Skip to content

appsync-aurora-serverless-v2-rds-data-api-cdk: GraphQL over Aurora with zero Lambda - #3307

Open
NithinChandranR-AWS wants to merge 1 commit into
aws-samples:mainfrom
NithinChandranR-AWS:NithinChandranR-AWS-feature-appsync-aurora-serverless-v2-cdk
Open

NithinChandranR-AWS wants to merge 1 commit into
aws-samples:mainfrom
NithinChandranR-AWS:NithinChandranR-AWS-feature-appsync-aurora-serverless-v2-cdk

Conversation

@NithinChandranR-AWS

@NithinChandranR-AWS NithinChandranR-AWS commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

Description

An AWS AppSync GraphQL API reads and writes an Amazon Aurora Serverless v2 (PostgreSQL) database directly through the RDS Data API, with no AWS Lambda functions in the request path.

Architecture

GraphQL client -> AWS AppSync GraphQL API (API key auth, APPSYNC_JS resolvers) -> RDS Data API data source (HTTPS SQL, no AWS Lambda, no VPC-attached compute) -> Amazon Aurora Serverless v2 (PostgreSQL, Data API enabled, encrypted at rest). The admin credential lives in AWS Secrets Manager. Resolvers issue parameterised SQL via the @aws-appsync/utils/rds select/insert helpers. Removing any one of AWS AppSync, the RDS Data API, or Amazon Aurora Serverless v2 breaks the architecture.

Deployed and Tested

Deployed in us-west-2 and tested end-to-end: created the todos table via the RDS Data API, then ran a createTodo mutation followed by a listTodos query through the GraphQL endpoint and confirmed the row round-tripped from Amazon Aurora Serverless v2.

Checklist

  • IAM least-privilege (rds-data and Secrets Manager read scoped to the cluster and secret ARNs)
  • CDK synth passes
  • Deployed and tested end-to-end
  • Zero AWS Lambda; storage encrypted at rest; isolated VPC (no NAT)

…-relational pattern

AWS AppSync GraphQL API backed by Amazon Aurora Serverless v2 via the
RDS Data API, with zero AWS Lambda functions. APPSYNC_JS resolvers use
the rds module select/insert helpers with parameterised statements.
Least-privilege IAM scoped to the cluster and secret ARNs, storage
encrypted, isolated VPC.

Deploy-tested live in us-west-2: createTodo mutation and listTodos query
round-trip through AppSync to Aurora Serverless v2 verified end to end.
Aurora PostgreSQL pinned to 16.8 (GA).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants