Description
Amazon MSK is a managed service for running Apache Kafka-based streaming applications. Terraform represents a cluster with an aws_msk_cluster resource. A bill of materials (BOM) provides an inventory of these assets for ongoing management.
An inventory entry alone does not establish that a cluster is vulnerable or missing tags. Assess its security by reviewing the actual configuration and operating environment.
Uses of the inventory
- Associate clusters with their responsible teams, services, and environments.
- Identify the clusters that need separate reviews of network access, encryption, authentication, logging, and monitoring.
- Compare the Terraform configuration with the deployed asset inventory to identify differences in your management records.
Follow-up checks
- Add each cluster to the asset inventory and record its purpose and owner.
- Check actual deployment settings and service defaults when reviewing network access and encryption.
- Use tags to describe purpose and environment. Review network exposure, encryption, authentication, and logging through separate security checks.
Inventory examples
The examples show how tags add information for managing an asset. Tags help identify its purpose and environment, but do not themselves configure encryption or access controls. Versions and resource IDs are illustrative values.
Cluster without tags
resource "aws_msk_cluster" "streaming" {
cluster_name = "streaming"
kafka_version = "3.6.0"
number_of_broker_nodes = 3
broker_node_group_info {
instance_type = "kafka.m5.large"
client_subnets = ["subnet-a", "subnet-b", "subnet-c"]
security_groups = ["sg-12345678"]
}
}
Cluster with tags
resource "aws_msk_cluster" "streaming" {
cluster_name = "streaming"
kafka_version = "3.6.0"
number_of_broker_nodes = 3
broker_node_group_info {
instance_type = "kafka.m5.large"
client_subnets = ["subnet-a", "subnet-b", "subnet-c"]
security_groups = ["sg-12345678"]
}
tags = {
Service = "streaming"
Environment = "production"
}
}
Explanation:
- Cluster without tags: The resource defines the basic cluster configuration without tags identifying its service and environment.
- Cluster with tags:
ServiceandEnvironmentadd operational context. These tags do not configure encryption or access controls.