aws / aws/aws-cdk

(s3tables-alpha): support ReplicationConfiguration for TableBucket

Open
#37,653 2 comments 0 reactions 0 assignees View on GitHub
@aws-cdk/aws-s3tables-alpha effort/medium feature-request p2
Dominant language
TypeScript
Stars
12.9k
Forks
4.6k
Avg merge
2d 3h
Merged PRs (30d)
83

Description

### Describe the feature

Add support for S3 Tables Bucket replication by exposing the L1
`AWS::S3Tables::TableBucket` `ReplicationConfiguration` property through the
L2 `TableBucket` construct in `@aws-cdk/aws-s3tables-alpha`.

Related docs:
- https://docs.aws.amazon.com/AmazonS3/latest/userguide/s3-tables-replication.html
- https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-s3tables-tablebucket-replicationconfiguration.html

### Use Case

We want to replicate S3 Tables across Regions / accounts for DR and
cross-account analytics. The L1 already accepts `ReplicationConfiguration`,
but the L2 `TableBucket` has no first-class API, so users have to drop down
to the `CfnTableBucket` escape hatch today.

### Proposed Solution

Add two flat props to `TableBucketProps` (mirroring the pattern used by
`aws-s3`'s `replicationRole` / `replicationRules`):

```ts
export interface TableBucketProps {
// ... existing props

/**
* Destination table buckets to replicate to.
*
* @default - No replication
*/
readonly replicationDestinations?: ITableBucket[];

/**
* The role to be used by the replication.
*
* When setting this property, you must also set `replicationDestinations`.
*
* @default - a new role will be created.
*/
readonly replicationRole?: iam.IRole;
}

// Usage
const dest = TableBucket.fromTableBucketArn(this, 'Dest', 'arn:...');
new TableBucket(this, 'Source', {
tableBucketName: 'src',
replicationDestinations: [dest],
});
```

When `replicationRole` is omitted the construct creates a role with
least-privilege replication permissions and an `s3tables.amazonaws.com` trust
policy with `aws:SourceAccount` / `aws:SourceArn` confused-deputy conditions.

Notes:
- The CFN `ReplicationConfiguration` wraps destinations in a `rules: []`
array, but a rule currently has no fields other than `destinations`, so
flattening to a single `replicationDestinations: ITableBucket[]` avoids a
speculative abstraction. If AWS later adds per-rule settings (filter,
priority, etc.), we can evolve the API — breaking changes are acceptable
in the alpha package.
- Escape hatch remains available via `node.defaultChild` on the underlying
`CfnTableBucket`.

### Other Information

- L1 types (`CfnTableBucket.ReplicationConfigurationProperty` etc.) already
exist in `aws-cdk-lib/aws-s3tables`, so no L1 work is needed.
- Additive props, no breaking change.

### Acknowledgements

- [x] I may be able to implement this feature request
- [ ] This feature might incur a breaking change

### AWS CDK Library version (aws-cdk-lib)

2.250.0

### AWS CDK CLI version

2.1030.0

### Environment details (OS name and version, etc.)

macOS 14.6 (Darwin 23.6.0)

Contributor guide

Open the contributing guide

Research direction

Start by reading the TableBucket and TableBucketProps entry points in @aws-cdk/aws-s3tables-alpha, then compare them with the existing CfnTableBucket.ReplicationConfigurationProperty types and the aws-s3 replicationRole/replicationRules pattern. Verify the AWS S3 Tables replication documentation and define done as exposed destination and role props, correct L1 synthesis, and the required role permissions and trust conditions.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, typescript
Domain
cloud, infrastructure
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.