<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>China on Martin Liu's Blog</title><link>https://martinliu.cn/en/tags/china/</link><description>Recent content in China on Martin Liu's Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Fri, 09 Oct 2026 16:01:45 +0800</lastBuildDate><atom:link href="https://martinliu.cn/en/tags/china/index.xml" rel="self" type="application/rss+xml"/><item><title>AWS China in Practice: The Real Gaps Beyond the Service Catalog</title><link>https://martinliu.cn/en/blog/aws-china-region-gap-beyond-catalog/</link><pubDate>Wed, 07 Oct 2026 15:00:00 +0800</pubDate><guid>https://martinliu.cn/en/blog/aws-china-region-gap-beyond-catalog/</guid><description>&lt;img src="https://martinliu.cn/blog/aws-china-region-gap-beyond-catalog/insight-aws-china-gap.webp" alt="Featured image of post AWS China in Practice: The Real Gaps Beyond the Service Catalog" /&gt;&lt;p&gt;Which services are available in AWS China? I answered that question in the &lt;a class="link" href="https://martinliu.cn/chinaready/" &gt;Chinaready parity checklist&lt;/a&gt;: 120 service rows, how Beijing and Ningxia split the coverage, and the absence of Bedrock, Q, Connect, and friends. Teams who have actually built on AWS China know the catalog is only the first gate. Even when a service has a checkmark, the real gap with AWS Global begins the moment you open the console.&lt;/p&gt;
&lt;p&gt;This article is not another catalog comparison. Over several days I ran read-only API calls against the Beijing and Ningxia regions with a pair of accounts, and measured the gaps behind the checkmarks across five dimensions: version, features, quotas, experience, and cost. Before your next China architecture review or PoC planning session, these are the numbers you want in your back pocket. The article will be updated as testing continues (data collected 2026-10-07/09).&lt;/p&gt;
&lt;h2 id="five-dimensions-from-is-it-listed-to-does-it-work"&gt;Five Dimensions: From &amp;ldquo;Is It Listed&amp;rdquo; to &amp;ldquo;Does It Work&amp;rdquo;
&lt;/h2&gt;&lt;p&gt;The catalog answers a binary question: listed or not. Whether a service actually works in China takes at least five layers.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Dimension&lt;/th&gt;
&lt;th&gt;Question&lt;/th&gt;
&lt;th&gt;What a gap means in practice&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Version&lt;/td&gt;
&lt;td&gt;Are engine/runtime/API versions in sync?&lt;/td&gt;
&lt;td&gt;New features unavailable, migration scripts break, docs mismatch&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Features&lt;/td&gt;
&lt;td&gt;Are key sub-features (integrations, regional linkage, managed options) present?&lt;/td&gt;
&lt;td&gt;You discover mid-build that you have to roll your own&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Quotas&lt;/td&gt;
&lt;td&gt;Do default quotas and increase paths match Global?&lt;/td&gt;
&lt;td&gt;Test day arrives and you cannot launch instances&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Experience&lt;/td&gt;
&lt;td&gt;Do docs, sample code, and tooling work?&lt;/td&gt;
&lt;td&gt;Following the official tutorial step by step into an error&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cost&lt;/td&gt;
&lt;td&gt;Are pricing structure, free tiers, and billing consistent?&lt;/td&gt;
&lt;td&gt;Your PoC budget doubles&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;A concrete example first. Deploy a static site with CloudFront in Global and you can use a free AWS-managed SSL certificate alongside it. In China that path is closed: managed free certificates do not work with CloudFront, so HTTPS means uploading and maintaining your own certificate. Nothing in the catalog hints at this. You only find out by doing.&lt;/p&gt;
&lt;p&gt;Each section below gives the measured data first, then the conclusions.&lt;/p&gt;
&lt;h2 id="version-core-services-are-in-sync--dont-trust-the-stereotype"&gt;Version: Core Services Are in Sync — Don&amp;rsquo;t Trust the Stereotype
&lt;/h2&gt;&lt;p&gt;I went through 18 common engines and components across three regions. The result contradicts most expectations: &lt;strong&gt;version lag is not the main problem in AWS China&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Open-source database engines&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Engine&lt;/th&gt;
&lt;th&gt;us-east-1&lt;/th&gt;
&lt;th&gt;Beijing&lt;/th&gt;
&lt;th&gt;Ningxia&lt;/th&gt;
