Review SimpleDB domain use

Check storage requirements and existing dependencies before choosing SimpleDB.

Description

AWS::SDB::Domain is a valid CloudFormation resource for declaring a SimpleDB domain. Its declaration is not inherently a security vulnerability, but new systems should assess whether its data model and operational capabilities meet their needs.

Potential impact

Choosing storage that does not meet requirements can create operational constraints or increase later migration costs.

Remediation

Avoid creating unnecessary new domains. Before replacing an existing domain, migrate its data and application dependencies and assess deletion effects, then remove it from the template.

Examples

The examples omit an unneeded SimpleDB declaration from a new configuration. Applying this change directly to an existing stack can delete the resource, so complete data preservation and migration first.

Before

yaml
Resources:
  HostedZone:
    Type: AWS::Route53::HostedZone
    Properties:
      Name: "HostedZone"

  SBDDomain:
    Type: AWS::SDB::Domain
    Properties:
      Description: "Example domain description"

After

yaml
Resources:
  HostedZone:
    Type: AWS::Route53::HostedZone
    Properties:
      Name: "HostedZone"

References