High Availability and Cross-Region Availability

This section describes the High Availability (HA) and Cross-Region Availability (CRA) strategy for Sectona PAM-Cloud. It explains how the platform is designed to maintain service availability, minimize service disruption, and support recovery from infrastructure, Availability Zone, and regional-level failures.

The availability architecture distinguishes between Intra-Region Availability (IRA) and Cross-Region Availability (CRA). IRA provides high availability within the primary region by using redundant components across multiple Availability Zones, protecting against component and zone-level failures. CRA is an optional disaster recovery capability that extends resilience to a separate geographic region, providing recovery capabilities in the event of a primary-region outage.

This section also describes the supported deployment models, workload distribution, redundancy mechanisms, and recovery architecture used to provide resilient and reliable Sectona PAM-Cloud services while supporting defined business continuity, Recovery Time Objective (RTO), and Recovery Point Objective (RPO) requirements.

High Availability

Intra-Region Availability (IRA) provides high availability and fault tolerance within the primary cloud region. It is designed to maintain continuous PAM service availability during component-level and Availability Zone failures without requiring recovery in a separate geographic region.

Key capabilities include:

  • Multi-AZ Deployment: Sectona PAM-Cloud components are deployed across multiple Availability Zones (AZs) within the primary region to improve service availability and resilience.

  • Component Redundancy: Application and supporting components are distributed across multiple AZs, eliminating dependency on a single Availability Zone and reducing the impact of localized infrastructure failures.

  • Automatic Failover: The architecture supports automatic failover when an application instance or an Availability Zone becomes unavailable, allowing traffic to be redirected to healthy, available components.

  • In-Region Resilience: Multi-AZ deployment provides protection against component and Availability Zone failures within the primary region. IRA does not provide protection against a complete regional outage; regional-level recovery is addressed separately through Cross-Region Availability (CRA).

Failover (Optional Add-on License)

Cross-Region Availability (CRA) is an optional add-on capability that extends the Intra-Region Availability (IRA) architecture with a separate regional recovery environment. IRA provides high availability within the primary region, while CRA provides disaster recovery capabilities for a primary-region outage. The CRA architecture maintains standby resources in a separate geographic region to support recovery and restoration of PAM services when the primary region becomes unavailable.

Key failover capabilities include:

  • Cross-Region Recovery Environment: Maintains a dedicated CRA environment in a separate geographic region to provide disaster recovery capabilities for Sectona PAM-Cloud.

  • Standby Infrastructure: Maintains the required PAM components and replicated data in a standby state for use during a regional-level outage.

  • Failover Process: The failover process from the primary IRA environment to the CRA environment includes promoting the standby Vault, activating the required application services, and updating the applicable DNS records to redirect user traffic to the recovery region.

  • Service Restoration: Enables recovery and restoration of Sectona PAM-Cloud services following an outage or disaster affecting the primary region.

  • Business Continuity: Provides an additional recovery layer for environments with defined business continuity and disaster recovery requirements, subject to the applicable CRA configuration, RTO, and RPO.

IRA provides high availability for component and Availability Zone failures within the primary region, while CRA provides recovery for regional failures. CRA is an optional add-on and does not replace IRA.

Component Availability Matrix

The following matrix defines the component-level Recovery Time Objective (RTO) and Recovery Point Objective (RPO) applicable to Sectona PAM-Cloud across Intra-Region Availability (IRA) and Cross-Region Availability (CRA) configurations.

The matrix distinguishes between high availability within the primary region and regional recovery capabilities. IRA addresses component and Availability Zone failures within the primary region, while CRA provides recovery capabilities for regional-level failures.

The specified RTO and RPO values serve as the reference objectives for service continuity, disaster recovery, and business continuity planning and are applicable based on the customer's licensed deployment model and configured CRA capabilities.

Component

IRA Availability Model

IRA RTO

IRA RPO

Application Node

Regional Availability 1

2 minutes

0 minute

Vault Node

Regional Availability 1

2 minutes

1 minute

Video Log Storage

Regional Availability 1

1 minute

0 minute

RNA Proxy

Regional Availability 1

1 minute

0 minute

KMS

Regional Availability

5 minutes

0 minute

Email Gateway

Regional Availability

5 minutes

0 minute

  • 1: indicates that the component is deployed redundantly across multiple Availability Zones within the same region.

  • Recovery Time Objective (RTO): The maximum targeted duration within which a service or component should be restored following a disruption.

  • Recovery Point Objective (RPO): The maximum targeted period of data that may be lost following a disruption.

IRA Recovery Objectives

  • IRA RTO and RPO values represent component-level availability and failover within the primary region. These objectives apply to failures affecting individual components or Availability Zones and do not represent cross-region disaster recovery targets.

CRA Recovery Objectives

  • CRA RTO and RPO values apply to the recovery of Sectona PAM-Cloud services from the primary IRA environment to the CRA environment following a regional-level outage.

  • CRA recovery may be invoked when critical components, such as the Application Node, Vault Node, or Video Log Storage, experience a complete failure that cannot be addressed through IRA redundancy and availability mechanisms.

  • The migration from IRA to CRA can take up to 60 minutes, depending on factors such as the licensed user capacity, vault data size, and video log retention requirements.

CRA Limitations

The following limitations apply while operating in the CRA environment and during subsequent recovery to the primary IRA environment:

  • Video Log Availability: The most recent two days of video logs are unavailable for viewing while the platform is operating in CRA.

  • Video Log Synchronization: After services are migrated from CRA back to IRA, video logs generated during the CRA operating period become available in IRA within 24 hours.

  • Minimum CRA Operating Period: The CRA environment must remain operational for a minimum of 4 hours before initiating a failback to the primary IRA environment.

IRA provides high availability within the primary region, whereas CRA provides regional disaster recovery. CRA is an optional add-on capability and is subject to the customer's licensed deployment model.

Service Availability Matrix

The following matrix identifies the availability of key Sectona PAM-Cloud functions and services in Intra-Region Availability (IRA) and Cross-Region Availability (CRA) configurations.

IRA represents the primary production environment and provides normal PAM operations with high availability within the region. CRA represents the recovery environment used following a regional-level failure. Service availability in CRA may differ from IRA based on the recovery architecture and supported capabilities.

Function/Service

Intra-Region Availability (IRA)

Cross-Region Availability (CRA)

User Authentication & MFA

Yes

Yes

Target Sessions

Yes

Yes

Password Management

Yes

Yes

Asset & Account Discovery

Yes

Yes

Session Management (Video Log)

Yes

No

SIEM & Log Forwarding

Yes

Yes

Ticketing System

Yes

Yes

Satellite Vault

Yes

Yes

Reporting and Analysis

Yes

Yes

Notifications

Yes

Yes

Just-In-Time Access

Yes

Yes

Workflow

Yes

Yes

Email-Based Workflow Approval

Yes

Yes

API

Yes

Yes

Availability Assumption: The Service Availability Matrix represents the availability of Sectona PAM-Cloud services and assumes that the required customer-managed infrastructure, target systems, network connectivity, and dependent services are operational and available. Failures or unavailability within customer-managed infrastructure or external dependencies are outside the scope of the availability commitments represented in this matrix.