Skip to content

Repository files navigation

Terraform AWS DocumentDB Module

Reusable Amazon DocumentDB module available on the Terraform Registry as native-cube/documentdb/aws.

Supports provisioned and Serverless instance clusters, mixed instance classes, global databases, Elastic clusters, snapshot and point-in-time restores, one-time snapshots, event subscriptions, parameter groups, subnet groups, security groups, and CloudWatch log groups.

The root module accepts existing VPCs, subnets, KMS keys, and SNS topics. Configure AWS providers in the calling configuration. Defaults include encrypted storage, seven-day backups, deletion protection and a required final snapshot for instance-based clusters, managed credentials for new standalone primaries, and no security group traffic rules until declared. The default compute configuration is one instance; add readers for compute redundancy.

Usage

Requires Terraform 1.11.4 or later and AWS provider 6.63.0 or later within v6. Install the module using its Registry source address:

module "documentdb" {
  source  = "native-cube/documentdb/aws"
  version = "~> 1.0"

  name                      = "orders-production"
  engine_version            = var.documentdb_engine_version
  instance_class            = var.documentdb_instance_class
  vpc_id                    = var.vpc_id
  subnet_ids                = var.private_subnet_ids
  final_snapshot_identifier = "orders-production-final-v1"

  instances = {
    writer = {}
    reader = { promotion_tier = 1 }
  }

  ingress_rules = {
    application = {
      description                  = "Application database access"
      referenced_security_group_id = var.application_security_group_id
    }
  }

  tags = {
    Environment = "production"
    Service     = "orders"
  }
}

The ~> 1.0 constraint accepts v1 releases and excludes v2. To select the initial release exactly, use version = "1.0.0". Review available versions and release-specific documentation on the Terraform Registry before upgrading.

Configure your AWS provider and supply the referenced input variables, then initialize and review the plan:

terraform init
terraform plan

Deployment modes

Mode Configuration
Provisioned cluster_type = "instance" (default), with instances keyed by stable names
Serverless Set serverless_v2_scaling_configuration and use db.serverless instances
Mixed compute Override instance_class on individual entries to mix provisioned and Serverless instances
Global primary create_global_cluster = true, with caller-managed credentials
Global secondary Existing global_cluster_identifier, is_primary_cluster = false, and the secondary Region's provider or region
Global container only create_cluster = false and create_global_cluster = true; optionally supply an existing external primary ARN
Elastic cluster_type = "elastic", elastic_cluster, and elastic_admin_user_password
Disabled create = false creates no resources or data lookups

instances = {} permits a cluster whose compute is managed externally. Map keys determine Terraform addresses; an entry called writer does not permanently assign the writer role, which AWS may change during failover. Promotion tiers control failover priority.

Provider coverage

Every documented configurable argument and nested configuration block for these eight resources is exposed directly, through a typed object, or through a module-managed relationship. Engine versions and instance classes are not restricted to a hard-coded release list. Read-only attributes, generated id, and provider-derived tags_all are not input arguments.

Resource Module configuration
aws_docdb_cluster Cluster inputs, three password modes, restore/scaling blocks, cluster_timeouts, and managed network/parameter/global relationships
aws_docdb_cluster_instance instances overrides and shared instance defaults; includes CA rotation, Performance Insights, identifier prefixes, maintenance and timeouts
aws_docdb_global_cluster create_global_cluster, global_cluster_*, shared engine/encryption settings and timeouts
aws_docdbelastic_cluster elastic_cluster, sensitive password input, shared backups/networking/encryption/tags, and Elastic timeouts
aws_docdb_subnet_group Create/reuse subnet group, name/prefix, description, subnet IDs, Region and tags
aws_docdb_cluster_parameter_group cluster_parameter_group, including name/prefix, family, description, parameters and tags
aws_docdb_event_subscription event_subscriptions, including explicit or all-source subscriptions, SNS target, categories, names/prefixes, tags and timeouts
aws_docdb_cluster_snapshot snapshots, including an optional external source, snapshot name and create timeout

The provider exposes cluster_members as an optional computed set, but does not use it to create instances. Leave it null and manage membership with instances. Global containers and DocumentDB cluster snapshots do not expose tags in this provider version.

The resource set includes those in the dare-global reference module, plus global databases, Elastic clusters, snapshots, and event subscriptions. Implementation was verified against the AWS provider 6.63.0 source and its Elastic resource.

