Description
Amazon MSK always encrypts data at rest. If no KMS key is specified at creation, it uses an AWS managed key. By default, client–broker traffic requires TLS and traffic between brokers is also encrypted. Omitting EncryptionInfo does not by itself mean data is stored or transmitted in plaintext.
However, allowing PLAINTEXT or TLS_PLAINTEXT for client connections, or disabling InCluster, permits plaintext communication. Configure client authentication, topic permissions and network restrictions separately from TLS encryption.
Potential impact
An attacker with access to a plaintext communication path could observe or alter messages and sensitive information. Disabling a key or removing required permissions can disrupt access to stored data and service operation.
Remediation
- Prepare clients for TLS and use
ClientBroker: TLSandInCluster: true. Verify connectivity and permissions for legitimate producers and consumers. - Choose the default key or a customer managed key according to organizational requirements, and retain the required key permissions.
- Review the change set for existing clusters. Changing
InClusterthrough CloudFormation requires replacement, so plan data migration and client cutover.
Examples
These compare creation defaults with explicit settings. Supply a supported Kafka version, subnets in three distinct Availability Zones, and appropriate security groups. Configure client authentication and authorization separately.
Default encryption settings
Parameters:
KafkaVersion:
Type: String
BrokerSubnets:
Type: List<AWS::EC2::Subnet::Id>
BrokerSecurityGroups:
Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
TestCluster:
Type: AWS::MSK::Cluster
Properties:
ClusterName: ClusterWithAllProperties
KafkaVersion: !Ref KafkaVersion
NumberOfBrokerNodes: 3
BrokerNodeGroupInfo:
InstanceType: kafka.m5.large
ClientSubnets: !Ref BrokerSubnets
SecurityGroups: !Ref BrokerSecurityGroups
This uses the default encryption at rest and TLS settings. It does not establish that plaintext communication is permitted.
Explicit encryption settings and key
Parameters:
KafkaVersion:
Type: String
BrokerSubnets:
Type: List<AWS::EC2::Subnet::Id>
BrokerSecurityGroups:
Type: List<AWS::EC2::SecurityGroup::Id>
DataKeyArn:
Type: String
Resources:
TestCluster:
Type: AWS::MSK::Cluster
Properties:
ClusterName: ClusterWithAllProperties
KafkaVersion: !Ref KafkaVersion
NumberOfBrokerNodes: 3
EncryptionInfo:
EncryptionAtRest:
DataVolumeKMSKeyId: !Ref DataKeyArn
EncryptionInTransit:
ClientBroker: TLS
InCluster: true
BrokerNodeGroupInfo:
InstanceType: kafka.m5.large
ClientSubnets: !Ref BrokerSubnets
SecurityGroups: !Ref BrokerSecurityGroups
This specifies transport settings and a real KMS key ARN. Check key permissions and review replacement and cutover requirements before applying it to an existing cluster.