Reusable Amazon DocumentDB module available on the Terraform Registry as native-cube/documentdb/aws.
Supports provisioned and Serverless instance clusters, mixed instance classes, global databases, Elastic clusters, snapshot and point-in-time restores, one-time snapshots, event subscriptions, parameter groups, subnet groups, security groups, and CloudWatch log groups.
The root module accepts existing VPCs, subnets, KMS keys, and SNS topics. Configure AWS providers in the calling configuration. Defaults include encrypted storage, seven-day backups, deletion protection and a required final snapshot for instance-based clusters, managed credentials for new standalone primaries, and no security group traffic rules until declared. The default compute configuration is one instance; add readers for compute redundancy.
Requires Terraform 1.11.4 or later and AWS provider 6.63.0 or later within v6. Install the module using its Registry source address:
module "documentdb" {
source = "native-cube/documentdb/aws"
version = "~> 1.0"
name = "orders-production"
engine_version = var.documentdb_engine_version
instance_class = var.documentdb_instance_class
vpc_id = var.vpc_id
subnet_ids = var.private_subnet_ids
final_snapshot_identifier = "orders-production-final-v1"
instances = {
writer = {}
reader = { promotion_tier = 1 }
}
ingress_rules = {
application = {
description = "Application database access"
referenced_security_group_id = var.application_security_group_id
}
}
tags = {
Environment = "production"
Service = "orders"
}
}The ~> 1.0 constraint accepts v1 releases and excludes v2. To select the initial release exactly, use version = "1.0.0". Review available versions and release-specific documentation on the Terraform Registry before upgrading.
Configure your AWS provider and supply the referenced input variables, then initialize and review the plan:
terraform init
terraform plan| Mode | Configuration |
|---|---|
| Provisioned | cluster_type = "instance" (default), with instances keyed by stable names |
| Serverless | Set serverless_v2_scaling_configuration and use db.serverless instances |
| Mixed compute | Override instance_class on individual entries to mix provisioned and Serverless instances |
| Global primary | create_global_cluster = true, with caller-managed credentials |
| Global secondary | Existing global_cluster_identifier, is_primary_cluster = false, and the secondary Region's provider or region |
| Global container only | create_cluster = false and create_global_cluster = true; optionally supply an existing external primary ARN |
| Elastic | cluster_type = "elastic", elastic_cluster, and elastic_admin_user_password |
| Disabled | create = false creates no resources or data lookups |
instances = {} permits a cluster whose compute is managed externally. Map keys determine Terraform addresses; an entry called writer does not permanently assign the writer role, which AWS may change during failover. Promotion tiers control failover priority.
Every documented configurable argument and nested configuration block for these eight resources is exposed directly, through a typed object, or through a module-managed relationship. Engine versions and instance classes are not restricted to a hard-coded release list. Read-only attributes, generated id, and provider-derived tags_all are not input arguments.
| Resource | Module configuration |
|---|---|
aws_docdb_cluster |
Cluster inputs, three password modes, restore/scaling blocks, cluster_timeouts, and managed network/parameter/global relationships |
aws_docdb_cluster_instance |
instances overrides and shared instance defaults; includes CA rotation, Performance Insights, identifier prefixes, maintenance and timeouts |
aws_docdb_global_cluster |
create_global_cluster, global_cluster_*, shared engine/encryption settings and timeouts |
aws_docdbelastic_cluster |
elastic_cluster, sensitive password input, shared backups/networking/encryption/tags, and Elastic timeouts |
aws_docdb_subnet_group |
Create/reuse subnet group, name/prefix, description, subnet IDs, Region and tags |
aws_docdb_cluster_parameter_group |
cluster_parameter_group, including name/prefix, family, description, parameters and tags |
aws_docdb_event_subscription |
event_subscriptions, including explicit or all-source subscriptions, SNS target, categories, names/prefixes, tags and timeouts |
aws_docdb_cluster_snapshot |
snapshots, including an optional external source, snapshot name and create timeout |
The provider exposes cluster_members as an optional computed set, but does not use it to create instances. Leave it null and manage membership with instances. Global containers and DocumentDB cluster snapshots do not expose tags in this provider version.
The resource set includes those in the dare-global reference module, plus global databases, Elastic clusters, snapshots, and event subscriptions. Implementation was verified against the AWS provider 6.63.0 source and its Elastic resource.