&lt;th&gt;Verdict&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;RDS MySQL&lt;/td&gt;
&lt;td&gt;8.4.9&lt;/td&gt;
&lt;td&gt;8.4.9&lt;/td&gt;
&lt;td&gt;8.4.9&lt;/td&gt;
&lt;td&gt;Fully in sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;RDS PostgreSQL&lt;/td&gt;
&lt;td&gt;18.6 (56 versions)&lt;/td&gt;
&lt;td&gt;18.6 (45 versions)&lt;/td&gt;
&lt;td&gt;Same as Beijing&lt;/td&gt;
&lt;td&gt;Latest in sync, 11 fewer historical versions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;RDS MariaDB&lt;/td&gt;
&lt;td&gt;12.3.3&lt;/td&gt;
&lt;td&gt;12.3.3&lt;/td&gt;
&lt;td&gt;12.3.3&lt;/td&gt;
&lt;td&gt;Fully in sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Aurora MySQL 8.x&lt;/td&gt;
&lt;td&gt;3.13.0&lt;/td&gt;
&lt;td&gt;3.13.0&lt;/td&gt;
&lt;td&gt;3.13.0&lt;/td&gt;
&lt;td&gt;Latest in sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Aurora PostgreSQL&lt;/td&gt;
&lt;td&gt;18.6&lt;/td&gt;
&lt;td&gt;18.4&lt;/td&gt;
&lt;td&gt;18.4&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;2 minor versions behind&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DocumentDB&lt;/td&gt;
&lt;td&gt;8.0.2&lt;/td&gt;
&lt;td&gt;8.0.2&lt;/td&gt;
&lt;td&gt;8.0.2&lt;/td&gt;
&lt;td&gt;Fully in sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Neptune&lt;/td&gt;
&lt;td&gt;1.4.8.0&lt;/td&gt;
&lt;td&gt;1.4.8.0&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;1.4.8.1&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Ningxia is actually newest&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Cache, search, and messaging&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Engine&lt;/th&gt;
&lt;th&gt;us-east-1&lt;/th&gt;
&lt;th&gt;Beijing&lt;/th&gt;
&lt;th&gt;Ningxia&lt;/th&gt;
&lt;th&gt;Verdict&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;ElastiCache Redis / Valkey / Memcached&lt;/td&gt;
&lt;td&gt;7.1 / 9.1 / 1.6.6&lt;/td&gt;
&lt;td&gt;Same&lt;/td&gt;
&lt;td&gt;Same&lt;/td&gt;
&lt;td&gt;Fully in sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MemoryDB Redis / Valkey&lt;/td&gt;
&lt;td&gt;7.1 / 7.3&lt;/td&gt;
&lt;td&gt;Same&lt;/td&gt;
&lt;td&gt;Same&lt;/td&gt;
&lt;td&gt;Fully in sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;OpenSearch&lt;/td&gt;
&lt;td&gt;3.7 (36 versions)&lt;/td&gt;
&lt;td&gt;3.7 (36 versions)&lt;/td&gt;
&lt;td&gt;3.7 (36 versions)&lt;/td&gt;
&lt;td&gt;Fully in sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Amazon MQ RabbitMQ&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;4.3&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;4.2&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;4.2&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;1 major version behind&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Amazon MQ ActiveMQ&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;5.19&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;5.18&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;5.18&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;1 major version behind&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Containers&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;th&gt;us-east-1&lt;/th&gt;
&lt;th&gt;Ningxia&lt;/th&gt;
&lt;th&gt;Verdict&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;EKS cluster versions&lt;/td&gt;
&lt;td&gt;1.32–1.37&lt;/td&gt;
&lt;td&gt;1.32–1.37 (identical)&lt;/td&gt;
&lt;td&gt;In sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EKS vpc-cni addon&lt;/td&gt;
&lt;td&gt;117 versions&lt;/td&gt;
&lt;td&gt;117 versions&lt;/td&gt;
&lt;td&gt;In sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EKS aws-ebs-csi-driver&lt;/td&gt;
&lt;td&gt;100 versions&lt;/td&gt;
&lt;td&gt;100 versions&lt;/td&gt;
&lt;td&gt;In sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EKS pod-identity-agent&lt;/td&gt;
&lt;td&gt;17 versions&lt;/td&gt;
&lt;td&gt;17 versions&lt;/td&gt;
&lt;td&gt;In sync&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EKS Auto Mode&lt;/td&gt;
&lt;td&gt;Available&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Available&lt;/strong&gt; (verified)&lt;/td&gt;
&lt;td&gt;In sync&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;14 out of 18 are fully in sync. The open-source database line is the tightest: MySQL, MariaDB, and DocumentDB all match the latest version, and even Valkey, an engine that only appeared in 2024, is current. The widely repeated claim that &amp;ldquo;database versions lag in AWS China&amp;rdquo; is not supported by measurement.&lt;/p&gt;
