Description
Allowing Action: "*" in an SQS queue policy can permit more operations than a message-processing workload needs. Separate permissions for message producers from those for receiving or deleting messages. Effective access also depends on principals, queue resources, conditions and permissions or denies in other policies.
SQS limits the actions that queue policies can grant across accounts. For example, DeleteQueue and SetQueueAttributes cannot be granted cross-account this way. A wildcard therefore does not establish that every external principal can administer the queue. Deleting messages and deleting the queue are separate operations.
Potential impact
- Excess effective permissions can allow unintended message reading, sending or deletion.
- Unwanted messages or message loss can affect consumer results, data flows between services and availability.
Remediation
- Specify the required actions, such as
sqs:SendMessageorsqs:ReceiveMessage, and remove unnecessary blanket grants. - Put the actual queue ARN in
Resourceand restrictPrincipaland conditions to approved accounts, roles or services. Review permissions and explicit denies in other policies too. - Inspect the applied queue policy and test that required message processing still works while unwanted requests are denied. In
community.aws1.5.0, omittingpolicyalone does not remove an existing queue policy.
Examples
These alternatives use the same queue and approved producer role. Supply the actual queue name, owning account, Region and ARN of an existing producer role. Check additional requirements, including relevant IAM permissions, for cross-account access.
Before
- name: SQS queue with broad policy
community.aws.sqs_queue:
name: "{{ queue_name }}"
region: "{{ aws_region }}"
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
AWS: "{{ producer_role_arn }}"
Action: "*"
Resource: "arn:aws:sqs:{{ aws_region }}:{{ aws_account_id }}:{{ queue_name }}"
state: present
All actions are allowed for the producer role, potentially exceeding what it needs to send messages.
After
- name: SQS queue with limited policy
community.aws.sqs_queue:
name: "{{ queue_name }}"
region: "{{ aws_region }}"
policy:
Version: "2012-10-17"
Statement:
- Effect: Allow
Principal:
AWS: "{{ producer_role_arn }}"
Action: sqs:SendMessage
Resource: "arn:aws:sqs:{{ aws_region }}:{{ aws_account_id }}:{{ queue_name }}"
state: present
This statement grants the role only message-sending permission. If a consumer is needed, grant receiving and deletion permissions separately to its role, and review the complete policy set.