Upgrade to Pro — share decks privately, control downloads, hide ads and more …

CSC510 Lecture 13

CSC510 Lecture 13

AWS DynamoDB
(20260925)

Avatar for Javier Gonzalez-Sanchez

Javier Gonzalez-Sanchez PRO

October 07, 2026

Transcript

  1. CSC 5100 Modern Software Engineering Lecture 12. DynamoDB Persistence Dr.

    Javier Gonzalez-Sanchez [email protected] www.javiergs.info ffi o ce: 14 -227
  2. Goal • Underst nd wh t Dyn moDB stores nd

    how J v t lks to it. • Con igure • Persist loc l m chine so AWS SDK code c n uthentic te. Temper tureL mbd result in Temper tureRe dings. • Verify the stored item with n integr tion test. a a a a a a a a f a a a a a a a a a a a a a a a 4 f • You should be ble to repe t the work low for YOUR service (comming next)
  3. Persistence Before After Request arrives Lambda computes a result Reading

    is stored in DynamoDB HTTP response is returned Result disappears after the request We can retrieve/analyze it later 5
  4. DynamoDB in 60 seconds • Dyn moDB is AWS’s m

    n ged NoSQL d t b se. • A t ble cont ins items; n item cont ins ttributes. • Every item must cont in the t ble’s prim ry key. • Non-key ttributes c n v ry from item to item. a a a a a a a a a a a a a a a pplic tion ccesses Dyn moDB through the AWS SDK. a a a a a a a 6 a • Our J v
  5. SQL vs. DynamoDB schema Relational table Define columns first. Rows

    follow the table schema. Example columns: id, value, from_unit, to_unit, result. DynamoDB table Define the primary key structure first. Non-key attributes are supplied per item. Items may have different non-key attributes. Application code should still enforce a sensible model. 7
  6. Same idea, different setup “Schemaless” does not mean “structureless.” Your

    application still needs a consistent data model. # DynamoDB table creation Primary key: id (String) # Application later stores: id, value, from, to, result, timestamp, sensor, ... 8
  7. Our table: TemperatureReadings • T ble n me: Temper tureRe

    dings • P rtition key: id (String) • The t ble de inition does not predecl re v lue, from, to, result, etc. • Temper tureL mbd supplies those ttributes when it stores n item. a a a a a a a a f a a a a 9 a The key identifies the item; the remaining attributes describe the reading.
  8. How does Java reach DynamoDB? • J v needs the

    AWS SDK for Dyn moDB. • The SDK provides Dyn moDbClient nd request/response cl sses. • The client signs requests using AWS credenti ls. • AWS checks the identity’s IAM permissions. a a speci ic AWS region. f a a a a a a 11 a • The request is sent to Dyn moDB in
  9. What the DynamoDB SDK gives us • Dyn moDbClient —

    entry point for Dyn moDB oper tions. • AttributeV lue — represents Dyn moDB v lues. • PutItemRequest / PutItemResponse — cre te or repl ce n item. • GetItemRequest / GetItemResponse — retrieve one item by key. • Sc nRequest / Sc nResponse — inspect items in t ble. a a a a a a a a a a a a a a 13 a • Query, Upd teItem, DeleteItem, nd more.
  10. Creating the client DynamoDbClient dynamoDb = DynamoDbClient.builder() .region(Region.US_WEST_2) .build(); Important

    question: where are the credentials? They are intentionally NOT in the Java source. 14
  11. Creating the client • Dyn moDbClient — the AWS SDK

    type. • dyn moDb — our reference to the client object. • builder() — st rts client con igur tion. • region(Region.US_WEST_2) — chooses the AWS region. • build() — cre tes the client. a a a f a a a a a 15 a • The client c n c ll putItem(), getItem(), sc n(), query(), upd teItem(), deleteItem(), …
  12. Authentication vs. authorization Authentication Who are you? Credentials establish an

    AWS identity. Typical error: credentials cannot be loaded. Authorization What may that identity do? IAM policies allow/deny DynamoDB actions. Typical error: AccessDeniedException. 16
  13. Note on credentials • My m chine w s lre

    dy con igured with AWS credenti ls. • The AWS SDK utom tic lly se rches supported credenti l sources. • Therefore builder().build() could uthentic te without credenti ls in the code. a a a a a f a a a f a a a a a a a a a 17 a • A new m chine m y not h ve th t con igur tion yet.
  14. AWS CLI con iguration $ aws configure 18 f AWS

    Access Key ID: ******** AWS Secret Access Key: ******** Default region name: us-west-2 Default output format: json
  15. Where AWS CLI con iguration lives ~/.aws/credentials ~/.aws/config # Example

    structure only — never share real secrets [default] aws_access_key_id = ******** aws_secret_access_key = ******** [default] region = us-west-2 19 f The AWS CLI and AWS SDK can use the same local configuration.
  16. Checkpoint 1: who does AWS think I am? $ aws

    sts get-caller-identity Run this before debugging Java. If it fails, fix authentication first. 20
  17. Checkpoint: can I reach DynamoDB? $ aws dynamodb list-tables --region

    us-west-2 { "TableNames": [ "TemperatureReadings" ] } If CLI access fails, the Java SDK is unlikely to succeed with the same identity/configuration. 21
  18. Local Java vs. deployed Lambda 22 Running JUnit locally Running

    in AWS Lambda Java/JUnit Lambda ↓ DynamoDbClient ↓ DynamoDbClient ↓ local credential provider ↓ Lambda execution role ↓ your AWS identity ↓ IAM permissions DynamoDB DynamoDB
  19. Inject the DynamoDB dependency We pass the dependency in instead

    of hiding its creation inside business logic. 23
  20. Our request low • Input body: { v lue: 77,

    from: F, to: C } • Temper tureL mbd p rses the request. • The service converts 77°F → 25°C. • It stores the re ding in Temper tureRe dings. a a a f a a a a 26 a • It returns the HTTP response.
  21. Common client operations Read/write one item putItem() — store/replace getItem()

    — retrieve by primary key updateItem() — change attributes deleteItem() — remove by key Read multiple items query() — efficient key-based access scan() — examine table items Scan is useful for this teaching test, but it is not the default choice for production reads. 27
  22. What should the test prove? • A 200 response proves

    the h ndler returned success. • It does NOT by itself prove th t Dyn moDB cont ins the expected item. • Our new test c lls the L mbd nd then re ds Dyn moDB. a a a a a a a a a a a a a a a a a 29 a • Th t m kes it n integr tion test: J v + AWS SDK + re l Dyn moDB.
  23. Step 1: connect + execute DynamoDbClient dynamoDb = DynamoDbClient.builder().region(Region.US_WEST_2).build(); TemperatureLambda

    lambda = new TemperatureLambda(dynamoDb); event.put("body", "{\"value\":77,\"from\":\"F\",\"to\":\"C\"}"); Map<String, Object> response = lambda.handleRequest(event, null); assertEquals(200, response.get("statusCode")); At this point the Lambda should have written the item. 31
  24. Step 2: build a ScanRequest ScanRequest request = ScanRequest.builder() .tableName("TemperatureReadings")

    .build(); Building the request does NOT contact AWS yet. It describes what we want to do. 32
  25. Step 3: execute and receive a response ScanResponse scan =

    dynamoDb.scan(request); List<Map<String, AttributeValue>> items = scan.items(); dynamoDb.scan(request) is the network/service operation. ScanResponse contains the result. 33
  26. Why .s() and .n()? item.get("from").s() item.get("to").s() // "F" // "C"

    item.get("value").n() item.get("result").n() // "77" // "25" Double.parseDouble(item.get("value").n()) s() reads a DynamoDB String. n() returns the Number representation, which we parse when we need a Java numeric value. 34
  27. Step 4: verify the stored item boolean found = items.stream().anyMatch(item

    -> item.containsKey("value") && Double.parseDouble(item.get("value").n()) == 77.0 && item.get("from").s().equals("F") && item.get("to").s().equals("C") && Double.parseDouble(item.get("result").n()) == 25.0 ); assertTrue(found); The assertion now checks persistence, not only the HTTP response. 35
  28. Authentication vs. authorization Authentication Who are you? Credentials establish an

    AWS identity. Typical error: credentials cannot be loaded. Authorization What may that identity do? IAM policies allow/deny DynamoDB actions. Typical error: AccessDeniedException. 37
  29. Error: credentials cannot be loaded • Me ning: the SDK

    could not ind us ble credenti ls. • Check: ws sts get-c ller-identity • If using tempor ry credenti ls: refresh them. • Check the expected pro ile/con igur tion. a a a a a f f a f a a a f a 38 a • Do not “ ix” this by h rd-coding keys in J v .
  30. Error: AccessDeniedException • Me ning: AWS knows who you re,

    but IAM does not llow the requested ction. • Identify the ction: Sc n? PutItem? ListT bles? • Check the IAM policy/role ssigned by the course environment. a a a a a a a a a a a a a a 39 a • Loc l identity permissions nd L mbd execution-role permissions re sep r te.
  31. Error: ResourceNotFoundException • Check the t ble n me ex

    ctly: Temper tureRe dings. • Check the region: us-west-2. • Con irm the t ble exists in th t region in the AWS Console. a a a a a a a a a a f 40 a • A t ble c n exist in one region nd be invisible from nother.
  32. When the test fails but AWS is reachable • Inspect

    the t ble item in the AWS Console or CLI. • Check ttribute n mes: v lue vs. temper ture, from vs. fromUnit, etc. • Check Dyn moDB types: String vs. Number. • Check the expected conversion result. a a a a a a a a a 41 a • Use the f ilure to loc te the l yer: environment, AWS request, persistence, or ssertion.
  33. References • AWS Console — inspect t bles, items, region,

    nd IAM roles. • AWS CLI — verify identity nd isol te AWS ccess from J v . • AWS SDK for J v 2.x docs — discover request/response cl sses nd client methods. a a a a a a a a a a a a a a a a 42 a • IDE utocomplete / J v Doc — inspect Dyn moDbClient oper tions nd builder methods.
  34. Takeaways • Dyn moDB stores items; the t ble de

    ines the prim ry key, not every non-key ttribute. • Dyn moDbClient comes from the AWS SDK nd performs Dyn moDB oper tions. • Credenti ls should come from the environment—not source code. a a a ff a a a f a a a a f a a a a 43 a • Authentic tion, IAM permission, region, nd t ble con igur tion re di erent f ilure points.
  35. CSC 5100 Modern Software Engineering Javier Gonzalez-Sanchez, Ph.D. [email protected] Fall

    2026 Copyright. These slides may be used only as study material for CSC 5100 within the California State University system. They may not be distributed or used for any other purpose.