Description
A public MQ broker endpoint provides a path for connection attempts from the internet. Message brokers carry internal events and application communication, so public access should have a clear operational need. A public endpoint does not itself permit anonymous message access; authentication and permissions still apply.
Potential impact
- Unnecessary external connections and password-guessing attempts may increase.
- Compromise of an account or broker can expose or alter messages, or disrupt service.
Remediation
- If public connections are unnecessary, set publicly_accessible to false and prepare private connectivity for clients.
- Restrict ActiveMQ security groups and user permissions to actual clients and required operations, and use TLS.
- Changing this property requires broker replacement in Terraform. Plan message preservation, the new broker and client cutover, then verify required connections and rejection of unwanted access.
Examples
This is an ActiveMQ creation excerpt. Supply a supported activemq_engine_version and verify compatibility with the instance type. Configure users and networking separately, protecting passwords and Terraform state.
Before
resource "aws_mq_broker" "mq_broker" {
broker_name = "example"
engine_type = "ActiveMQ"
engine_version = var.activemq_engine_version
host_instance_type = "mq.t2.micro"
publicly_accessible = true
}
This requests a public broker endpoint. Authentication and authorization still need separate configuration.
After
resource "aws_mq_broker" "mq_broker" {
broker_name = "example"
engine_type = "ActiveMQ"
engine_version = var.activemq_engine_version
host_instance_type = "mq.t2.micro"
}
Omitting the property uses the provider default of false. For an existing broker, review replacement and private client connectivity before applying the change.