I'm getting this as well, and assume it's because S3 Transfer Acceleration is not available in GovCloud. I'm going to open a support case about it, since I think the app should gracefully handle that.
... View more
The IAM user/group or role you're using for collection needs permissions to decrypt using the key, specifically the "kms:Decrypt" action. This can be scoped to just the KMS key used on the bucket you're collecting from. An example policy document:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "kms:Decrypt",
"Resource": "ARN-OF-KMS-KEY"
}
]
}
... View more