Why this matters
- VaultCommerce purges expired session tokens and idempotency keys with TTL — no scheduled Scan jobs deleting rows one page at a time.
- Throttled requests (
ProvisionedThroughputExceededException) mean keys or capacity misconfigured — not "DynamoDB is down." - The Instagram-stories pattern — high write volume, time-ordered reads, automatic expiry — maps directly to VaultCommerce flash-sale countdown banners.
Partition key: USER#42Routes to shard
Items in partition
ORDER#2026-001Sort key
ORDER#2026-002Sort key
PROFILESort key
TTL automatic cleanup
aws dynamodb update-time-to-live \
--table-name VaultCommerce \
--time-to-live-specification "Enabled=true, AttributeName=expiresAt"
import time
table.put_item(Item={
"PK": f"IDEM#{token}",
"SK": "TOKEN",
"expiresAt": int(time.time()) + 86400, # epoch seconds
})
DynamoDB deletes expired items within ~48 hours at no WCU charge — do not rely on instant deletion for security-critical expiry; enforce TTL plus application checks.
Production knobs
- On-demand billing — default for unknown traffic; watch for cost spikes on scans.
- Point-in-time recovery — continuous backups for accidental deletes.
- CloudWatch —
ConsumedReadCapacityUnits,UserErrors, throttled requests. - PartiQL / BatchGet — batch reads up to 100 items per call for BFF layers.
Stories-style time-ordered pattern
VaultCommerce flash banners mirror social-stories access: many writes, read recent items per user, auto-expire.
{ "PK": "USER#42", "SK": "STORY#1710000000", "mediaUrl": "s3://...", "expiresAt": 1710086400 }
{ "PK": "USER#42", "SK": "STORY#1710003600", "mediaUrl": "s3://...", "expiresAt": 1710086400 }
table.query(
KeyConditionExpression=Key("PK").eq("USER#42") & Key("SK").begins_with("STORY#"),
ScanIndexForward=False,
Limit=10,
)
High-cardinality PK=USER#id spreads writes across partitions. TTL on expiresAt removes stale stories without batch jobs.
Monitoring and alarms
aws cloudwatch put-metric-alarm \
--alarm-name vaultcommerce-dynamo-throttles \
--metric-name UserErrors \
--namespace AWS/DynamoDB \
--dimensions Name=TableName,Value=VaultCommerce \
--statistic Sum --period 60 --threshold 10 \
--comparison-operator GreaterThanThreshold
Investigate throttles: hot partition keys, insufficient GSI capacity, or sudden scan in a deploy.
Quick recall
Everything you need if you only revisit this box.
- TTL deletes expired items asynchronously — ideal for tokens, stories, session data.
- On-demand scales automatically; still avoid scans and hot partition keys.
- Stories pattern:
PK=USER#, time-orderedSK, TTL onexpiresAt. - CloudWatch throttling alarms catch capacity and key-design issues early.
- Enable point-in-time recovery on production tables.
- VaultCommerce stores media in S3; DynamoDB holds keys, metadata, and expiry.
Test yourself
Answer these before moving on — recall is what makes it stick.