我有下面的代码来通过CF创建KMS,但是我从这一节得到了模板错误。这里有没有遗漏什么?
KmsKey:
Type: AWS::KMS::Key
Properties:
Description: KMS-Key
KeyPolicy:
Version: "2012-10-17"
Id: encryption-key
EnableKeyRotation: "True"
PendingWindowInDays: 7
Statement:
- Sid: Allow administration of the key
Effect: Allow
Resource: "*"
Principal:
AWS: arn:aws:iam::#{AWS::AccountId}:root
Action:
- kms:Create*
- kms:Describe*
- kms:Enable*
- kms:List*
- kms:Put*
- kms:Update*
- kms:Revoke*
- kms:Disable*
- kms:Get*
- kms:Delete*
- kms:ScheduleKeyDeletion
- kms:CancelKeyDeletion发布于 2021-05-06 18:10:51
目前唯一明显的是以下内容:
AWS: arn:aws:iam::#{AWS::AccountId}:root应该是:
AWS: !Sub "arn:aws:iam::${AWS::AccountId}:root"https://stackoverflow.com/questions/67415371
复制相似问题