AWS Security ChangesHomeSearch

AWS msk: MSK IAM: CreateCluster requires config resource or wildcard

Service: msk · 2026-09-27 · Documentation medium

File: msk/latest/developerguide/security_iam_service-with-iam-id-based-policies.md · Type: iam

Summary

Adds an Important note explaining that kafka:CreateCluster/kafka:CreateClusterV2 with a custom configuration are evaluated against both the cluster ARN and the configuration ARN, causing AccessDeniedException, and recommends granting the actions on Resource "*" or on the configuration resource in addition to the cluster ARN.

Security assessment

The added guidance documents IAM authorization evaluation semantics for Amazon MSK cluster creation, including a wildcard-resource policy example and the alternative of scoping to configuration and cluster ARNs. It clarifies access-control behavior rather than fixing a disclosed vulnerability, though the wildcard example has least-privilege implications worth noting.

Evidence

+        "Resource": "*"

Diff

diff --git a/msk/latest/developerguide/security_iam_service-with-iam-id-based-policies.md b/msk/latest/developerguide/security_iam_service-with-iam-id-based-policies.md
index cdf844b4f..9b5f33628 100644
--- a//msk/latest/developerguide/security_iam_service-with-iam-id-based-policies.md
+++ b//msk/latest/developerguide/security_iam_service-with-iam-id-based-policies.md
@@ -65,0 +66,19 @@ Some Amazon MSK actions, such as those for creating resources, cannot be perform
+###### Important
+
+When you create a cluster with a custom configuration (the `ConfigurationInfo` parameter), Amazon MSK evaluates `kafka:CreateCluster` and `kafka:CreateClusterV2` against both the cluster resource and the configuration resource. A policy that grants these actions on a cluster ARN alone returns an `AccessDeniedException` that names the configuration ARN.
+
+To avoid this, grant the cluster creation actions in a separate statement that uses the wildcard (*):
+    
+    
+    {
+        "Sid": "AllowClusterCreation",
+        "Effect": "Allow",
+        "Action": [
+            "kafka:CreateCluster",
+            "kafka:CreateClusterV2"
+        ],
+        "Resource": "*"
+    }
+
+Alternatively, grant `kafka:CreateCluster` and `kafka:CreateClusterV2` on the configuration resource in addition to the cluster resource. Other Amazon MSK actions, such as `kafka:DescribeCluster` and `kafka:DeleteCluster`, can still be scoped to specific cluster ARNs.
+