AWS::DynamoDB::GlobalTable SSESpecification - AWS CloudFormation

AWS::DynamoDB::GlobalTable SSESpecification

Represents the settings used to enable server-side encryption.


To declare this entity in your AWS CloudFormation template, use the following syntax:


{ "SSEEnabled" : Boolean, "SSEType" : String }


SSEEnabled: Boolean SSEType: String



Indicates whether server-side encryption is performed using an AWS managed key or an AWS owned key. If disabled (false) or not specified, server-side encryption uses an AWS owned key. If enabled (true), the server-side encryption type is set to KMS and an AWS managed key is used (AWS KMS charges apply). If you choose to use KMS encryption, you can also use customer managed KMS keys by specifying them in the ReplicaSpecification.SSESpecification object. You cannot mix AWS managed and customer managed KMS keys.

Required: Yes

Type: Boolean

Update requires: No interruption


Server-side encryption type. The only supported value is:

  • KMS - Server-side encryption that uses AWS Key Management Service. The key is stored in your account and is managed by AWS KMS (AWS KMS charges apply).

Required: No

Type: String

Allowed values: AES256 | KMS

Update requires: No interruption