Which gate closed?
A nightly export runs as ReportsExportRole, and debugging it has landed on you. The role has kms:Decrypt in its IAM policy, and the export still fails.
Open the Two-gate simulator. It holds one decrypt call against alias/reports and lets you set each gate independently. Set gate 1 to Allows kms:Decrypt and gate 2 to Does not name this caller, which is the state the export is in.
Now do what a developer under pressure does: press Rotate now three times and watch the result.
After pressing Rotate now three times, what changed for the failing call?
Questo esercizio fa parte del corso
Using AWS Security for Developers
esercizio interattivo pratico
Trasforma la teoria in pratica con uno dei nostri esercizi interattivi
Inizia esercizio