DynamoDB
Read every item insert, change and removal from DynamoDB Streams as a typed event. Use it to start workflows, fetch related items and write results back with conditional writes.
Database
Category
Streaming
Sync mode
p95 600 ms
Latency
8 min
Setup time
What it can do
- Item insertedStream
- Item modifiedStream
- Item removedStream
- TTL expiredStream
- Get an itemRead
- Query by keyRead
- Put an itemWrite
- Update an itemWrite
- Write with a conditionWrite
Overview
The DynamoDB connector reads the stream attached to each table you choose, so workflows react to item changes without scanning. Each record arrives as a typed event with the old and new images, and every event shows up in the trace of the run it started.
Teams use it to send a SendGrid receipt when an order item is written, to archive expired sessions to Amazon S3 and to sync subscription state from Stripe into a single table.
Supported features
Provisioned and on-demand tables, in Standard or Standard-IA class
Streams with
NEW_AND_OLD_IMAGES,NEW_IMAGEorKEYS_ONLYGlobal tables, read from the replica in the region you choose
How streams work
Tessel assumes an IAM role in your account and reads every shard of the stream with GetShardIterator and GetRecords. It checkpoints each shard after delivery and follows shard splits in order, so changes to the same key always arrive in sequence.
Stream retention
DynamoDB keeps stream records for 24 hours. If Tessel is paused for longer, it backfills with a parallel scan and marks the gap in the trace. Removals made by TTL carry the DynamoDB service as the principal, so Tessel types them as a separate trigger.
Permissions needed
Tessel signs in through a cross-account IAM role that trusts Tessel's account and checks an external ID. No access keys are stored. Write permissions are only required if a workflow puts or updates items.
dynamodb:DescribeStream,dynamodb:GetShardIteratoranddynamodb:GetRecordson the streamdynamodb:GetItemanddynamodb:Queryfor read actionsdynamodb:PutItemanddynamodb:UpdateItemonly on tables you write to
Five steps. About eight minutes.
Most of the time goes into the IAM role. Tessel assumes it once to check the trust policy before you continue.
- Turn on streams with new and old imagesAWS1 min
- Create an IAM role with Tessel's external IDAWS4 min
- Attach the stream and table policyAWS1 min
- Paste the role ARN and pick tablesTessel2 min
- Put a test item and watch the event arriveVerify600 ms
Every item change, in a workflow.
Connect DynamoDB on the free plan. Up to three builders and 10,000 runs a month, no card required.