DynamoDB point-in-time recovery disabled

Use DynamoDB point-in-time recovery to provide recovery options for mistakes or data corruption.

Description

DynamoDB Point-in-Time Recovery (PITR) restores data from a point within the available recovery window into a new table. When disabled, recovery options are reduced if operational mistakes or data corruption occur.

Potential impact

  • It can be harder to restore accidentally deleted or incorrectly modified data to the required point in time.
  • Depending on other backup coverage, recovery can take longer and data loss can increase.

Remediation

Set pointInTimeRecovery.enabled to true according to your recovery requirements. Check the available recovery window and test restoration to a new table and application cutover. Enabling PITR does not create recovery history for earlier periods; assess separate needs such as long-term backups.

Examples

These table excerpts compare PITR settings. Other required settings, including keys and capacity, are omitted.

Before

yaml
name: aws-eks
runtime: yaml
resources:
  example:
    type: aws:dynamodb:Table
    properties:
      serverSideEncryption:
        enabled: true
      pointInTimeRecovery:
        enabled: false

After

yaml
name: aws-eks
runtime: yaml
resources:
  example:
    type: aws:dynamodb:Table
    properties:
      serverSideEncryption:
        enabled: true
      pointInTimeRecovery:
        enabled: true

The after-example enables PITR. A restore creates a new table rather than reverting the existing one; verify the required settings and application connections.

References