See below for the AWS requirements for Vault BYOK.
AWS account requirements
To use AWS with BYOK, you must create a new, unique service account user in your AWS account.
Do not use an existing user account or existing access key. Create the service account with the required permissions.
Create an access key by logging in to AWS using the service account.
Do not use the access key more than one time.
Do not delete any access keys from the service account.
Do not attach the same AWS account to multiple Cryptographic Security Platform Vault clusters.
Do not share the AWS BYOK service account.
- Use the following permissions to create the AWS service account:
KMS:FullAccess
IAM:GetUser
IAM:ListUsers
IAM:ListAccessKeys
IAM:CreateAccessKey
IAM:DeleteAccessKey
IAM:UpdateAccessKey
EC2:DescribeRegions
SSM:GetParameter
tag:GetResources
Your JSON file should look like the following:
{ "Version": "2022-10-17", "Statement": [ { "Sid": "ServiceAccountPolicy", "Effect": "Allow", "Action": [ "kms:*", "ec2:DescribeRegions", "ssm:GetParameter", "iam:ListUsers", "iam:GetUser", "iam:CreateAccessKey", "iam:UpdateAccessKey", "iam:ListAccessKeys", "iam:DeleteAccessKey" ], "Resource": "*" } ]}AWS endpoint access requirements
If your organization restricts outbound access to the public internet, whitelist the following endpoints for AWS BYOK to work correctly.
https://iam.amazonaws.comWhitelist the following endpoints individually for each region you want to use.
https://kms.<region>.amazonaws.comhttps://ssm.<region>.amazonaws.comhttps://ec2.<region>.amazonaws.comIf a proxy is in use in the network, you can test these endpoints in the Vault application on the Settings > Proxy Settings Vault page.