Overview
DynamoDBTable creates an Amazon DynamoDB table with defaults tuned for serverless workloads: on-demand billing, point-in-time recovery on, and an AWS-managed KMS key. It also supports provisioned capacity, global secondary indexes, streams, and TTL expiry.
Point-in-time recovery defaults to true and removalPolicy defaults to RETAIN, so a stack deletion leaves the table and its backups in place.
DynamoDB is not a
fjall add database --type option. --type accepts Aurora, Instance, GlobalAurora and ClickHouse only. Declare a DynamoDB table by editing your application’s infrastructure.ts directly.Add a table
UseDatabaseFactory and register the result with app.addDatabase(). The factory returns a DynamoDBDatabase wrapper that plugs into connections: on your compute resources.
Properties
BothDatabaseFactory.build("Id", { type: "DynamoDB", ... }) and new DynamoDBTable(scope, "Id", ...) accept the same properties, with one exception noted below.
tableName exists on DynamoDBTableProps but not on the factory’s DynamoDBDatabaseProps. Factory-built tables always take a CloudFormation-generated name.
deletionProtection and removalPolicy are independent. removalPolicy decides what CloudFormation does when the stack is deleted. deletionProtection blocks any DeleteTable call, including one issued outside CloudFormation.AWS_MANAGED encrypts with the AWS-managed aws/dynamodb KMS key and bills KMS API requests. AWS_OWNED uses an AWS-owned key at no cost. CUSTOMER_MANAGED encrypts with the stack’s shared customer-managed key (one key per stack, created on first use, about $1–3 a month).Key types
Global secondary index fields
Methods
The factory and the construct expose different method names. Pick the table that matches how you built the resource.DynamoDBDatabase (returned by DatabaseFactory)
DynamoDBTable (the construct)
Examples
Composite key table
Table with a global secondary index
Provisioned throughput
Streams into Lambda
addDynamoDbEventSource() lives on the LambdaFunction construct, so reach it with getLambdaFunction(). It takes a CDK ITable, so pass getTable() rather than the Fjall wrapper.
TTL for automatic expiry
expiresAt as a Unix epoch in seconds. DynamoDB deletes expired items within 48 hours at no cost.
Connecting to compute
List the table inconnections: on a Lambda function or an ECS service. Fjall grants the table’s IAM actions to the ECS task role or the Lambda execution role. DynamoDB has no network primitive, so no security group rule is added.
readWrite. Narrow the grant with an access level of read, write or readWrite:
migrations: also receives DYNAMODB_TABLE_NAME and AWS_REGION in the migration task environment, plus a CRUD policy covering the table and its indexes.
Listing anything in
connections puts the compute in the application VPC. ComputeFactory.build treats a non-empty connections array as a VPC requirement and passes app.getVpc() in, so a Lambda that only talks to DynamoDB still gets ENIs in private subnets and pays for the NAT gateway or interface endpoints that reach the DynamoDB API. DynamoDB itself needs no VPC. To keep a function out of the VPC, leave connections off and grant it directly with grantReadData / grantReadWriteData.grantStreamRead() requires stream to be set on the table. Calling it on a table without streams fails at synth.
CloudFormation outputs
Each table exports the following, where{id} is the construct id you passed:
Next Steps
Database Factory
Compare DynamoDB against Aurora, RDS and ClickHouse
Lambda Function
Process DynamoDB streams with Lambda
Compute Factory
Wire tables into ECS services and Lambda functions
RDS Aurora
Use a relational store for joins and transactions