Amazon iconAmazonAug 31, 2026 ~6 min source read

Provision a secure Amazon DocumentDB cluster with Terraform

This approach transforms the infrastructure provisioning process into a reliable, repeatable pattern that scales with your organization's needs. Solution overview Amazon DocumentDB version 8.0 offers added support for drivers compatible with MongoDB API versions 6.0, 7.0, and 8.0.

Provision a secure Amazon DocumentDB cluster with Terraform

Share this story

Send the public story page.

Useful takeaways from this story.

This approach transforms the infrastructure provisioning process into a reliable, repeatable pattern that scales with your organization's needs.

This post demonstrates how to deploy a secure Amazon DocumentDB 8.0 cluster with multiple layers of security to protect your data:

Solution overview Amazon DocumentDB version 8.0 offers added support for drivers compatible with MongoDB API versions 6.0, 7.0, and 8.0.

The useful part

This approach transforms the infrastructure provisioning process into a reliable, repeatable pattern that scales with your organization's needs. Solution overview Amazon DocumentDB version 8.0 offers added support for drivers compatible with MongoDB API versions 6.0, 7.0, and 8.0. Amazon DocumentDB 8.0 also improves query latency by up to 7x and compression ratio by up to 5x, so you can build high-performance applications at a lower cost.

How it works

  • This post demonstrates how to deploy a secure Amazon DocumentDB 8.0 cluster with multiple layers of security to protect your data:
  • Using AWS Key Management Service (AWS KMS) customer managed keys to encrypt stored data.
  • Configuring encrypted Amazon CloudWatch logs for audit and profiler data, and enabling Performance Insights.
  • The following diagram shows the architecture of the Amazon DocumentDB 8.0 deployment within a VPC with private subnets across two Availability Zones.
  • An AWS account with permissions to create VPC, Amazon DocumentDB, AWS KMS, AWS Secrets Manager, CloudWatch, SSM Parameter Store, and AWS Identity and Access Management (IAM) resources.

What to take from it

The VPC enables enable_dns_hostnames and enable_dns_support because Amazon DocumentDB cluster endpoints are DNS names (for example, docdb-terraform-demo.cluster-xxxxx.us-east-1.docdb.amazonaws.com). The password does not appear in Terraform state, alleviating a common security risk. Deploying the Amazon DocumentDB cluster in an Amazon Virtual Private Cloud (Amazon VPC) with private subnets and no direct internet access.

Example or evidence

  • To clone the repository and examine the network module Open your terminal and clone the repository: git clone https://github.com/aws-samples/amazon-documentdb-samples.git cd...
  • Using AWS Secrets Manager managed passwords for secure credential handling.
  • Walkthrough In this walkthrough, we deploy a secure Amazon DocumentDB 8.0 cluster using Terraform.
  • AWS Command Line Interface (AWS CLI) configured with your credentials and appropriate AWS Region.

Details worth keeping

Provision a secure Amazon DocumentDB cluster with Terraform | AWS Database Blog Skip to Main Content AWS Database Blog Provision a secure Amazon DocumentDB cluster with Terraform Infrastructure as code (IaC) provides a systematic approach to managing deployments with version control, peer reviews, and automated deployments. For Amazon DocumentDB (with MongoDB compatibility), IaC makes sure critical security configurations like encryption keys, network isolation, and access controls are consistently applied across development, staging, and production environments. In this post, we show you how to provision a secure Amazon DocumentDB cluster using Terraform, implementing best practices and comprehensive security controls including encryption, authentication, network isolation, and monitoring.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app