AWS SageMaker无法创建Notebook实例求助:KMS密钥ARN无效
Hey there! Let’s work through this KMS key issue you’re facing when setting up your first SageMaker Notebook instance—super common for folks just getting started, so no worries.
The error message is telling us exactly what’s wrong: the KMS key ARN you specified either doesn’t exist, is formatted incorrectly, or your AWS identity doesn’t have permission to access it. Here’s how to fix it step by step:
Double-check your KMS key ARN format
AWS KMS key ARNs follow a strict structure:arn:aws:kms:<region>:<account-id>:key/<key-id>
For example:arn:aws:kms:us-east-1:123456789012:key/1a2b3c4d-5e6f-7g8h-9i0j-k1l2m3n4o5p6
Don’t type this manually—head to the AWS KMS console, find the key you want to use, and copy the ARN directly to avoid typos.Verify the KMS key exists in the right region
KMS keys are region-specific! Make sure you’re looking in the same AWS region where you’re trying to create the SageMaker Notebook instance. Go to the KMS console, switch to the correct region, and check the "Customer managed keys" list. If the key isn’t there, it might have been deleted, or you’re in the wrong region.Ensure your IAM identity has the right KMS permissions
Even if the key exists, the IAM role (or your console user) creating the Notebook instance needs permissions to interact with the KMS key. At minimum, you’ll need these permissions:kms:CreateGrantkms:DescribeKeykms:GenerateDataKey(required for encrypting the EBS volume)
You can add a policy like this to your IAM role (replace the resource ARN with your actual key’s ARN):
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "kms:CreateGrant", "kms:DescribeKey", "kms:GenerateDataKey" ], "Resource": "arn:aws:kms:<your-region>:<your-account-id>:key/<your-key-id>" } ] }Skip encryption entirely (for testing purposes)
If you’re just experimenting and don’t need encrypted storage right now, you can disable the "Encrypt volume" option when creating the Notebook instance. This will bypass the KMS key requirement and let you create the instance without hitting this error.
One last thing to check: if you’re part of an AWS Organization, there might be an organization-level policy restricting access to KMS keys. If none of the above steps work, reach out to your AWS admin to confirm there aren’t any policy blocks in place.
内容的提问来源于stack exchange,提问作者kokorambo

