Description
AWS::SDB::Domain is a valid CloudFormation resource for declaring a SimpleDB domain. Its declaration is not inherently a security vulnerability, but new systems should assess whether its data model and operational capabilities meet their needs.
Potential impact
Choosing storage that does not meet requirements can create operational constraints or increase later migration costs.
Remediation
Avoid creating unnecessary new domains. Before replacing an existing domain, migrate its data and application dependencies and assess deletion effects, then remove it from the template.
Examples
The examples omit an unneeded SimpleDB declaration from a new configuration. Applying this change directly to an existing stack can delete the resource, so complete data preservation and migration first.
Before
Resources:
HostedZone:
Type: AWS::Route53::HostedZone
Properties:
Name: "HostedZone"
SBDDomain:
Type: AWS::SDB::Domain
Properties:
Description: "Example domain description"
After
Resources:
HostedZone:
Type: AWS::Route53::HostedZone
Properties:
Name: "HostedZone"