Description
Message brokers handle application messages and connection information. Amazon MQ always encrypts stored data and uses an AWS owned key by default. Omitting encryption_options does not mean plaintext storage.
Select a customer managed KMS key for an ActiveMQ broker when separate key policies or lifecycle management are required. Check whether the default key meets organizational requirements.
Potential impact
Unmet key-management requirements or loss of required key permissions can affect compliance and broker operation. Encryption at rest does not replace message permissions or protection in transit.
Remediation
- Choose default or customer managed keys according to requirements. For a customer managed key, set
kms_key_idanduse_aws_owned_key = false. - Verify the actual key and permissions, and inspect the Terraform plan for broker replacement. Encryption-key configuration changes require replacement, so plan message preservation and client cutover.
Examples
These are ActiveMQ excerpts. Define the referenced resources and variables, and select a supported engine-version and instance combination. Supply the password securely and restrict access to Terraform state, which stores its value.
Default encryption key
resource "aws_mq_broker" "mq_broker" {
broker_name = "example"
configuration {
id = aws_mq_configuration.test.id
revision = aws_mq_configuration.test.latest_revision
}
engine_type = "ActiveMQ"
engine_version = var.activemq_engine_version
host_instance_type = "mq.t2.micro"
security_groups = [aws_security_group.test.id]
user {
username = "ExampleUser"
password = var.broker_password
}
}
Default storage encryption applies. Check whether separate key-management requirements exist.
Customer managed key
resource "aws_mq_broker" "mq_broker" {
broker_name = "example"
configuration {
id = aws_mq_configuration.test.id
revision = aws_mq_configuration.test.latest_revision
}
engine_type = "ActiveMQ"
engine_version = var.activemq_engine_version
host_instance_type = "mq.t2.micro"
security_groups = [aws_security_group.test.id]
user {
username = "ExampleUser"
password = var.broker_password
}
encryption_options {
kms_key_id = "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
use_aws_owned_key = false
}
}
Replace the example ARN with a usable key ARN in the same Region. Selecting a key does not complete message permissions or networking.