The environment has the following configuration:✑ The instance is allowed the kms:Decrypt action in its IAM role for all resources✑ The AWS KMS CMK status is set to enabled✑ The instance can communicate with the KMS API using a configured VPC endpointWhat is causing the issue?

2 Comments

  1. Walter
    Author

    I sort that the answer is:
    The KMS CMK key policy that enables IAM user permissions is missing

  2. Austin
    Author

    In my experience, the answer is:
    The KMS CMK key policy that enables IAM user permissions is missing

Leave a Reply

Your email address will not be published. Required fields are marked *

two × 1 =