Description
SQS protects stored message bodies with server-side encryption. It supports SQS-managed encryption (SSE-SQS) and KMS-based encryption (SSE-KMS), so an absent kms_master_key_id does not establish that encryption is disabled.
Potential impact
If encryption at rest is actually disabled, message bodies lack that protection. SSE-SQS may also be insufficient where separate KMS key control is required.
Remediation
Check the queue’s current encryption mode. When KMS-based control is required, set kms_master_key_id and grant producers and consumers the required access to the key.
Examples
The revised example configures SSE-KMS with alias/MyQueueKey and retains the existing visibility timeout and message retention period. Check the queue to determine the first example’s effective encryption mode.
Before
- name: SQS 큐 생성
community.aws.sqs_queue:
name: my-queue
region: ap-southeast-2
default_visibility_timeout: 120
message_retention_period: 86400
After
- name: SQS 큐 생성
community.aws.sqs_queue:
name: my-queue
region: ap-southeast-2
default_visibility_timeout: 120
message_retention_period: 86400
kms_master_key_id: alias/MyQueueKey
kms_data_key_reuse_period_seconds: 3600