Credentials

New standalone primaries use DocumentDB-managed passwords by default. master_user_secret_arn and master_user_secret expose secret metadata, never its password. This provider has no DocumentDB input for selecting the managed secret's KMS key; kms_key_id controls database storage encryption.

For caller-managed credentials, set manage_master_user_password = false, pass the ephemeral master_password_wo, and supply a positive master_password_wo_version. Increment the version whenever the password changes. Terraform 1.11+ sends the write-only value without persisting it in plan or state. The optional legacy master_password argument is sensitive but is stored in state; prefer the write-only alternative. These password modes conflict.

Restored primaries inherit credentials by default. After restoration completes, set manage_credentials_after_restore = true on a subsequent apply to enable the same password-management inputs while retaining the restore configuration. The inherited username remains unchanged. See the restore procedure below.

Global databases require caller-managed credentials on the primary; the module omits credentials on secondaries. This follows AWS's managed-password restrictions.

Elastic uses a separate elastic_admin_user_password. Its provider resource has no write-only argument, so Terraform stores that sensitive value in state. The provider exposes both PLAIN_TEXT and SECRET_ARN authentication enums; the runnable example uses PLAIN_TEXT. AWS currently lists Secrets Manager among Elastic limitations, so do not assume the API enum means the service supports that workflow in your deployment.

Networking, logging, and upgrades

Supply private subnets in at least two Availability Zones. Live network checks validate the provided subnets, existing security groups, and reused subnet group's VPC/network type. Explicit availability_zones must contain three distinct AZs because AWS otherwise adds storage AZs, causing persistent Terraform differences. Null leaves storage AZ selection to AWS. network_type = "DUAL" requires IPv6-capable subnets.

Each security rule requires exactly one IPv4 CIDR, IPv6 CIDR, prefix list, or referenced security group. TCP/UDP ports default to the database port. Other protocols use the supplied ports/type/code; protocol -1 must omit ports. create_security_group = false requires existing security group IDs and means rule maps are not used. Use generated names for managed security/parameter groups to permit create-before-destroy replacement; fixed names may require an explicit rename when replacing a resource.

cluster_endpoint, cluster_reader_endpoint, and instances wait for module-managed instances and security group rules to complete before downstream Terraform resources consume them. elastic_cluster_endpoint similarly waits for the Elastic cluster and managed rules. These dependencies do not test database connectivity or wait for externally managed instances/rules. Use structural outputs such as security_group_id when wiring network rules; making a rule depend on an endpoint that waits for that rule would create a dependency cycle.

validate_engine_capabilities queries the selected Region for the requested engine version, instance class, Availability Zone, log exports and parameter family. Keep both validation switches enabled for normal plans. Mocked/offline consumers can disable them. Regional service combinations, quotas, Serverless availability, and global database eligibility remain AWS validations; a successful mocked plan does not prove deployability in an account.

Configure engine parameters to enable auditing/profiling and select the corresponding enabled_cloudwatch_logs_exports. Log groups are created first with configurable retention, KMS encryption, deletion protection and skip-destroy behavior. See AWS's two-step log export setup. Generated cluster identifier prefixes require create_cloudwatch_log_groups = false, since their eventual log group names are unknown before cluster creation. Other resources continue to use name as their naming base.

Set engine_version explicitly for controlled upgrades; null permits the AWS default. Instance minor upgrades and certificate settings are configurable. apply_immediately = false defers eligible changes to maintenance. storage_type = "iopt1" selects I/O-Optimized storage. Serverless DCUs support half-unit increments with minimum capacity at least 0.5 and maximum capacity from 1 to 256; removing the scaling block forces replacement.

Each instance can override enable_performance_insights. The shared performance_insights_kms_key_id is sent only to instances with Insights enabled, so an individual instance can disable Insights even when a shared key is configured. An explicit per-instance key still requires Insights to be enabled on that instance.

Restore, global lifecycle, and snapshots

Choose one of snapshot_identifier or restore_to_point_in_time. PITR requires exactly one of an RFC3339 restore_to_time or use_latest_restorable_time = true. The restore example requires exactly one restore source and rejects empty snapshot names, preventing accidental creation of a fresh database when inputs are omitted. The root module continues to permit new clusters without a restore source.

