Sitelet https://github.com/kubernetes/kops/pull/18671
Skip to content

aws: Restrict KMS permissions to service-mediated calls - #18671

Merged
kubernetes-prow[bot] merged 4 commits into
kubernetes:masterfrom
hakman:kms-scoped-permissions
Aug 8, 2026
Merged

kubernetes-prow[bot] merged 4 commits into
kubernetes:masterfrom
hakman:kms-scoped-permissions

Conversation

@hakman

@hakman hakman commented Aug 8, 2026

Copy link
Copy Markdown
Member

Roles that use customer managed KMS keys (etcd volumes, EBS CSI volumes, Karpenter root volumes, state store SSE-KMS) previously received kms:CreateGrant and kms:DescribeKey unconditionally on Resource: "*". A compromised role could use CreateGrant to authorize itself on any key in the account whose key policy defers to IAM.

In all supported flows an AWS service makes the KMS calls on the role's behalf, so kms:CreateGrant is now allowed only for grants created by an AWS service (kms:GrantIsForAWSResource), and kms:DescribeKey joins the data-plane actions restricted to calls made through EC2 and S3 (kms:ViaService). With EncryptionConfig, control-plane roles keep unconditional data actions for kms-plugins, which do not create grants.

The comment claiming the EBS CSI driver calls CreateGrant directly was outdated: neither aws-ebs-csi-driver v1.58.0 nor karpenter-provider-aws v1.13.0 makes any direct KMS calls. Workloads that do need spec.additionalPolicies or a service account IAM role; a release note documents this. The policy tests now compare complete rendered statements instead of only action presence.

/cc @rifelpet @ameukam

@kubernetes-prow
kubernetes-prow Bot requested review from ameukam and rifelpet August 8, 2026 06:06
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. area/documentation labels Aug 8, 2026
@hakman

hakman commented Aug 8, 2026

Copy link
Copy Markdown
Member Author

/retest

@hakman

hakman commented Aug 8, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-scenario-aws-karpenter

hakman added 4 commits August 8, 2026 15:49
All supported flows that need KMS grants on customer managed keys (etcd
volumes, EBS CSI volumes, Karpenter root volumes) have EC2 create the
grant on the role's behalf, so kms:CreateGrant can be guarded with the
kms:GrantIsForAWSResource condition key instead of being unconditional.
This prevents a compromised role from delegating itself access to
unrelated keys whose key policies defer authorization to account IAM.

kms:DescribeKey is likewise only called through EC2 or S3 in these
flows, so it joins the data-plane actions guarded by kms:ViaService,
falling back to unconditional only for the EncryptionConfig kms-plugin
path where KMS is called directly.
@hakman
hakman force-pushed the kms-scoped-permissions branch from 6c1cd05 to ca9483f Compare August 8, 2026 12:51
@hakman

hakman commented Aug 8, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-scenario-aws-karpenter

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Aug 8, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rifelpet

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 8, 2026
@hakman

hakman commented Aug 8, 2026

Copy link
Copy Markdown
Member Author

/test pull-kops-e2e-cni-cilium

@hakman

hakman commented Aug 8, 2026

Copy link
Copy Markdown
Member Author

/retest

@kubernetes-prow
kubernetes-prow Bot merged commit aafd06a into kubernetes:master Aug 8, 2026
41 of 42 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/documentation cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants