AWS Security ChangesHomeSearch

AWS msk: MSK: add best practice to remove dynamic advertised.listeners override

Service: msk · 2026-09-27 · Documentation low

File: msk/latest/developerguide/custom-domain-setup.md

Summary

Adds a 'Best practices' section (and nav entry) recommending that after setting up custom domain names, operators remove any dynamic advertised.listeners override with kafka-configs.sh --alter --delete-config advertised.listeners on each broker, noting it affects only that override.

Security assessment

This is configuration hygiene guidance to keep advertised listener settings consistent with the custom domain setup. It does not address a vulnerability, credential handling, encryption, or access control, so it is a low-severity, non-security-adjacent change.

Evidence

+After you set up custom domain names using the preceding steps, we recommend that you remove any dynamic `advertised.listeners` override by running `kafka-configs.sh --alter --delete-config advertised.listeners` on each broker. This removes only the advertised listeners override and doesn't affect other dynamic configurations.

Diff

diff --git a/msk/latest/developerguide/custom-domain-setup.md b/msk/latest/developerguide/custom-domain-setup.md
index 5334fa327..d39b7f6fb 100644
--- a//msk/latest/developerguide/custom-domain-setup.md
+++ b//msk/latest/developerguide/custom-domain-setup.md
@@ -7 +7 @@
-Step 1: Add the custom domain to your Amazon MSK configurationStep 2: Apply the configurationStep 3: Track the rolloutStep 4: VerifyScaling and broker replacementRemove a custom domain
+Step 1: Add the custom domain to your Amazon MSK configurationStep 2: Apply the configurationStep 3: Track the rolloutStep 4: VerifyBest practicesScaling and broker replacementRemove a custom domain
@@ -70,0 +71,4 @@ If you can list topics through the custom domain endpoint, clients are successfu
+## Best practices
+
+After you set up custom domain names using the preceding steps, we recommend that you remove any dynamic `advertised.listeners` override by running `kafka-configs.sh --alter --delete-config advertised.listeners` on each broker. This removes only the advertised listeners override and doesn't affect other dynamic configurations.
+