Amazon MQ broker inventory

Track message-broker ownership and connection paths.

Description

AWS::AmazonMQ::Broker declares a managed message broker. Its presence belongs in the asset inventory and is not itself a vulnerability.

Potential impact

An unmanaged broker can be overlooked when reviewing access permissions and incident-response ownership.

Remediation

Record the broker’s owner and connected applications, and check network access, user authentication, and availability requirements.

Examples

These excerpts omit other required settings; the second selects a private multi-AZ deployment. Both encrypt stored data. Changing the deployment mode or public access of an existing broker requires considering replacement and migration.

Before

yaml
Resources:
  BasicBroker:
    Type: AWS::AmazonMQ::Broker
    Properties:
      BrokerName: MyBasicBroker
      DeploymentMode: SINGLE_INSTANCE
      PubliclyAccessible: true
      EngineType: ACTIVEMQ

After

yaml
Resources:
  BasicBroker:
    Type: AWS::AmazonMQ::Broker
    Properties:
      BrokerName: MyBasicBroker
      DeploymentMode: ACTIVE_STANDBY_MULTI_AZ
      PubliclyAccessible: false
      EngineType: ACTIVEMQ
      EncryptionOptions:
        UseAwsOwnedKey: true

References