You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用boto3调用GetSecretValue时遇KMS访问拒绝问题求助

AWS Secrets Manager调用GetSecretValue时KMS访问被拒问题排查

遇到的错误

botocore.exceptions.ClientError: An error occurred (AccessDeniedException) when calling 
the GetSecretValue operation: Access to KMS is not allowed

使用的代码

import boto3
client = boto3.client("secretsmanager", region_name = "eu-west-1")
client.get_secret_value(SecretId="rds_secret")

完整报错栈

Traceback (most recent call last):
File "<input>", line 1, in <module>
client.get_secret_value(SecretId="rds_secret")
File "/home/julien/Documents/cloud-tools/lib/python3.11/site-packages/botocore/client.py", line 553, in _api_call
return self._make_api_call(operation_name, kwargs)
       ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/home/julien/Documents/cloud-tools/lib/python3.11/site-packages/botocore/client.py", line 1009, in _make_api_call
raise error_class(parsed_response, operation_name)
botocore.exceptions.ClientError: An error occurred 
(AccessDeniedException) when calling the GetSecretValue 
operation: Access to KMS is not allowed

已确认信息

  • 执行sts get-caller-identity返回正确的用户ARN、访问密钥和账号ID
  • 使用的是AWS管理员账号

当前KMS密钥策略

{
"Version": "2012-10-17",
"Id": "auto-secretsmanager-2",
"Statement": [
    {
        "Sid": "Allow access through AWS Secrets Manager for all principals in the account that are authorized to use AWS Secrets Manager",
        "Effect": "Allow",
        "Principal": {
            "AWS": "*"
        },
        "Action": [
            "kms:Encrypt",
            "kms:Decrypt",
            "kms:ReEncrypt*",
            "kms:CreateGrant",
            "kms:DescribeKey"
        ],
        "Resource": "*",
        "Condition": {
            "StringEquals": {
                "kms:CallerAccount": "<account-number>",
                "kms:ViaService": "secretsmanager.eu-west-1.amazonaws.com"
            }
        }
    },
    {
        "Sid": "Allow access through AWS Secrets Manager for all principals in the account that are authorized to use AWS Secrets Manager",
        "Effect": "Allow",
        "Principal": {
            "AWS": "*"
        },
        "Action": "kms:GenerateDataKey*",
        "Resource": "*",
        "Condition": {
            "StringEquals": {
                "kms:CallerAccount": "<account-number>"
            },
            "StringLike": {
                "kms:ViaService": 
"secretsmanager.*.amazonaws.com"
            }
        }
    },
    {
        "Sid": "Allow direct access to key metadata to the account",
        "Effect": "Allow",
        "Principal": {
            "AWS": "arn:aws:iam::<account-number>:root"
        },
        "Action": [
            "kms:Describe*",
            "kms:Get*",
            "kms:List*",
            "kms:RevokeGrant"
        ],
        "Resource": "*"
    }
]
}

排查方向

  • 管理员权限并非绝对:AWS管理员账号默认权限可能被KMS密钥策略覆盖。当前密钥策略中,解密所需的kms:Decrypt等权限仅允许通过Secrets Manager服务调用(kms:ViaService条件),而第三条仅开放了root用户的元数据访问权限,管理员用户不在直接授权范围内。
  • 验证Secrets Manager权限:确认管理员用户是否拥有secretsmanager:GetSecretValue权限,排查是否存在权限边界(Permission Boundary)或组织SCP限制该操作。
  • 检查KMS策略的服务条件:确认Secrets Manager密钥确实在eu-west-1区域,调用时指定的region与策略中的kms:ViaService匹配。
  • 排查KMS Grant冲突:调用kms:ListGrants查看该密钥的授权记录,若存在限制当前用户的Grant,可尝试撤销。
  • 直接测试KMS权限:用boto3调用KMS客户端的decrypt方法,直接测试是否能访问KMS密钥,区分是KMS层面还是Secrets Manager转发的问题。
  • 检查IAM权限边界与SCP:在IAM控制台查看用户的权限边界,或在Organizations控制台检查组织级SCP是否限制了KMS/Secrets Manager操作。

内容的提问来源于stack exchange,提问作者moulip

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.26 05:50:54