AWS secret manager access deny issue (AWS Secrets Manager)
AWS secret manager access deny issue (AWS Secrets Manager): From the accepted Stack Overflow answer: The most difficult concept with cross-account permissions is that it requires granting permission from both directions .
From the accepted Stack Overflow answer: The most difficult concept with cross-account permissions is that it requires granting permission from both directions . In your situation, you have: Secrets Manager in Account-A EC2 instance in Account-B An IAM Role ( Role-B ) in Account-B This requires permissions from A to B: The Secret in Account-A needs a "Secret Key Resource Policy" that permits access from Role-B (You have already done this) And it also requires permissions from B to A: Role-B must be given permission to access the Secret in Account-A This might seem strange, but I like to think of it like this: By default, an IAM User / IAM Role has no permission To use the Secrets Manager (even in the same account), the IAM Role must be given permission such as secretsmanager:GetSecretValue -- otherwise it isn't permitted to do anything By default, an AWS Account cannot be accessed from another AWS Account (eg I cannot access your account) If an AWS Account is willing to have another account access it, then it must grant access. This can be done at the resource-level in services such as S3, SNS, SQS, KMS and Secrets Manager because they have the ability to create policies on resources. Services without this capability cannot grant cross-account access and must be used by assuming a role in the same account. The configuration in your question appears to be missing the permissions that need to be granted to Role-B to acc
Context: Problem: Accepted solution (score 16): The most difficult concept with cross-account permissions is that it requires granting permission from both directions . In your situation, you have: Secrets Manager in Account-A EC2 instance in Account-B An IAM Role ( Role-B ) in Account-B This requires permissions from A to B: The Secret in Account-A needs a "Secret Key Resource Policy" that permits access from Role-B (You have already done this) And it also requires permissions from B to A: Role-B must be given permission to access the Secret in Account-A This might seem strange, but I like to think of it like this: By default, an IAM User / IAM Role has no permission To use the Secrets Manager (even in the same account), the IAM Role must be given permission such as secretsmanager:GetSecretValue -- otherwise it isn't permitted to do anything By default, an AWS Account cannot be accessed from another AWS Account (eg I cannot access your account) If an AWS Account is willing to have another account access it, then it must grant access. This can be done at the resource-level in services such as S3, SNS, SQS, KMS and Secrets Manager because they have the ability to create policies on resources. Services without this capability cannot grant cross-account access and must be used by assuming a role in the same account. The configuration in your question appears to be missing the permissions that need to be granted to Role-B to access the Secrets Manager, such as: { "Version" : "2012-10-17", "Statement" : [ { "Effect": "Allow", "Action": "secretsmanager:GetSecretValue", "Resource": "arn:aws:secretsmanager:us-east-2:ACCOUNTA:secret - USRFTP" } ] }
Matched source
Source: Stack Overflow question: https://stackoverflow.com/questions/63728452/aws-secret-manager-access-deny-issue Original query: "AWS secret manager access deny issue (AWS Secrets Manager)" Key terms: access, deny, issue, manager, secret, secrets