AWS DynamoDB resource inventory

Document DynamoDB tables and their owners.

Description

A DynamoDB table inventory helps identify the purpose and ownership of data stores. This is asset-management information; the presence of a table is not itself a vulnerability.

Potential impact

Tables omitted from the inventory may also be missed during access, backup, and encryption-key reviews.

Remediation

Record each table’s service and owner, then review access policies, point-in-time recovery (PITR), and encryption-key settings.

Examples

The examples add service and environment tags without editing access-policy or backup configuration. Also check the effect of any tag-based IAM policies.

Before

hcl
resource "aws_dynamodb_table" "orders" {
  name         = "orders"
  billing_mode = "PAY_PER_REQUEST"
  hash_key     = "id"

  attribute {
    name = "id"
    type = "S"
  }
}

After

hcl
resource "aws_dynamodb_table" "orders" {
  name         = "orders"
  billing_mode = "PAY_PER_REQUEST"
  hash_key     = "id"

  attribute {
    name = "id"
    type = "S"
  }

  tags = {
    Service     = "orders"
    Environment = "production"
  }
}

References