All Products
Search
Document Center

Key Management Service:Manage cross-region resource synchronization

Last Updated:Aug 20, 2026

After you configure cross-region resource synchronization for a KMS primary instance, you can view the synchronized resources, update the resources to synchronize, and add or remove replica instances. This helps you maintain consistent key and secret management across regions for disaster recovery and data compliance.

View synchronized resources from the primary instance

  1. Log on to the Key Management Service console. In the top navigation bar, select a region. In the left-side navigation pane, choose Security Operations > Disaster Recovery > Cross-region Synchronization.

  2. Find the target primary instance and click Manage in the Actions column.

  3. View the synchronized resources:

    1. On the details page, click the Replica Instance tab. Find the target replica instance, then click View Synchronized Resources in the Actions column.

    2. In the View Synchronized Resources panel, filter by Resource Type. The available options are Key and Secret.

  4. On the Key Sync Resources tab of the details page, view the synchronization information for keys of the primary instance, including the Resource ID (key ID), Replica Instance ID, Synchronization Status, and Failure Cause.

  5. On the Secret Sync Resources tab of the details page, view the synchronization information for secrets of the primary instance, including the Resource ID (secret name), Replica Instance ID, Synchronization Status, and Failure Cause. Filter by Replica Instance ID.

Update synchronization resources

You can add resources to an existing synchronization task. However, you cannot remove resources that are already being synchronized.

  1. Go to the primary instance details page. On the Replica Instance tab, click Update Synchronization Resources to modify the resources to be synchronized.

  2. In the update panel, in the Key Sync Type and Secret Sync Type sections, select the keys or secrets to synchronize, and then click Next.

    Note

    Only adding synchronization resources is supported. Resources that have already been manually selected for synchronization cannot be removed.

  3. On the Confirm Configurations step, review the configuration information, and then click OK.

Add a new replica instance

  1. Go to the primary instance details page. On the Replica Instance tab, click Add Replica Instance.

  2. Select a replica instance and configure Synchronize Resources. For more information, see Synchronize resources across KMS instances.

Disassociate a replica instance

Warning

After disassociation, the binding cannot be restored, and you cannot create new keys or secrets in the replica instance. Proceed with caution.

  1. Go to the primary instance details page. On the Replica Instance tab, click Remove Replica Instance in the Actions column of the target replica instance.

  2. In the Remove Replica Instance dialog box, click OK.