Risk Level: Low
Cloud Entity: Simple Queue Service (SQS)
CloudGuard Rule ID: D9.TF.AWS.OPE.12
Covered by Spectral: No
aws_sqs_queue should have redrive_policy
Perform the following to set a dead-letter queue for existing queue:
- Sign in to the Amazon SQS console at https://console.aws.amazon.com/sqs/
- Choose Create New Queue.
- On the Create New Queue page, ensure that you're in the correct region and then type the Queue Name.
- Standard is selected by default. Choose FIFO.
- Choose Configure Queue.
- Enable the redrive policy for your new queue, select any queue as the dead-letter queue, and set the number of maximum receives to 50.
aws sqs set-queue-attributes --queue-url <Queue url> --attributes <file:update_attributes.json>
Where the file should contain RedrivePolicy with deadLetterTargetArn different then the source queue.
Amazon Simple Queue Service (SQS) is a fully managed message queuing service that enables you to decouple and scale microservices, distributed systems, and serverless applications. SQS eliminates the complexity and overhead associated with managing and operating message oriented middleware, and empowers developers to focus on differentiating work. Using SQS, you can send, store, and receive messages between software components at any volume, without losing messages or requiring other services to be available. Get started with SQS in minutes using the AWS console, Command Line Interface or SDK of your choice, and three simple commands.
- Terraform AWS CIS Foundations
Updated 16 days ago