> Why should the U.S. let Chinese tech companies compete in the U.S. marketplace when China doesn't let U.S tech companies compete in their marketplace?
That is a point that very few people grasp. I've found that it's a bit easier to explain how the policies impact the technical side. You can extrapolate other facets from there (say, sales, for which I don't have direct expertise, although from what I hear, it's worse).
Let's say you want to sell stuff over there. Given that it's 2022, maybe you want a website to go with that? Possibly using some AWS services?
Ok let's do this.
Maybe you just want to translate your stuff and continue hosting from the US(or anywhere else really). Well, even if the traffic was allowed(it probably will be, at least initially), the firewall will make the experience miserable (ranges wildly, down to single digit bytes per second). The first request to anywhere is usually blocked. Geographical distance doesn't matter. Cross the border and the experience is terrible. So, that's not really an option. You really need to host from there.
First of all, your website needs a license. Even if all it says is "coming soon". Doesn't matter. Port 80(and 443) will be blocked until you get your ICP license. If you check wikipedia it talks about a 'grace period'. I'm not sure that is accurate. Traffic is usually blocked by providers regardless.
As a foreign company, you can't get one. You will need boots on the ground. And a lot of documentation. You cannot have non-Chinese DNS servers pointing to IPs in China. Yes this is scanned for and flagged and you better fix it otherwise you can lose your license. No it does not matter that these are automation/internal use domains.
This license thing takes at least a month in a happy day scenario. Potentially more.
You also need your 'AWS' account. It's in quotes because it's not really AWS. And no, it's not like "Amazon", the parent company, has an overseas "branch" or "affiliate" which, even though it's registered locally with the host country, it is effectively also Amazon and controlled by Amazon. No. The Beijing region is operated by Sinnet, Nginxia is operated by NWCDD. They are not Amazon, they are third parties. One wonders why Amazon went that route, since it seems suboptimal.
The process to get this account may take months.
Once you get your account, _you do not get the root credentials_. Those companies have it. They will tell you "there's no root user concept". That's not true(even though this is in the documentation now!). It's still basically the same AWS software, it has a root account. But they hold it, then use it to create an IAM user for you, and hand off that one to you instead. Over email.
Ok you have signed off on all those things. Now let's import some AMIs like we do everywhere else on the planet and start the services? No, you cannot do that. AWS China is a different 'partition'. Just like GovCloud. So they cannot be transferred. Same goes for just about everything else. Even S3 buckets. The one silver lining is that you can reuse the same bucket names. So let's just rebuild those images right? Well, remember the firewall thing? It's going to hit you here too. You will be using unbearably slow links that barely compete with dialup _unless_ everything you need is already mirrored over there.
Containers for the rescue. Or not? Your k8s cluster takes 5 minutes to download all containers in the US? It's going to take hours or days for you. Assuming it's not blocked - I hope none of your stuff uses gcr.io, for example (like K8s own components like to do). If they do, better mirror everything.
Money can help some of these link issues. You can pay companies to get around the firewall(but not around the regulations – if a destination is blocked it will stay blocked). If you do so, you will also have to provide a list of IPs that you will be talking to and what their purpose is. They will be vetted. If you have anything serious there, go that route(but be prepared to pay 5 digits for a link that's slower than your average Comcast business DSL).
"AWS" to AWS connections also seem to have some special rules, because the bandwidth is consistently better(not amazing, but better). So maybe setup your command and control that way. Can't do that via IPSEC tunnels though, that's not allowed. Unless done by "approved" vendors, to approved destinations. If try to do that by yourself, you risk your services getting shutdown, if not your entire account. SSH may or may not work.
Some of that affects local companies too (they all have to get the ICP thing) and can be, charitably, be blamed on excessive bureaucracy. Some of that may be due to decisions made specifically by AWS. But not everything can be explained that way.
And all you wanted to do was to setup a website.