For a restored primary, password management uses this sequence:

  1. Complete restoration with manage_credentials_after_restore = false (the default), inheriting the source credentials.
  2. Keep the original restore input configured and set manage_credentials_after_restore = true on a subsequent apply. Leave manage_master_user_password = true to adopt DocumentDB-managed passwords, or set it to false and provide master_password_wo plus a positive master_password_wo_version for caller-managed credentials. The legacy sensitive master_password is also supported.
  3. For later write-only password rotations, update the ephemeral password and increment its version. Review the plan and the applicable apply_immediately setting before applying.

Enabling password management does not set master_username; restores always retain the inherited username, avoiding a username-driven replacement. Global secondaries still receive no credentials. Keep the opt-in enabled while managing credentials and change the password mode or password explicitly; disabling the flag is not a rollback and can plan changes to password management. Do not enable it during the initial PITR creation: AWS provider 6.63.0 does not send password settings in that creation path, and write-only values cannot be recovered from state for a later retry. Restore first, then opt in and supply the password/version.

The provider's PITR creation path does not forward every ordinary cluster setting. Review a subsequent plan after restoration to reconcile settings such as backup retention, maintenance windows and parameter-group association. Storage encryption is inherited from the source; setting storage_encrypted = true is not a conversion mechanism for an unencrypted snapshot. The restore APIs do not attach global membership, so the module rejects a restore combined with a global identifier.

To create a global database from an existing primary, use a separate module call with create_cluster = false and global_cluster_source_db_cluster_identifier set to that external cluster ARN. The new container inherits engine, database name and encryption. The source cluster's owning configuration must account for the resulting global membership. Do not reference a cluster created by the same container call. Global major version upgrades and failovers have service-specific procedures; after a failover, reconcile role settings before applying Terraform. See the provider's global database documentation.

snapshots creates one-time snapshots after module-managed instances exist; it is not a recurring schedule. Use stable map keys and unique snapshot names. Omit a snapshot's cluster identifier to target this module's instance cluster, or supply an external instance-cluster identifier. Event subscriptions accept an existing SNS topic; use_cluster_source = true selects this module's instance cluster. Without that setting or explicit source filters, the subscription receives events for all sources supported by the selected categories.

Instance clusters require a unique final_snapshot_identifier unless final snapshots are explicitly skipped. Before deletion, disable applicable cluster/global/log-group deletion protection and review the resulting plan. Change final snapshot names before deleting a recreated cluster to avoid collisions.

Elastic's separate API does not expose instance-cluster deletion protection, final-snapshot-on-delete, PITR, parameter groups, instance-level Performance Insights or DocumentDB global membership. Shared instance-only defaults such as deletion_protection, skip_final_snapshot, manage_master_user_password, instances, and instance tuning do not configure Elastic. Backups, maintenance, shard capacity/count, 1-16 instances per shard, networking and KMS settings do. The root module rejects explicit unsupported restore, global, Serverless, parameter and log-export combinations. See Elastic setup and shard limits.

Examples

  • Basic: provisioned standalone cluster with managed credentials.
  • Complete: writer/reader, I/O-Optimized storage, encryption, logging, parameters, events and a snapshot.
  • Serverless: Serverless writer and reader.
  • Global cluster: primary and secondary with regional providers and ephemeral primary credentials.
  • Elastic: sharded deployment using the separate Elastic API.
  • Restore: snapshot or point-in-time recovery.

Examples consume ../.. so they run against the repository checkout, and take existing infrastructure as required inputs. To use an example in another project, replace each module's local source with source = "native-cube/documentdb/aws" and add version = "~> 1.0", as shown in Usage. Engine versions remain caller-selected so examples do not silently choose an upgrade or assume regional availability.

Development

Run make check for formatting, generated docs, initialization, validation, native Terraform tests, endpoint dependency checks, and validation of every example. Native tests use mocked providers; make test-dependencies checks dependency paths in Terraform's graph without contacting AWS APIs. Python 3 is required for the graph check. make lint runs TFLint; make security runs Trivy. make hooks enables the repository-local pre-commit hook.

GitHub Actions checks formatting, generated docs, TFLint and Trivy, then runs minimum and latest supported compatibility jobs. The minimum job explicitly pins AWS 6.63.0; the latest job upgrades within v6. Do not edit the generated documentation below manually; run make docs instead.

