Skip to content

DynamoDB  >  Structures  >  SSESpecification

SSESpecification

Structure Class

SSESpecification dataclass

Represents the settings used to enable server-side encryption.

Attributes

enabled class-attribute instance-attribute
enabled: bool | None = None

Indicates whether server-side encryption is done using an Amazon Web Services managed key or an Amazon Web Services owned key. If enabled (true), server-side encryption type is set to KMS and an Amazon Web Services managed key is used (KMS charges apply). If disabled (false) or not specified, server-side encryption is set to Amazon Web Services owned key.

kms_master_key_id class-attribute instance-attribute
kms_master_key_id: str | None = None

The KMS key that should be used for the KMS encryption. To specify a key, use its key ID, Amazon Resource Name (ARN), alias name, or alias ARN. Note that you should only provide this parameter if the key is different from the default DynamoDB key alias/aws/dynamodb.

sse_type class-attribute instance-attribute
sse_type: SSEType | None = None

Server-side encryption type. The only supported value is:

  • KMS - Server-side encryption that uses Key Management Service. The key is stored in your account and is managed by KMS (KMS charges apply).