Back to news

AWS adds auto-tiered log storage; Cloudflare flags DNSSEC bypass in DNS responses

Two infrastructure updates reshape how teams handle log costs and DNS trust signals at scale.

AWS adds auto-tiered log storage; Cloudflare flags DNSSEC bypass in DNS responses

What happened

Amazon CloudWatch Logs launched intelligent storage tiering, an automated system that sorts log data across three tiers — Standard, Infrequent Access, and Archive Instant Access — based on observed access patterns, with no manual intervention required. The feature allows organizations to retain logs for longer periods while paying lower storage rates on data that is rarely queried. Separately, Cloudflare detailed how a failed DNSSEC key rollover knocked the entire .al country-code TLD offline, forcing the company to deploy a Negative Trust Anchor (NTA) to restore resolution for affected domains. To address the opacity that has historically surrounded NTA deployments, Cloudflare's 1.1.1.1 resolver now returns Extended DNS Error code 33 in responses, explicitly signaling to clients that DNSSEC validation was bypassed rather than silently succeeding.

Why it matters for your business

For engineering and operations teams, CloudWatch's intelligent tiering removes a persistent cost-versus-retention tradeoff: logs that age out of active use are automatically moved to cheaper tiers without requiring custom lifecycle rules or manual audits. This is particularly relevant for compliance-heavy industries where long-term log retention is mandatory but storage budgets are constrained. On the DNS side, the introduction of EDE 33 gives security teams an actionable signal when DNSSEC validation is being bypassed — previously, a silent NTA deployment was indistinguishable from a clean resolution, creating a blind spot for anyone monitoring DNS integrity. Organizations running their own resolvers or depending on third-party DNS providers should verify whether their tooling surfaces extended error codes, since the transparency benefit only materializes if the downstream stack can read and alert on EDE responses.

What to watch next

AWS has not yet detailed how intelligent tiering interacts with existing metric filters or CloudWatch Logs Insights queries against archived data, so teams should validate retrieval latency before assuming seamless access across all tiers. On the DNS front, broader adoption of EDE codes across other public resolvers and enterprise DNS products will determine whether EDE 33 becomes a reliable cross-platform trust signal or remains a Cloudflare-specific feature. The .al incident also renews attention on registry-level DNSSEC operational hygiene, and further TLD outages tied to misconfigured rollovers remain a credible risk.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp