KMS and IAM role

  1. need to add KMS operations permission to the IAM role definition
  2. need to grants operations to the IAM role(as principla) in KMS grants definition