AWS CloudFormation
User Guide (Version )

The AWS Documentation website is getting a new look!
Try it now and let us know what you think. Switch to the new look >>

You can return to the original look by selecting English in the language selector above.

AWS::DynamoDB::Table SSESpecification

Represents the settings used to enable server-side encryption.

Syntax

To declare this entity in your AWS CloudFormation template, use the following syntax:

JSON

{ "KMSMasterKeyId" : String, "SSEEnabled" : Boolean, "SSEType" : String }

YAML

KMSMasterKeyId: String SSEEnabled: Boolean SSEType: String

Properties

KMSMasterKeyId

The KMS customer master key (CMK) that should be used for the AWS KMS encryption. To specify a CMK, use its key ID, Amazon Resource Name (ARN), alias name, or alias ARN. Note that you should only provide this parameter if the key is different from the default DynamoDB customer master key alias/aws/dynamodb.

Required: No

Type: String

Update requires: No interruption

SSEEnabled

Indicates whether server-side encryption is done using an AWS managed CMK or an AWS owned CMK. If enabled (true), server-side encryption type is set to KMS and an AWS managed CMK is used (AWS KMS charges apply). If disabled (false) or not specified, server-side encryption is set to AWS owned CMK.

Required: Yes

Type: Boolean

Update requires: No interruption

SSEType

Server-side encryption type. The only supported value is:

  • KMS - Server-side encryption that uses AWS Key Management Service. The key is stored in your account and is managed by AWS KMS (AWS KMS charges apply).

Required: No

Type: String

Allowed Values: AES256 | KMS

Update requires: No interruption

On this page: