Description
Kafka streams carry messages and events between services, so broker communication and client connections need protection as well as stored data. Amazon MSK always encrypts stored data and uses the default AWS managed KMS key when no key is specified. By default, client connections require TLS and communication between brokers is encrypted.
Omitting encryption_info does not imply plaintext storage or transport. However, permitting PLAINTEXT or TLS_PLAINTEXT, or disabling in_cluster, allows plaintext communication. Configure client authentication and restrict topic permissions and network access separately from TLS.
Potential impact
An attacker with access to a plaintext communication path can eavesdrop on or alter messages and sensitive information. Disabling a KMS key or removing required permissions can disrupt data access and service operation.
Remediation
- Prepare clients for TLS and explicitly set
client_broker = "TLS"andin_cluster = true. Check connectivity and permissions for legitimate producers and consumers. - Choose the default key or a customer managed key according to organizational requirements, and maintain required permissions.
- For an existing cluster, review supported changes and any replacement in the Terraform plan. If replacement is needed, preserve data and prepare client and processing-workload cutover.
Examples
These excerpts compare encryption settings. Supply a supported Kafka version and required broker, subnet and security-group configuration separately. The second excerpt also needs the remaining cluster settings and a valid KMS key.
Before
resource "aws_msk_cluster" "msk_cluster" {
cluster_name = "example"
kafka_version = var.kafka_version
number_of_broker_nodes = 3
encryption_info {
encryption_in_transit {
client_broker = "PLAINTEXT"
in_cluster = false
}
}
}
This uses plaintext client connections and disables encryption between brokers. Stored data itself remains protected by MSK’s default encryption.
After
resource "aws_msk_cluster" "msk_cluster" {
encryption_info {
encryption_at_rest_kms_key_arn = aws_kms_key.kms.arn
encryption_in_transit {
client_broker = "TLS"
in_cluster = true
}
}
}
This encrypts client and inter-broker communication and specifies the key for stored data. It does not replace authentication and permission review.