AWS msk: Removed permission troubleshooting content
Summary
Deleted IAM permission error resolution guidance and replaced with general MSK Data Delivery overview.
Security assessment
Removal of IAM troubleshooting content reduces security documentation but doesn't indicate vulnerability remediation. Severity low due to loss of security-adjacent guidance.
Evidence
- * **Resolution:** Compare the current policy against the required policy; check recent bucket-policy changes via CloudTrail; verify the trust policy still includes `kafka.amazonaws.com`; if using KMS, verify the key policy grants the role access.
Diff
diff --git a/msk/latest/developerguide/msk-data-delivery-ts-permission-denied.md b/msk/latest/developerguide/msk-data-delivery-ts-permission-denied.md index 559b4f482..61b71a0b5 100644 --- a//msk/latest/developerguide/msk-data-delivery-ts-permission-denied.md +++ b//msk/latest/developerguide/msk-data-delivery-ts-permission-denied.md @@ -1 +1 @@ -[View a markdown version of this page](msk-data-delivery-ts-permission-denied.md) +[View a markdown version of this page](msk-data-delivery.md) @@ -3 +3 @@ -[](/pdfs/msk/latest/developerguide/MSKDevGuide.pdf#msk-data-delivery-ts-permission-denied "Open PDF") +[](/pdfs/msk/latest/developerguide/MSKDevGuide.pdf#msk-data-delivery "Open PDF") @@ -7 +7 @@ -# Permission denied errors in Amazon CloudWatch Logs +# Amazon MSK Data Delivery @@ -9 +9 @@ - * **Symptom:** Logs show `AccessDenied` or 403 errors. +With Amazon MSK data delivery, you can deliver Apache Kafka data from Amazon MSK Express brokers directly to Amazon S3, without connectors or additional infrastructure to manage. Amazon MSK Express automatically handles scaling, retries, and backpressure, and manages routine operations such as capacity scaling and version upgrades without introducing delivery gaps. Because these are native broker capabilities, they add no broker egress throughput, so you avoid the incremental infrastructure costs that scaling connector-based pipelines typically incurs and match capacity to actual workload demand rather than provisioning for peak. Each capability supports throughput of up to 10 GBps. @@ -11 +11 @@ - * **Causes:** Service-role IAM policy modified; destination bucket policy or KMS key policy denying access; trust policy no longer allows the Kafka service to assume the role. +The two capabilities are: @@ -13 +13,12 @@ - * **Resolution:** Compare the current policy against the required policy; check recent bucket-policy changes via CloudTrail; verify the trust policy still includes `kafka.amazonaws.com`; if using KMS, verify the key policy grants the role access. + * **Data delivery to streaming tables for Apache Iceberg** — With Amazon MSK Data Delivery, you can continuously materialize Apache Kafka topics as Apache Iceberg tables on Amazon S3 Tables. Intelligent inline compaction eliminates the performance impact of small files and keeps query performance predictable without sacrificing data freshness. Built-in coordination resolves concurrent writer conflicts across high-throughput consumers. Amazon S3 Tables automatically handles ongoing table maintenance, including compaction, snapshot expiration, and unreferenced file cleanup. + + * **Data delivery to Amazon S3 general purpose buckets** — With Amazon MSK Data Delivery, you can deliver Apache Kafka data in the source format to Amazon S3 general purpose buckets for downstream processing, with end-to-end reliability for mission-critical workloads. Use it to land Kafka data in Amazon S3 for use cases such as log archival, compliance retention, Kafka replay, and training AI/ML models. This approach removes the need to build self-managed connector pipelines that grow costly and operationally complex as workloads scale. + + + + +###### Topics + + * [data delivery for streaming tables to Apache Iceberg](./msk-data-delivery-iceberg.html) + + * [data delivery to Amazon S3 general purpose buckets](./msk-data-delivery-s3.html) @@ -24 +35 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please -Delivery stops after a schema change (Iceberg) +Troubleshooting @@ -26 +37 @@ Delivery stops after a schema change (Iceberg) -Channel not available on cluster +data delivery for streaming tables to Apache Iceberg