Skip to content

Knowledge base ingestion fails for SSE-KMS encrypted S3 buckets: KB service role lacks kms:Decrypt #2440

Description

@i-jankovic-levi9-com

Description

A knowledge base created with agentcore add knowledge-base and an S3 data source can't ingest documents when the source bucket uses SSE-KMS with a customer-managed key. The ingestion job finishes as COMPLETE with every document reported as failed. The only failure reason is a truncated message: ["The IAM Role (arn:aws:iam"].

The service role that AgentCoreKnowledgeBase (in @aws/agentcore-cdk) creates only grants:

  • bedrock:InvokeModel on amazon.titan-embed-text-v2:0 and inference-profile/*
  • s3:GetObject and s3:ListBucket on the source bucket

It has no kms:Decrypt on the bucket's KMS key, so the service can list objects but can't read them. agentcore.json has no field for a KMS key on a knowledge base or data source, so this can't be fixed through the schema.

A managed knowledge base created in the AWS console against the same bucket works. The console detects the bucket's default encryption key and adds this statement to the role:

{
  "Effect": "Allow",
  "Action": "kms:Decrypt",
  "Resource": "arn:aws:kms:<region>:<account>:key/<key-id>",
  "Condition": { "StringEquals": { "kms:ViaService": "s3.<region>.amazonaws.com" } }
}

Steps to Reproduce

  1. Create an S3 bucket with default encryption aws:kms using a customer-managed KMS key, and upload a document (a CSV in my case).
  2. agentcore add knowledge-base with an S3 data source s3://<bucket>.
  3. agentcore deploy.
  4. Start a sync (console or agentcore run ingest).

Expected Behavior

The document is indexed. Either the construct detects the bucket's KMS key, or agentcore.json lets you set a KMS key ARN for the data source, and the role gets kms:Decrypt scoped via kms:ViaService = s3.<region>.amazonaws.com, the same as the console.

Actual Behavior

The ingestion job reports Scanned: 1, Added: 0, Failed: 1. failureReasons is ["The IAM Role (arn:aws:iam"], which is truncated and doesn't mention KMS, so the cause is hard to find.

CLI Version

0.30.0 (@aws/agentcore-cdk 0.1.0-alpha.53)

Operating System

macOS

Additional Context

Workaround in agentcore/cdk/lib/cdk-stack.ts, after AgentCoreApplication is created:

this.application.knowledgeBases.get('<kbName>')?.role.addToPolicy(
  new iam.PolicyStatement({
    actions: ['kms:Decrypt'],
    resources: [`arn:${this.partition}:kms:${this.region}:${this.account}:key/<key-id>`],
    conditions: { StringEquals: { 'kms:ViaService': `s3.${this.region}.amazonaws.com` } },
  }),
);

Suggested fix: add an optional kmsKeyArn to the S3 DataSource schema (or detect it with GetBucketEncryption at deploy time) and grant kms:Decrypt in AgentCoreKnowledgeBase. The truncated failureReasons message is probably a separate bug in the service.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions