MSK cluster encryption settings need review

Distinguish MSK encryption defaults from actual transport settings and prevent plaintext communication.

Description

Amazon MSK always encrypts data at rest. If no KMS key is specified at creation, it uses an AWS managed key. By default, client–broker traffic requires TLS and traffic between brokers is also encrypted. Omitting EncryptionInfo does not by itself mean data is stored or transmitted in plaintext.

However, allowing PLAINTEXT or TLS_PLAINTEXT for client connections, or disabling InCluster, permits plaintext communication. Configure client authentication, topic permissions and network restrictions separately from TLS encryption.

Potential impact

An attacker with access to a plaintext communication path could observe or alter messages and sensitive information. Disabling a key or removing required permissions can disrupt access to stored data and service operation.

Remediation

  • Prepare clients for TLS and use ClientBroker: TLS and InCluster: true. Verify connectivity and permissions for legitimate producers and consumers.
  • Choose the default key or a customer managed key according to organizational requirements, and retain the required key permissions.
  • Review the change set for existing clusters. Changing InCluster through CloudFormation requires replacement, so plan data migration and client cutover.

Examples

These compare creation defaults with explicit settings. Supply a supported Kafka version, subnets in three distinct Availability Zones, and appropriate security groups. Configure client authentication and authorization separately.

Default encryption settings

yaml
Parameters:
  KafkaVersion:
    Type: String
  BrokerSubnets:
    Type: List<AWS::EC2::Subnet::Id>
  BrokerSecurityGroups:
    Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
  TestCluster:
    Type: AWS::MSK::Cluster
    Properties:
      ClusterName: ClusterWithAllProperties
      KafkaVersion: !Ref KafkaVersion
      NumberOfBrokerNodes: 3
      BrokerNodeGroupInfo:
        InstanceType: kafka.m5.large
        ClientSubnets: !Ref BrokerSubnets
        SecurityGroups: !Ref BrokerSecurityGroups

This uses the default encryption at rest and TLS settings. It does not establish that plaintext communication is permitted.

Explicit encryption settings and key

yaml
Parameters:
  KafkaVersion:
    Type: String
  BrokerSubnets:
    Type: List<AWS::EC2::Subnet::Id>
  BrokerSecurityGroups:
    Type: List<AWS::EC2::SecurityGroup::Id>
  DataKeyArn:
    Type: String
Resources:
  TestCluster:
    Type: AWS::MSK::Cluster
    Properties:
      ClusterName: ClusterWithAllProperties
      KafkaVersion: !Ref KafkaVersion
      NumberOfBrokerNodes: 3
      EncryptionInfo:
        EncryptionAtRest:
          DataVolumeKMSKeyId: !Ref DataKeyArn
        EncryptionInTransit:
          ClientBroker: TLS
          InCluster: true
      BrokerNodeGroupInfo:
        InstanceType: kafka.m5.large
        ClientSubnets: !Ref BrokerSubnets
        SecurityGroups: !Ref BrokerSecurityGroups

This specifies transport settings and a real KMS key ARN. Check key permissions and review replacement and cutover requirements before applying it to an existing cluster.

References