SQS queue policy uses Principal '*'

Restrict a wildcard SQS queue principal to required accounts, roles or services and appropriate source conditions.

Description

Allowing Principal: "*" in an SQS queue policy can grant message operations more broadly than intended. Review Action, Resource, conditions and other policies together. A principal wildcard alone does not grant every reading, deletion or queue-administration operation.

Queues using server-side encryption (SSE) require HTTPS and Signature Version 4 and reject anonymous SendMessage and ReceiveMessage requests. Encryption does not replace access control; authenticated principals and services still need appropriately restricted permissions.

Potential impact

  • Broad effective sending permissions can let principals that do not need access inject messages and affect consumer results.
  • If reading or deletion is also allowed, message contents can be exposed or messages removed. Actual impact also depends on the application's validation and processing.

Remediation

  • Specify required accounts, roles or services in Principal, required operations in Action, and the actual queue ARN in Resource.
  • For SNS integration, combine the sns.amazonaws.com service principal, sqs:SendMessage, the target queue ARN and an aws:SourceArn condition for the approved source topic.
  • Keep queue encryption enabled and check required KMS permissions for integrated services and conditions or denies in other policies. Test that required delivery succeeds while unapproved principals and sources are denied.

Examples

Supply the ARN of my-queue in the specified account and Region as queue_arn, and the approved source topic ARN as sns_topic_arn. The policy does not create an SNS subscription; configure the subscription and required encryption permissions separately.

Before

yaml
- name: example
  community.aws.sqs_queue:
    name: my-queue
    region: ap-southeast-2
    policy:
      Version: "2012-10-17"
      Statement:
        Sid: First
        Effect: Allow
        Principal: "*"
        Action: sqs:SendMessage
        Resource: "{{ queue_arn }}"

The statement broadly allows principals to send messages. Applicable request requirements and other access controls still matter.

After

yaml
- name: example
  community.aws.sqs_queue:
    name: my-queue
    region: ap-southeast-2
    policy:
      Version: "2012-10-17"
      Statement:
        Sid: First
        Effect: Allow
        Principal:
          Service: sns.amazonaws.com
        Action: sqs:SendMessage
        Resource: "{{ queue_arn }}"
        Condition:
          ArnEquals:
            aws:SourceArn: "{{ sns_topic_arn }}"

Sending is restricted to the SNS service with the approved topic as its source. Verify successful delivery from that topic and rejection of requests from other sources.

References