












源账户中的 IAM 用户或角色需要共享 AMI 的权限(EC2 ModifyImageAttribute )





配置目标账户。目标账户中的 IAM 用户或角色需要能够在 cmkSource 上执行 AWS KMS DescribeKey、CreateGrant、ReEncrypt* 和 Decrypt 作,以便从共享加密的 AMI 启动实例


{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"kms:DescribeKey",
"kms:ReEncrypt*",
"kms:CreateGrant",
"kms:Decrypt"
],
"Resource": [
"arn:aws:kms:us-east-1:xxxx:key/09d8aba5-25e0-41d2-86b6-1f2aaa138923"
]
}
]
} |