&lt;p&gt;Three gaps belong on your selection checklist. Aurora PostgreSQL sits two minor versions behind, so version-sensitive teams should read the version numbers before migrating. Amazon MQ is the only service among all 18 with a major-version gap: RabbitMQ and ActiveMQ are each one major version behind, and messaging-heavy architectures should price that in. One odd detail: the latest Neptune 1.4.8.1 exists only in Ningxia while Beijing is still on 1.4.8.0. Small inter-region skews are real; pick your region with eyes open.&lt;/p&gt;
&lt;p&gt;EKS Auto Mode deserves its own paragraph. The managed mode, launched at the end of 2024, works in China too. You will not find a toggle for it in the API listing. I probed it by calling create-cluster with a computeConfig payload: the server error came back quoting Auto Mode&amp;rsquo;s configuration-completeness rule, which means the validation logic is live. For migration teams this is unambiguously good news: EKS&amp;rsquo;s newest managed form factor adds zero extra gap.&lt;/p&gt;
&lt;p&gt;The big picture is clear. AWS China has roughly a third of Global&amp;rsquo;s service count, but almost the entire core layer (EKS, RDS, Aurora, ElastiCache, OpenSearch) is version-current. What actually falls behind are two categories: policy-sensitive services (SES, SMS, anything touching personal identity data) and the new AI line (Bedrock, Q, CodeWhisperer). If your architecture leans on the former, version is a non-issue. If it leans on the latter, what is missing is the entire service, not a version.&lt;/p&gt;
&lt;h2 id="features-the-switches-that-go-gray-after-the-checkmark"&gt;Features: The Switches That Go Gray After the Checkmark
&lt;/h2&gt;&lt;p&gt;This section covers two kinds of problems: entire product lines that are absent (Bedrock, training-grade GPUs), and services that exist with key sub-features grayed out (CloudFront certificates, Route 53 traffic policies).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Table 1: AI, edge, and compute features&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Service&lt;/th&gt;
&lt;th&gt;In Global&lt;/th&gt;
&lt;th&gt;Measured in China&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;CloudFront&lt;/td&gt;
&lt;td&gt;Available (global CDN)&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;End of support announced&lt;/strong&gt;: AWS will discontinue CloudFront in the China (Ningxia) region on May 31, 2027. &lt;a class="link" href="https://www.amazonaws.cn/cloudfront/#end-of-support-notice" target="_blank" rel="noopener"
&gt;Official notice&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EC2 instance types&lt;/td&gt;
&lt;td&gt;1,375&lt;/td&gt;
&lt;td&gt;Beijing 432 / Ningxia 461, &lt;strong&gt;about one third of Global&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EC2 GPU chips&lt;/td&gt;
&lt;td&gt;9: T4/A10G/L4/L40S/A100/H100/H200/Trainium etc.&lt;/td&gt;
&lt;td&gt;Only NVIDIA T4 (2018), NVIDIA A10G (2021), and AWS Inferentia (2020). &lt;strong&gt;No A100/H100-class training cards&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EC2 GPU sizes within a family&lt;/td&gt;
&lt;td&gt;g4dn 7 / g5 8 / inf1 4 sizes&lt;/td&gt;
&lt;td&gt;g4dn 7 / g5 8 / inf1 4 sizes. &lt;strong&gt;No shrinkage within families&lt;/strong&gt;. What is missing is whole product lines: g6, inf2, p4d, p5, trn1, 11 families entirely absent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Bedrock&lt;/td&gt;
&lt;td&gt;Available (122 models)&lt;/td&gt;
&lt;td&gt;Not deployed at all, not &amp;ldquo;coming soon&amp;rdquo;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Rekognition / Textract / Translate / Polly / Q / CodeWhisperer / OpenSearch Serverless&lt;/td&gt;
&lt;td&gt;Mostly available&lt;/td&gt;
&lt;td&gt;None available in Beijing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Route 53&lt;/td&gt;
&lt;td&gt;Available (full)&lt;/td&gt;
&lt;td&gt;Ningxia only. Hosted Zones and health checks work; traffic policies do not; no domain registration&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The most important signal in this table is CloudFront&amp;rsquo;s fate: AWS has officially announced the end of support for the Ningxia region on May 31, 2027. If CloudFront is in your China architecture, start planning the replacement now. This is not a feature gap; it is a service exit.&lt;/p&gt;
&lt;p&gt;On the AI line, two conclusions. First, the most powerful single machine you can get in China is g5.48xlarge: 8 A10G cards with 24 GB each. Inference for models that fit in 24 GB works; training or fine-tuning anything above 70B parameters currently has no answer. Second, the managed AI APIs are absent wholesale: beyond Bedrock, Rekognition, Textract, Translate, Polly, Q, and CodeWhisperer are all unavailable in Beijing. SageMaker is the only fully functional AI service. Running AI in AWS China means a SageMaker do-it-yourself build as essentially the only official path, and that path hits the first wall: there are no large-memory training cards. Both walls stand together.&lt;/p&gt;
&lt;p&gt;Beyond API probes, I clicked through the CloudFront, S3, and Route 53 consoles region by region. The manual comparison agrees with the APIs: these services expose visibly fewer options in China.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://martinliu.cn/blog/aws-china-region-gap-beyond-catalog/china-route53-s3-cloudfront.png"
width="920"
height="641"
srcset="https://martinliu.cn/blog/aws-china-region-gap-beyond-catalog/china-route53-s3-cloudfront_hu_6d9eb06e5dce9752.png 480w, https://martinliu.cn/blog/aws-china-region-gap-beyond-catalog/china-route53-s3-cloudfront_hu_a25a0b84ba6b18a2.png 1024w"
loading="lazy"
alt="Feature gap in China"
class="gallery-image"
data-flex-grow="143"
data-flex-basis="344px"
&gt;
&lt;/p&gt;
&lt;p&gt;There is a quieter category that is easy to miss: data and governance plumbing. These services do not vanish wholesale the way AI does; the traps are better hidden. I tested seven of them.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Table 2: Data and governance parity&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Service&lt;/th&gt;
&lt;th&gt;Parity&lt;/th&gt;
&lt;th&gt;Differences&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;DynamoDB&lt;/td&gt;
&lt;td&gt;Full parity&lt;/td&gt;
&lt;td&gt;All APIs work; account/table throughput caps identical (80,000/40,000 CU). One caveat: global tables do not replicate across partitions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ElastiCache&lt;/td&gt;
&lt;td&gt;Engines in sync, ~70% breadth&lt;/td&gt;
&lt;td&gt;Engine versions identical across regions; purchasable node SKUs 167 vs 236 in Global&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DocumentDB&lt;/td&gt;
&lt;td&gt;Version in sync, instance classes trimmed&lt;/td&gt;
&lt;td&gt;Latest engine identical; instance classes Beijing 33/39, Ningxia 27/39, missing mostly older r4 generation, core r5 intact&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ECS&lt;/td&gt;
&lt;td&gt;API parity&lt;/td&gt;
&lt;td&gt;The difference is in quota management: service-quotas returns an empty list in China&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CloudWatch metrics/synthetics/SLO&lt;/td&gt;
&lt;td&gt;Parity&lt;/td&gt;
&lt;td&gt;Metrics, Synthetics canaries, and Application Signals all work across regions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CloudWatch RUM&lt;/td&gt;
&lt;td&gt;Unavailable&lt;/td&gt;
&lt;td&gt;Service not offered&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Organizations&lt;/td&gt;
&lt;td&gt;Works within China&lt;/td&gt;
&lt;td&gt;SCP and multi-account fully functional, but completely independent from the Global org. Two systems, no bridge&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;IAM Identity Center&lt;/td&gt;
&lt;td&gt;Works within China&lt;/td&gt;
&lt;td&gt;Permission Sets, application registration (OIDC/SAML), trusted token issuers, and local identity store all available, including recent features&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;These results yield the feature dimension&amp;rsquo;s most actionable conclusion: &lt;strong&gt;the data layer is nearly a lift-and-shift&lt;/strong&gt;. DynamoDB is at full parity, ElastiCache even tracks the new Valkey engine, and DocumentDB only lacks older instance generations. For teams moving the data layer into China, the technical friction is small.&lt;/p&gt;
&lt;p&gt;Two traps. Observability has a hole: metrics, canaries, and SLOs are present, but RUM (Real User Monitoring) is definitively unavailable, so frontend experience monitoring teams need an alternative lined up. Account governance is where misjudgments happen: Global Organizations and Identity Center do not extend into China, but China can host its own complete set, and it is not a stripped-down version. Recent feature APIs verified working. Your multi-account strategy, SCP hierarchy, and SSO all need to be rebuilt for China. In one sentence: the architecture can be copied, but governance cannot be inherited.&lt;/p&gt;
&lt;h2 id="quotas-the-landmines-you-step-on-during-load-tests"&gt;Quotas: The Landmines You Step on During Load Tests
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Results (default and applied API layers)&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Quota&lt;/th&gt;
&lt;th&gt;us-east-1&lt;/th&gt;
&lt;th&gt;Beijing&lt;/th&gt;
&lt;th&gt;Ningxia&lt;/th&gt;
&lt;th&gt;Nature&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;EC2 On-Demand Standard vCPU (default)&lt;/td&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;5&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;5&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Partition-consistent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EC2 On-Demand Standard vCPU (applied)&lt;/td&gt;
&lt;td&gt;32&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;td&gt;Account variance, not partition&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lambda concurrency (default)&lt;/td&gt;
&lt;td&gt;1,000&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;1,000, adjustable&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Same as Beijing&lt;/td&gt;
&lt;td&gt;Partition-consistent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lambda concurrency (applied)&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;td&gt;Uninitialized&lt;/td&gt;
&lt;td&gt;Uninitialized&lt;/td&gt;
&lt;td&gt;Cold-start account state&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ECS quotas (default layer)&lt;/td&gt;
&lt;td&gt;62 items&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;62 items (identical)&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Same as Beijing&lt;/td&gt;
&lt;td&gt;Partition-consistent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ECS quotas (applied layer)&lt;/td&gt;
&lt;td&gt;28 items (all adjustable ones)&lt;/td&gt;
&lt;td&gt;Empty list&lt;/td&gt;
&lt;td&gt;Empty list&lt;/td&gt;
&lt;td&gt;Account has no adjustable-quota records yet&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;EKS quotas (both layers)&lt;/td&gt;
&lt;td&gt;13/12 items&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;Both layers report &amp;ldquo;service unavailable&amp;rdquo;&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Same as Beijing&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;The one real partition gap&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;One piece of background for reading this table: service-quotas data comes in two layers. The default layer holds AWS&amp;rsquo;s documented defaults; the applied layer holds your account&amp;rsquo;s values. EC2 applied values grow automatically with account usage and have nothing to do with partition. ECS&amp;rsquo;s empty applied list is also account state: nearly all its quotas are non-adjustable, only adjustable ones enter the applied layer, and a fresh account has no such records. The console still shows the full catalog.&lt;/p&gt;
&lt;p&gt;Filter out the account noise and exactly one partition-level gap remains in quotas: &lt;strong&gt;EKS is not integrated with service-quotas in China at all&lt;/strong&gt;. Both API layers return &amp;ldquo;service unavailable,&amp;rdquo; and EKS does not appear in the console&amp;rsquo;s service list. There is no self-service way to check EKS node or cluster limits; the only channel is a support ticket. IaC that references EKS quota values as guardrails will fail right here.&lt;/p&gt;
&lt;p&gt;That conclusion is itself the lesson: when comparing quotas across partitions, applied values are polluted by account history. Only default values reflect partition policy. Query the wrong layer and you will read account variance as partition difference.&lt;/p&gt;
&lt;p&gt;A few default values from the console worth memorizing. Small numbers, zero room for negotiation:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Scenario&lt;/th&gt;
&lt;th&gt;Quota&lt;/th&gt;
&lt;th&gt;Default&lt;/th&gt;
&lt;th&gt;Who hits it first&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;BI concurrency&lt;/td&gt;
&lt;td&gt;Athena active DML queries&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;20&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Report queues&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;High-frequency deploys&lt;/td&gt;
&lt;td&gt;Lambda control-plane API rate&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;15/sec, not adjustable&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;CI/CD pipelines&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Elastic scaling&lt;/td&gt;
