DynamoDB point-in-time recovery is disabled

Plan point-in-time recovery and a tested restore process for important tables.

Description

DynamoDB Point-in-Time Recovery (PITR) restores a chosen point within the available retention window to a new table. It helps recover from accidental deletion or incorrect application writes. When disabled, recovery for that period depends on separate backups or manual repair.

Potential impact

  • Recovering a desired point after accidental deletion or incorrect updates can be harder.
  • Recovery time, data loss, and manual work can increase.

Remediation

Set point_in_time_recovery { enabled = true } on tables that require it. Check the available recovery period and test restoring a new table, restoring required settings, and switching the application. Maintain long-term backups and recovery procedures separately.

Examples

These examples compare only PITR enablement on the same table. A restore creates a new table rather than rewinding the existing one in place.

Before

hcl
resource "aws_dynamodb_table" "orders" {
  name         = "orders"
  billing_mode = "PAY_PER_REQUEST"
  hash_key     = "id"

  attribute {
    name = "id"
    type = "S"
  }

  point_in_time_recovery {
    enabled = false
  }
}

After

hcl
resource "aws_dynamodb_table" "orders" {
  name         = "orders"
  billing_mode = "PAY_PER_REQUEST"
  hash_key     = "id"

  attribute {
    name = "id"
    type = "S"
  }

  point_in_time_recovery {
    enabled = true
  }
}

Enabling PITR provides recovery within the available window after enablement. It does not retroactively recover changes from before it was enabled.

References