Which gate closed?
A nightly export runs as ReportsExportRole, and debugging it has landed on you. The role has kms:Decrypt in its IAM policy, and the export still fails.
Open the Two-gate simulator. It holds one decrypt call against alias/reports and lets you set each gate independently. Set gate 1 to Allows kms:Decrypt and gate 2 to Does not name this caller, which is the state the export is in.
Now do what a developer under pressure does: press Rotate now three times and watch the result.
After pressing Rotate now three times, what changed for the failing call?
Deze oefening maakt deel uit van de cursus
Using AWS Security for Developers
Interactieve oefening met praktijkervaring
Zet theorie om in actie met een van onze interactieve oefeningen
Begin oefening