Updated on 2025-08-25 GMT+08:00

DMS for Kafka Queues Are Not Publicly Accessible

Rule Details

Table 1 Rule Details

Parameter

Description

Rule Name

dms-kafka-public-access-enabled-check

Identifier

DMS for Kafka Queues Are Not Publicly Accessible

Description

If a DMS for Kafka queue can be accessed over a public network, this queue is non-compliant.

Tag

dms

Trigger Type

Configuration change

Filter Type

dms.kafka

Rule Parameters

None

Application Scenarios

You can enable public access to a Kafka instance to use it over a public network. In this case, you do not need this preset policy, but you need to take strict security measures, such as configuring strict security group or firewall rules and enabling public network access.

If public network access is no longer needed, disable it to prevent the Kafka queues from being exposed to the public network.

Solution

Disable public network access. For details, see Configuring Kafka Public Access.

Rule Logic

  • If a DMS for Kafka queue can be accessed over a public network, this queue is non-compliant.
  • If a DMS for Kafka queue cannot be accessed over a public network, this queue is compliant.