Amazon Web Services (AWS) has expanded its Elastic Block Store (EBS) Volume Clones capability to support cross-account operations. This update allows users to create instant copies of EBS volumes and share them with other AWS accounts, while optionally re-encrypting the data with a key from the target account’s AWS Key Management Service (KMS). The feature is designed to facilitate secure data sharing for development, testing, and experimentation without exposing production environments to unnecessary risk.
How cross-account cloning works
To initiate a cross-account EBS volume clone, the volume owner must first grant access to the target account using AWS Resource Access Manager (RAM). This step involves sharing the volume through the Amazon EBS console or programmatically via APIs. Once the target account accepts the resource share in RAM, the shared volume becomes visible in the target account’s EBS volume page. Users can then create a copy of the volume, which retains the original data but can be re-encrypted with a different KMS key if needed.
The process is constrained to the same Availability Zone as the source volume, and users must reference Availability Zone IDs to ensure the copy is created in the correct physical location. AWS has also introduced monitoring capabilities, allowing users to track the status of cross-account copies through AWS CloudTrail and Amazon EventBridge. Events are generated at the start and completion of the copy operation, providing details such as the shared volume ID, consuming account ID, and timestamps.
Technical and operational considerations
Cross-account EBS volume cloning supports unencrypted volumes and those encrypted with customer-managed keys (CMKs). However, volumes encrypted with AWS’s default managed key (AMK) cannot be shared. If the source volume uses a CMK, that key must also be shared with the target account unless a different CMK is specified for re-encryption. Pricing for the feature includes a one-time fee based on the volume size, charged to the target account, in addition to standard EBS volume charges for the copied data.
For professionals: This feature simplifies workflows for teams managing multi-account AWS environments, particularly for refreshing test and development environments with up-to-date production data. Operators should review their KMS policies and RAM configurations to ensure seamless access and encryption key sharing across accounts.
The feature is available in all AWS Regions that support EBS Volume Clones, with no additional cost for sharing volumes through RAM. AWS has provided documentation and API support for programmatic access, including integration with AWS MCP Server and AI coding tools for automation.
Use cases and limitations
The primary use case for cross-account EBS volume cloning is the secure transfer of production data to secondary environments, such as staging or development accounts. This allows teams to work with realistic datasets while maintaining isolation between environments. The feature also supports compliance and security requirements by enabling re-encryption with account-specific keys, reducing the risk of unauthorized access.
However, the feature has limitations. Cross-account copies must be created in the same Availability Zone as the source volume, which may require coordination between teams managing different accounts. Additionally, the one-time fee for cloning could impact cost-sensitive workloads, particularly for large volumes. AWS has not disclosed specific pricing tiers, so users should consult the EBS pricing documentation for details.
Companies mentioned
Automated pipeline · Cloud & Infrastructure
Synthesized from 1 industry feed on 10 Sep 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 2 candidates
- Checking for duplicates — New story No existing article covers Amazon EBS Volume Clones cross-account functionality.
- Checking for duplicates — New story pre_write:; No existing article covers Amazon EBS Volume Clones with cross-account copy functionality.
- Writing the article — Draft created article_id=542 slug=aws-enables-cross-account-ebs-volume-cloning
-
Editor review — Approved
- Score: 95/100
- Factual grounding: The draft states the feature is available in 'all AWS Regions that support EBS Volume Clones,' but the source specifies 'all AWS Regions that support Amazon EBS Volume Clones.' While likely equivalent, the phrasing should match the source verbatim for precision.
- Style compliance: The draft includes a 'Use cases and limitations' section, which is not one of the recommended section headings (e.g., 'What happened,' 'Why it matters,' 'What to watch'). While the content is valid, the section title deviates from the style guide.
- No copied phrasing: The phrase 'Cross-account EBS volume cloning supports unencrypted volumes and those encrypted with customer-managed keys (CMKs)' closely mirrors the source's 'You can share unencrypted volumes and volumes encrypted with a customer managed key (CMK).' While the meaning is identical, the phrasing should be restructured further to avoid similarity.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Reused library image reused image #9
- Linking related stories — Linked 0 relations from 472 candidates
- Publishing — Published aws-enables-cross-account-ebs-volume-cloning
- Mastodon — Posted https://mstdn.social/@hostingpaper/117247782521280919

Discussion · coming soon
Be the first to join the thread when community discussion launches.