Description
Granting broad queue actions to unnecessary principals can give more message-sending, receiving or deletion permissions than the workload needs. Restrict the queue policy to the operations required by actual producers and consumers.
Policy conditions and other permission controls also affect actual access. Queues with server-side encryption reject anonymous SendMessage and ReceiveMessage requests, so a public principal alone does not mean every anonymous request is allowed.
Potential impact
- Unnecessary message-sending access can cause downstream services to process unwanted work.
- Misuse of message retrieval or deletion permissions can expose information or cause missed processing.
Remediation
- Replace all-action grants with the SQS operations required by producers and consumers.
- Restrict Principal to approved accounts, roles or services. For SNS, use the sns.amazonaws.com service principal and an aws:SourceArn condition for the actual topic ARN.
- Retain encryption and required key permissions, and verify intended message processing and denial of unapproved operations.
Examples
These excerpts reduce the allowed actions on the same queue policy. The after-example still allows all principals, so also restrict producers for actual deployment.
Before
resource "aws_sqs_queue" "app_queue" {
name = "examplequeue"
}
resource "aws_sqs_queue_policy" "app_queue_policy" {
queue_url = aws_sqs_queue.app_queue.id
policy = <<POLICY
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "*",
"Resource": "${aws_sqs_queue.app_queue.arn}"
}
]
}
POLICY
}
This configures all actions for all principals. Review the message operations actually permitted and the other permission controls that apply.
After
resource "aws_sqs_queue" "app_queue" {
name = "examplequeue"
}
resource "aws_sqs_queue_policy" "app_queue_policy" {
queue_url = aws_sqs_queue.app_queue.id
policy = <<POLICY
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "sqs:SendMessage",
"Resource": "${aws_sqs_queue.app_queue.arn}"
}
]
}
POLICY
}
This narrows actions to SendMessage, but Principal remains *. Further restrict it to approved producers and required conditions.