VectleSkillsAWS secret manager access deny issue (AWS Secrets Manager)

AWS secret manager access deny issue (AWS Secrets Manager)

Export

AWS secret manager access deny issue (AWS Secrets Manager): From the accepted Stack Overflow answer: The most difficult concept with cross-account permissions is that it requires granting permission from both directions .

From the accepted Stack Overflow answer: The most difficult concept with cross-account permissions is that it requires granting permission from both directions . In your situation, you have: Secrets Manager in Account-A EC2 instance in Account-B An IAM Role ( Role-B ) in Account-B This requires permissions from A to B: The Secret in Account-A needs a "Secret Key Resource Policy" that permits access from Role-B (You have already done this) And it also requires permissions from B to A: Role-B must be given permission to access the Secret in Account-A This might seem strange, but I like to think of it like this: By default, an IAM User / IAM Role has no permission To use the Secrets Manager (even in the same account), the IAM Role must be given permission such as secretsmanager:GetSecretValue -- otherwise it isn't permitted to do anything By default, an AWS Account cannot be accessed from another AWS Account (eg I cannot access your account) If an AWS Account is willing to have another account access it, then it must grant access. This can be done at the resource-level in services such as S3, SNS, SQS, KMS and Secrets Manager because they have the ability to create policies on resources. Services without this capability cannot grant cross-account access and must be used by assuming a role in the same account. The configuration in your question appears to be missing the permissions that need to be granted to Role-B to acc

Context: Problem: Accepted solution (score 16): The most difficult concept with cross-account permissions is that it requires granting permission from both directions . In your situation, you have: Secrets Manager in Account-A EC2 instance in Account-B An IAM Role ( Role-B ) in Account-B This requires permissions from A to B: The Secret in Account-A needs a "Secret Key Resource Policy" that permits access from Role-B (You have already done this) And it also requires permissions from B to A: Role-B must be given permission to access the Secret in Account-A This might seem strange, but I like to think of it like this: By default, an IAM User / IAM Role has no permission To use the Secrets Manager (even in the same account), the IAM Role must be given permission such as secretsmanager:GetSecretValue -- otherwise it isn't permitted to do anything By default, an AWS Account cannot be accessed from another AWS Account (eg I cannot access your account) If an AWS Account is willing to have another account access it, then it must grant access. This can be done at the resource-level in services such as S3, SNS, SQS, KMS and Secrets Manager because they have the ability to create policies on resources. Services without this capability cannot grant cross-account access and must be used by assuming a role in the same account. The configuration in your question appears to be missing the permissions that need to be granted to Role-B to access the Secrets Manager, such as: { "Version" : "2012-10-17", "Statement" : [ { "Effect": "Allow", "Action": "secretsmanager:GetSecretValue", "Resource": "arn:aws:secretsmanager:us-east-2:ACCOUNTA:secret - USRFTP" } ] }

Matched source

Source: Stack Overflow question: https://stackoverflow.com/questions/63728452/aws-secret-manager-access-deny-issue Original query: "AWS secret manager access deny issue (AWS Secrets Manager)" Key terms: access, deny, issue, manager, secret, secrets

Published recentlyPublished Oct 1, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Mar 30, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=AWS+secret+manager+access+deny+issue+%28AWS+Secrets+Manager%29&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.