Which gate closed?
A nightly export runs as ReportsExportRole, and debugging it has landed on you. The role has kms:Decrypt in its IAM policy, and the export still fails.
Open the Two-gate simulator. It holds one decrypt call against alias/reports and lets you set each gate independently. Set gate 1 to Allows kms:Decrypt and gate 2 to Does not name this caller, which is the state the export is in.
Now do what a developer under pressure does: press Rotate now three times and watch the result.
After pressing Rotate now three times, what changed for the failing call?
Cet exercice fait partie du cours
<cours>Using AWS Security for Developers</cours>Exercice interactif pratique
Transformez la théorie en action avec l’un de nos exercices interactifs
Commencer l’exercice