&lt;td&gt;ECS task launch rate&lt;/td&gt;
&lt;td&gt;500, not adjustable&lt;/td&gt;
&lt;td&gt;Scaling storms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Backup windows&lt;/td&gt;
&lt;td&gt;EBS concurrent snapshots per volume&lt;/td&gt;
&lt;td&gt;5, not adjustable&lt;/td&gt;
&lt;td&gt;Batch backup scripts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cache busting&lt;/td&gt;
&lt;td&gt;CloudFront active wildcard invalidations&lt;/td&gt;
&lt;td&gt;15, not adjustable&lt;/td&gt;
&lt;td&gt;Release systems&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Multi-cert sites&lt;/td&gt;
&lt;td&gt;CloudFront SSL certs per distribution&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;1, not adjustable&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Multi-domain architectures&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Note the words &amp;ldquo;not adjustable.&amp;rdquo; Resource quotas can be raised with a ticket; this batch can only be solved by changing the architecture. More than half the quotas in the console carry that mark. Design around them from day one. Quota console: &lt;a class="link" href="https://console.amazonaws.cn/servicequotas/home/dashboard" target="_blank" rel="noopener"
&gt;https://console.amazonaws.cn/servicequotas/home/dashboard&lt;/a&gt; .&lt;/p&gt;
&lt;h2 id="developer-experience-docs-images-and-tooling"&gt;Developer Experience: Docs, Images, and Tooling
&lt;/h2&gt;&lt;p&gt;This section is for the people who write code every day. Architects read catalogs; developers care about three things: can I find the docs, can I pull the images, does CI pass.&lt;/p&gt;
&lt;p&gt;China has its own documentation site: &lt;a class="link" href="https://docs.amazonaws.cn" target="_blank" rel="noopener"
&gt;https://docs.amazonaws.cn&lt;/a&gt; . Docs for the same service are not always in sync with the global site, so when behavior contradicts documentation, first check which site you are reading.&lt;/p&gt;
&lt;p&gt;Images are the most painful part. EC2 and EKS nodes run inside the mainland network, where Docker Hub, GitHub, and the official Kubernetes image registries are effectively unreachable. The workable substitute is pulling from a self-hosted registry or registry proxy outside the firewall. GitHub itself mostly works; cloning small-to-medium repositories takes acceptable time, and you can pull your own code into the China environment and build images there.&lt;/p&gt;
&lt;p&gt;The AWS CLI is a non-issue. Two profiles on one machine, one pointing at China and one at Global, used side by side. China endpoints live on separate domains, but the difference is transparent to the CLI. Direct connectivity from mainland China to AWS China services is smooth.&lt;/p&gt;
&lt;p&gt;Domains and DNS follow a different rulebook. China does not support domain registration. Buy your domain from a registrar licensed in China, complete the ICP filing, and only then can the domain be used with AWS China. An unfiled domain resolves fine, but the website will not open.&lt;/p&gt;
&lt;p&gt;One more thing that is easy to miss: there is no CloudShell in China (Global has it). Engineers used to a browser terminal need to bring their own local tooling.&lt;/p&gt;
&lt;h2 id="cost-the-beijingningxia-price-inversion"&gt;Cost: The Beijing–Ningxia Price Inversion
&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Linux/Shared/on-demand hourly prices (pricing API)&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Instance&lt;/th&gt;
&lt;th&gt;us-east-1&lt;/th&gt;
&lt;th&gt;Beijing&lt;/th&gt;
&lt;th&gt;Ningxia (USD equiv.)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;m5.xlarge&lt;/td&gt;
&lt;td&gt;$0.192&lt;/td&gt;
&lt;td&gt;¥2.026 ($0.285, +48%)&lt;/td&gt;
&lt;td&gt;¥1.356 ($0.191, &lt;strong&gt;-1%&lt;/strong&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;c6i.2xlarge&lt;/td&gt;
&lt;td&gt;$0.340&lt;/td&gt;
&lt;td&gt;¥2.958 ($0.417, +23%)&lt;/td&gt;
&lt;td&gt;¥1.972 ($0.278, -18%)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;g4dn.xlarge&lt;/td&gt;
&lt;td&gt;$0.526&lt;/td&gt;
&lt;td&gt;¥5.223 ($0.736, +40%)&lt;/td&gt;
&lt;td&gt;¥3.711 ($0.523, -1%)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;g5.12xlarge&lt;/td&gt;
&lt;td&gt;$5.672&lt;/td&gt;
&lt;td&gt;¥53.641 ($7.556, &lt;strong&gt;+33%&lt;/strong&gt;)&lt;/td&gt;
