See below for the AWS requirements for Vault BYOK.

AWS account requirements 

To use AWS with BYOK, you must create a new, unique service account user in your AWS account.

  • Do not use an existing user account or existing access key. Create the service account with the required permissions.

  • Create an access key by logging in to AWS using the service account.

  • Do not use the access key more than one time.

  • Do not delete any access keys from the service account.

  • Do not attach the same AWS account to multiple Cryptographic Security Platform Vault clusters.

  • Do not share the AWS BYOK service account.

  • Use the following permissions to create the AWS service account:
    • KMS:FullAccess

    • IAM:GetUser

    • IAM:ListUsers

    • IAM:ListAccessKeys

    • IAM:CreateAccessKey

    • IAM:DeleteAccessKey

    • IAM:UpdateAccessKey

    • EC2:DescribeRegions

    • SSM:GetParameter

    • tag:GetResources

Your JSON file should look like the following:

{
"Version": "2022-10-17",
"Statement": [
{
"Sid": "ServiceAccountPolicy",
"Effect": "Allow",
"Action": [
"kms:*",
"ec2:DescribeRegions",
"ssm:GetParameter",
"iam:ListUsers",
"iam:GetUser",
"iam:CreateAccessKey",
"iam:UpdateAccessKey",
"iam:ListAccessKeys",
"iam:DeleteAccessKey"
],
"Resource": "*"
}
]
}

AWS endpoint access requirements

If your organization restricts outbound access to the public internet, whitelist the following endpoints for AWS BYOK to work correctly.

https://iam.amazonaws.com

Whitelist the following endpoints individually for each region you want to use.

https://kms.<region>.amazonaws.com
https://ssm.<region>.amazonaws.com
https://ec2.<region>.amazonaws.com

If a proxy is in use in the network, you can test these endpoints in the Vault application on the Settings > Proxy Settings Vault page.