Description
AWS::DynamoDB::Table declares a managed NoSQL database table. This is an asset-inventory item; using a table alone does not require changing or removing it.
Potential impact
An omitted table can become a gap in access, backup, and cost management.
Remediation
Include the table in the inventory and check access policies, encryption-key selection, backups, and point-in-time recovery requirements.
Examples
Both configurations encrypt stored data. Omitting SSEEnabled uses an AWS owned key; setting it to true here selects an AWS managed key, for which KMS charges can apply.
Before
yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
DynamoDBOnDemandTable:
Type: AWS::DynamoDB::Table
Properties:
TableName: test
AttributeDefinitions:
- AttributeName: pk
AttributeType: S
KeySchema:
- AttributeName: pk
KeyType: HASH
BillingMode: PAY_PER_REQUEST
After
yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
DynamoDBOnDemandTable:
Type: AWS::DynamoDB::Table
Properties:
TableName: test
AttributeDefinitions:
- AttributeName: pk
AttributeType: S
KeySchema:
- AttributeName: pk
KeyType: HASH
BillingMode: PAY_PER_REQUEST
SSESpecification:
SSEEnabled: true