I have an architecture developed with CDK with a S3 bucket and an event notification which will send a message to a SQS for each uploaded file to S3.
It works fine.
Now I'm trying to activate the encryption and I have the following:
- for S3 -> I have activated the encryption using S3_MANAGED key and everything works fine
- for SQS -> I have activated the encryption using KMS_MANAGED key and there is no message sent to SQS.
So I'm assuming some permissions are missing but I don't know how to fix it.
Do I need to add missing permissions to SQS to read from S3? Or permissions to S3 to send messages to a encrypted SQS?