Module documentation

Requirements

Name Version
terraform >= 1.11.4
aws >= 6.63.0, < 7.0.0

Providers

Name Version
aws >= 6.63.0, < 7.0.0

Resources

Name Type
aws_cloudwatch_log_group.main resource
aws_docdb_cluster.main resource
aws_docdb_cluster_instance.main resource
aws_docdb_cluster_parameter_group.main resource
aws_docdb_cluster_snapshot.main resource
aws_docdb_event_subscription.main resource
aws_docdb_global_cluster.main resource
aws_docdb_subnet_group.main resource
aws_docdbelastic_cluster.main resource
aws_security_group.main resource
aws_vpc_security_group_egress_rule.main resource
aws_vpc_security_group_ingress_rule.main resource

Inputs

Name Description Type Default Required
allow_major_version_upgrade Allow an explicit major engine version upgrade. bool false no
apply_immediately Apply modifications immediately instead of during the maintenance window. bool false no
auto_minor_version_upgrade Default instance automatic minor version upgrade setting. bool true no
availability_zones Optional cluster storage Availability Zones. Supply exactly three to avoid perpetual AWS-added AZ drift. set(string) null no
backup_retention_period Days to retain automated backups (1-35). number 7 no
ca_cert_identifier Default instance CA certificate identifier. string null no
certificate_rotation_restart Default instance restart behavior for certificate rotation. bool null no
cloudwatch_log_group_class Class for exported service logs. DocumentDB service delivery uses STANDARD. string "STANDARD" no
cloudwatch_log_group_deletion_protection Protect managed log groups from deletion. bool true no
cloudwatch_log_group_kms_key_id Existing KMS key ARN for log encryption. string null no
cloudwatch_log_group_retention_in_days Retention for managed CloudWatch log groups. number 30 no
cloudwatch_log_group_skip_destroy Retain log groups when removing them from Terraform management. bool false no
cluster_identifier_prefix Optional generated cluster-name prefix instead of name. Related resource names still use name. string null no
cluster_members Optional expected cluster member identifiers for provider drift detection. Membership is created through instances; normally leave null. set(string) null no
cluster_parameter_group Optional cluster parameter group, including TLS, audit, profiler, and other engine parameters.
object({
name = optional(string)
use_name_prefix = optional(bool, true)
description = optional(string)
family = string
parameters = optional(list(object({ name = string, value = string, apply_method = optional(string, "immediate") })), [])
tags = optional(map(string), {})
})
null no
cluster_timeouts Optional create/update/delete operation timeouts; null uses provider defaults. object({ create = optional(string), update = optional(string), delete = optional(string) }) null no
cluster_type Deployment type: instance (provisioned or Serverless) or elastic. string "instance" no
copy_tags_to_snapshot Copy instance tags to instance snapshots. bool true no
create Whether to create module-managed resources. bool true no
create_cloudwatch_log_groups Create log groups before enabling exports. bool true no
create_cluster Whether to create a regional cluster. Set false for a global container or standalone event/snapshot resources. bool true no
create_db_subnet_group Create a subnet group for an instance cluster; false requires db_subnet_group_name. bool true no
create_global_cluster Create a DocumentDB global container. bool false no
create_security_group Create a security group with only explicitly declared rules. bool true no
db_cluster_parameter_group_name Existing cluster parameter group; conflicts with cluster_parameter_group. string null no
db_subnet_group_description Description of the managed subnet group. string "DocumentDB subnet group" no
db_subnet_group_name Name of an existing or module-created DocumentDB subnet group. string null no
db_subnet_group_use_name_prefix Generate a unique subnet group name using db_subnet_group_name or name as a prefix. bool false no
deletion_protection Protect instance-based clusters from deletion. bool true no
egress_rules Explicit egress rules keyed by stable names. TCP/UDP ports default to the database port; exactly one traffic source/destination is required.
map(object({
description = optional(string)
ip_protocol = optional(string, "tcp")
from_port = optional(number)
to_port = optional(number)
cidr_ipv4 = optional(string)
cidr_ipv6 = optional(string)
prefix_list_id = optional(string)
referenced_security_group_id = optional(string)
tags = optional(map(string), {})
}))
{} no
elastic_admin_user_password Elastic administrator password or secret ARN according to auth_type. The provider persists this sensitive value in state and has no write-only alternative. string null no
elastic_cluster Required Elastic cluster settings when cluster_type is elastic. Provider auth_type supports PLAIN_TEXT or SECRET_ARN; service availability must be confirmed.
object({
admin_user_name = optional(string, "dbadmin")
auth_type = optional(string, "PLAIN_TEXT")
shard_capacity = number
shard_count = number
shard_instance_count = optional(number, 2)
})
null no
elastic_cluster_timeouts Optional create/update/delete operation timeouts; null uses provider defaults. object({ create = optional(string), update = optional(string), delete = optional(string) }) null no
enable_performance_insights Enable Performance Insights on instances by default. bool false no
enabled_cloudwatch_logs_exports Instance cluster logs to export. Enable corresponding audit/profiler parameters as well. set(string) [] no
engine DocumentDB database engine. string "docdb" no
engine_version Engine version for instance-based and new global clusters. Null uses the AWS default; pin explicitly for controlled upgrades. string null no
event_subscriptions Subscriptions to existing SNS topics. Set use_cluster_source to target this instance cluster; otherwise pass source_type/source_ids or omit both for all sources.
map(object({
name = optional(string)
name_prefix = optional(string)
sns_topic_arn = string
enabled = optional(bool, true)
event_categories = optional(set(string))
source_type = optional(string)
source_ids = optional(set(string))
use_cluster_source = optional(bool, false)
tags = optional(map(string), {})
timeouts = optional(object({ create = optional(string), update = optional(string), delete = optional(string) }))
}))
{} no
final_snapshot_identifier Unique final snapshot name required unless skip_final_snapshot is true. Change before deleting a recreated cluster. string null no
global_cluster_database_name Optional provider database_name argument for a new empty global container; not used when inheriting from a source. string null no
global_cluster_deletion_protection Protect the global container from deletion. bool true no
global_cluster_identifier Existing global container to join, or new container name (defaults to -global). string null no
global_cluster_source_db_cluster_identifier Existing external primary cluster ARN for creating a global container. Requires create_cluster = false to avoid circular dependencies. string null no
global_cluster_timeouts Optional create/update/delete operation timeouts; null uses provider defaults. object({ create = optional(string), update = optional(string), delete = optional(string) }) null no
ingress_rules Explicit ingress rules keyed by stable names. TCP/UDP ports default to the database port; exactly one traffic source/destination is required.
map(object({
description = optional(string)
ip_protocol = optional(string, "tcp")
from_port = optional(number)
to_port = optional(number)
cidr_ipv4 = optional(string)
cidr_ipv6 = optional(string)
prefix_list_id = optional(string)
referenced_security_group_id = optional(string)
tags = optional(map(string), {})
}))
{} no
instance_class Default instance class; any regionally supported class is accepted, including db.serverless. string "db.r6g.large" no
instance_timeouts Optional create/update/delete operation timeouts; null uses provider defaults. object({ create = optional(string), update = optional(string), delete = optional(string) }) null no
instances Instance configurations keyed by stable caller-chosen keys. Empty maps permit externally managed compute; used only for instance clusters.
map(object({
identifier = optional(string)
identifier_prefix = optional(string)
instance_class = optional(string)
availability_zone = optional(string)
apply_immediately = optional(bool)
auto_minor_version_upgrade = optional(bool)
ca_cert_identifier = optional(string)
certificate_rotation_restart = optional(bool)
copy_tags_to_snapshot = optional(bool)
enable_performance_insights = optional(bool)
performance_insights_kms_key_id = optional(string)
preferred_maintenance_window = optional(string)
promotion_tier = optional(number, 0)
tags = optional(map(string), {})
timeouts = optional(object({ create = optional(string), update = optional(string), delete = optional(string) }))
}))
{
"one": {}
}
no
is_primary_cluster Whether this is the primary cluster; false requires a global cluster identifier and omits credentials. bool true no
kms_key_id Existing KMS key ARN for cluster storage encryption; null uses the AWS-managed key. string null no
manage_credentials_after_restore Opt in to managing a restored primary's password after restoration completes. Enable on a subsequent apply, retaining the restore input. Uses the normal managed or caller-managed password settings; the inherited username is never changed. bool false no
manage_master_user_password Let DocumentDB manage the password in Secrets Manager. Set false for global databases or caller-managed passwords. Restored clusters inherit credentials unless manage_credentials_after_restore is enabled. bool true no
master_password Optional legacy caller-managed password stored in Terraform state. Prefer master_password_wo. Conflicts with managed passwords and write-only credentials. string null no
master_password_wo Ephemeral write-only password; never stored in plans or state. Supply a version to trigger rotation. string null no
master_password_wo_version Positive password rotation version. Increment whenever master_password_wo changes. number null no
master_username Primary cluster administrator username. Omitted for restores and global secondaries. string "dbadmin" no
name Cluster name and default prefix for related resources. string n/a yes
network_type Instance cluster network stack. DUAL requires IPv6-capable subnets. string "IPV4" no
performance_insights_kms_key_id Default existing KMS key for instances with Performance Insights enabled. Omitted for instances that disable Performance Insights. string null no
port Database port; Elastic supports only 27017. number 27017 no
preferred_backup_window Daily UTC backup window (hh:mm-hh:mm); null lets AWS select. string null no
preferred_maintenance_window Weekly UTC cluster maintenance window (ddd:hh:mm-ddd:hh:mm). string null no
region Optional resource Region; defaults to the AWS provider Region. string null no
restore_to_point_in_time Point-in-time restore source and exactly one time selection. Credentials are inherited unless manage_credentials_after_restore is enabled after restoration.
object({
source_cluster_identifier = string
restore_type = optional(string, "full-copy")
restore_to_time = optional(string)
use_latest_restorable_time = optional(bool, false)
})
null no
revoke_rules_on_delete Revoke security group rules before deleting the group. bool false no
security_group_description Description of the managed security group. string "DocumentDB access" no
security_group_ids Existing VPC security groups to attach alongside the optional managed group. list(string) [] no
security_group_name Optional name of the module-created security group. string null no
security_group_use_name_prefix Generate a unique security group name from its configured name. bool true no
serverless_v2_scaling_configuration Serverless DCU range. Use db.serverless instances. Removing this block replaces the cluster. object({ min_capacity = number, max_capacity = number }) null no
skip_final_snapshot Skip the final instance-cluster snapshot at deletion. bool false no
snapshot_identifier Existing snapshot identifier or ARN to restore; conflicts with point-in-time restore. string null no
snapshots One-time snapshots keyed by stable names. Omit db_cluster_identifier to snapshot this module cluster after its instances are ready.
map(object({
db_cluster_snapshot_identifier = string
db_cluster_identifier = optional(string)
create_timeout = optional(string)
}))
{} no
storage_encrypted Whether instance cluster storage is encrypted. Elastic always encrypts storage. bool true no
storage_type Instance cluster storage configuration: standard or I/O-Optimized (iopt1). string "standard" no
subnet_ids Existing private subnet IDs spanning at least two Availability Zones. list(string) [] no
tags Tags applied to all resources supporting tags, plus DocumentDB module identity tags. map(string) {} no
validate_engine_capabilities Query regional engine versions and instance offerings during planning. bool true no
validate_network_configuration Read subnet/security-group metadata to check VPC, AZ, and IPv6 compatibility. bool true no
vpc_id Existing VPC ID. Required when creating a security group; also used by network validation. string null no

