You must be logged in to view saved presets
Configuration to create an AWS KMS Replica Customer Key based on an existing multi-region key
Note: For CLI templates, you must select the region
The template can also be used to create a primary key. The following settings are available:
AWSTemplateFormatVersion: '2010-09-09'
Description: ''
Resources:
ReplicaKeyKmsKey:
Type: 'AWS::KMS::ReplicaKey'
Properties:
PrimaryKeyArn: ''
KeyPolicy:
Version: '2012-10-17'
Statement:
- Sid: Enable IAM User Permissions
Effect: Allow
Principal:
AWS:
'Fn::Join':
- ''
- - 'arn:aws:iam::'
- Ref: 'AWS::AccountId'
- ':root'
Action: 'kms:*'
Resource: '*'
Parameters: {}
Metadata: {}
Conditions: {}