<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Unable to initialize compute cluster CDP Public cloud in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/414031#M254330</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/122440"&gt;@Lorenzo_F&lt;/a&gt;&amp;nbsp;Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.&amp;nbsp; Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 08 May 2026 03:48:09 GMT</pubDate>
    <dc:creator>DianaTorres</dc:creator>
    <dc:date>2026-05-08T03:48:09Z</dc:date>
    <item>
      <title>Unable to initialize compute cluster CDP Public cloud</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/413970#M254304</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I’m facing an issue while initializing a compute cluster on an existing CDP Public Cloud environment (AWS) using restricted IAM policies.&lt;/P&gt;&lt;P&gt;The operation fails with the following error:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;IAM Restricted Resource Policy validation cannot be completed on AWS:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;secret encryption is enabled but the secret encryption KMS key is not provided.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Liftie does not have the permission to create the KMS key.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Please provide a valid Customer Managed Key for secret encryption&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the other experience (CDE,CDF) &lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;I bypassed this error by adding skip validation. Unfortunately, skip validation is not possible when activating the compute cluster.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; I've modified also the cross account role by adding the action as mentioned on paragraph "For Let CDP generate CMK"&amp;nbsp;&lt;A href="https://docs.cloudera.com/dataflow/cloud/aws-requirements/cdf-aws-requirements.pdf" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/dataflow/cloud/aws-requirements/cdf-aws-requirements.pdf&lt;/A&gt;&amp;nbsp;but nothing to do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any suggestion?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 07:43:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/413970#M254304</guid>
      <dc:creator>Lorenzo_F</dc:creator>
      <dc:date>2026-04-29T07:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to initialize compute cluster CDP Public cloud</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/413998#M254319</link>
      <description>&lt;P&gt;Use a pre‑created Customer Managed KMS Key (CMK) for secret encryption; with restricted IAM, Liftie cannot create the key automatically.&lt;/P&gt;&lt;P&gt;In AWS KMS, create or select a symmetric CMK in the same region as the CDP environment.&lt;/P&gt;&lt;P&gt;Edit the Compute Restricted IAM policy and in the statement RestrictedKMSPermissionsUsingCustomerProvidedKey, replace the placeholder with the exact CMK ARN.&lt;/P&gt;&lt;P&gt;Make sure that statement includes KMS actions such as kms:CreateGrant, kms:DescribeKey, kms:Encrypt, kms:Decrypt, kms:ReEncrypt*, kms:GenerateDataKey*.&lt;/P&gt;&lt;P&gt;On the CMK itself, edit the KMS key policy to allow the required service roles (for example AWSServiceRoleForAutoScaling and the EKS/EC2 roles used by CDP) to use the key with the same KMS actions.&lt;/P&gt;&lt;P&gt;Re‑run the compute cluster activation; since skip‑validation is not supported here, it will only succeed once the CMK and all related permissions are correctly configured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If, after these changes, the error persists, the next step is to capture the environment name, CMK ARN, and the full key policy, and open a case with Cloudera Support&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/122440"&gt;@Lorenzo_F&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 09:33:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/413998#M254319</guid>
      <dc:creator>RAGHUY</dc:creator>
      <dc:date>2026-05-05T09:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to initialize compute cluster CDP Public cloud</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/413999#M254320</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/101097"&gt;@RAGHUY&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;thanks for the suggestion.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;I already have other Cloudera experiences installed (CDE, CDF, CML) and haven't used custom CMKs.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Do you know if enabling the CMK at the environment level would have any impact on these services?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz"&gt;&lt;SPAN class="ryNqvb"&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 10:03:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/413999#M254320</guid>
      <dc:creator>Lorenzo_F</dc:creator>
      <dc:date>2026-05-05T10:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to initialize compute cluster CDP Public cloud</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/414000#M254321</link>
      <description>&lt;P&gt;Enabling a CMK at the environment level is meant for new encryption use in that environment, not for changing how already running services are encrypted.&lt;/P&gt;&lt;P&gt;It should not disrupt existing CDE, CDF, or CML services that are already deployed and running.&lt;/P&gt;&lt;P&gt;Existing services generally continue using the encryption setup they already have.&lt;/P&gt;&lt;P&gt;The CMK choice is typically applied to new resources or new clusters created after the CMK is configured.&lt;/P&gt;&lt;P&gt;In practice, the main impact is on future deployments, not on the current installed services.&lt;/P&gt;&lt;P&gt;The CMK setting is usually a one-time environment configuration for that environment.&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/122440"&gt;@Lorenzo_F&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 10:16:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/414000#M254321</guid>
      <dc:creator>RAGHUY</dc:creator>
      <dc:date>2026-05-05T10:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to initialize compute cluster CDP Public cloud</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/414031#M254330</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/122440"&gt;@Lorenzo_F&lt;/a&gt;&amp;nbsp;Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.&amp;nbsp; Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2026 03:48:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Unable-to-initialize-compute-cluster-CDP-Public-cloud/m-p/414031#M254330</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2026-05-08T03:48:09Z</dc:date>
    </item>
  </channel>
</rss>

