KMS keys do not inherit tags from parent stack #6102
Labels
@aws-cdk/aws-kms
Related to AWS Key Management
bug
This issue is a bug.
in-progress
This issue is being actively worked on.
p1
When creating a KMS key in a stack with tags, the key does not get tagged with the stack's tags.
Reproduction Steps
This stack:
Should create a key with a tag on the kms key, but no tags are present on the kms key.
The created key does not have permissions to kms:TagResource or kms:UntagResource, so tagging is not possible.
Error Log
key (keyFEDD6EC0) Did not have IAM permissions to process tags on AWS::KMS::Key resource.
cdk deploy
output:Environment
Other
Adding kms:TagResource and kms:UntagResource to default IAM policy for kms keys should resolve this issue. Adding TagResource and UntagResource to when creating the key allow tags to be created on the key.
This is 🐛 Bug Report
The text was updated successfully, but these errors were encountered: