Hashicorp Vault AutoUnseal Lab Seems Broken

I think the ARN and AWS static secrets may no longer be working.

This is Installing Vault → Lab: Configure Auto Unseal

Steps

# configure
source ~/AWS_Credentials.txt
cat << EOF >> /etc/vault.d/vault.hcl

seal "awskms" {
  region     = "$(cat $AWS_REGION)"
  kms_key_id = "$(cat ~/kms_key)"
}
EOF
cp ~/AWS_Credentials.txt /etc/vault.d/vault.hcl

# start service
systemctl start vault

Actual Results

From journalctl -u vault.service:

Apr 17 00:08:20 KMS wrapping key information: UnrecognizedClientException: The security token included in the request is invalid.
Apr 17 00:08:20 vault-node vault[1877]: status code: 400, request id: 499d8ece-90eb-4ce4-ae4b-e8124f0003c5

cc @rob_kodekloud @btkrausen

It is broken.
There is already a ticket for the lab team to fix.

I have the same issue, upvoted.

Almost a month still remains broken.

I can see that the ticket has an assignee, but don’t have access to know when it will be worked on.