Skip to content
Blog

AWS Disaster Recovery to Sovereign Infrastructure via Equinix Fabric

Onam Cloud Engineering 4 min read

You run production on AWS ap-south-1 (Mumbai). Your compliance team needs a disaster recovery site that's not on the same hyperscaler, true infrastructure diversity. But your RTO/RPO requirements demand sub 10ms latency to the DR site, public internet won't cut it, and you need the DR environment to be sovereign: Indian jurisdiction, Indian operations, no foreign law exposure.

Onam Cloud at Equinix MB4 connects to AWS Direct Connect via Equinix Fabric, a software defined interconnection platform that provisions private, low latency Layer 2 connections between any two participants on the Equinix campus. No public internet, no shared bandwidth, deterministic latency.

Equinix Fabric is not a VPN tunnel. It's a physical cross connect marketplace: you provision a dedicated Layer 2 circuit between your AWS Direct Connect port, hosted at Equinix Mumbai, and Onam Cloud's network edge, also at Equinix Mumbai. The traffic never leaves the building. First, AWS maintains a physical presence at Equinix Mumbai, and you provision a Hosted or Dedicated Direct Connect port through the AWS console. Second, from the Equinix portal, you create a virtual connection between your AWS Direct Connect port and Onam Cloud's network service profile, a software defined circuit provisioned in minutes, not weeks. Third, Onam Cloud's edge routers peer with your AWS Virtual Private Gateway over the private VLAN, and your VPCs can reach Onam Cloud's DR network directly. Fourth, database replication, object sync, and Kubernetes state all flow over this dedicated circuit at sub-2ms round trip, with no internet egress charges from AWS since Direct Connect pricing applies instead.

With sub-2ms latency on a private circuit, you can run near synchronous replication. Databases stream to hot standby replicas on Onam Cloud with an RPO measured in seconds and automatic failover promotion. Object storage replicates continuously from AWS S3 to Onam Cloud's Ceph Object Gateway over an S3-compatible API. Kubernetes state is backed up via Velero with GitOps manifests mirrored to a sovereign Git repository, enabling a full cluster rebuild in under 15 minutes. VM snapshots use changed block tracking, transferred nightly over the private circuit for full recovery within RTO targets.

A DR site on another AWS region doesn't solve the sovereignty problem, your backup is still under the same foreign jurisdiction, the same CLOUD Act exposure, the same vendor dependency. If AWS suspends your account, both production and disaster recovery go dark simultaneously. Onam Cloud as your DR target gives you jurisdictional diversity, since your DR is under Indian law and operated by an Indian entity; vendor diversity, since an AWS outage or policy change doesn't affect your DR; key sovereignty, since encryption keys for DR data are held in Onam Cloud's sovereign vault and AWS cannot decrypt your backups even if compelled; and regulatory alignment, since DR data remains within India under Indian jurisdiction, satisfying DPDP Act, RBI, and SEBI requirements by architecture.

Compared to a public internet DR path, Equinix Fabric delivers deterministic sub-2ms latency instead of 5-15ms variable latency, near zero jitter on a dedicated path instead of a shared best effort one, guaranteed bandwidth instead of best effort, and materially lower AWS egress costs under Direct Connect pricing versus standard internet egress.

Setting this up requires coordination across three parties: AWS for the Direct Connect port, Equinix for the Fabric virtual connection, and Onam Cloud for network peering and the DR environment. We handle the Equinix and Onam Cloud sides for you, starting with a discovery call to understand your current AWS architecture and RTO/RPO targets, then a DR architecture design tailored to your workloads, interconnect provisioning with a typical lead time of 3-5 business days, and replication setup and validation with failover drills before you go live.

Run production on AWS. Keep sovereign DR at Onam Cloud. Connect them over Equinix Fabric with sub-2ms private interconnect. No public internet, no shared bandwidth, no single point of jurisdictional failure. True hybrid sovereign disaster recovery, without compromising on latency, security, or compliance.

Want to learn more?

Talk to our team about building sovereign infrastructure for your organisation.

Talk to us