Amazon DynamoDB
AWS native.
Access mode: Read-only (typically)
Required information
| Field | Details |
|---|---|
| AWS Account ID | Account containing the DynamoDB tables. |
| Region(s) | AWS region(s) where tables reside. DynamoDB is regional. |
| Table name(s) | Specific tables. DynamoDB has no database/schema hierarchy, just tables. |
| IAM role | Cross-account IAM role ARN for Flume to assume. Preferred over static access keys. |
| Access level | Read-only: dynamodb:Scan, dynamodb:Query, dynamodb:DescribeTable, dynamodb:ListTables. Read-write: add PutItem, UpdateItem, DeleteItem. |
Network considerations
Default: DynamoDB is a public AWS service. Connections over HTTPS to dynamodb.<region>.amazonaws.com.
VPC Endpoint (Gateway): If Flume runs in AWS and the client wants to keep traffic on the AWS backbone, create a VPC Gateway Endpoint for DynamoDB.
No firewall rules needed: IAM policies control all access.
Credential and auth management
Preferred: Cross-account IAM role assumption. Client creates an IAM role with DynamoDB permissions, trusts Flume’s AWS account. Flume calls sts:AssumeRole. Short-lived credentials, no secrets to share.
Acceptable: IAM user access keys. Long-lived, requires rotation. Use only if cross-account role assumption isn’t possible.
DynamoDB Streams: If we need change data capture, add dynamodb:GetRecords, dynamodb:GetShardIterator, dynamodb:DescribeStream permissions.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | aws dynamodb list-tables --region <region> | Returns table list |
| Table access | aws dynamodb describe-table --table-name <table> | Returns table metadata |
| Read test | aws dynamodb scan --table-name <table> --max-items 1 | Returns an item |
| Permission check | Attempt a Query with a known partition key | Returns expected items |
| IAM validation | aws sts get-caller-identity | Shows assumed role ARN |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.