Build DocumentDB cluster configurations with instances, encryption, backup windows, and CloudWatch log exports.
Build DocumentDB cluster configurations with instances, encryption, backup windows, and CloudWatch log exports.
Required Fields
DBClusterIdentifierEngineMasterUsernameDBSubnetGroupNameInstancesOutput will appear here...Build a DocumentDB (MongoDB-compatible) cluster with a writer/reader instance topology spread across AZs, storage encryption via a customer-managed KMS key, and EnableCloudwatchLogsExports for audit and profiler logs, which aren't captured anywhere by default. DocumentDB's replication model is important to know going in: it's a single-writer, multi-reader architecture built on a distributed, auto-scaling cluster storage volume (similar to Aurora's architecture), not genuine multi-region multi-master, and it's MongoDB API-compatible up to specific supported MongoDB versions, not a literal MongoDB fork, meaning some MongoDB-specific features and driver behaviors aren't identical.
EnableCloudwatchLogsExports for audit/profiler logs needs to be turned on before you need it, there's no retroactive audit trail if it wasn't enabled, treat it as a default-on setting for any production cluster from day one, not something to add reactively.
DocumentDB's MongoDB compatibility is real but bounded, verify your application's actual driver behavior and any aggregation pipeline features against DocumentDB's documented compatibility list before assuming a lift-and-shift from real MongoDB will work unchanged.
DeletionProtection is a cheap, high-value safeguard for any production cluster, there's essentially no operational downside to enabling it, and it's saved more than one team from an accidental destroy in a shared or misconfigured environment.
The builder validates that DBClusterIdentifier, Engine, MasterUsername, DBSubnetGroupName, and Instances all resolve before accepting the JSON as a valid combined CreateDBCluster plus CreateDBInstance request set, the fields needed to identify the cluster, its engine, credentials, network placement, and instance topology; it can't verify the referenced subnet group or security groups actually exist, or that MasterUserPassword meets DocumentDB's complexity requirements, those checks happen only against the live API.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.