Skip to content

Conversation

@schoemme
Copy link

@schoemme schoemme commented Aug 29, 2024

Add kms:Encrypt, kms:GenerateDataKey*, and kms:ReEncrypt* actions to allow use of key

Why?

These permissions are needed for cross-account roles to access the artifact bucket.

Issue #, if available: #756

What?

Description of changes:

Added:

  • kms:Encrypt
  • kms:GenerateDataKey*
  • kms:ReEncrypt*
    ...actions to DeploymentFrameworkRegionalKMSKey's "Allow use of the key" statement

By submitting this pull request, I confirm that you can use, modify, copy, and
redistribute this contribution, under the terms of your choice.

Add kms:Encrypt, kms:GenerateDataKey*, and kms:ReEncrypt* actions to allow use of key
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant