Amazon MQ broker encryption key settings need review

Check Amazon MQ default storage encryption against organizational KMS key requirements.

Description

Message brokers handle application messages and connection information. Amazon MQ always encrypts stored data and uses an AWS owned key by default. Omitting encryption_options does not mean plaintext storage.

Select a customer managed KMS key for an ActiveMQ broker when separate key policies or lifecycle management are required. Check whether the default key meets organizational requirements.

Potential impact

Unmet key-management requirements or loss of required key permissions can affect compliance and broker operation. Encryption at rest does not replace message permissions or protection in transit.

Remediation

  • Choose default or customer managed keys according to requirements. For a customer managed key, set kms_key_id and use_aws_owned_key = false.
  • Verify the actual key and permissions, and inspect the Terraform plan for broker replacement. Encryption-key configuration changes require replacement, so plan message preservation and client cutover.

Examples

These are ActiveMQ excerpts. Define the referenced resources and variables, and select a supported engine-version and instance combination. Supply the password securely and restrict access to Terraform state, which stores its value.

Default encryption key

hcl
resource "aws_mq_broker" "mq_broker" {
  broker_name = "example"

  configuration {
    id       = aws_mq_configuration.test.id
    revision = aws_mq_configuration.test.latest_revision
  }

  engine_type        = "ActiveMQ"
  engine_version     = var.activemq_engine_version
  host_instance_type = "mq.t2.micro"
  security_groups    = [aws_security_group.test.id]

  user {
    username = "ExampleUser"
    password = var.broker_password
  }
}

Default storage encryption applies. Check whether separate key-management requirements exist.

Customer managed key

hcl
resource "aws_mq_broker" "mq_broker" {
  broker_name = "example"

  configuration {
    id       = aws_mq_configuration.test.id
    revision = aws_mq_configuration.test.latest_revision
  }

  engine_type        = "ActiveMQ"
  engine_version     = var.activemq_engine_version
  host_instance_type = "mq.t2.micro"
  security_groups    = [aws_security_group.test.id]

  user {
    username = "ExampleUser"
    password = var.broker_password
  }

  encryption_options {
    kms_key_id        = "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
    use_aws_owned_key = false
  }
}

Replace the example ARN with a usable key ARN in the same Region. Selecting a key does not complete message permissions or networking.

References