ambitious-air-9293810/31/2023, 2:20 PM
The IAM Role associated with the OIDC config and audience has admin privs across the whole AWS account. Our stack config uses KMS as a secrets provider. The stack config is configured to use an AWS profile thus:
Error: Preview failed: error: getting stack configuration: get stack secrets manager: operation error KMS: Decrypt, failed to sign request: failed to retrieve credentials: failed to refresh cached credentials, no EC2 IMDS role found, operation error ec2imds: GetMetadata, canceled, context deadline exceeded
but I'm overriding that in the Deployment config with the mapping
(at least I'm assuming that's overriding it). I've also verified that the KMS key has a policy attached to it that allows access from the whole AWS account. Anyone have any ideas what I'm doing wrong?
red-match-1511611/01/2023, 1:49 AM
but I'm overriding that in the Deployment config with the mappingwhat's the command you're using to do this? and does the config you expect show up in the stack update?
ambitious-air-9293811/01/2023, 10:28 AM