&lt;td&gt;¥37.781 ($5.321, &lt;strong&gt;-6%&lt;/strong&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The numbers hide a counterintuitive conclusion: &lt;strong&gt;Beijing and Ningxia pricing is inverted&lt;/strong&gt;. Beijing runs 23 to 48 percent above Global; Ningxia flips it, with general-purpose and GPU instances at or below Global prices. A g5.12xlarge in Ningxia works out to $5.32 an hour, 6 percent cheaper than us-east-1. A 30 percent price spread between two regions of the same country has no parallel in Global.&lt;/p&gt;
&lt;p&gt;Ningxia is using price to pull compute westward, and AI inference workloads are the clearest example. If your workload tolerates latency, placing GPU inference in Ningxia instead of Beijing saves a third of the cost and beats Virginia. Within China alone, the region choice deserves its own line in the cost model.&lt;/p&gt;
&lt;h2 id="the-one-hour-pre-launch-checklist"&gt;The One-Hour Pre-Launch Checklist
&lt;/h2&gt;&lt;p&gt;Everything measured above condensed into one checklist. Run it before the architecture review and most China surprises get caught early. Every command here was validated during this experiment.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Check versions&lt;/strong&gt;: run &lt;code&gt;aws eks describe-cluster-versions&lt;/code&gt; and &lt;code&gt;aws rds describe-db-engine-versions&lt;/code&gt;, and compare the target region against your current one.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check instance types&lt;/strong&gt;: run &lt;code&gt;aws ec2 describe-instance-type-offerings&lt;/code&gt; and confirm every instance type your architecture references exists in China. GPU workloads should additionally verify the chip model.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check service availability&lt;/strong&gt;: go through docs.amazonaws.cn and confirm the China support status of every service your architecture depends on.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check quotas&lt;/strong&gt;: run &lt;code&gt;aws service-quotas get-service-quota&lt;/code&gt; first; if it comes back empty, run &lt;code&gt;get-aws-default-service-quota&lt;/code&gt;. EKS in China reports &amp;ldquo;service unavailable&amp;rdquo; outright, and that error is your answer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Check pricing&lt;/strong&gt;: compare the three regions with the pricing API. The Beijing–Ningxia spread may change your deployment decision.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="from-gaps-to-decisions"&gt;From Gaps to Decisions
&lt;/h2&gt;&lt;p&gt;Put the five dimensions side by side and the conclusion stays cool-headed. AWS China is not a discounted clone of AWS Global. It is a target platform that deserves its own evaluation.&lt;/p&gt;
&lt;p&gt;Versions are in sync: 14 of 18 measured items align exactly, and even EKS Auto Mode, the newest managed form factor, is present. Default quotas match, and the only partition-level quota gap is EKS&amp;rsquo;s missing self-service integration. Ningxia pricing undercuts us-east-1, so the cost picture is calculable. The data layer is close to lift-and-shift, and the governance stack can be rebuilt in full.&lt;/p&gt;
&lt;p&gt;But AI compute stopped in 2021, the managed AI API line is absent wholesale, and CloudFront already has its exit date on the calendar. None of this appears in the catalog.&lt;/p&gt;
&lt;p&gt;So the real watershed in a migration decision is not &amp;ldquo;is AWS China good enough.&amp;rdquo; It is which line your architecture leans on. On core compute, databases, containers, and observability, China is a respectable and price-friendly platform. On AI, there is currently one road, SageMaker self-managed, and the ceiling of that road is set by silicon.&lt;/p&gt;
&lt;p&gt;This article will be updated as testing continues. If your team is running a China architecture review, &lt;a class="link" href="https://martinliu.cn/chinaready/" &gt;Chinaready&amp;rsquo;s assessment service&lt;/a&gt; can turn this five-dimension check into a formal process. For a catalog-level parity list, see &lt;a class="link" href="https://martinliu.cn/blog/china-market-technical-readiness-checklist/" &gt;the China market technical readiness checklist&lt;/a&gt;. And if your actual problem is &amp;ldquo;our overseas site is slow in China,&amp;rdquo; start with &lt;a class="link" href="https://martinliu.cn/blog/why-overseas-sites-slow-in-china/" &gt;the troubleshooting guide&lt;/a&gt;.&lt;/p&gt;</description></item></channel></rss>