Which gate closed?
A nightly export runs as ReportsExportRole, and debugging it has landed on you. The role has kms:Decrypt in its IAM policy, and the export still fails.
Open the Two-gate simulator. It holds one decrypt call against alias/reports and lets you set each gate independently. Set gate 1 to Allows kms:Decrypt and gate 2 to Does not name this caller, which is the state the export is in.
Now do what a developer under pressure does: press Rotate now three times and watch the result.
After pressing Rotate now three times, what changed for the failing call?
Acest exercițiu face parte din cursul
Using AWS Security for Developers
Exercițiu interactiv practic
Transformă teoria în practică cu unul dintre exercițiile noastre interactive
Începe exercițiul