Description
AWS::MSK::Cluster declares a provisioned Kafka cluster. Cluster use is not itself a vulnerability; this asset information supports tracking data flows and operational ownership.
Potential impact
An omitted cluster can be missed during reviews of broker access, encryption, and incident response.
Remediation
Record the cluster’s owner, producers, and consumers, and check broker access, authentication, encryption, and monitoring.
Examples
These excerpts disable public access on an existing cluster that meets the public-access prerequisites. Supply a supported compatible KafkaVersion and three actual ClientSubnets in different AZs. Clients need private connectivity and IAM permissions; public access cannot be enabled during cluster creation.
Before
Resources:
TestCluster:
Type: AWS::MSK::Cluster
Properties:
ClusterName: ClusterWithAllProperties
KafkaVersion: !Ref KafkaVersion
NumberOfBrokerNodes: 3
ClientAuthentication:
Sasl:
Iam:
Enabled: true
Unauthenticated:
Enabled: false
EncryptionInfo:
EncryptionInTransit:
ClientBroker: TLS
InCluster: true
BrokerNodeGroupInfo:
InstanceType: kafka.m5.large
ClientSubnets: !Ref ClientSubnets
ConnectivityInfo:
PublicAccess:
Type: SERVICE_PROVIDED_EIPS
After
Resources:
TestCluster:
Type: AWS::MSK::Cluster
Properties:
ClusterName: ClusterWithAllProperties
KafkaVersion: !Ref KafkaVersion
NumberOfBrokerNodes: 3
ClientAuthentication:
Sasl:
Iam:
Enabled: true
Unauthenticated:
Enabled: false
EncryptionInfo:
EncryptionInTransit:
ClientBroker: TLS
InCluster: true
BrokerNodeGroupInfo:
InstanceType: kafka.m5.large
ClientSubnets: !Ref ClientSubnets
ConnectivityInfo:
PublicAccess:
Type: DISABLED