New standalone primaries use DocumentDB-managed passwords by default. master_user_secret_arn and master_user_secret expose secret metadata, never its password. This provider has no DocumentDB input for selecting the managed secret's KMS key; kms_key_id controls database storage encryption.
For caller-managed credentials, set manage_master_user_password = false, pass the ephemeral master_password_wo, and supply a positive master_password_wo_version. Increment the version whenever the password changes. Terraform 1.11+ sends the write-only value without persisting it in plan or state. The optional legacy master_password argument is sensitive but is stored in state; prefer the write-only alternative. These password modes conflict.
Restored primaries inherit credentials by default. After restoration completes, set manage_credentials_after_restore = true on a subsequent apply to enable the same password-management inputs while retaining the restore configuration. The inherited username remains unchanged. See the restore procedure below.
Global databases require caller-managed credentials on the primary; the module omits credentials on secondaries. This follows AWS's managed-password restrictions.
Elastic uses a separate elastic_admin_user_password. Its provider resource has no write-only argument, so Terraform stores that sensitive value in state. The provider exposes both PLAIN_TEXT and SECRET_ARN authentication enums; the runnable example uses PLAIN_TEXT. AWS currently lists Secrets Manager among Elastic limitations, so do not assume the API enum means the service supports that workflow in your deployment.
Supply private subnets in at least two Availability Zones. Live network checks validate the provided subnets, existing security groups, and reused subnet group's VPC/network type. Explicit availability_zones must contain three distinct AZs because AWS otherwise adds storage AZs, causing persistent Terraform differences. Null leaves storage AZ selection to AWS. network_type = "DUAL" requires IPv6-capable subnets.
Each security rule requires exactly one IPv4 CIDR, IPv6 CIDR, prefix list, or referenced security group. TCP/UDP ports default to the database port. Other protocols use the supplied ports/type/code; protocol -1 must omit ports. create_security_group = false requires existing security group IDs and means rule maps are not used. Use generated names for managed security/parameter groups to permit create-before-destroy replacement; fixed names may require an explicit rename when replacing a resource.
cluster_endpoint, cluster_reader_endpoint, and instances wait for module-managed instances and security group rules to complete before downstream Terraform resources consume them. elastic_cluster_endpoint similarly waits for the Elastic cluster and managed rules. These dependencies do not test database connectivity or wait for externally managed instances/rules. Use structural outputs such as security_group_id when wiring network rules; making a rule depend on an endpoint that waits for that rule would create a dependency cycle.
validate_engine_capabilities queries the selected Region for the requested engine version, instance class, Availability Zone, log exports and parameter family. Keep both validation switches enabled for normal plans. Mocked/offline consumers can disable them. Regional service combinations, quotas, Serverless availability, and global database eligibility remain AWS validations; a successful mocked plan does not prove deployability in an account.
Configure engine parameters to enable auditing/profiling and select the corresponding enabled_cloudwatch_logs_exports. Log groups are created first with configurable retention, KMS encryption, deletion protection and skip-destroy behavior. See AWS's two-step log export setup. Generated cluster identifier prefixes require create_cloudwatch_log_groups = false, since their eventual log group names are unknown before cluster creation. Other resources continue to use name as their naming base.
Set engine_version explicitly for controlled upgrades; null permits the AWS default. Instance minor upgrades and certificate settings are configurable. apply_immediately = false defers eligible changes to maintenance. storage_type = "iopt1" selects I/O-Optimized storage. Serverless DCUs support half-unit increments with minimum capacity at least 0.5 and maximum capacity from 1 to 256; removing the scaling block forces replacement.
Each instance can override enable_performance_insights. The shared performance_insights_kms_key_id is sent only to instances with Insights enabled, so an individual instance can disable Insights even when a shared key is configured. An explicit per-instance key still requires Insights to be enabled on that instance.
Choose one of snapshot_identifier or restore_to_point_in_time. PITR requires exactly one of an RFC3339 restore_to_time or use_latest_restorable_time = true. The restore example requires exactly one restore source and rejects empty snapshot names, preventing accidental creation of a fresh database when inputs are omitted. The root module continues to permit new clusters without a restore source.
For a restored primary, password management uses this sequence:
- Complete restoration with
manage_credentials_after_restore = false(the default), inheriting the source credentials. - Keep the original restore input configured and set
manage_credentials_after_restore = trueon a subsequent apply. Leavemanage_master_user_password = trueto adopt DocumentDB-managed passwords, or set it tofalseand providemaster_password_woplus a positivemaster_password_wo_versionfor caller-managed credentials. The legacy sensitivemaster_passwordis also supported. - For later write-only password rotations, update the ephemeral password and increment its version. Review the plan and the applicable
apply_immediatelysetting before applying.
Enabling password management does not set master_username; restores always retain the inherited username, avoiding a username-driven replacement. Global secondaries still receive no credentials. Keep the opt-in enabled while managing credentials and change the password mode or password explicitly; disabling the flag is not a rollback and can plan changes to password management. Do not enable it during the initial PITR creation: AWS provider 6.63.0 does not send password settings in that creation path, and write-only values cannot be recovered from state for a later retry. Restore first, then opt in and supply the password/version.
The provider's PITR creation path does not forward every ordinary cluster setting. Review a subsequent plan after restoration to reconcile settings such as backup retention, maintenance windows and parameter-group association. Storage encryption is inherited from the source; setting storage_encrypted = true is not a conversion mechanism for an unencrypted snapshot. The restore APIs do not attach global membership, so the module rejects a restore combined with a global identifier.
To create a global database from an existing primary, use a separate module call with create_cluster = false and global_cluster_source_db_cluster_identifier set to that external cluster ARN. The new container inherits engine, database name and encryption. The source cluster's owning configuration must account for the resulting global membership. Do not reference a cluster created by the same container call. Global major version upgrades and failovers have service-specific procedures; after a failover, reconcile role settings before applying Terraform. See the provider's global database documentation.
snapshots creates one-time snapshots after module-managed instances exist; it is not a recurring schedule. Use stable map keys and unique snapshot names. Omit a snapshot's cluster identifier to target this module's instance cluster, or supply an external instance-cluster identifier. Event subscriptions accept an existing SNS topic; use_cluster_source = true selects this module's instance cluster. Without that setting or explicit source filters, the subscription receives events for all sources supported by the selected categories.
Instance clusters require a unique final_snapshot_identifier unless final snapshots are explicitly skipped. Before deletion, disable applicable cluster/global/log-group deletion protection and review the resulting plan. Change final snapshot names before deleting a recreated cluster to avoid collisions.
Elastic's separate API does not expose instance-cluster deletion protection, final-snapshot-on-delete, PITR, parameter groups, instance-level Performance Insights or DocumentDB global membership. Shared instance-only defaults such as deletion_protection, skip_final_snapshot, manage_master_user_password, instances, and instance tuning do not configure Elastic. Backups, maintenance, shard capacity/count, 1-16 instances per shard, networking and KMS settings do. The root module rejects explicit unsupported restore, global, Serverless, parameter and log-export combinations. See Elastic setup and shard limits.
- Basic: provisioned standalone cluster with managed credentials.
- Complete: writer/reader, I/O-Optimized storage, encryption, logging, parameters, events and a snapshot.
- Serverless: Serverless writer and reader.
- Global cluster: primary and secondary with regional providers and ephemeral primary credentials.
- Elastic: sharded deployment using the separate Elastic API.
- Restore: snapshot or point-in-time recovery.
Examples consume ../.. so they run against the repository checkout, and take existing infrastructure as required inputs. To use an example in another project, replace each module's local source with source = "native-cube/documentdb/aws" and add version = "~> 1.0", as shown in Usage. Engine versions remain caller-selected so examples do not silently choose an upgrade or assume regional availability.
Run make check for formatting, generated docs, initialization, validation, native Terraform tests, endpoint dependency checks, and validation of every example. Native tests use mocked providers; make test-dependencies checks dependency paths in Terraform's graph without contacting AWS APIs. Python 3 is required for the graph check. make lint runs TFLint; make security runs Trivy. make hooks enables the repository-local pre-commit hook.