Outputs

Name Description
cloudwatch_log_group_arns Log group ARNs keyed by export type.
cluster_arn Cluster ARN.
cluster_endpoint Writer DNS endpoint, available to dependent resources after module-managed instances and security group rules complete.
cluster_engine_version Actual engine version.
cluster_hosted_zone_id Endpoint Route 53 hosted zone ID.
cluster_identifier Cluster identifier.
cluster_members Cluster instance identifiers.
cluster_parameter_group_arn Module-created parameter group ARN.
cluster_parameter_group_name Managed or supplied cluster parameter group name.
cluster_port Database port.
cluster_reader_endpoint Reader DNS endpoint, available to dependent resources after module-managed instances and security group rules complete.
cluster_resource_id Immutable regional cluster resource ID.
db_subnet_group_arn Module-created subnet group ARN.
db_subnet_group_name Managed or supplied subnet group name.
elastic_cluster_arn Elastic cluster arn.
elastic_cluster_endpoint Elastic cluster endpoint, available to dependent resources after the cluster and module-managed security group rules complete.
elastic_cluster_id Elastic cluster id.
event_subscription_arns Event subscription ARNs keyed by caller names.
global_cluster_arn DocumentDB global container arn.
global_cluster_id DocumentDB global container global cluster identifier.
global_cluster_members DocumentDB global container global cluster members.
global_cluster_resource_id DocumentDB global container global cluster resource id.
global_cluster_status DocumentDB global container status.
instances Instance metadata keyed by the caller-provided instance keys, available after module-managed instances and security group rules complete.
master_user_secret Managed secret metadata only: ARN, KMS key, and status. No password is returned.
master_user_secret_arn ARN of the DocumentDB-managed password secret, when available.
security_group_id Module-created security group ID.
security_group_ids Security group IDs attached to the cluster.
snapshot_arns Snapshot ARNs keyed by caller names.

About

Terraform module supporting creation of AWS DocumentDB resources

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages