Harness secret handling: AWS KMS 403, hidden log values, and naming rules
Shows how to fix harness secret handling: AWS KMS 403, hidden log values, and naming rules. Use it when you hit this exact problem. Skip it when your error message or symptom looks different.
TL;DR
[Harness Developer Hub troubleshooting]: 'Service: AWSKMS; Status Code: 403' means the delegate cannot reach the default Harness AWS KMS: curl the KMS URL from the delegate host and check proxies are not blocking port 443.
Steps
- [Harness Developer Hub troubleshooting]: 'Service: AWSKMS; Status Code: 403' means the delegate cannot reach the default Harness AWS KMS: curl the KMS URL from the delegate host and check proxies are not blocking port 443. If a secret's value shares content with another variable, Harness masks it in logs with the secret's name; the values still substitute correctly, so do not chase it as a bug. Entity names are restricted to alphanumerics, underscores, and hyphens: a Git trigger on a branch with a dot in its name silently never fires. For pipeline execution failures, open the runtime validation logs; with executeOnDelegate set, the View Delegate Tasks Logs dialog shows the delegate task log.
When to use
You are seeing this: [Harness Developer Hub troubleshooting]: 'Service: AWSKMS; Status Code: 403' means the delegate cannot reach the default Harness AWS KMS: curl the KMS URL from the delegate host and check proxies are not blocking port 443. Use this skill when you run into "Harness secret handling: AWS KMS 403, hidden log values, and naming rules".
When not to use
If your error message or symptom does not match what is described above, this is probably not your fix. Search for your exact error text instead of forcing this one to fit.
Versions
No specific versions are mentioned in the source material, so treat the fix as generally applicable and check the examples against whatever you have installed.
Why this happens
The original report does not dig into a root cause. It documents the symptom and the fix that resolved it.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.