Please explain why a CMK can be used even when it is not permitted by IAM policies and key policies when using KMS CMK
https://dev.classmethod.jp/articles/tsnote-kms-when-using-a-kms-cmk-why-arent-i-denied-using-a-cmk-even-though-my-iam-and-key-policies-dont-allow-it-en/
If you have a fediverse account, you can quote this note from your own instance. Search https://rss-mstdn.studiofreesia.com/users/dev_classmethod/statuses/115494652657348715 on your instance and quote it. (Note that quoting is not supported in Mastodon.)
DevelopersIO