Description
AWS::AmazonMQ::Broker declares a managed message broker. Its presence belongs in the asset inventory and is not itself a vulnerability.
Potential impact
An unmanaged broker can be overlooked when reviewing access permissions and incident-response ownership.
Remediation
Record the broker’s owner and connected applications, and check network access, user authentication, and availability requirements.
Examples
These excerpts omit other required settings; the second selects a private multi-AZ deployment. Both encrypt stored data. Changing the deployment mode or public access of an existing broker requires considering replacement and migration.
Before
yaml
Resources:
BasicBroker:
Type: AWS::AmazonMQ::Broker
Properties:
BrokerName: MyBasicBroker
DeploymentMode: SINGLE_INSTANCE
PubliclyAccessible: true
EngineType: ACTIVEMQ
After
yaml
Resources:
BasicBroker:
Type: AWS::AmazonMQ::Broker
Properties:
BrokerName: MyBasicBroker
DeploymentMode: ACTIVE_STANDBY_MULTI_AZ
PubliclyAccessible: false
EngineType: ACTIVEMQ
EncryptionOptions:
UseAwsOwnedKey: true