DynamoDB
Connect DynamoDB step by step: the read-only user, its policy, and how each table's fields are worked out.
Connect it
- Name it: what to call this connection, and the deployment it belongs to.
- Name the region: the AWS region the tables are in.
- Create the read-only user: a read-only IAM user in your account, and its key.
- Add the access key: an access key for the reading identity.
- Choose what is read: optional: narrow it to some tables.
- Test the connection: check Convalesce can reach it with what you entered.
- Choose how often: how often Convalesce reads it.
- Review and connect: check everything, then save the connection.
Convalesce reads your DynamoDB tables through one read-only IAM user that you create in your own account. The connect screen writes the policy and the commands that create the user, scoped to the region you name.
DynamoDB is regional, so each region is its own connection.
Convalesce is a hosted service, so it connects to AWS or your storage over the internet. Nothing is installed on your side.
Before you start
Have these ready and the rest takes a few minutes:
- The AWS region your tables are in.
- The AWS CLI signed in as an IAM admin, to run one block of commands. Or an existing AWS connection in Convalesce whose key you want to share.
Connect it
In Convalesce, open Integrations, choose DynamoDB, and follow the steps. Each one is shown below as it looks on screen, with what it asks for and anything to copy and run.
Step 1 of 8: Name it
What to call this connection, and the deployment it belongs to.

| What it asks for | Needed | What to enter |
|---|---|---|
| Name | Yes | How it is listed in Convalesce. Something that says which one it is, if there will be more than one. For example, Orders database. |
| Deployment | Yes | Which environment this is. Choose the same one as the pipelines that write to it, so both name its tables alike. Choose one of: Production, Staging, Development, Test, Quality assurance, User acceptance, Pre-production, Sandbox. |
| Instance name | Optional | Only when you connect two of these in the same deployment, such as two production servers: it keeps their tables apart. Leave it empty otherwise. For example, eu1. |
Step 2 of 8: Name the region
The AWS region the tables are in.

DynamoDB is a regional service, and this connector doesn't loop through all regions on your behalf: aws_region must be set explicitly, and only tables in that region are read.
To cover multiple regions, add one connection per region.
| What it asks for | Needed | What to enter |
|---|---|---|
| AWS region | Yes | For example, us-west-2. |
Step 3 of 8: Create the read-only user
A read-only IAM user in your account, and its key.

Make one IAM user for Convalesce in your own account with only the policy below, and issue it an access key. The commands do all three.
The policy below reads only tables in the region you named. AWS's managed AmazonDynamoDBReadOnlyAccess works too, but reaches every table in every region.
dynamodb:ListTables and dynamodb:DescribeTable find tables and their key schema.
dynamodb:Scan is required because DynamoDB has no fixed schema and DescribeTable doesn't return one: the connector samples items and infers a schema from what it reads. Without Scan, tables show up with no fields.
There is no network rule to add: Convalesce calls AWS's own API, which is public. The exception is an IAM condition that limits source addresses (aws:SourceIp): it has to allow 34.66.85.47, the address Convalesce connects from.
cat > convalesce-read.json <<'EOF'
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ConvalesceList",
"Effect": "Allow",
"Action": ["dynamodb:ListTables"],
"Resource": "*"
},
{
"Sid": "ConvalesceRead",
"Effect": "Allow",
"Action": ["dynamodb:DescribeTable", "dynamodb:Scan"],
"Resource": "arn:aws:dynamodb:eu-west-1:*:table/*"
}
]
}
EOF
aws iam get-user --user-name convalesce-reader >/dev/null 2>&1 || aws iam create-user --user-name convalesce-reader
aws iam put-user-policy --user-name convalesce-reader --policy-name ConvalesceDynamoDBRead \
--policy-document file://convalesce-read.json
aws iam create-access-key --user-name convalesce-readerRun it as an IAM admin in your own account, where the AWS CLI is signed in (set AWS_PROFILE first if you use a named profile). It is safe to run again: the user is made once, and each tool's policy goes on under its own name. The last command prints AccessKeyId and SecretAccessKey once: paste them straight into the next step, nowhere else. AWS allows two keys per user, so delete an old one before issuing a third. In the IAM console instead, paste the JSON between the EOF lines as an inline policy.
Step 4 of 8: Add the access key
An access key for the reading identity.

An access key for an IAM user in your account that has only read access to these tables. Convalesce has no AWS identity of its own, so it reads only what that user is granted.
| What it asks for | Needed | What to enter |
|---|---|---|
| Access key ID | Yes | |
| Secret access key | Yes | Stored encrypted the moment you enter it, and shown to no one afterwards. |
| Session token | Optional | Only for temporary credentials. Stored encrypted the moment you enter it, and shown to no one afterwards. |
Step 5 of 8: Choose what is read (optional)
Optional: narrow it to some tables.

Everything the credential can see is read unless you narrow it here. List the tables you want, the ones to leave out, or both.
| What it asks for | Needed | What to enter |
|---|---|---|
| Tables to read | Optional | Add each one as region.table. A * stands for any part of a name, as in us-east-1.orders*. Leave this empty to read all tables. For example, us-east-1.orders*. |
| Tables to skip | Optional | Written the same way. Anything added here is skipped even if it is also added above. |
Step 6 of 8: Test the connection
Check Convalesce can reach it with what you entered.

The test runs on the same worker a real run would, with the recipe exactly as it will be saved, so it fails the way a run would.
Step 7 of 8: Choose how often
How often Convalesce reads it.

Step 8 of 8: Review and connect
Check everything, then save the connection.

Network
There is no network rule to add: Convalesce calls AWS's own API, which is public. The exception is an IAM condition that limits source addresses (aws:SourceIp): it has to allow 34.66.85.47, the address Convalesce connects from.
Settings
What the connect screen asks for
| Input | On the step | Needed |
|---|---|---|
| Name | Name it | Yes |
| Deployment | Name it | Yes |
| Instance name | Name it | Optional |
| AWS region | Name the region | Yes |
| Access key ID | Add the access key | Yes |
| Secret access key | Add the access key | Yes |
| Session token | Add the access key | Optional |
| Tables to read | Choose what is read | Optional |
| Tables to skip | Choose what is read | Optional |
Set for you
These are the same on every connection. The connect screen does not ask for them.
| What it means | Setting |
|---|---|
| Something that is no longer there is marked as removed. | stateful_ingestion.enabled: true |
Troubleshooting
AccessDenied. The policy has to be attached to the user whose key you entered. Run the commands on Create the read-only user again.- A table shows no fields. The policy is missing
dynamodb:Scan, or the table is empty. - A table is missing. It is in another region, or left out on Choose what is read.







