serverless-application-model
serverless-application-model copied to clipboard
KMSEncryptPolicy cannot be used to encrypt
Related to #1186, is the KMSEncryptPolicy policy template actually usable as written? It can't be used to publish KMS-encrypted data to an SNS topic, for example, because KMSEncryptPolicy doesn't include kms:GenerateDataKey.
I second this. I'm facing the exact same issue.
what's the workaround for this? can someone help?
@wchengru Hi, what kind of example are you looking for?
I'm looking for a more usable out-of-the-box SAM policy template, for example:
kms:Encrypt
kms:ReEncrypt*
kms:GenerateDataKey*
kms:DescribeKey