GitHub Actions checks formatting, generated docs, TFLint and Trivy, then runs minimum and latest supported compatibility jobs. The minimum job explicitly pins AWS 6.63.0; the latest job upgrades within v6. Do not edit the generated documentation below manually; run make docs instead.
| Name | Version |
|---|---|
| terraform | >= 1.11.4 |
| aws | >= 6.63.0, < 7.0.0 |
| Name | Version |
|---|---|
| aws | >= 6.63.0, < 7.0.0 |
| Name | Type |
|---|---|
| aws_cloudwatch_log_group.main | resource |
| aws_docdb_cluster.main | resource |
| aws_docdb_cluster_instance.main | resource |
| aws_docdb_cluster_parameter_group.main | resource |
| aws_docdb_cluster_snapshot.main | resource |
| aws_docdb_event_subscription.main | resource |
| aws_docdb_global_cluster.main | resource |
| aws_docdb_subnet_group.main | resource |
| aws_docdbelastic_cluster.main | resource |
| aws_security_group.main | resource |
| aws_vpc_security_group_egress_rule.main | resource |
| aws_vpc_security_group_ingress_rule.main | resource |
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| allow_major_version_upgrade | Allow an explicit major engine version upgrade. | bool |
false |
no |
| apply_immediately | Apply modifications immediately instead of during the maintenance window. | bool |
false |
no |
| auto_minor_version_upgrade | Default instance automatic minor version upgrade setting. | bool |
true |
no |
| availability_zones | Optional cluster storage Availability Zones. Supply exactly three to avoid perpetual AWS-added AZ drift. | set(string) |
null |
no |
| backup_retention_period | Days to retain automated backups (1-35). | number |
7 |
no |
| ca_cert_identifier | Default instance CA certificate identifier. | string |
null |
no |
| certificate_rotation_restart | Default instance restart behavior for certificate rotation. | bool |
null |
no |
| cloudwatch_log_group_class | Class for exported service logs. DocumentDB service delivery uses STANDARD. | string |
"STANDARD" |
no |
| cloudwatch_log_group_deletion_protection | Protect managed log groups from deletion. | bool |
true |
no |
| cloudwatch_log_group_kms_key_id | Existing KMS key ARN for log encryption. | string |
null |
no |
| cloudwatch_log_group_retention_in_days | Retention for managed CloudWatch log groups. | number |
30 |
no |
| cloudwatch_log_group_skip_destroy | Retain log groups when removing them from Terraform management. | bool |
false |
no |
| cluster_identifier_prefix | Optional generated cluster-name prefix instead of name. Related resource names still use name. | string |
null |
no |
| cluster_members | Optional expected cluster member identifiers for provider drift detection. Membership is created through instances; normally leave null. | set(string) |
null |
no |
| cluster_parameter_group | Optional cluster parameter group, including TLS, audit, profiler, and other engine parameters. | object({ |
null |
no |
| cluster_timeouts | Optional create/update/delete operation timeouts; null uses provider defaults. | object({ create = optional(string), update = optional(string), delete = optional(string) }) |
null |
no |
| cluster_type | Deployment type: instance (provisioned or Serverless) or elastic. | string |
"instance" |
no |
| copy_tags_to_snapshot | Copy instance tags to instance snapshots. | bool |
true |
no |
| create | Whether to create module-managed resources. | bool |
true |
no |
| create_cloudwatch_log_groups | Create log groups before enabling exports. | bool |
true |
no |
| create_cluster | Whether to create a regional cluster. Set false for a global container or standalone event/snapshot resources. | bool |
true |
no |
| create_db_subnet_group | Create a subnet group for an instance cluster; false requires db_subnet_group_name. | bool |
true |
no |
| create_global_cluster | Create a DocumentDB global container. | bool |
false |
no |
| create_security_group | Create a security group with only explicitly declared rules. | bool |
true |
no |
| db_cluster_parameter_group_name | Existing cluster parameter group; conflicts with cluster_parameter_group. | string |
null |
no |
| db_subnet_group_description | Description of the managed subnet group. | string |
"DocumentDB subnet group" |
no |
| db_subnet_group_name | Name of an existing or module-created DocumentDB subnet group. | string |
null |
no |
| db_subnet_group_use_name_prefix | Generate a unique subnet group name using db_subnet_group_name or name as a prefix. | bool |
false |
no |
| deletion_protection | Protect instance-based clusters from deletion. | bool |
true |
no |
| egress_rules | Explicit egress rules keyed by stable names. TCP/UDP ports default to the database port; exactly one traffic source/destination is required. | map(object({ |
{} |
no |
