SQS queue policy specifies Action '*'

Restrict blanket SQS queue permissions to required message operations and approved principals.

Description

Allowing Action: "*" in an SQS queue policy can permit more operations than a message-processing workload needs. Separate permissions for message producers from those for receiving or deleting messages. Effective access also depends on principals, queue resources, conditions and permissions or denies in other policies.

SQS limits the actions that queue policies can grant across accounts. For example, DeleteQueue and SetQueueAttributes cannot be granted cross-account this way. A wildcard therefore does not establish that every external principal can administer the queue. Deleting messages and deleting the queue are separate operations.

Potential impact

  • Excess effective permissions can allow unintended message reading, sending or deletion.
  • Unwanted messages or message loss can affect consumer results, data flows between services and availability.

Remediation

  • Specify the required actions, such as sqs:SendMessage or sqs:ReceiveMessage, and remove unnecessary blanket grants.
  • Put the actual queue ARN in Resource and restrict Principal and conditions to approved accounts, roles or services. Review permissions and explicit denies in other policies too.
  • Inspect the applied queue policy and test that required message processing still works while unwanted requests are denied. In community.aws 1.5.0, omitting policy alone does not remove an existing queue policy.

Examples

These alternatives use the same queue and approved producer role. Supply the actual queue name, owning account, Region and ARN of an existing producer role. Check additional requirements, including relevant IAM permissions, for cross-account access.

Before

yaml
- name: SQS queue with broad policy
  community.aws.sqs_queue:
    name: "{{ queue_name }}"
    region: "{{ aws_region }}"
    policy:
      Version: "2012-10-17"
      Statement:
        - Effect: Allow
          Principal:
            AWS: "{{ producer_role_arn }}"
          Action: "*"
          Resource: "arn:aws:sqs:{{ aws_region }}:{{ aws_account_id }}:{{ queue_name }}"
    state: present

All actions are allowed for the producer role, potentially exceeding what it needs to send messages.

After

yaml
- name: SQS queue with limited policy
  community.aws.sqs_queue:
    name: "{{ queue_name }}"
    region: "{{ aws_region }}"
    policy:
      Version: "2012-10-17"
      Statement:
        - Effect: Allow
          Principal:
            AWS: "{{ producer_role_arn }}"
          Action: sqs:SendMessage
          Resource: "arn:aws:sqs:{{ aws_region }}:{{ aws_account_id }}:{{ queue_name }}"
    state: present

This statement grants the role only message-sending permission. If a consumer is needed, grant receiving and deletion permissions separately to its role, and review the complete policy set.

References