Amazon MSK brokers have public access enabled

Review the need for public Amazon MSK broker connections, and use private connectivity for internal-only clients.

Description

PublicAccess.Type: SERVICE_PROVIDED_EIPS enables public access to brokers in an MSK Provisioned cluster. Public connections require a supported cluster version, public subnets and routes, security group access, authentication and encryption. Public access does not itself grant unauthenticated message reads or writes.

Potential impact

  • Allowing unnecessary sources to broker ports can expose the service to unwanted connections and attacks.
  • Excessive permissions or authentication weaknesses can lead to event-data disclosure, modification or processing interruptions.

Remediation

  • Set PublicAccess.Type: DISABLED when public connectivity is unnecessary. First prepare private client paths and the correct bootstrap addresses.
  • If public connectivity is required, restrict security groups to approved sources and ports. Verify supported authentication, permissions, client-to-broker encryption and encryption between brokers.
  • Public access cannot be enabled while creating a new cluster. Update an existing cluster's connectivity and, after the operation completes, verify required client connections and message processing.

Examples

These compare public settings for an existing MSK Provisioned cluster. The first example, with public access enabled, is not for initial creation. Match the cluster name and other properties to the existing resource. Supply a supported Kafka version and broker type, subnets in three Availability Zones of the same VPC, and security groups; verify the Region supports that arrangement. Public connectivity requires internet-gateway routes, and client IAM permissions must be granted separately.

Before

yaml
Parameters:
  KafkaVersion:
    Type: String
  BrokerInstanceType:
    Type: String
  ClientSubnetIds:
    Type: List<AWS::EC2::Subnet::Id>
  SecurityGroupIds:
    Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
  TestCluster:
    Type: AWS::MSK::Cluster
    Properties:
      ClusterName: ClusterWithRequiredProperties
      KafkaVersion: !Ref KafkaVersion
      NumberOfBrokerNodes: 3
      ClientAuthentication:
        Sasl:
          Iam:
            Enabled: true
        Unauthenticated:
          Enabled: false
      EncryptionInfo:
        EncryptionInTransit:
          ClientBroker: TLS
          InCluster: true
      BrokerNodeGroupInfo:
        InstanceType: !Ref BrokerInstanceType
        ClientSubnets: !Ref ClientSubnetIds
        SecurityGroups: !Ref SecurityGroupIds
        ConnectivityInfo:
          PublicAccess:
            Type: SERVICE_PROVIDED_EIPS

This enables public broker access with IAM authentication and TLS. Also review network source restrictions and actual client permissions.

After

yaml
Parameters:
  KafkaVersion:
    Type: String
  BrokerInstanceType:
    Type: String
  ClientSubnetIds:
    Type: List<AWS::EC2::Subnet::Id>
  SecurityGroupIds:
    Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
  TestCluster:
    Type: AWS::MSK::Cluster
    Properties:
      ClusterName: ClusterWithRequiredProperties
      KafkaVersion: !Ref KafkaVersion
      NumberOfBrokerNodes: 3
      ClientAuthentication:
        Sasl:
          Iam:
            Enabled: true
        Unauthenticated:
          Enabled: false
      EncryptionInfo:
        EncryptionInTransit:
          ClientBroker: TLS
          InCluster: true
      BrokerNodeGroupInfo:
        InstanceType: !Ref BrokerInstanceType
        ClientSubnets: !Ref ClientSubnetIds
        SecurityGroups: !Ref SecurityGroupIds
        ConnectivityInfo:
          PublicAccess:
            Type: DISABLED

This disables public access only. Private network paths and IAM permissions remain necessary; verify client configuration as well.

References