Skip to content
Get startedRequest a demo
Databases, lakes, and warehouses

Amazon DynamoDB

AWS native.

Access mode: Read-only (typically)

Required information

FieldDetails
AWS Account IDAccount containing the DynamoDB tables.
Region(s)AWS region(s) where tables reside. DynamoDB is regional.
Table name(s)Specific tables. DynamoDB has no database/schema hierarchy, just tables.
IAM roleCross-account IAM role ARN for Flume to assume. Preferred over static access keys.
Access levelRead-only: dynamodb:Scan, dynamodb:Query, dynamodb:DescribeTable, dynamodb:ListTables. Read-write: add PutItem, UpdateItem, DeleteItem.

Network considerations

Default: DynamoDB is a public AWS service. Connections over HTTPS to dynamodb.<region>.amazonaws.com.

VPC Endpoint (Gateway): If Flume runs in AWS and the client wants to keep traffic on the AWS backbone, create a VPC Gateway Endpoint for DynamoDB.

No firewall rules needed: IAM policies control all access.

Credential and auth management

Preferred: Cross-account IAM role assumption. Client creates an IAM role with DynamoDB permissions, trusts Flume’s AWS account. Flume calls sts:AssumeRole. Short-lived credentials, no secrets to share.

Acceptable: IAM user access keys. Long-lived, requires rotation. Use only if cross-account role assumption isn’t possible.

DynamoDB Streams: If we need change data capture, add dynamodb:GetRecords, dynamodb:GetShardIterator, dynamodb:DescribeStream permissions.

Validation checks

CheckMethodExpected result
Authenticationaws dynamodb list-tables --region <region>Returns table list
Table accessaws dynamodb describe-table --table-name <table>Returns table metadata
Read testaws dynamodb scan --table-name <table> --max-items 1Returns an item
Permission checkAttempt a Query with a known partition keyReturns expected items
IAM validationaws sts get-caller-identityShows assumed role ARN

Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.