Description
Amazon MQ always encrypts data at rest. Omitting EncryptionOptions or a KMS key uses default encryption with an AWS-owned key; it does not disable encryption.
If your organization requires a customer-managed KMS key and a separate key policy, the default key may not meet that requirement. Check key ownership and permissions, while treating broker authentication and network access as separate controls.
Potential impact
- The actual key-management arrangement may differ from organizational control or audit requirements.
- Disabling or deleting a customer-managed key, or revoking required permissions, can disrupt broker operation.
Remediation
- Check the actual broker settings and key-management requirements. Where an AWS-owned key is appropriate,
UseAwsOwnedKey: truemakes the choice explicit. - Where a customer-managed key is required, prepare a supported key and permissions, then configure
UseAwsOwnedKey: falseandKmsKeyId. - Changing encryption options through CloudFormation requires broker replacement. Plan message migration and client connectivity, then verify normal sending and receiving.
Examples
Supply an instance type supported for ActiveMQ in the Region and securely managed user credentials. The engine version uses the service default. Review the public-access setting separately; these examples are not complete production security configurations.
Default key selection
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
BrokerInstanceType:
Type: String
BrokerUsername:
Type: String
BrokerPassword:
Type: String
NoEcho: true
Resources:
BasicBroker:
Type: AWS::AmazonMQ::Broker
Properties:
AutoMinorVersionUpgrade: true
BrokerName: MyBasicBroker
DeploymentMode: SINGLE_INSTANCE
EngineType: ACTIVEMQ
HostInstanceType: !Ref BrokerInstanceType
PubliclyAccessible: true
Users:
- ConsoleAccess: true
Groups:
- MyGroup
Password: !Ref BrokerPassword
Username: !Ref BrokerUsername
Stored data remains encrypted with an AWS-owned key when the encryption options are omitted.
Explicit key selection
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
BrokerInstanceType:
Type: String
BrokerUsername:
Type: String
BrokerPassword:
Type: String
NoEcho: true
Resources:
BasicBroker:
Type: AWS::AmazonMQ::Broker
Properties:
AutoMinorVersionUpgrade: true
BrokerName: MyBasicBroker
DeploymentMode: SINGLE_INSTANCE
EncryptionOptions:
UseAwsOwnedKey: true
EngineType: ACTIVEMQ
HostInstanceType: !Ref BrokerInstanceType
PubliclyAccessible: true
Users:
- ConsoleAccess: true
Groups:
- MyGroup
Password: !Ref BrokerPassword
Username: !Ref BrokerUsername
This explicitly selects the same AWS-owned key option. It is not an example of using a customer-managed key.