Conversation
…eplica (aws#37783) TableV2MultiAccountReplica rendered replica-level SSE info but omitted the top-level SSESpecification on AWS::DynamoDB::GlobalTable, which CFN reads as SSE disabled and rejects when replicas carry KMS keys. Mirrors TableV2, which always renders encryption._renderSseSpecification(). Extends the existing custom-encryption test to assert top-level SSEEnabled/SSEType alongside the replica KMSMasterKeyId.
aws-cdk-automation
requested changes
Sep 21, 2026
Collaborator
There was a problem hiding this comment.
The pull request linter fails with the following errors:
❌ Fixes must contain a change to an integration test file and the resulting snapshot.
If you believe this pull request should receive an exemption, please comment and provide a justification. A comment requesting an exemption should contain the text Exemption Request. Additionally, if clarification is needed, add Clarification Request to a comment.
✅ A exemption request has been requested. Please wait for a maintainer's review.
Author
|
Exemption Request: integration test + snapshot for this fix. Justification:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #37783.
TableV2MultiAccountReplicarendered replica-levelSSESpecification.KMSMasterKeyIdbut omitted the top-levelSSESpecificationonAWS::DynamoDB::GlobalTable, which CloudFormation reads as SSE disabled and rejects when replicas carry KMS keys (ReplicaSSESpecification and SSEType must be null when SSE is set to default).One-line fix in
packages/aws-cdk-lib/aws-dynamodb/lib/table-v2.ts, mirroringTableV2(which always rendersencryption._renderSseSpecification()): render the top-level spec fromprops.encryption. Per-type behavior is unchanged and matchesTableV2—dynamoOwnedKey()renders{sseEnabled: false},awsManagedKey()/customerManagedKey()render{sseEnabled: true, sseType: 'KMS'}.Extended the existing
TableV2MultiAccountReplica with custom encryptiontest to assert the top-levelSSEEnabled/SSETypealongside the replicaKMSMasterKeyId.Note: could not run the package suite locally — a fresh clone needs the full monorepo bootstrap (
cdk-build-tools+ codegen) before jest resolves generated modules, which exceeds this environment. The change mirrors the establishedTableV2pattern line-for-line; leaving full verification to CI.