What happened
Amazon Managed Grafana has received FedRAMP High authorization across both AWS GovCloud regions — US-East and US-West — opening the managed observability platform to federal agencies and enterprises bound by the strictest tier of U.S. government cloud security requirements. Separately, Cloudflare documented how a botched DNSSEC key rollover by Albania's .al top-level domain registry knocked the entire TLD offline, forcing Cloudflare's 1.1.1.1 resolver to deploy a Negative Trust Anchor to restore resolution. To accompany that workaround, 1.1.1.1 now returns Extended DNS Error code 33 in responses, giving downstream clients an explicit, machine-readable signal that DNSSEC validation was intentionally bypassed rather than silently suppressed.
Why it matters for your business
For public sector contractors and regulated enterprises, the Grafana authorization removes a significant procurement hurdle: teams can now build unified dashboards across hybrid AWS environments without spinning up a self-managed Grafana deployment that would require its own compliance evidence. On the DNS side, the .al outage is a reminder that DNSSEC misconfigurations at the registry level can instantly render an entire namespace unreachable — and that resolvers sometimes have to make unilateral decisions to restore connectivity. The addition of EDE 33 means security tooling, logging pipelines, and monitoring stacks can now detect and flag those bypass events programmatically rather than relying on manual investigation when validation anomalies appear.
What to watch next
AWS is likely to pursue FedRAMP High authorization for additional managed services as federal cloud adoption accelerates, so compliance-driven procurement teams should track the AWS compliance roadmap closely. On the DNS front, broader adoption of Extended DNS Error codes across other major resolvers — Google Public DNS, Quad9 — will determine whether EDE 33 becomes a reliable industry-wide signal or remains a Cloudflare-specific diagnostic. Registry operators globally should treat the .al incident as a forcing function to audit their own DNSSEC key rollover procedures before a similar failure disrupts their namespace.
