Which gate closed?
A nightly export runs as ReportsExportRole, and debugging it has landed on you. The role has kms:Decrypt in its IAM policy, and the export still fails.
Open the Two-gate simulator. It holds one decrypt call against alias/reports and lets you set each gate independently. Set gate 1 to Allows kms:Decrypt and gate 2 to Does not name this caller, which is the state the export is in.
Now do what a developer under pressure does: press Rotate now three times and watch the result.
After pressing Rotate now three times, what changed for the failing call?
แบบฝึกหัดนี้เป็นส่วนหนึ่งของหลักสูตร
Using AWS Security for Developers
แบบฝึกหัดเชิงโต้ตอบแบบลงมือทำจริง
เปลี่ยนทฤษฎีให้เป็นการลงมือทำด้วยแบบฝึกหัดเชิงโต้ตอบหนึ่งในของเรา
เริ่มแบบฝึกหัด