Review MSK cluster encryption settings

Review MSK default storage encryption and require TLS for actual client and broker communication.

Description

Kafka streams carry messages and events between services, so broker communication and client connections need protection as well as stored data. Amazon MSK always encrypts stored data and uses the default AWS managed KMS key when no key is specified. By default, client connections require TLS and communication between brokers is encrypted.

Omitting encryption_info does not imply plaintext storage or transport. However, permitting PLAINTEXT or TLS_PLAINTEXT, or disabling in_cluster, allows plaintext communication. Configure client authentication and restrict topic permissions and network access separately from TLS.

Potential impact

An attacker with access to a plaintext communication path can eavesdrop on or alter messages and sensitive information. Disabling a KMS key or removing required permissions can disrupt data access and service operation.

Remediation

  • Prepare clients for TLS and explicitly set client_broker = "TLS" and in_cluster = true. Check connectivity and permissions for legitimate producers and consumers.
  • Choose the default key or a customer managed key according to organizational requirements, and maintain required permissions.
  • For an existing cluster, review supported changes and any replacement in the Terraform plan. If replacement is needed, preserve data and prepare client and processing-workload cutover.

Examples

These excerpts compare encryption settings. Supply a supported Kafka version and required broker, subnet and security-group configuration separately. The second excerpt also needs the remaining cluster settings and a valid KMS key.

Before

hcl
resource "aws_msk_cluster" "msk_cluster" {
  cluster_name           = "example"
  kafka_version          = var.kafka_version
  number_of_broker_nodes = 3

  encryption_info {
    encryption_in_transit {
      client_broker = "PLAINTEXT"
      in_cluster    = false
    }
  }
}

This uses plaintext client connections and disables encryption between brokers. Stored data itself remains protected by MSK’s default encryption.

After

hcl
resource "aws_msk_cluster" "msk_cluster" {
  encryption_info {
    encryption_at_rest_kms_key_arn = aws_kms_key.kms.arn

    encryption_in_transit {
      client_broker = "TLS"
      in_cluster    = true
    }
  }
}

This encrypts client and inter-broker communication and specifies the key for stored data. It does not replace authentication and permission review.

References