When launching instances in Flexera Ocean on AWS, you may see an error indicating that an Amazon EBS volume cannot be encrypted. This error occurs when Ocean attempts to create or attach an encrypted EBS volume, but the required permissions are missing on the AWS Key Management Service [KMS] key.
This issue is most common when you use customer‑managed KMS keys to encrypt EBS volumes.
Symptoms
Instance launches fail with an error similar to the following:
If your launch specification includes an encrypted EBS volume, you must grant the AWSServiceRoleForEC2Spot service‑linked role access to any custom KMS keys.
Cause
The AWS service‑linked role AWSServiceRoleForEC2Spot does not have permission to use the KMS key configured for EBS encryption. Without these permissions, AWS cannot encrypt the volume during instance launch, and the request fails.
Solution
Grant the required permissions to the KMS key used for EBS encryption.
Choose the option that matches how your KMS key is configured.
-
Configure a KMS key in the same AWS account
If the KMS key exists in the same AWS account, update the key policy to allow access from the EC2 Spot service‑linked role.
See Create an encryption key for step‑by‑step guidance.
-
Configure a cross‑account KMS key
If the KMS key is owned by a different AWS account, configure cross‑account access so the EC2 Spot service‑linked role can use the key.
See Use a cross‑account KMS key to encrypt EBS volumes for detailed instructions.
Related Articles
Resolve security group and subnet network mismatch errors 4Number of Views Resolve GKE launchSpec update errors caused by missing node pools 2Number of Views Fix the “can’t spin instances due to duplicate tags” error in Flexera Ocean 2Number of Views Resolve Failed to create pod sandbox errors in EKS when assigning IP addresses 3Number of Views Understand the “instance types are not a subset of ocean cluster” error 2Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago