AWS msk: Replaced security best practices with MSK Data Delivery overview
Summary
Removed IAM permission scoping, trust policy conditions, and CloudTrail auditing guidance. Added service description and links to Iceberg/S3 delivery topics.
Security assessment
Removed critical IAM security guidance about permission scoping and trust policies, which directly impacts authorization controls. Loss of this documentation increases misconfiguration risks.
Evidence
- * Scope IAM permissions to the specific destination bucket (and schema registry for Iceberg) used by each Channel.
Diff
diff --git a/msk/latest/developerguide/msk-data-delivery-bp-security.md b/msk/latest/developerguide/msk-data-delivery-bp-security.md index 5251e77ad..61b71a0b5 100644 --- a//msk/latest/developerguide/msk-data-delivery-bp-security.md +++ b//msk/latest/developerguide/msk-data-delivery-bp-security.md @@ -1 +1 @@ -[View a markdown version of this page](msk-data-delivery-bp-security.md) +[View a markdown version of this page](msk-data-delivery.md) @@ -3 +3 @@ -[](/pdfs/msk/latest/developerguide/MSKDevGuide.pdf#msk-data-delivery-bp-security "Open PDF") +[](/pdfs/msk/latest/developerguide/MSKDevGuide.pdf#msk-data-delivery "Open PDF") @@ -7 +7 @@ -# Security +# Amazon MSK Data Delivery @@ -9 +9 @@ - * Scope IAM permissions to the specific destination bucket (and schema registry for Iceberg) used by each Channel. +With Amazon MSK data delivery, you can deliver Apache Kafka data from Amazon MSK Express brokers directly to Amazon S3, without connectors or additional infrastructure to manage. Amazon MSK Express automatically handles scaling, retries, and backpressure, and manages routine operations such as capacity scaling and version upgrades without introducing delivery gaps. Because these are native broker capabilities, they add no broker egress throughput, so you avoid the incremental infrastructure costs that scaling connector-based pipelines typically incurs and match capacity to actual workload demand rather than provisioning for peak. Each capability supports throughput of up to 10 GBps. @@ -11 +11 @@ - * Use the `aws:SourceArn` condition in the trust policy to prevent other clusters or services from assuming the Channel role. +The two capabilities are: @@ -13 +13,12 @@ - * Enable CloudTrail logging to audit all Channel API calls. + * **Data delivery to streaming tables for Apache Iceberg** — With Amazon MSK Data Delivery, you can continuously materialize Apache Kafka topics as Apache Iceberg tables on Amazon S3 Tables. Intelligent inline compaction eliminates the performance impact of small files and keeps query performance predictable without sacrificing data freshness. Built-in coordination resolves concurrent writer conflicts across high-throughput consumers. Amazon S3 Tables automatically handles ongoing table maintenance, including compaction, snapshot expiration, and unreferenced file cleanup. + + * **Data delivery to Amazon S3 general purpose buckets** — With Amazon MSK Data Delivery, you can deliver Apache Kafka data in the source format to Amazon S3 general purpose buckets for downstream processing, with end-to-end reliability for mission-critical workloads. Use it to land Kafka data in Amazon S3 for use cases such as log archival, compliance retention, Kafka replay, and training AI/ML models. This approach removes the need to build self-managed connector pipelines that grow costly and operationally complex as workloads scale. + + + + +###### Topics + + * [data delivery for streaming tables to Apache Iceberg](./msk-data-delivery-iceberg.html) + + * [data delivery to Amazon S3 general purpose buckets](./msk-data-delivery-s3.html) @@ -24,2 +34,0 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please -S3 object layout (S3 bucket) - @@ -27,0 +37,2 @@ Troubleshooting +data delivery for streaming tables to Apache Iceberg +