| elastic_admin_user_password | Elastic administrator password or secret ARN according to auth_type. The provider persists this sensitive value in state and has no write-only alternative. | string |
null |
no |
| elastic_cluster | Required Elastic cluster settings when cluster_type is elastic. Provider auth_type supports PLAIN_TEXT or SECRET_ARN; service availability must be confirmed. | object({ |
null |
no |
| elastic_cluster_timeouts | Optional create/update/delete operation timeouts; null uses provider defaults. | object({ create = optional(string), update = optional(string), delete = optional(string) }) |
null |
no |
| enable_performance_insights | Enable Performance Insights on instances by default. | bool |
false |
no |
| enabled_cloudwatch_logs_exports | Instance cluster logs to export. Enable corresponding audit/profiler parameters as well. | set(string) |
[] |
no |
| engine | DocumentDB database engine. | string |
"docdb" |
no |
| engine_version | Engine version for instance-based and new global clusters. Null uses the AWS default; pin explicitly for controlled upgrades. | string |
null |
no |
| event_subscriptions | Subscriptions to existing SNS topics. Set use_cluster_source to target this instance cluster; otherwise pass source_type/source_ids or omit both for all sources. | map(object({ |
{} |
no |
| final_snapshot_identifier | Unique final snapshot name required unless skip_final_snapshot is true. Change before deleting a recreated cluster. | string |
null |
no |
| global_cluster_database_name | Optional provider database_name argument for a new empty global container; not used when inheriting from a source. | string |
null |
no |
| global_cluster_deletion_protection | Protect the global container from deletion. | bool |
true |
no |
| global_cluster_identifier | Existing global container to join, or new container name (defaults to -global). | string |
null |
no |
| global_cluster_source_db_cluster_identifier | Existing external primary cluster ARN for creating a global container. Requires create_cluster = false to avoid circular dependencies. | string |
null |
no |
| global_cluster_timeouts | Optional create/update/delete operation timeouts; null uses provider defaults. | object({ create = optional(string), update = optional(string), delete = optional(string) }) |
null |
no |
| ingress_rules | Explicit ingress rules keyed by stable names. TCP/UDP ports default to the database port; exactly one traffic source/destination is required. | map(object({ |
{} |
no |
| instance_class | Default instance class; any regionally supported class is accepted, including db.serverless. | string |
"db.r6g.large" |
no |
| instance_timeouts | Optional create/update/delete operation timeouts; null uses provider defaults. | object({ create = optional(string), update = optional(string), delete = optional(string) }) |
null |
no |
| instances | Instance configurations keyed by stable caller-chosen keys. Empty maps permit externally managed compute; used only for instance clusters. | map(object({ |
{ |
no |
| is_primary_cluster | Whether this is the primary cluster; false requires a global cluster identifier and omits credentials. | bool |
true |
no |
| kms_key_id | Existing KMS key ARN for cluster storage encryption; null uses the AWS-managed key. | string |
null |
no |
| manage_credentials_after_restore | Opt in to managing a restored primary's password after restoration completes. Enable on a subsequent apply, retaining the restore input. Uses the normal managed or caller-managed password settings; the inherited username is never changed. | bool |
false |
no |
| manage_master_user_password | Let DocumentDB manage the password in Secrets Manager. Set false for global databases or caller-managed passwords. Restored clusters inherit credentials unless manage_credentials_after_restore is enabled. | bool |
true |
no |
| master_password | Optional legacy caller-managed password stored in Terraform state. Prefer master_password_wo. Conflicts with managed passwords and write-only credentials. | string |
null |
no |
| master_password_wo | Ephemeral write-only password; never stored in plans or state. Supply a version to trigger rotation. | string |
null |
no |
| master_password_wo_version | Positive password rotation version. Increment whenever master_password_wo changes. | number |
null |
no |
| master_username | Primary cluster administrator username. Omitted for restores and global secondaries. | string |
"dbadmin" |
no |
| name | Cluster name and default prefix for related resources. | string |
n/a | yes |
| network_type | Instance cluster network stack. DUAL requires IPv6-capable subnets. | string |
"IPV4" |
no |
| performance_insights_kms_key_id | Default existing KMS key for instances with Performance Insights enabled. Omitted for instances that disable Performance Insights. | string |
null |
no |
| port | Database port; Elastic supports only 27017. | number |
