CloudFormation 24 itself knows nothing about DynamoDB 24 . Each resource type is a resource provider in the CloudFormation registry: a JSON schema for its properties plus handlers, code that calls the service. Beside AWS 24 's own AWS:: types, the registry holds third-party extensions you activate (such as MongoDB 1,815 ::Atlas::Cluster), private types, modules (Modules) and hooks. The schemas are public:
mkdir -p ~/v5-ch7/schemas && cd ~/v5-ch7/schemas
curl -sSLO https://schema.cloudformation.us-east-1.amazonaws.com/CloudformationSchema.zip
unzip -oq CloudformationSchema.zip && ls aws-*.json | wc -l
jq -c '.primaryIdentifier, .createOnlyProperties, .readOnlyProperties' aws-dynamodb-table.json
jq -r '.handlers | to_entries[] | "\(.key): \(.value.permissions | length) permissions"' \
aws-dynamodb-table.json1794 ["/properties/TableName"] ["/properties/TableName","/properties/ImportSourceSpecification"] ["/properties/Arn","/properties/StreamArn"] read: 7 permissions create: 45 permissions update: 35 permissions list: 1 permissions delete: 2 permissions
primaryIdentifier is what the physical ID is made of. createOnlyProperties force a replacement when changed: renaming a table creates a new, empty one. readOnlyProperties can be read with Fn::GetAtt but never set. Each handler's permissions are what a deployment role needs for that type (IAM for CloudFormation). us-east-1 has 1,794 AWS:: types; LocalStack 4.13.1 63,725 ships 98 providers, each with a copy of AWS's schema (count the services/*/resource_providers/*.schema.json files in its container).