Amazon Keyspaces table inventory

Include Keyspaces tables in the asset inventory.

Description

AWS::Cassandra::Table declares a table in Amazon Keyspaces, a managed service compatible with Apache Cassandra. The presence of a table is not itself a vulnerability.

Potential impact

A table missing from the inventory can be overlooked when reviewing ownership, access, and recovery plans.

Remediation

Record the table’s owner and purpose, and check access permissions, encryption keys, and recovery requirements.

Examples

These examples require an existing my_keyspace. Both configurations encrypt stored data; the second explicitly selects the default AWS owned key.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  MyTable:
    Type: AWS::Cassandra::Table
    Properties:
      KeyspaceName: my_keyspace
      TableName: my_table
      PartitionKeyColumns:
        - ColumnName: Message
          ColumnType: ASCII

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  MyTable:
    Type: AWS::Cassandra::Table
    Properties:
      KeyspaceName: my_keyspace
      TableName: my_table
      PartitionKeyColumns:
        - ColumnName: Message
          ColumnType: ASCII
      EncryptionSpecification:
        EncryptionType: AWS_OWNED_KMS_KEY

References