【问题标题】:How to create/add an encryption/key to a dynamo table via cloudformation?如何通过 cloudformation 创建/添加加密/密钥到 dynamodb 表?
【发布时间】:2021-11-17 01:22:21
【问题描述】:

请参阅下面的示例 dynamodb 表和 cloudformation 模板。当我创建下表时,encrpytion aws 会采取什么措施来保护我的数据,如果可以的话?如果没有,我如何在下面的模板中指定我想用 aws 本身提供的密钥加密我的数据,如果可能的话。如果不是我假设,我还需要为此添加一个关键资源。

AWSTemplateFormatVersion: "2010-09-09"
Resources: 
  myDynamoDBTable: 
    Type: AWS::DynamoDB::Table
    Properties: 
      AttributeDefinitions: 
        - 
          AttributeName: "product"
          AttributeType: "S"
        - 
          AttributeName: "model"
          AttributeType: "S"
      KeySchema: 
        - 
          AttributeName: "product"
          KeyType: "HASH"
        - 
          AttributeName: "Model"
          KeyType: "RANGE"
      ProvisionedThroughput: 
        ReadCapacityUnits: "5"
        WriteCapacityUnits: "5"
      TableName: "InfoTable"

【问题讨论】:

    标签: amazon-dynamodb amazon-cloudformation amazon-kms


    【解决方案1】:

    如here 所述,将SSESpecification 添加到您的表中。所以:

    AWSTemplateFormatVersion: "2010-09-09"
    Resources: 
      myDynamoDBTable: 
        Type: AWS::DynamoDB::Table
        Properties: 
          AttributeDefinitions: 
            - 
              AttributeName: "product"
              AttributeType: "S"
            - 
              AttributeName: "model"
              AttributeType: "S"
          KeySchema: 
            - 
              AttributeName: "product"
              KeyType: "HASH"
            - 
              AttributeName: "Model"
              KeyType: "RANGE"
          ProvisionedThroughput: 
            ReadCapacityUnits: "5"
            WriteCapacityUnits: "5"
          TableName: "InfoTable"
          SSESpecification:
            SSEEnabled: 'true'
    
    

    这将使用 AWS 托管的加密密钥对表进行加密。

    【讨论】:

    • 谢谢。我有点困惑,因为文档状态如果启用(真),服务器端加密类型设置为 KMS 并使用 AWS 托管密钥。如果禁用 (false) 或未指定,则服务器端加密设置为 AWS 拥有的密钥。那么 AWS 托管密钥与 AWS 拥有的密钥有什么区别?
    猜你喜欢
    • 1970-01-01
    • 2019-06-22
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2021-02-23
    • 2019-03-23
    相关资源
    最近更新 更多