Publicly accessible AWS MSK broker

Verify the need for public Kafka connectivity and restrict client access.

Description

MSK public access provides a path to Kafka brokers over the internet. A public endpoint does not mean unrestricted access to message streams, but it adds an external connection path. Actual access requires network permission and supported authentication and authorization.

Potential impact

  • External clients that do not need access may attempt connections.
  • Poorly managed credentials or permissions can lead to stream-data exposure, modification or processing interruptions.

Remediation

  • If public connections are unnecessary, set public_access.type to DISABLED. First prepare private client paths and the appropriate bootstrap broker addresses.
  • If public connectivity is required, allow only approved sources in security groups and configure authentication, TLS and required Kafka permissions.
  • Test actual client connectivity and rejection of unwanted access after the change. Disabling public access does not change subnets or automatically create private paths.

Examples

These excerpts compare connectivity settings for an existing cluster. MSK public access is enabled after cluster creation and requires service prerequisites such as public subnets, an internet gateway, TLS and authentication. Supply a supported kafka_version and configure the omitted broker, subnet and security settings separately.

Before

hcl
resource "aws_msk_cluster" "msk_cluster" {
  cluster_name           = "example"
  kafka_version          = var.kafka_version
  number_of_broker_nodes = 3

  broker_node_group_info {
    connectivity_info {
      public_access {
        type = "SERVICE_PROVIDED_EIPS"
      }
    }
  }
}

SERVICE_PROVIDED_EIPS requests public connectivity. Verify authentication and access from restricted sources before using it.

After

hcl
resource "aws_msk_cluster" "msk_cluster" {
  cluster_name           = "example"
  kafka_version          = var.kafka_version
  number_of_broker_nodes = 3

  broker_node_group_info {
    connectivity_info {
      public_access {
        type = "DISABLED"
      }
    }
  }
}

This disables public connectivity. Clients must use the prepared private path and corresponding bootstrap addresses.

References