Troubleshooting Issues Related to Customer-Managed KMS Keys

Issue Possible Cause What You Can Do
SCM stack fails while creating SCM file storage with a KMS key. The defined tag, dynamic group, File Storage service policy, or KMS key-use policy is missing or incorrect. Verify the KMS key OCID, tag namespace, tag key, tag value, dynamic group rule, File Storage service principal, and policy propagation.
SCM boot volume encryption fails. The Block Volume service cannot use the KMS key. Verify the blockstorage service policy for the SCM file storage KMS key.
Siebel environment stack rejects the payload. siebel_storage_kms_key_ocid and siebel_storage_kms_key_dg_defined_tag were not provided together, or they were provided for BYO FSS. Provide both fields together only for SCM-created Siebel File Systems or omit both fields to use Oracle-managed encryption.
BYO file systems are not encrypted with the supplied key. SCM does not create or re-encrypt BYO file systems. Configure encryption on the BYO file systems outside SCM.
The OKE work request reports that the cluster resource principal cannot use the KMS key. The OKE cluster is not matched by the dynamic group, or the dynamic group does not have key-use permission. Verify the KMS key OCID, defined tag namespace, defined tag key, defined tag value, dynamic group rule, and IAM policy. Allow time for IAM policy propagation.
SCM logs warnings and proceeds but may fail later. For example, KMS prerequisite preflight could not verify defined tag, dynamic group, or policy prerequisites. The SCM OCI profile cannot inspect tenancy-level prerequisites. Ask the OCI administrator to verify the KMS key, defined tag, dynamic group, and IAM policy configuration.