SNS topic policy uses a wildcard principal

Restrict SNS topic principals and publishing, subscription, and administration permissions to the required scope, and review service-integration conditions.

Description

Granting permissions to wildcard principals in an SNS topic policy can allow unintended access. Effective permissions depend on Action, Resource, conditions, and other applicable policies. Review publishing, subscription, and administration permissions separately.

Potential impact

  • If principals that do not need publishing permission receive sns:Publish, unwanted messages can enter the topic. Downstream systems that trust them may send incorrect alerts or perform unintended automation.
  • Excessive subscription or administration permissions can affect information delivery and topic operation.

Remediation

  • Identify required publishers and operators, then grant each only the actions and topic ARNs they need. An account's :root ARN delegates authority to that account; it does not identify only its root user.
  • Use supported condition keys and accurate values for service integrations. aws:SourceAccount identifies the account owning the original resource that triggered a service-to-service request, not every ordinary publisher's account. aws:ResourceAccount identifies the resource owner and is different from restricting the caller.
  • If using a module, check policy selection and merging for that version. Test that the final policy permits required requests and denies unapproved ones.

Examples

These examples replace broad access with publishing permission for an approved role. Define topic_name and publisher_role_arn, the ARN of the actual publishing role. For an existing topic, review Terraform state and the plan, and avoid managing the same policy through both an inline setting and a separate policy resource.

Before

hcl
resource "aws_sns_topic" "public_topic" {
  name = var.topic_name
  policy = <<EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "",
      "Effect": "Allow",
      "Action": "*",
      "Principal": {
        "AWS": "*"
      },
      "Resource": "*"
    }
  ]
}
EOF
}

The policy allows wildcard principals a broad scope of actions and resources. Its effective permissions depend on the operations supported by SNS and other applicable policies.

After

hcl
resource "aws_sns_topic" "public_topic" {
  name = var.topic_name
}

resource "aws_sns_topic_policy" "restricted_policy" {
  arn = aws_sns_topic.public_topic.arn

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [{
      Sid       = "AllowApprovedPublisher"
      Effect    = "Allow"
      Principal = { AWS = var.publisher_role_arn }
      Action    = "sns:Publish"
      Resource  = aws_sns_topic.public_topic.arn
    }]
  })
}

The approved role is allowed to publish messages to this topic. Configure required subscription or administration permissions separately and verify them with actual requests.

References