AWS msk: Replaced IAM security guidance with MSK Data Delivery overview
Summary
Removed IAM security best practices (least privilege, confused deputy prevention) and replaced with feature description.
Security assessment
The deletion of IAM security guidance (including prevention of confused deputy attacks) removes security documentation without adding new protections or addressing vulnerabilities.
Evidence
-# IAM and access control
Diff
diff --git a/msk/latest/developerguide/msk-data-delivery-security-iam.md b/msk/latest/developerguide/msk-data-delivery-security-iam.md index 74b54a52e..61b71a0b5 100644 --- a//msk/latest/developerguide/msk-data-delivery-security-iam.md +++ b//msk/latest/developerguide/msk-data-delivery-security-iam.md @@ -1 +1 @@ -[View a markdown version of this page](msk-data-delivery-security-iam.md) +[View a markdown version of this page](msk-data-delivery.md) @@ -3 +3 @@ -[](/pdfs/msk/latest/developerguide/MSKDevGuide.pdf#msk-data-delivery-security-iam "Open PDF") +[](/pdfs/msk/latest/developerguide/MSKDevGuide.pdf#msk-data-delivery "Open PDF") @@ -7 +7 @@ -# IAM and access control +# Amazon MSK Data Delivery @@ -9 +9 @@ -A Channel uses IAM roles for authorization. Follow least privilege: +With Amazon MSK data delivery, you can deliver Apache Kafka data from Amazon MSK Express brokers directly to Amazon S3, without connectors or additional infrastructure to manage. Amazon MSK Express automatically handles scaling, retries, and backpressure, and manages routine operations such as capacity scaling and version upgrades without introducing delivery gaps. Because these are native broker capabilities, they add no broker egress throughput, so you avoid the incremental infrastructure costs that scaling connector-based pipelines typically incurs and match capacity to actual workload demand rather than provisioning for peak. Each capability supports throughput of up to 10 GBps. @@ -11 +11 @@ A Channel uses IAM roles for authorization. Follow least privilege: - * Scope S3 Tables / S3 permissions to the specific bucket used by the Channel. +The two capabilities are: @@ -13 +13 @@ A Channel uses IAM roles for authorization. Follow least privilege: - * Scope Glue Schema Registry permissions (Iceberg) to the specific registry used by the Channel. + * **Data delivery to streaming tables for Apache Iceberg** — With Amazon MSK Data Delivery, you can continuously materialize Apache Kafka topics as Apache Iceberg tables on Amazon S3 Tables. Intelligent inline compaction eliminates the performance impact of small files and keeps query performance predictable without sacrificing data freshness. Built-in coordination resolves concurrent writer conflicts across high-throughput consumers. Amazon S3 Tables automatically handles ongoing table maintenance, including compaction, snapshot expiration, and unreferenced file cleanup. @@ -15 +15,10 @@ A Channel uses IAM roles for authorization. Follow least privilege: - * Use `aws:SourceArn` and `aws:SourceAccount` in the trust policy to prevent confused deputy attacks. + * **Data delivery to Amazon S3 general purpose buckets** — With Amazon MSK Data Delivery, you can deliver Apache Kafka data in the source format to Amazon S3 general purpose buckets for downstream processing, with end-to-end reliability for mission-critical workloads. Use it to land Kafka data in Amazon S3 for use cases such as log archival, compliance retention, Kafka replay, and training AI/ML models. This approach removes the need to build self-managed connector pipelines that grow costly and operationally complex as workloads scale. + + + + +###### Topics + + * [data delivery for streaming tables to Apache Iceberg](./msk-data-delivery-iceberg.html) + + * [data delivery to Amazon S3 general purpose buckets](./msk-data-delivery-s3.html) @@ -26 +35 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please -Encryption at rest +Troubleshooting @@ -28 +37 @@ Encryption at rest -Monitoring +data delivery for streaming tables to Apache Iceberg