Amazon MQ encryption key settings need review

Amazon MQ encrypts stored data by default. Verify and explicitly configure the key ownership and management required by your organization.

Description

Amazon MQ always encrypts data at rest. Omitting EncryptionOptions or a KMS key uses default encryption with an AWS-owned key; it does not disable encryption.

If your organization requires a customer-managed KMS key and a separate key policy, the default key may not meet that requirement. Check key ownership and permissions, while treating broker authentication and network access as separate controls.

Potential impact

  • The actual key-management arrangement may differ from organizational control or audit requirements.
  • Disabling or deleting a customer-managed key, or revoking required permissions, can disrupt broker operation.

Remediation

  • Check the actual broker settings and key-management requirements. Where an AWS-owned key is appropriate, UseAwsOwnedKey: true makes the choice explicit.
  • Where a customer-managed key is required, prepare a supported key and permissions, then configure UseAwsOwnedKey: false and KmsKeyId.
  • Changing encryption options through CloudFormation requires broker replacement. Plan message migration and client connectivity, then verify normal sending and receiving.

Examples

Supply an instance type supported for ActiveMQ in the Region and securely managed user credentials. The engine version uses the service default. Review the public-access setting separately; these examples are not complete production security configurations.

Default key selection

yaml
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
  BrokerInstanceType:
    Type: String
  BrokerUsername:
    Type: String
  BrokerPassword:
    Type: String
    NoEcho: true
Resources:
  BasicBroker:
    Type: AWS::AmazonMQ::Broker
    Properties:
      AutoMinorVersionUpgrade: true
      BrokerName: MyBasicBroker
      DeploymentMode: SINGLE_INSTANCE
      EngineType: ACTIVEMQ
      HostInstanceType: !Ref BrokerInstanceType
      PubliclyAccessible: true
      Users:
        - ConsoleAccess: true
          Groups:
            - MyGroup
          Password: !Ref BrokerPassword
          Username: !Ref BrokerUsername

Stored data remains encrypted with an AWS-owned key when the encryption options are omitted.

Explicit key selection

yaml
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
  BrokerInstanceType:
    Type: String
  BrokerUsername:
    Type: String
  BrokerPassword:
    Type: String
    NoEcho: true
Resources:
  BasicBroker:
    Type: AWS::AmazonMQ::Broker
    Properties:
      AutoMinorVersionUpgrade: true
      BrokerName: MyBasicBroker
      DeploymentMode: SINGLE_INSTANCE
      EncryptionOptions:
        UseAwsOwnedKey: true
      EngineType: ACTIVEMQ
      HostInstanceType: !Ref BrokerInstanceType
      PubliclyAccessible: true
      Users:
        - ConsoleAccess: true
          Groups:
            - MyGroup
          Password: !Ref BrokerPassword
          Username: !Ref BrokerUsername

This explicitly selects the same AWS-owned key option. It is not an example of using a customer-managed key.

References