Description
PublicAccess.Type: SERVICE_PROVIDED_EIPS enables public access to brokers in an MSK Provisioned cluster. Public connections require a supported cluster version, public subnets and routes, security group access, authentication and encryption. Public access does not itself grant unauthenticated message reads or writes.
Potential impact
- Allowing unnecessary sources to broker ports can expose the service to unwanted connections and attacks.
- Excessive permissions or authentication weaknesses can lead to event-data disclosure, modification or processing interruptions.
Remediation
- Set
PublicAccess.Type: DISABLEDwhen public connectivity is unnecessary. First prepare private client paths and the correct bootstrap addresses. - If public connectivity is required, restrict security groups to approved sources and ports. Verify supported authentication, permissions, client-to-broker encryption and encryption between brokers.
- Public access cannot be enabled while creating a new cluster. Update an existing cluster's connectivity and, after the operation completes, verify required client connections and message processing.
Examples
These compare public settings for an existing MSK Provisioned cluster. The first example, with public access enabled, is not for initial creation. Match the cluster name and other properties to the existing resource. Supply a supported Kafka version and broker type, subnets in three Availability Zones of the same VPC, and security groups; verify the Region supports that arrangement. Public connectivity requires internet-gateway routes, and client IAM permissions must be granted separately.
Before
Parameters:
KafkaVersion:
Type: String
BrokerInstanceType:
Type: String
ClientSubnetIds:
Type: List<AWS::EC2::Subnet::Id>
SecurityGroupIds:
Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
TestCluster:
Type: AWS::MSK::Cluster
Properties:
ClusterName: ClusterWithRequiredProperties
KafkaVersion: !Ref KafkaVersion
NumberOfBrokerNodes: 3
ClientAuthentication:
Sasl:
Iam:
Enabled: true
Unauthenticated:
Enabled: false
EncryptionInfo:
EncryptionInTransit:
ClientBroker: TLS
InCluster: true
BrokerNodeGroupInfo:
InstanceType: !Ref BrokerInstanceType
ClientSubnets: !Ref ClientSubnetIds
SecurityGroups: !Ref SecurityGroupIds
ConnectivityInfo:
PublicAccess:
Type: SERVICE_PROVIDED_EIPS
This enables public broker access with IAM authentication and TLS. Also review network source restrictions and actual client permissions.
After
Parameters:
KafkaVersion:
Type: String
BrokerInstanceType:
Type: String
ClientSubnetIds:
Type: List<AWS::EC2::Subnet::Id>
SecurityGroupIds:
Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
TestCluster:
Type: AWS::MSK::Cluster
Properties:
ClusterName: ClusterWithRequiredProperties
KafkaVersion: !Ref KafkaVersion
NumberOfBrokerNodes: 3
ClientAuthentication:
Sasl:
Iam:
Enabled: true
Unauthenticated:
Enabled: false
EncryptionInfo:
EncryptionInTransit:
ClientBroker: TLS
InCluster: true
BrokerNodeGroupInfo:
InstanceType: !Ref BrokerInstanceType
ClientSubnets: !Ref ClientSubnetIds
SecurityGroups: !Ref SecurityGroupIds
ConnectivityInfo:
PublicAccess:
Type: DISABLED
This disables public access only. Private network paths and IAM permissions remain necessary; verify client configuration as well.