Description
Amazon MQ's PubliclyAccessible: true enables public access for connections from outside the VPC hosting the broker. Actual connectivity also depends on security groups and network settings; public access does not remove authentication or message permissions.
Use approved private connectivity when messaging is needed only between internal systems.
Potential impact
- A reachable broker can face unwanted login and exploitation attempts.
- Authentication or authorization weaknesses can combine with exposure to cause message disclosure, modification or service interruption.
Remediation
- Set
PubliclyAccessible: falsefor an internal-only broker and prepare private client connectivity and required security group rules. - Changing this property through CloudFormation requires broker replacement. Plan the new broker name, continuity of message processing, client cutover and downtime.
- Even when public access is required, minimize sources and service ports and verify authentication, message permissions and TLS. Test required connections and message operations after cutover.
Examples
These are alternatives for a new single-instance ActiveMQ broker. Supply a supported instance type, a subnet and security group in the same VPC, and a username. Store a valid broker password under the password key in Secrets Manager and grant the deployment principal permission to read it. Omitting the engine version uses the service default. These examples do not guarantee an uninterrupted update of an existing broker.
Before
Parameters:
BrokerName:
Type: String
HostInstanceType:
Type: String
SubnetId:
Type: AWS::EC2::Subnet::Id
SecurityGroupId:
Type: AWS::EC2::SecurityGroup::Id
BrokerUsername:
Type: String
BrokerPasswordSecretArn:
Type: String
Resources:
BasicBroker:
Type: AWS::AmazonMQ::Broker
Properties:
BrokerName: !Ref BrokerName
DeploymentMode: SINGLE_INSTANCE
EngineType: ACTIVEMQ
AutoMinorVersionUpgrade: true
HostInstanceType: !Ref HostInstanceType
SubnetIds:
- !Ref SubnetId
SecurityGroups:
- !Ref SecurityGroupId
Users:
- Username: !Ref BrokerUsername
Password: !Sub '{{resolve:secretsmanager:${BrokerPasswordSecretArn}:SecretString:password}}'
PubliclyAccessible: true
This enables public access. Also inspect the supplied network and security group to determine actual allowed connections.
After
Parameters:
BrokerName:
Type: String
HostInstanceType:
Type: String
SubnetId:
Type: AWS::EC2::Subnet::Id
SecurityGroupId:
Type: AWS::EC2::SecurityGroup::Id
BrokerUsername:
Type: String
BrokerPasswordSecretArn:
Type: String
Resources:
BasicBroker:
Type: AWS::AmazonMQ::Broker
Properties:
BrokerName: !Ref BrokerName
DeploymentMode: SINGLE_INSTANCE
EngineType: ACTIVEMQ
AutoMinorVersionUpgrade: true
HostInstanceType: !Ref HostInstanceType
SubnetIds:
- !Ref SubnetId
SecurityGroups:
- !Ref SecurityGroupId
Users:
- Username: !Ref BrokerUsername
Password: !Sub '{{resolve:secretsmanager:${BrokerPasswordSecretArn}:SecretString:password}}'
PubliclyAccessible: false
This disables public access. Verify that clients can reach the new broker privately and perform required message operations.