AWS msk: MSK IAM: CreateCluster requires config resource or wildcard
Summary
Adds an Important note explaining that kafka:CreateCluster/kafka:CreateClusterV2 with a custom configuration are evaluated against both the cluster ARN and the configuration ARN, causing AccessDeniedException, and recommends granting the actions on Resource "*" or on the configuration resource in addition to the cluster ARN.
Security assessment
The added guidance documents IAM authorization evaluation semantics for Amazon MSK cluster creation, including a wildcard-resource policy example and the alternative of scoping to configuration and cluster ARNs. It clarifies access-control behavior rather than fixing a disclosed vulnerability, though the wildcard example has least-privilege implications worth noting.
Evidence
+ "Resource": "*"
Diff
diff --git a/msk/latest/developerguide/security_iam_service-with-iam-id-based-policies.md b/msk/latest/developerguide/security_iam_service-with-iam-id-based-policies.md index cdf844b4f..9b5f33628 100644 --- a//msk/latest/developerguide/security_iam_service-with-iam-id-based-policies.md +++ b//msk/latest/developerguide/security_iam_service-with-iam-id-based-policies.md @@ -65,0 +66,19 @@ Some Amazon MSK actions, such as those for creating resources, cannot be perform +###### Important + +When you create a cluster with a custom configuration (the `ConfigurationInfo` parameter), Amazon MSK evaluates `kafka:CreateCluster` and `kafka:CreateClusterV2` against both the cluster resource and the configuration resource. A policy that grants these actions on a cluster ARN alone returns an `AccessDeniedException` that names the configuration ARN. + +To avoid this, grant the cluster creation actions in a separate statement that uses the wildcard (*): + + + { + "Sid": "AllowClusterCreation", + "Effect": "Allow", + "Action": [ + "kafka:CreateCluster", + "kafka:CreateClusterV2" + ], + "Resource": "*" + } + +Alternatively, grant `kafka:CreateCluster` and `kafka:CreateClusterV2` on the configuration resource in addition to the cluster resource. Other Amazon MSK actions, such as `kafka:DescribeCluster` and `kafka:DeleteCluster`, can still be scoped to specific cluster ARNs. +