounded retries/timeouts and per-region retained partial results. Disable Cloudflare capture during acceptance and demonstrate AWS collection still completes; make one AWS source unavailable and demonstrate the other regions keep collecting. Restore only the tested measurement path afterward. No independent ledger failover or new qualification is implied.

Use the existing inventory and Alchemy ownership decisions: register the probe resources and add focused live identity readback for the new resource types rather than claim that the current API-Gateway-only AWS inventory covers them. The source composition remains explicit under ADR-0021, executable limits under ADR-0025, ownership under ADR-0029 and consumer admission under ADR-0033. Promote a new qualification rule only after the separately planned control, contradiction and held-out/outage validation.

Price evidence

Prices checked 22 September 2026 against the public AWS regional price-list offers for AWSLambda, AmazonS3, AmazonCloudWatch and AWSDataTransfer, in the four originally proposed regions; this revision uses only the Sydney/Melbourne extracts. Saved extracts remain with the private #184 operational evidence under roadmap-184-aws-*-pricing-<region>.json.