<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;Aws Invalid Kms Key State&amp;quot; when trying to start new cluster on AWS in Administration &amp; Architecture</title>
    <link>https://community.databricks.com/t5/administration-architecture/quot-aws-invalid-kms-key-state-quot-when-trying-to-start-new/m-p/122265#M3491</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/152274"&gt;@xx123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The error indicates that the AWS KMS key used for encryption is either misconfigured or missing required permissions.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure the KMS key is enabled&lt;/LI&gt;&lt;LI&gt;Verify that the KMS key and your Databricks workspace are in the same AWS region&lt;/LI&gt;&lt;LI&gt;Update the key policy to include your Databricks cross-account IAM role with the following permissions:&lt;BR /&gt;kms:CreateGrant, kms:Decrypt, kms:GenerateDataKey*, kms:DescribeKey&lt;/LI&gt;&lt;LI&gt;Ensure the IAM role ARN is properly included in the key policy&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Thu, 19 Jun 2025 14:41:32 GMT</pubDate>
    <dc:creator>SP_6721</dc:creator>
    <dc:date>2025-06-19T14:41:32Z</dc:date>
    <item>
      <title>"Aws Invalid Kms Key State" when trying to start new cluster on AWS</title>
      <link>https://community.databricks.com/t5/administration-architecture/quot-aws-invalid-kms-key-state-quot-when-trying-to-start-new/m-p/122037#M3481</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;We just established new environment based on AWS. Our first step was to create Cluster but while doing so, we have encountered an error. We tried different policies, configurations and instance types. All resulted in:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Aws Invalid Kms Key State:
The VM was terminated due to invalid KMS key. [details] Client.InvalidKMSKey.InvalidState: Client.InvalidKMSKey.InvalidState: The KMS key provided is in an incorrect state(OnDemand)&lt;/LI-CODE&gt;&lt;P&gt;Any clues how to fix it? What part of config I did messed up? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 19:47:05 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/quot-aws-invalid-kms-key-state-quot-when-trying-to-start-new/m-p/122037#M3481</guid>
      <dc:creator>xx123</dc:creator>
      <dc:date>2025-06-17T19:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: "Aws Invalid Kms Key State" when trying to start new cluster on AWS</title>
      <link>https://community.databricks.com/t5/administration-architecture/quot-aws-invalid-kms-key-state-quot-when-trying-to-start-new/m-p/122265#M3491</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.databricks.com/t5/user/viewprofilepage/user-id/152274"&gt;@xx123&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The error indicates that the AWS KMS key used for encryption is either misconfigured or missing required permissions.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure the KMS key is enabled&lt;/LI&gt;&lt;LI&gt;Verify that the KMS key and your Databricks workspace are in the same AWS region&lt;/LI&gt;&lt;LI&gt;Update the key policy to include your Databricks cross-account IAM role with the following permissions:&lt;BR /&gt;kms:CreateGrant, kms:Decrypt, kms:GenerateDataKey*, kms:DescribeKey&lt;/LI&gt;&lt;LI&gt;Ensure the IAM role ARN is properly included in the key policy&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 19 Jun 2025 14:41:32 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/quot-aws-invalid-kms-key-state-quot-when-trying-to-start-new/m-p/122265#M3491</guid>
      <dc:creator>SP_6721</dc:creator>
      <dc:date>2025-06-19T14:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: "Aws Invalid Kms Key State" when trying to start new cluster on AWS</title>
      <link>https://community.databricks.com/t5/administration-architecture/quot-aws-invalid-kms-key-state-quot-when-trying-to-start-new/m-p/122885#M3518</link>
      <description>&lt;P&gt;Yes, I followed &lt;A href="https://docs.databricks.com/aws/en/security/keys/configure-customer-managed-keys#step-1-create-or-select-a-key-in-aws-kms" target="_self"&gt;this document&lt;/A&gt; and that fixed it. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 20:02:29 GMT</pubDate>
      <guid>https://community.databricks.com/t5/administration-architecture/quot-aws-invalid-kms-key-state-quot-when-trying-to-start-new/m-p/122885#M3518</guid>
      <dc:creator>xx123</dc:creator>
      <dc:date>2025-06-25T20:02:29Z</dc:date>
    </item>
  </channel>
</rss>

