Skip to content

Conversation

@leonmk-aws
Copy link
Contributor

See CHANGELOG

xuxey and others added 3 commits August 27, 2025 16:25
…#35223)

### Issue # (if applicable)
Related to #33054 

### Reason for this change

This PR includes backward-compatible changes being made to add L2 support for the [CfnTable](https://docs.aws.amazon.com/cdk/api/v2/docs/aws-cdk-lib.aws_s3tables.CfnTable.html) and [CfnTablePolicy](https://docs.aws.amazon.com/cdk/api/v2/docs/aws-cdk-lib.aws_s3tables.CfnTablePolicy.html) constructs with a consistent user interface, recommended defaults, and in-built validations for managing Table level IAM resource policies.

### Description of changes

**New L2 Construct**: TablePolicy: defines an underlying [CfnTablePolicy](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-s3tables-tablepolicy.html) resource

**New methods added to Table construct**:
- `addToResourcePolicy`: Attaches a policy statement to the Table's IAM policy
- `grantRead`: Grants read access to the table for the given principal
- `grantWrite`: Grants write access to the table for the given principal
- `grantReadWrite`: Grants read and write access to the table for the given principal

### Describe any new or updated permissions being added


Method | IAM Actions | Description
-- | -- | --
table.grantRead | s3tables:Get* | Grants read permission to S3 Table
table.grantWrite | s3tables:PutTableData<br>s3tables:UpdateTableMetadataLocation<br>s3tables:RenameTable | Grants write permission to S3 Table
table.grantReadWrite | s3tables:Get*<br>s3tables:PutTableData<br>s3tables:UpdateTableMetadataLocation<br>s3tables:CreateTable | Grants read and write permissions to S3 Table


### Description of how you validated changes

- Unit tests
- Passing Integration tests with snapshots and assertions via API calls

### Checklist
- [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md)

----

*By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
### Reason for this change

Adding new feature for DynamoDB Contributor Insights Mode: https://docs.aws.amazon.com/AWSCloudFormation/latest/TemplateReference/aws-properties-dynamodb-table-contributorinsightsspecification.html#cfn-dynamodb-table-contributorinsightsspecification-mode

### Description of changes

Changes to Table and TableV2 to provide CCI Mode

### Describe any new or updated permissions being added




### Description of how you validated changes

Yes, integ and unit tests.

### Checklist
- [X] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md)

----

*By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
@leonmk-aws leonmk-aws added pr/no-squash This PR should be merged instead of squash-merging it pr-linter/analytics-metadata-change labels Aug 27, 2025
@github-actions github-actions bot added the p2 label Aug 27, 2025
@aws-cdk-automation aws-cdk-automation requested a review from a team August 27, 2025 14:34
@mergify mergify bot added the contribution/core This is a PR that came from AWS. label Aug 27, 2025
@mergify
Copy link
Contributor

mergify bot commented Aug 27, 2025

Thank you for contributing! Your pull request will be automatically updated and merged without squashing (do not update manually, and be sure to allow changes to be pushed to your fork).

@mergify mergify bot merged commit b7f0d30 into v2-release Aug 27, 2025
43 of 44 checks passed
@mergify mergify bot deleted the patch/v2.213.0 branch August 27, 2025 15:06
@github-actions
Copy link
Contributor

Comments on closed issues and PRs are hard for our team to see.
If you need help, please open a new issue that references this one.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Aug 27, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

contribution/core This is a PR that came from AWS. p2 pr/no-squash This PR should be merged instead of squash-merging it pr-linter/analytics-metadata-change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants