If your secrets are encrypted with a customer-managed KMS key (rather than the default AWS-managed key), you must also grant the kms:Decrypt action on your Role permissions by adding the following:
You can restrict access to specific resources using wildcards.However, ssm:DescribeParameters must always target Resource: "*" — AWS does not support resource-level restrictions for this action. Without it, Qovery cannot list available parameters when configuring an external secret.Example:
If your secrets are encrypted with a customer-managed KMS key (rather than the default AWS-managed key), you must also grant the kms:Decrypt action on your Role permissions by adding the following:
You can restrict access to specific resources using wildcards.However, ssm:DescribeParameters must always target Resource: "*" — AWS does not support resource-level restrictions for this action. Without it, Qovery cannot list available parameters when configuring an external secret.Example:
If your secrets are encrypted with a customer-managed KMS key (rather than the default AWS-managed key), you must also grant the kms:Decrypt action on your Role permissions by adding the following:
You can restrict access to specific resources using wildcards.However, ssm:DescribeParameters must always target Resource: "*" — AWS does not support resource-level restrictions for this action. Without it, Qovery cannot list available parameters when configuring an external secret.Example:
If your secrets are encrypted with a customer-managed KMS key (rather than the default AWS-managed key), you must also grant the kms:Decrypt action on your Role permissions by adding the following: