Verifying Resource Principal Access to Encryption Keys

If a file system is encrypted with your own key, IAM policies are required for the file system to read the keys stored in Vault. We recommend using the resource principal in these policies.

You can use the CLI or API to verify whether a file system is using the resource principal. If the file system uses the service principal, update the IAM policies so that the resource principal has access.

Was this article helpful?