Description
A DynamoDB gateway VPC endpoint adds a service route to its associated route tables. Creating the endpoint alone does not direct traffic from an application subnet through it.
Potential impact
Missing routing associations can cause DynamoDB access to fail or use another path, such as an internet gateway or NAT.
Remediation
Set the endpoint’s route_table_ids to the route tables used by the application subnets. Confirm that the subnets, route tables, and endpoint belong to the same VPC and that access policies allow the required operations.
Examples
The second example associates the subnet’s route table with the gateway endpoint. All referenced resources are assumed to be in the same VPC.
Before
hcl
resource "aws_vpc_endpoint" "dynamodb_vpce" {
vpc_id = aws_vpc.main.id
service_name = "com.amazonaws.us-east-1.dynamodb"
}
After
hcl
resource "aws_route_table_association" "private_rtb_assoc" {
subnet_id = aws_subnet.private_subnet2.id
route_table_id = aws_route_table.private_rtb2.id
}
resource "aws_vpc_endpoint" "dynamodb_vpce" {
vpc_id = aws_vpc.main.id
service_name = "com.amazonaws.us-east-1.dynamodb"
route_table_ids = [aws_route_table.private_rtb2.id]
}