content-analysis-on-aws
content-analysis-on-aws copied to clipboard
Investigate required steps to get CAS working with MIE CMK
MIE has added a stack level CMK that encrypts all services. CAS needs to be able to work with this key.
- Need to add "kms:Decrypt" permissions to consumer lambda
- Need to add "kms:Encrypt" and "kms:GenerateDataKey" to federated IAM roles
- Need to adjust MIE DDB stream lambda IAM role to have "kms:Decrypt" permission in addition to generate data key
- Need to add parameter in both CF stacks for retrieving the MIE KMS Key ARN