Skip to content

Commit 83d2161

Browse files
authored
Merge pull request #33 from rectalogic/kms
Need to pass KMS key ARN when checking kms:Decrypt
2 parents 1016e81 + 5ca604f commit 83d2161

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

check-ecs-exec.sh

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -543,6 +543,7 @@ else
543543
kmsEvalResult=$(${AWS_CLI_BIN} iam simulate-principal-policy \
544544
--policy-source-arn "${taskRoleArn}" \
545545
--action-names "${kmsDecrypt}" \
546+
--resource-arns "${kmsKeyId}" \
546547
--output json \
547548
| jq -r ".EvaluationResults[0].EvalDecision")
548549
showEvalResult "${kmsEvalResult}" "${kmsDecrypt}"

0 commit comments

Comments
 (0)