Description
A wildcard Principal in an SQS queue policy can grant permissions to unspecified identities. Actual access depends on Action, Resource, conditions and other permission controls; a public principal alone does not mean every request is allowed.
An IP condition restricts the connection path but does not identify the caller. Specify approved producers and consumers and retain encryption and required KMS permissions. Encrypted queues reject anonymous SendMessage and ReceiveMessage requests.
Potential impact
- Misuse of permitted message actions can inject unwanted work or expose or delete messages.
- A shared source address can also permit unwanted identities using the same path.
Remediation
- Restrict Principal to required accounts, roles or services and reduce message actions to business needs.
- For IP conditions on a public endpoint, use the actual external source addresses. For a VPC endpoint, review conditions suited to that path.
- Review the queue policy, producer and consumer permissions and key access together; test intended processing and denial of unapproved access.
Examples
Define the referenced queue separately. Replace documentation range 203.0.113.0/24 with the approved external source range, and replace the role ARN with the actual value.
Before
resource "aws_sqs_queue_policy" "example" {
queue_url = aws_sqs_queue.q.id
policy = <<EOF
{
"Version": "2012-10-17",
"Id": "Queue1_Policy_UUID",
"Statement": [{
"Sid":"Queue1_AnonymousAccess_AllActions_AllowlistIP",
"Effect": "Allow",
"Principal": "*",
"Action": "sqs:*",
"Resource": "${aws_sqs_queue.q.arn}",
"Condition" : {
"IpAddress" : {
"aws:SourceIp":"203.0.113.0/24"
}
}
}]
}
EOF
}
This allows all principals subject to an IP condition. It is not open to every internet address; review whether unwanted identities can access it through the permitted path.
After
resource "aws_sqs_queue_policy" "example" {
queue_url = aws_sqs_queue.q.id
policy = <<POLICY
{
"Version": "2012-10-17",
"Id": "Queue1_Policy_UUID",
"Statement": [{
"Sid":"Queue1_AnonymousAccess_AllActions_AllowlistIP",
"Effect": "Allow",
"Principal": {"AWS": "arn:aws:iam::111122223333:role/queue-client"},
"Action": "sqs:*",
"Resource": "${aws_sqs_queue.q.arn}",
"Condition" : {
"IpAddress" : {
"aws:SourceIp":"203.0.113.0/24"
}
}
}]
}
POLICY
}
This narrows the principal to the specified role while retaining the same IP condition. sqs:* remains broad, so allow only the message operations actually needed.