使用boto3调用GetSecretValue时遇KMS访问拒绝问题求助
AWS Secrets Manager调用GetSecretValue时KMS访问被拒问题排查
遇到的错误
botocore.exceptions.ClientError: An error occurred (AccessDeniedException) when calling the GetSecretValue operation: Access to KMS is not allowed
使用的代码
import boto3 client = boto3.client("secretsmanager", region_name = "eu-west-1") client.get_secret_value(SecretId="rds_secret")
完整报错栈
Traceback (most recent call last): File "<input>", line 1, in <module> client.get_secret_value(SecretId="rds_secret") File "/home/julien/Documents/cloud-tools/lib/python3.11/site-packages/botocore/client.py", line 553, in _api_call return self._make_api_call(operation_name, kwargs) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/home/julien/Documents/cloud-tools/lib/python3.11/site-packages/botocore/client.py", line 1009, in _make_api_call raise error_class(parsed_response, operation_name) botocore.exceptions.ClientError: An error occurred (AccessDeniedException) when calling the GetSecretValue operation: Access to KMS is not allowed
已确认信息
- 执行
sts get-caller-identity返回正确的用户ARN、访问密钥和账号ID - 使用的是AWS管理员账号
当前KMS密钥策略
{ "Version": "2012-10-17", "Id": "auto-secretsmanager-2", "Statement": [ { "Sid": "Allow access through AWS Secrets Manager for all principals in the account that are authorized to use AWS Secrets Manager", "Effect": "Allow", "Principal": { "AWS": "*" }, "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:CreateGrant", "kms:DescribeKey" ], "Resource": "*", "Condition": { "StringEquals": { "kms:CallerAccount": "<account-number>", "kms:ViaService": "secretsmanager.eu-west-1.amazonaws.com" } } }, { "Sid": "Allow access through AWS Secrets Manager for all principals in the account that are authorized to use AWS Secrets Manager", "Effect": "Allow", "Principal": { "AWS": "*" }, "Action": "kms:GenerateDataKey*", "Resource": "*", "Condition": { "StringEquals": { "kms:CallerAccount": "<account-number>" }, "StringLike": { "kms:ViaService": "secretsmanager.*.amazonaws.com" } } }, { "Sid": "Allow direct access to key metadata to the account", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::<account-number>:root" }, "Action": [ "kms:Describe*", "kms:Get*", "kms:List*", "kms:RevokeGrant" ], "Resource": "*" } ] }
排查方向
- 管理员权限并非绝对:AWS管理员账号默认权限可能被KMS密钥策略覆盖。当前密钥策略中,解密所需的
kms:Decrypt等权限仅允许通过Secrets Manager服务调用(kms:ViaService条件),而第三条仅开放了root用户的元数据访问权限,管理员用户不在直接授权范围内。 - 验证Secrets Manager权限:确认管理员用户是否拥有
secretsmanager:GetSecretValue权限,排查是否存在权限边界(Permission Boundary)或组织SCP限制该操作。 - 检查KMS策略的服务条件:确认Secrets Manager密钥确实在
eu-west-1区域,调用时指定的region与策略中的kms:ViaService匹配。 - 排查KMS Grant冲突:调用
kms:ListGrants查看该密钥的授权记录,若存在限制当前用户的Grant,可尝试撤销。 - 直接测试KMS权限:用boto3调用KMS客户端的
decrypt方法,直接测试是否能访问KMS密钥,区分是KMS层面还是Secrets Manager转发的问题。 - 检查IAM权限边界与SCP:在IAM控制台查看用户的权限边界,或在Organizations控制台检查组织级SCP是否限制了KMS/Secrets Manager操作。
内容的提问来源于stack exchange,提问作者moulip
相关产品推荐
相关产品推荐

