Build Amazon MQ broker configurations for ActiveMQ/RabbitMQ with multi-AZ, encryption, users, and logging.
Build Amazon MQ broker configurations for ActiveMQ/RabbitMQ with multi-AZ, encryption, users, and logging.
Required Fields
BrokerNameEngineTypeHostInstanceTypeDeploymentModeUsersOutput will appear here...Build an Amazon MQ broker (ActiveMQ or RabbitMQ engine) with ACTIVE_STANDBY_MULTI_AZ deployment mode for automatic failover, VPC-scoped networking via SecurityGroups and SubnetIds, and broker-level Users, a fundamentally different security model from IAM-based AWS-native messaging services, since MQ broker authentication uses application-level usernames/passwords (or LDAP), not IAM policies, meaning access control here lives in the broker's own user/group model, not in an IAM policy document.
The builder validates that BrokerName, EngineType, HostInstanceType, DeploymentMode, and Users all resolve before accepting the JSON as a valid CreateBroker request, the fields Amazon MQ needs to provision the broker, its engine, sizing, deployment topology, and initial user accounts; it can't verify the referenced subnet/security group IDs exist or that broker-level user passwords meet the engine's complexity requirements, those checks happen only against the live API.
Don't assume IAM policies control message-level access the way they do for SQS/SNS, Amazon MQ's actual pub/sub authorization lives in the broker's own Users/Groups model, verify broker-level permissions are correctly scoped, not just the IAM policy governing the broker resource itself.
Separate admin (console-access) credentials from application (publish/consume-only) credentials from the start, using one shared admin credential for both broker management and application message publishing means a leaked application credential also grants broker admin access.
ACTIVE_STANDBY_MULTI_AZ is worth the modest additional cost for any production messaging workload where broker downtime translates into lost or delayed messages, SINGLE_INSTANCE's cost savings usually aren't worth the availability tradeoff outside of dev/test.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.