IP限制策略致AWS CodeCommit加密密钥访问异常,如何兼顾IP限制与控制台可用?
Let's break down what's happening here and how to fix it:
Root Cause
When you add IP restrictions to your IAM policy, you're blocking all requests that don't come from your allowed IPs—including the service-side requests CodeCommit makes to KMS to decrypt repository data when you use the AWS Console. SSH Git works because those requests originate directly from your trusted IPs, but the Console relies on CodeCommit's internal service calls to KMS, which don't carry your client IP, triggering the EncryptionKeyAccessDeniedException.
Step-by-Step Solution
1. Update Your KMS Key Policy to Allow CodeCommit Service Access
First, we need to let the CodeCommit service itself access the KMS key (this is separate from your user/role permissions). Go to the KMS console, find your encryption key, and edit its policy to add this statement:
{ "Sid": "AllowCodeCommitServiceToUseKMS", "Effect": "Allow", "Principal": { "Service": "codecommit.amazonaws.com" }, "Action": [ "kms:Decrypt", "kms:GenerateDataKey" ], "Resource": "*", "Condition": { "StringEquals": { "aws:SourceAccount": "YOUR_AWS_ACCOUNT_ID" }, "ArnLike": { "aws:SourceArn": "arn:aws:codecommit:YOUR_REGION:YOUR_AWS_ACCOUNT_ID:*" } } }
This ensures CodeCommit can use the key to decrypt repo data when handling Console requests, without being blocked by IP restrictions.
2. Refine Your IAM Policy to Target IP Restrictions Correctly
Next, adjust your IAM user/role policy to apply IP limits only to your client-side requests (both SSH Git and Console actions), while letting the service-side KMS calls work. Here's a sample policy:
{ "Version": "2012-10-17", "Statement": [ { "Sid": "AllowAllCodeCommitActionsFromTrustedIPs", "Effect": "Allow", "Action": "codecommit:*", "Resource": "arn:aws:codecommit:YOUR_REGION:YOUR_AWS_ACCOUNT_ID:*", "Condition": { "IpAddress": { "aws:SourceIp": [ "TRUSTED_IP_1/32", "TRUSTED_IP_2/32" ] } } }, { "Sid": "AllowKMSAccessForCodeCommitFromTrustedIPs", "Effect": "Allow", "Action": [ "kms:Decrypt", "kms:GenerateDataKey" ], "Resource": "arn:aws:kms:YOUR_REGION:YOUR_AWS_ACCOUNT_ID:key/YOUR_KMS_KEY_ID", "Condition": { "IpAddress": { "aws:SourceIp": [ "TRUSTED_IP_1/32", "TRUSTED_IP_2/32" ] }, "StringEquals": { "kms:EncryptionContext:aws:codecommit:repositoryName": "*" } } }, { "Sid": "AllowBasicConsoleActionsFromTrustedIPs", "Effect": "Allow", "Action": [ "sts:GetCallerIdentity", "codecommit:ListRepositories" ], "Resource": "*", "Condition": { "IpAddress": { "aws:SourceIp": [ "TRUSTED_IP_1/32", "TRUSTED_IP_2/32" ] } } } ] }
- Replace all placeholders (like
YOUR_AWS_ACCOUNT_ID,TRUSTED_IP_1) with your actual values. - The first statement restricts all CodeCommit actions to your trusted IPs.
- The second statement lets your user access KMS for CodeCommit only from the allowed IPs, using the encryption context to tie it directly to CodeCommit repos.
- The third statement grants basic Console navigation permissions (adjust if you need more Console-related actions).
Verification
- Save both the KMS and IAM policies.
- From your trusted IPs:
- Open the AWS Console and navigate to CodeCommit—you should no longer see the encryption key error, and repositories will load correctly.
- Use SSH Git to pull/push code—this should still work as before.
- From an untrusted IP:
- Both Console access and Git operations should be blocked, as expected.
内容的提问来源于stack exchange,提问作者nikitasius