27017 |
no |
| preferred_backup_window | Daily UTC backup window (hh:mm-hh:mm); null lets AWS select. | string |
null |
no |
| preferred_maintenance_window | Weekly UTC cluster maintenance window (ddd:hh:mm-ddd:hh:mm). | string |
null |
no |
| region | Optional resource Region; defaults to the AWS provider Region. | string |
null |
no |
| restore_to_point_in_time | Point-in-time restore source and exactly one time selection. Credentials are inherited unless manage_credentials_after_restore is enabled after restoration. | object({ |
null |
no |
| revoke_rules_on_delete | Revoke security group rules before deleting the group. | bool |
false |
no |
| security_group_description | Description of the managed security group. | string |
"DocumentDB access" |
no |
| security_group_ids | Existing VPC security groups to attach alongside the optional managed group. | list(string) |
[] |
no |
| security_group_name | Optional name of the module-created security group. | string |
null |
no |
| security_group_use_name_prefix | Generate a unique security group name from its configured name. | bool |
true |
no |
| serverless_v2_scaling_configuration | Serverless DCU range. Use db.serverless instances. Removing this block replaces the cluster. | object({ min_capacity = number, max_capacity = number }) |
null |
no |
| skip_final_snapshot | Skip the final instance-cluster snapshot at deletion. | bool |
false |
no |
| snapshot_identifier | Existing snapshot identifier or ARN to restore; conflicts with point-in-time restore. | string |
null |
no |
| snapshots | One-time snapshots keyed by stable names. Omit db_cluster_identifier to snapshot this module cluster after its instances are ready. | map(object({ |
{} |
no |
| storage_encrypted | Whether instance cluster storage is encrypted. Elastic always encrypts storage. | bool |
true |
no |
| storage_type | Instance cluster storage configuration: standard or I/O-Optimized (iopt1). | string |
"standard" |
no |
| subnet_ids | Existing private subnet IDs spanning at least two Availability Zones. | list(string) |
[] |
no |
| tags | Tags applied to all resources supporting tags, plus DocumentDB module identity tags. | map(string) |
{} |
no |
| validate_engine_capabilities | Query regional engine versions and instance offerings during planning. | bool |
true |
no |
| validate_network_configuration | Read subnet/security-group metadata to check VPC, AZ, and IPv6 compatibility. | bool |
true |
no |
| vpc_id | Existing VPC ID. Required when creating a security group; also used by network validation. | string |
null |
no |
| Name | Description |
|---|---|
| cloudwatch_log_group_arns | Log group ARNs keyed by export type. |
| cluster_arn | Cluster ARN. |
| cluster_endpoint | Writer DNS endpoint, available to dependent resources after module-managed instances and security group rules complete. |
| cluster_engine_version | Actual engine version. |
| cluster_hosted_zone_id | Endpoint Route 53 hosted zone ID. |
| cluster_identifier | Cluster identifier. |
| cluster_members | Cluster instance identifiers. |
| cluster_parameter_group_arn | Module-created parameter group ARN. |
| cluster_parameter_group_name | Managed or supplied cluster parameter group name. |
| cluster_port | Database port. |
| cluster_reader_endpoint | Reader DNS endpoint, available to dependent resources after module-managed instances and security group rules complete. |
| cluster_resource_id | Immutable regional cluster resource ID. |
| db_subnet_group_arn | Module-created subnet group ARN. |
| db_subnet_group_name | Managed or supplied subnet group name. |
| elastic_cluster_arn | Elastic cluster arn. |
| elastic_cluster_endpoint | Elastic cluster endpoint, available to dependent resources after the cluster and module-managed security group rules complete. |
| elastic_cluster_id | Elastic cluster id. |
| event_subscription_arns | Event subscription ARNs keyed by caller names. |
| global_cluster_arn | DocumentDB global container arn. |
| global_cluster_id | DocumentDB global container global cluster identifier. |
| global_cluster_members | DocumentDB global container global cluster members. |
| global_cluster_resource_id | DocumentDB global container global cluster resource id. |
| global_cluster_status | DocumentDB global container status. |
| instances | Instance metadata keyed by the caller-provided instance keys, available after module-managed instances and security group rules complete. |
| master_user_secret | Managed secret metadata only: ARN, KMS key, and status. No password is returned. |
| master_user_secret_arn | ARN of the DocumentDB-managed password secret, when available. |
| security_group_id | Module-created security group ID. |
| security_group_ids | Security group IDs attached to the cluster. |
| snapshot_arns | Snapshot ARNs keyed by caller names. |