Why does AWS CloudWatch encrypted log groups breaks session manager?

Viewed 3047

Recently attached a key from AWS KMS to encrypt CloudWatch log groups for AWS Systems Manager Session Manager. Now I can't connect to any session.

What is this error and how to fix?

Your session has been terminated for the following reasons: ----------ERROR------- Encountered error while initiating handshake. Fetching data key failed: Unable to retrieve data key, Error when decrypting data key AccessDeniedException: The ciphertext refers to a customer master key that does not exist, does not exist in this region, or you are not allowed to access. status code: 400, request id:

The key definitely exists and worked fine when attaching to the log group. Session Manager was also working fine before trying to encrypt them. Are there extra permissions I need to add to a policy somewhere?

3 Answers

Based on the comments.

The issue was caused by incorrect permissions in the instance role used.

Changing policies in the role from AmazonSSMManagedInstanceCore to AmazonEC2RoleforSSM solved the issue.

Permissions need to be modified.

Select a role from the permission settings of the service you are using You need to add a policy.

Please add the following information to the policy.

{
     "Version": "2012-10-17",
     "Statement": [
         {
             "Effect": "Allow",
             "Action": "kms:Decrypt",
             "Resource": "*"
         }
     ]
}

=======================================================================

In my case, the above error occurred while executing the Lambda function.

I solved it by adding a policy like this:

enter image description here

Here is the solution provided by AWS, essentially adding permissions to your instance profile to create encrypted logs on Cloudwatch, of course, you also need to add permissions to Decrypt the session as mentioned in some of the answers above. Be aware that for security reasons you should scope permissions as much as possible.

Related