Review encryption at rest for SQS messages

Check the encryption and key-management mode applied to stored SQS messages.

Description

SQS protects stored message bodies with server-side encryption. It supports SQS-managed encryption (SSE-SQS) and KMS-based encryption (SSE-KMS), so an absent kms_master_key_id does not establish that encryption is disabled.

Potential impact

If encryption at rest is actually disabled, message bodies lack that protection. SSE-SQS may also be insufficient where separate KMS key control is required.

Remediation

Check the queue’s current encryption mode. When KMS-based control is required, set kms_master_key_id and grant producers and consumers the required access to the key.

Examples

The revised example configures SSE-KMS with alias/MyQueueKey and retains the existing visibility timeout and message retention period. Check the queue to determine the first example’s effective encryption mode.

Before

yaml
- name: SQS 큐 생성
  community.aws.sqs_queue:
    name: my-queue
    region: ap-southeast-2
    default_visibility_timeout: 120
    message_retention_period: 86400

After

yaml
- name: SQS 큐 생성
  community.aws.sqs_queue:
    name: my-queue
    region: ap-southeast-2
    default_visibility_timeout: 120
    message_retention_period: 86400
    kms_master_key_id: alias/MyQueueKey
    kms_data_key_reuse_period_seconds: 3600

References