Amazon MSK cluster inventory

Track Kafka clusters and streaming-data paths.

Description

AWS::MSK::Cluster declares a provisioned Kafka cluster. Cluster use is not itself a vulnerability; this asset information supports tracking data flows and operational ownership.

Potential impact

An omitted cluster can be missed during reviews of broker access, encryption, and incident response.

Remediation

Record the cluster’s owner, producers, and consumers, and check broker access, authentication, encryption, and monitoring.

Examples

These excerpts disable public access on an existing cluster that meets the public-access prerequisites. Supply a supported compatible KafkaVersion and three actual ClientSubnets in different AZs. Clients need private connectivity and IAM permissions; public access cannot be enabled during cluster creation.

Before

yaml
Resources:
  TestCluster:
    Type: AWS::MSK::Cluster
    Properties:
      ClusterName: ClusterWithAllProperties
      KafkaVersion: !Ref KafkaVersion
      NumberOfBrokerNodes: 3
      ClientAuthentication:
        Sasl:
          Iam:
            Enabled: true
        Unauthenticated:
          Enabled: false
      EncryptionInfo:
        EncryptionInTransit:
          ClientBroker: TLS
          InCluster: true
      BrokerNodeGroupInfo:
        InstanceType: kafka.m5.large
        ClientSubnets: !Ref ClientSubnets
        ConnectivityInfo:
          PublicAccess:
            Type: SERVICE_PROVIDED_EIPS

After

yaml
Resources:
  TestCluster:
    Type: AWS::MSK::Cluster
    Properties:
      ClusterName: ClusterWithAllProperties
      KafkaVersion: !Ref KafkaVersion
      NumberOfBrokerNodes: 3
      ClientAuthentication:
        Sasl:
          Iam:
            Enabled: true
        Unauthenticated:
          Enabled: false
      EncryptionInfo:
        EncryptionInTransit:
          ClientBroker: TLS
          InCluster: true
      BrokerNodeGroupInfo:
        InstanceType: kafka.m5.large
        ClientSubnets: !Ref ClientSubnets
        ConnectivityInfo:
          PublicAccess:
            Type: DISABLED

References