# Disaster recovery: how do I design an active-passive scenario around RTO and RPO?

> RPO 5min buys continuous cross-region replication and PITR, RTO 30min an IaC-provisioned warm standby behind Route 53 failover, rehearsed on a game-day.

- Asked: 2026-05-31
- Answered: 2026-06-03
- Asked by: Levent
- Tags: dayaniklilik, altyapi, veritabani
- Source: https://muhammetsafak.com/just-ask/disaster-recovery-strategy-setting-rto-and-rpo/
- Language: en-US
- Author: Muhammet Şafak

---
**Question:** AWS Frankfurt (`eu-central-1`) became completely unreachable. Our company policy is RTO 30 minutes (maximum downtime) and RPO 5 minutes (maximum data loss).

To meet these targets, how do I design an active-passive disaster recovery scenario covering the database (cross-region replication), static files and DNS routing (Route 53 latency/failover)?


Short answer: you don't choose the architecture, **RTO 30min / RPO 5min** chooses it. Those two numbers determine, on their own, which disaster recovery strategy you build.

## Short answer

The real issue is this: RPO and RTO aren't abstract goals, they're figures that translate directly into technical decisions. Read the number, build the architecture to match. I covered how a promotion decision should be made inside a single region in [the split-brain and quorum answer](/just-ask/avoiding-postgresql-split-brain-with-quorum-and-consensus/); here the same question is asked at region scale.

## Why

1. **RPO determines replication frequency.** A 5-minute data-loss ceiling rules out nightly dumps from the start; continuous replication is mandatory.

2. **RTO determines your readiness level.** You can't stand up infrastructure from zero in 30 minutes; the second region has to be up and ready to promote.

3. **Active-active is overkill for these numbers.** Complexity you don't need is a cost you shouldn't pay.

## What to do

1. **Set up continuous replication for RPO 5min.** Cross-region streaming replication (or an RDS cross-region read replica) + ship WAL/PITR to S3.

2. **Keep a warm standby for RTO 30min.** Have a pre-provisioned copy in the second region ready to promote.

3. **Provision the infrastructure in advance with IaC.** Define the second region's network, servers and config as code with Terraform; clicking through a setup by hand during a disaster blows the RTO.

4. **Prepare static files and DNS.** Replicate static assets with S3 Cross-Region Replication; use Route 53 health-check / failover routing to swing traffic automatically.

5. **Rehearse the failover regularly (game-day).** An untested disaster recovery plan is nothing but a guess that it'll work.

**Bottom line:** I'd set up a cross-region replica + PITR + Route 53 failover and pre-provision the standby with IaC. Active-passive fits these targets exactly; don't buy complexity you don't need. I separately discuss the cloud-vs-own-server question on sade.dev.

## Related Reading

- [Why is keeping the key in .env risky when encrypting sensitive financial data — what do KMS/Vault give you?](https://muhammetsafak.com/just-ask/encrypting-sensitive-financial-data-at-rest-and-key-management/) — Just Ask
- [How do I rewind to seconds before a disaster with WAL archiving and PITR?](https://muhammetsafak.com/just-ask/point-in-time-recovery-with-wal-archiving/) — Just Ask
- [Health check design: how do I separate Liveness and Readiness?](https://muhammetsafak.com/just-ask/health-check-design-liveness-vs-readiness/) — Just Ask
