AWS::DynamoDB::GlobalTable SSESpecification - Amazon CloudFormation
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

AWS::DynamoDB::GlobalTable SSESpecification

Represents the settings used to enable server-side encryption.

Syntax

To declare this entity in your Amazon CloudFormation template, use the following syntax:

JSON

{ "SSEEnabled" : Boolean, "SSEType" : String }

YAML

SSEEnabled: Boolean SSEType: String

Properties

SSEEnabled

Indicates whether server-side encryption is performed using an Amazon managed key or an Amazon owned key. If enabled (true), server-side encryption type is set to KMS and an Amazon managed key is used (Amazon KMS charges apply). If disabled (false) or not specified,server-side encryption is set to an Amazon owned key. If you choose to use KMS encryption, you can also use customer managed KMS keys by specifying them in the ReplicaSpecification.SSESpecification object. You cannot mix Amazon managed and customer managed KMS keys.

Required: Yes

Type: Boolean

Update requires: No interruption

SSEType

Server-side encryption type. The only supported value is:

  • KMS - Server-side encryption that uses Amazon Key Management Service. The key is stored in your account and is managed by Amazon KMS (Amazon KMS charges apply).

Required: No

Type: String

Allowed values: AES256 | KMS

Update requires: No interruption