Build Neptune graph database cluster configurations with serverless scaling, IAM auth, and stream settings.
Build Neptune graph database cluster configurations with serverless scaling, IAM auth, and stream settings.
Required Fields
DBClusterIdentifierEngineDBSubnetGroupNameInstancesOutput will appear here...Build a Neptune graph database cluster, optionally using Serverless V2 scaling (MinCapacity/MaxCapacity in Neptune Capacity Units) so the writer and reader instances scale compute automatically with query load rather than running fixed-size provisioned instances continuously. IamDatabaseAuthenticationEnabled lets IAM-based credentials authenticate to the cluster instead of (or alongside) a static database password, which matters for eliminating long-lived database credentials in favor of temporary, IAM-role-scoped access, but it needs the application's Gremlin/SPARQL/openCypher client configured to actually sign requests with SigV4, it's not a transparent drop-in for existing password-based client code.
IAM database authentication requires client-side SigV4 request signing, it's not a transparent swap for existing password-based Gremlin/SPARQL client code, budget for actual client library changes, not just a configuration flag flip on the cluster.
A Serverless V2 MinCapacity of 0 versus a small non-zero floor is a real latency-versus-cost tradeoff, don't default to 0 for a latency-sensitive production workload without testing what the actual cold-start delay looks like for your query patterns.
neptune_query_timeout should be set deliberately based on your legitimate slowest expected query, not left at an overly generous default, a timeout that's too permissive doesn't actually protect against the runaway-query scenario it's meant to guard against.
The builder validates that DBClusterIdentifier, Engine, DBSubnetGroupName, and Instances all resolve before accepting the JSON as a valid combined cluster-plus-instance creation request, the fields Neptune needs to identify, network-place, and provision the cluster; it can't verify the referenced KMS key, subnet group, or security groups actually exist, those checks happen only against the live account.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.