Review DynamoDB gateway endpoint routing associations

Associate the application subnet’s route table with the endpoint.

Description

A DynamoDB gateway VPC endpoint adds a service route to its associated route tables. Creating the endpoint alone does not direct traffic from an application subnet through it.

Potential impact

Missing routing associations can cause DynamoDB access to fail or use another path, such as an internet gateway or NAT.

Remediation

Set the endpoint’s route_table_ids to the route tables used by the application subnets. Confirm that the subnets, route tables, and endpoint belong to the same VPC and that access policies allow the required operations.

Examples

The second example associates the subnet’s route table with the gateway endpoint. All referenced resources are assumed to be in the same VPC.

Before

hcl
resource "aws_vpc_endpoint" "dynamodb_vpce" {
  vpc_id       = aws_vpc.main.id
  service_name = "com.amazonaws.us-east-1.dynamodb"
}

After

hcl
resource "aws_route_table_association" "private_rtb_assoc" {
  subnet_id      = aws_subnet.private_subnet2.id
  route_table_id = aws_route_table.private_rtb2.id
}

resource "aws_vpc_endpoint" "dynamodb_vpce" {
  vpc_id       = aws_vpc.main.id
  service_name = "com.amazonaws.us-east-1.dynamodb"
  route_table_ids = [aws_route_table.private_rtb2.id]
}

References