Step 8 - Create an IAM KMS Policy
Perform the following steps if the S3 bucket has KMS enabled.
- Click Services and select IAM.
- Select Policies and click Create Policy.
- Click the JSON tab.
- From an S3 bucket, obtain the KMS key for the KMS policy information.
- Click an S3 bucket.
- Click Bucket Properties.
- Scroll to the default encryption section and copy the AWS KMS key ARN.
If different keys are assigned to buckets, you will need to add them under Resource in the policy information (step 5).
- Copy and paste the policy information:
{ "Sid": "VisualEditor0", "Effect": "Allow", "Action": [ "kms:Decrypt", "kms:Encrypt", "kms:GenerateDataKey", "kms:ReEncryptTo", "kms:DescribeKey", "kms:ReEncryptFrom" ], "Resource": ["<AWS_KMS_key_ARN>" ] }
- Click Review Policy.
- Name the policy lookout-kms-policy and click Create Policy.