AWS Security ChangesHomeSearch

AWS aurora-dsql: Update CDC setup links and handle unknown record types in sample script

Service: aurora-dsql · 2026-09-27 · Documentation low

File: aurora-dsql/latest/userguide/cdc-setup.md

Summary

Reworks cross-reference wording to point to current record payload/field descriptions, and adds defensive handling in the Python Kinesis CDC consumer sample so records whose `record_type` is not "full" or "chunked" are detected, logged, and skipped instead of being processed.

Security assessment

The only functional change is input validation/tolerance in a documentation sample consumer script: unrecognized `record_type` values are logged and skipped rather than parsed. This is defensive coding for schema/format evolution, not a fix for a named vulnerability or a security control, and no credentials, encryption, or authorization behavior is affected.

Evidence

                    if record_type not in {"full", "chunked"}:
                        print(f"[UNKNOWN RECORD TYPE] type={record_type}")
                        continue

Diff

diff --git a/aurora-dsql/latest/userguide/cdc-setup.md b/aurora-dsql/latest/userguide/cdc-setup.md
index 09334b5ef..7b4c67b03 100644
--- a//aurora-dsql/latest/userguide/cdc-setup.md
+++ b//aurora-dsql/latest/userguide/cdc-setup.md
@@ -43 +43 @@ Measure the average on-disk row size to understand the volume that CDC will prod
-The CDC record envelope adds column names, metadata, and encoding overhead on top of the row size. For the exact record format, see [Record payload](./cdc-record-format.html#cdc-record-payload). For how Aurora DSQL handles records that exceed the Kinesis record size limit, see [Handling oversized records](./cdc-record-format.html#cdc-oversized-records). For the full set of Kinesis service limits, see [Amazon Kinesis Data Streams quotas and limits](https://docs.aws.amazon.com/streams/latest/dev/service-sizes-and-limits.html) in the _Amazon Kinesis Data Streams Developer Guide_.
+The CDC record envelope adds column names, metadata, and encoding overhead on top of the row size. For record payload examples, see [Record payload](./cdc-record-format.html#cdc-record-payload). For how Aurora DSQL handles records that exceed the Kinesis record size limit, see [Handling oversized records](./cdc-record-format.html#cdc-oversized-records). For the full set of Kinesis service limits, see [Amazon Kinesis Data Streams quotas and limits](https://docs.aws.amazon.com/streams/latest/dev/service-sizes-and-limits.html) in the _Amazon Kinesis Data Streams Developer Guide_.
@@ -257 +257 @@ Each record's `Data` field contains a JSON payload. When you use the AWS CLI, th
-For a complete description of each field, see [Understanding CDC records](./cdc-record-format.html).
+For descriptions of the current fields, see [Understanding CDC records](./cdc-record-format.html).
@@ -315,0 +316,3 @@ The following Python script reads CDC records from a Kinesis data stream and pri
+                    if record_type not in {"full", "chunked"}:
+                        print(f"[UNKNOWN RECORD TYPE] type={record_type}")
+                        continue